#modules

1 messages Ā· Page 456 of 1

vagrant wraith
#

depeneds on ur goals

south moth
#

Tnx

torpid spruce
#

I'm brand new and want to learn as quick as possible. I'm seeking a career change into cyber security.

shut delta
vagrant wraith
#

brah i finally got the flag i thought sum was wrong with the lab lmaoo

unborn summit
#

You don't need to add it to /etc/hosts for vhost fuzzing, if you specify the IP and port. I'm assuming they tell you to add it to /etc/hosts so you can visit the page after you have discovered it.

shut delta
#

Can anyone help here iv got a shell on the machine and keep looking trough logs but cant find the pass🐣

#

like iv dun the 3 sections after it

echo pecan
#

module

frank bloom
#

Hello, I am a beginner. Can restrictions be removed from ChatGPT?

terse bloom
#

Hello people, File Upload Module --> Whitelist filters. I have managed to bypass the whitelist and blacklist filters and upload php files (various via burp intruder), but I cannot access them! I get 404, even though I should get at least something

brave field
terse bloom
#

It returns 404 for all the bypasses that had "File successfully uploaded" message. /profile_images/ comes from HTML code inspection, it has to be the same for most exercises in the module...

brave field
terse bloom
brave field
terse bloom
gentle jolt
#

Hello

#

How to learn hacking I'm new

compact patrolBOT
terse bloom
keen crescent
#

oops. wrong chat!

rain mirage
#

attackig common services - hard

Once logged in, what other user can we compromise to gain admin privileges?

i have tryed lot of stuff but can figure what to do here ... i just need a single short hint ..

swift flame
#

Hey, I go through CJCA learning path and in Linux part - "Backup and Restore" there is excercise to practice rsync, and do backup to local pwn machine. What is the password for local user to ssh to 127.0.0.1?

little terrace
#

im redoing password attacks: Pass the Hash

whenever i rdp (remmina) using pth, i can only do it once, if i exit out and try again it tells me that the username\password is wrong

how do i rdp in again if thats the case

rain pecan
#

Yi

#

Yo guys

acoustic owl
rain pecan
#

No what I mean is pls check your discords

#

Bc sm might be hacked

#

And ty but I've been in this server for almost an year

#

I'm usually off but I will try to be more active

rain pecan
acoustic owl
rain pecan
#

Ama do it again

#

And see if it works

rustic sage
#

It may be out of topic, but do you recommend me finishing the ctps and then sec+ or the other way around?

wide dove
#

Where can I post jobs?

frank trench
pine arrow
#

Hey

rustic sage
storm elk
#

Don’t cross post @stoic heart - posted in all wrong channels - #1024429874246590575 might be better. But we’re not your homework helpers

wild sage
#

bump

#

Still need help

stoic heart
storm elk
#

Also - if you want access to more channels, all the instructions you need are in #welcome

tender nimbus
#

Hey guys, I tried to figure out what the problem is and tried to fix it but I can't any idea? On my laptob it is not working I have what you can see on the screen, but on my pc home when I do a multi handler of this (like in the module) everything is good (module tunneling and pivoting section meterpreter)

jovial robin
#

OSINT: Corporate Recon | Section staff

that seems like it should be the number but it doesnt work ? ( also not working with +1 )

rain mirage
#

i cant hit finish , even though i have submitted the flag , what do i do ?

tender nimbus
rain mirage
#

I did ... ..

rain mirage
tender nimbus
#

Or try a refresh of the page

rain mirage
#

Naa.. only had 1 question to submit the flag ..

rain mirage
tender nimbus
#

Hmm weird maybe just an issue i guess can’t help you further ^^

rain mirage
#

Dude... sadglas

calm abyss
#

you still stuck there ?

#

you still stuck there ?

pale island
#

i keep getting stuck at the filter contents for linux where i need to: How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)

fathom pendant
# rain mirage

looks like the medium skill lab you're missing something

fathom pendant
rain mirage
#

It's just stuck

fathom pendant
rain mirage
fathom pendant
#

otherwise reach out to support on the website

fathom pendant
tender nimbus
fathom pendant
#

if it's not the pwnbox then there's gonna be very little help aside from advising you to reinstall meterpreter/msfconsole ĀÆ_(惄)_/ĀÆ

#

if it is in the pwnbox -> reach out to website support

turbid kindle
#

Hi all, can someone give a hint on how to solve the last challenge of the "Intruduction to NoSQL Injection" academy module? I already tried all payloads seen during the course.
I'm guessing it is Server Side JavaScript Injection but

  1. I can't see any javascript on the pages
  2. I can't find an oracle
    I also tried fuzzing the three requests (/login, forgot and reset) with the two wordlists mentioned in the course without any result, I'm pretty stuck šŸ™„ if someone could help with a slight hint that would be great 🄹
agile spindle
#

where is this thing in academy 2.0 ? šŸ˜„ do I need to open my eyes or its missing

mint rover
wooden fiber
#

Hello, I think there is a bug on the Skills Assessment - SQL Injection Fundamentals. I managed to login to the app, and found out the supposed vuln parameter within the chat. However, it always returns 200 ok, and the chat dissapears entirerly no matter what, unless the param is just a text without any sql. At this point, I took a look through solution as I was stuck, follow the exact steps, which already did before, and have the same persistent issue. Any thoughts?

wooden fiber
fathom pendant
cold sorrel
#

Hi all im new here, I have been with HTB before but decided to make a new account

brisk flume
#

Hi guys I'm stuck on SQL Injection Fundamentals: Skills Assessment - SQL Injection Fundamentals
I'm been stuck on the first question "What is the password hash for the user 'admin'? ", and I've tried all the different type of auth bypass injection for the login page, but they give me errors. The module says I need to use Burpsuite but Idk how I'm supposed to use it for this section.

river crystal
#

Hi guys, im new to ctf. May i ask how long roughly it's covered?

rustic sage
#

Can I finish ctps just with the pentester job role path?

jade orbit
#

Sorry if this isn’t the right spot. Are there groups that tackle Bug Bounties? These critical bugs have good payouts that could be divided across a team of hunters

echo pecan
#

This module is a tier 0 "free" module. What is the total cubes that will be rewarded back to you by completing it?

#

help me

cloud urchin
echo pecan
#

Error Incorrect answer! It appeared like that

acoustic owl
echo pecan
acoustic owl
# echo pecan ok

While you are working on the module, there will be questions that you have to answer. These questions will sometimes give you cubes in return. A total of 10 cubes. Not all questions reward cubes. They are distributed in such a way that when you have finished the module, you will have received the 10 cubes that you spent to unlock it.

rustic quiver
#

Is there something i'm missing about sqlplus? I"m working opn the footprinting module and its saying use sqlplus to login to the oracle db but when I try to use it in the pwnbox it wont install and when I try installing it both on the pwnbox and on my own system it says it can't be located

limpid hemlock
#

Hey can anyone help me with the skill assessment 2 for introduction to evasion techniques i tried creating a vbsvrupt and putting it on the target folder but not getting a shell

opal shuttle
opal shuttle
opal shuttle
limpid hemlock
# opal shuttle which module

The intro to windows evasion one I managed to find the flag couldn't get a reverse shell had to start a server and capture the flag on desktop of the user that clicks on the file

devout lily
#

Vulnerability Assessment - Nessus skills assessment
"Alternatively, use the pre-populated scan data to answer the questions below without having to wait for the scan to finish but feel free to practice configuring and running it." where can i find the pre-populated scan data?

ocean coral
#

Hello everyone… fingerguns new here is it possible to do the modules in a virtual machine if I’ve don’t have a paid account

waxen totem
echo pecan
#

...

ocean coral
waxen totem
silent palm
#

hi im new to HTB. im working on one of the network fundamentals module and i wanted to do the extra skill assessment. some how i cant to ctrl-v in shell?

devout lily
silent palm
#

the part im on says i have to do user anonymous ctrl+v enter enter and it just says command not found

fathom pendant
devout lily
fathom pendant
fathom pendant
devout lily
fathom pendant
#

ctrl+v enters "verbose keys" mode

fathom pendant
fathom pendant
#

the vpn only gives you access to the 10.129.0.0/16 range of targets

waxen totem
#

For Hack The Box VPNs treat 10.x ips as if they were public ips. Other than that you can retain the private and public classifications

devout lily
#

Another question, when i put the credentials in Nessus in Windows section, whats the goal of it?

fathom pendant
#

Nessus does a wide sweeping scan; if you provide credentials, it attempts to log in and enumerate using said credentials on various services

devout lily
fathom pendant
devout lily
fathom pendant
#

You don't really need to do the scan yourself tbh, as was already stated there's a pre-populated scan... unless you WANT to wait like an hour for the scans to finish

devout lily
#

whats the difference?

fathom pendant
# devout lily whats the difference?

the credentials you provide will be used to attempt to log in to services
with a non-credentialed scan, the only attempt to be made would be for anonymous/null sessions

waxen totem
# devout lily whats the difference?

