#modules

1 messages · Page 452 of 1

strong acorn
#

HTB site down for me

inland oak
#

u means server is down? but mine is okay since 10am till now..

strong acorn
lapis sky
#

AD Enumeration & Attacks - Skills Assessment Part II
--> Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.

is it normal that i get no results while using
||sudo crackmapexec smb 172.16.7.50 -u A... -p w*** --users||
i get no users or anything at all, just confirming im logging with the right credentials, used kerbrute and got users but nothing was useful

inland oak
storm elk
#

site is working fine for me

desert inlet
#

hey everybody! i have a question concerning the Advanced deserialization module

#

because of reasons i had to change laptop and i have some problems while adding breakpoints in dnspy

#

is somebody able to give me some advice?

strong acorn
lapis wadi
#

guys how do i gain user flag in soulmate

#

its been 7 days and i haven't been able to get even user flag

#

at this point its discouraging

desert inlet
#

NVM , it looks like executing Enable-IISAssemblyDebugging for 20 times while been angry has worked

strong acorn
#

Understanding Log Sources & Investigating with Splunk / Using Splunk Applications

Sysmon App for Splunk doesn't exist in the target machine.

strong acorn
inland oak
#

qwer1234

desert inlet
#

i am back again everybody! can anybody help me with the advanced deserialization module?

cunning cape
#

Hey

#

Why I can't speak in modules?

#

I want to ask something

waxen totem
cold pilot
#

hey did you figure this out? can't seem to run commands through SharpNoPSExec either...

cunning cape
#

why i can't speak in general

waxen totem
cunning cape
#

i'm leaving

grizzled schooner
#

Then leave, no need for that

storm elk
fossil sequoia
#

hello in the Active Directory Enumeration & Attacks on the Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux section

#

i can't crack the hash of the user in the question #1

frank bloom
#

I want WiFi penetration testing and network basics lessons in PDF format

storm elk
#

@frank bloom - there's modules in academy

#

no need to cross post

opal shuttle
#

try passing the hash

fossil sequoia
opal shuttle
#

there should be something they should have mentioned in the module

#

read that seciton carefully

opal shuttle
gray yacht
opal shuttle
#

maybe hashtype is wrong

gray yacht
#

This module is over Tier 0, so I am deleting your screenshot. You can ask your question and for sharing specifics, take it to DMs when someone agrees to take it to DMs.

#

I'm deleting your screenshot as this content is above Tier 0.

opal shuttle
#

you can dm me

fossil sequoia
#

I think that the problem is my wordlist 😂

opal shuttle
#

rockyou.txt works fine brother

#

that's not the problem

gray yacht
opal shuttle
quiet ember
#

Has anyone else had trouble with getting WSUS to work in the Windows Lateral Movement skills assessment? ||I can get a shell when from SUPPORT when I force it to check for updates but nothing happens when I let it sit, the gui shows that the update will be at 100% but nothing gets executed it seems||

snow stream
#

I need help learning OSINT for a specific project task can anyone please dm me if they can help or know someone who can help me.

dusty pilot
#

I'm doing the footprinting medium lab and I found the NFS server, but I get a permission denied error when I try to cd into the mounted folder. Any idea why that is? I can't even change permissions with sudo chmod

gray yacht
crisp remnant
#

Anyone had issues with the "Attacking AI - Application and System" module and specifically the challenge for section "Rogue actions" ?

waxen totem
dusty pilot
waxen totem
rustic sage
waxen totem
rustic sage
#

Thank you for the help

jolly oasis
#

I don't think that's what this channel is for. This is for asking questions related to specific HTB modules. Also, pinging everyone is not the way to get your question answered.

obtuse anchor
#

w h a t

#

just where is that server

#

tell me

sick stump
weak knoll
#

lol

crisp remnant
#

Is there someone that have finished the module "Attacking AI - Application and System" i need a bit of assistance on one of the sections if possible

iron viper
#

Hey guys did any one solve dusty Alles challenge I'm stuck on the part where is the key

devout tide
#

Guys

#

Is there a way to get free modules?

acoustic owl
#

All Tier 0 modules are free. Activation costs 10 cubes, but you will receive 10 cubes back upon completion of the module.

fringe thistle
#

Hi, I have a big issue solving the Prompt Injection Attacks Skill Assessment. Nothing seems to work within the chat. I was able to get the system leak the admin key and could login into the admin pannel (where there is just a report of the chatbot that analyzed the chats). But to get the CEOs out deleted or banned wont work. I cant find hints to it or something. Can the flag be archieved to the chatbot or do i need to attack another part?

#

@cunning canopy thx

icy egret
#

hello guys, anyone here can help me with Windows Privilege Escalation Citrix Breakout?

#

I have found the flag using paint dialog box, but i am not able to see my share from my attack box, like how htb shows me to do.

#

any ideas?

wary turret
delicate adder
#

I'm trying to enumerate a host name but I don't understand which nmap option I need to find out the host name

acoustic owl
wary turret
hasty mauve
#

Module: Windows Lateral Movement
Section: Skills Assessment
Question: What is the password for VNC?

I used the user || rossy to create a malicious update to add myself to the administrators group ||, I was able to force that on the || SUPPORT ||, but the || BACKUP || device seems to be unreachable.
The || WSUS || shows that it did not report status back in a long time.
I'm stuck and have no idea what should I do.
I already have an admin account on SUPPORT but have no idea how to go from there.

paper vapor
#

Hello, i'm stuck in the Session Hijacking module, it's said that my url is invalid but it's working in firefox ...
Can someone come DM pls §

timid bloom
#

yo

dark jay
#

Hello i am doing hackthebox Login brute force skills assessment 2 and it is kinda strange, i dont understand what to bruteforce with the skills assessment 1 username i mean it asks the username of ftp and how do i use last username that i got for that can anyone help?'

terse bloom
#

Does the weekly streak have any rewards? I have a 17 week streak and don't know what is the point of it

hasty mauve
gray yacht
cyan arch
#

i would guess the latter

dark jay
#

oh sorry i did not see this message

#

okay thanks delete it i am doing it rn if i have some problems i will dm you

inland oak
#

I sent someone a dm today to ask something, but I forgot the question. Two minutes later, he mentioned my name in the channel… I felt so shy. Now I’m scared to dm anyone again.

upper hedge
#

Hola Amigos,

I'm trying to understand the Pivoting & Tunneling module but there is this PROXYCHAINS which always causing the problems for every chapter.
I can't nmap, ping etc... even after following step by step process. I tried sudo, but it still doesn't solve the problem. Am i missing something from basics...? I don't know.
Please help me(DM is also appreciated)

gray yacht
flint palm
digital pendant
#

worth mentioning #rules does say don't DM anyone without prior permission, but yeah asking questions in the relevant channel is encouraged

fading hare
fading hare
#

Same ... did you find the solution?

#

I'm also stuck at that part

#

Did you find a solution?

#

Me too, did you find a solution?

silk laurel
#

Is anyone available to answer a question about the Skills Assessment of the Attacking AI - Application and System module? I found an LFI - but cant find a flag location + a possible SQL injection (which always crashes the server) and am therefore stuck. - Is there someone that can give me a nudge please?

fading hare
austere forge
#

In module web proxies skills assessment, I dont get the flag taking out the disabled

paper vapor
#

No inside the XSS module, the session hijacking, i have this issue

cosmic hornet
#

Any tutorial about how to configure HTB's OpenVPN on OPNsense so I can share the connection with multiple virtual machines?
Is that good to post it here? I can't post anywhere else since I have no permission

still edge
#

Hi I have a question about this module Academy: Attacking Common Services | Attacking DNS
i found some subdomain with gobuster but the one i need doesn't seems to be found . i know in the module they talk about subbrute but is it possible to find it without subbrute ?

paper vapor
#

i reiterate my question because i'm still stuck on the session hijacking from the XSS module and i can't get the flag even if it'sworking from my browser

crisp remnant
#

Well same as everyone i guess "Rogue Actions"...

wild sage
cosmic patrol
warm pumice
#

Is the new module red or blue team

rain hawk
#

Hello everyone

rustic sage
#

@fathom pendant Hey quick question, during the exam with the document is the "report date" when you started the report? or when it ends?

fathom pendant
rustic sage
#

Okay

#

where can i check for that?

fathom pendant
#

i believe sysreptor allows for a start - end date for the assessment

rustic sage
#

theres a pentest start and end but theres a report date

stable flume
#

umm... guys im confused does skills assessments medium level on attacking common application modules supposed to be this easy??? i just finished it like in 2 steps which is ironic because i spent hours on the easy level

stable flume
#

aint no way im that smart 😭

silk lagoon
#

Anyone able to help with **Exploitation of PDF Generation Vulnerabilities
**. Please pm

still edge
void valley
#

Hi peeps, I'm doing the Footprinting section, and I'm stuck on the last question in the DNS module. What is the FQDN of the host where the last octet ends with "x.x.x.203"? I've been stuck on this for 3 days. I ran the command for sub in $(cat /usr/share/seclists/Discovery/DNS/combined_subdomains.txt);do dig $sub.inlanefreight.htb @10.129.1.80 | grep -v ';|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done but all I get are 3 zones, and they all point to the local 127.0.0.1 and not the IP address ending with .203. Can someone please be kind, and give me a hint that actually helps? The forum on this was not helpful at all.

little terrace
#

is it better to use bloodhound ce or bloodhound legacy

silk lagoon
#

Was able to get the flag for **Exploitation of PDF Generation Vulnerabilities
**
But want to know initially why I kept getting errors, way around that was just going straight to the target, without spoiling too much. If anyone can dm, would be highly appreciated.

brittle olive
#

Anyone know the indented path for the WIndows lateral Movement SA. I finished it but I dont think the path taken was indented one. DM if you have input.

