#modules

1 messages · Page 474 of 1

crisp nacelle
#

dont think so

#

its just an ip and port

limpid void
#

let me dm you

crisp nacelle
#

ok

fathom pendant
#

Use the udp vpn

brittle basin
dark hatch
#

Hello! Is anyone willing to help me with Question 3 from the CrackMapExec Skill Assessment? I've been stuck on this for so long. I will really appreciate it! If I can DM someone or discuss some hint here, any support will be appreciated!

solemn prawn
#

In the DNSAdmin privilege escalation module I can start dns service, and also don't have the permission to remove registry key. Am I missing something as the provided solution also does it the same.

cloud urchin
#

@solemn prawn Please take care not to post content from modules above tier 0

#

If you go over the section again you'll see you need to run it under a certain context

terse galleon
#

Somehow, in DP-SGD Challenge of Ai Privacy Modules, uploading models always return {'error': 'Evaluation timed out. Model may be malformed or causing issues.'}. Even the given solution as well. Is this possibly a platform-side problem, or are there specific constraints that might cause this timeout?

limber surge
#

can some one nudge me for this.

API Attacks -> Broken Object Property Level Authorization -> Exploit another Mass Assignment vulnerability and submit the flag.

fallen trail
#

Hello. Windows Lateral Movement skill assesstment. There is no way I can get a reverse shell in question 5. The solution proposed by HTB does not work and using my own PS shell does not also. I can ping the machines, so they see themselves, I can execute PS, but something fails. Thanks

reef axle
#

Hello, Im struggling with

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \\DC01\julio. of Password Attack Module

Ive reached till here but I cant figure out whats next.

Ticket cache: FILE:/tmp/krb5cc_647401106_HRJDux
Default principal: julio@INLANEFREIGHT.HTB

Valid starting       Expires              Service principal
10/07/2022 11:32:01  10/07/2022 21:32:01  krbtgt/INLANEFREIGHT.HTB@INLANEFREIGHT.HTB
    renew until 10/08/2022 11:32:01
#

Now trying smb ```root@linux01:/tmp# smbclient //dc01/julio -k -c ls
gensec_spnego_client_negTokenInit_step: gse_krb5: creating NEG_TOKEN_INIT for cifs/dc01 failed (next[(null)]): NT_STATUS_INVALID_PARAMETER
session setup failed: NT_STATUS_INVALID_PARAMETER


gets me to this error
#

tried to ip too

dark hatch
#

Hey! Is anyone able to give me a small hint for Question 3 of the CME Skill Assessment? I’ve been stuck for a while.
I got the NTLMv2 hashes for DEV01 and SQL01, plus 4 accounts. Would really appreciate a nudge in the right direction.

zenith acorn
#

yey another module bites the dust

#

thatw a ssome fuzzing fun

#

only completed it becaus eof my completionist mentality

#

but learned some new tricks thorugh

vale narwhal
#

I test the skill assessments with ligolo work fine.

fathom pendant
dark hatch
# dark hatch Hey! Is anyone able to give me a small hint for Question 3 of the CME Skill Asse...

Hey! Is anyone able to give me a small hint for Question 3 of the CME Skill Assessment? I’ve been stuck for a while.
I got the NTLMv2 hashes for DEV01 and SQL01, plus 4 accounts. Would really appreciate a nudge in the right direction. Tried responder + drop-sc on DEV_Intern share; captured only the hashes of the DEV01$ and SQL01$ machines, never got James. Tried Responder + scuffy on DEV Intern, same results. Responder + slinkly -> access denied on share. I have Jte, in30, Al, and sqev creds so far.

reef axle
# fathom pendant looks like that ticket is far expired maybe there's an unexpired one 😉
Ticket cache: FILE:/tmp/krb5cc_647401106_muRVgr
Default principal: julio@INLANEFREIGHT.HTB

