#modules

1 messages · Page 453 of 1

native turtle
#

yeah but it takes 30 min only for spawing the first RDP session and is very laggy

gray yacht
native turtle
#

I tried many times to switch vpn server

#

tcp udp yeah

gray yacht
#

Are you using EU or US VPN?

native turtle
#

EU

gray yacht
#

I know it prolly sounds dumb and very well could be, but have you tried US just to check that box?

gray yacht
native turtle
#

sincerly not because I though it will be worse since im in europe but I will give it a shot and let you know... I tried tcp udp in all UE servers

native turtle
#

but the entry point is always the same IP

gray yacht
native turtle
#

thank you

#

I'll try

#

worse :/

gray yacht
# native turtle worse :/

That sucks, sorry. You could always open a ticket and explain what you are experiencing on your end.

arctic night
#

Hello, I'm currently doing the "Hunting for Stuxbot" section in the "Introduction to Threat Hunting & Hunting With Elastic". I'm a bit confused but a Kibana query. The query used there seems contradictory to me. Can anyone explain that to me please?
dns.question.name:* is included then excluded from the same query

dim sable
#

I read this ROQ example multiple times and I still can't use this on my own, does anyone know a resource that teaches ROQ separately or the only content about it is this?

#

I finished the module but I think learning ROQ early-on would be really good

livid kayak
#

Hi all. I just entered the correct answer for a section Skills Assessment and did not receive the "Mark Complete and Next" option. Does anyone know how to solve this?

hollow kernel
#

hi anyone can help me in upload file modules? I have a problem in client-side validation module

gaunt elbow
#

hi can some one help me on the saml wraping attack ? i cant undestanding how to execute the attack, i already try saml rider but no success

jolly oasis
hollow kernel
#

I could, thanks

timber thunder
#

hey idk if anyone has had an issue with the windows attacks and defense module on academy. I think I'm losing my mind because the Kali box IP is not working I've lost my moind for the last hour

timber thunder
# exotic coral whats the issue??

The IP for Linux in section 2 isn’t replying. I’m able to run the Kerberoast fine on the Win001 machine but I can’t get to Kali to run Hashcat

timber thunder
# exotic coral ss?

You mean ssh? Yea I’m trying to connect and it times out sorry I’m not in front of the computer anymore I can try again tomorrow

exotic coral
#

mmmm id have to look at the module, id have to look at it tmr what question is it?

native mica
#

Has anyone successfully solved the “Follow The Money” OSINT challenge? I’m currently stuck on question, 4 and can’t figure out why my solution isn’t working. Tried many permutations of the found name and partial email to no avail. Thanks in advance.

cloud urchin
#

@dusk holly Please take care not to post content from modules above tier 0

dusk holly
#

okay, I was just making sure reader would understand.

cloud urchin
#

Keep in mind anyone who has done the module will not really need the extra context

dusk holly
#

Kerberos Attacks: Unconstrained Delegation - Computers, I should force DC01 into authenticate to my SQL01 service, but I am not getting TGT for DC01 rather for SQL01 and darek.walker

cloud urchin
#

You may want to restart the target or try another server if you think you've done it right

#

i got a few more results than just 1

#

or double check your commnads etc

dusk holly
dusk holly
cloud urchin
#

it's possible it only happens once, so you may need to restart

#

i forget which module but i've seen an exploit just work one time then that was it til you rebooted

dusk holly
#

yeah right just making sure, we have to start to listen on Rubeus first then exploit the Printer bug right?

cloud urchin
#

yeah

dusk holly
#

thanks

dusk holly
# cloud urchin yeah

I got TGT for DC01 and it is enough to read the C disk inside Domain controller right?

#

but i am getting access denied error

cloud urchin
#

did you renew it

dusk holly
#

yeah i renewed it

#

let me try again, quickly to make sure

#

yeah still getting error

cloud urchin
#

when you type klist do you see the dc01$ ticket in memory

dusk holly
#

i am in Powershell

#

working with Rubeus

cloud urchin
#

you need to follow all the steps, and sometimes it isn't exactly 1:1

#

you can't just stop at getting the dc01$ ticket, you have to do the rest

dusk holly
#

yeah, I am will try, thank you for helping mate

arctic nimbus
#

Hi there! I'm kind of stuck with Shells & Payloads: PHP Web Shells.

When I have uploaded the .php file from WhiteWinterWolf's Web Shell to the Vendor, and I have changed the Content-Type to image/gif, forwarded twice, and then I access IP/images/vendor/phpfilename; instead of showing the webshell, it shows the whitewinterwolf webshell github repo???
Idk if its a bug or just something that I have done wrong.

sonic dirge
#

fundamental linux

What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?

I tried everything, and I can't find the answer.

#

can someone help me

dusk holly
devout lily
#

Hi everyone, is this command dnsenum --dnsserver 10.129.61.71 --enum -p 0 -s 0 -o subdomains.txt -f /home/juser/Desktop/subdomains-top1million-5000.txt inlanefreight.htb correct?

devout lily
# eager spindle Yes,it's right

i got another problem, seems like the name server generated for the DNS section is down, i tried to rigenerated the target and performed the ping command, but it doesn't work

eager spindle
devout lily
paper vapor
#

Hello i'm strugling with Server-side Attacks > Exploiting SSRF module.
I found the other service but can't exploit it.
can someone give me some help pls 🙂

heavy spoke
#

Hi! any hint for "injections attacks skill assessment" ? i could inject on description path a html, but when i tried aonther path internal not reflected i tried with another ports, but still in the same path stuck

nocturne pilot
#

Hello. I'm working through the Getting Started module. I'm on part 7 learning about nmap. When I spin up the target machine and connect to the VPN this is what I get when calling nmap. I tried ping too, but as indicated by the message those aren't getting through.

autumn pilot
#

We can't, you are on your own

autumn pilot
#

Any attempt to ask for help within an exam can lead to the termination of the exam attempt

mighty forum
#

ohh fairs

nocturne pilot
surreal goblet
#

Anyone feeling like playing THE FINALS?

#

And help me learn from you.

#

I mean the modules

heavy spoke
surreal goblet
nocturne pilot
autumn pilot
#

If you are using the provided workstation, then you are already connected to the VPN

#

What is the Nmap command and IP you are trying to run

nocturne pilot
#

Ok... I DIDN'T try pwnbox. I've been in a parrot vm. That's worth a shot

autumn pilot
#

Make sure to disconnect the VPN connection in your Parrot VM to not introduce any conflicts with two VPN connections running at the same time

nocturne pilot
brave field
autumn pilot
#

Sometimes company laptops can have additional settings in the firewall that will prevent packets/data flowing through, which can be the ones from nmap

heavy spoke
#

😆

nocturne pilot
#

Yea, I'll check firewall stuff later. What I didn't do, is try to connect to the VPN over TCP. I just kept using UDP files. That might change things.

heavy spoke
gaunt elbow
#

hello guys need some guidence, can some one give me i hint in how to resolve the saml wrapping attack module?

gray yacht
#

You should be able to keyword search that one.

short orbit
#

Hey i've been trying to do the Wordpress module, the very first question seemed easy, so i did a bunch of stuff and couldn't get it so after a couple of days gave up and looked the answer online, tried doing it by myself, didn't work i even did a feroxbuster but the flag.txt just isnt there

gray yacht
#

You can DM what you are using.

rose lagoon
#

can someone help me for TNS in the footprinting we have to setup ODAT but I think that the commands are obselete

grand willow
#

i want a password of a insta acc by hacking

heavy spoke
short orbit
#

The first one

#

Did that before feroxbuster but all files are empty or contain empty files

surreal goblet
#

You play

#

?

#

Wooow

#

Would be fun to play and pick up some skills together.

paper vapor
acoustic owl
#

Did you scan all ports?

paper vapor
#

yes i solve the question but i thought it was a mistake

glossy forum
#

does anybody know why i can't acces a webpage but the ip address and domain are added in etc/hosts?

storm elk
#

Are you connected to the vpn if it’s a 10.x.x.x ip?

glossy forum
#

i'm connected to pawnbox and pings are okay

storm elk
#

Did you add the port if required?

#

What’s the entry?

glossy forum
#

echo "10.129.128.223 unika.htb" | sudo tee -a /etc/hosts

storm elk
#

Is this for a module?

glossy forum
#

no port required it's from starting point lab responder

storm elk
#

Please ask there

gaunt elbow
# heavy spoke yerp

pay close attention on the responses to determine the injection and from there you can code a script to exfiltrate the flag

storm elk
#

English only please @chrome shale

chrome shale
#

@storm elk I was making cobblestone machine , and i need some tips , i have the web shell y upload via sqli , but i can get the reverse shell , can you give me some tips please.

storm elk
#

Please read and follow instructions in #welcome that’ll give access to #boxes

#

This channel is solely for academy module help 🙂

chrome shale
#

okay sorry

#

nice to meet you bro

storm elk
#

No problem 😄

chrome shale
#

❤️ 💪

storm elk
#

(I haven’t done cobblestone I think, people in there will be able to help you more)

light zealot
#

hey all, anyone recently work on the Pentest in a Nutshell module? The target box they give you does not have the vulnerabilities they indicate in the walkthrough. Just wondering if this is to be expected

grizzled schooner
#

Attacking Web Applications With Ffuf

Noticed earlier after doing some of the ffuf modules that there's an RSS summary file on my desktop, is this normal / anyone know where it came from? Please @ with replies

cedar void
cedar void
glass veldt
#

Hey guys Im working on login brute forcing and Im in the custome word list section, I've done everything perfect, updated cupp, downloaded ruby, got the username anarchy directory and everything else that you need to do that the section talks about but when I run the hydra command to brute force the log in after 2 hours of running the attack I get multple child wit pid terminating error, anyone have any pointers on what I can do? thank you!

#

this the second time this happened, I thought terminating and reseting my instance would help the first time but it didnt

cloud urchin
glass veldt
#

Yeah I made sure to keep my instance alive and then the second time around I kept an eye on my targets life span thinking that was the issue but it was still alive when I got the error

pastel flare
#

I tried the module again after a few days

I used the same commands but ||downloaded printerbug.py using wget instead of using the one preinstalled on the machine||

||either it was fixed from using a fresh machine, or by downloading the one linked in the reading||

hopefully this helps someone in the event they have the same issue

crimson moon
#

Attacking Thick Client Applications This is such a drag the app and VM is slow af

cloud urchin
#

Make sure you're on the TCP VPN. Also could try changing servers or regions if it's unbearable.

crimson moon
#

Restart-Oracle Services.exe doesn't seem to start after execution when checking with ProcMon64 anyone encountering this issue while doing Attacking Thick Client Applications??? Also, x64dbg is sluggish

#

tried terminating instances and respawning but same performance

#

target as well

frosty crescent
#

I'm completing the attacking common applications module and I must say people who write PoCs are some of the shittiest programmers I've ever seen

#

I don't think I could voluntarily write code this janky 😂

supple scaffold
ivory tide
#

Hi all, i am currently on NoSQL Injection: https://academy.hackthebox.com/module/171/section/1690 (Server-Side Javascript Injection - Automating the process).

