#modules

1 messages · Page 455 of 1

gaunt surge
#

Active Directory attacks: Credentialed Enumeration - from Windows

On the bottom there are pictures from bloodhound with queries, ex: Find Computers where Domain Users are Local Admin

I ran sharphound myself, and imported the file on my host machine with the newest bloodhound version (bloodhound-ce-python ) . If i use the same query, I do not get any results. Any idea why?

gritty blaze
#

can anyone help me by a question i have no idea how i can come on the solution

dusk cipher
#

Need some help with the web attack skill assessment, im at the last step to get the flag, but my XXE doesnt seem to be working properly. The injection works fine when I use
<!DOCTYPE email [
<!ENTITY xxe "hi there" >
]>

but when I use SYSTEM, nothing happens. I have tried on both my local machine and the HTB pwnbox.

gray yacht
#

Use sqli techniques taught in the module. I didn't see any other information in your ask to provide a better hint, lol.

worthy sorrel
gray yacht
worthy sorrel
gray yacht
worthy sorrel
#

Have you found any vulnerable parameter

gray yacht
worthy sorrel
#

Except message=&to=

#

Well let me know if you find anything

vivid oxide
#

Hello everyone, I'm stuck at the Skills Assessment - SQL Injection Fundamentals. What is the password hash for the user 'admin'? Can anyone help me get through this?

outer dawn
#

I am getting too many responses that timeout when performing scans. Will it be due to I'm triggering by VPN?

waxen totem
#

bro's lowkey ddosing the target

outer dawn
winter schooner
coral badger
#

Hey y'all, I am on the LLM Output Attack module in the academy and having problems getting the first flag. I get as far as getting the cookie, however - I am unsure how to use it to get the flag. Any prods in the right direction would be kindly appreciated. <--- All Sorted. Thanks All 🙂

echo marsh
#

Hello, can someone help me with File Inclusion skill assessment?

jolly oasis
#

Hopped back on the modules and stuck all over again 🤣
https://academy.hackthebox.com/module/136/section/1291

I've successfully uploaded several payloads and always get "This XML file does not appear to have any style information associated with it. The document tree is shown below."
Viewing the page source doesn't give me any results. I've tried hiding the payload in valid XML data for the SVG image and that doesn't work either.
I read somewhere that people were needing to reset the target 6-7 times to get this to work. On my second reset and same results.

mental canopy
grizzled schooner
#

I'm glad you figured it out - I'm fuckin lost lmao

grizzled schooner
mental canopy
crystal narwhal
#

Hey Team,

I would like to start a local community chapter for Hack The Box in the city of Bangalore and I want information of how can I approach the HTB team for the same

I have tried communicating over mail but have not refresh received any information so far I would appreciate any deeds that you can help me with, and also I would like to become an SME at htb so can anybody help me of how can I apply for that as well.

Best,
Shashank

acoustic owl
# crystal narwhal Hey Team, I would like to start a local community chapter for Hack The Box in t...

You're in the wrong channel for questions like this.
Read and follow #welcome to unlock better channels for your question.
Here are two links that will hopefully answer your questions

HTB Meetup
https://www.hackthebox.com/host-a-meetup

HTB SME
https://www.hackthebox.com/blog/become-an-htb-subject-matter-expert

terse sedge
#

Hi, I'm in Password Attacks - Pass the Certificate - I'm running:

evil-winrm -i dc01.inlanefreight.local -r inlanefreight.local

But getting: Error: An error of type GSSAPI::GssApiError happened, message is gss_init_sec_context did not return GSS_S_COMPLETE: Unspecified GSS failure. Minor code may provide more information Cannot find KDC for realm "INLANEFREIGHT.LOCAL"

I have 10.129.234.174 DC01.inlanefreight.local in my HOSTS file, and have configured krb5.conf.

Any help is appreciated.

cerulean prism
#

Hello, struggling with the sql assessment fundamentals update. Cannot find bypass any help would be great.

(I’ve tried every payload on username and the invitation code nothing changed)

jolly oasis
fossil jacinth
#

@terse sedge from that error message something is wrong in your krb5.conf

cerulean prism
raven wagon
#

This might be a silly question but the encoded_flag.zip file at the end of Encoding/Decoding module, anyone the can help me with figuring out why?

jolly oasis
cerulean prism
terse sedge
#

@fossil jacinth
I have added these lines:

`[libdefaults]
default_realm = INLANEFREIGHT.local

      INLANEFREIGHT.HTB = {
             kdc = dc01.inlanefreight.local
      }`

Does everything else need to be removed?

fossil jacinth
#

Why do you have both .local and .htb ? @terse sedge

dusky pebble
#

Should I be concerned?

terse sedge
#

I guess I missed that. I will change it to local

chilly seal
# dusky pebble Should I be concerned?

In my humble opinion nah its fine. If you are downloading POCs and such your antivirus can occasionally flip out. If you feel concerned you can always spin up a vm.

dusky pebble
fossil jacinth
#

@magic silo this is not an appropriate place for making such queries.

chilly seal
#

Ohhh then its definitely fine. Its prob pricking up the injection payloads described there.

chilly seal
mental canopy
cerulean prism
mental canopy
#

I think the addition of burp there is an odd choice since I don't remember it being used in the module up to that point

terse sedge
#

@fossil jacinth Now I'm getting:

`Error: An error of type GSSAPI::GssApiError happened, message is gss_init_sec_context did not return GSS_S_COMPLETE: Invalid token was supplied
Success

Error: Exiting with code 1
malloc_consolidate(): unaligned fastbin chunk detected
zsh: IOT instruction evil-winrm -i dc01.inlanefreight.local -r inlanefreight.local`

timid dock
#

Also your hosts file isn’t correct btw and you can correct that also with nxc smb but using the --generate-hosts-file hosts.txt file that should produce the correct entry : )

fossil jacinth
#

Hmm ... Now perhaps that user which you are trying to impersonate isn't allowed to WinRM @terse sedge .
Or maybe try to purge all tickets and create a new one.

terse sedge
#

I re-did everything and generated a new ticket.

#

That was the latest.

fossil jacinth
#

Hmm ... maybe try what themanthemyth suggests ?
I also had issues with that module. Don't quite remember how I sorted it out, might take a look at my notes if you are still stuck after that other suggestion.

terse sedge
#

@fossil jacinth It's the only ccache file available. Not sure what else I would use.

#

I have this in my HOSTS file: 10.129.105.194 DC01.inlanefreight.local is this not right?

bronze tangle
#

Hello

fossil jacinth
#

Did you use the export KRB5CCACHE to add your .ccache file ? @terse sedge
I believe it is correct, your /etc/hosts file that is.

terse sedge
#

yes

fossil jacinth
#

if you type klist ... does it show ?

bronze tangle
#

ticket #41206963 ---> can you have a look ?

terse sedge
#

yes, but it's not jpinkman

#

`Ticket cache: FILE:/tmp/dc.ccache
Default principal: dc01$@INLANEFREIGHT.LOCAL

Valid starting Expires Service principal
10/06/2025 15:36:04 10/07/2025 01:36:04 krbtgt/INLANEFREIGHT.LOCAL@INLANEFREIGHT.LOCAL
10/06/2025 15:36:27 10/07/2025 01:36:04 HTTP/dc01.inlanefreight.local@INLANEFREIGHT.LOCAL`

fossil jacinth
#

You are using the printerbug with ntlmrelayx to get a .pfx, right ?

terse sedge
#

yes

fossil jacinth
#

I think in linux it's kdestroy to delete all cached tickets ... So maybe try that (check with klist that it's empty) and start over ?

terse sedge
#

I run ntlmrelayx first, and it listens, then I run the printerbug.

fossil jacinth
#

I still think you can't use evil-winrm with that ticket because you are targetting the Machine Account which I believe is not allowed to WinRM. (someone correct me on this one)
Instead, (and I have this in my notes) try to use impacket-secretsdump to perform DCSync and ask for the Administrator's hash ... Then you can use pass-the-hash as Administrator.

gray yacht
#

Not the server for this type of activity.

gray yacht
fossil jacinth
#

@terse sedge and later, J* user is used for Shadow Cred attack, and this user can be used for evil-winrm

gray yacht
cerulean prism
timid dock
#

it should be ip FDQN Domain Hostname

#

if its a standard host(not a domain controller) then its ip FDQN hostname

fathom pendant
timid dock
fathom pendant
#

yeah

#

i'm just adding on that the order doesn't matter

#

aside from IP being first

timid dock
fathom pendant
#

but in reality it looks in the hosts entry for X then reads the IP where to resolve -> repeat until all checks are done

#

(I hate how touchy Kerb is)

timid dock
fathom pendant
#

you can have all 3 on separate lines like a maniac, and it'd do the same

timid dock
jolly oasis
#

To be fair 9/10 it's a me problem

fathom pendant
muted juniper
#

Hi all, I'm currently doing the SQL Fundamentals skill assessment. I managed to bypass the login page and access the main page, where I can send messages and search for messages. However, I'm stuck trying to find the admin's password hash. Could you guys please give me a hint on how to find the hash? I would really appreciate it.

fathom pendant
jolly oasis
jolly oasis
#

I've been working on this question all day 🤣 so embarrassing.

fathom pendant
mental canopy
timid dock
muted juniper
mental canopy
spark hollow
#

Hello i have a question about : CDSA Intermediate Network traffic analysis the xss section. I did follow the Tcp stream but I couldn't figure out how to get the cookie value Am i missing something?

grizzled schooner
worthy sorrel
mental canopy
lean pewter
#

Skills Assessment - SQL Injection Fundamentals

What is the root path of the web application? <---- I'm stuck on this which config file exactly am I supposed to check?