fathom pendant
#

@void valley please try not to reveal module content. but also try a more fierce wordlist, the i* subdomain isn't the only one you can dig through. But a tool in the module can do the work for you

#

@void valley the spoiler tags don't work too well. But i gave you a hint to the proper wordlist

#

if you're gonna use spoiler tags; still redact information

still edge
#

i guess i do really need to use subbrute. for the DNS seems to be the only one that give the one needed

timber hatch
#

API Attacks
Broken Authentication
Exploit another Broken Authentication vulnerability to gain unauthorized access to the customer with the email 'MasonJenkins@ymail.com'. Retrieve their payment options data and submit the flag.

||I think the logic is that I have to try to figure out the correct OTP and set a new password, which I tried with:
ffuf -w /opt/useful/seclists/Passwords/xato-net-10-million-passwords-10000.txt:PASS -w customerEmails.txt:EMAIL -u http://94.237.57.1:50993/api/v1/authentication/customers/passwords/resets -X POST -H "Content-Type: application/json" -d '{"Email": "EMAIL", "OTP": "PASS", "NewPassword":"supersafe1234"}' -t 100 -fs 23||

i do not gain any results, so is my logic right, but the command is still wrong, or is also my logic wrog?

fiery berry
timber hatch
#

like in the provided command from the module:
@htb[/htb]$ ffuf -w /opt/useful/seclists/Passwords/xato-net-10-million-passwords-10000.txt:PASS -w customerEmails.txt:EMAIL -u http://94.237.59.63:31874/api/v1/authentication/customers/sign-in -X POST -H "Content-Type: application/json" -d '{"Email": "EMAIL", "Password": "PASS"}' -fr "Invalid Credentials" -t 100

fiery berry
fathom pendant
#

i.e. 0000 -> 9999

timber hatch
#

thanks 🙂

timber hatch
quartz ridge
#

Hi guys

#

Why locked this module ??

storm elk
#

no clue there @quartz ridge - are you on a plan? or do you buy modules with cubes?

quartz ridge
#

I was buy bug bounty hunter path

#

With cubes

#

And I solved 2 modules

autumn pilot
#

You need to have 100 cubes in your account to unlock the module

quartz ridge
#

Next step is close like that

storm elk
#

Then yes, its normal that its locked. If you use cubes, you will have to buy each module separately

#

Try looking into a plan as thats mostly more cost effective

quartz ridge
#

Okay I know . Thank you for replying

rugged hull
#

Sorry, I'm doing the "Using Splunk Applications" and have followed every single step right so far. However with the question: Fix the search associated with the "Net - net view" report and provide the complete executed command as your answer. Answer format: net view /Domain:_.local. Well, I've reached the command part but there are no domains or anything like that. Can u guys tell me what my problem is?

exotic venture
#

I am new at hack the box, from where should I should, please help me, Friends

compact patrolBOT
errant wing
amber heath
#

Are there multiple ways to get foothold in AEN or just one?

#

I'm in blind just wondering, please no spoiler 😄

digital pendant
delicate adder
#

I'm doing the nmap pattern and there's a query that tells me to enumerate the host name and I can't find the name

#

I tried DNS resolution but it doesn't say anything in the output.

worn roost
#

Why can’t i chat in general

waxen totem
vagrant wraith
#

Hey guys currently tryna solve the AEN lab needed help with an IDOR vuln on the careers subdomain but stuck on what to do next. Any tips on exploiting the profile ID parameter?

#

i mean the idor worked by chaning the "id=9" param by creating other accounts yet i cant find the flag nor do i know what im doing wrong

thick depot
#

hi guys, can you help me for this challenge "Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer." im stuck in here, if you can give me a clue or another step?

gray yacht
edgy karma
#

Did u find a solution?

tender nimbus
edgy karma
#

.

#

And it run

hybrid pilot
#

In Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux I'm trying to run the first command displayed:

GetUserSPNs.py -target-domain FREIGHTLOGISTICS.LOCAL INLANEFREIGHT.LOCAL/wley

but I'm always getting [-] [Errno 113] No route to host ? What am I missing here

#

tried fiddling with the /etc/resolv.conf (which comes later in the section) to no avail

gray yacht
hybrid pilot
#

interfaces look correct to me

hybrid pilot
gray yacht
# hybrid pilot not yet. this would have been my last resort

Since you are SSH'd into the attack host, you shouldn't have any issues with a route, so I would simply reset the target and after it spawns give it a couple of minutes before you access the attack host, just to make sure things are finished configuring within the environment.

#

If that doesn't fix it, you can DM.

drifting dirge
olive cedar
#

Hello, im stuck in the "filter contents" part with the question:
  Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths (https://www.inlanefreight.com/directory" or "/another/directory") of that domain. Submit the number of these paths as the answer.
I have first tried to get the source code with curl https://www.inlanefreight.com > source-code.txt , but I get the error:
curl: (28) Failed to connect to www.inlanefreight.com port 443 after 133767 ms: Couldn't connect to server

still edge
burnt linden
median kettle
#

anyone complete or working on the wifi attack module? im stuck on the last mask question attaack. apparently its gonna take me 3 years to crack the wpa hash.....help

median kettle
#

nvm figured it out

wraith trellis
#

hey ! i cannot write in the general field.. anyone know why ?

thick depot
gray yacht
jade frigate
#

can someone help me with the report sample of inlanefreight.local at the module "Documentation and Reporting"?

I tried to download and extract the content of the zip folder but both the files keep getting the same error message: 0x80004005

fathom pendant
#

that error is just a generic "Access Denied" error, iirc the archive is password protected

jade frigate
#

so how should I proceed? It doesn't ask for a password or anything, it just don't get extracted out of the zip file

digital pendant
#

It wont ask for password with zip on windows, use 7zip instead. Password prompt then

jade frigate
digital pendant
#

At least it never did for me! Maybe we have something disabled

#

https://learn.microsoft.com/en-us/answers/questions/4139006/password-requiring-dialogue-doesnt-appear-when-ope

Looks more like the source of how it was encrypted is not readable by the windows zip utility.

Hi,
I was sent a password-protected zip file, and I have the password.
I can open the zip folder without any problem, but not the files inside. When I click on one, a message like this appears:
"Windows cannot complete the extraction.
The…

#

<@&861185840277487616> probably not a serious one but not worth the spam

fathom pendant
#

@red fossil this isn't the server for that

edgy karma
#

In the malware analysis module, skill assessment, I am trying to match the address of an arbitrary instruction from IDA to x64dbg but I always get a mismatch. According to the debugging session, I am expected to do that. What is going on?

tiny frigate
#

I'm currently re-reading the Login Brute Forcing module, and realized that I don't really understand how Content-Length in the http header is dealt with when using Hydra and Medusa.
Honestly I don't recall ever really messing with this (meaning I wouldn't manually include it in the command, it is however included in some of the examples), but it doesn't look like it gets dynamically adjusted, does it? Wouldn't that mess with the request if there's a mismatch or the parameter is missing?

tiny frigate
#

You don't have to add it for either, but as far as I understand you can

fossil sequoia
#

hello

tiny frigate
#

Thanks, yeah, that's kind of where my question came from. Neither have I ever bothered.
But isn't that parameter required for a proper request?

#

I'd think the server might reject it with "malformed" etc. otherwise...or trunk the data sent if the announced length is too short.
I guess I'm wondering if Hydra or Medusa calculate it dynamically somehow...or if the target servers are configured in a way that they ignore it

gray yacht
#

Why not play around with it to figure things out or just use an Internet search? This is from content over Tier 0 so I am going to delete this screenshot. If you are still truly lost after just messing with it or using an Internet search, you can DM.

plain summit
#

Attacking Enterprise Networks Post-Exploitation
After running sudo ip route add 172.16.9.0/24 dev ligolo
and tunneling on proxy, I was not able to ping 172.16.9.25 on my machine while I am able to ping 172.16.8.120 on my machine (sudo ip route add 172.16.8.0/24 dev ligolo)

normal vigil
#

what kind of server is this and what is hack the box

fathom pendant
pallid pilot
#

Hi, can somebody give me a hand with parameter logic bugs SA, if somebody can just give me a hint or something im stuck

rotund sorrel
#

Hi all!

I'm working on the question for Attacking common services -> Attacking DNS (https://academy.hackthebox.com/module/116/section/1512)

My /etc/hosts and resolvers.txt looks like this:

 ~/Desktop/commonattacks/subbrute  master !1 ?2  cat /etc/hosts                                                                          ✔  14:26:04 
127.0.0.1       localhost
127.0.1.1       kali
::1             localhost ip6-localhost ip6-loopback
ff02::1         ip6-allnodes
ff02::2         ip6-allrouters
10.129.75.19 inlanefreight.htb
10.129.75.19 ns1.inlanefreight.htb

 ~/Desktop/commonattacks/subbrute  master !1 ?2  cat resolvers.txt                                                                       ✔  14:26:07 
10.129.75.19
ns1.inlanefreight.htb
#

Then, running subbrute does not yield results, though it returns a number of errors, which are supposed to be fixed by adding the STMIP to /etc/hosts and resolvers.txt.