Brute force: You provide a list of credentials and it will try all of them but not go further
Dedicated: You provide known credentials and it will utilize them to scan the internals

fathom pendant
#

I generally wouldn't concern myself too much with learning the ins and outs of a vulnerability scanner tbh

fathom pendant
#

[unless it's actually part of your job]

fathom pendant
#

I generally dislike this module as part of the path because it's just a dartboard module; throw stuff at the dartboard and see what sticks

#

vuln scanners can be useful, but they're more of compliance checklist tools than they are fully helpful, like linpeas/winpeas

waxen totem
#

I only really liked the theory parts of it.

fathom pendant
#

sure, you'll find SOMETHING but like you'd find it faster just manually enumerating

devout lily
fathom pendant
waxen totem
devout lily
#

the third phase is vulnerability assessment

fathom pendant
#

Vulnerability Assessments are done in the early stages of security hardening

#

before a pentest is performed

waxen totem
#

Vulnerability Assessment IS NOT Vulnerability Scanning

devout lily
fathom pendant
#

A vuln assessment is just there to tell you of POTENTIAL vulnerabilities; A vulnerability SCAN is to actually go through and verify what is/isn't vulnerable

devout lily
waxen totem
# devout lily whats the difference?

Vulnerability Scan: Automated way of locating POTENTIAL vulnerabilities, detected in automated ways (it's a form of information gathering)
Vulnerability Assessment: Judgement of the pentester on whether a vulnerability is worth looking into and continue to exploiting and so on (chance of exploitation, complexity, and chance of damage)

fathom pendant
#

I think that's kinda incorrect w1ld as a vulnerability assessment is a form of auditing as well

devout lily
#

If this module named Vulnerability Assessment, why is not?

waxen totem
fathom pendant
#

It's a different thing entirely; A company will perform a Vulnerability Assessment PRIOR to actually hiring pentesters in order to qualify their scope

devout lily
#

i think that the using of Nessus come after the Information Gathering

waxen totem
fathom pendant
#

A vulnerability assessment just shows potential surface level vulns that a company can harden prior to having a pentest performed.

#

But that's why i hate the scanners as a whole because, again, dartboards

devout lily
#

ok and the third fase of a pen test process called Vulnerability Assessment when is perfomed? And which tools are used?

waxen totem
fathom pendant
#

it's not a bad module; but it's placement just also feels lacking

devout lily
fathom pendant
#

you shouldn't necessarily need automated tools in order to hunt vulns

#

the only time you'd need an automated tool is if you've tried literally everything else and haven't moved forward

devout lily
# fathom pendant your brain

so the process is Information Gathering --> look at the results to see if something could be vulnerable (Vulnerability Assessments) --> Exploit

#

right?

waxen totem
waxen totem
devout lily
fathom pendant
#

It was honestly one of my least favorite modules because i didn't really 'learn' anything off it, just "here's a scanner that will likely provide false positives, have fun"

fathom pendant
vagrant wraith
waxen totem
vagrant wraith
devout lily
fathom pendant
devout lily
#

i will proceed to delete this modulo from the Vulnerability Assessment phase so

waxen totem
fathom pendant
#

--script vuln

waxen totem
#

don't think of any of these tools as the end all be all, treat them like tools in a toolbox, if one doesn't fit or work, then find one that does.

#

there's a reason all these modules cover multiple ways to do the exact same thing

devout lily
devout lily
waxen totem
devout lily
#

so can i think Vulnerability Assessment and Information Gathering as a single phase right?

turbid kindle
waxen totem
#

it's better to have all the information before making a judgement is all.

devout lily
waxen totem
waxen totem
#

don't judge a vulnerability too quickly

devout lily
#

so the vulnerability assessment is just a phase where u study the information you got before

#

is it right?

waxen totem
#

You might think: Ohh this is a low impact vulnerability since it's easily fixed, but what if you have an ssh key in there? or a RootCA?

waxen totem
waxen totem
#

CVSS highly depends on Impact, not just vulnerability itself.

fathom pendant
#

^

fathom pendant
#

also in-general, you should be able to roughly defend your CVSS score you provide.

#

i.e. normally this would be an info/CVSS 1.0 however, this vuln leaked extremely sensitive credentials

waxen totem
fathom pendant
devout lily
waxen totem
#

TLDR: something you can exploit on it's own yes counts as a vulnerability, BUT a chain of exploits also counts as a vulnerability.

Imagine you have anonymous access to a file share with an encrypted zip file containing, ssh keys, but the zip encryption is crackable.

Weak Encryption Password- Vulnerability
Anonymous FTP login - Vulnerability

SSH Key leak through Anonymous FTP login and Weak Encryption Password - MASSIVE Vulnerability.

fathom pendant
#

CVSS deals with the CIA triad

#

and some other factors

#

i.e. how do you access this resource [can you access it externally or is it required to be on the same network]; is there some other factor involved, does it breach any part of the CIA triad

waxen totem
fathom pendant
#

i.e. i wouldn't necessarily say something being hosted on the admin share is a vulnerability in and of itself

#

because, if only admins can access the share -> then it's relatively confidential

devout lily
#

making a syntex, Vulnerability Assessment can be done rating the informations i got before, using CVSS and CVE

#

and personal experience

fathom pendant
#

CVSS is generally better for post-exploitation

#

not before exploiting

devout lily
fathom pendant
#

because an anon share can have absolutely nothing on it; thus making it more of an informative vuln like "Hey some idiot spun up a share and it was never taken down"

waxen totem
fathom pendant
#

^

fathom pendant
waxen totem
#

was just using CVSS as an example on how to rate vulnerabilities, but you should be fine by just judging: high chance of exploitation, low chance of damage to systems, and low complexity

fathom pendant
#

in general after the scanning phase you want to rank the potential vulns in order of most to least likely and start there

devout lily
#

so the correct definition is: Vulnerability Assessment can be done rating the informations i got before using personal experience and google

waxen totem
devout lily
#

really appreciate your help guys

fathom pendant
#

I like to think of it this way as well: Say you have 2 vulns presented, anon share and an SSH server that MAY BE vulnerable to shellshock; the more likely thing is anon share and you start your enumeration from that point instead of diving down the shellshock rabbit hole

#

and your list could also be ranked in "how comfortable am I in attempting to exploit these potential vulns"

waxen totem
#

and you go back into info gathering when you reach that one vulnerability in the list that you really couldn't be bothered to exploit 02kek

rustic sage
sand rose
#

Hello guys, I need help with the SeDebugPrivilege Section in the Windows escalation module. I was able to use minikatz to make the lsass.dump file... but since im using xfreerdp3, I have no clue how to actually get it to my own system to crack it offline.

#

Is anyone able to help?

fathom pendant
#

/drive:name,/path/ or /drive:/path/,name

sand rose
#

Do I have to run it as I use it to RDP in? Or can I open another terminal and do it that way?

fathom pendant
sand rose
#

with the /drive: name,/path/ you mentioned. I assume path is the path to where the file is... is name the name of the file I assume?

queen dust
#

reverse shelling after making it semi interactive with /bin/bash it gets stuck on some commands and takes a while before I can execute something else, any fixes?

fathom pendant
#

name is what it'll appear as in the file viewer; it's spinning up a share, basically

sand rose
#

So... im struggling to connect some dots here. So its spinning up a share for all intents and purposes... I'm not following how this helps me get the file on the remote machine locally.

fathom pendant
#

in the cmd line on windows it would be //tsclient/name

fathom pendant
#

i.e. an inconspicuous name like "Tools"

#

for instance if you want to transfer files to/from the session and don't want a dedicated folder to use you can use /tmp

#

so /drive:tools,/tmp/

#

and it will mount YOUR /tmp/ folder on YOUR linux machine

#

in the remote session you can drag and drop files to/from that folder to transfer files

sand rose
#

is cp or move a thing in windows cmd?

fathom pendant
#

or use the copy command

#

but you'll need to use //tsclient/tools/ (for example) to copy a file over

#

or move iirc it's move and copy; windows is more verbose in a lot of its commands

#

fun fact: the rdp binary in windows is called mstsc.exe -> Microsoft Terminal Services Client. that's why it's mounted as //tsclient/name

#

where name is whatever you decide to name it

sand rose
#

It keeps saying network name can't be found

#

and Im using the name I used before

fathom pendant
#

?