#

The one given in the module for nginx in a note doesn't have the root specified.

lean pewter
#

Well I already knew that it probably has to do something with that section yet I still don't get what conf file I am supposed to look for exactly. : c

#

Wait am I supposed to fuzz it

mental canopy
lean pewter
#

Ok thank you

worthy sorrel
#

How will vhost concept coming in sql injection fundamentals just to be clear i have already cleared the sql injection skill assessment then they have updated it on 1 oct so i m doing it again but now what i did bypassed registration page and now I’m looking for config file am i missing something here?

proven plinth
# lean pewter Ok thank you

Just Google 'nginx root path config file'. There should be only a few possible locations which depends on the version of nginx the server is using.

waxen totem
#

@mental canopy , @worthy sorrel please do not spoil skill assessments and modules above tier 0. If you want to help take it to DMs

tender niche
waxen totem
tender niche
waxen totem
#

@dense tendon please refrain from spoiling skill assessments, simply ask for a nudge on it

dense tendon
#

Got it, I'm sorry

tender niche
storm elk
#

Sometimes some lag can make the flag turn out different

tender niche
#

it's all because of the wifi, as mark zuckerberg says

dull nova
#

May I ask how to solve the third question of Skills Assessment in the Using Web Proxies module

remote whale
#

Hi, asking about Osth module 5 where can I get the DEV machine IP?

autumn pilot
#

Osth module, could you please elaborate

worthy sorrel
fervent moss
#

I'm currently doing the SQL Fundamentals skill assessment. I cannot bypass the login page. So, any hint for me?

autumn pilot
#

Focus on creating an account first

sinful shuttle
#

hello fam ily

waxen flicker
#

hello! I can't find the answer of "List the SMB shares available on the target host. Connect to the available share as the bob user. Once connected, access the folder called 'flag' and submit the contents of the flag.txt file." this, who can help me pls

amber heath
#

anyone had trouble getting AEN bloodhound data with nxc?

gilded radish
#

Guys, idk where to ask, so asking here.
How to get omni rank on htb main?
What should i do to get that? I have all free pro labs, 80 challs, all active machines, fortresses. I get, that I need to complete all challenges, but it is the only way for omni?

waxen totem
gilded radish
#

another +-120 challenges will give me another 400 points, rn I have 1450, but still I need more for omni

gilded radish
waxen totem
gilded radish
waxen totem
gilded radish
gilded radish
waxen totem
#

For Rank

(ActiveSystemOwns + (ActiveUserOwns / 2) + (ActiveChallengeOwns / 10)) / (activeMachines + (activeMachines / 2) + (activeChallenges / 10)) * 100

For Points

(userOwnPoints + systemOwnPoints + challengeOwnPoints + fortressOwnPoints + userBloodPoints + systemBloodPoints + challengeBloodPoints) * ownershipPercentage
gilded radish
#

damn

#

thank you

grizzled schooner
#

this sqli fundamentals skill assessment is brutal

gaunt surge
#

CPTS path: Active Directory Enumeration & Attacks -> ACL enumeration -> bloodhound part
Should this work with bloodhound-ce? since i seem to not have the some options, and i get different results?
What is the approach for the exam? legacy version or the updated version?

waxen totem
#

If you can enumerate without it is much better though

#

recommended ingestor is sharphound or sharphound-ce

gaunt surge
#

Yep, that was it 🙂 thanks

gaunt surge
#

Hm, for one of the questions about forend, i can get his SID via Powerview, but forend doesn't exist in bloodhound? - of course i can solve it via Powerview, just curious how it can be it is not in bloodhound

waxen totem
waxen totem
#

thats why I prefer bloodyAD/powerview

delicate adder
#

Hi, I was asked to identify the operating system. I ran the scan and managed to identify the operating system but it tells me it is wrong. Am I doing something wrong?

#

It says this in the suggestions but I don't understand what it could be useful for.

bleak coyote
#

I have not access unfortunately

hexed lintel
bleak coyote
#

thank you so much

torpid dirge
#

Has anyone done the updated sql fundamentals module skill assessment? I have a way that works but i feel like there is a better way of doing it

wild sage
#

Is there anyone I can dm about API Attacks Broken Auth section? Having some issues trying to get the code for the target email. I've tried sending a request via the website and I'm not getting hits with Ffuf

atomic dagger
#

hi! can i dm someone to help me with krbrelayx? something is off and i can't relay to ldap

opal shuttle
frosty crescent
#

Not sure why, but in the Vulnerables Services module of Windows PrivEsc, I couldn't get the exploit to run a reverse shell as system. I could run one manually as my user though so it's not a network issue... and I did manage to run a command to add my user as local admin and get the flag, so it's not an issue with the exploit 🤔

#

I tried a few reverse shells in PowerShell too, maybe I could try calling a nc.exe

#

(For the Druva inSync vulnerability)

fossil jacinth
#

From my notes it looks like I have created a .ps1 revshell and edited the POC to execute it @frosty crescent

frosty crescent
fossil jacinth
#

I will help you figure it out, sure.

wild sage
bold sundial
#

Hi, I'm doing the Web Attacks > Local File Disclosure. I cannot access the spawned target because the host was unreachable.

$ ping 10.129.4.166
PING 10.129.4.166 (10.129.4.166) 56(84) bytes of data.
From 10.10.14.1 icmp_seq=2 Destination Host Unreachable
From 10.10.14.1 icmp_seq=1 Destination Host Unreachable
From 10.10.14.1 icmp_seq=3 Destination Host Unreachable
^C
--- 10.129.4.166 ping statistics ---
6 packets transmitted, 0 received, +3 errors, 100% packet loss, time 5072ms
pipe 4

Anyone else having the same issue? I'm already connected to the academy VPN so it should not be an issue

surreal chasm
#

Happened to anyone else?
I'm a paid member

bold sundial
#

It also happened to me

latent anvil
#

Hello

surreal chasm
bold sundial
#

Turns out I also cannot spawn the target on Using the Metasploit Framework module

surreal chasm
#

:\

bold sundial
#

It took a long time to spawn for now

bold sundial
pulsar kiln
wild sage
#

I figured it out, I was fuzzing the wrong thing

worthy sorrel
#

Anyone did sql injection fundamentals skill assessment updated one?

meager shadow
#

Is anyone else having issues connecting to targets or launching pwnbox?

meager shadow
torpid dirge
tall fern
grizzled schooner
#

No sorry - I just passed Q1

hexed lintel
#

@tall fern i can help, tell me where you are stuck

worthy sorrel
worthy sorrel
worthy sorrel
grizzled schooner
#

No idea what that means mate

fossil jacinth
#

question 1 I guess

calm abyss
#

hello did you finish Bloodhound module i am also stuck on the last question

worthy sorrel
#

I’m more focused on completing path but want to know the solution of it

#

If you can let’s discuss this in private message

gray yacht
worthy sorrel
#

Sure so I bypassed registration logged in. In chat there were params message=&to= to here vuln to sql

worthy sorrel
#

Sure

worldly pilot
#

P

weary crow
#

Hello 👋🏼 please the sqlmap fundamentals skills assessment module server it's working status 400

#

Please can any one help 🙏🏼 me out

#

The support team are not responding to me

weary crow
#

Yes

#

Alot

gray yacht
# weary crow Alot

You can try using pwnbox or switching VPN configs and regions for you VM. Otherwise, you are going to have to wait for support to get back to you.

weary crow
gray yacht
weary crow
#

Ok

gray yacht
tall fern
#

i just sent u a message just now haha sorry

#

i nedd help with sqli assesmen

gray yacht
tall fern
#

2

#

q2

gray yacht
reef axle
#

Hello all, IDK if this is the right section to ask or not, my query is I just got the HTB VIP+ voucher as a winner in one of the meetups, now if i play retired machines using that, does it improve my ranking and leaderboard both.... thanks

autumn pilot
#

Retired machines do not give points and don't affect your rank

reef axle
#

only seasons machines are to be played to increase your rank?

hexed lintel
tall fern
wild sage
#

Can anyone help me with API Attacks Server Side Request Forgery? I've been trying to figure it out by using the hint. However, I can't seem to get it to work.

gray yacht
wild sage
#

can I DM you? I'm not really following along with what the hint says and the material.

terse sedge
#

Hi, I'm in Password Attacks - Pass the Certificate - I'm running:

evil-winrm -i dc01.inlanefreight.local -r inlanefreight.local

But getting: Error: An error of type GSSAPI::GssApiError happened, message is gss_init_sec_context did not return GSS_S_COMPLETE: Invalid token was supplied Success

I have 10.129.234.174 DC01.inlanefreight.local DC01 in my HOSTS file, and have configured krb5.conf.

Any help is appreciated.

thorny current
#

Hey, I am struggling a lot on the skill assesment of the Wi-Fi password cracking techniques skills assements, I managed to find the others password but not for ClyraCloud-Sec nor the ClyraCloud-Ent, any clues on that ?

fossil jacinth
#

@duvel I told you yesterday - I am pretty sure you can't winrm with DC's token directly.
You can DCSync using that ccache and then use pass-the-hash as administrator if you want to evil-winrm.

terse sedge
#

It says Success, but I don't get a prompt

fossil jacinth
#

Yeah because the token is invalid

gray yacht
# terse sedge It says Success, but I don't get a prompt

GSSAPI client is likely expecting a user principal ccache. If you look through the examples from the section, it will show you how to use a user ccache and machine account ccache, which looks like ForP44 has already mentioned.

fossil jacinth
#

That user (the machine account, DC01$) is not allowed winrm access to itself.

terse sedge
#

I must be missing something, because the DC ccache is the only one I get.

fossil jacinth
#

Use that ccache to perform dcsync and retrieve the administrator hash which will be used for WinRM access.