Valid starting       Expires              Service principal
03/01/2026 15:00:00  03/02/2026 01:00:00  krbtgt/INLANEFREIGHT.HTB@INLANEFREIGHT.HTB
    renew until 03/02/2026 15:00:00```

```root@linux01:/tmp# smbclient //dc01/julio -k -c ls
gensec_spnego_client_negTokenInit_step: Could not find a suitable mechtype in NEG_TOKEN_INIT```

Again tried with the valid ticket.
#

I tried the IP too instead of DC01

#

moving the ticket from /tmp to /home worked

red cypress
#

how about you try -A

brittle basin
red cypress
foggy jackal
#

guys, i need help with the first question of esc4 attacks..Abuse ESC4 to change the configuration for the template ESC4. Afterward, submit the value of the property Certificate Name Flag.
it doesnt accept any answer i input..could someone help me out on this?
nvm i got it finally

dark hatch
#

Hello! Can I DM anyone about the CrackMapExec Skill Assessment Question 3?

cedar forum
#

the machines on the "Introduction to the WIndows Commandline" module won't start FeelsBadMan

#

is anyone experiencing a similar problem?

foggy jackal
#

guys for adcs attacks module..the ntlm relay section. i am not able to coerce the authentication. and when i ping the 172.16.19.5 it shows this $ ping ws01.lab.local PING ws01.lab.local (172.16.19.5) 56(84) bytes of data. From 172.16.19.19 icmp_seq=1 Destination Host Unreachable From 172.16.19.19 icmp_seq=2 Destination Host Unreachable From 172.16.19.19 icmp_seq=3 Destination Host Unreachable From 172.16.19.19 icmp_seq=4 Destination Host Unreachable
did anyone face this issue?

vagrant wraith
#

nvm i got a shell! lol

fathom pendant
quick cloud
#

Hey , i need help in solving nmaps firewall bypassing labs i stuck at the hard lab i can only get the 53 port as filterd i cant bypass the firewall dont know whats to do can pllease anyone help me?

gray yacht
fathom pendant
cobalt quest
#

Anyone having issues with targets spawning at the moment?

#

nvm came up, just took a long time

quasi wave
#

hi I am doing the automatic modifications section of web proxies module. I need some help with following along with the tutorial. I tried setting it up according to what the instructions said to do but it still requires me to enter in a number each time I refresh the page or go back. Can someone help me out here?

#

I'm following instructions but its not working. if someone with a CPTS, CWES or CWEE is available for a DM that would be splendid

#

please let me know

#

I need this so I can continue with the web proxes module

reef gyro
quasi wave
#

the user agent requests won't update either

#

can someone help me out here?

#

please DM if you are available

crystal lion
#

how is it possible that ntlm relay works without a responder?

#

I am currently working on the NTLM Cross-protocol Relay Attacks module, last question (Use impacket's SOCKS server to hold NPORT's relayed connections and abuse them to access the MSSQL service at 172.16.117.60; query the 'flag' table within the 'development01' database and submit the flag). I had errors with the responder, but after turning it off, it suddenly worked

gaunt fox
#

hi, just started on my linux module i came across the question which kernel release is installed on the system? i found out just how but it doens't give the green light. tried multiple command all came at the same answer too??

fathom pendant
#

are you ssh into the target system (note that "spawn instance" is not the same as "spawn target"

gaunt fox
devout turtle
#

Hi team, I am having an issue with "Network Services" within the "Password Attacks" module.

for some reason the "flag.txt" file is empty.

As you can see in this screenshot.

Can you please let me know if this is something from your end or I am just being stupid please?

devout turtle
fathom pendant
quasi wave
quasi wave
quasi wave
cloud urchin
#

@shell glacier Please take care not to post content from modules above tier 0. You're showing a lot of info from the module there. Anyone who has completed it and can help doesn't need all that extra stuff. Just ask your question without revealing sensitive info please.

shell glacier
#

my bad, i got the issue, i was on WSL and i guess that has something to do with the virtualization? im not sure

#

my only questions is now, why does WSL affect whether i can crack the pin with reaver or not?

quasi wave
#

hi @cloud urchin can I DM you tomorrow to ask some questions about the Automatic Modifications section of the Web Proxies Module?

#

what time are you available?

#

I'm gonna attempt it one more time tomorrow and we'll see I think I can get it then

#

but if not I was thinking I could message you

#

or is anyone else available for DM anytime tomorrow?

cloud urchin
#

You'll have to ask me tomorrow, but it's been a long long time since I did that module so someone else who did it more recently may be able to better help.

boreal vine
#

guys, I am wondering about the very first section in Linux Privesc of CPTS, the "Environment Enumeration" one

#

I did manage to go into /root and grab the flag but it's incorrect for some reasons

#

is that a bug or I am missing something ?

green mulch
boreal vine
#

pretty sure there isn't, can I share the flag here or somewhere ?

boreal vine
#

so a private DM maybe ?

green mulch
boreal vine
#

that's fair, thank btw, I will just wait for someone else

surreal mortar
#

Paypal was removed as the billing option for academy? I wanted to get the student monthly plan but only shows credit card as the payment method, kinda defeats the point.