I tried to build my own script instead of following the module. I have almost gotten the flag. I compared the flag to my friend's and 1 char of mine is incorrect. Could someone be kind to DM me to review my code to see what went wrong?

storm elk
tight seal
#

Has anyone solved the footprinting lab hard

#

As I am trying to fetch a message from openssl but it now fetching

hasty mauve
#

Module: Using CrackMapExec
Section: Skills Assessment
Question 1: What's the password of the account you found?

I started the challenge from an unauthenticated standpoint, I tried SMB Null authentication but it didn't work, I tried guest account, disabled, I thought of enumerating usernames through jsmith.txt wordlist, but this will take a lot of time.
But just to not waste anytime, I saw the hint, it says Review "Exploiting NULL/Anonymous Session", what can you use to enumerate users?.
Which doesn't make sense, as Null auth is disabled on all of the 3 devices, SQL01, DEV01, & DC01

Any help would be appreciated, I don't know if I'm missing something or the environment is bugged.
Tried resetting the target, didn't work.

sterile path
#

for the wireshark packet inception lab

I can't see enso224

#

only enso3

fathom pendant
fathom pendant
#

1 fetch <ID> <specifics>

tight seal
#

I already did ....idk why it was working inside htb parrot os

#

But not in my attacker machine

fathom pendant
#

¯_(ツ)_/¯

#

it worked on my machine when i did it a while ago

#

also make sure you turn off the pwnbox when you use your own vm

tight seal
#

Yesss I did that

#

I got the flag

sterile path
fathom pendant
#

so the interface doesn't exist on the target?

sterile path
#

xfreerdp /v:10.129.43.4 /u:htb-student /p:HTB_@cademy_stdnt!
sudo -E wireshark

#

are the commands I ran on wireshark

#

sudo wireshark doesn't work and running wireshark from the /usr/bin/wireshark from the gui file explorer doesn't work either

fathom pendant
#

so are you running wireshark IN the target

sterile path
#

nope

brave field
hasty mauve
sterile path
#

have to authenticate mrb3n

quaint glade
#

Is starting point a module ? It is the next to the last case.

sterile path
fathom pendant
fathom pendant
brave field
hasty mauve
cunning gulch
#

Whait

#

We are haker

storm elk
#

welcome @cunning gulch

cunning gulch
#

Ok

swift flame
#

Hi, I have a question - where I can find the IP of target machine? I do Network Foundations and the IP from the description is not visible for me to scan

#

I think it is issue with the platform as I could do part of the tasks yesterday, and same commands worked yesterday

autumn pilot
#

Within the questions there is a button with the text Click here to spawn the target system! once you click it after a few seconds it will populate it with the IP address of the target

#

Some questions may not have target(s)

swift flame
#

Thank you, it works for me after spawning the target system. Last thing - can I submit answers with enter or only by mouse click?

civic inlet
#

try adding to hosts file?

atomic dagger
#

wtf, my message has been fucked up ahahah

#

hello guys! I'm stuck from yesterday on using smbclient.py with kerberos

proxychains getST.py inlanefreight.ad/james -debug -hashes :HASHHHHHHHHHHHH -spn CIFS/dc02.logistics.ad

[………..]
[*] Saving ticket in james@CIFS_dc02.logistics.ad@LOGISTICS.AD.ccache

#

KRB5CCNAME=james@CIFS_DC02.logistics.ad@LOGISTICS.AD.ccache proxychains smbclient.py DC02.logistics.ad -k -no-pass -target-ip 172.16.118.252 -debug
I Always get this error:
[…………………]

[+] Using Kerberos Cache: james@CIFS_DC02.logistics.ad@LOGISTICS.AD.ccache
[+] Domain retrieved from CCache: INLANEFREIGHT.AD
[+] Returning cached credential for CIFS/DC02.LOGISTICS.AD@LOGISTICS.AD
[+] Using TGS from cache
[+] Changing sname from CIFS/DC02.logistics.ad@LOGISTICS.AD to CIFS/DC02.LOGISTICS.AD@INLANEFREIGHT.AD and hoping for the best
[+] Username retrieved from CCache: james
Traceback (most recent call last):
File "/............./python3.12/site-packages/impacket/smbconnection.py", line 321, in kerberosLogin
return self._SMBConnection.kerberosLogin(user, password, domain, lmhash, nthash, aesKey, kdcHost, TGT,
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/............./python3.12/site-packages/impacket/smb3.py", line 832, in kerberosLogin
if ans.isValidAnswer(STATUS_SUCCESS):
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/............./python3.12/site-packages/impacket/smb3structs.py", line 460, in isValidAnswer
raise smb3.SessionError(self['Status'], self)
impacket.smb3.SessionError: SMB SessionError: STATUS_MORE_PROCESSING_REQUIRED({Still Busy} The specified I/O request packet (IRP) cannot be disposed of because the I/O operation is not complete.)

rancid eagle
#

Hi , i wanna play some blue CTF , how can i sort them in CTFs

atomic dagger
#

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
File "/............./bin/smbclient.py", line 103, in main
smbClient.kerberosLogin(username, password, domain, lmhash, nthash, options.aesKey, options.dc_ip )
File "/............./python3.12/site-packages/impacket/smbconnection.py", line 324, in kerberosLogin
raise SessionError(e.get_error_code(), e.get_error_packet())
impacket.smbconnection.SessionError: SMB SessionError: code: 0xc0000016 - STATUS_MORE_PROCESSING_REQUIRED - {Still Busy} The specified I/O request packet (IRP) cannot be disposed of because the I/O operation is not complete.
[-] SMB SessionError: code: 0xc0000016 - STATUS_MORE_PROCESSING_REQUIRED - {Still Busy} The specified I/O request packet (IRP) cannot be disposed of because the I/O operation is not complete.

hasty mauve
rancid eagle
#

thanks , the remaining challanges all are red?

hasty mauve
rancid eagle
#

also i used to play the CTFs in SIEM . how can i find those ? in THM i would just search splunk and they would show up

hasty mauve
#

I'm an all red guy, so I don't know much about blue stuff on the platform lol.
Someone else will answer tho if they know.

spiral sapphire
rancid eagle
#

Thanks for the attention

charred pasture
#

Hello everyone. I have a problem with the submission of the skill assessment model in Applications of AI in InfoSec. The model I created on my machine works on the provided dataset and performs well, however when I upload it to the verification server, I get 0.0%, which is the same when I upload an invalid model. I am not sure how to proceed or 'debug' this situation. Can someone help me?

gray yacht
#

Did you run it with -debug at all?

amber heath
#

Anyone done AI Red teamer path? How was it?

gray yacht
#

You get this sorted out?

hasty mauve
# gray yacht You get this sorted out?

Yes, but still stuck on the same question XD
I know the password that I have to use (this is because I bruteforced it into the answer to save myself time from spraying a wrong password over 2355 users kek)
But, I cannot seem to get the correct username.
Tried the password on SQL01 smb NTLM auth & smb local auth, nothing.
Tried the password on DC01 smb kerberos & ldap NTLM auth, still nothing.
Now I'm trying it on DC01 smb local auth.
I don't know if It's supposed to work on SQL01 or am I supposed to suffer like this LOL

gray yacht
rancid eagle
#

guys i need some help .i have the pcap and have found the malware name but it asks for the virustotal hash . i can not find it in VT

final kite
hasty mauve
#

You can ask your question, if I know the answer I'll help, if I don't, I'm sure someone else will

gray yacht
#

Because it is incorrect? I'd look over the SSL certs.

amber heath
cyan arch
#

did that, still didn't get it. I can extract and get the restart-service.exe, but can't go past that. Literally followed the steps.

cyan arch
#

yup that's what I tried, having only the exit breakpoint and looking for the executable stored in the region, as dictated by them

final kite
wicked tiger
#

#!/bin/bash

var="8dm7KsjU28B7v621Jls"
value="ERmFRMVZ0U2paTlJYTkxDZz09Cg"

for i in {1..40}
do
var=$(echo "$var" | base64) # Encode with adding newline
if [[ "$var" == "$value" && $(echo "$var" | wc -c) -gt 113450 ]]; then
echo "$var" | tail -c 20 # Print last 19 chars + newline
break
fi
done

wet glen
#

Hi, i'm stuck doing the exercise in "Rouge Actions" section of "Attacking AI - Application and System ", I discovered that Time SQL injection can work for getting the flag, but i'm not sure it's the intended way.. If someone has done it can dm me?

glad patrol
#

Hlo

#

Guys

#

Can anyone guide

#

Guide me

#

I want to learn things in ethical hacking

#

I have many doubts

#

please anyone give me some time and clear my doubts

compact patrolBOT
mint adder
#

Hi, I'm having an issue with wpscan in the "Linux Information Gathering" section of the module Pentest in a Nutshell.
wpscan command is not returning the same 'theme' and 'Plugin' information as it has in the walkthrough, the rest of the output is fine tho. I would appreciate it if anyone could help me

oblique skiff
#

I am in the intro to network traffic analysis and I can't get wireshark to run a capture on any of the interfaces. This is in the Familiarity with Wireshark section. I am not connecting to a target host. The lab just wants me to capture traffic on any of the interfaces. The error says I don't have permission to capture traffic on XYZ interface.

oblique skiff
mint adder
hasty mauve
#

Create an account at wpscan website and get a free API key and use it

mint adder
hasty mauve
sand valve
#

😈

mint adder
#

wpscan -e p --url https://1.2.3.4 --disable-tls-checks --no-banner --plugins-detection passive -t 100

mint adder
hasty mauve
#

Try to just run wpscan --url <url> --enumerate --api-key <api key>

I'm writing it from memory lol so adjust that based on the actual flags

mint adder
hasty mauve
#

Hmm, this is weird.
Maybe try to update the tool?
I beleive it is wpscan --update or smth

mint adder
#

I'm using the latest docker image

hasty mauve
#

I'm not familiar with that module tbh, but did they show how to manually enumerate plugins / themes with curl or not?