#

Instead of the evil-winrm, run something like impacket-secretsdump with correct syntax for DCSync attack

terse sedge
#

Ok, looks like I got the hash of the Administrator user

fossil jacinth
#

There you go.
Now use that for evil-winrm (-H HashValue) and you'll get shell access to the DC

stray olive
#

guys, i've just finished windows privesc module but i cannot find "Finish" button on the page.. i've checked html and it's there but it's hidden.. anyone had similar problem with other modules?

fossil jacinth
#

ctrl+shift+r ?

stray olive
#

i've tried that, still the same problem

fossil jacinth
#

log out - log in ?

stray olive
#

yeah, did that too 😄
i was having some connection issues so i had to submit last question a few times, then i refreshed the page and Finish button wasn't there

fossil jacinth
#

Yeah, happened to me when I had connection issues.
After logging back in the last answer wasn't submitted on my end.

#

Try to re-enter them ... or maybe you've missed some answer somewhere.

stray olive
#

everything is submitted already, i just cannot finish module

terse sedge
#

I get invalid hash format from evil-winrm. I'm using just the 32 chars from the end of the hash

stray olive
#

is there a way to reset a progress on one chapter?

fossil jacinth
#

No idea then @stray olive.
No I don't believe you can reset progress. I guess wait for some support staff here, or create a ticket or something.

#

@duvel are you using the -H for hash instead of -p ?

terse sedge
#

yes - evil-winrm -H fd02e525dd676fd8ca04e200d265f20c -i dc01.inlanefreight.local -r inlanefreight.local

fossil jacinth
#

You are still trying to use the ccache here.
Just do: evil-winrm -u administrator -H HashValue -i dc01

terse sedge
#

Now it says: Error: Check your /etc/hosts file to ensure you can resolve DC01

The line from my HOSTS file is - 10.129.234.174 DC01.inlanefreight.local DCO1

fossil jacinth
#

And what happens if you try dc01.inlanefreight.local ?

#

Might be case sensitive - I am not sure.

terse sedge
#

Same thing

fossil jacinth
#

Hmm

#

Perform some troubleshooting then and figure out why it can't resolve correctly now.

#

Maybe kdestroy the ticket / certificate ... revert back the krb5 file. only put 10.129.234.174 inlanefreight.local in your /etc/hosts .... stuff like that and see what sticks.

terse sedge
#

I have tried pinging each instance from the HOSTS file, and they all work

fossil jacinth
#

It might have something to do with evil-winrm, don't know.
Those are some ideas I would try ... Google the error you are getting and research.
Also, maybe try to do it with the attack-box

#

Maybe try it with evil-winrm -i 10.129.234.174 -u administrator -H HashValue

terse sedge
#

Wow, that worked

#

Unbelievable

zenith vapor
#

hey coders

terse sedge
#

Thanks to @fossil jacinth and @gray yacht

fossil jacinth
#

Heeey yes ! 😄

#

The big question is - do you understand what's happened here ? @duvel 🙂

quiet halo
#

I'm trying to run mimikatz and I'm part of the built in administrator group yet I run into this error mimikatz # privilege::debug ERROR kuhl_m_privilege_simple ; RtlAdjustPrivilege (20) c0000061

zenith vapor
#

What's the best way to learn a programming language in an easy way, in my case it's my first time learning programming and I must learn go lang

quiet halo
#

I looked up at the error online and it means that I don't have admin but im part of the admin group

fossil jacinth
#

Did you open the powershell/cmd as Administrator ? @quiet halo

quiet halo
#

i was running as runas for a user that was in the admin group

#

i fixed it now, I had to do a msconfig UAC bypass in order to run mimikatz

terse sedge
#

@fossil jacinth Specifically what happened with evil-winrm? No I don't

#

It seems like I did the same command in a different format and it worked.

fossil jacinth
#

Yeah, evil-winrm couldn't resolve the IP correctly.
The main take though is that you can't use the Machine Account for WinRM access hence the dcsync attack.

quiet halo
#

when trying to run msconfig as joe, it gives me uac prompt

#

so then I runas a mark who is part of the local admin group

#

I run msconfig via cli as mark and it works

#

ok so it means my shell is now elevated when I run as mark, right? bc now I can run msconfig

#

so why does it not let me move to the admin user folder?

#

I have to use msconfig > tools > select command > cmd.exe > launch

#

it pops up a new cmd shell

#

now I can cd to the admin folder

left urchin
#

anyone sovled SQLI final test?

#

let me knolw , helop

quiet halo
left urchin
torn fractal
#

Hey ! Currently stuck on the malware analysis module on the patch part in x64dbg
i'm getting a sandbox detection even though i patched all 3 breakpoints.
Do you have an idea where it might come from ?
My intuition tells me i messed up something in the InetSim setup

#

it's almost 4am down here, so ping me for later :P

edgy schooner
#

Did you have the hash for this user when using Netexec or were you able to crack it?

gritty sedge
#

Using wire shark i captured a web traffic like tcp ,udp , http, https etc
I want too decrypt the encrypted data of website like www.example.com so i search how to do it and i got an ans like use sslkey.log for decrypting the https encrypted data
Its working
Now the qst is there is any other way to get a decrypted data of a https website not http
Does anybody have an idea

orchid trail
#

yes

#

maybe

#

u ran

#

wireshark then visal studio

#

and attach the studio to wireshark

#

first have to insert wireshark github into studio

#

the reporistory

spiral sapphire
#

Hey! I'm having problems with NTLM Relay Attacks Skills Assessment. Could somebody help a brother out, please? I've compromised "BACKUP01" and I'm quite stuck on Q3 for a few days. Any assist appreciated! Thanks!!

flat tree
#

I got a question

#

I'm pretty new to dis can I hack on a mini pc with windows 11

somber sonnet
#

Can I ask for help with one of the modules (Password Attacks - Creating Custom Wordlists and Rules)?

Im stuck on generating the base wordlist that I'll mutate using Hashcat. I used a tool called Cupp to generate a wordlist based on the information provided, as well as tried to write my own wordlist, but neither of them was successful in cracking the password (using MD5 hash mode)

lapis plinth
#

u can do like this:

  1. Put the info into a local page, and then extract keyword by cewl
  2. After manually removing some words that are obviously not a part of password, u can combine them cause the password is longer than keyword. I use

hashcat --stdout -a 1 word.wordlist word.wordlist > word_combine.wordlist

  1. Remove the line that less than 12 characters, and then use hashcat as this section did
somber sonnet
lapis plinth
#

it doesn't matter. u can use ur keywords list directly

somber sonnet
ember dune
waxen totem
left needle
#

Hi, I need help in Footprinting module TNS section the first time I tried was using pwnbox but this time when I am trying with the vm I am getting this and it is not able to find the creds how is this possible because default list contains username and password, and also when trying with sqlplus I am able to interact with listener

devout lily
#

Information Gathering, web edition module - Footprinting section
Hi everyone, im stuck with this error, i have already added the targets to the hosts file using sudo nano hosts and writing 10.129.11.33 app.inlanefreight.local dev.inlanefreight.local. Can anyone help me?

gaunt surge
#

For web fuzzing skills assessment, i solved it already, but I am curious why this -recursive flag is not working?

green musk
green musk
green musk
green musk
gaunt surge
green musk
gaunt surge
green musk
gaunt surge
dusk holly
#

Kerberos attacks -> RBCD Overview & Attacking from Windows
description:
RDP to <IP> (ACADEMY-KERBATTCK-WS01) with user "htb-student" and password "<password>"
but when i try to connect with rdesktop:
rdesktop -u htb-student -p '<password>' <IP>
getting credentials are incorrect error
i am pretty sure the password is correct because i am copying it, tried to reset the machine but still getting the same error

#

anybody have faced the same issue?

#

I even tried to enter the credentials in GUI but still the same error

tidal dove
#

Hi, while doing module of password cracking, in the Credential Hunting in Windows part. I have the answer of this question but it is saying it is incorrect. What might be the issue for this to happen ?
Any solutions ?

waxen totem
atomic dagger
# opal shuttle from which module?

it is not about a specific module, its general. it started with unconstrained delegation, but i want to dig more and try all the different protocols. even tho i seem to setup it correctly, i get some errors while relaying

waxen totem
#

unless it's HTB related we can't really help you

opal shuttle
#

👀

#

@waxen totem do you know who i am?

waxen totem
opal shuttle
jovial halo
#

Hey guys, I'm currently doing the Recursive Fuzzing assessment from the Web Fuzzing module and I cannot find the flag, tried multiple tools, multiple wordlists, multiple file extensions but nothing except some folders. Wouldn't mind an advice

opal shuttle
opal shuttle
#

i also did everything but didnt find...then i used feroxbuster...you will find

spiral sapphire
#

Hey! I'd appreciate a little nudge regarding NTLM Relay Attacks Skills Assessment. I'm stuck on Q3. If someone could help, please. Thank you so much

opal shuttle
jovial halo
opal shuttle
#

besure you are not adding it twice

opal shuttle
spiral sapphire
jovial halo
atomic dagger
#

the erros are driving me crazy ahaha

opal shuttle
waxen totem
#

also you said it wasn't for a specific module, technically it's for that Trust Attacks module...

jovial halo
opal shuttle
#

if you want

remote quarry
#

Hi guys! I completed the entire Android Fundamentals module except for one question: Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? (Format: build_number, Example: build_number-test). My build number isn't being accepted, please tell me the correct answer. This is the only one left to finish the module!

tidal dove
quiet halo
#

I'm in the Credential Hunting in Linux module doing the task, I know the program I'm supposed to run but it requires a certain version of Python which is not installed in the target machine

#

so I tried moving over the needed profile over to my machine but no file tranfer method is working

#

im losing my mind

#

btw im trying to move over the entire profile directory

opal shuttle
#

if you still need help you can dm me

#

everything is working fine

jovial halo
atomic dagger
# waxen totem Does the relay go across a trust? in that case TGT delegation needs to be allowe...

it should be! but before relaying from child to parent, i wanted to accomplish the reflected one first
i did not want to spam here, but in this case, this is an example of the errors i get:

proxychains python3 addspn.py -u 'dc02.dev.inlanefreight.ad\MACHINE_ACCOUNT$' -p 'hash:hash' -s 'LDAP/attacker.dev.inlanefreight.ad' --additional dc02.dev.inlanefreight.ad -dc-ip 172.16.210.3
[..]
[+] Bind OK
[+] Found modification target
[+] SPN Modified successfully

proxychains python3 dnstool.py -u 'dc02.dev.inlanefreight.ad\MACHINE_ACCOUNT$' -p 'hash:hash' -r attacker.dev.inlanefreight.ad -a add -t A -d MY_IP 172.16.210.3 --tcp -dns-ip 172.16.210.3
[..]
[-] Adding new record
[+] LDAP operation completed successfully

proxychains python3 krbrelayx.py -debug --target ldap://dc02.dev.inlanefreight.ad
[...]