sand rose
#

Alright this is the command in linux I ran:

#

xfreerdp /drive:test, /test/ /v:$target /u:<redacteduser> /p:<redacted password>

I exported the ip into target

sand rose
#

yes it does

wicked apex
#

anyone encounter problems trying bloodhound-python and nxc-ldap-bloodhound around module-163(AEN)?
is this a ligolo-ng specific problem?

fathom pendant
sand rose
#

when i run //tsclient/test on windows it says "The network name cannot be found"

wicked apex
#

oh also error being related to dns and ldap timeout mostly

fathom pendant
#

can you copy over a test file using
copy <file location on windows> //tsclient/test/

#

hi this isn't #general ; you'll need to follow the instructions in #welcome to gain access to typing there

fathom pendant
wicked apex
#

though it should be the same host the module is telling me to run sharphound on,
with full access of course

fathom pendant
#

that means just spinning up and going from boot to Domain Admin (or highest priv level)

#

and not answering the questions

#

or reading the module

wicked apex
#

agree
I am in half the way through
Initally I tried to do it blind but I head into some roadblocks real early on so I just went lazy lol

fathom pendant
#

learn to tough it out and fight through the roadblocks instead of looking for the easiest way out

#

AEN blind is a test of your methodology and notes

#

it's not JUST about completing the module, it's about hardening your methodology and problem solving skills

#

it's alright to take a peak if you feel like you've tried everything, but you shouldn't be using it as a guidebook. The simplest thing to do is reset the target and see if that resolves the issue, getting back to that same point would be trivial

sand rose
fathom pendant
wicked apex
#

now I just kinda memorized the methodology of passing through the first few machines
Maybe I'll take a break to reset my mind first

fathom pendant
sand rose
#

is lsass.dmp not specifying the file? the file name is lsass.dmp?

fathom pendant
sand rose
#

it also says the system cannot find the specified file

fathom pendant
#

cannot find specified file
is that on the local end? that means that lsass.dmp isn't where you think it is ig (procdump can still run even if you specify a bad file location iirc)

sand rose
#

I already ran procdump and it created lsass.dmp

The file path to lsass.dmp is: C:\Tools\Procdump\lsass.dmp

fathom pendant
#

and you can verify that it does in fact exist? :)

sand rose
#

I'm staring at it right now

fathom pendant
#

then try this: open the file explorer -> this pc -> tsclient -> test

sand rose
#

folder is empty... but it is there

#

ill just drag and drop it?

fathom pendant
#

ye

sand rose
#

ok. thank you so much

fathom pendant
#

no idea why it's not working via command line but also sometimes it's tricky ĀÆ_(惄)_/ĀÆ

#

i mean the alternative is mounting it as a drive using net use

sand rose
#

I was honestly close to saying screw it and spinning up a smb server and just doing it that way

fathom pendant
#

also curious if it's a direction issue

#

// vs \\

sand rose
#

ill try it here in a sec

#

let me get it to my local machine and ill test it

fathom pendant
#

but that may just be a "windows is dumb sometimes"

#

typically // and \\ is automatically translated with windows, but some commands can be touchy

sand rose
#

sooo... now I have a different issue

#

When I go to drag and drop, the rdpclient keeps flickering on and off almost... and it doesnt finish copying over.

#

It gets to like 40 percent and then flickers and never copies and I have to keep moving it over.

haughty fiber
#

stuck in file uploads module. Able to upload the php file but cant find it in the uploads directory even after the correct naming scheme

sand rose
#

nvm

#

We got it over.

Also direction didn't matter for me sooo I dont know what was going on there.

#

But we got there. I appreciate it. Thank you!

#

We are in fact not there yet... I'm now having issues parsing the dmp file locally... its encrypted and I don't know how to decrypt it so I can run it through hashcat.

rustic sage
#

When I finish the information security foundations, do I just jump straight into pentesting job role path or are there any other paths I should be doing or modules that you guys recommend?

fathom pendant
#

IIRC it's SAM and SYSTEM

sand rose
fathom pendant
fathom pendant
sand rose
#

kk

jovial robin
thick ice
#

Hello, everyone! I am having an issue with the Password Attacks: Credential Hunting in Windows module.

I found the answer to the question ā€œWhat is the default password of every newly created Inlanefreight Domain user account? (Format: Case-Sensitive)ā€ in the script, but it is not being accepted. I would be very grateful for your response.

red shuttle
#

delete flag bro

cunning fern
sand rose
#

Yeah... but still dont post them. I also believe its against htb TOS to post any kind of spoilers... especially flags for anything not tier 0.

cunning fern
#

how else do you want me to show that the only given flag is "incorrect" 😭

sand rose
#

Ask for help and see if someone is willing to have you DM them to talk in private about it

#

Or just say what you did and mention that the flag you saw is not showing as correct

#

someone who is able to help will when they have time and see it

cunning fern
#

i still dont understand whats the fuss about sincei ts clearly marked as spoiler but here ya go

red shuttle
cunning fern
#

hey guys, im currently doing the network enumeration with nmap module, on nmap scripting engine there is a question "Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer.". i used ||nmap 10.129.2.49 -p- -sV --script banner | grep "_banner" ||and got the result, but the found flag is shown as incorrect? not sure if it matters but im using beta

#

^when i didnt use ||grep|| there werent any ||banners other than what I have here||

fiery loom
#

i have problem with one modul where i need to satart a box and find how many software interface modes are awalible but it seems there are none but answer was 2

#

Check the driver capabilities for the interface. How many software interface modes are available? (Answer in digit format: e.g., 3)

heavy slate
#

Advice on LLM Output Attacks - Skills Assessment
Im stuck and no out of ideas to try, can someone point me toward right direction?

floral fulcrum
#

could anyone give me a nudge for advanced sql injections skills assessment question1? having trouble || dumping password hashes||

smoky whale
#

Guys

dull solar
#

"Above, we created the user JLawrence and did not set a password. So this account is active and can be logged in without a password. Depending on the version of Windows we are using, by not setting a Password, we are flagging to windows that this is a Microsoft live account, and it attempts to login in that manner instead of using a local password."

Can anyone explain this in regards to the cmd in the section above it?

Module: Intro to Windows CLI Section: User and Group Management

What is meant by live accounts, isnt the no-password login similar to a guest account?

brave field
fathom pendant
cunning fern
hollow kernel
#

Can somoeone help with module common attacking aplications
The submodule
Thick client applications

#

Can I compile java with IDE like eclipse?
Or is necessary to do commands in powershell?

lean bronze
#

If you're still stuck

zealous hazel
#

Sorry ik this isnt the right channel but why is this the only channel i can talk in

maiden thunder
#

I'm stuck on Skills Assesment in ADCS Attacks module
I managed to get machine's certificate dev01.pfx but it fails to authenticate
||
certipy auth -pfx dev01.pfx -dc-ip 172.16.19.3
[-] Got error while trying to request TGT: Kerberos SessionError: KDC_ERR_PADATA_TYPE_NOSUPP(KDC has no support for padata type)

Though I can use -ldap-shell and set_rbcd
I can't get a ticket to proceed
getST.py -spn cifs/DEV01.LAB.LOCAL -impersonate Administrator -dc-ip 172.16.19.3 lab.local/tom:tom123
||

low ravine
devout lily
zealous hazel
low ravine
unique willow
#

Hello all, I'm having the same issue as this guy (though he didnt get an answer), aquatone is too old its completely broken I downloaded it the exact way the course shows (e.g. latest version which came out 4 years ago) the repo has been archived since 2023 and when I generate the report it's completely broken (while eyeWitness scan worked amazingly).