If not, try to run wpscan on different pages

mint adder
mint adder
#

but thanks for your help

glad patrol
#

I am begginear

gray yacht
# glad patrol I am begginear

You posted this same stuff earlier and were provided with a link for information that is related to beginners. This channel is for assistance with HTB Academy modules and your posts are not related to any of the modules. Please refrain from posting that to this channel. You should go to #welcome to verify your account and gain access to other channels that are more for asking questions related to your doubts. I would also recommend reading over the #rules

hasty mauve
glad patrol
#

Bro I am begginear but I know many things and readed all text in htb

hasty mauve
#

If you're facing issues with a specific question then better to include that sp that we know how to help better

cyan arch
#

Yeah I faced this too as well, also no haven't dumped the bin to disk, my problem is that I don't see the bin at all

glad patrol
#

I have doubt In http and https website.i saw in many toturial they teach us about to compromise http but this is big 2025 we should know about how to gain access a https website it's isn't possible to get access https website or what? please clear this

mint adder
cyan arch
#

What we look for is some kind of functionality to abuse in a web app, which is unrelated to it running on either of them

#

ikr 😂😂😂

#

ive extracted the exe, which seems to print the banner correctly but locally it just exits idk y

#

yeah resetting the machine makes it work fine

#

okay finally oooof

#

I got it

#

thanks mate

quasi wave
#

hi I am on question 3 of ACL Enumeration section of AD Enumeration and Attacks module. I'm trying to get information about the specific AD subgroup and the specific user's rights over that group but my commands aren't working. I think that if I post the terminal output I will spoil. Anyone available for DM?

#

Can someone help me out here?

#

I want to show the commands I have tried but I'm scared its gonna spoil

cyan arch
#

I took a shortcut way, updated the bat file, so now the oracle.txt is created and no ps/exe, then I copied it to my machine. Wrote ps script to decode that and saved the exe.

#

Since I took a break and later started half way, I was assuming the first exe to be the one and running x64dbg on it because I named them the same xD.

river grove
#

Are you planning on updating Burp in the browser vms? Right now the burp version is so old that burp intruder doesnt work on it.

gray yacht
river grove
gray yacht
#

If you need further assistance with it, you can DM.

weak sun
#

i am getting issue in rdp connection in malware analysis lab. Anyone having same issue??

rare condor
#

why machine have not sqlplus ?

#

|| Enumerate the target Oracle database and submit the password hash of the user DBSNMP as the answer.||

#

please update path modules

sacred rock
#

@whole merlin I saw your post on the Erratum channel, I assume you managed to get it to work right?

whole merlin
#

@sacred rock Yes

fathom pendant
dreamy tapir
#

sometimes i cant ssh into the machine does anyone know why

cloud urchin
dreamy tapir
strange gale
rustic sage
#

before u can perform actions

quasi wave
#

doing last question of section I thought I needed help with today

#

I thought I needed help with question 3 but I didn't

#

figured it out. just had to take a break and come back to it

#

now on 5th and last question. we'll see if I finish the section by the time my friend is ready to pick me up

#

I think I'm doing increasingly better with this stuff

#

How long does it normally take to get full output from the right AD command for last question of sectiom

#

Is it like a 10 minute thing?

quasi wave
#

hi I am on the last question of this section. how long should I give this command to run?

#

before it gives me the output

#

this is for last question of ACL Enumeration section of AD Enumeration and Attacks module

#

hi so even when I try either of the two commands that should get me the output it never shows up

#

whether I run the command over the user or the group or whichever version of the command I use to specify

#

like it loads forever but I never get any output

#

wait I think I know what I am doing wrong

#

nope not getting it I will try again tomorrow

crimson moon
#

Anyone doing attacking thick client applications?

cloud urchin
#

If you need help you're better off just asking your question

crimson moon
#

have you completed the labs? I'm getting errors while doing it step by step as the module explains it.

strange gale
#

Module 216 section 2301. Analyzing Evil with Sysmon & Event logs. I am rdp'd into a windows machine from parrotOS and everytime I try to run the sysmon application it force closes. How do I solve this issue so I can simulate the attack from this module for a DLL injection?

cyan arch
crimson moon
upper widget
#

has anybody done Password Attacks module. I need favor in Pass the certificate section

rain mirage
eager spindle
#

I need help in this module Skills Assessment - File Inclusion.I have got the answer but not via burp suite,I want to know how to use burpsuite to get the answer.when I changed the UA to payload ,it return 500,I cheack out error.log.but I don't understand why

upper widget
eager spindle
upper widget
upper widget
eager spindle
upper widget
devout lily
#

openssl s_client -connect 10.129.182.3:imap is this command correct?

cyan arch
brave field
crimson moon
cyan arch
crimson moon
#

Can I Pm you?

waxen totem
#

@dire lily please don't spoil skill assessments

#

As for your inquiry, it's common to attempt all recovered credentials for every account, this is known as a password spray when done automatically.

dire lily
#

Apologies. I will go and check the rules again.

cyan arch
hushed hazel
#

you ever have those moments where you just go away, get a coffee and everything falls into place... after spending an hour just looking at text...

scarlet dock
#

hi guys im at the skills assesment of buffer overflow in Linux but i have 2 problems
when i create the string to send :

  1. the "\x90" in the memory become \xc2 and \x90
  2. the shellcode with all the bad chars deleted is still not correct in memory
    help
scarlet dock
#

i found the problem: for someone that have my same problem
you have to use python and not python3
because python3 with only print print not everytime correcty the byte
you have to use python or python3 with b'' and sys.stdout.buffer.write

icy dagger
#

Can I dm someone about the prompt injection attack module? I owned the skills assessment some while ago but I cannot figure out why my previous injection is not working rn

devout lily
#

Footprinting module - SNMP section
Hi everyone, the third question is "Enumerate the custom script that is running on the system and submit its output as the answer". Have i to answer with the name of the script or with its output as the question asks?

devout lily
waxen totem
#

do some footprinting and find out

devout lily
waxen totem
hushed hazel
waxen totem
brave field
devout lily
waxen totem
odd surge
#

please help me with this one

dire cedar
#

I'm in the next question, i stuck

odd surge
#

wait

#

@dire cedar can i dm you?

dire cedar
#

sure man

brave field
odd surge
brave field
odd surge
#

@brave field check

wicked apex
#

is it possible to extract the data from Documentation & Reporting Practice Lab?

The RDP session'd bloodhound is abit too slow and clanky to be used

#

I wanna just get the zip file and dump it into my local bloodhound so as to have easier and faster control w/ it

worn aurora
wicked apex
#

So you just ligolo-ng or chisel and just do it on your main?

#

aight ima try this too

worn aurora
#

I'm having an issue on that with the third question. I've done both a DC_Sync and dumped the NTDS file with crackmap and secretsdump.py. But I don't see the svc_reporting user

crude grove
#

Skills Assessment - Web Fuzzing
what's the answer template please? usually there's an example how to answer

cloud urchin
crude grove
gray yacht
crude grove
worn aurora
gray yacht
wicked apex
wet glen
#

Did anyone do the "Model Deployment Tempering" exercise in AI Red Teamer Path?
I don't get what error is causing this result:

curl -X POST 'http://127.0.0.1:8081/workflows?url=http://127.0.0.1:8000/pwn.war'

{
  "code": 500,
  "type": "InvalidWorkflowException",
  "message": "Failed to parse yaml."
}```
thorny karma
#

hey im working on the attacking enterprise networks, im currently on the lateral movement section, when using proxychains with any command it just doesn't work
proxychains evil-winrm -i 172.16.8.50 -u backupadm
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
<snip>
Info: Establishing connection to remote endpoint
[proxychains] Strict chain ... 127.0.0.1:8081 ... 172.16.x.x:5985 ... OK
Error: An error of type WinRM::WinRMAuthorizationError happened, message is WinRM::WinRMAuthorizationError

Error: Exiting with code 1

i used the right password

naive parrot
dusk crater
#

hello everyone, I'm working on module Upload file attack, I'm stacked on 2 section, cause in tryng to understand how open a reverse shell. It is not required for the flag, but it is explained in the section, i repeated all point, but it doesn't work.
I downloded from pentestmonkey php file reverse-shell.php, I changed the IP address with the one of my VM and I changed the port of the IP generated by the challenge. I uploated this file, downloaded this one, opened a shell using "nc -lvnp port", but it doens't work

#

can someone help me 🙂 ? thx to everyone

weak sun
#

Hi everyone, i am stuck in malware analysis debugging module. I manage to get connection to C2 message but still can’t get “This is the INetSim default binary” message. And for second “sandbox detection” message if it continue given instructions which is changing je shell.402F09 to jne shell.402F09, i ma getting “sandbox detection” message and if I continue with as it is je shell.402F09, I got “connection to c2” message. Any hints to how to move forward from here??

rustic sage
#

just wanted to ask , is there any other way to earn cubes ? like without you going to have to buy it

#

like tier 0 modules return equal amount of cubes and when you move forward in tiers you spend more cubes and they return less , the cube system is designed that way , that you have to buy them once you get over tier 0

rose lagoon
#

hello I'm in the Footprinting Medium lab and I want an hint please

foggy jackal
#

guys,,for those who have done android dyamic analysis...for the insecure library load through deep linking...did your apps update from v1 to v2 after clicking the update button? when i try to do that i it doesnt update to v2

#

i would appreciate someone who has been able to solve it to assist

round parrot
#

In MSSQL, EXCHANGE and Sccm Attacks skill assement i have tried pwd spray but not any luck. Am I going the wrong way? Got users but and read the policy

cloud urchin
#

You can also win some by placing in the seasonal challenges

rose lagoon
#

hello I'm in the Footprinting Medium lab and I want an hint please

#

good

coral willow
#

Hello, in the Injection Attacks module that is part of CWEE, the PDF attacks use SSRF to ultimately find the flag. There is a point where we are supposed to use the PDF vuln to "enumerate the server" so that we can figure out an internal API we can use to exfiltrate data. Can someone explain the server enumeration? how is that supposed to happen via the PDF vuln? the solutions in the module dont provide context, they just say students should enumerate the server but dont say how

fathom pendant
#

the context is gonna be in the reading

vale heart
#

Could someone help me with the cobblestone user.txt?

hushed hazel
#

as a linux user for the last 8 or so years, i'm finding stuff within Linux privilege escalation that i'd never considered...