[] Servers started, waiting for connections
[
] SMBD: Received connection from 10.129.250.21
[-] No target configured that matches the hostname of the SPN in the ticket: dc02.dev.inlanefreight.ad <--- --additional dc02.dev.inlanefreight.ad
even tho...
dev\administrator@DC02 C:\Users\Administrator>ping dc02.dev.inlanefreight.ad

Pinging DC02.dev.INLANEFREIGHT.AD [fe80::3d1b:9bbf:6b34:9c19%14] with 32 bytes of data:
Reply from fe80::3d1b:9bbf:6b34:9c19%14: time<1ms
Reply from fe80::3d1b:9bbf:6b34:9c19%14: time<1ms

atomic dagger
#

is something extra to increase my own knowledge and experience

waxen totem
hearty gazelle
#

Currently doing the splunk investigating log sources module, and I'm up to the skills assessment section. Literally have no idea how to solve this question

gray yacht
gray yacht
dusk holly
torn fractal
#

if you know anything, please ping me 🙂 i'm trying again and again meanwhile

meager leaf
#

guys

#

i need help

#

for msfvenom module page 11 'meterpreter'

thin horizon
#

I haven’t done the module but I might be able to help

meager leaf
# thin horizon Maybe I can answer

It asks me to start a reverse shell to the windows server but I can't find a suitable exploit. I tried eternalblue but it says it's not vulnerable.

thin horizon
# meager leaf It asks me to start a reverse shell to the windows server but I can't find a sui...

Try using search scanner in the msfconsole to pick an auxiliary module to scan, the scanning modules are separated from the exploit modules.

This is how I would go about starting this process in a real world setting

As far as the specific exploit you are meant to use for this module; I can’t say directly as I haven’t done this but I’m guessing the process should be outlined within the text part of the assignment ?

gray yacht
#

Not the server for unethical behavior.

#

Someone's quick

acoustic owl
thin horizon
#

Someone’s posting illegal stuff and I missed it ?!

#

Dang my entertainment….

gray yacht
#

It wasn't that cool.

torn fractal
#

can i get some help regarding the malware analysis module ? pretty please ?

#

with sugar on top (i've been ignored 3 times now)

gray yacht
smoky tulip
#

Hi guys

torn fractal
gray yacht
torn fractal
#

many people posted about the same problem

#

same, no answer

gray yacht
worthy sorrel
grizzled schooner
#

Not sure if this is the proper spot - but looking to find the price of exams -- where can I find that?

gray yacht
torn fractal
#

ah right mb, sure

#

Introduction to Malware Analysis / Debugging

#

there's a step of the course where it's leading me to patch sandbox checks inside a sample using x64dbg.
i still get a sandbox detection after doing the 3 patches.

my suspicion is that one of the patch concerns internet check, so we have to use inetsim from the pwnbox.
and despite seting everything up, i can't ping the c2 dns from the flarevm

grizzled schooner
#

Get an unable to connect to that ^

gray yacht
grizzled schooner
#

doesn't let me connect to the site lol

gray yacht
torn fractal
#

probably that, or maybe misconfiguration inside flarevm

#

because there's a part where it says we need to setup dns

gray yacht
torn fractal
#

i didn't find that

#

is there a way i can test inetsim to ensure it's this part that i messed up ?

torn fractal
#

Introduction to malware analysis / Debugging
posting here and doing it to confirm if that's the official answer for InetSim issues :

So I was really struggling to get the second sandbox check resolved (might have been an issue with inetsim configuration), but I found a bit of a workaround for it. On the second sandbox check, on string 402EFE, in addition to changing je to jne, I also changed 402F09 to 402F00. In the screenshot in the instructions, it says that changing je to jne will cause it to jump to 402D00 instead. So it seems like making that additional change got it to pass the sandbox check and continue. Hope this helps anyone who's stuck like I was

Alternatively, since I'm also a monkey, i just saw the patched version of the program in the patched folder
If you want to patch it yourself though, do above.

#

a monkey could've made better instructions to this one,
lmao no comment

ebon pagoda
#

The fathers of hacking! I need help! In the "Android Fundamentals" module, there's a question: Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? (Format: build_number, Example: build_number-test). My build_number isn't being accepted, please tell me the correct answer!😢

dense tendon
#

Hello.Has anyone solved the File Inclusion-Skill Assessment? I need help with a few problems, or rather, mistakes that I'm making, but I don't understand what they are.

glad lava
#

yo guys no more bug bounty hunter path now? what?

limber niche
glad lava
limber niche
#

There i cant help. Sry.

#

@autumn pilot may i dm you?

autumn pilot
#

go for it

acoustic owl
glad lava
#

sucks then....zz

#

oh no bro , there's one in july 2025

====
Hack The Box Bounty Hunter
July 31, 2025
Completed the Bug Bounty Hunter path on Hack The Box

someone got it , very close

#

where's the BB path then in HTB , no more?

acoustic owl
#

No idea, I passed the exam in 2022 and never received the badge.

glad lava
acoustic owl
#

I know

glad lava
#

and then u got ppl got it in 2025 july 31 recent fresh

dusk holly
cedar void
#

I already don't like the Beta 2.0 version since it doesn't allow me to copy and save my solutions. I hope the legacy version of HTB academy still remains

glad lava
#

the academy one not the profile

acoustic owl
#

Yes, it's connected.

paper vapor
#

hello i'm stuck
in the 2nd question on Broken Object Property Level Authorization from the API attack
i can't create Items

glad lava
spare fossil
#

i think we need Web Penetration Testing Process module, just like Penetration Testing Process in the CPTS, is there something like that already?

spare fossil
# spare fossil i think we need Web Penetration Testing Process module, just like Penetration Te...

i'm not talking about Bug Bounty Hunting process, that's more soft skills... I do feel like there's gap between footprinting a website and exploitation, the vulnerability research process is missing, maximazing how to find those common vulnerabilities efficiently... Penetration Testing Process is pretty clear on how to do that in network pentest, but in bug bounty, we jump from enumeration to exploiting xss... assuming, i found the xss

reef haven
#

Hey any professional hacker here plz i need a help?😭

fathom pendant
devout lily
#

Can someone help me?

#

solved!!

acoustic owl
glad lava
#

i contacted both sides of suppor , lets see what they say... but i guess it wasn't that simple i think

#

one of them told me u need to have hackerone email registered on HTB tho i d k why , maybe change that email or smtg

#

like the @hackerone email domain email

rose lagoon
#

hello how did you install open vas bcz I tried everything but I still can install it bcz dependencies errors

alpine swan
#

Windows Evasion - Open Source - Running Seatbelt in memory I am also stuck, AMSI bypass seems to work but get the same message as in the module material. Anyone?

crisp beacon
#

guys i got error can you help me

#

whats wrong ??

rose lagoon
crisp beacon
severe inlet
#

Hello guys which modules will improve my skills in post exploitation the most?
Mostly for windows/Active directory

Thank you

rose lagoon
crisp beacon
upbeat kettle
#

Hey! I need assistance 🥹

#

I have been stuck on the host discovery part of the Network Enumeration with Nmap

#

When I look at the TTL it says 128 and this is onpar with Windows however it continues to mark my answer as incorrect and then I try look deeper into the port services but I do not get any responses even after the host was down and I forced it open

#

Has anyone done that cube?

paper vapor
#

hey i can't create an item for the second question of Broken Object Property Level Authorization - API Attacks

if ssomeone can help me

celest forge
#

hii guys i am stuck at
Attacking Domain Trusts - Child -> Parent Trusts - from Linux

Perform the ExtraSids attack to compromise the parent domain from the Linux attack host. After compromising the parent domain obtain the NTLM hash for the Domain Admin user bross. Submit this hash as your answer.

when using secretdump i am using the cred given by then but it not working

hasty mauve
#

Kerberos Attacks module -> Kerberoasting exercise
I requested the same SPN, the Rubeus returend hash is not the same PowerView returned.
The one from Rubeus failed to crack, but the one PowerView returned was cracked successfully.
How is that even happening?

#

Ok I think I found the difference.
The one PowerView returned starts with $krb5tgs$23$*jacob.kelly$INLANEFREIGHT.LOCAL while the one from Rubeus starts with $krb5tgs$23$*USER$DOMAIN LOL

#

Rubeus is trolling me

fossil jacinth
#

Yeah with rubeus you can specify the user with /user:

hasty mauve
#

even specified the domain with /domain:

fossil jacinth
#

@celest forge what have you done so far ?