cloud urchin
#

defeats the point? no it doesn't lol. just pay with your debit instead.

#

i don't recall paypal being an option there but that doesn't mean it wasn't

jovial walrus
#

File Inclusion module log poisoning - Server log poisoning I am modifying my user agent but it is not visible in the response?

waxen totem
quick cloud
restive marsh
#

hello

#

i have a question

#

i stuck in Broken Authentication Brute-Forcing Password Reset Tokens
in that question "Takeover another user's account on the target system to obtain the flag."
can anyone help me

restive marsh
#

yes

#
seq -w 0 999999 > token.txt
rare lava
#

I think the question asks for 4 digit token

restive marsh
#

really?

rare lava
#

Yeah, try for yourself

restive marsh
#

solved it

#

thx

rare lava
#

np

jovial walrus
normal pecan
#

anyone from asia experiencing lag from academy ? is it the same for the exam cus theres no other vpn than eu and us only ?

glad flicker
jovial walrus
glad flicker
#

well if you take a look at some log entries you'll see that one entry will usually, for example, include the http response code - 404, 200 etc

#

consider the primary purpose of the logging being to track functionality of the webserver. It doesn't assume that you're handling authentication events or sensitive data - it just wants to log each request and its outcome

#

if you logged every response separate to the request, you would immediately double the size of the logs (almost). At scale, that's very bad for storage costs and CPU thread utilization

#

they'd also be much harder to analyse as you'd have to correlate the two separate parts

turbid scarab
#

Anynone else also problems with spawning targets? Cant spawn targets since 30 Minutes. US ans EU VPNs

scenic parcel
dim hound
#

Does other ppl have this too ?

turbid scarab
dim hound
rare lava
#

Web Attacks Module - Bypassing Encoded References;
The question says either use contract parameter or .pdf file name. I've solved it by using contract parameter and now trying to get the answer by using file name.
I made a list of pdf names by hashing but just can't find where do i fuzz them.
Need some help pls.

tough totem
dim hound
#

Yup! Indeed 😁

shell glacier
# fathom pendant Because; tl;dr WSL sucks

according to claude/GPT

WSL doesn't have real WiFi adapter access — it can't pass through wireless NICs to the kernel in a way that supports monitor mode or raw packet injection
No nl80211 support — WSL's kernel lacks the wireless stack needed for tools like reaver, airmon-ng, and airodump-ng to work properly
EAPOL packets never actually transmitted — what you were seeing was the simulated lab AP, but reaver couldn't complete the handshake because WSL was dropping/mangling the raw frames

A VM (VirtualBox, VMware) works because:

You can pass through a USB WiFi adapter in monitor-mode-capable mode
The full Linux kernel wireless stack is available
Raw packet injection works as expected

shell glacier
#

well now...i think both answers are suffice

delicate void
#

Is anyone having trouble installing the "sqlcmd" command on the new Parrot OS? Or can someone help with how they did it?

fathom pendant
#

sqlcmd isn't installable on ParrotOS; it's not in the repos

stone shoal
#

hello guys
is it normal that it takes forever for subbrute to find a subdomain in attacking DNS(on attacking common services) !!!
I don't get it

autumn gulch
#

I am facing issue in Active directory Module Skill assessment Part 1. Issue is with proxychains. Can someone help me !

#

I am getting this error

#

even nmap scan says host is up but all ports are filtered.

brave field
autumn gulch
#

It's running i am using metasploit module

brave field
spiral hollow
#

For the windows attack and defense: AS-REProasting section, I perform the attack and when I check the DC1 server to find the log for svc-iam, nothing is logged in the event viewer for svc-iam... what am i doing wrong.

autumn gulch
#

Thansk for the nudge

grizzled schooner
#

Probably the 10th time I've asked. Working through AEN, can't seem to get the Priv Esc to work. It worked once before, I'm using the same syntax as I was previously, but the reverse shell isn't working on DEV01 --> DMZ. Can anyone lend a hand? Please @ with replies

young tinsel
#

having some trouble w/ the Attacking SMB section of Attacking Common Services, could someone give me a hand?

high citrus
#

Guys i just did the section 3, about interfaces of the Wi-Fi PT Basics Module, i would like to know if the fact that the ||txpower wasnt changing in the iwconfig but still worked to find the requested ESSID is normal or not||

hidden urchin
#

i have tried logout login, refreshing the page changing my network nothing helps

compact temple
#

Might be a bigger issue. I cannot spawn target on Advanced SQL Injections > Error-Based SQL from the CWEE path. I had no issues couple of hours ago.

barren crystal
#

targets having issues spawning on new ui?

compact temple
#

I'm on old one still

#

logged a ticket with support

barren crystal
#

alright must be just in general then, guess ill come back to academy in a bit

compact temple
#

status page shows no issues tho shrug

coarse trout
#

Same for me

stark hedge
#

same issue

lost stirrup
#

Same

viral lotus
#

not sure if it has fixed for others but mine has been fine, on Kerberos module. I terminated it a respawned it and its fine.

wintry pagoda
#

same issue here

devout turtle
pseudo bane