Requests:
 - Successful : 15
 - Failed     : 0

 - 2xx : 15
 - 3xx : 0
 - 4xx : 0
 - 5xx : 0

Screenshots:
 - Successful : 2
 - Failed     : 13

Either there's something very wrong with my setup (go/1.22) or the flag is impossible to get

What does the header on the title page say when opening the aquatone_report.html page with a web browser? (Format: 3 words, case sensitive)

Does anyone know how to skip this? (/module/details/113 -> Application Discovery & Enumeration)

dull solar
#

Module: Introduction to Windows Command Line
Section: User and Group Management
Anyone, a little help? It asks "Connect to the target host and search for a domain user with the given name of Robert. What is this users Surname?" and every time I try to filter for him, it says "Server has rejected client credentials"

twilit fjord
#

geniune question but im expected to complete the linux fundamentals module in 6hrs according to HTB academy, is this seriously realistic progress and learning?

queen dust
twilit fjord
#

i feel like i can only achieve that time if i make no notes and dont practice

#

just confusing

vernal tapir
queen dust
#

do you have prior experience with linux?

twilit fjord
#

so ig i dont have as much as i thought

#

tbh idk what my experience level with linux looks like, im not too confident abt it

vernal tapir
#

Hey, send me a pm if you'd like I can help you with a nudge

green musk
opal shuttle
#

hii guys how to get sharable link of htb labs

wooden niche
#

Hello guys
Please I am new here and I needed guide and I am interested to learn cyber security

Please how can I get started??

brave field
static belfry
#

hi guys
who can help me to reverse ip?

compact patrolBOT
acoustic owl
#

@wooden niche ^

wooden niche
jovial robin
acoustic owl
jovial robin
#

i swear i am going mad i entered the number, without adding sth, like 5 times yesterday, and it didnt work but it just worked and now i doubt my sanity (i even entered all numbers from 1-100 manually) kek

#

well it works ... thx ! :D

static belfry
#

@acoustic owl thx for your response but it's not working

acoustic owl
static belfry
#

what percentage can succeed?

acoustic owl
ebon minnow
#

Question: Try to read the details of the user with 'uid=5'. What is their 'uuid' value?

I got the "staff_admin" cookie by going to uid 10, can i have a hint on what im missing because ive tried entering 5 in api endpoint like the hint said.

topaz tundra
#

Greetings
I have a question why is it that when I connect with a vpn I can’t get the flag but as soon as i tried it with the htb box I had the flag with the same command? It happened to me twice in different modules and I found it weird

woeful blade
#

And proton vpn or surshark if you want your data nit tò get leacked:)

ebon minnow
#

Web Attacks, IDOR. But I managed I get it via curl in terminal lol. Burp wasn’t working because I got confused

dull solar
topaz tundra
dull solar
#

And were you able to ping target?

topaz tundra
dull solar
topaz tundra
topaz tundra
dull solar
#

Depends on context of cmd though, I don't know what they are.

topaz tundra
dull solar
#

If it's allowed. put a spoiler

#

If you want to ofc.

topaz tundra
dull solar
topaz tundra
topaz tundra
dull solar
#

Just hide the actual thing you submit. Not the cmd.

topaz tundra
#

Another I couldn’t get a file from the ftp servers on the following module but the the htb box I could is it supposed to be like that just asking

cunning fern
fathom pendant
cunning fern
# fathom pendant --script http-enum I believe gets you there the quickest

yeah i saw "the thing we need" few other times while scrolling through walls of text some scripts gave me but i didnt rly think the answer was right in front of me, ngl i think this was an interesting lesson to leave no rocks unturned and i hope more modules will be like that to force that approach upon students

dense stump
#

Hello

fringe thistle
#

Hi a short question to the module "AI Data Attacks" is there a jp notebook which I can spawn. If yes where do i find it?

#

Ok problem solved i installed it myself on the parrot system

fleet spear
#

windows privesc well me an my AI are stupid we cant find out how you can find out what privilegie are set when you are allowed to run powershell as administrator

strong vector
#

Hi! Can someone help me with the Pass The Certificate session on the password attacks modules, i rlly cant get the administrator flag. Pls dm me

ocean coral
#

so i'm having issues getting to connecting with vm

strong vector
#

which module is it, and did u tried with the -Pn flag in nmap

#

also i dont think is a good thing to share flags, but idk

ocean coral
#

i'm like really new to all of this but it's the fawn

strong vector
ocean coral
#

oh ok i'll see

ocean coral
brave field
#

If anyone is able to explain? Thanks.

ocean coral
strong vector
#

nmap -sV -Pn

ocean coral
#

together?

ocean coral
strong vector
ocean coral
#

oh i see thank you... fawn has been pwned thanks to you, will note that down as well.

ocean coral
strong vector
#

idk, i used kali before switching to arch

#

i only use arch bcuz of ricing tho

ocean coral
near breach
#

Hi everyone! I need a help in Attacking Web Applications with Ffuf.Filltering Results lesson, it says to add the htb.academy URL to etc/hosts so I can send a request using the Host header for vhost fuzzing. Could you please tell me why I need to add the IP address to etc/hosts? Why can't I just specify the full IP:port in the ffuf request?

DNS substitutes ip instead of URL.

So, with etc/host like this:

94.237.57.115 academy.htb

These two requests will be equivalent:

curl http://94.237.57.115:49747
curl http://academy.htb:49747

So, I don't have to add a DNS record and just send the request.

ffuf -w subdomains-top1million-20000.txt:FUZZ -u http://94.237.57.115:49747 -H "Host: FUZZ.academy.htb" -fs 0

but it returns an error.
And the next request without the host header works correctly.

ffuf -w  subdomains-top1million-20000.txt:FUZZ -u http://94.237.57.115:49747/FUZZ
waxen totem
#

TLDR; cos you can't make a request to: example.academy.htb:49747 using example.94.237.57.115:49747 that's not a thing

#

But for your fuzz command you're filtering incorrectly and you have a typo: FUZZ.academy.htb. you added a . by mistake at the end, it should be FUZZ.academy.htb

near breach
waxen totem
soft mural
#

Module: Password Attacks
Section: Writing Custom Wordlists and Rules
hi guys, i have stucked on this section for 1 day. I have tried manually creating the password, then expand it using oneruletorulethemall, but it still not working, can someone share some tips on it?
https://academy.hackthebox.com/module/147/section/1391

devout lily
#

Hi, can someone help me to understand the CVE web site or NVD website to see the specifications about vulnerabilities?

#

im browsing but i didn't see nothing yet

waxen totem
hidden parcel
#

Hey, on the Nmap module, on the hard lab I wasnt able to do it and ended up looking at a writeup, but I still dont understand the solution. Is it common to enumerate all the filtered ports and try to communicate manually? Im guessing automating a tool would be useful but I want to know if this is a common practice or done in this lab because the question is to get a service's version.

waxen totem
lusty flint
#

Module: Password Attacks
Section: Skills Assessment
Link: https://academy.hackthebox.com/module/147/section/1356

I submitted the ntlm hash for the question. It got marked as correct.
However, I the Mark Complete Option is not showing up. ( I Have completed all other sections and marked as complete too)

naive pelican
#

Module: Stack-Based Buffer Overflows on Windows x86
Section: Remote Exploitation
Link: https://academy.hackthebox.com/module/89/section/952

I think I did everything right. I get a connection from the reverse shell but the connection closes after 5-10 seconds, and I don't get the shell on the windows machine.
I used windows/shell/reverse_tcp on msfvenom
Need some help guys I am lost.

soft mural
hazy lance
#

heyy guys

I'm having some issues with secretsdump in the Pass the Certificate section (Password Attacks Module).

$ impacket-secretsdump -k -no-pass -dc-ip 10.129.234.109 -just-dc-user Administrator 'INLANEFREIGHT.LOCAL/DC01$'@DC01.INLANEFREIGHT.LOCAL


[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
[-] 'NoneType' object has no attribute 'getRemoteHost'
[*] Something went wrong with the DRSUAPI approach. Try again with -use-vss parameter
[*] Cleaning up... 

When i use the -use-vss flag (as the output is saying) i recieve this error:

$ impacket-secretsdump -k -no-pass -dc-ip 10.129.234.109 -use-vss 'INLANEFREIGHT.LOCAL/DC01$'@DC01.INLANEFREIGHT.LOCAL


[-] Policy SPN target name validation might be restricting full DRSUAPI dump. Try -just-dc-user
[*] Cleaning up... 
#

I abused of the NTLM RELAY attack and now i need to dump the hashes but i'm having this error

#

thank you in advance.

brave field
fleet spear
#

usally you have to split ut 'domain'/'account'@host but when secretsdump suggest -use-vss or other flags there is usally some underlying problem use -debug aswell

unborn berry
#

Guys, what should I have to apply to pentester??

brave vine
#

I am doing Pro lab solar htb, i have an issue with jail escape after accessing jupiter.solarsystem.htb machine. Any help?

acoustic owl
#

If you have no access, read and follow #welcome

acoustic owl
neon tinsel
hidden ledge
#

Hello, in the Skill Assessment of the Password Attack module I tried to set up ligolo for pivoting but i'm new to this and there is a weird behaviour I cannot say if it comes from me or not. When the session is started in ligolo I can ping DC01 in the internal network corresponding to: 172.16.119.11 but I can't ping FILE01 and JUMP01. Do you have any idea how this is possible ? Wrong set up from me ? Or it's definitly weird and I should reset the machine? (I did this yesterday and it worked totally,)

waxen totem
#

@neon tinsel I just need the command you used, not the results, as those are spoilers

neon tinsel
waxen totem
#

ok that's interesting, can you DM me with the full output of that command?