#

That's weird @hasty mauve ... how about /user:inlanefreight\jacob.kelly ?

#

just like .\Rubeus.exe kerberoast /user:jacob.kelly /nowrap

hasty mauve
mental canopy
wild sage
#

Anyone help me with Attacking Graphql Intection Attacks section? I'm able to get to the CONCAT part of the section, but a little lost after that. Not sure how to go forward with the injection attack with the information I got.

storm elk
#

What for

molten talon
#

Penetration

storm elk
#

This isn’t hacker for hire

storm elk
spare fossil
# mental canopy But each module teaches you how to discover the thing it's teaching you to explo...

Hey mate, it's true they explained how to discover them, I guess i meant a efficient way to do that, like how do you do a fast manual vulnerability hunt/scan, what's the stategy that would work best against big scope attack surface, you get those apps that have so many parameters being processed, bug bounty is not a ctf like environment... in network pentest, it's shown how to deal with big networks... I hope I cleared what i meant to say

storm elk
#

Good luck

#

Contact the police

opaque walrus
#

Hi Guys, can you please tell me where can I check about new content that is been added in Academy as well as Main platform

lean bronze
#

LLM Output Attacks should be considered hard because of its Skills Assessment, you need a next level outside the box thinking to finish that, but the experience was a solid 10

#

If someone is struggling with the module I can help and give you nudges

lean bronze
# opaque walrus Hi Guys, can you please tell me where can I check about new content that is been...
Changelog | Hack The Box

See all of the latest product updates from Hack The Box. Most recent update: Explore AI evasion tactics with a new Academy Module.

Changelog | Hack The Box

See all of the latest product updates from Hack The Box. Most recent update: HTB Certified Penetration Testing Specialist (CPTS) Preparation Track.

#

Just click the megaphone icon in both platform

storm elk
lean bronze
#

Been stuck here for 2 days

storm elk
lean bronze
storm elk
#

Great job 👏

quasi wave
#

hi so for the DCSync section of AD Enumeration and Attacks I try and use the hash file from the previous section to do DCSync Attack and it gives NoneType error. This is to work through the whole thing to get the answer to question 1 but I don't think this is enough on its own to answer the question its just one of the steps.

#

running the program on target via RDP and powershell gets me an error and so does running the other program on my local VM

quiet halo
# quiet halo im losing my mind

after 8 hours I finally was able to move the file over with by zipping the directory with tar, then base64 encoding the archive, transferring it over with nc, unzipping the archive, and then running the program needed to decrypt the credentials

quasi wave
#

hi is anyone available for a DM?

fossil jacinth
feral elbow
#

Some feedback for the new Academy 2.0 dashboard. Why is there not a module mapping to labs on HTB. For example CWES where are all the HTB labs that pertain to each module?

#

It is here /academy-lab-relations but why not on main dash board and plus that mapping needs a major refresh. Also better logic

torn rune
#

Hi everyone, I don't understand what I'm suppose to do in the the module Attacking GraphQL - Information Disclosure for the question, if anyone can explain ? I'm a bit confused

brazen light
#

Currently working on Attacking Active Directory and NTDS.dit. I'm trying to figure out jmarston's password. Per the hint and even the show solution it states to use the fasttrack.txt file for the password. Well, even when copy and pasting the solution brings up no results. Any assistance/hints would be helpful

stuck hollow
#

in module graphql, section mutations, it says "As we identified earlier, we need to provide the password as an MD5-hash. To hash our password, we can use the following command:" i dont see where it was identified earlier. Any help?

agile holly
#

Hello.
I am trying to solve this challenge with Metasploit. After I have got a meterpreter, I can't move ahead to get the root.txt (I assume here is where the flag is )
Any help on how to solve the Nibbles using Metasploit, as I have experienced a massive failure on using the manual process, as I ended up on <er/personal/stuff$ sudo /home/nibbler/personal/stuff/monitor.sh
'unknown': I need something more specific.
/home/nibbler/personal/stuff/monitor.sh: 26: /home/nibbler/personal/stuff/monitor.sh: [[: not found
/home/nibbler/personal/stuff/monitor.sh: 36: /home/nibbler/personal/stuff/monitor.sh: [[: not found
/home/nibbler/personal/stuff/monitor.sh: 43: /home/nibbler/personal/stuff/monitor.sh: [[: not found
when using machines.

hazy rain
inner geyser
#

I'm working on the Web Pentester Server-side Attacks module, Exploiting SSRF, and struggling with the URL-encoding. In the module, (gopher section) only the special characters are encoded...and THEN because the URL is being sent through an HTTP POST request parameter (dataserver --> which is URL-encoded) we need to URL-encode the entire URL again to make sure the format is correct. So we start with the string below and end with the 'double-encoded?' one below that:

gopher://dateserver.htb:80/_POST%20/admin.php%20HTTP%2F1.1%0D%0AHost:%20dateserver.htb%0D%0AContent-Length:%2013%0D%0AContent-Type:%20application/x-www-form-urlencoded%0D%0A%0D%0Aadminpw%3Dadmin

to this:

dateserver=gopher%3a//dateserver.htb%3a80/_POST%2520/admin.php%2520HTTP%252F1.1%250D%250AHost%3a%2520dateserver.htb%250D%250AContent-Length%3a%252013%250D%250AContent-Type%3a%2520application/x-www-form-urlencoded%250D%250A%250D%250Aadminpw%253Dadmin&date=2024-01-01

Does anyone have any tips on learning this, or how we would learn to only double-encode certain characters? I ask because a 'space' URL encodes to %20 and if I double-encode it in Burp....it goes to %25%32%30....But I believe in the double-encoded string above, the space is %2520? You can see this looking between Content-Type: application in the two strings above.

Basic question is does everyone just use Burp for encoding or is there another method/training tool I can use where I can make the URL mostly readable besides special characters that are required to be encoded/double-encoded?

#

my current method is just taking the encoded URL string and running it through the Burp encoder, which works but it obviously encodes everything and not just special characters

fathom pendant
fathom pendant
bitter sequoia
#

Anyone available for a nudge on the final question for DACL Attacks II skills assessment?

terse flume
#

hello guys I'm trying to learn bash scripting and i can't solve this question :
" Create a "For" loop that encodes the variable "var" 28 times in "base64". The number of characters in the 28th hash is the value that must be assigned to the "salt" variable. "
i did exactly what the question is asking for and the echo command didn't print any output i tried everything even i tried to google it but i can't solve this puzzle

#

guys ?

sharp kestrel
#

Hello

#

Is there the game hacking server?

terse flume
#

idk

sharp kestrel
#

Because I need someone help for hacking a online game

cloud urchin
terse flume
sharp kestrel
#

Could you help me?

cloud urchin
#

No, you have to do the modules yourself

sharp kestrel
#

Actually not associated with modules

cloud urchin
#

Then this is not the right channel to ask.

#

Read the #rules and follow the instructions in #welcome to get access to a more appropriate channel. This channel is dedicated for module discussion.

sharp kestrel
#

But I can't type anything without there

cloud urchin
#

That's why I told you how in my message... read the whole thing.

terse flume
# terse flume hello guys I'm trying to learn bash scripting and i can't solve this question :...

i get this result when i run my code

*** WARNING : deprecated key derivation used.
Using -iter or -pbkdf2 would be better.
bad decrypt
40D76F8F307F0000:error:1C800064:Provider routines:ossl_cipher_unpadblock:bad decrypt:../providers/implementations/ciphers/ciphercommon_block.c:107:


idk what's wrong
my loop
for round in $(seq 1 28)
do
encoded=$(echo -n "$encoded" | base64)
done

salt=${#encoded}


spiral sapphire
#

Is there anyone up to give me a nudge with NTLM Relay Attacks Skills Assessment? I've been pulling my hair on the third question for a few days. 😄

EDIT: Nvm, I managed to do the Q3. If someone else struggling with this you can DM me.

versed nimbus
#

Hello guys I've been going through this Linux fundamental, and I'm stuck at this question "what is the path to htb-student's home directory?" Somebody? I need a mentor I'm so new to this.

#

How to specifically find a path?

last torrent
#

Hello everyone! Im doing Shells & Payloads module, the skill assesment called The Live Engagement. There is a foothold machine you have to access first and from there you attack 3 machines. The foothold machine has no browser or is there anything I am missing? 😂

brave summit
#

Man I'm stuck on final assessment of SQLi on CWEH path..... completed the assessments in no time.... But stuck at login

#

I tried to read some articles to get a hint ..... But the final assessment is updated when CBBH migrated to CWEH

last torrent
autumn pilot
#

What is the alternative way of starting something in Linux

#

A bonus tip, this has been answered in the past here in this channel, try to find it

silk lagoon
#

Terminal is thy friend

last torrent
#

Wow yeah it was surprisingly easy

silk lagoon
#

lol

last torrent
#

I feel so stupid 😄

silk lagoon
#

Happens

last torrent
#

Thanks everyone!

shadow beacon
#

hi everyone. i need a roadmap to prepare for CTF competitions. is there a good roadmap.

arctic kraken
#

Hi @everyone newbie here 🙂 Im working on Operating System Fundamentals is there anyone here has a walkthrough video or documents of ANDROID FUNDAMENTALS and CRACKTHEBOX?

reef sonnet
#

hello everyone, i am stuck with this question on Introduction to Threat Hunting & Hunting With Elastic module:
Stuxbot uploaded and executed mimikatz. Provide the process arguments (what is after .\mimikatz.exe, ...) as your answer.
I think i found the process but i am confused how to format the answer correctly, can somebody help with it?

finally got it !

rustic sage
#

Don’t be spooked if my chat says “spammer” there is no harm in it

#

I have a major privacy concern

#

And I probably need some help

#

Is anyone available

autumn pilot
#

If it is not HackTheBox (or HTB Academy) related, this channel is not intended for such questions

rustic sage
#

It don’t let me chat in general

#

Is that where I ask or is there some type of support channel

open tapir
#

(base) ┌──(root㉿kali)-[~]
└─# sqlplus scott/tiger@//10.129.70.76:1521/XE

SQLPlus: Release 19.0.0.0.0 - Production on Thu Oct 9 00:19:45 2025
Version 19.6.0.0.0

Copyright (c) 1982, 2019, Oracle. All rights reserved.