#

is this assesment bugged ? HTTP Misconfigurations - Skills Assessment - Hard i restarted 3 times and followed the steps in solution but still not runnign, sorry if this is not the correct place for this

rugged hull
#

Is this a bug? It said "Targets are spawning" but 20 secs later it turned back into "Click here to spawn the target system". I've tried changing my Pwnbox's locations and VPN Servers but it did not work.

cloud urchin
languid fjord
#

hi,
yes we are aware of issues with targets, this is affecting eu servers

#

try using other regions for now

whole kindle
#

Ive tried UK and AU, nothing working

crystal lion
whole kindle
#

yeah, I've just noticed that, im doing that now. Thank you

young tinsel
jovial walrus
#

cwee should be as a prerequisite to file inclusion skiils assessment fml

junior thicket
#

idk why it is not starting

#

i click many times but it doesn't give me any ip to test

fathom pendant
#

for those struggling try switching to the US vpn servers

junior thicket
junior thicket
jovial walrus
#

even claude is down

#

htb as well as htb assistance provider both r down

junior thicket
#

oh that's the case

brave field
autumn gulch
#

I am unable to rdp into the target machine . Can anyone help here

eternal zealot
#

Can anyone help explain why I've ran into this issue? For the last 2 days I've been trying to hack the 'Firewall and IDS/IPS Evasion - Medium Lab' module, but I kept getting a useless result from the scans. I was sure I had tried everything in the module, so I went looking online and found someone that said that using PwnBox instead of a Kali VM worked for them. I tried the simplest command I had used on kali on PwnBox and voila: immediately got the flag. Why is this happening and, more importantly: what is the risk of this happening when doing the CPTS exam? I don't want to somehow get stuck because of a weird networking bug with the VPN. Also not keen on using PwnBox instead of a normal Kali VM with VPN.

brave field
eternal zealot
viral lotus
#

I am going to assume there is a bit of a general networking issue with academy at the minute? my instances are loading but my rdp sessions keep being kicked out whether via pwnbox or via vm over vpn.

stark hedge
grizzled schooner
autumn gulch
#

Can someone tell me why this is not working . I am doing AD Enumeration & Attacks - Skills Assessment Part II.

pseudo kiln
#

Anyone else having sudden issues with academy?

#

well USA vpn seems to work, while EU is down

#

this is becoming recurrent....

sturdy sandal
#

Hi all, having issues with "MSSQL, Exchange and SCCM Attacks" module. In the "Exchange" section, "Enumeration", I can connect to the OWA but when I try to login with given credentials, it returns a 500 error...I looked at the answer and it is exactly what I am trying to achieve. The lab is up for more than 10 minutes. Anyone else encountered this issue ?

sturdy sandal
#

Switching back to EU solved the issue...

spiral hollow
#

In Windows Attack and Defense, why doesn't anything get logged on the DC1 server, I look for the logs I am supposedly making when performing attacks but they don't get logged. Anyone can explain why? Do I actively have to RDP to the server first then perform attacks?

#

seems like this has been an ongoing issue with the module, people in this discord has had this issue since 2025 as well.

rotund trellis
#

Just some feedback for the new UI for Academy. Copying code blocks from the new UI does not format it properly in Markdown, the old UI works great. For example, copying this code from the new Academy UI to Obsidian looks like this

humble hemlock
vocal holly
#

In "Attacking Drupal" topic lab, you need to explicitly enable PHP code for your user (even if it's administrator). Configuration -> Content authoring -> Text formats
From there you will be able to enable it and then PHP will show in your options.
Pls note that you also have to enable PHP filter module for the site and install it if it isn't there.

keen onyx
#

Can someone give me a sanity check for Attacking Common Applications - Attacking Splunk? The instructions make it seem like it's just --> scan to figure out Windows vs. Linux --> edit the script in /bin to have your IP and Port --> tar (or spl) --> listener --> upload --> shell. I've tried both tar.gz and spl, I've tried editing the apps permissions on Splunk, disabling and reenabling, and restarting the target, but no matter what I do my listener doesn't catch the shell. Maybe I have to edit the config file? I'm probably just missing something stupid, but I can't seem to figure it out. Any pointers are appreciated, thanks!

keen onyx
#

From what I remember, the first step in the skills assessment doesn't use a double extension

#

try to think of ways to get more information

cloud urchin
#

@soft moon
Please take care not to post content from modules above tier 0..

cloud urchin
# soft moon sorry

No worries, you can just ask your question without the pics. Someone who has done the module doesn't need that extra context.

soft moon
scenic parcel
soft moon
#

ok through problem solving i figured it out instead of creating my own i just used and edited a image already

faint hill
#

Working my way through the DACL Attacks II skill assessment (Question 2 of 3). I am trying to obtain credentials. One set I have, the other I am trying to catch via a method not covered in the module; but it's going nowhere. Anyone who has done the module available for a DM session to discuss / help with a nudge in the right direction?

gray yacht
faint hill
gray yacht
#

Have you tried mimikatz?

faint hill