solar vessel
#

H

inland parrot
#

Anyone available for discussion regarding "Attacking Common Applications - Skills Assessment II"

hollow kernel
fathom pendant
#

running an nmap -Pn scan may reveal info to ensure that the internal targets are operating properly

#

Windows targets, generally, dont respond to pings

pastel ice
#

hi guys

hidden ledge
#

So I got the foothold on dmz01, I'm able to ping DC01, but not the others, I have not changed the /etc/hosts since i'm workinng with ips (Tell me if i'm wrong). I tought maybe jump01 and file01 blocked pings ? It seems nmap work fine in fact :))

pastel ice
#

do u guys have tool for the hackthebox

fathom pendant
hidden ledge
#

Thank you :))

fathom pendant
pastel ice
fathom pendant
#

I suggest reading #welcome and #rules to see what the server is about @pastel ice

fathom pendant
pastel ice
#

sorry kinda new to the environment

fathom pendant
pastel ice
#

ok wait a bit

fathom pendant
#

In order to gain access to chat there, youll need to link your hackthebox account to the discord server

zealous hearth
#

Hi guys, I’m working on the web attack section of the web pentester path. In the bypassing basic authentication section of http verb tampering, it says we can use curl -i -X OPTIONS http://SERVER_IP:PORT/ to see which methods are allowed, but this actually does not show the options in practice as it does with the module. Is this on purpose or does my lab have some form of error ?

green musk
little terrace
#

after pivoting to a machine with ligolo, is there a way to get the sudo responder -I <int-name> -A working from my host? seems like i HAVE to rely on the linux attack host that they provide to use responder

fathom pendant
fathom pendant
zealous hearth
fathom pendant
fathom pendant
green musk
zealous hearth
fathom pendant
fathom pendant
zealous hearth
#

Ok thanks

fathom pendant
#

Also: website support doesnt help with content problems if the issue is not technical (lab is broken/not spawning/etc)

#

This server is more focused on community help, not everyone has done the module you're on

#

Log off of the account, then log back onto the account after setting it

#

That's literally the solution to your problem

#

Closing the rdp session doesnt log you off btw

#

Also deleted the message because its a spoiler

green musk
waxen totem
fathom pendant
green musk
fathom pendant
#

You're asking for help with something thats out of scope for what's being asked of the module

green musk
#

Thank you @fathom pendant appreciated your help

fathom pendant
#

I do hope you're doing AEN blind and not answering the questions and reading the module

#

As that will help strengthen and reinforce your methodology more

green musk
fathom pendant
#

Afterwards, the module basically becomes simple to read and go through and see what methods the author used instead

#

Getting hung up on one step before completing it is just going to be a detriment, especially in cases where you may actually be on a timed test

green musk
fathom pendant
green musk
fathom pendant
#

In general; just stick as close to the sample report as possible and be consistent in your labeling

waxen totem
fathom pendant
waxen totem
green musk
fathom pendant
fathom pendant
waxen totem
fathom pendant
#

Imo one of the more important things with AEN is solving where your weak points are

green musk
waxen totem
fathom pendant
waxen totem
# cunning fern Why is that?

Because that section, or some sections, are just so hard, that even after doing them, and gaining deeperknowledge and skill in those areas, people won't be willing to provide help for it, at least not for free

cunning fern
#

Understandable

waxen totem
cunning fern
fathom pendant
#

module tier moreso relates to the required underlying knowledge more than difficulty

#

tier 0 -> you don't know shit
tier 1 -> you kinda know shit
tier 2 -> ok now you know a bit of something
tier 3 -> wtf it goes deeper?
tier 4 -> now you're just fucking with us

bold niche
# waxen totem but the template is public for the exam anyway on systreptor *speaking of sysre...

While it’s understandable that encountering issues with the cloud version during an exam is inconvenient, it’s important to view this in context. Over the past 90 days, we’ve maintained an uptime of 99.936% (see status.sysreptor.com), which translates to only a few hours of total downtime. Today’s interruption was caused by an incident at our server provider’s data center. unfortunate and naturally, it’s when people notice most and complain.

That said, I don’t fully agree with the suggestion to ā€œhighly recommend the local installation.ā€ Running a local setup comes with its own significant overhead. keeping everything running smoothly, handling updates, handling the database, and preparing for unexpected failures. Users must also manage backups and test recovery procedures. We’ve seen many cases of users losing their encryption keys because they forgot to back them up, resulting in data loss. We receive a fair number of support requests about this though you don’t often see those issues here on Discord.

In the end, choosing cloud or local is a personal decision both have pros and cons šŸ™‚

cunning fern
fleet spear
#

this question is driving me crazy in the windows prisec module, how do i enumerate im allowed to run as administrator...

fathom pendant
fleet spear
#

ok sorry

#

i will take it to erratum

fathom pendant
fleet spear
#

well i find it to be an error to not explain

burnt path
#

Evil Twin Attack on WPA2
I'm completely stuck on this module. I have already recovered the handshake, but inside the module's VM there is no wordlist to crack the handshake and obtain the answer to the question: "Perform the evil twin attack as demonstrated in this section. What is the discovered value of the WPA PSK?"

inner juniper
#

Hello everyone. I am stuck with module "ATTACKING AI - APPLICATION AND SYSTEM", its about the 'Model Deployment Tampering' task. When I am trying to replicate the attack and execute the last curl cmd on the page, then I get error '{"code": 500, "type": "NullPointerException", "message": "Cannot invoke "java.util.Map.entrySet()" because "modelsInfo" is null"}'. Does anyone know how to fix it?

slender stirrup
#

can someone help me in how do i get permission so i can taljk in general and the other chanels

slender stirrup
fathom pendant
weary coyote
#

Is thre any methods to root xiaomi phones without bootloader access

pale island
#

for this taks i have to find what type of service the dconf service is. the only problem is i can't seem to find it and keep getting blank outputs. does anybody have an idea? also just searching for it using systemctl gives me no result. EDIT: found the file but it smeems to have an empty type. TYPE:

fathom pendant
pale island
fathom pendant
pale island
fathom pendant
pale island
fathom pendant
pale island
#

okay got it. thanks a lot for the help

boreal raven
#

Hi Can you help me out the answer of the first question, i tried all the possible combination but it does not accept the hash. Have solved other task but this one is being a pain

wheat tiger
#

Hello Everyone,
i was wondering if anyone could help me with ā€žTerminate Pwnbox to switch locationā€œ.
I googled and watched youtube videos, also read the help to Pwnbox, but the button mentioned there is nowhere to be found on my page.
My location is set to UK, but i need it to be DE since im from Germany.
Also, if i press ā€žStart Instanceā€œ, there is a popup in the upper right corner of my screen which says ā€žThere are no available instances. Please try laterā€œ

fathom pendant
#

Reach out to website support

compact patrolBOT
lone talon
lean bronze
#

@swift dove thank you for recommending Google Colab, especially in trojan attacks section in AI Data Attacks, helps a lot

tiny frigate
#

seems very much like an issue on the entire platform? having this for a few hours now

blazing nova
#

New here! Does anyone know how to obtain more Pwnbox instance spawns? I didn't see anywhere to "purchase" more spawns?

fathom pendant
fathom pendant
#

but it appears plenty of people having spawn issues with the pwnbox, could be an upstream issue with their provider

dull badger
#

good evening everyone, about AI red teamer: LLM output attack: Function calling 3, could any one drop some hint for this? e.g., is it SQL injection or? Totally clueless for this one -3-

tame nimbus
#

Howcome i cant talk in general

cloud urchin
#

Make sure to read the #rules and then #welcome which shows you how to link it

tame nimbus
#

Ohh luv bro

#

I jus wanna ask questions im stuck lol

winter schooner
#

Hello, can anyone help me on server side attacks skills assessment?

ivory umbra
#

How come grep prints some lines starting with random numbers (red) but when I pipe it into sort it removes the random numbers?

#

Linux foundations module

#

Last screenshot was grep with -o, heres the output for normal

fathom pendant
fathom pendant
ivory umbra
fathom pendant
strong vector
#

I cant use rdp with proxychains in the password attacks skills assesment, could someone help me

fathom pendant
#

ligolo-ng avoids the need for proxychains; but errors tend to help more. did you try running proxychains with sudo?

strong vector
#

i changed to socks 4 and it worked

#

thx

vestal sorrel
naive pelican
fervent gale
#

Hi - I have completed the AI Red Teaming Track and am left with 9 flags overall. If someone who can help pls ping me so I can connect for any hints to complete the track

strong vector
#

hey, im 2 days deep in the password attacks skills assesment and i dont have enough money to continue my academy subscription so i can't waste any more time, if someone could dm me to help i would be gratefull ^^ (i rlly need helpsadglas )

ruby lintel
#

I have finished the Advanced Deserialization attack. I don't see where can I review/feedback to the module, so I think I will write it here.