./subbrute.py http://inlanefreight.htb -s /usr/share/seclists/Discovery/DNS/namelist.txt -r resolvers.txt
/home/kali/Desktop/commonattacks/subbrute/./subbrute.py:462: SyntaxWarning: invalid escape sequence '\.'
  permute_filter = re.compile("^[a-zA-Z0-9]{" + str(self.permute_len) + "}\.")
Warning: Fewer than 16 resolvers per process, consider adding more nameservers to resolvers.txt.
Warning: No nameservers found, trying fallback list.
Process lookup-3:
Traceback (most recent call last):
  File "/usr/lib/python3.13/multiprocessing/process.py", line 313, in _bootstrap
    self.run()
    ~~~~~~~~^^
  File "/home/kali/Desktop/commonattacks/subbrute/./subbrute.py", line 422, in run
    response = self.check(hostname, query_type, timeout_retries)
  File "/home/kali/Desktop/commonattacks/subbrute/./subbrute.py", line 342, in check
    resp = self.resolver.query(host)
  File "/home/kali/Desktop/commonattacks/subbrute/./subbrute.py", line 57, in query
    name_server = self.get_ns()
  File "/home/kali/Desktop/commonattacks/subbrute/./subbrute.py", line 107, in get_ns
    ret = self.nameservers[self.pos]
          ~~~~~~~~~~~~~~~~^^^^^^^^^^
IndexError: list index out of range

Can anyone help?

rotund sorrel
#

I've tried including the default resolvers.txt entries below my own, the result remains the same

mighty forum
#

can anyone help with web service and api attack module. Where does the SQLi injection located within the SOAP Request

rustic sage
#

Does "ip a" work the same as ifconfig?

#

Because I can't use ifconfig on my parrot

rustic sage
rustic sage
#

Thank you

remote fulcrum
#

Good evening all. I have an "issue". Doing the Password Attacks Module, Section "Cracking Protected Archives" (https://academy.hackthebox.com/module/147/section/1323). Whun running Hashcat on the Bitlocker hash (for the downloaded VHD file), it cannot find the pwd in the Rockyou list. So whats wrong with this?

digital pendant
rotund sorrel
#

I ended up switching vpn servers & files due to the high load

#

That seemed to have fixed it

digital pendant
#

<@&861185840277487616>

remote fulcrum
#

GO AWAY!!!

digital pendant
#

Try more general chat @hallow dust this is for htb academy module discussions

digital pendant
strange gale
#

Guys i am on module siem use case visualization pt 1. and everytime I use my virtualbox it squishes the screen and I can't see anything

#

It fixes after I move the tab I am on but then squishes down again

signal rain
strange gale
#

Dude you're awesome it worked thank you

signal rain
#

Yuppers

rustic sage
#

Do we have a mod or admin available? I need an intervention to get my HTB account linked to Discord.

ashen mountain
#

Is there some way to check history of module purchases?

#

because i see some modules which i don't remember getting for cubes (or i just have a dementia)

rustic sage
#

Helping users with modules if they would like in DMs

cloud urchin
rustic sage
crimson moon
#

Hi guys im in the web attacks skills assessment and wasn't able to escalate privilege. I have found IDORs and see there are some interesting endpoints to make use of but don't know how to approach it 🙁

#

need some nudge.

silk lagoon
crimson moon
#

i have enumerated deeply found neccessary info but when i try to change passwd it throws error on the front end you know. I'm doing sth dumb i know but i can't put my finger on it lol

silk lagoon
#

Make sure you are using the “necessary info” that you found.

#

Dm if you still can’t wrap your head around it

violet flicker
#

Hey, I am also stuck on this one. I was able to get the admin_key but I can't get command injection

#

Hey would you be able to help with the LLM output attack assessment? I got to the admin chat, but ca't get the flag.

#

Did you figure it out?

potent brook
normal dagger
#

How did you solve the second question I been stuck for days

silk lagoon
#

Anyone able to help with Injection Attacks Skills Assessment? Please dm

solar mango
#

Did you find the credentials? Stuck here

crimson moon
#

can we get rid of the middleman clipboard? I just want to reduce that one step of copy-paste between pwnbox and host lol

autumn pilot
#

Check the permissions in your browser, the copy-pasting should mostly work without needing to use the middleman-feature

brave field
solar mango
compact atlas
#

./subbrute.py http://inlanefreight.htb -s /usr/share/seclists/Discovery/DNS/namelist.txt -r resolvers.txt
/home/kali/Desktop/commonattacks/subbrute/./subbrute.py:462: SyntaxWarning: invalid escape sequence '.'
permute_filter = re.compile("^[a-zA-Z0-9]{" + str(self.permute_len) + "}.")
Warning: Fewer than 16 resolvers per process, consider adding more nameservers to resolvers.txt.
Warning: No nameservers found, trying fallback list.
Process lookup-3:
Traceback (most recent call last):
File "/usr/lib/python3.13/multiprocessing/process.py", line 313, in _bootstrap
self.run()
~~~~~~~~^^
File "/home/kali/Desktop/commonattacks/subbrute/./subbrute.py", line 422, in run
response = self.check(hostname, query_type, timeout_retries)
File "/home/kali/Desktop/commonattacks/subbrute/./subbrute.py", line 342, in check
resp = self.resolver.query(host)
File "/home/kali/Desktop/commonattacks/subbrute/./subbrute.py", line 57, in query
name_server = self.get_ns()
File "/home/kali/Desktop/commonattacks/subbrute/./subbrute.py", line 107, in get_ns
ret = self.nameservers[self.pos]
~~~~~~~~~~~~~~~~^^^^^^^^^^
IndexError: list index out of range

full echo
#

You can dm me

rain mirage
#

password attack , pth for linux
Check Carlos' crontab, and look for keytabs to which Carlos has access. Try to get the credentials of the user svc_workstations and use them to authenticate via SSH. Submit the flag.txt in svc_workstations' home directory.

i cant crack this hash , tried hashcat (-m 1400) any hint ? and wordlist was rockyou

proven plinth
sleek tundra
#

Attacking AI - Application and System > Model Deployment Tampering
Receiving that 500 error when attempting to exploit for module. I did my own research, formed my own POCs, ran into issues, defaulted to what the module itself says, same issues. I ran line for line what the walkthrough says to, same issue. I contacted support and they claim it works, can anyone spot what I did wrong here?

#

Appears that people have asked the same question in this channel and received no help, so I guess it's just gg's until it's accepted that there's an issue with this box? 🤷‍♂️

shut owl
#

Looking at your error message, I have also been receiving 500 errors back as well. I am also trying to figure it out.

autumn pilot
#

I have just tested the exercise following the steps in the walkthrough, and it is working as expected. Also, please obfuscate some of the payload in the screenshot phlebas to avoid spoiling the exercise for others

sleek tundra
autumn pilot
#

As you can see in the screenshot I have a reverse shell connection

sleek tundra
#

And I count 7 others in this chat that have had the same/similar issues

#

9 including us two

autumn pilot
#

Reset the target and try to follow the steps again, if it doesn't work feel free to DM me

sleek tundra
#

Ok, it worked this time around... Gonna try to figure out what I did differently, if anything 🤔

slate trellis
#

Hi, in Intro to Whitebox Pentesting, Skills Assessment challenge it says: There are at least 2 different ways to obtain remote code execution on the target.
I found only one of them, can anyone give a hint about the second vector?

lapis plinth
wild temple
#

hi guys!

#

I'm new

#

nice meeting y'all

delicate stream
#

Hello

delicate stream
dawn parrot
#

module: Web Attacks
section: Bypassing Encoded References
I used the parameter to get the flag as shown in the image. But doubt is how do i get the file with the filename?? coz it's mentioned in the question that we can also do it with filename. And yes is tried /download.php as well as /contracts.php with filename and it's not working
@rustic sage

lapis whale
#

Everything looks correct, I'm just lost as to what is causing the problem

sweet escarp
digital pendant
#

I had some issues with getting this section to work and commenting that out solved issues I was having. I can't recall if it was this specific issue though

#

and your msfconsole socks_proxy module options reads socks5 instead of socks4 right?

lapis whale
#

Ooh, I'll try that. I've tested both socks 4/4a and 5

#

Verified they match both times

digital pendant
#

understood, hopefully the proxy_dns is the issue then and solved by commenting it out

rustic sage
#

and provide a hint

lapis whale
digital pendant
#

recommend jumping onto the pwnbox then. Remove the environment as a factor by using a known good build. Then attempt it with the exact way module reads. Thats how I troubleshoot anyway

lapis whale
#

Sounds like a good idea ^-^

rain mirage
#

module : password attack , ptt for linux
Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

i cant get into the smb for some reason ,

subtle nebula
#

Can someone help me with Wi-Fi Password Cracking Techniques - Skills Assessment?
I don't understand how to crack the 1st, 2nd and 4th wpa handshake

queen verge
#

just wanted to ask everybody whats the best way to learn fuzzing from scratch

queen verge
#

thanks

#

any books or material besides this

#

??

storm elk
#

Google will show you lots of resources 🙂 this module is a free one btw, you get the cubes back on completion

queen verge
#

cool thanks and if i specifically want to do it in context of OS so any reccomendations on this bro

storm elk
#

can't help you there, sorry

#

I'm more of a web guy

queen verge
#

cool

#

thanks

#

what are some good HTB labs for intermidiate ctf questions related to binary and that stuff

#

for google ctf

#

specifically

storm elk
#

Might wanna read #welcome and then ask in another channel as this channel is specifically for Academy modules

queen verge
#

thanks

violet flicker
lapis whale
#

It seems the webserver also randomly crashes or I loose conenction to it when using pwnbox

gray yacht
lapis whale
#

Yes

gray yacht
#

Are you hard set on using Metasploit and proxychains? I get wanting to do it multiple ways, so just curious.

lapis whale
#

No but I've used the others before and want to learn how msf is used for this

#

When it works it also looks like a nice experience so would be nice to get it to work 😄

gray yacht
lapis whale
#

That would be awesome! 😄

median kettle
#

has anyone done the wifi password attacks? im stuck on generating default creds

fading hare
#

Hi all, completed all modules from the Red Teaming AI but I am stuck for many many days at the Model Deployment Tampering section.

I tried everything I could from following the HTB guidelines to MetaSploit CVE-2023-43654 but no luck so far. Added screenprint of MetaSploit where I am stuck ... hope someone has some tips or guidelines.