#

turning out to be a nice insight from a blue team perspective.

cyan blade
fathom pendant
vale heart
fathom pendant
#

the second part of my statement tells you how to gain access

worn ginkgo
#

guys need help in Attacking Common Applications - Skills Assessment II. I got the answer but I just want to know whats the format
Image

coral willow
rose lagoon
#

Can someone help me in the Footprinting medium lab pls

rare narwhal
#

I’m on the Peeps module and would like a hint

cyan blade
#

I think nginx have it in /etc/nginx.conf

#

But yeah it's better to google those out because there's more than a default one

#

Also /etc/services might give something but I haven't tried that out personally

timber thunder
#

On the Windows Attacks on Defense module Kereberoasting section; I am able to kerberoast and get the file with the hashes but when I have to move it over to Linux and haven't been able to connect and I know the answer is probably in my face I cant connect to Kali with any of the IPs

abstract ingot
#

in passwords attacks skill assesment, any help?

vernal hamlet
#

i have the student subscription in the academy if i buy the gold sub while have the student sub does my student sub get canceled which mean i lose access to tier 0,I,II ?

rose lagoon
#

Can I have help in the hard lab footprinting pls

viral mica
#

Why does google think i am deteriorating? Do i look like i fuckin eat carrots?

viral mica
#

"We adjusted your settings for a more age appropriate solution."

viral mica
viral mica
rose lagoon
viral mica
#

Good take a break and go back later

rose lagoon
viral mica
#

Or you probably dont understand how to use dig

rose lagoon
rose lagoon
balmy knoll
#

Hello everyone, I'm having an issue with the virtualization module. In particular the Proxmox doesn't want to boot correctly. I've checked the RAM and CPU settings are good and once I have the ISO image inserted; everything seems to be in working order until I click enter for the "graphical" set up. It should give me text or something but instead goes black with no out put at all. can someone tell me what I'm doing wrong?

dreamy tapir
#

the question "What is the index number of the "sudoers" file in the "/etc" directory?" , how do you get the answer? I tried "stat /etc/sudoers" and wrote the Inode number

jolly oasis
#

Anyone available to help with File Upload Attacks > Whitelist Filters > "The above exercise employs a blacklist and a whitelist test to block unwanted extensions and only allow image extensions. Try to bypass both to upload a PHP script and execute code to read "/flag.txt" "
https://academy.hackthebox.com/module/136/section/1289

I already used the bash script to generate the wordlist for fuzzing with Intruder. I have several extensions that 'should' work. I got 'File successfully uploaded' in the responses. When fuzzing I injected the PHP Hello World script. Browsing to the files I uploaded I don't see the PHP code render at all though.
It also looks like when attempting to browse to the uploaded files, my \ are changing to // which is confusing.

#

And in one case, I get the message "Forbidden You dont have permission to access this resource"

brittle olive
timber thunder
#

are there certain modules that you can not use the pwnbox for and need to use the VPN? that might be my issue

fiery trench
#

Can any one give a hand with Advanced Deserialization Attacks, Example 2: XML
I've gone through the whole process and have the payload and the type string but it seems that I'm not finding the correct way to combine it together. Any help would be appreciated.

NVM: Figured it out , I missed the important POST 😅

brave field
jolly oasis
brave field
jolly oasis
potent pier
#

Cracking Wireless (WPA/WPA2) Handshakes with Hashcat
https://academy.hackthebox.com/module/20/section/226
Tells us to install hashcat-utils and use cap2hccapx.bin , but its giving me

hashcat-utils/bin/cap2hccapx.bin:Deprecated Notice. This tool is fully replaced with extraction tools from https://github.com/ZerBea/hcxtools 

and not returning a file. when running it on the provided .cap file.
Tested on both local and pwnbox.

cloud urchin
potent pier
#

Will do, thanks.

river grove
round parrot
#

Need some hints on MSSQL, Sccm skill assessment question 1. I got the useremailsbut not the right pwd list

pliant gazelle
#

With the CDSA path, i'm more wondering is there a few fields i should get a lot more comfortable with or should it be more equal? like should i focus on Wireshark, Windows Event Logs, IDS/IPS or everything in general.

wet glen
#

Did anyone do the "Model Deployment Tempering" exercise in AI Red Teamer Path?
I don't get what error is causing this result:

curl -X POST 'http://127.0.0.1:8081/workflows?url=http://127.0.0.1:8000/pwn.war'

{
  "code": 500,
  "type": "InvalidWorkflowException",
  "message": "Failed to parse yaml."
}```
sick stump
#

@stark egret here

#

forgot to change ubuntu to web but anyways, i want to transfer the lssas.dmp file from the windows internal host to attacker host

any ideas?

stark egret
sick stump
stark egret
# sick stump yeah

can you host a server on it? and then send a request from windows to pivot

#

or vice versa

#

describe the webshell?

#

lssas.dmp size?

sick stump
#

i thought of a smb server to host it, but failed miserably

sick stump
#

for the size my VM crashed cuz i did something stupid with proxychains sooo its gone 💔 🥀

stark egret
#

if lssas.dmp is not too big u can b64 encode it

sick stump
icy dagger
#

Can I DM someone about the whitebox analysis skills assessment? I think I found the bug but I’m having issues with quotation marks

devout lily
#

Footprinting module - MySQL section
Hi everyone, in this section there is this example with the Nmap enumeration to a MySQL server, but the text below says "This scan above is an excellent example of this, as we know for a fact that the target MySQL server does not use an empty password for the user root, but a fixed password". Is there an error?

hidden ledge
#

Hello I have a little issue when I want to upload the .aspx Webshell in the "Laudanum, One Webshell to Rule Them All" Module. I have this error when I try to upload the file. Is it my mistake ?

hidden ledge
#

Fixed

gray yacht
shrewd moss
#

can someone help me fixing this please? im struggling

#!/bin/bash

var="8dm7KsjU28B7v621Jls"
value="ERmFRMVZ0U2paTlJYTkxDZz09Cg"

for i in {1..40}
do
        var=$(echo $var | base64)
        
        #<---- If condition here:
done
 Create an "If-Else" condition in the "For"-Loop that checks if the variable named "var" contains the contents of the variable named "value". Additionally, the variable "var" must contain more than 113,450 characters. If these conditions are met, the script must then print the last 20 characters of the variable "var". Submit these last 20 characters as the answer.

#

i dit this but its the wrong result:

#!/bin/bash 

var="8dm7KsjU28B7v621Jls"
value="ERmFRMVZ0U2paTlJYTkxDZz09Cg"

for i in {1..40}
do
    var=$(echo "$var" | base64)

    if echo "$var" | grep -q "$value"; then
        if [ ${#var} -gt 113450 ]; then
            echo "${var: -20}"
        fi
    fi
done
abstract ingot
#

why is ssh pivot not working in Skills Assessment - Password Attacks?????

devout lily
#

Can someone explain?

abstract ingot
round parrot
devout lily
#

do you know why?

abstract ingot
#

it is --script=(script) the correct syntaxis i think

devout lily
#

does anyone else know something about?

waxen totem
devout lily
#

i don't know how to solve

waxen totem
devout lily
#

no result

waxen totem
devout lily
waxen totem
waxen totem
devout lily
#

but why nmap see this file if it searches script frm the scripts directory?

waxen totem
#

bash is evaluating it before nmap does

devout lily
waxen totem
#

no it's for cwd

stoic wyvern
#

can any body help me with logrotate privilege escalation

#

im not able to get the reverse shell

waxen totem
spring kindle
#

hey, can anyone help me with this : chmod 600 id_rsa
❯ ssh -i id_rsa tom@10.129.202.20
tom@10.129.202.20: Permission denied (publickey). is for the hard lab footprinting.

stray wadi
#

Hi I just started taking the cjca exam & I am having some connectivity issues. Can I possibly PM someone for assistance?

compact patrolBOT
devout lily
#

i have tried with different combinations but the output is the same everytime

#

done!!

wild oriole
#

Hello guys,

I am running socks_proxy from MSF, and after ~ 5-10min the connection becomes timeout, even I can confirm the Pivot host itself still functional and working

spring root
#

is htb ever goanna make a wi-fi hacking skill path or even better a certificate?

acoustic owl
#

Nothing has been confirmed yet, but the number of modules suggests this is the case.

stray wadi
plain summit
#

Any other Pro Labs outside of P.O.O., Dante, and Offshore for CPTS Prep?

storm elk
plain summit
#

I got the subscription to do the three labs before I start the exam.

storm elk
#

Zephyr is a fun one

delicate adder
#

Hi, I'm doing the module on nmap and I have to find the flag in the services. I tried all the types of scans listed but it doesn't work. Now I'm trying with the manual scan with tcpdump and netcat but I don't get any banners.

#

what could be the problem?

toxic shell
#

It so frustrating that when you start an instance for VM doesn’t connect and you lose it if you refresh the page

#

Free is not the way to go

vernal cove
#

Hola Migos

cloud urchin
#

Hi and welcome. Please make sure to read the #rules and follow the instructions in #welcome to gain access to more channels.

vernal hamlet
#

guys

#

i bought the platinum subscription and got only 700 cube shouldnt i get 1000 cube as it says ???!

cloud urchin
vernal hamlet
cloud urchin
#

Support is not provided over Discord

vernal hamlet
#

but the platinum subscription gives a 1000 cube right ?

cloud urchin
#

Looks like it yes

twilit fjord
#

hey just an ask but with interactive sections, i know im meant to reapply the commands im learning and play around with them myself.

But would it be effect to also note them down or would it just be hindering?

cloud urchin
#

The commands? I'd definitely recommend adding those to your notes

civic inlet
sinful pewter
#

Uh hello, how do I claim the certificate for Holmes 2025 CTF?

plain summit
wispy nest
#

I seem to be stuck on a pretty easy question asking "How many layers are typically included in device protection? (Format: <number>)" I'm pretty sure the answer is <4> but that doesn't seem to be working #modules

#

turns out just 4 was fine. not sure why it suggested that format and <> was required

chilly dagger
#

hi

wispy nest
#

it was the question at the end of the "Mobile Security" page in the "Introduction to Information Security" module. But I figured it out thank you. Just the number by itself worked

cloud urchin
silk hazel
#

I'm going through the "Cracking Passwords with Hashcat" module and there is an optional exercise involving an NTDS dump and a responder log. I was able to get a few passwords for the NT hashes but I have no heckin' clue what this thing is asking me for and I don't know anything about NTLM yet as I haven't done any AD modules like that yet. Did I miss something in the hashcat module or is this something I should come back to after learning more about NTLM2? It's at the bottom of https://academy.hackthebox.com/module/20/section/113

Recently, however, you read about another method to obtain something usable when you have an NTLMv2 password hash.
🤷

silk hazel
drifting torrent
#

did anyone use DBeaver to connect to Oracle DB? I am on GUI of DBeaver, where can i find the password hash of DBSNMP?