I hope this module should add more content to it such as reproduce custom gadget in old CVE and sharing the road to it as the same approach in the module. As my point of view, it's not "advanced" too much as the title (the current content).

Anyway, the module provides additional idea, how to approach the issue and more deep understanding the well-known gadget. It will be helpful if you doesn't work with this kind of vuln before.

brave field
#

In the module: Command Injections, section: Advanced Command Obfuscation, subsection: Reversed Commands there is a tip given:

Tip: If you wanted to bypass a character filter with the above method, you'd have to reverse them as well, or include them when reversing the original command.

I want to know how would this work against the character semi-colon ( ; ). Thanks!

dull spruce
#

hola

digital ore
ruby lintel
sacred herald
#

hello guys, i am doing web proxies module in that zap scanner and i got stuck like how we can get the flag like i got 1 dir called devtools there is ping.php

#

can someone help me in this please

waxen totem
sacred herald
#

ok brother

soft mural
#

Modules: Password Attacks
Section: Network Services
Link: https://academy.hackthebox.com/module/147/section/1327

Hi guys, I am stucked on the rdp part for few hours, where i tried bruteforcing with the username.list and password.list given, with -t 4, but it still not working, i did found some credentials but those are for winrm only, can someone provide some tips on that?

lapis plinth
#

u can bruteforce smb first, and then use cracked credentials directly to rdp

slow flare
#

Does anyone play dab

#

Steal a Brainrot

final shale
#

New HTB Academy design sucks and its too heavy on my old laptop.

#

That is my feedback

soft mural
#

i think cuz i put /u: and /p: with space

#

ahhhhhhhhsadglas

lapis plinth
#

perhaps u need xfreerdp3 instead of xfreerdp, I also cant use itprayge

slow flare
#

Can anyone DM me?

opal shuttle
hazy comet
#

Advanced SQL Injection module - The error for failed compilejava for fernflower. To fix this update to JDK 21 install rather than 17 mentioned in the module. šŸ‘

little terrace
#

is there a good stable reverse shell that isnt meterpreter? i still want to use multi/handler but entirely remove my usages of meterpreter

spare fossil
quiet halo
#

I tried using online decodeers and also linu cli but it outputs gibberish

cyan veldt
#

Hello, is introduction to Python3 enough to write my own tools ?

waxen totem
waxen totem
#

Should you expect to write something like netexec? probably not

cyan veldt
waxen totem
thin horizon
#

general suggestion

as green is the "dopamine" button to pass next stage, I think submit should be green and show solution blue as I always accidentally click on show solution instead of submitting to continue

cyan veldt
waxen totem
waxen totem
cyan veldt
#

Should my knowledge in Python be beyond that module?

quiet halo
#

oh

waxen totem
waxen totem
# quiet halo oh

You'd have to first convert it into a ccache file then you can check it using MIT KRB

quiet halo
waxen totem
#

Read more in the article

#

There's also probably a way to pass it straight onto mimikatz but I prefer using remote tools on linux

#

Welp, a little google searching shows you can get the info straight from Rubeus

devout arrow
#

I'm having a little issue with an academy module.
In the Intro to Network Traffic Analysis, Networking Primer - Layers 5-7 I've answered all of the questions and I can't interact with the answers, but it won't let me mark it as complete. I've tried other browsers and incognito mode

waxen totem
devout arrow
#

CTRL+F5, no luck unfortunately

unique field
#

i need a help on NEW -module-Web Fuzzing-Validating Findings , after fuzzing target system using directory-list-2.3-medium.txt i find few directories i am afraid if im going on the right track .

waxen totem
compact patrolBOT
devout arrow
#

thank you

viral cobalt
#

can someone help me with Attacking Thick Client Applications, Im not understanding how to complete this section of the Attacking Common Applications module

opal shuttle
#

but you have to solve byyourself at the end

terse bloom
#

The proxy server is refusing connections. (non-VPN machine) Anyone else experiencing the same?

waxen totem
terse bloom
#

nice, forgot to turn it off yesterday bruh

brave field
#

@waxen totem may I DM you regarding a module? Thanks.

brave field
#

In the module: Command Injections, section: Advanced Command Obfuscation, subsection: Reversed Commands there is a tip given:

Tip: If you wanted to bypass a character filter with the above method, you'd have to reverse them as well, or include them when reversing the original command.

I want to know how would this work against the character semi-colon ( ; ). Thanks!

waxen totem
tulip urchin
#

I put links as answer and for some reason it isnt correct

brave field
waxen totem
tulip urchin
#

so anyone gonna help me with my question, cuz for some reason "links" isnt correct

#

even tho thats the correct answer

waxen totem
tulip urchin
#

from network foundations

meager yacht
#

Hello everyone!

I'm stuck on a question from the "Introduction to Command Line" module in the "Managing Services" section, and I have used the two possible answers so far.

The question is: What command string will stop a service named 'red-light'? (full command as the answer).

I answered sc stop 'red-light' and it's marked as incorrect. Then I tried the command Stop-Service -Name 'red-light' and it's also being marked as incorrect.

I need your guidance.

devout lily
#

Hi everyone, the File Transfer module is more indicated for exploitation phase or post-exploitation phase?

tulip urchin
waxen totem
waxen totem
devout lily
waxen totem
waxen totem
#

Active Directory Enumeration and Attacks is before Web Attacks but more likely than not you'll have access to Web first if it's a fully external test

waxen totem
meager yacht
#

And I also tried with net stop and nothing

brave field
brave field
# meager yacht Thanks a lot.

In cmd, you should use double quotes " instead of single quotes when your service name (or any argument) contains special characters or spaces. Single quotes ' don’t work the same way they do in Linux shells like Bash.

#

However, if you’re in PowerShell, both quotes work fine.

meager yacht
#

I see

#

i'm going to write that down

slate matrix
#

Hi new here

fossil jacinth
#

You need credentials for that one

scenic arrow
fossil jacinth
#

Hmm ... did you set the vhost ?

#

and the rhosts

fossil jacinth
#

Or as an alternative, you can specify the folder (I believe it's saved somewhere on the box itself - or maybe you have it in your kali) with -m /home/FolderPath and then search with the filename

scenic arrow
#

Ahh, okay sweet. Thanks!

fossil jacinth
#

šŸ˜‰

fathom pendant
#

module is above tier 0 also don't share info about skill assessments @scenic arrow

scenic arrow
calm abyss
#

Try OneShot

#

YOu still need help with this one ?

#

I finished today, you still need help ?

limber dawn
#

Hey guys, trying myself with module getting started n having some troubles with Public Exploits, mb someone could help me with understanding of finding services?

fathom pendant
limber dawn
#

okay, ty

uneven lava
#

Anyone up for a quick question on ai evasion - foundation?

cyan arch
#

Hi, stuck at bopla / mass assignment one in api attacks, I can create order but I get error when creating items, and really can't figure what's wrong here?.

wintry sonnet
lyric agate
#

Guys, how to learn unethical hacking?

#

Blackhat hacking*

acoustic owl
rich salmon
#

Hi guys. I'm currently doing the malicious document analysis and i'm currently at the analysis of XLL Add-ins. After 6 hrs i somehow managed to get the bin file but when i try to run speakeasy i keep getting the "invalid instructions" error. I've tried speakeasy with different options but i still get the same error. Can somebody help pls?

grave jackal
#

If anyone is free I could use a nudge on Attacking Common Services SMTP, I've been trying to get q2 for a few hours, and with a lot of experimentation, I still don't have the creds for the found user.

grave jackal
fathom pendant
#

@drifting hazel thats illegal, and we dont do that here

twilit cipher
#

Has anyone complete the "Jailbreaks II" module in "Prompt Injection Attacks" module? I have tried everything in the module, read the papers it references and tried a few things from there as well. Any help would be appreciated.

zenith canopy
#

Module name: Attacking common services. When we enumerate users on SMTP or POP3 with the USER command or VRFY, does a returned name like john refer to an email address for that domain or OS level account?

fathom pendant
#

SMTP/POP3/IMAP are all mail protocols, so i wouldn't make broad assumption that its an OS level account when the account could just be somewhere in the system

#

Its hard to make sweeping generalizations as well

zenith canopy
fathom pendant
woeful topaz
#

Can anyone help me out a but, right now I am own my penetration tester path but In the module of pivoting and tunneling, I am sending one dll file for socks over rdp but it's gettting deleted by AV even the thing is mentioned in the module course, but machine is deleting it, and I am not able to solve the challenge.

fathom pendant
#

Google should be your first stop if you're gonna ask how

woeful topaz
#

not that dumb, but thanks!!

woeful topaz
#

But tell me one thing, are we allowed to turn it off during our exams?

fathom pendant
woeful topaz
#

Cool, Thanks!!

worthy condor
#

There was another person in the past having problems with another question in this same module, I am slowly losing my mind on this

fathom pendant
twilit cipher
twilit cipher
# twilit cipher Nevermind, I got it, but I am not sure it was the intended way...