MetaSploit output:
[] Started reverse TCP handler on 127.0.0.1:9000
[
] Running automatic check ("set AutoCheck false" to disable)
[+] The target appears to be vulnerable. Version 0.8.1 is vulnerable.
[] Using URL: http://127.0.0.1:8080/Cw299gS5f3/
[
] Registering the model archive...
[] Server stopped.
[
] Exploit completed, but no session was created.

fossil sequoia
#

hello i have a tech issues on the AD Enumeration & Attacks - Skills Assessment Part I

#

The target goes down every time

#

within 3min (max) after spawning

#

i tried more than 5 times

sleek tundra
grizzled schooner
waxen totem
#

@noble spire please don't post flags in chat, have you checked whether there are leading or trailing spaces?

rustic sage
#

Um guys is the bash scripting module with enough weight as learning python??

waxen totem
# noble spire yes

Please simply post the following here without spoiling any module content:

  • Module
  • Section
  • Exact question
noble spire
#

Repeating Requests 2- Try using request repeating to be able to quickly test commands. With that, try looking for the other flag.

rain mirage
sterile anchor
#

module: Network Enumeration with Nmap
section: Nmap Scripting Engine
which nmap wildcard would work with scripts?

rustic sage
#

Um guys?

unique field
#

hello, i need a help - on module -Information Gathering - Web Edition > Fingerprinting-i tried everything i can think off, can anyone who able to guide me a little to understand how to get cms ?

noble spire
#

Web Proxies 2- Repeating Requests 3- Try using request repeating to be able to quickly test commands. With that, try looking for the other flag.

rain mirage
#

one is expired and other is alive

gray yacht
digital pendant
#

sorry couldnt help further

lapis whale
#

Basically a network issue with the target environment

#

It started working on the pwnbox and 3 seconds later stopped, then 15 seconds later it worked and so on

unique field
#

yes

digital pendant
#

oh 🙁 restart of the lab I take it fixed then

lapis whale
#

No XD

#

I gave up, read the answers to understand the attack path and then went on to the next SA

digital pendant
#

#1234357888114364508 maybe worth putting it into here then if its a known bug / issue with the environment, even effecting pwnbox

#

ah okay all good

unique field
#

yes, Thank you

digital pendant
#

did you change something? it was 1080 port before. Just curious

lapis whale
#

I messed around with using port 1080 and 9050 as well as socks 4 and 5

#

Nothing changed in between those 2 commands

noble spire
digital pendant
lapis whale
#

Yeah, I thought it would be an issue with my attack host or something

late dawn
#

I want to learn how to hack

#

Who's gonna teach me?@cunning canopy

gray yacht
digital pendant
#

and private messages too.. jeez

#

really committed to their learning

gray yacht
#

Hey you just sent me something?

frosty crescent
#

In Attacking Common Applications - Attacking Tomcat, I'm running the Ghostcat exploit and all I get are 404s, even though the files exists backend from what I can see through the RCE obtained earlier...

#

I tried other PoC code and it gave me the same errors....

gray yacht
#

All good, just wanted to make sure it was intentional.

unique field
#

yes , sent DM

glacial wagon
#

Hi guys

sweet escarp
#

For anyone stuck on AI: Model Deployment Tampering: IT ONLY WORKS ON PARROT, not Kali, due to version of TorchServe Workflows

jade frigate
#

Is normal for me to get disconnected in seconds after using xfreerdp in the "Documenting & Reporting" module?

gray yacht
jade frigate
#

Okay I'll try that

#

I noticed that I get disconnected everytime I open the bash terminal inside the Target Machine

#

If I use xfreerdp and don't open the bash terminal, I don't get disconnected, but as soon as I open the bash terminal it goes off

jade frigate
#

Yes, and I'm using the spawned pwnbox to do it

#

I noticed a lot of problems when trying to use Kali

gray yacht
jade frigate
#

Okay

rotund sorrel
#

I had to fiddle with some packages on my own Kali to get RDP to work right

jade frigate
rotund sorrel
#

As well as doing stuff like cert:ignore

rotund sorrel
gray yacht
#

Hello and welcome. I suggest going to #welcome so you can access more channels, that include general chat, as this is a channel for HTB Academy modules. Also worth reading over the #rules

dark jay
#

Hello, i am doing Broken Authentication module, i am on Brute-Forcing 2FA Codes and the ffuf command does not work? can i send it to this module? can anyone help?

coarse leaf
#

Skills Assessment
Setup
You are tasked with executing a security assessment of a customer's MCP server. The customer is RootLocker, a platform that provides cloud storage of documents as well as a password management service. Your goal is to identify security issues in the server implementation and obtain the flag. Anyone who achive this ?

#

Submit a 5D float vector (comma-separated) to unlock the flag.
Input vector: Expected 5 comma-separated float values.
WTF is this ?

proper dune
#

Say a module is completed, but then updated. Do you still "own it"?

Like what if Intro to C2 Operations with Sliver got updated after I completed it AND my subscription is over. Would I still own it?

fathom pendant
#

Yes

median kettle
#

@proper dune yes

obsidian cove
#

Hello, has anyone here solved the Identifying Unkeyed Parameters lab? I can successfully poison the cache and retrieve my cached payload when I visit the page, but the bot doesn’t seem to trigger it.

frosty crescent
#

Did you end up solving this? Same issue here, I even tried PoC code and it doesn't work either for some reason...

digital pendant
digital pendant
#

I put the user add code after my rev shell code, and the user was still added so I know my rev shell clearly was janky but used multiple examples, pshell nops, you name it.

frosty crescent
#

Ill dm you

digital pendant
#

I feel like its intentional ya know?

#

I can't prove that but feels like persistence was intended with that move into the back-end

silk lagoon
#

Anyone able to help with Injection Attacks Skills Assessment? Please dm

civic inlet
#

Hello guys just having issue setting up proxychains for ADCS attacks module for ESC5

I followed the sections reading for setting up proxy

sshpass -p 'HTB_@cademy_stdnt!' ssh -N -f -D 127.0.0.1:9050 htb-student@10.129.205.205 -oStrictHostKeyChecking=accept-new

Then commented out proxy_dns
sudo sed -i "s/proxy_dns/#proxy_dns/" /etc/proxychains.conf

Then when I try to enumerate it doesnt work
proxychains -q cme smb 172.16.19.3-5 -u cken -p Superman001 --verbose
[19:52:56] INFO Socket info: host=172.16.19.3, connection.py:160
hostname=172.16.19.3, kerberos=False,
ipv6=False, link-local ipv6=False
INFO Socket info: host=172.16.19.4, connection.py:160
hostname=172.16.19.4, kerberos=False,
ipv6=False, link-local ipv6=False
INFO Socket info: host=172.16.19.5, connection.py:160
hostname=172.16.19.5, kerberos=False,
ipv6=False, link-local ipv6=False
[19:53:01] INFO Failed to create connection object for connection.py:219
target 172.16.19.3, exiting...
INFO Failed to create connection object for connection.py:219
target 172.16.19.5, exiting...
INFO Failed to create connection object for connection.py:219
target 172.16.19.4, exiting...
Running nxc against 3 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00

Could anyone help?

Thank you!

royal grotto
#

Gm

civic inlet
uncut girder
#

@civic inlet

plain summit
#

File Upload Attacks Client-Side Validation
After running the targetip:targetport in browser, the upload button doesn't work.

civic inlet
stone storm
storm elk
untold flint
#

Hi all,

Please I cannot connect to the attack machine for NTLM Relay attacks.

bold birch
#

I want to do free CTF on HTB

#

Can anyone help me? i can't found free machine

#

tired fluffy, editor, outbound

#

and soulmate

tight glen
#

start with academy 🙂

bold birch
#

I have already done them 🙂

tight glen
#

all of them? 🙂

bold birch
#

You are saying meow ? and that type of machines?

tight glen
#

there should be a module available where you actually learn how to play your first machines, including the free ones

bold birch
#

okay let me try

bold birch
#

They are blue teaming...

#

HTB is confusing...

#

ngl

tight glen
tight glen
low seal
#

I am still stuck on that AEN module connection problem, initially I was on UDP but it kept dropping even though the HTB website shows "Low Load" for US Academy 4, the HTB support suggested me to switch to TCP, the conenction was stable but for some reason ligolo wasn't working with TCP (specifically unable to RDP to an internal network machine 172.x.x.x), now I am trying back UDP (to test if TCP is the problem) but it is dropping like some 2nd grade ctf platform

river grove
dark jay
#

I messaged you

blissful folio
#

hey im working on SIEM and SOC fundamentals, and I can't find the answer for SIEM Visualization example 4 section's question. Anyone able to help me?

waxen totem
digital pendant
#

nvm it took well over 5 minutes to load ... ignore me

pallid gulch
#

Hi

#

I am new here

still tusk
#

hiii, quick question about Password Attacks modules precisely the Attacking LSASS and attacking SAM...
in the previous module we use └─$ netexec smb 10.129.XX.XX --local-auth -u Bob -p 'HTB_@cademy_stdnt!' --lsa to dump lsa secrets, but in section Attacking LSASS we can't do the same? isn(t lsa and lsass the same?

outer shale
#

Try using request repeating to be able to quickly test commands. With that, try looking for the other flag.

icy egret
#

yes

normal dagger
#

How did you figure out the second question

#

Can someone please help me on dacl attacks II skills assessment question 2 , I can create a gpo but have no way to the user who can link it 😭

normal glacier
#

Have anyone know how to finish the Applications of AI in InfoSec(Model Evaluation (Malware Image Classification)), because I follow the instruction source code, but i don't know why I upload the the model file is invalid

wheat silo
#

I’m working on exploiting web vulnerabilities in thick client applications. I followed all the steps in the reading but I’m still getting connection errors. Wireshark also doesn’t seem to be detecting any DNS traffic. Can anyone help solve this issue?

brave field
native turtle
#

Hi everyone, someone is facing problems with the module Intro to C2 Operation with Sliver ? because all the labs are very slow and most of the commands in the sliver sessions do not works. I tried to switch VPN multiple times

modern beacon
#

Hello

coarse leaf
#

Is there someone who can check why my flag not working ?