#

i found the DBSNMP user, but could not find password hash

worn ginkgo
#

Did anyone solve RDP and Socks tunneling with socksoverrdp in pivoting module with ligolo? This section is a double pivot, anyone.?

dark glen
#

Hi.. is there any required format for submitting the SID(security identifier) for the windows module. I have been trying this for the past 1 hour and it's always wrong:
S-1-5-21-2614195641-1726409526-3792725429-1003

cloud urchin
dark glen
mint niche
#
  • 3 Create a "For" loop that encodes the variable "var" 28 times in "base64". The number of characters in the 28th hash is the value that must be assigned to the "salt" variable.

guys i have problem with this question i need help [ room bash script ]

river grove
#

you can dm me

remote steppe
#

Is there a way to reset my progress in an academy path or module?

boreal kelp
wet glen
#

Did anyone do the "Model Deployment Tempering" exercise in AI Red Teamer Path? I'm really out of ideas for extracting the flag

warm shell
#

hi

#

anyone here

hidden lava
#

Hello guys semoene sent me a link can semeone check it

gilded harness
#

hi guys

idle frost
#

Bonjour

#

Je viens d'integrer hack the box
Et j'aimerai que quelqu'un me guide pour les premieres etapes
Et merci

compact patrolBOT
acoustic owl
#

This blog post shows you how to get started.

idle frost
#

Hello,
I just joined Hack the Box.
And I'd like someone to guide me through the first steps.
Thank you.

acoustic owl
#

Check out the blog post I posted above.

idle frost
#

Okay thank u

keen jacinth
#

hey guys I'm literally stuck at Burp intruder Using web proxies

I tried the intruder using burp but only get 301's and no flag

can anyone help?

round parrot
#

i got a question about mssql and sccm skill. I can use nxc with mssql but not impacket-mssql or powerup.. i think the way to escalate but cant get it to work over nxc

round parrot
#

ok. i get logon failure as soon as i use impacket but works with nxc. i think my syntax is right. i have used domain/name:pwd@ip and without

gray yacht
round parrot
#

hahhahaha, thanks

#

i thought i have read the help so many times. but apparently not enough 🙂

glacial quiver
#

I need help!!!

heavy bronze
#

ok

#

Now we all have it kek

glacial quiver
#

Have what?

glacial quiver
gray yacht
glacial quiver
#

Oh

gray yacht
# glacial quiver Oh

If that is the correct flag, check for leading or trailing space and maybe a page refresh is necessary to resubmit.

brave field
drifting pike
#

is there any way to earn cubes or voucher without giveaway, like keeping streak or solving ctf, for individual? givewaway has huge randomness and also public competitions as well.

drifting pike
#

I need cubes to learn but at the point of life, I can't spend that much from this circumstance.

drifting pike
#

I've already seen it. Thanks ❤️

dull galleon
#

guys ive been trying to solve the Virtual Hosts for more than 3h idk what working with it i mean i've tryd to change thing and it just wont work

drifting pike
limpid hemlock
#

In the intro to windows evasion module I'm stuck at opensource section can anyone help me there been stuck for s long time there

jolly oasis
#

Greetings all, I just finished File Upload Attacks > Whitelist Filters. After fuzzing extensions, to make sure the PHP code actually renders on page, I manually browsed to every single file I uploaded with the appropriate response length 😬

That seems very inefficient. Is there a way to dump those URLs to a file and check if the code renders on the page? I don’t think cURL would do the trick?

jolly oasis
#

So in this case we already knew PHP was being used on the site. But we had to go through and validate which extension allowed to PHP Hello World code to actually run.

leaden island
#

yo guys

#

one problem.. many questions

#

im on SQLmap essentials

#

on the 6th section 'Attack Tuning'

#

well

#

my question is answered while im typing so

#

thanks for anyone who was a part of it

jolly oasis
#

Right. I used Burp Intruder to fuzz. Now that I think about it, I should have just went to the Render tab in the responses huh…🤣

jolly oasis
#

Right. But this doesn't this doesn't show if the code actually runs does it?

#

Ok, thank you for the responses!

final kite
#

I found flag but for some reason it doens't accept it

#

i url decoded it also

cloud urchin
#

then it's the wrong flag. maybe manually type make sure no whitespaces if you think you have it.

steel juniper
#

Is there any way to make Nmap run a service scan faster?

cloud urchin
fathom pendant
civic inlet
crystal cove
#

Is there a ranking somewhere à la duolingo for the weakly streaks ? Or is it just a personal metric ?

cloud urchin
#

This isn't a duolingo server

crystal cove
#

so no ranking then

#

(on the streaks)

fathom pendant
#

no

left urchin
#

just curious guys if any of u wana help me with AD module?

#

i am trying to take the points so i can purchase another path

cloud urchin
#

Always best to just ask your question. Make sure to include the module, section, and question you're on. Relevant details like what you've tried helps too. Just don't spoil any content above tier 0.

left urchin
#

in other words i just want the points if that's possible? , i do not know AD tho and this is pivoting

#

it would require a lot of work i dnt understand , i just need the points so i can purchase the path i wanted but yea

cloud urchin
#

No one's going to just give you the answer.

#

Like I said, best to say which module, section, and question you're on. You haven't said that so no one can help.

#

There are a number of modules that use AD.

left urchin
#

just a few questions , like why not? i am going to buy cubes later on but i wana collect the left over points

u dont want a hackthebox customer? i am going to spend later but i jsut need to take the left over points

#

i am like 80% done but the remaining one requires heavy pivoting , i dnt know honestly

cyan palm
cloud urchin
left urchin
left urchin
#

gona spend it on the bug hunter path

#

but i figure i got 1 AD module which has cubes to take

#

however these questions aint easy lol , like i dnt know AD tho honestly.

cyan palm
#

well that violated TOS

fathom pendant
left urchin
#

i only left with 4 cubes remaining , wont make a big diff , so i moving on to buy cubes to unlock my desired path

fathom pendant
#

i mean it's part of the CPTS path if you're planning on doing that one

#

¯_(ツ)_/¯

#

but whatever boats your float

left urchin
#

i am doing the bug hunter path

fathom pendant
#

¯_(ツ)_/¯

left urchin
#

yea why still error in the repo i downloaded , no time for it atm , too hassle , it should be simple but gives me an error on the code while i try to run the server

#

that's just 1 simple question anyways
the rest of it requires pivoting and getting the flag on the compromised machine

#

i have no idea honestly but yea

fathom pendant
#

i mean you can solve it using any other pivoting technique if you don't wanna use rpivot

#

you're not forced to use the tool in the section

left urchin
#

i dk pivoting tho , what other tools? let me try

#

chisel? lingolo?

fathom pendant
#

chisel, ligolo, even just the remote/reverse pf technique from earlier in the module

#

even sshuttle

#

the fact you're saying "i don't know pivoting" means you didn't take notes going through the module and were just hoping to skate by on 3rd party guides that break ToS so that you didn't have to put in the legwork to actually learn WHY what you're doing may not be working

left urchin
#

i am working on bug hunter path now , but 4 cubes not much big diff , i asssume the bug hutner path gives cubes like 10-20 for each completed room or smtg

#

i can always come back to learn fully , but now i am fighting against the time
is better to work smart sometimes why waste time when i can use my brain
but 4 cubes , oh well

#

it was just 1 module of AD i dint buy the entire thing , i would study if i wana buy the entire thing lol

i think i got it back then was cause i wanted to see academy's pivotting when i was looking into the OSCP
so i only got like 1-2 AD related moduels from academy i dint get the entire CPST path course

fathom pendant
#

respectully lol that wasn't what i was saying at all

heavy dome
#

why? 😭 2 days im here...

#

Why can't I find the file on Arturo's desktop RDP IPv4?

#

the module is Windows Laterlal Movements: Skills Assessment: Q2

glad flicker
#

Also maybe you need to specify the AD domain?

heavy dome
#

Thank you, but I don't think so. I believe the password and domain are correct.

hasty mauve
median gale
#

Anyone did the new wpa3 attacks module ? Stuck in the final q of sa. What is the password of the Wi-Fi network "Orionexa-IOT"?

#

Nvm, anyone stuck here just have a little more patience and you will get it

glad finch
#

Hi! Which modules have you liked the most? I have a month left until my silver subscription expires and I'd like to do a few good modules

dull galleon
#

hey guys im stuck at the Virtual Hosts thing for more than one day like when i visit the domain its down when i put it the etc/hosts and still the domain still not working like i know the flag but still the web site down and i wont submit
it

flint folio
#

Hi,

I am stuck at Information Gathering - Skills Assessment (last 2 questions).

Can anyone help me out?

EDIT: nvm I got it

dull galleon
#

hey guys im stuck at the Virtual Hosts thing for more than one day like when i visit the domain its down when i put it the etc/hosts and still the domain still not working like i know the flag but still the web site down and i wont submit
it

dark glen
#

Hi.. am having connectivity issues using reminna on my machine kali2025.3. I can confirm that openvpn is working ifconfig and using ip route get lab_machine_ip_address goes throught the tunnel. Also i ping my tun ip_address and all were success. Currently working on windows module. Any help would be appreciated

shadow phoenix
#

Could someone please give me a clue about the skills assessment for the 'LLM Output Attacks' module? I've already found the admin key and accessed the Adminbot, but then I don't know what else to do to get the flag.

autumn pilot
#

Try to understand the features the adminbot supports

shadow phoenix
#

Could you please confirm if the calculate_shipment_time function is the correct way to go? It's the only function that accepts user input.

autumn pilot
#

🤷‍♂️

#

if it's the only one, analyze it

shadow phoenix
#

I can't get this function to generate any kind of indication of a possible SQLi. Is that the correct path?

autumn pilot
#

Recall what you've learned throughout the module

gray yacht
rain mirage
#

PASSWORD ATTACKS
Skills Assessment - Password Attacks

i have access to the external host DMZ01 , the next step is to get access to the internal DMZ01 (i think) , but i dont know how to , i tried searching for low hanging fruits , ANY HINTS ?

dull galleon
#

hey guys im stuck at the Virtual Hosts thing for more than one day like when i visit the domain its down when i put it the etc/hosts and still the domain still not working like i know the flag but still the web site down and i wont submit
it

gray yacht
gray yacht
rain mirage
#

i dont know what to do next

gray yacht
dull galleon
gray yacht
rain mirage
near flint
#

Hello. I had a question about the student account in HTB. How do I add a student account and how long does it take to be approved? I added a student account, but to make it the first one, I need to change it, and when I try to change it, it says that you can't change it until October 10th, what is the reason for this?