Just for funsies, along with the flag, I got the lab to write a poem about HackTheBox Academy with "flowery" language:

In a field of beauty, where petals sway,
A rare bloom of knowledge, in a special way.
HackTheBox Academy, a place to explore,
Where flowers of wisdom, forever bloom more.
With every petal, a lesson is learned,
And in its center, a hacker is yearned.
A flower of knowledge, that's what it is,
HackTheBox Academy, a place to grow and rise."
worthy condor
frosty crescent
#

Not sure if this is the best place to ask, but I have the student plan on HTB academy, does the VIP plan on HTB Labs add an extra $18 a month or does it include the student plan

twilit cipher
#

Pretty sure it's extra. But not positive...

frosty crescent
#

makes sense

dire lily
#

Hello, I have a quick question about Wappalyzer.

In the HTB module screenshots, Wappalyzer shows the Web Server and Programming Language, but on my VM, it only detects the CDN and jQuery for the same target.

I also noticed nmap shows the ports as filtered. Is this filtered status the reason why Wappalyzer isn't showing the backend tech details?

cloud urchin
viral yoke
#

Just daily reminder you don't have to be working on academy like a regular high school day your brain retains information if you were to work for an hour and then take a break for about 30-50 mins maybe total work time a day 3-4 hours give your mind more time to think on itprayge

unborn stream
#

@everyone I hope someone is up and available to help me with an issue i am having. about answering a question in the "Linux Fundamentals"

cyan arch
daring wigeon
#

Hello can y'all hack servers

rustic quiver
#

anything i did wrong? enabled ssh and everything. And I tried connecting with th http server but it refuses to connect back to me.

autumn pilot
#

You have a typo, look carefully at the end of your command

rustic quiver
civic sinew
#

Hi everyone, I'm taking the SQL Fundamentals Skills Assessment in CWES. I found the hash for the admin, but when I submit it as answer, I get that the answer is not correct. I even looked at the solution, and it's seems the correct hash. I checked the spaces before and after it and also removed the first part of the hash. Could someone help me with this? I am afk for now and will look later. thank already!

junior halo
civic sinew
#

@junior halo yes, start with || ')|| and then follow the course material to get table data etc.

wicked apex
#

Domain Compromised in AEN!
Is there more than one route from DMZ that I can get my way to Domain admin?
Cuz I heard that cpts exam is more linear

near breach
vocal schooner
boreal raven
dusk holly
#

what is best module i can buy in CAPE path for 500 cubes (other than kerberos attacks)?

drowsy grove
#

Hey, if any staff are around you might wanna take a look at the Dynamic Port Forwarding with SSH and SOCKS Tunneling module, the second host seems to be down

#

Same on my local machine, same on the pwnbox

#

can't access it from the pivot host

fathom pendant
#

either that or you need to run powershell as admin

onyx herald
#

Hey guys. Is it just me or someone also have a similar problem. I have been working on the password attack module and under Pass the Certificate section all the IP addresses that i am being provided are not working.
The error message is always the host is down and unreachable.

I have done some parts but now not working at all.
Its either you get a connection for a few minutes and drops or one host will be up and the other one down.

How can i fix this?

fathom pendant
#

reach out to website support; i'd also check to make sure you don't have multiple vpn connections running

fathom pendant
boreal raven
#

I am Stuck on the module Skills Assessment - SQL Injection Fundamentals
the First question "What is the password hash for the user 'admin'? Have obtained the hash but that is not working."

Rest of the question including the last flag is completed but this gives me error, can someone please guide me on this

runic nacelle
#

Hello can anyone Help me with file inclusion
Skills Assessment - File Inclusion I can't bypass this
if (isset($_GET["region"])) {
if (str_contains($_GET["region"], ".") || str_contains($_GET["region"], "/")) {
echo "'region' parameter contains invalid character(s)";

green musk
runic nacelle
strong spruce
#

Hi, I have a question for the Brute-Forcing Password module in the Broken Authentication course.

Towards the end of the module, is says, "Upon providing an incorrect username, the login response contains the message (substring) "Invalid username", therefore, we can use this information to build our ffuf command to brute-force the user's password:"

I double-checked the error message I get on the deployed machine and for an invalid username as well valid username but invalid password, the message is the same: "Invalid username or password". Thus, when I built my ffuf command with this message, I get nothing

I tried the steps as mentioned in the module and though I got the password, I am curious as to this discrepancy. Am I not understanding it correctly ?

hardy jacinth
#

can any one assist me how to install adb?

#

cause I try to install it by sudo but I couldn't

boreal raven
fathom pendant
gray yacht
civic sinew
#

@boreal raven what is whole thing including p= or even more?

gray yacht
nimble tangle
#

hey in the attacking common services easy skill assessment trying to brute force the rdp and ftp with the user and pass lists in the resources gave nothing any help with that ?

inland oak
#

hi ,,
anyone can help me since im stuck on this module almost 1 month.
I need help with module Window Privilege Escalation , the question is " What service is listening on port 8080 (service name not the executable)? "

vocal schooner
nimble tangle
green musk
inland oak
#

Initial Enumeration

#

I hv tried everything.. now exhausted

#

please gimme any hint

green musk
#

Did you see if that service is open using netstat -ano commad?

nimble tangle
green musk
inland oak
#

check this out

green musk
inland oak
#

ok ..

green musk
# inland oak ok ..

Whenever you see some ports open specially 80,443 or 8080 your first instinct should be to look for installed services

fathom pendant
fathom pendant
devout pumice
#

Hi who do I contact about a billing issue. I emailed customerops. They replied asking for more info and seem to have gone into a blackhole, no longer responding to emails.

hexed lintel
latent marsh
#

Can someone help me with Blacklist filter in File upload module - I have tried different extension and some of them says "upload successful" and tried using GET request but I get php code a output

devout pumice
#

@hexed lintel thanks

mint rover
#

Module: API Attacks
Section: Broken Authentication
Question: Exploit another Broken Authentication vulnerability to gain unauthorized access to the customer with the email 'MasonJenkins@ymail.com'. Retrieve their payment options data and submit the flag.
Problem What I am supossed to do with the Password Reset & OTP Endpoints here? šŸ™‚

gray yacht
nimble tangle
#

hey in the attacking common services easy skill assessment trying to brute force the rdp and ftp with the user and pass lists in the resources gave nothing is there anyone who solved that lab might hint me please?

gray yacht
quick folio
#

In the new UI there is no resources button. FYI

nimble tangle
#

@gray yacht can i dm you please

leaden rampart
#

I am running kali-arm64 in my MacBook and i have the BloodHound CE v8.2.0 running. The BloodHound UI have no Analysis tab, and does not automatically render a graph view. Does your BloodHound CE behave the same way?

gray yacht
wheat orbit
#

One message removed from a suspended account.

hollow kernel
#

you can transfer the txt

stoic anchor
#

Hey everyone, I'm working on the new file inclusion skills assessment and could use a small hint. I've successfully identified an Arbitrary File Read vulnerability, which I used to discover an Unrestricted File Upload vulnerability. I can upload a PHP shell to the /uploads/ directory and can predict its MD5-hashed filename. However, direct access to the shell is blocked by a deny all rule in the Nginx configuration, resulting in a 403 error.

I feel like I'm just one step away but am missing a small detail. Any pointers would be appreciated!