#

I have dumped local admin yup.... with secretsdump.... but a DM session is way more appropriate than public exchange

gilded socket
#

Hi, I'm stuck on Advanced SQL Injections in Part 2 of the Skills Assessment. Could someone help me? I'm out of ideas for attacks.

tender nimbus
#

Hey guys question about the NetExec tool. as you can see in the picture I do a bruteforce attack against a DC, what I saw online(and what you can see in on the picture) the DC is associated to the dac.local domain. What I want to understand is the follow: Why does the bruteforce happen on inlanefreight.local (since the domain of the dc is dac.local) + how does it know that he need to attempt the bruteforce against the inlanefreight.local since the domain is not specified in the command?

#

command:

#

Spritzouu@htb[/htb]$ netexec smb 10.129.201.57 -u bwilliamson -p /usr/share/wordlists/fasttrack.txt

SMB 10.129.201.57 445 DC01 [*] Windows 10.0 Build 17763 x64 (name:DC-PAC) (domain:dac.local) (signing:True) (SMBv1:False)
SMB 10.129.201.57 445 DC01 [-] inlanefrieght.local\bwilliamson:winter2017 STATUS_LOGON_FAILURE
SMB 10.129.201.57 445 DC01 [-] inlanefrieght.local\bwilliamson:winter2016 STATUS_LOGON_FAILURE
SMB 10.129.201.57 445 DC01 [-] inlanefrieght.local\bwilliamson:winter2015 STATUS_LOGON_FAILURE
SMB 10.129.201.57 445 DC01 [-] inlanefrieght.local\bwilliamson:winter2014 STATUS_LOGON_FAILURE
SMB 10.129.201.57 445 DC01 [-] inlanefrieght.local\bwilliamson:winter2013 STATUS_LOGON_FAILURE
SMB 10.129.201.57 445 DC01 [-] inlanefrieght.local\bwilliamson:P@55w0rd STATUS_LOGON_FAILURE
SMB 10.129.201.57 445 DC01 [-] inlanefrieght.local\bwilliamson:P@ssw0rd! STATUS_LOGON_FAILURE
SMB 10.129.201.57 445 DC01 [+] inlanefrieght.local\bwilliamson:P@55w0rd

ancient niche
#

ey guys i need help with machine of box i don't have any listenning ports

#

and i don't know why

#

unified machine

cloud urchin
fervent ether
#

Can anyone lend a hand with the sliver modules

#

Got a couple outstanding questions that ive missed

mellow latch
mellow latch
# mellow latch

I've also tried various ACL rules and stuff, but to no avail

gray yacht
mellow latch
# gray yacht The privilege doesn't have to be an enabled one.

so I tried the other one too and now I'm kinda like?? (neither works haha =/ )


PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State
============================= ============================== ========
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
gray yacht
quaint vale
#

Module: Active Directory Trust Attacks
Section: Skills Assessment
Question: Gain access to the DC03 (Apexcargo.ad) and submit the contents of the flag located in "C:\Users\Administrator\Desktop\flag.txt"

|| SID History Injection I believe is the right path, but it is not working at the moment ||

Any help?

mellow latch
plain adder
#

Hello y'all. I've been working on the module "Windows Event Logs > Logging Basics", and i confused with the exercises. I have two questions:

  1. The correct .evtx for the exercises is "DLLHijack", right?

  2. Is needed to use the security logs and not the sysmon?

sly kelp
copper dune
#

Hi i'm finding some troubles with this exercise https://academy.hackthebox.com/module/21/section/135 basically it looks like is falling because it is deprecated, does some body know how to solve it ?

the question

Create a "For" loop that encodes the variable "var" 28 times in "base64". The number of characters in the 28th hash is the value that must be assigned to the "salt" variable.

fathom pendant
#

@copper dune the module is above tier 0, avoid sharing things from it

modest vigil
#

whats wrong with the sql injection skill assessment" site?

copper dune
#

@fathom pendant my bad, sorry, do you know which channel or channels can i use to get some help about this and possible future similar issues ?

fathom pendant
#

People who have done the module generally dont need all of that info

#

Also you're using the wrong thing to count @copper dune ; the module expects echo $var | wc -m

#

Not the built-in feature to count length

copper dune
#

Thank you so much @fathom pendant

fathom pendant
#

it's $var not $salt

#

but the principle is the same

faint gulch
#

Is there any ongoing issue on the platform that does not allow for the targets to be spawned by any chance, or it is just me?

pale island
#

Does anybody have a reliable way to rdp to the module boxes? I keep getting disconnected and now i am just stuck at the last 3 modules (attacking common applications)

jovial walrus
#

I couldnt quite get an understanding of whitelist filter in file upload attacks module specially the double extensions and reverse double extension part

#

we just reversed shell.jpg.php to shell.php.jpg

#

r they trying to say we should try the reverse of all double extensions while fuzzing?

pale island
jovial walrus
#

This new UI is gonna make my eyes bleed

rugged hull
#

Damn me too

#

Why do you guys change the UI? It's so unnecessary.

humble hemlock
#

This evasion module having me create 564 C# executables 😂

keen cliff
#

just finished the first 3 modules, about to start footprinting

#

been hearing its LONG

tidal kelp
#

the UI sure is a downgrade :S

pallid gate
#

it's not null session, it's guest session try:
nxc smb ip -u "something" -p '' --shares

hidden ledge
crude grove
#

bring back the old UI please or make this "table of content" smaller and remove progress bar from below,the actual content of the module has less space of the screen.

crude grove
fresh vector
#

anyone else having issues spawning pwn box?