acoustic owl
nocturne sun
#

Can I dm someone for File Upload Whitelist Filters

brave field
nocturne sun
edgy marlin
#

Hi everyone, I'm stuck at Pass the Ticket from Windows, i'm trying to do the "Optional Exercise" and doing PtT using PowerShell Remoting only with Rubeus.exe but I always fall into "KRB-ERROR (24) : KDC_ERR_PREAUTH_FAILED" I put the key decoded in hex format. What I am doing wrong? Thanks

opal shuttle
edgy marlin
opal shuttle
edgy marlin
# opal shuttle which command you are executing
  1. Rubeus.exe dump /nowrap
  2. Convert base64 key in HEX format
  3. Rubeus.exe createnetonly /program:"C:\Windows\System32\cmd.exe" /show
  4. Rubeus.exe asktgt /user:john /domain:INLANEFREIGHT.HTB /aes256:<hex> /ptt
    Here I have the issue "KRB-ERROR (24) : KDC_ERR_PREAUTH_FAILED"

The HEX converted key it's the same I can dump from Mimikatz using "mimikatz.exe sekurlsa::tickets /export" Session Key aes256_hmac

#

The point 4. was runned in the new cmd.exe session

quiet sun
#

hello if i want to get the academy with studiant email how can i do it¿?

final raptor
#

Sorry maybe this a dumbass question but I have answered all the questions...but button mark complete & next is missing even and because of that I cannot finish the module...

opal shuttle
#

maybe u can try rubeus kerberoast instead of asktgt

heavy spoke
#

hi Everyone, i'm stuck on Injection Attacks skill Assessment, actualy i've ssrf, but i tried with xpath/sqli and still stucked, anybody has pwned the lab?

edgy marlin
tranquil wren
#

Hello, i am working on 'Credential Hunting in Network Shares' https://academy.hackthebox.com/module/147/section/1334, i have ran snaffler, but it returns alot of info. i have also tried using the -u paramenter for a user i found from the user folders on the target. Also ran netexec with no luck as well, i couldn't get powershuntshares to run really.

#

anyone had any luck with this module

limpid hemlock
#

he anyone finished the intro to windows evasion module free to help im stuck at the open source part of the module

tranquil wren
#

nevermind i got it

paper heart
#

Heey guys, I am stuck on a Introduction to Active Directory / Active Directory Groups / Q1. What group type is best utilized for assigning permissions and right to users?

Can somebody help me with this ?

I think the answer is "Security groups" but its not.

drowsy grove
#

|| ┌──(root㉿kali)-[/opt/subbrute] └─# ./subbrute.py inlanefreight.htb -s ./names.txt -r ./resolvers.txt /opt/subbrute/./subbrute.py:462: SyntaxWarning: invalid escape sequence '\.' permute_filter = re.compile("^[a-zA-Z0-9]{" + str(self.permute_len) + "}\.") /opt/subbrute/dnslib/lex.py:141: SyntaxWarning: invalid escape sequence '\.' """ Warning: Fewer than 16 resolvers per process, consider adding more nameservers to resolvers.txt. Warning: No nameservers found, trying fallback list. Process lookup-3: Traceback (most recent call last): File "/root/.pyenv/versions/3.12.7/lib/python3.12/multiprocessing/process.py", line 314, in _bootstrap self.run() File "/opt/subbrute/./subbrute.py", line 422, in run response = self.check(hostname, query_type, timeout_retries) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/opt/subbrute/./subbrute.py", line 342, in check resp = self.resolver.query(host) ^^^^^^^^^^^^^^^^^^^^^^^^^ File "/opt/subbrute/./subbrute.py", line 57, in query name_server = self.get_ns() ^^^^^^^^^^^^^ File "/opt/subbrute/./subbrute.py", line 107, in get_ns ret = self.nameservers[self.pos] ~~~~~~~~~~~~~~~~^^^^^^^^^^ IndexError: list index out of range ||

This is sooo broken lol

#

I have no idea how I'm supposed to fix this lol

mystic agate
#

Hey everyone! I’m new to the cyber path — started today. You all seem super experienced — any tips for a beginner? I’m planning to take the CEH (EC-Council) in 3 months, so any guidance, study resources, or lab recommendations would be amazing. Thanks in advance!tux

gray yacht
half ice
#

hello can someone help me. I am having a hard time to RDP.
I tried xfreerdp /v:IP ADDRESS /u:USERNAME /p:PASSWORD but it prompts bash !@# Event not found
I'm working on the Windows Event Logs

gray yacht
weak knoll
#

Hello, im trying to figure out the SQLi fundamentals skill assessment. I dont quite understand why if i have the FILE privileges and SECURE_FILE_PRIVILEGE with no restrictions, yet i cant just write the webshell in /var/www/html

gusty dune
#

Hello guys, I'm a complete beginner hacking, I know how to code with Java, Php, JavaScript , SQL... What should I start learning and how?

gray yacht
gusty dune
#

And why I can't acces the general chat?

spare condor
#

@short hare I have the same problem. Did you find the correct format? Anyone on this?

gray yacht
mystic agate
gray yacht
gray yacht
opal shuttle
#

There is another path where you can write

#

They want you search that in which folder you have privs for writing

cobalt frigate
#

im stuck nearly 2 days (

#

i did

#

which one i need choose? ffuf or gobuster?

#

using fuzzing

#

on firefox

gray yacht
cobalt frigate
#

hmm okayy

opal shuttle
shadow phoenix
#

Could someone please give me a clue about the skills assessment for the 'LLM Output Attacks' module? I've already found the admin key and accessed the Adminbot, but then I don't know what else to do to get the flag.

round parrot
#

is it my box that is buggy but i can load any in memory or upload anything to sccm skill assesment db02

dark jay
#

hello, i am doing Command Injections module and i am stuck on Advanced Command Obfuscation can anyone help please?

jolly oasis
#

Currently working through: File Upload Attacks > Type Filters > "Exercise: Try to run the above scan to find what Content-Types are allowed."
https://academy.hackthebox.com/module/136/section/1290

I figured this would be super simple. I created the wordlist for only image types using the commands in the section. Fired off Intruder with Content-Type as the position. All the responses were either 226 or 227 length and had the message "Only images are allowed". Changing the filename to shell.php (as shown in the section screenshot) results in "Extension not allowed". Not a huge deal but I figured I would get the same results shown in the section.

wild oriole
#

Hello guys
In "AD Enumeration & Attacks - Skills Assessment Part II"
Why do we have to run the "Inveigh" again if we have already run the Responder and found one user? AFAIK, if we are within the same network, we can listen to all LLMNR requests.

Please correct me if I am wrong

cloud urchin
#

@tepid horizon Please take care not to spoil content from modules above tier 0

tepid horizon
cloud urchin
tepid horizon
#

I am stuck on DACL Attacks II: Q1. Can anyone discuss how to proceed?

I am asking because I was warned that I must not reveal the detail of course here. so I am looking for someone who can discuss on DM

quiet ember
#

On DACL Attacks II Skills Assessment Q2, I have the ||GPO created and linked|| but when I run ||gpupdate /force|| nothing happens?

frosty glen
#

"Configure SELinux to prevent a user from accessing a specific file."
Anyone can help me in this question. from Linux fundamentals - Network Configuration

jolly oasis
#

I'm pretty stuck again:
File Upload Attacks > Type Filters > "The above server employs Client-Side, Blacklist, Whitelist, Content-Type, and MIME-Type filters to ensure the uploaded file is an image. Try to combine all of the attacks you learned so far to bypass these filters and upload a PHP file and read the flag at "/flag.txt""
https://academy.hackthebox.com/module/136/section/1290

I'm just starting by fuzzing a file extension that isn't blocked. All the extensions I've tried are blocked. Next I tried adding the Magic Byte and fuzzed with that as well - all extensions still blocked.

cloud urchin
jolly oasis
#

Been through it twice now

cloud urchin
#

Start simple, find something that actually uploads. Like a real picture. From there use Burp to iterate through the extensions til you find one that works.

jolly oasis
cloud urchin
#

I used the list they taught in the module

jolly oasis
cloud urchin
#

make sure to use the techniques in the file extension section too

jolly oasis
cloud urchin
#

Try what's provided in the Whitelist Filters section

jolly oasis
cloud urchin
#

i believe it's the same list but with some additional techniques

#

just take it 1 step at a time. the first goal is finding a file extension that uploads.

#

then move on to the next filter, etc

jolly oasis
cloud urchin
jolly oasis
cloud urchin
#

the script is for character injection

jolly oasis
#

Tried using the PayloadsAllTheThings extension list as well as the SecLists one.

cloud urchin
#

Use the very first technique shown in that section

spark hollow
#

Hello Everyone !
I need help with this one please, I know the answer because I know stuff from pentest experience. However I want to know how am I supposed to do this without guessing !!!

Extract and scrutinize the memory content of the suspicious PowerShell process which corresponds to PID 6744. Determine which tool from the PowerSploit repository (accessible at https://github.com/PowerShellMafia/PowerSploit) has been utilized within the process, and enter its name as your answer.

jolly oasis
#

Tried the first thing in Blacklist filters - no luck. All it has us to is alter the name of the file and insert our shell code. Immediately after that we go to trying the wordlists. First for extension fuzzing, then character injection.

worn aurora
#

In the AEN module I have the NTLMv2 password hash for the mpalledorous user, however I've tried multiple wordlists (rockyou.txt, password.txt from earlier) and am not getting it

cloud urchin
jolly oasis
cloud urchin
#

ok

desert pelican
#

Anyone can help with Advanced command obfuscation?

civic inlet
desert pelican
viscid bolt
#

Currently doing MSSQL, Exchange, and SCCM Attacks, in the Exchange section for Enumeration, the third question is ||Find valid credentials and submit the email|| not really sure what it means by this if someone has a nudge, probably straightforward

autumn pilot
#

You have gathered potential email addresses, try to find a way to obtain access to one of them

viscid bolt
unique field
#

Hello, on the Attacking Web Applications with Ffuf module- the Skills Assessment . I am stuck on third question saying "One of the pages you will identify should say 'You don't have access!'. What is the full page URL?". any guidance would be much appreciated.

viscid bolt
sinful oak
#

Hey everyone, newbie here with his first ask for help lol. I'm on the knowledge check in the getting started module. I finally cracked the admin password after like an hour of trying to get hashcat to work, utterly defeated to find not a trace of the user.txt flag... where on earth am I supposed to be looking???

dark jay
river grove
foggy snow
#

Hey! im doing the Pivoting, Tunneling, and portforwarding skill assessment but the pivot host just isn't stable, im trying to use ligolo-ng, and I got it to work with xfreerdp, but my agent keeps getting dropped, is there a way to stabilize the connection so it doesn't constantly get dropped?

waxen totem
foggy snow
viscid bolt
gusty mulch
#

can someone point me toward the Theranos device

rain mirage
#

Password attack , skill assessment
I'm in the DMZ01 (external) trying to get any ticket and stuff so I can enter the internal network , do I need to do privilege escalation of DMZ01 to get crediantials of internal network first?