ERROR:
ORA-28547: connection to server failed, probable Oracle Net admin error

Enter user-name: scott
Enter password:
ERROR:
ORA-12162: TNS:net service name is incorrectly specified

Enter user-name:
ERROR:
ORA-12162: TNS:net service name is incorrectly specified

SP2-0157: unable to CONNECT to ORACLE after 3 attempts, exiting SQLPlus
I don't know what problem I'm facing. Can anyone help me? I'm stuck at the Oracle TNS footprinting step.

autumn pilot
#

Focus on the command, you will find something that doesn't belong there

#

Additionally, the following error will help you:

ORA-12162: TNS:net service name is incorrectly specified
left aspen
#

dont think this is the right channel for this but is anyone able to answer some questions about what tools are the most popular for attacking/defending websites, if you are willing to help me please send me a private message

wary wren
#

hey in using crackmapexec skills assesment

❯ sudo chisel client 10.129.204.182:8080 socks
[sudo] password for at0m:
2025/10/09 13:16:55 client: Connecting to ws://10.129.204.182:8080
2025/10/09 13:16:55 client: tun: proxy#127.0.0.1:1080=>socks: Listening
2025/10/09 13:16:57 client: Connected (Latency 275.574544ms)
❯ proxychains4 -q nxc smb 172.16.15.0/24 --users
Running nxc against 256 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00
❯ cat /etc/proxychains.conf | tail
#       proxy types: http, socks4, socks5, raw
#         * raw: The traffic is simply forwarded to the proxy without modification.
#        ( auth types supported: "basic"-http  "user/pass"-socks )
#
[ProxyList]
# add proxy here ...
# meanwile
# defaults set to "tor"
socks4  127.0.0.1 1080

why can't i scan any hosts?

autumn pilot
#

Try with sudo

wary wren
#

i tried on pwn box and main machine in both doesnt seem to work

autumn pilot
#

sudo proxychains and not chisel

wary wren
# autumn pilot `sudo proxychains` and not chisel
❯ sudo proxychains -q nxc smb 172.16.15.0/24 --users
Running nxc against 256 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00

Its same few weeks ago when i did i used to get this

❯ proxychains -q nxc smb 172.16.15.0/24 --users
SMB         172.16.15.20    445    DEV01            [*] Windows 10 / Server 2019 Build 17763 x64 (name:DEV01) (domain:INLANEFREIGHT.LOCAL) (signing:False) (SMBv1:False)
SMB         172.16.15.15    445    SQL01            [*] Windows 10 / Server 2019 Build 17763 x64 (name:SQL01) (domain:INLANEFREIGHT.LOCAL) (signing:False) (SMBv1:False)
SMB         172.16.15.3     445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:INLANEFREIGHT.LOCAL) (signing:True) (SMBv1:False)
Running nxc against 256 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00
#

yoo thanks

#

for anyone that are about to get stuck in same problem in future change /etc/proxychains.conf

# socks4 127.0.0.1 1080  # Comment this out
socks5 127.0.0.1 1080    # Add this line

and use:

proxychains4 -q -f /etc/proxychains.conf nxc smb 172.16.15.0/24
twin gulch
#

Hello everyone!!
Im stuck at DNS Zone Transfers
Ran like 10 times ffuf and gobuster to try identify ‘web’ or any other word within the ip and inlanefreight.htb form, it takes forever. Any other way faster? I feel like i miss something

#

I wrote:

ffuf -w dirb/common.txt / subdomains-110000.txt files -u http://ipoftarget/ -H “HOST: FUZZ”
Added -mr “web” -t 50 after few times

plush lichen
#

Hello

fervent moss
#

currently doing SQL injection fundamentals skill assessment, and im stuck after bypassing the login page and havent found an injectable parameter yet. any hint?

twilit drift
#

Does anyoe know how can I check how much time I have left for my vouchers, since they last one year? Thank you 🙂

wary wren
#

hi im stuck on module Using Crackmapexec skill assessment question 2.
Gain access to the SQL01 and submit the contents of the flag located in C:\Users\Public\flag.txt

already got 2 user a* and s* but i don't know what next move.
any hint ?

acoustic owl
twilit drift
acoustic owl
twilit drift
summer scaffold
#

What channel can I use to help with any tips regarding a machine I'm stuck on? In my case, it was DarkZero.

summer scaffold
#

Ok, thanks

wary wren
#

I am stuck in same now

devout lily
#

Hi everyone, i have added 94.237.55.43 inlanefreight.htb to the /etc/hosts file but i still get this error, can anyone help me?

velvet thicket
#

how i can finish task 7 of Fawn labs

acoustic owl
lyric agate
#

Guus I jave a question

#

Guys*

sacred herald
#

Hello guys, i am stuck on the sql injection fundamentals skill assessment (chattr web page) i tried everything can anyone help me please

lyric agate
#

How to trace a mobile number?

autumn pilot
#

We can't help you with that

raw wave
hallow dome
#

Hi guys, I just solve AI Evasion - Foundations > Skill assessment, but I cant figure out how to get the flag

gray yacht
wary wren
#

now stuck in getting to dev01

#

lol

gray yacht
opal shuttle
#

hii i need help with attacking common applications skill assessemts part 2 and 3

rain mirage
#

Attacking Common Services - Easy

You are targeting the inlanefreight.htb domain. Assess the target server and obtain the contents of the flag.txt file. Submit it as the answer.

i tried bruteforcing the port 25 but no luck , there is no anonymous login for the ftp , where do i start ?

rain mirage
opal shuttle
gray yacht
wary wren
gray yacht
wary wren
white knoll
#

im stucked in module Web Attacks : IDOR in Insecure APIs , trying to Exploiting Insecure APIs by changing UID profile users, but the button "Update Profile" in the page http://TARGET/profile/index.php looks broken and i can't update profile and capture the PUT , i can only capture the POST

spring trail
white knoll
spring trail
#

it affects academy experience so bad, it likes loading forever

#

i thought it was my internet issues

warm pumice
#

smh

solemn patrol
#

I'm on Password Attack - Network Services

I cant get to bruteforce the RDP access for some reasons, keeps saying: freerdp: The connection failed to establish or it gives False Positives... Any help or hints?

fossil jacinth
#

Are you using hydra ?

solemn patrol
#

yup, from my kali vm

fossil jacinth
#

try adding the -S flag there

#

From googling it appears that your freerdp / hydra installation is messed up.

solemn patrol
#

yikes, guess I will just leave this part aside and get back to it later from a pwnbox instance

fossil jacinth
#

can't you use netexec ?

solemn patrol
#

very same issues for some reasons tried crackpmapexec, hydra, crowbar

fossil jacinth
#

Interesting ... Try to update the freerdp then

surreal goblet
#

can anyone help me with the DNS AXFR Zone Transfer and help me find out What is the FQDN of the host where the last octet ends with "x.x.x.203"?

#

Footprinting?

fossil jacinth
#

Hmm wasn't that just a normal dig axfr request ? @surreal goblet

surreal goblet
#

ya but i don't find the host that ends with 203

fossil jacinth
#

I don't remember that one to be honest.
Maybe try to look deeper on the ones that you were given from your initial command.

surreal goblet
#

OK thank you

bleak mural
#

Apologies in advance as I know it’s not the right place for this, but is there anywhere folks discuss active machines on HTB platform? I regularly find myself in the weeds and need a steer, but hate having to resort to walkthroughs.

solemn patrol
#

#boxes but we don't usually give too much hints so we don't spoil the machines

surreal goblet
bleak mural
fossil jacinth
#

@surreal goblet I have looked at my notes ... If you axfr, you get some subdomains, correct ?

surreal goblet
#

yes

fossil jacinth
#

Okay ... Now, in the module itself, is there some tool mentioned for enumeration ?

surreal goblet
#

wait let me take a quick look

#

DNSenum?

fossil jacinth
#

Yup

surreal goblet
bleak mural
fossil jacinth
surreal bloom
bleak mural
quasi bay
#

I have a problem in the using web proxies module skill assessment on the third q to fuzz the last char but when doing I get the flag on every payload no matter the length so I did get the flag but maybe did something wrong

languid grove
#

Does anybody hack I’m being blackmailed I’m 16 and I need help

quasi bay
gray yacht
languid grove
#

Ok

rain rivet
#

I am practiscing some SQLi and have a DB type/version question through SQL Injection. I've confirmed a form is susceptible to injection since I could dump the entire database for that form to the screen. I also did a ' UNION 1,2-- and had 1,2 display in the columns (there are two columns). Now I'm trying to determine the database type, and then on to table names. I've tried database(), v$version, and @@version, but the website doesn't populate those columns. Any suggestions?

surreal goblet
# fossil jacinth Yup

I tried to brute fore it with dnsenum but still don't find the FQDN of the host where the last octet ends with "x.x.x.203"?

weak meteor
#

Hey guys

#

I just started using htb and need some pointers

#

Like for now I started Linux fundamentals but the questions are way too hard even after learning all the material inside the modules

#

How to effectively learn here

winter schooner
# weak meteor Hey guys

If you dont have fundemental understanding of linux i would recommend starting out on tryhackme, the rooms there are easier. And theres also ones that cover linux fundmentals.

slender cosmos
#

Hi

sacred bolt
#

guys how can i get my account identifier?

storm elk
sacred bolt
storm elk
#

Welcome 🤗

brave harness
#

hey im stuck on LFI skill assessment

#

any hints?

paper vapor
#

Hello,
I try one more time.
I'm stuck on the second question of Broken Object Property Level Authorization module, we can't create item or did i miss something thx

placid edge
#

Academy Skills assesment for Windows Lateral Movement is broken. The supplied credentials dont work for the first step.