#

Attacking AI - Application and System

sleek temple
#

hi, what is vip? im confused, I just paid for student plan and there is another thing I can pay for monthly? Is it useful for studying and completing cpts certification?

forest dagger
#

It's not letting me message on general chat

#

Oh I'll have to verify right?

fathom pendant
grizzled schooner
#

Anyone have a second? I think this module may be bugged?

#

Using Web Proxies | Repeating Requests

coarse leaf
forest dagger
#

I can't remember if I've registered but is labs or academy better? I've moved from THM cos they're using user data for some AI startup.

grizzled schooner
#

I put the answer in last night, got it correct... Logged on today, answer disappeared, ran back through it. Answer is now wrong?

forest dagger
#

Is HTB Labs or academy better

grizzled schooner
#

Depends what you're trying to do

forest dagger
#

More learn at the moment

fathom pendant
grizzled schooner
#

Than most likely academy will be better

fathom pendant
#

Academy: lots of reading and practice
Labs: Lots of research and more blind

forest dagger
#

I'll start with academy and go to labs lol

#

I'm on mobile right now can someone say how much it is for both

grizzled schooner
#

Marcie, can you sanity check this answer for me? It was right last night... answer disappeared this morning, and it's now apparently wrong? lol?

blissful folio
fathom pendant
#

@grizzled schooner

1b83fe2e0985ca20a9ef8b942da9a437  -
ddba986c7a8b1ef6debc4828af09b099  -

1st is echo -n "flag" | md5sum
2nd is echo "flag" | md5sum

harsh gorge
fathom pendant
grizzled schooner
#

wtf? I have words, not md5 hashes

#

or did you pipe to md5 to not spoil answer

fathom pendant
#

i piped to md5 to not spoil answers

grizzled schooner
#

10-4

fathom pendant
#

first is using echo -n to not send the new line, the other is just echo with the newline

grizzled schooner
#

... my answer doesn't relate to either hash lol

wispy sail
#

Hello 👋

fathom pendant
#

HTB{qu...75}

grizzled schooner
#

I mean there's two answers... the first flag is obvious... I found the second directory by searching... I can give you the path for this flag if that would help? I don't want to spoil though

#

I have 1n73r....

fathom pendant
grizzled schooner
#

Wat lol

fathom pendant
#

1 = i, 7 = T...

#

a fair bit of the flags are l33tsp34k (leetspeak)

wispy sail
#

Please accept my Hi 😀

grizzled schooner
#

so I think that this module is a little busted then... the answer for this module is where the answer for intercepting req should be, and the repeating reqs was where intercepting should be lol

#

nevermind, this answer isn't right either lol... I've checked both flags, somethings not adding up

coarse leaf
fathom pendant
fathom pendant
coarse leaf
fathom pendant
coarse leaf
fathom pendant
#

just ask your question here (without spoiling information) and someone that's done it may be able to help you

coarse leaf
#

Can somebody check my flag? Attacking AI - Application and System /Skills Assessment It is not working

sweet escarp
coarse leaf
#

Yep

coarse leaf
sweet escarp
# coarse leaf Yep

I don't think your flag is correct either... It's way easier to get the flag...

sacred rock
sweet escarp
coarse leaf
sacred rock
coarse leaf
sacred rock
glad finch
#

I've been doing the 'Web Attacks' module and it seems like almost not working. I must wait 5 min to load the page, 10 min to get Burpsuite make a Forward and so on. It just happens with this module. I had no problems with the rest. Am I the only one?

wheat silo
#

I'm working on the Exploiting Web Vulnerabilities in Thick-Client Applications section in Attacking Common Applications, I've edited all the files that I need to change like it does in the reading but when I run the updated JAR app and try to log in I'm still getting a connection error. When modifying the hosts file I used the same command that was used in the reading echo 10.10.10.174 server.fatty.htb >> C:\Windows\System32\drivers\etc\hosts . Is the IP supposed to be same as the command in the example? I'm not getting any other way to get this one working

fallow heron
#

Can someone help me in Linux fundamentals module

coarse leaf
faint rampart
#

Hey, anyone manage to perform this WSUS Update attack using an account that belongs to the WSUS admin group but not local admin in the Windows Lateral Movement module?
It fails for me with this error when I try to approve the malicious update, a little research and I discovered WSUS approval via SharpWSUS relies on directly querying the SUSDB SQL database.
and it appears this account doesn’t have SQL EXECUTE permissions on certain stored procedures (like fnGetComputerTargetID) in the WSUS database. Just curious if anybody was able to perform this successfully

fallow heron
faint rampart
fallow heron
#

There are many

faint rampart
# fallow heron There are many

I get you lool, try reading it over again section by section and then if you still have a problem start by asking for help with questions one after the other after putting considerable effort yourself.

fallow heron
#

How I can figure out which command should I apply in for the question: "How many total packages are installed on the target system?"

uneven gale
#

why I'm not able to share photo here

#

i have to ask with photo

fallow heron
#

@coarse leaf @faint rampart tell me

faint rampart
#

you could pipe the output to another command such as awk to retrieve the number of installed packages
I havent really done this module so I cant tell the way for sure

acoustic owl
glass thorn
#

Idk if this is a good place to ask about general question

#

Ok nvm figure it out

fallow heron
crystal cove
#

hi chat, I'm confused in the Code Analysis > Reverse Engineering & Code Analysis > Recognizing the Main Function in IDA, the author says "*Based on the overall structure of this function, we can conjecture that this is the possible main function. *" but I don't understand what are the criteria ? is it because its has 3 call instructions ? it it because it checks for the registry key ? is it because it imports an external function from a DLL ? all of that ? what makes this specfic function/block likely to be a main() rather than any other ? I would have expected a main() to be something massive with a lot of functions and instructions

hollow holly
#

Hey everybody. I'm doing the path to CPTS right now and i was wondering, when I should try my first machine from the labs. also what machine is suggested first for someone who is a total beginner

faint rampart
obsidian cove
#

I am working on the Identifying Unkeyed Parameters lab and am very stuck. Could someone DM me? I found two Unkeyed inputs that can poison the cache with XSS, but I can’t seem to get the flag.

static shadow
#

Hey , Im doing the linux privesc module , NFS export question from misc techniques

whenever i use this command my terminal gets stuck , tried resetting machine twice. Any advice ?

sudo mount -t nfs 10.129.182.211:/tmp /mnt

calm forge
#

Hey guys i am preparing for the CPTS current doing the prerequisite for penetration tester pathway infoSec foundation doing Linux module ahh can anyone say how you approached the remote desktop protocol in linux

quasi wave
#

for the second question of Kerberoasting from Windows section of AD Enumeration and Attacks module, I am trying to crack the hash and I get "separator unmached." I tried both hash modes in the section.

#

and tried using two different versions of the hash file

#

can someone help me out?

cloud urchin
#

Sounds like the hash isn't valid, I've seen that error when there's a mistake in the format.

quasi wave
#

I am using the right hash like I'm 99% sure

cloud urchin
quasi wave
#

because I copied the exact hash that's why

compact atlas
#

oops

#

don’t email me

quasi wave
#

@compact atlas can I DM you?

#

wait cracked it

digital pendant
#

or if you have valid creds for RDP its likely SSH is available (if its not then oh well, least you're aware of how), so you could use that too

calm forge
#

Thank you dude

tranquil robin
#

I tried many times to connect to the inlanefreight.com and get download.php but it keeps on saying failed. This was done with the parrot os vm provided. Then i used my own Kali Linux vm to try it and it worked but this is what the file said: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL was not found on this server.</p> <hr> <address>Apache/2.4.41 (Ubuntu) Server at inlanefreight.com Port 443</address> </body></html>. I am very confused and even tried asking ChatGPT so any help would be much appreciated.

#

was redirected here and told it would be helpful to give module and section name

#

not sure how to see those tho

fathom pendant
tranquil robin
tranquil robin
fathom pendant
tranquil robin
#

omd im stupid

torn dome
#

Guys does anyone playing in the season 9

fathom pendant
fathom pendant
tranquil robin
#

thank you very much

unique spruce
mint rover
#

Hi

solemn shale
#

@graceful jay

يسطا 😢

fathom pendant
steel path
#

Struggling with Windows Lateral movement Skills Assessment question 2. Explored the hints even and I'm sure I have the proper users access on the machine, looking for the flag where the question refers and I'm not finding it, anyone who's done it able to guide a little bit?

solemn shale
fathom pendant
solemn shale
#

im talking english

#

yeah meat neck

#

yeah bin ill whisker

fathom pendant
#

can you actually make sense?

spiral sapphire
#

If anyone could give me a little nudge on Module's 'DACL Attacks II' Skills Assessment, I'd highly appreciate. Been stuck for a while. Thanks in advance!

brittle olive
civic inlet
#

has anybody done the Advanced Deserialisation attacks module? need some help

crimson moon
#

In attacking drupal got the RCE and exploring the folder don’t seem to find the flag.is it only visible after doing drupalgeddon?

rain mirage
#

password attack , ptt for linux

Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_).

the only step remaining is running the Linikatz.sh , but to do that i gotta access the linux machine and rn im in windows inlanefreight\julio , how do i get into the linux ,?