brave field
pallid gate
#

you can also enable guest flag but it's not by default, on nxc.conf

thin hearth
#

I find a pretty useful point of the new UI is that now it doesn’t bug out when I create another tab and zoom the screen to 100% to use pwnbox. but new UI very slow

brave field
hidden urchin
#

it's been 4 days i'm getting this much Latency on all the server i've tried changing my own network but the issue presist ??

#

this have been the case for me for all the academy modules

eternal vigil
hidden urchin
eternal vigil
#

The worst part is we can’t copy the code blocks anymore and its more scrolling less reading

hidden urchin
#

yeah

crystal lion
#

Why have you changed the UI? The previous one was perfect...

green mulch
humble hemlock
#

I am at "Introduction to Windows Evasion Techniques". Regarding the Skill Assessment I.

I managed to get a revershell with some spaghetti C# code, I would like to know how can I make it better, if someone completed the module, please let me know. I can share proof of successful exploitation so no cheating here.

solid pewter
swift aspen
#

How can I get the "old" UI in the HTB Academy back? I dislike the new UI. The "old" UI was perfect.

green mulch
#

No rollback

cobalt quest
solid pewter
#

yes that is what im getting as well

ebon spoke
#

Hi guys, I'm really struggling to get promox to connect to the web page, it keeps saying "refusing to connect" no matter what i try. any suggestions on what to do? im still new so im learning how to set up vm's but i cannot get it to even open the web page url

heavy sluice
cosmic vine
#

sticky header + sticky footer + huge whitespace on left + table of contents taking up half the screen = 25% of visible screen is actually useful. maybe it's easier to navigate on mobile than before but desktop is slow unpleasant. usernames and passwords are easier to copy so that's nice at least.

median crane
#

Is Pwnbox down rn?

#

I can’t access it rn it says “no available instances right now”

reef axle
#

There shold be a option to use old UI

#

New one is not lit as previous

#

Seems like completly vibe coded

digital rain
hidden urchin
reef axle
#

Once I drop the section I cant evern close it

#

I have to click the other section close, to close that I have to click the other section, to close that I have to select the otehr section.

stoic cove
#

Hi,

I was wondering if I can reset my progress for a module. Like, if I can remove the answers I have given and do it all over again.

Thanks

stoic cove
reef axle
#

Am I only one facing this issue on academy

#

Tried multiple regions

balmy grove
fresh vector
#

ive found that when this happens, I usually have to wait a day to be able to spawn the pwnbox

solid pewter
#

really a whole day? wow thats a long time. I hope not cause i would like to get more done today. @violet umbra can we find that out and how we can get this started. Its a real bummer 🙁 thanks

fresh vector
solid pewter
#

Oh ok i guess something is up with the server side of things in the cloud where they host the machines

fresh vector
#

Thats what I think is going on, im not sure, I noticed though that at 8:30 MST is when I wasnt able to spawn the pwn box anymore. so thats before the ui update, but i was on the new ui as well. So maybe something on the backend like you said

gray yacht
golden torrent
#

where can I download the vpn ?

acoustic forge
#

Looking at the new site - very nice - is there any reason why you can search for "Not Completed" in the status

languid fjord
#

We are having issues with our upstream provider that is impacting PwnBox, we are looking into the matter

acoustic forge
humble hemlock
#

Got the same issue, did you figure it out ?

#

You found the reason for the timeout ? am at the exact same Timeout

fathom pendant
stark hedge
#

could someone help me with Q4 MSSQL, Exchange, and SCCM Attacks please?

humble hemlock
#

Alright nevermind guys, I figured it out

#

The script timedout when multiple .ps1 scripts where chained

#

Executing the VBS manually works with bypasses and all, but when the bot runs it, it fails

quasi wave
#

the sectionI thought was too hard two days ago when I was sick turned out to be easy

#

now I'm doing the next section which is harder but I'm gonna come back to it tomorrow

#

SCALE is going great

#

gonna attend a workshop at 2PM

jagged zenith
#

The old version(htb academy) is better than this one this version is very slow compared to the previous version.

jagged zenith
#

I am facing a problem due to the website’s new update every minute, these annoying messages keep appearing.

fathom pendant
jagged zenith
fathom pendant
#

Its been fairly responsive for me so idk

jagged zenith
#

The old version is better and easier to use.

fathom pendant
#

Staff dont regularly check the discord, thats why I said reach out to support. Perhaps something funky is going on with your account thats creating a niche issue

hollow bolt
#

I am used to the old UI !!! so simple ! I feel like i can't study in this new UI >.<

lilac palm
#

Does the new UI affords viewing the paths that include some module? I could see it in the details for the module before.

harsh cove
#

Payloads are no longer copied in code format when pasted into Markdown 🙁
That was amazing :(sadglas

tired locust
#

Have anyone faced an issue while starting pwnbox.I've tried different locations but it didn't work

cloud urchin
#

Yeah there's an upstream provider issue right now. VPN only till they fix it I guess.

quiet heart