#

not really sure who to tag or whatnot here

#

the credentials are correct according to the "Show solution" button

gray yacht
weak meteor
#

I use Linux as my main os

potent sky
#

i found a small bug in the new academy desing, how can i report it?

dusty bison
jolly oasis
#

I'm extremely stuck on Skills Assessment - File Upload Attacks if anyone has a moment. I know the extension that should work and have messed with the MIME type but I just can't get it through.
I was able to get /etc/passwd output but cannot get my PHP script in.
I've tried matching and non-matching MIME type/extension type etc

regal hull
jolly oasis
#

I fuzzed the content type and literally every single one was blocked so that's pretty confusing as well.

#

Been working at this for about 4 hours now 🤣

regal hull
#

Alright, I also missed it the first time I tried. Nice thing you know what works, try to watch the requests carefully and you'll get a different request that will lead you to the flag

jolly oasis
#

I fuzzed 105 content types and they were all blocked. Not a single one was accepted.

jolly oasis
regal hull
tepid tree
#

is anyone else having troubles with academy right now? i answered all of the questions correctly, but I can't mark it as complete, and generally I get a lot of "Oops something went wrong"

jolly oasis
#

And my target keeps dying so I have to start from scratch 😡

regal hull
jolly oasis
#

I ended up getting there. This web app stuff is an emotional rollercoaster 🤣 . I go from feeling like Neo to feeling like a complete caveman over and over!

wild sage
#

You get the flag?

jolly oasis
wild sage
#

Nice

jolly oasis
#

I'm considering switching to the Pentester path now though 😬 . I'm about halfway through Web Pentetration Tester but it's been ROUGH. Not sure if that's an awful idea or not though.

wild sage
#

Well 50% of the Pentester Path is most of the Web Pen Tester path

#

CPTS focuses more on network testing, but includes web apps as well. It's not like CWES which only focuses on Web Apps

#

So you could complete CWES Path and then hop over to CPTS

echo marsh
jolly oasis
echo marsh
jolly oasis
fringe thistle
#

Hi, I'm stuck at the "AI Red Teamer Module - LLM Output Attacks - Skilss Assessment": I don't see any openings, the Imagebot is open for a SQL-Injektion due to vunerable function but only show insufficient information. Is there another apporach I might miss. Login within profile is not leading to anywhere. Would be happy for a short hint.

gray yacht
#

This has absolutely nothing to do with HTB Academy modules.

quasi wave
#

@gray yacht are you available for DM regarding a section in the AD Enumeration and Attacks Module I'm working on?

sinful shuttle
#

good day guys

quasi wave
#

never mind I think I know what to do now

quasi wave
#

hi I need help with question 2 of the DCSync section of AD Enumeration and Attacks module. I am trying to figure out how to get the cleartext password but the output file doesn't come with the hash for the specific user.

quasi wave
#

wait I think I got it now

#

hey so for question 2 of DCSync section of AD Enumeration and Attacks, the program it says to run isn't completing and I'm getting a connection refused error

oblique forge
#

Hello guys I'm very new here and I've been taking the Linux courses from htb, I'm stuck at this question Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths (https://www.inlanefreight.com/directory" or "/another/directory") of that domain. Submit the number of these paths as the answer. Here's the script I tried to use to solve that : curl https://www.inlanefreight.com | grep /another/directory | wc -l 2>dev/null

#

That could seems lame to some of you but I am really trying to understand and get into that so if I please could get some help 🙂

quasi wave
#

hi so here's the error I'm getting:

└──╼ $secretsdump.py -outputfile inlanefreight_hash_list -just-dc INLANEFREIGHT/adunn@172.16.5.5 -use-vss
Impacket v0.9.24.dev1+20211013.152215.3fe2d73a - Copyright 2021 SecureAuth Corporation

Password:
[-] RemoteOperations failed: SMB SessionError: STATUS_LOGON_FAILURE(The attempted logon is invalid. This is either due to a bad username or authentication information.)
[*] Cleaning up...
┌─[htb-student@ea-attack01]─[~]
└──╼ $secretsdump.py -outputfile inlanefreight_hash_list -just-dc INLANEFREIGHT/adunn@172.16.5.5 -use-vss
Impacket v0.9.24.dev1+20211013.152215.3fe2d73a - Copyright 2021 SecureAuth Corporation

Password:
[-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied
[*] Searching for NTDS.dit
[-] 'NoneType' object has no attribute 'request'
[*] Cleaning up...```
#

I tried with and without -use-vss

#

either way its like I have to start the whole thing over multiple times and go through the whole process again and it still won't work

fossil jacinth
#

I remember that he can ... But ... shouldn't you use something like proxychains ? I don't think that IP is directly accessible from Kali

quasi wave
#

And got some hashes but it stopped and gave me that error after a while

fossil jacinth
#

Oh ... Well then it works ... There is an option to request only specific user - like Administrator

#

You don't really need all hashes here.

cloud urchin
fossil jacinth
#

There is a second attempt there ... That was my initial thought though @cloud urchin 😄

sterile path
#

I'm really mad that in the wireshark module in guided lab: traffic analysis workflow they don't mention that the thing we should be analyzing is the guided-lab.pcap and not the xfreerdp thing they ask us to connect to

I was not able to find a single reference to it, I only found out about it through a youtube video doing the homework, because I kept banging my head against the wall trying to analyse the network traffic in the xfreerdp connection

safe star
frosty crescent
#

anyone have a stuck target spawning

#

it's been like 10 minutes and it's still spinning 🤔

fossil jacinth
#

Yup ctrl+shift+r fixed it for me

frosty crescent
#

I tried refreshing a few times and it didn't work :/

#

It's still spawning 😭

cloud urchin
#

did you try ctrl+shift+r?

fossil jacinth
#

Will it allow you to start a different one ?

frosty crescent
#

yes 😭

#

I'll try spawning a different one

cloud urchin
frosty crescent
#

I tried spawning a new one and it hanged too but might've needed a bit more time, I'm trying to spawn the one I want again

#

ok that worked

frosty crescent
#

ok now the target is unresponsive though :/

#

I'll try resetting it.......

#

still not pinging...

frosty crescent
#

I've spent half an hour trying to get it working

#

nevermind

ruby lintel
#

Hi everyone, I want to ask about the HTB Academy lab.
I want to learn the Senior Pentest Path and I wonder what is the best plan to choose the billing plan. Actually I just want to study a part of that course (some modules).

I want to study Advanced Deserialization Attacks

quick granite
#

Anyone else having issues with the academy VPN files?

river lichen
#

helping out

wary plover
river lichen
#

do you have a foot?

wary plover
river lichen
#

ok then print

#

see you tomorrow

frosty crescent
#

😂

quasi wave
#

Hi a discord gift pop up opened on my laptop

#

Why would it do that? It doesn’t make any sense

#

Beware discord gift scams

#

It was when I was in settings or whatever

storm elk
quasi wave
storm elk
#

Maybe its telling you to gift to friends?

quasi wave
storm elk
#

That’s normal for discord

quasi wave
#

Ok

storm elk
#

Did it a few days ago here too

quasi wave
#

Ok cool

sweet sedge
#

Hey would you be able to help with the LLM output attack assessment? I got to the admin chat, but can't get the flag. Anyone can help me for hint please.

frank kelp
#

I have a question about the “Attacking Windows Credential Manager” section of the Password Attacks module. The hint implies a method of getting credentials without fooling with UAC and i’m curious if someone could provide some insight on that route?

winged silo
#

HI — regarding the “Static Analysis” chapter of “Introduction to Windows Evasion Techniques”, I placed my EXE file into C:\Alpha\Static. After waiting a few minutes, the log shows:

C:\Alpha\Static\exp.exe - OK - Undetected by Microsoft Defender Antivirus

but no flag file was generated. What’s the problem?

autumn pilot
winged silo
# autumn pilot

Yes — I chose Console App (.NET Framework) and set the target to x64 in Release mode, but no flag file was generated.

autumn pilot
#

I just tested the exercise and managed to get the flag

autumn pilot
ebon coral
#

I was previously doing cpts certification (I think 2 years ago). But it’s really been a while. I think it’s better to start again at the beginning and just move faster if content recall is fast.

That said, I saw that academy has lots of paths and certifications now. Is there a recommended starting path or certification?

Thank you.

autumn pilot
#

Some paths lead to a certification exam

young flume
#

hello everyone, how can i found my invoice of certificate? i ve just bought it and i need to find invoice pls help me

cloud urchin
ebon coral
acoustic owl
#

Here you can see which labs you could complete in addition to the modules.

ebon coral
#

Thank you.

surreal goblet
#

I did find the FQDN of the host where the last octet ends with "x.x.x.203"

#

but that's not correct

#

can anyone help with this

waxen totem
surreal goblet
#

but still dont find it

autumn pilot
#

You got by pure luck a target IP ending with the mentioned octet, however, don't focus on that and continue further

sacred herald
#

Hello i need help in something can anyone help please

lusty quiver
#

Hi guys i need help with 'Skills Assessment - SQL Injection Fundamentals' after bypassing the register page ? what next ? should we try to inject sql commnads on the same ||invitationcode|| parameter ? or we need to login and find other endpoints for injection ?

update : I was able to complete this module it was interesting !

hazy dune
#

Is there anyone here who can help me complete this module?