#

or do i run it in svc_workstations ?

graceful bolt
#

Hi Everyone,

If I subscribe to the monthly student plan on HTB Academy, will it include access to the Android Application Pentesting path?

acoustic owl
#

The student subscription includes all modules up to Tier II. The modules from Android Application Pentesting are all Tier III ( except Android Fundamentals) and are therefore not included.

visual pewter
digital willow
#

Hi. I’m stuck on the “Attacking common applications” module, in the attacking gitlab section. Anyone could give a nudge, please? 🙂

gray yacht
gray yacht
steel path
slate gale
#

Hi ! I'm doing Attacking Thick Client Applications lab. But when I connect with RDP, there is no user Matt. Moreover, the file C:/programdata/restart-service.exe is not present. So I can't retrieve the flag. Already try to reset lab (CPTS path) nvm i just failed copy paste lol

mighty harness
#

nvm i got it

native turtle
#

Does anyone have connectivity and latency problems with module Intro to C2 Operations with Sliver ?

#

I tried to change vpn region and reset target multiple times but its tremendously slow and laggy

floral fulcrum
#

Hi currently at Intro to WhiteBox pentesting at Blind Exploitation, was wondering if anyone managed to get boolean-based exfiltration to work via status codes?
This was the closest i got but i'm still struggling to set the status code to what i want
|| ```
malicious = f"'+(require('fs').readFileSync('./flag.txt','utf8')[0]==='{char_guess}'?(function(){{throw({{statusCode:403,message:'match'}})()}}):(function(){{throw({{statusCode:500,message:'nomatch'}})()}}))}})//"

spring helm
#

Hello, i'm currently on Public exploit part, and there is task related to Wordpress simple backup plugin, i've got output from this file but not sure what to do with it
root❌0:0:root:/root:/bin/bash
daemon❌1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin❌2:2:bin:/bin:/usr/sbin/nologin
sys❌3:3:sys:/dev:/usr/sbin/nologin
sync❌4:65534:sync:/bin:/bin/sync
games❌5:60:games:/usr/games:/usr/sbin/nologin
man❌6:12👨/var/cache/man:/usr/sbin/nologin
lp❌7:7:lp:/var/spool/lpd:/usr/sbin/nologin

eager matrix
#

?

spring helm
#

i'm looking for some advice

silk sage
#

Hello,

Doing the wayback machine / Web archives / Information gathering - Web edition, trying to answer questions about hackthebox.eu itself.
In all cases the stats section in waybacked website is zeroed (all stats are zeroes), independly really of the date chosen.

Yes, suffix is as in screenshot and tried alternative machines.

EDIT: It's not about this section in the website. Look in the text 🙂

spring helm
#

Pentesting basics

#

this was previous one i think , this one is related to wordpress simple backup plugin, i used msf to get output from /etc/psswd

#

and than i'm stuck

#

i think it is Getting Started > Public Exploits

#

Questions
Answer the question(s) below to complete this Section and earn cubes!

Target(s): 94.237.57.211:54628

Life Left: 24 minute(s)

  • 1 Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)
#

wow, that was simple... thanks a lot 😅

#

i though it is only accepting folders

#

oh yeah, you are right

rustic sage
#

What are hard links?
I even googled it and still I don't understand..

spiral sapphire
#

Hey guys! I'm really, really stuck on DACL Attacks II Skill's Assessment. If someone could give a little nudge I'd highly appreciate! Thanks in advance!

lilac socket
#

Sup everyone! Need help.
Components of a Network: (Question)
What type of network cable is used to transmit data over long distances with minimal signal loss?
(I tried fiber optic cable), it's dosn't count

rugged hull
#

Hi, I have a question. I was stuck with question about the Port in the Splunk Module. I think my query is correct however both the ports (80 and 443) are not correct answers.

lime cosmos
#

How can I use responder to capture hashes while pivoting?

steady forge
#

Hey all I am trying to complete this lab located with this link (https://academy.hackthebox.com/module/289/section/3246). I'm doing netcat to get FTP connection when doing the lab and before I get to the next step I get a connection error. I am not sure how to resolve this, but I was currently using the Parrot OS that HTB provides. I also tried it out on my own linux environment using the openvpn and I still get that issue. I am not sure how I'm supposed to troubleshoot when there's no directions on what to do.

slow lichen
#

Does the junior cybersecurity analyst path still work? I wanted to try it today but for some reason it wouldn't open

alpine mural
#

Hi. In module "OSINT Corporate Recon" in Technologies in Use, question: Which version of WordPress is used on the Inlanefreight domain page? I dont see the problem...any hint in this?

cloud urchin
silk nimbus
#

Some1 reply

cloud urchin
#

yep

compact patrolBOT
storm elk
#

Have a look around the platform

#

If you wanna do bug bounty, you’ll have to go through content and do some educated guesses 🙂

storm elk
nocturne pilot
#

Hello. Very new here. Not a complete noob, but running through the Academy stuff so I know that I know what I'm expected to know. I'm in Getting Started - Basic Tools (/module/77/section/847). I was having issues netcating my target (because I'm an idiot and left the generated port number on the address) so I revealed the answer and submitted it because I know how to use netcat. Right after that I realized my mistake and issued the command successfully in my terminal and got back a different SSH banner than what the module told me the answer was. Is it normal for this kind of question to have multiple right answers?

crude grove
#

i'm stuck in this question active directory , privileged access ,first question
any hint please?

cloud urchin
silk nimbus
crimson moon
#

In attacking drupal got the RCE and exploring the folder don’t seem to find the flag.is it only visible after doing drupalgeddon?

cloud urchin
worn sapphire
#

Can we upgrade from Silver to Gold monthly plan while in middle of finishing the pen test job path? We started with Silver then once we get through module 2 we wanted to upgrade to Gold.

civic inlet
cedar void
#

For those who have the silver or gold membership what is your daily route like for competing the modules

civic inlet
#

Anybody doing the Advanced Deserialisation Attacks?

I need help with the binary example

Thanks!

cedar void
civic inlet
#

I would also try to balance it out with machines aswell

silk hazel
#

I am working through the Pentest in a Nutshell module and I have a question about sudo. Does NOPASSWD actually require a password to elevate? Is this just because I authenticated via SSH and the private key? I was caught off guard by being prompted for the password here, what might I not be understanding?

john@ubuntu:~$ sudo -l
Matching Defaults entries for john on ubuntu:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty

User john may run the following commands on ubuntu:
    (root) NOPASSWD: /usr/bin/nano
    (ALL : ALL) ALL
john@ubuntu:~$ sudo /usr/bin/nano
[sudo] password for john: 
silk hazel
#

Is it because (ALL : ALL) ALL applies later in sudoers for that user (due to group membership)?

When multiple entries match for a user, they are applied in order. Where there are multiple matches, the last match is used (which is not necessarily the most specific match).

civic inlet
silk hazel
# civic inlet in this case you can refer to GTFObins and look at exploits for nano

Yeah, thats all good. I'm hanging out as root already. What I'm asking though is it feels like this excercise was set up in a way via the focus on sudo -l at a certain stage that I expected to be able to use the ^R^X tricks from GTFOBins to get a root shell without a password. Like ... why bother adding john ALL=(root) NOPASSWD: /usr/bin/nano to sudoers at all if the rule for %sudo ALL=(ALL:ALL) ALL seems to apply. For example, I am also able to do exactly the same (root shell) with vim.

silk hazel
hoary coral
#

Anyone knows how to unzip a hidden file on kali linux

#

Have been trying to solve a problem for hours

#

But not getting there

cloud urchin
#

Always best to say which module and section you're on

#

unzip or gunzip usually works

silk hazel
idle atlas
#

Does anyone know why when I want to use nc on a port it stays listening and never receives the reverse shell? For example, it listens to the LDAP correctly, but when I use nc it always stays listening.

silk hazel
cloud urchin
full echo
#

Pay close attention to the header required when constructing http request.

idle atlas
cloud urchin
#

Too broad of a question. You'll have to check everything in the chain. Make sure you can reach the target, it can reach you, make sure all the command syntax is correct.

idle atlas
#

ookai tysm!

rustic sage
cloud urchin
clever quartz
#

Hi - I' currrent working on DC Sync section in Active Directory Enumeration and Attacks module. Need help since i'm stuck

I'm getting the following error after trying DC sync attack using impacket-secretsdump. I realise that this is due to adunn not having write permission on ADMIN$ share.

Would appreciate help or suggestion from users who have completed this module.

What i have done till now:

  1. Verified that user adunn has DS-Replication-Get-Changes-All and DS-Replication-Get-Changes rights via PowerView.ps1
  2. Verified that i am using correct password via crackmapexec
  3. Reset the lab several times.

Error:
┌─[htb-student@ea-attack01]─[/opt/impacket/examples]
└──╼ $./secretsdump.py -just-dc INLANEFREIGHT/adunn@172.16.5.5
Impacket v0.9.24.dev1+20211013.152215.3fe2d73a - Copyright 2021 SecureAuth Corporation

Password:
[] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[
] Using the DRSUAPI method to get NTDS.DIT secrets
[-] Cannot create "sessionresume_NZacLtlf" resume session file: [Errno 13] Permission denied: 'sessionresume_NZacLtlf'
[*] Something wen't wrong with the DRSUAPI approach. Try again with -use-vss parameter

hybrid pilot
#

I'm currently doing AD Enumeration & Attacks - Skills Assessment Part I. I'm close to the end (2nd last question) ,

I thought about running Sharphound.exe on MS01 and ingest it in bloodhound. This brings me to 2 questions:

  1. On my kali box there's bloodhound CE 8.1.0 and I'm completely stumped on how to use it to answer the question
  2. On pwnbox there's an older version but once started with bloodhound and trying to upload the data i'ts just stuck at 0%
#

Is there any other way to answer the Q: What attack can this user perform? ?

heavy mango
clever quartz
hybrid pilot
hybrid pilot
waxen totem
heavy mango
brave field
hybrid pilot
hybrid pilot
#

Update: using the latest sharphound.exe worked for me, so the hint with the version incompatabilities was spot on!

waxen totem
hybrid pilot
crimson moon
#

hey guys how do you get rid of middleman clipboard in pwnbox?