#

Congrats revmusc

thin hearth
#

Hello everyone, I have a question regarding the Attack DNS section in Attack Common Services.
What is the difference between Gobuster and Subbrute that allows me to discover hr.inlanefreight.htb using Subbrute, while Gobuster cannot find it ?

#

wordlist gobuster have "hr" (but why this tools cannot find it), resolve DNS (same)

chilly night
echo heron
#

Where can I grab the Academy VPN file since PWNbox is down? (RIP pwnbox)

olive depot
#

You cant get more time on boxes anymore? I just cant find the button

echo heron
#

I only see "reset" as well.

olive depot
#

ye

echo heron
pseudo kiln
#

is academy down? got "Target spawning..." now for a while, using USA VPN

pseudo kiln
vocal schooner
#

i'have too that's why i said yes xD

brave field
pseudo kiln
#

yesterday EU was down and USA was working FeelsWeirdMan

vocal schooner
#

Let's try with EU

brave field
jovial walrus
brave field
jovial walrus
vale pulsar
#

Man I just downloaded the USA one yesterday for today

ocean night
#

Sorry, but seriously, read the question carefully, and the information provided... and for the third time, this is the appropriate channel @feral thicket

jovial walrus
#

Is cross compiling binaries covered in any module ?

feral thicket
ocean night
feral thicket
#

done

ocean night
#

Well done 🙂

brave pasture
#

hey guys anyone's active ?

#

i just need some help

ivory flower
#

can you not easily access next module in a path anymore? 💔 or am i missing smth? like when youre on the completed module screen

slate palm
vale pulsar
#

Do you think that the legacy thing will stay as an option?

brave field
stark hedge
#

I'm not exactly sure what you're asking or which specific hash you were expecting, but it's important to note that you extracted credentials from the SAM, which only stores local accounts within machine.

brave field
#

What you're seeing is actually expected and correct — nothing is wrong. lsa_dump_sam dumps the local SAM database, which only contains local account hashes. The domain is showing as SQL01 (the machine name), not INLANEFREIGHT.LOCAL, which confirms these are local accounts.

#

Use creds_all to dump from memory

spice sequoia
fathom pendant
#

both of these articles break HTB's ToS for writeups as they are both tier 2

fathom pendant
spice sequoia
#

ohhh I didnt know that

vocal holly
#

I need help with attacking tomcat from attacking common applications. I identified the creds to access manager-gui but suddenly now it doesn't let me login. like the creds worked some time ago and i spinned the lab again and now the lab isn't accepting the same creds. i've tried burte forcing but no luck.

spice sequoia
fathom pendant
#

i also wouldn't rely on meterpreter to do all the heavy lifting, i often avoid MSFconsole wherever possible in place of running commands directly on the machine

paper crest
#

Hello, everyone! Who can help with the task “Use the Heartbleed vulnerability to obtain the server's private key. Send the first 10 digits of d.” I am using the module from msf, scanner/ssl/openssl_heartbleed. Set the KEYS action. But for some reason, I am unable to obtain the private keys. Can anyone suggest how to solve this task? Module HTTPs/TLS Attacks - Theory Heartbleed Bug

fathom pendant
paper crest
solid forge
#

HOW

fathom pendant
# solid forge HOW

try various things to discover information from the module readings. There's a way to discover what happens on upload

solid forge
onyx vapor
#

Can a member of staff help me out with my ticket at all, I submitted it a week ago and still have not gotten a response

acoustic owl
compact patrolBOT
onyx vapor
#

I did that last week and my ticket is in the 'Hivemind will pick this up soon' When i go to the chat it says the conversation is closed

fathom pendant
#

note that you should replace direct variables with something else

twin gulch
#

Hey guys, im at shells & payloads module at php webshells. Just found put the .gif file’s name in question 2 but it aint working. Anyone please? Maybe a bug?

rare lava
#

Can't use XXEInjector tool.
Web attacks module - Skills assessment;
I have completed the assessment manually, now trying to get the flag with tool but can't make it work. Idk if my injection point or parameters are wrong, help pls.

weak patrol
#

I need help with this question under Network Services: Spraying, Stuffing and Defaults Password spraying.
I have managed to ssh into the target but cannot seem to find the MySQL credentials, I have used the tool discussed in the module but those passwords haven't worked. I have also travessed through the different directories to see if I can find them but still no luck.
Anyone to help?

green mulch
weak patrol
burnt sundial
#

am i going crazy

green mulch
weak patrol
#

Okay... let me look

candid juniper
#

Is anyone else experiencing modules displaying 100% but not being perceived as "completed" in paths?

viral lotus
weak patrol
candid juniper
#

They were already completed prior to 2.0 push

#

Now they've reverted to not say completed and just say 100% progress, as well as the seemingly impossibility to overwrite said status using "Mark as Complete & Next"

green mulch
candid juniper
#

Also seems like the "contact support" button is a dead link.

candid juniper
fathom pendant
candid juniper
#

Fair and understandable, my only main gist is the fact that it seems to have lost widescreen support. Which I think is the only sad change

fathom pendant