#

Or I can get it with the local user itself (which I tried but can find anything)

foggy snow
vague rivet
#

The Password Attacks module, I am still stuck on the Pass the Certificate, the second question. The Printerbug.py is showing an error. Any help? And yes, I have tried running it as root on both occasions.

fathom pendant
rain mirage
fathom pendant
rain mirage
fathom pendant
devout lily
#

Can anyone help me with ODAT installation? The script on the HTB academy section doesn't work

fathom pendant
#

also parrot has ODAT in their repo

devout lily
fathom pendant
#

:)

#

specifically the 'note'

primal pasture
#

Hey, I’ve completed all the questions in the Introduction to Windows Command Line – Skills Assessment module, but the “Mark Complete & Next” button isn’t showing up. I can’t finish the module because of that… has anyone else run into this?

spice sequoia
#

hi i'm currently doing the password attacks module. I managed to get the Notes.zip file thru ftp into my desktop.

I generated a hash using zip2john Notes.zip > notes.hash I found out it is a pkzip but no matter what wordlist i use it doesnt work. rockyou.txt etc. Am I missing something?

green musk
#

am i the only one facing this issue in ATTACKING ENTERPRISES NETWORK? [ERR] yamux: keepalive failed: i/o deadline reached
ERRO[0040] Connection error: keepalive timeout
FATA[0040] keepalive timeout
i'm using ligolo till now but since today itself it keeps getting timedout

wicked tiger
# mint niche + 3 Create a "For" loop that encodes the variable "var" 28 times in "base64". T...

#!/bin/bash

Decrypt function

function decrypt {
MzSaas7k=$(echo $hash | sed 's/988sn1/83unasa/g')
Mzns7293sk=$(echo $MzSaas7k | sed 's/4d298d/9999/g')
MzSaas7k=$(echo $Mzns7293sk | sed 's/3i8dqos82/873h4d/g')
Mzns7293sk=$(echo $MzSaas7k | sed 's/4n9Ls/20X/g')
MzSaas7k=$(echo $Mzns7293sk | sed 's/912oijs01/i7gg/g')
Mzns7293sk=$(echo $MzSaas7k | sed 's/k32jx0aa/n391s/g')
MzSaas7k=$(echo $Mzns7293sk | sed 's/nI72n/YzF1/g')
Mzns7293sk=$(echo $MzSaas7k | sed 's/82ns71n/2d49/g')
MzSaas7k=$(echo $Mzns7293sk | sed 's/JGcms1a/zIm12/g')
Mzns7293sk=$(echo $MzSaas7k | sed 's/MS9/4SIs/g')
MzSaas7k=$(echo $Mzns7293sk | sed 's/Ymxj00Ims/Uso18/g')
Mzns7293sk=$(echo $MzSaas7k | sed 's/sSi8Lm/Mit/g')
MzSaas7k=$(echo $Mzns7293sk | sed 's/9su2n/43n92ka/g')
Mzns7293sk=$(echo $MzSaas7k | sed 's/ggf3iunds/dn3i8/g')
MzSaas7k=$(echo $Mzns7293sk | sed 's/uBz/TT0K/g')

flag=$(echo $MzSaas7k | base64 -d | openssl enc -aes-128-cbc -a -d -salt -pass pass:$salt)

}

#Variables
var="9M"
salt=""
hash="VTJGc2RHVmtYMTl2ZnYyNTdUeERVRnBtQWVGNmFWWVUySG1wTXNmRi9rQT0K"

for i in {1..28}
do
var=$(echo "$var" | base64)
if [ $i -eq 28 ]; then
salt=$(echo "$var" | wc -c)
fi
done

if [[ ! -z "$salt" ]] 
then
   decrypt
   echo $flag

else
exit 1
fi

fiery crane
#

anyone having issues with VPN ?

elder bear
waxen totem
unkempt fern
#

Please I need a job i am am ethical hacker I can do other stuff

hidden ledge
#

Hello, In the Password Attack module, in this section: "Attacking Windows Crendential Manager". I can't run mimikatz like in the course because I don't have enough permissions, the hint says we should look at UAC bypass but I really don't know how to do it since there is nowhere it explains it in the course at this point and there is a lot of different techniques on internet. Where should I look ?

unkempt fern
#

Explain

waxen totem
#

@low solstice this is not that kind of server, please familiarize yourself with the #rules

fathom pendant
hidden ledge
#

I did but there is a lot of different technique from what I see, I'll look further more

fathom pendant
#

(i believe the section mentions it as a footnote)

#

@hidden ledge don't spoil things 😉

hidden ledge
#

Woops my bad sorry !

#

Thank you for your help

proper parrot
#

I'm trying to do this Module. RDP keeps disconnecting 🙁 like every 30 seconds of use.. it drops..

#

I changed wifi , restart machine, restart vpn. Same

#

Ping works just fine. RDP port is open

#

So i'm not sure what's happening

covert yacht
#

Hi guys,
So in Hackthebox academy I am stuck in getting started with the web enumaration. There was a port 32776 open about Inlane Freight however this port suddenly closed and new instances this port is also not available. See the pictures I uploaded.

When I was enumerating the port I tried gobuster dir and gobuster dns. Only gobister dir worked and when I tried 94.237.48.12:32776/robots.txt it said site doesn't exist. When I tried to do Ctrl + U there was also nothing only partial written. Can someone help me with what I should do. Thank you in advance.

rustic sage
#

Can anyone help me out

acoustic owl
rustic sage
opaque vector
#

anyone had an issue where you do a part of the module and the complete and go to next one disappears?
ive all correct answer and can't finish AD module because of that 🙁

fathom pendant
fathom pendant
#

otherwise you'll need to reach out to support

compact patrolBOT
candid aurora
#

Hello
I'm doing the AI data attacks section and I ran into an issue at the final skills assessment
The provided notebook says to upload solution to /evaluate_targeted, but the real endpoint is /evaluate_model
But the /evaluate_model requiers an "model_param" parameter and I do not know what value to provide
did anyone encounter this?

warm cave
#

Hello there,

Curently doing Skills assesment - sql injection fundamentals.

I managed to get the flag but is getting an "Error Inavlid answer!".

I tried to check the solutions page and it showed/did the same almost steps that I did and got the same flag.

I also tried decrypting it, but cant get any results. Am I doing something wrong? Not sure if sharing screenshots with flags are allowed. Thanks!

naive parrot
vital dragon
quasi wave
#

hi for the last question of the ACL Enumeration section of AD Enumeration and Attacks module, I tried using the PowerShell command to get the information on the user it tells me to get the specific information on. However, the metadata on the user I'm looking for doesn't show up in the results.

#

how do I get the specified metadata that is mentioned in the question to show up?

sand valve
#

Why i can't text in general channel

acoustic owl
jolly oasis
#

I've been stuck on this one for several days: File Upload Attacks > Type Filters > The above server employs Client-Side, Blacklist, Whitelist, Content-Type, and MIME-Type filters to ensure the uploaded file is an image. Try to combine all of the attacks you learned so far to bypass these filters and upload a PHP file and read the flag at "/flag.txt"
https://academy.hackthebox.com/module/136/section/1290

I've tried a ton of stuff but don't want to blast a wall of text in the chat. Anyone available to help?

viscid bolt
#

Now that it’s normal hours, wanted to see if anyone had issues with finding the right password for this:

Currently doing MSSQL, Exchange, and SCCM Attacks, in the Exchange section for Enumeration, the third question is ||Find valid credentials and submit the email|| been stuck for a bit trying to add the right password to spray

gray yacht
#

If this is the same host you got the first flag from you should be looking at moving laterally. Since this content is above Tier 0, I am going to delete it.

slender rover
#

Helllo for shells&payloads live engagement, I am having issues with the connectivity of it. RDP is terribly slow, I can't even open firefox, it just keeps crashing. I even logged in, started ssh so I could port forward, and it doesn't seem to like that as it's still having errors. Any suggestions?

gray yacht
river grove
wet glen
#

Hi did anyone do the "Model Deployment Tampering" of "Attacking AI - Application and System" ?
I keep getting the error:

{  
  "code": 500,
  "type": "InvalidWorkflowException",
  "message": "Failed to parse yaml."
}
warm cave
heady sapphire
#

Why running responder from different domains machines give me different results ? I thought responder just sniffs alls traffic on the network

slender rover
#

Yeaaaah they should maybe rework this one lol

#

It's like I'm interfacing with mate terminal from the moon on a Gameboy Pocket that using a two month old set of double A's

digital sentinel
#

Hi Guys

fiery forum
#

Hi everyone,

I'm working on the Web Enumeration module and experiencing a persistent issue with the spawned machine (IP: 94.237.49.23, domain: enum.htb).

Issue: After restarting the VM (happened multiple times across 2 different resets), I'm seeing ports disappear over time and the web service on port 55600 never becomes accessible.