terse lotus
#

Gday folks, new here and enjoying myself so far but for the life of me I can't get passed this last question. Any help would be very appreciated! pepepray

sand valve
#

New to HTB Academy , and i have been enjoying it for a while i really wanna make Ethical Hacking my life 😊. Any tips ??

terse lotus
uneven ferry
#

Has anyone here completed the Android Fundamentals course on Hackthebox?

edgy schooner
#

Would you mind passing on any tips here? I am in the same position.... have been for a day or so.

tame basalt
waxen totem
tame basalt
sand valve
waxen totem
sand valve
tame basalt
#

You'll go in the rabbit hole, be ready 🤣 Soooo much in my personal live had to change

sand valve
waxen totem
#

and support on the site for any site problems

tame basalt
sand valve
waxen totem
#

learn to balance

sand valve
sand valve
tame basalt
mental bane
#

Hi guys im new here what should i start from the basic?

sand valve
tame basalt
compact patrolBOT
sand valve
tame basalt
mental bane
eager spindle
#

Can anyone help me with sqlmap skills assessment. I can't find any potential attack vectors。Only find one POST request

eager spindle
waxen totem
eager spindle
waxen totem
#

you don't really need to add them

#

also that looks like the wrong post endpoint, that's for a maps API

#

keep looking

eager spindle
#

I only find this POST request

waxen totem
eager spindle
#

ok,thank you

waxen totem
tame basalt
#

I started as a Senior Developer, and I still learned a lot.

mental bane
#

sheeesh

tame basalt
#

Plus it's cheap 😄

tame basalt
little magnet
#

Hello, is there someone who finished module Using CrackMapExec, i have a question about skills assessment because i connected through chisel changed port to 1080 and still cannot scan for any host using CME (e.g. proxychains cme smb <IP range>). Is there someone that can help?

civic inlet
little magnet
#

I know ligolo but chisel is the only way in this skills assessment, it is required as 'connecting to the internal network' on the first step of the skills assessment

gray yacht
harsh gorge
#

Thanks Rick

odd surge
#
2025-09-22 19:02:24 TLS Error: local/remote TLS keys are out of sync: [AF_INET]154.57.164.103:1337 (received key id: 0, known key ids:  [key#0 state=S_GENERATED_KEYS auth=KS_AUTH_TRUE id=2 sid=31b19e60 ed532014] [key#1 state=S_GENERATED_KEYS auth=KS_AUTH_TRUE id=1 sid=31b19e60 ed532014] [key#2 state=S_UNDEF auth=KS_AUTH_FALSE id=0 sid=00000000 00000000])```
#

does this mean ur vpn is doomed

unique field
#

hello, i see module -Attacking Web Applications with Ffuf is to be phased out with Web Fuzzing , so here should i work in this (never worked with fuff before) or wait for new module , kindly suggest.

#

okay , thank you and DM'd you

normal glacier
#

Have anyone finish Application of AI in InfoSec, if yes please dm me

little magnet
gray yacht
tight kraken
# little magnet Hello, is there someone who finished module Using CrackMapExec, i have a questio...

Unfortunately I couldn't find a way to use ligolo on this one. This is one of the few exercises where I believe there's no avoiding proxychains, because you're expected to connect to the agent that's already running on the pivot machine. Two things that tripped me up were the socks version and the proxychains command defaulting to a different config file than I was expecting. What worked for me was using socks5 (comment out socks4 config line if present) and explicitly specifying my intended config file every time I used the proxychains4 command.

silk lagoon
#

Anyone able to help with Injection Attacks Skills Assessment? Please dm

rare condor
#

this not be chdir ?

waxen totem
still edge
#

i would have thought pwd

waxen totem
amber rose
#

intro to networking is this not correct ?

potent pier
#

Nope. The format tells you xxx-xxx xxx

amber rose
#

two words one of which

#

still it meant two words right ?

fathom pendant
amber rose
#

mb

fathom pendant
#

English is a terrible language ik

amber rose
#

yep

livid kayak
#

Hi all, is anyone else having trouble spawning targets?

#

Im on the Windows Privilege Escalation - Windows Server section, and the box refuses to spawn.

coarse leaf
#

Hi All, anyone who know why instanses not working ?

jovial vine
#

Same, cannot start any instance

median kettle
#

can someone help me with the cracking wifi password assessments? i feel like im on the right track just missing a hint or clue

radiant stirrup
hallow iris
#

Is there a way to DM a mod? I have funds in my account, but it won't let me purchase cubes.

compact patrolBOT
hallow iris
#

Anyone who has access to Academy.

I opened a ticket though, thanks!

waxen totem
muted path
#

Hi, i need help in Linux Fundamental/Containerization/LXC - Problem with DNS Server. Ping for IP as Numbers is ok, when i put name of Website - doesn't work, i try all what i can find... i cannot update and install in LXC "Ubuntu" any Programms... :((

vestal ore
#

I stuck in section htb academy, can anyone help me?

https://academy.hackthebox.com/module/109/section/1039
i use this payload seem true but it's didn't work.

ip=127.0.0.1%0abash<<<$(base64${IFS}-d<<<ZmluZCAvdXNyL3NoYXJlLyB8IGdyZXAgcm9vdCB8IGdyZXAgbXlzcWwgfCB0YWlsIC1uIDEK)

think have a issue with bash but i can't fix

agile cedar
#

I connected to the academy-regular.ovpn but don't able to ping the ip, ┌──(root㉿astra)-[/home/astra/Downloads]
└─# ping 10.129.130.185
PING 10.129.130.185 (10.129.130.185) 56(84) bytes of data.
From 10.10.16.1 icmp_seq=1 Destination Host Unreachable
From 10.10.16.1 icmp_seq=2 Destination Host Unreachable
From 10.10.16.1 icmp_seq=3 Destination Host Unreachable
From 10.10.16.1 icmp_seq=4 Destination Host Unreachable
^C
--- 10.129.130.185 ping statistics ---
5 packets transmitted, 0 received, +4 errors, 100% packet loss, time 4068ms
pipe 4

┌──(root㉿astra)-[/home/astra/Downloads]
└─# traceroute -i tun0 10.129.130.185
traceroute to 10.129.130.185 (10.129.130.185), 30 hops max, 60 byte packets
1 10.10.16.1 (10.10.16.1) 195.102 ms 393.965 ms 393.975 ms
2 10.10.16.1 (10.10.16.1) 3256.053 ms !H 3480.760 ms !H 3480.771 ms !H

┌──(root㉿astra)-[/home/astra/Downloads]
└─#
, after seeing the traceroute output, it look like gateway don't able to find that ip, can anyone please tell me how to fix this issue???

rotund sorrel
#

some hosts dont respond to ping tbf

#

Not sure if thats whaty oure experiencing here

little magnet
#

Hello once again is there someone who finished the Using CME module and could give me a small hint about last step of the skills assessment i will apreciate someone I can dm. 🙂

fathom pendant
#

set IP=value

#

basic linux :)

#

in general it's best to use caps

#

unless you're writing a script ofc

mighty forum
#

Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download. --------> need help with this question. Module -> Hacking Wordpress Skills assesment 5th question

quiet halo
fathom pendant
fathom pendant
quiet halo
#

based on this I shouldn't be able to download files in the dummy share, right?

#
  comment = Priv
  path = /var/dummy
  read only = no
  browsable = yes
  public = yes
  available = yes
  writable = no
  guest ok = yes
fathom pendant
#

also your screenshot contained an answer to one of the questions

jolly oasis
#

Looking for a little help on File Upload Attacks > Upload Exploitation > Reverse Shell
https://academy.hackthebox.com/module/136/section/1261

I've seen a few people having problems with it but didn't see a solid answer. I'm assuming I'm entering an IP in the reverse shell script wrong. I've tried the tun0 ip as well as the ens3 ip. I've also tried changing up port numbers. Each time I get the error, "WARNING: Failed to daemonise. This is quite common and not fatal. Connection timed out (110)"

fathom pendant
jolly oasis
fathom pendant
#

public_ip:port -> no revshell

#

web shell != revshell

jolly oasis
#

Right, it's from the victim to the attacker. The IP we're putting in the reverse shell script should be the IP for our attack box?

#

And whatever port we choose for our listener

fathom pendant
#

you are NOT going to get a reverse shell on this lab

jolly oasis
#

I'm so confused 🤣 the section is literally titled 'Reverse Shell"

fathom pendant
#

the section name is "upload exploitation"

#

that's just something you MIGHT be able to do with upload exploitation

#

but the QUESTION itself, is asking you to upload a WEB shell

#

not a REVERSE shell

#

you won't be able to get a REVERSE shell on targets that have an IP:PORT

jolly oasis
fathom pendant
#

yes

jolly oasis
#

Alrighty. I appreciate your help as always!

molten swallow
#

Laudanum sub-module in Shells&Payloads. I have 2 correct answers but it's not finishing and don't show me part as complete one or even the button to finish. Does anyone had exact same problem?

thin fractal
#

guys the Pivoting, Tunneling, and Port Forwarding skills assessment, the target always freezing, please help

molten swallow
livid kayak
#

Hi, is there a way to revert completion of a section?

soft needle
cloud urchin
molten swallow
# cloud urchin Try pressing CTRL+SHIFT+R

even after rebooting the system , browser , attempt from different browser and android phone - it still shows available hints on completed answers and no Finish button

cloud urchin
#

You have to press Submit before finish shows up

molten swallow
cloud urchin
#

Do you have an adblock/pihole?

molten swallow
#

from this moment ive finished another sub-module , but this one particular is dead

molten swallow
cloud urchin
#

That's probably why, disable any ad blocking and pihole

molten swallow
#

weird stuff

cloud urchin
#

no idea. 403 is a forbidden error, maybe try logging out and logging back in

#

if that doesn't work i'd reach out to support on the site

molten swallow
#

Thx btw

pastel flare
#

Module Name: Password Attacks

Section Name: Pass the Certificate https://academy.hackthebox.com/module/147/section/1335

Question: What are the contents of flag.txt on jpinkman's desktop?