UPDATE:

Look at the contact.php source code page šŸ˜‰

wheat orbit
hollow kernel
#

pyhton -m http.server port and i your machine wget://victimip:port, you can see this en transfer methods

wheat orbit
hollow kernel
#

or try to do python -c 'import pty; pty.spawn("/bin/sh")' to give a interactive shell in linux

wheat orbit
wheat orbit
zenith canopy
#

Module: Attacking common services, does this mean that both entries are linked servers, but isremote = 0 means it is another database instance on the same machine?

tiny pendant
#

hello guys!
i am on the passwords skill assessment
i got creds from DMZ01 and pivoted using ligolo everything is working fine but i cant rdp into the next target?
i added everything into etc/hosts but still getting an error. nmap shows the port is open and NC shows the same

green musk
rustic geode
#

what is the best free nmap course

dawn gazelle
#

This is going to be a very generic, often asked question, but i want to know. Where should i start learning if i want to become advanced in this field?

gray yacht
compact patrolBOT
storm elk
#

šŸ‘† @dawn gazelle

dawn gazelle
#

Oh w

junior halo
boreal raven
heavy slate
#

AI Data Attacks + Pickles and Stenography - can i do it in Pwnbox or do i have to set up my own linux vm?

meager hill
#

any tips on the LLM Output attack final assignment? Stuck for days

fathom pendant
noble spire
#

hello I tried using your method, which involves using the password provided in the example (ā€œpentester3ā€), but it neither enabled OTP via SMS nor OTP via email. I also tried brute-forcing the password.

Additionally, I attempted to brute-force the OTP while passing the correct endpoint for the password reset, but that didn’t work either.

this is the quations in api attacks Broken Authentication
Exploit another Broken Authentication vulnerability to gain unauthorized access to the customer with the email 'MasonJenkins@ymail.com'. Retrieve their payment options data and submit the flag.

plain summit
#

Is there a module for Immunity Debugger setup/mona setup?

plain summit
zenith token
#

Hello There
I am currently working on the Module "Cracking Passwords with Hashcat" section "Cracking common hashes".
Could anyone give me some help regarding the question of cracking the following hash: 7106812752615cdfe427e01b98cd4083 ?

tawny quiver
#

I am working on the password attacks module. I'm logged into HTB on a Kali VM and I tried downloading the vpn link, starting the machine, but when I try to launch the openvpn file it just stops here:

oblique plume
#

Is there a module admin I can speak to about some lab issues I experienced in the Attacking WPA3 Wi-Fi Networks module? The training does not correctly outline the TTP for OWE Evil Twins

junior halo
fathom pendant
compact patrolBOT
fathom pendant
rare condor
#

hi

#

Working through the foothold is quite painful (it's extremely slow and keeps freezing up).

#

sometimes I think the paths haven't been updated .

wicked girder
#

You can open another terminal or use 'sudo -b openvpn "your_file_goes_here"' instead

errant moss
#

Hello!
I could use a hand on

Active Directory Enumeration & Attacks
Attacking Domain Trusts - Child -> Parent Trusts - from Linux

I'm supposed to get the NT hash of user "bross" but so far not going so well and I think I'm missing something. Anyone available to help?

uneven lava
#

Did you solve it?

hidden ledge
#

java/jsp_shell_reverse_tcp try this one with a netcat listener, I had same issue for some reasons

tiny frigate
#

In Active Directory Enumeration & Attacks > Credentialed Enumeration - from Windows ( https://academy.hackthebox.com/module/143/section/1421 ), I can't connect to the target? I copy-pasted IP, username, and password to be sure, and tried both xfreerdp and xfreerdp3 after installing that on Pwnbox...what am I missing here?

#

Never mind, just had to reset the target AGAIN, lol

glacial minnow
#

could someone hint me on why my php code is not executing, i managed to bypassed the filter and i ive tried null byte char and still didnt execute

fathom pendant
#

Also; your php code isn't taking any parameters

glacial minnow
#

yeah but that's just 1 attempt, i forgot to remove the query param

warm knot
#

Need help with connecting using the vpn for the academy modules. Is this the right place to get help?

cloud urchin
#

You can ask here but the website is the only official support

warm knot
#

Yup, did everything in that guide. The issue is I'm getting a no route to host despite the routes being established.

(base) ā”Œā”€ā”€(nuvious㉿kalimini)-[~/Code/HTBAcademy]
└─$ ip route                    
default via 192.168.11.1 dev wlan0 proto dhcp src 192.168.11.204 metric 600 
10.10.8.0/22 via 10.10.14.1 dev tun0 
10.10.14.0/23 dev tun0 proto kernel scope link src 10.10.14.2 
10.129.0.0/16 via 10.10.14.1 dev tun0 
172.17.0.0/16 dev docker0 proto kernel scope link src 172.17.0.1 linkdown 
192.168.11.0/24 dev wlan0 proto kernel scope link src 192.168.11.204 metric 600 
                                                                                                                                 
(base) ā”Œā”€ā”€(nuvious㉿kalimini)-[~/Code/HTBAcademy]
└─$ ssh htb-student@10.129.71.56
ssh: connect to host 10.129.71.56 port 22: No route to host

This is in the linux fundamentals section. The instance is reported to be up under that specific IP, it just isn't connecting even though the route is populated.

#

Going to try restarting the instance, but given it's a routing issue I'm not sure that will do anything.

#

Bounced it again, got a different IP but same result.

cyan veldt
#

can anyone help me in using web proxies Repeating Requests section?

#

idk which one of these are the flag

#

(its not flag.txt)

waxen totem
waxen totem
cyan veldt
waxen totem
cyan veldt
waxen totem
waxen totem
warm knot
waxen totem
compact patrolBOT
warm knot
#

Thanks!

rain mirage
#

PIVOTING, TUNNELING, AND PORT FORWARDING
Skills Assessment:

In previous pentests against Inlanefreight, we have seen that they have a bad habit of utilizing accounts with services in a way that exposes the users credentials and the network as a whole. What user is vulnerable?

i saw the hint it says i will probably get the password in the lsass , so i assume that i need to transfer the lsass to my attacker host and decrepit it ... so to transfer the lsass i tried .. transferring nc (its not accepting any packets) , scp (did not work) , and i have tryed alot to somehow get the lsass to my attacker host but cant .

#

any hint ?

cyan arch
#

Hey, stuck on api attacks skills assessment. I have broken access on products but nothing too interesting from there. Then I see a way to reset supplier password , got a list of interesting emails (5) and tried seclists htlm-colors as well as custom wordlist but still can't seem to crack reset their passwords? Could anyone give me a nudge?

#

also tried sqli there but failed

leaden basin
#

morning all šŸ™‚

green kernel
#

There's no official support on disscord

devout lily
#

Hi everyone, does someone know how to solve this?

#

VM language is italian

wanton ferry
#

Bounced it again, got a different IP but same result.

cyan veldt
#

do I add the DIRECTORY path?

#

or the request should include that?

crystal cliff
daring lava
#

Hi, i'm in the Getting Started module of the Penetration Tester path. In the Basic Tools section there's an optional exercise at the end of it, that says to grab the banner of the server. I run this netcat on port 22 and it gives me

SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u7

However when I reveal the answer on the exercise, it says the answer is
SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.1

prisma flame
#

Hello

daring lava
#

Nevermind, I'm an idiot. I figured it out. TY!

fathom pendant
worthy sorrel
#

anyone solved file inclusion updated skill assessment

worthy sorrel
#

Can you help a bit I got the param got lfi able to read logs put a webshell unable to execute it

worthy sorrel
worthy sorrel
#

How we will get it exeucted

fathom pendant
gray yacht
weary crow
#

Can someone help me out on the graphql module

green musk
green musk
green musk
wooden ivy
#

Android Application Dynamic Analysis > Dynamic Code Instrumentation > Hooking Native Methods is using Frida 16 and Module.findBaseAddress('libangler.so'); in its Code Snippet. However since Frida 17 this method was removed and replaced by Process.getModuleByName('libangler.so').base. Using the Frida 17 approach I'm always getting Error: unable to find module 'libangler.so'. Does someone have a working snippet for this module?

silent basin
#

Attacking Windows Credentials…..Can someone help me understand how we get minkatz onto the target system???

weary crow
green musk
#

Can someone nudge me with sql injection skill assessment like after doing the first step I’m struggling to find valid link where sql is vulnerable I tried every damm SQLi discovery on both search boxes

fathom pendant
#

it helps to know the module and section

green musk
fathom pendant
green musk
fathom pendant
#

there's multiple 'sql injection' modules

green musk
fathom pendant
#

i take it you found a way to log in already

green musk
fathom pendant
#

try manipulating the q

worthy sorrel
green musk
worthy sorrel
#

Uploading?

weary crow
#

Hey bro can I some help on attacking graphql module

worthy sorrel
#

In file inclusion. We have to upload the file

#

There is no upload.php I tried accessing but this page does not exist

#

Oh okay

#

There in the pdf

fathom pendant
#

take it to dms so we're not spoiling module content above tier 0 šŸ˜‰

worthy sorrel
#

Oh okay going to do it but for reference can I dm so

fathom pendant
weary crow
#

I'm working on the first section of the module