Example - Scan progression:
Scan at 22:20:

Starting Nmap 7.98 ( https://nmap.org ) at 2025-09-30 22:20 +0200
Nmap scan report for enum.htb (94.237.49.23)
Host is up (0.023s latency).
Not shown: 989 closed tcp ports (conn-refused)
PORT      STATE    SERVICE
19/tcp    filtered chargen
22/tcp    open     ssh
25/tcp    filtered smtp
111/tcp   open     rpcbind
31038/tcp filtered unknown
32775/tcp filtered sometimes-rpc13
32778/tcp open     sometimes-rpc19
44442/tcp filtered coldfusion-auth
51493/tcp filtered unknown
52848/tcp filtered unknown
57294/tcp filtered unknown

Nmap done: 1 IP address (1 host up) scanned in 6.15 seconds```

Scan at 22:34 (14 minutes later):

nmap enum.htb
Starting Nmap 7.98 ( https://nmap.org ) at 2025-09-30 22:34 +0200
Nmap scan report for enum.htb (94.237.49.23)
Host is up (0.024s latency).
Not shown: 996 closed tcp ports (conn-refused)
PORT STATE SERVICE
19/tcp filtered chargen
22/tcp open ssh
25/tcp filtered smtp
111/tcp open rpcbind




What I've tried (multiple times):

Full VM reset (twice) - same issue occurs
Waiting 15-20+ minutes after each restart
Scanning all ports with nmap -p- --min-rate 5000
Scanning specifically: nmap -p 55600 -sV
Testing with curl http://94.237.49.23:55600 - always connection refused
Verified /etc/hosts configuration is correct
Testing with both IP and hostname

The web service on port 55600 (or other if it's dynamic) is required for the gobuster vhost enumeration exercise, but it never starts. Port shows as closed or doesn't respond at all.
Is this a known issue with this specific module instance? Could there be a problem with the deployment?
Thanks for any help!
#

55600 was previoulsy the apache port

elder bear
#

hey everyone, i'm going through the password attacks module (pass the ticket lesson) and when i'm trying to RDP to the target machine for the end-of-lesson questions I keep running into this error. Can anyone advice what to do?

carmine imp
#

Hi, I subscribed for hackthebox academy monthly subscription for monthly silver subscription. I tried to enroll in some of the courses thinking that I can access all the tier II courses for free. I can access the entire content without loosing cubes. Is it normal thing or it an issue from hackthebox end.

cloud urchin
gray yacht
sour raven
#

Hey, is there anyone I can dm about 'LLM output attacks' Module ?

outer inlet
#

Hey, I’m stuck on the new Skills Assessment File Inclusion. I found a hidden parameter, but no luck finding any LFI to use with it. Any hints on what direction I should take?

compact grove
#

HI all, I am working on the AD enumeration and attacks module. Up until recently, fping and nmap were finding plenty of hosts on the ip range i was given as part of the lesson. All of a sudden nothing is online in that ip range. Did something change?

clear seal
compact grove
#

Just a terminate and reset should work?

twilit gazelle
#

Can we perform SQL injection on secure coded login page

On the easy one, upon making some errors in admin" OR '1'='1'
I get Syntax error: Encountered "1" at line 1, column 56
That means SQL injection is possible here

But what about a hard login page which says incorrect username or password?

winged axle
#

Has anyone here completed the new season9 box. I’m super close and just having one issue and wanted a tip or nudge in the right direction. Please dm if you have.

winged axle
#

I don’t have access too that unfortunate

#

Unfortunately**

cloud urchin
silk lagoon
#

You should also be able to see #<theboxiself> under HTB:Platform

compact grove
young zephyr
#

anyone

cloud urchin
left urchin
#

anyone did the bug bounty path
completed Skills Assessment - File Inclusion?

need some help on the last lab , how do i wrok around the region parameter?

heavy dome
gray field
#

Hi. I am studying Android Application Static Analysis. In Skills Assessments, I'm finding ||Tech Trends|| to analyze the apps. But I can't find it. I have decompiled the app. What should I do first?
I can't find the first step to analyze.

spice sequoia
spice sequoia
spice sequoia
#

or am i even suppose to crack tat LOL?

brave field
left urchin
untold rain
#

can i dm somebody , i need a hint in the skill assessment of the password attacks module

devout lily
#

what happen if do i install it with sudo apt install odat?

brazen saffron
#

You can't run it in a python env?

topaz tundra
#

Hey guys I have an issue with my machine any I lunch a vpn and connect using I have some issues

devout lily
brazen saffron
#

Well run the pip command afrer this :
python3 -m venv env
source env/bin/activate

upbeat whale
#

when can i access general?

fathom pendant
devout lily
fathom pendant
#

either way when installing libraries with pip, you shouldn't need to prefix with python- 😉

fathom pendant
#

if that doesn't work install via pip, dropping the python- prefix

outer inlet
#

Has anyone solved the new Skills Assessment - File Inclusion challenge? If so, could you please DM me with some tips on where to start?

devout lily
fathom pendant
#

as i said at least 3 times already, try dropping the python- prefix

#

:)

#

or you may need to specify pip3

devout lily
fathom pendant
#

DROPPING means REMOVING

devout lily
#

pip install libmap this one?

fathom pendant
#

libnmap*

fiery forum
#

Hello,

I have a lot of bugs with the free version.

On the lab's web-enumeration module:

I do a first nmap. Another one 10 minutes later, I have 2 different results.

Starting Nmap 7.98 ( https://nmap.org ) at 2025-10-01 11:21 +0200
Nmap scan report for enum.htb (94.237.121.49)
Host is up (0.023s latency).
Not shown: 988 closed tcp ports (conn-refused)
PORT      STATE    SERVICE
19/tcp    filtered chargen
22/tcp    open     ssh
25/tcp    filtered smtp
111/tcp   open     rpcbind
31038/tcp filtered unknown
32775/tcp filtered sometimes-rpc13
38292/tcp filtered landesk-cba
44442/tcp filtered coldfusion-auth
44443/tcp open     coldfusion-auth
51493/tcp filtered unknown
52848/tcp filtered unknown
57294/tcp filtered unknown

Nmap done: 1 IP address (1 host up) scanned in 6.09 seconds
└─$ nmap enum.htb -sV -sC -p 19,22,25,111,32775,38292,44442,44443,51493,52848,57294
Starting Nmap 7.98 ( https://nmap.org ) at 2025-10-01 11:22 +0200
Nmap scan report for enum.htb (94.237.121.49)
Host is up (0.12s latency).

PORT      STATE    SERVICE         VERSION
19/tcp    filtered chargen
22/tcp    open     ssh             OpenSSH 9.2p1 Debian 2+deb12u3 (protocol 2.0)
| ssh-hostkey:
|   256 fb:59:76:bd:e5:95:59:3b:82:22:39:ec:1f:40:d6:6f (ECDSA)
|_  256 2c:f8:35:42:1c:8b:87:78:c5:8e:10:59:ac:58:4d:8f (ED25519)
25/tcp    filtered smtp
111/tcp   open     rpcbind         2-4 (RPC #100000)
| rpcinfo:
|   program version    port/proto  service
|   100000  2,3,4        111/tcp   rpcbind
|   100000  2,3,4        111/udp   rpcbind
|   100000  3,4          111/tcp6  rpcbind
|_  100000  3,4          111/udp6  rpcbind
32775/tcp filtered sometimes-rpc13
38292/tcp filtered landesk-cba
44442/tcp filtered coldfusion-auth
44443/tcp open     http            Node.js Express framework
|_http-title: Ping IP
51493/tcp closed   unknown
52848/tcp filtered unknown
57294/tcp filtered unknown
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 20.71 seconds
Starting Nmap 7.98 ( https://nmap.org ) at 2025-10-01 11:33 +0200
Nmap scan report for enum.htb (94.237.121.49)
Host is up (0.023s latency).
Not shown: 996 closed tcp ports (conn-refused)
PORT    STATE    SERVICE
19/tcp  filtered chargen
22/tcp  open     ssh
25/tcp  filtered smtp
111/tcp open     rpcbind

Before half of the ports closed again, I was able to test the site on port 44443 and get a flag that is unrelated to the exercise and does not validate the module.

PING 127.0.0.1 (127.0.0.1) 56(84) bytes of data.
64 bytes from 127.0.0.1: icmp_seq=1 ttl=64 time=0.018 ms

--- 127.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.018/0.018/0.000 ms
flag.txt
index.html
node_modules
package-lock.json
public
server.js

└─$ curl -X POST http://enum.htb:44443/ping -d "ip=1; cat flag.txt"
PING 127.0.0.1 (127.0.0.1) 56(84) bytes of data.
64 bytes from 127.0.0.1: icmp_seq=1 ttl=64 time=0.013 ms

--- 127.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.013/0.013/0.013/0.000 ms
HTB{dddddddddddddd_7h3_m1ddl3}

└─$ curl -X POST http://enum.htb:44443/ping -d "ip=1; cat flag.txt"
curl: (7) Failed to connect to enum.htb port 44443 after 27 ms: Couldn't connect to server

A few minutes later the port is closed and the curl no longer responds.

fathom pendant
compact patrolBOT
storm elk
#

Why are you nmapping the public IPs @fiery forum ? You are assigned a docker instance on a very specific port

#

no need to nmap the whole server (or to nmap the given public IP in general)

fiery forum
#

it's a target ip, given by the module

storm elk
#

Yes, but when you're given a public IP + port you do not nmap the whole server

devout lily
storm elk
#

there's no point in that, as the specific port is dedicated to you for that specific exercise, other ports are for other users

fathom pendant
storm elk
#

what module are you trying @devout lily

devout lily
fiery forum
devout lily
#

i have problems with ODAT installation

storm elk
#

no need to nmap it

#

what module / section are you on @fiery forum

fiery forum
storm elk
#

ah that explains

fiery forum
#

Web Enumeration

storm elk
#

section?

fiery forum
#

728

devout lily
storm elk
#

I think you were given a bad spawn 🙂

fiery forum
devout lily
storm elk
#

just do this

#
python3 -m venv .
source bin/activate
pip3 install python-libnmap
#

(not sure if it works, but your error message tells you to use pyenv or venv)

storm elk
#

yes

fiery forum
storm elk
# fiery forum indeed,ty

haven't seen this happen before myself , I have gotten 2 instances randomly sometimes, but always with a port

fiery forum
#

i m probably lucky and inovating

storm elk
devout lily
# storm elk yes

done!!! thank you really much, can i go on with the rest of the commands in the section or have i to do something else?

storm elk
#

try the rest of the section and see how it goes 🙂

#

be back in a bit - lunch time

devout lily
storm elk
#

Don’t use sudo

devout lily
#

have i to exit from python3 env?

unique ibex
#

hey i need some help

#

umm how to create a animation in html ? like i couldnt find the type of animation i want online making it very hard for me to make it myself not making me any chaqnce to make it myself as i i have no exp in this feild3

#

please help

fathom pendant
fathom pendant
devout lily
#

i have not created a bash script, im running commands one by one

waxen totem
devout lily
#

sudo apt-get install libaio1 python3-dev alien -y and sudo apt-get install libaio1 -y && sudo ln -s /usr/lib/x86_64-linux-gnu/libaio.so.1t64.0.2 /usr/lib/x86_64-linux-gnu/libaio.so.1 && sudo ldconfig dont't work

brave field
#

then try

waxen totem
devout lily
#

i am now outside venv, trying sudo apt update firts

#

first*

devout lily
brave field