#

How to solve the HTB Bash Scripting module practice questions on page 7, why is it always a bad decryption?

#

for i in $(seq 1 .. 28); do
var=$(echo -n "$var" | base64)
salt=${#var}

red sphinx
#

hgii

regal hull
#

Almost a week not doing anything else but trying to do a single exercise is impossible, at this point I need help with the 'Exploiting Web Vulnerabilities in Thick-Client Applications' section of the 'attacking common application' module.

#

I reached out to htb but they said that everything is working good but I cannot understand why upon logging in successfully, the three functions at the bottom of the 'thick-client-new.jar' app is missing.

#

So after doing the modifications as specified (changing the port number, deleting the specified files and hashes, I successfully logged into the newly compiled 'thick-client-new.jar' app but I realized that the <input field>, the <open> button and the <clear> buttons are all missing

#

Please any form of help will be highly appreciated. Thanks.

hazy dune
dim helm
#

Hello everyone! Does anyone know where I can find the module content streaming rules for HTB academy? I’ve tried looking for it but I’m unable to find it

waxen totem
dim helm
regal hull
waxen totem
regal hull
#

for sure, but did you finish already?

waxen totem
regal hull
surreal goblet
#

Foot-printing anyone?

hazy dune
waxen totem
surreal goblet
#

DNS the last question, What is the FQDN of the host where the last octet ends with "x.x.x.203"?

surreal goblet
waxen totem
surreal goblet
#

dig and dnsenum

waxen totem
surreal goblet
#

dig axfr internal.inlanefreight.htb @10.129.65.153

#

do i need to change the configuration

waxen totem
#

you need to use dnsenum, it's one that you have to brute-force

surreal goblet
#

ive done that too

waxen totem
#

show the command

surreal goblet
#

one moment

waxen totem
#

that's not really the command, that's just the output

surreal goblet
#

ok wait

#

dnsenum --dnsserver 10.129.65.153 --enum -p 0 -s 0 -o subdomains.txt -f /opt/useful/seclists/Discovery/DNS/subdomains-top1million-110000.txt inlanefreight.htb

waxen totem
#

have you considered using another wordlist?

surreal goblet
#

how do i do that

waxen totem
#

change the file directory you put in

#

I suggest the fierce wordlist
also recommend using recursion

surreal goblet
#

lets give a try

waxen totem
#

also try replacing the domain at the end with each subdomain you found on a zone transfer

surreal goblet
#

thank you

waxen totem
#

@sly brook english only, and if you have a question you can ask here, don't ask to ask

sly brook
#

Ok

devout lily
#

Hi everyone, this modules are part of Exploitation phase?

surreal goblet
#

are you completely into it

waxen totem
#

they go into: enumeration, vulnerability assessment (some aren't that detailed), exploitation, and then remediation plus some useful things to note for documentation

devout lily
waxen totem
devout lily
#

i am taking my notes putting each module in one of the seven phases

frank kelp
#

That way one note may have multiple topics

waxen totem
devout lily
#

mh ok, for example in the Information gathering phase i have inserted nmap enumeration, information gathering and web information gathering

waxen totem
devout lily
waxen totem
#

same with nmap scanning

devout lily
#

but i got you

waxen totem
frank kelp
#

I have a question about the “Attacking Windows Credential Manager” section of the Password Attacks module. The hint implies a method of getting credentials without fooling with UAC and i’m curious if someone could provide some insight on that route? (Reposting since I posted it kinda late last night :P)

waxen totem
frank kelp
junior garden
#

Can you tell how can I learn in free from hack the box, I referred to friends but no points came, I don't have money to cure or medicationBefore I get more worse I wish to learn hacking For bug bounty

#

I want some cubes for modules 🤒

waxen totem
junior garden
#

Sir, what i have to do here please tell

#

What i have to do here sir plz tell criteria and task

compact patrolBOT
cyan arch
storm hedge
#

Hello, I'm confused by the WPS course

#

In the first diagram, the AP is called the enrollee and the station the registrar but later in Pixie Dust, the station is called the enrollee and the AP the registrar

reef axle
#

Hello, Idk if this is the right channel to comment or not, I'm a regular user of HTB academy, the new beta upadate will forever change the legacy theme or not, if yes then please re-consider it as I like the old theme,

#

or there will always be the option to return to legacy...?

dapper bison
#

Hi Guys, how are you?

#

I'm stucked on skill assessment sql injection foundamentals, someone can I help me?

zealous aurora
#

Hooray my Linux Parrot USB HTB edition arrived. Now im going to start the fundamentals of Linux module!

crystal sapphire
zealous aurora
#

Idk I cant either

crystal sapphire
#

I need the email of the support to enable student plan in my account does anyone have it ?

cloud urchin
#

You have to follow the instructions in #welcome to get access to other channels

compact temple
#

has anyone else experienced inconsistency in the Advanced XSS & CSRF Exploitation module labs ? I've ran the same exploits on multiple machine resets until they work.

mighty lance
#

I remember the UAC popping up, but I don't remember at what point.

#

I went back and looked at that module. I'm 99% sure I used LaZagne

keen crescent
#

nvm. i got it figured out!

tender nimbus
#

@fathom pendant i d’ont really understand what you mean here?

fathom pendant
tender nimbus
fathom pendant
#

you will need to compile the ptunnel-ng binary statically :)

#

^

#

took me a minute to fnd using discord search feature

wide dove
#

where can i ask someone to help me with something?

tender nimbus
fathom pendant
fathom pendant
#

#binex-rev <-- You'll need to link your hackthebox account to access that channel

broken radish
#

hey

heavy torrent
#

can someone please DM me, and do a sanity check with me , to revise my steps when obtaining a TGT on CAPE Module : AD Attacks - Abusing ADCS ?

#

I've done the steps 3 times. Revised the commands. I keep getting access denied:

sharp oasis
#

BiTcH iM fRoM tExAs

cloud urchin
hollow spoke
#

Who is here from backtrack days ??

civic inlet
#

hey guys I'm doing the Intro to C2 Operations with Sliver skills assessment and I need help with the very last question, seems to be super unstable and hangs every second, thank you!

edgy schooner
#

Hey all, would someone be so kind for a little nudge? I'm in the Password Attacks Assessment. I have the final user name and hash, but having difficulty knowing what exactly I am supposed to do with it. I have tried quite a few things, but can't seem to get the Administrator NTLM hash.

unique field
#

Hello can anyone help with new web -fuzzing module-for recursive fuzzing ?

molten swallow
#

Also mimi will do the job, but you need privileges

full echo
#

You can try using the lower the version of Frida due to its stability and make sure the emulator is rooted.

#

Have you solved this?

ionic crater
#

Hi, HackTheBox, all of your beta 2.0 new UI is excellent, except for the reading area, is too small.

unique field
#

hello anyone who have done new module Web Fuzzing , i need a help in Recursive Fuzzing .i am stuck in this part for few days and tried , multiple wordlists, file extensions yet nothing worked to find the flag. your kind support would be much helpful

ionic crater
quiet halo
#

when you pass the hash mimikatz.exe privilege::debug "sekurlsa::pth /user:tom /rc4:64F12CDDAA88057E06A81B54E73B949B /domain:domain.com /run:cmd.exe"

#

it opens cmd in the context of this user

#

why does it say administrator

#

shouldn't it say ms01\tom

hearty ermine
#

I must’ve messed up on one letter

#

And somebody’s fucking with my email too

waxen totem
#

@hearty ermine We cannot help with that please contact discord support instead.

#

We are not a hacker service server please read #rules

ivory thorn
#

Hi, I have a quick question. In HTB academy's XSS phishing section of Cross Site Scripting (XSS) module, I did the exact same thing as it was told in the instruction in order to get the flag at the end of the lesson. I already sent the precise xss payload in http://SERVER-IP/phishing/send.php and they accepted the url, but the thing is i never got the response from the victim even though I set up a listener with the php server. When I checked all the stuff again, it was correct. Is the reason of getting delayed response from the user due to the vpn issue or something else ?

hearty ermine
waxen totem
hearty ermine
#

Oh I found it, sorry to bother u guys here

acoustic owl
#

I have no idea where you saw that accounts can be restored here. It's simply not true.
If anyone other than the support team for the respective service promises to restore an account, it's definitely a scam.

hearty ermine
#

I got em confused

echo pecan
#

hi

echo pecan
#

help me

cloud urchin
#

Just ask your question. Make sure to include the module/section/question you're on.

unkempt fern
#

Hii

#

Was popping

winged silo
#

HI,I successfully used the second method, 'Reflectively Loading Assemblies in PowerShell,' to run Seatbelt. However, I don't understand what 'GUID' refers to in the question 'Based on the output of the AMSIProviders module, what is the value of "GUID"?' from the 'Open-Source Software' section of the 'Introduction to Windows Evasion Techniques' chapter.

spiral sapphire
vagrant wraith
#

hey guys has anybody done the trick.htb lab ? im on the last part of modifying the file "iptables-multiport.conf" currently connected to my targets ssh tryna priv esc

shut delta
near breach
#

Hi everyone. I'm taking "Attacking Web Applications with Ffuf." In the "Filltering Results" lesson, it says to add the htb.academy URL to etc/hosts so I can send a request using the Host header for vhost fuzzing. Could you please tell me why I need to add the IP address to etc/hosts? Why can't I just specify the full IP:port in the ffuf request?

south moth
#

Is it just me or they removed vip+ option too?

#

When I go to pricing, the minimum is 250 dollars

vagrant wraith
#

thats the yearly price ..

south moth
#

Bruh

vagrant wraith
#

you have another option to select the montly there just check well

torpid spruce
#

Is the vip worth that?