I am currently trying to use ntlmrelayx to listen for inbound connections and relay them to the web enrollment service. I am attempting to use the printerbug.py to force the dc01 to authenticate against my machine to be relayed to the certificate authority.

Attacker IP: 10.10.15.24

ACADEMY-PWATTCK-PTCDC01 (DC01): 10.129.126.87

ACADEMY-PWATTCK-PTCCA01 (CA01): 10.129.51.159

*I am using the pwnbox

The commands I am running are:

ntlmrelayx listener:

||sudo impacket-ntlmrelayx -t http://10.129.51.159/certsrv/certfnsh.asp --adcs -smb2support --template KerberosAuthentication --http-port 8080||

  • I changed the HTTP port to 8080 because the attackbox uses port 80 by default
  • I also tried installing impacket v0.12.0 as shown in the examples, but it did not change my output

printerbug.py exploit:

||sudo python3 printerbug.py INLANEFREIGHT.LOCAL/wwhite:"package5shores_topher1"@10.129.126.87 10.10.15.24 --verbose||

Screenshots:

  • Sometimes I will get a received connection output, but nothing happens, also I'm not sure what the ip (36.85.233.237) is

Any advice on how to move forward would be helpful, I have been stuck here for a while, and I am not sure what is stopping this from working

GitHub

Kerberos relaying and unconstrained delegation abuse toolkit - dirkjanm/krbrelayx

potent pier
#

So how do you go on about copy + pasting something like this

curl -s -O https://raw.githubusercontent.com/danielmiessler/SecLists/56a39ab9a70a89b56d66dad8bdffb887fba1260e/Passwords/2023-200_most_used_passwords.txt

from module instructions into the pawnbox 😄
3am hash manual copying is not fun.

cloud urchin
#

it probably already has it locally

#

there's a clipboard icon in the lower right you can click on to open a box where you can input/copy to the pwnbox's clipboard

dusk holly
#

Is there anyone who has done the Kerberos attacks module who can help me in DM?

plain summit
#

nvm

#

Silly me

red shuttle
#

Password Attacks - Network Services
is rdp broken there?

#

can you dm me pls

vernal bramble
#

Hi, I'm new here. I'm confused about the cubes and annual subscriptions. If I unlock a module with cubes , do I get permanent access including the labs? For the annual subscription, if I fully complete a module, do I also keep lifetime access to the labs after the subscription ends?

autumn pilot
#

yes

uneven lava
#

Can I ask for a little help on llm output attacck skill assessment?

devout lily
#

Footprinting module - DNS section
Hi everyone, im trying to answer to the second question using this command, but it denies my request

final slate
#

Hey I'm new here I want help

#

Can anyone help me in recovering my disabled Instagram account

autumn pilot
#

we can't help you, reach out to instagram

quaint glade
#

Since days I try to install mongodb: Install MongoDB Community Edition on Debian
BUT, when I do: sudo apt-get update, I get: Repository 'http://deb.debian.org/debian testing InRelease' changed its 'code name' value from 'trixie' to 'forky' => therefore I changed at /etc/apt the file: sorces.list BUT it don't work ; HACKTHEBOX did some changes at /var/lib/apt/lists BUT execution ist NOT possible Have somebody an idea how to fix that ???🤓

normal glacier
#

Have someone finished the module called Application of AI in Infosec?

strong acorn
#

Windows Attacks & Defense | Kerberoasting

passwords.txt file for cracking krb hashes doesn't exist

waxen totem
strong acorn
#

This ss states that the "passwords.txt" file exists in the home directory.

While in the instance there is no files like that. (I tried searching files with "find" command and it seems that there is nothing with the same name as "passwords.txt")

strong acorn
#

The same issue with the "Steps-to-reproduce" I've talked about before and in one of my linkedin posts (incomplete steps).

waxen totem
strong acorn
waxen totem
strong acorn
fathom pendant
#

also passwords.txt is just a placeholder in the cheatsheet

#

it's meant to be a generalized syntax

fathom pendant
strong acorn
#

Windows Attacks & Defense | Kerberoasting

fathom pendant
#

ah haven't done that one

strong acorn
#

this is frustrating, almost spent 1 hour to solve these issues. Which all lies under "incomplete Steps-to-reproduce"

#

@waxen totem I don't think it's wrong to make it clear where the files used in this module are existing, right?!

fathom pendant
#

looks like rockyou.txt is the intended wordlist

strong acorn
#

lol bro

fathom pendant
#

recapture the spns then

dusk holly
#

Is there anyone who has done the Kerberos attacks module?

fathom pendant
dusk holly
#

In the Kerberos Attacks module, Unconstrained Delegation - Computers, for the first question, I cannot find the flag, which is supposed to be at \\DC01\Shares\Marketing\flag.txt I think I got the TGS for the right user, but I cannot find the flag afterward. I tried different formats, but still no.

dusk holly
waxen totem
#

@strong acorn try this version of rockyou:

/usr/share/seclists/Passwords/Leaked-Databases/rockyou.txt
strong acorn
#

decompressed + tried with hashcat. Nothing to consider a successful attack

#

2 hours of error resolving

waxen totem
strong acorn
#

OMW to do that

vale geyser
#

anyone for "Attacking FTP" in the "Attacking Common Services" module?

fair kelp
#

Hi all please could someone point me in the right direction as I think I am getting confused. I'm working on the CORS Misconfigurations exercise. At the bottom of the page it says the vHosts needed for these questions are exploitserver.htb and cors-misconfigs.htb. Does this mean that I upload the payload to exploitserver.htb and then send it to cors-misconfigs.htb and receive some data back on the listener on my kali port 4443? This has not worked for me so far. Any help is greatly appreciated 🙂

brave field
devout lily
#

im really cooked

#

literally cooked

#

thx

devout lily
brave field
devout lily
radiant stirrup
#

xfreerdp /u:htb-student /p:'HTB_@cademy_stdnt!' /v:10.129.127.44 +clipboard /dynamic-resolution [15:12:29:943] [46325:46326] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]

What is going wrong?? Reset my target, reset my vpn connection, ...

devout lily
#

found!!

red shuttle
#

Password Attacks - Network Services
is rdp broken there?
anyone can help on that
tried cme and hydra

shut jewel
#

Hi everyone, is it possible to reset the progress on a module?

brave field
fair kelp
#

Please could someone help me with Advanced XSS and CSRF Exploitation: CORS Misconfigurations exercise?

abstract ingot
#

Hi, i need help with this module: Active Directory Enumeration & Attacks DCSync. anybody?

radiant stirrup
violet flicker
#

If you still need help, DM me

cosmic patrol
floral fulcrum
#

could i get a nudge for Modern Web Exploitation techniques - SSRF Basic Filter Bypasses
?, exploit is working locally but not remotely

grizzled schooner
#

Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

What is this question actually asking me to submit for the answer? Please, reply with @

rustic sage
#

Hello!
So for anyone who got the student subscription do you get access to "Enable step by step solutions to all questions"? And if you do what does it exactly do? Just to make sure if I should purchase it now or later..
Thanks!

waxen totem
#

as mentioned in #general it's only applicable to those with anual subs

rustic sage
#

Aw..

wary plover
#

Bro still wouldn't want to ask support

rustic sage
#

What is your problem?

wary plover
#

Adblock turned off?

rustic sage
#

Yes

wary plover
#

Weird

grizzled schooner
rustic sage
#

Jeez..

#

What the hell is this sarcasm dude..

#

Anyway.. have a good one! Thanks for the answers!

rancid eagle
#

Hello , im new at HTB . I'm a blue team member , have some experience on IRDF practically . is there a special path in HTB for me to use labs in correct order? also what should i do to be able to write on off topic channels?

rustic sage
waxen totem
rustic sage
rancid eagle
#

can anyone help me with the cubes? i do not get it , i know it is 8 bucks a moth but what is with cubes . isn't it like THm where i can use every room when im premium user?

waxen totem
rustic sage
rustic sage
waxen totem
rancid eagle
#

the cubes are so expensive isnt there any voucher or student discount i can use

waxen totem
rancid eagle
#

i found 8 bucks a months but idk how can i prove im a student

waxen totem
rancid eagle
#

i have such an email but i created my account with my own email

gray yacht
rancid eagle
delicate adder
#

Hi, I'm doing the hackthebox module in the services discovery section and when I start the tcpdump connection with nc I don't receive any banners. Do you have any advice?

crisp solstice
#

I am stuck at the skills assessment for password attacks. This is the revised one. I got the 'jbetty' username and I can ssh. Even my proxy works. I identified the hwilliam user. I managed to get access to SYSVOL. I got the username Administrator1 from one of the Registry.pol. BUt I don't know what else to do. Bruteforce takes to long. So does nmaping the whole machine. What to do next?

robust pecan
# abstract ingot ?

Just ask your question. What exactly do you need help with? What step? Tell us what you tried and what you are trying to achieve. A screenshot would also help.

trail needle
#

can I use a macbook pro for HBT?

storm elk
crisp solstice
gray yacht
#

I actually had to create a new machine account to get it to work, so I'd give that a shot. Since that post contains spoiler info, I am going to delete it.

crisp solstice
#

Can you elaborate on that? How did you createa a new machine account? Also, sometime the home directory is empty sometimes pwnkit is there. Has anyone else had this problem? Also, pwnkit doesn't actually give an elevated session.

#

Sorry I can't post my pics. I saved it all in obsidian and I can't seem to copy paste from it.

gaunt elbow
#

hello can i get some help on the saml wrapping attacks ? ||how am supossed to edit the xml and inject the payload ||

gray yacht
native turtle
gray yacht
gray yacht