#

if there is a feature missing/removed that you'd like you can always submit /feedback. that goes directly to the staff slack and, importantly, the teams that work on these things

#

speaking of you just reminded me of one

limber river
#

Can I still use the old UI ? The new one is very uncomfortable

fathom pendant
candid juniper
viscid bolt
#

Anyone have advice for Introduction to Windows Evasion Techniques Skills Assessment 1 with Regasm. Can't quite get a loader going (have minimal knowledge in building these.) Any help is appreciated!

pseudo kiln
#

anyone around for a question on XSS & CSRF skills assessment?

ocean night
gilded socket
#

someone can help me with Advanced SQL Injections Skills Assessment 2 part? I have no ide how to save data to file without privilege

gleaming nimbus
#

Hello, guys! I am currently on my way to finish the HTB Academy Linux Privilege Escalation Module (I am at the skills assessment) . There is a note over there stating the following:

"Note: There is a way to obtain a shell on the box instead of using the SSH credentials if you would like to make the scenario more challenging."

I tried multiple ways to get a shell, but none of them worked so far.
Has anyone here tried and obtained the shell? If so, please give me a hint if you can. Thank you!

upper spire
#

There are a lot of wrong things with the new UI. Like the module I want to study is 6 clicks aways. Old UI only thing you have to do was dashboard and go. lmao

gloomy compass
paper lava
covert vector
#

-sV

fathom pendant
# covert vector -sV

-sV is a version scan, a script scan (-sC) runs default scripts to gather some enumeration details

#

That may yield better results 😉

covert vector
#

-sV is service version ( correct @ Marcielee )

fathom pendant
#

-s (scan) then any combination of uppercase letters (like TVCX) will result in their corresponding scan types, my example is TCP, Version, Script, Christmas (read the docs to figure out what they do)

#

-sTVCX would be the tag, and yes they are order agnostic

plain hare
#

Hellow All, im currently doing the Advanced XSS and CSRF Exploitation module and aI am in section: Bypassing CSRF Tokens via CORS Misconfigurations, im traying to do the lab here but no matter what i try, i cant get it to work, i know the vulnerability but the exployt just dosent seem to work and im pretty sure itsh the right exploit
Any help would be much appreciated

#

the header in the server response adds Access-Control-Allow-Origin: null and Access-Control-Allow-Credentials: true

#

therefore im using a sandboxed iframe

#

but no luck
also i have tried viewing the exploit on the exploitserver.htb and i can see the request it is making, so it works and its getting it done, but when delivering it to the victim, nothing happens

paper lava
cloud urchin
#

@plain hare Please take care not to post spoilers from modules above tier 0, like code etc. If you feel like you need to show more info you can ask to DM someone.

fresh vector
#

anyone having problems spawing targets

paper lava
#

It is usually slow this time of night, peak hours

worldly rover
shy token
#

I can targets to spawn but I cant run commands successfully.

in section 7 of getting started I'm told to run an nmap scan and find the version of the software running on port 8080 but when I run the commands nothing is happening. I've even opened the hint and put the same exact command the hint says to use but no response

fresh vector
#

what does your command output look like? can you ping the host?

icy bramble
#

Hello. Please can anyone help me with the advanced sql injection skill assessment? I am having a tough time for some days now trying to bypass the login

shy token
left lintel
#

why does this not show boxes completed or anything just certifications and pro labs

#

seems lackluster for what is supposed to be a n overall profile

fathom pendant
#

because boxes completed is kinda moot and would get overcrowded with people that have been on the platform forever and have hundreds of boxes under their belt. Also box completion isn't that much of a flex

#

but also that's not really related to academy modules maybe you meant to ask over in #general ?

jovial walrus
icy bramble
sterile solstice
#

Is anyone able to help me with DACL Attacks 1, specifically the 'AddMembers' section.

cloud urchin
#

what's your question

sterile solstice
#

actually ... i think i solved it.

gleaming nimbus
spring trail
#

hi guys, how to download vpn for academy I can’t find 😭

cloud urchin
gray shoal
#

can someone help in the Hard machine, 3rd machine, in the footprinting module?

gray shoal
north frigate
#

Cheers everyone 🙂 Could someone briefly outline the relations between "Footprinting", "Attacking common services" and "attacking common applications" ? Is some kind of order recommended here? They are all Tier-2-modules but read fairly overlapping ^^"

feral trench
#

I have fully completed information security foundations but I can't get badge two modules are like that, but I completed everything, what to do?

plain charm
north frigate
feral trench
#

can I reset module progress by any chance?

brave field
#

Is there a way to use Ligolo-ng in the Using CrackMapExec module’s Skill Assessment instead of the provided Chisel to access the environment? Scanning with nmap via proxychains is extremely slow due to the SOCKS proxy architecture, and Ligolo-ng's TUN interface would allow full-speed scanning without proxychains.

waxen totem
brave field
narrow plume
# feral trench

lol wtf for me also the exact same modules are marked incomplete but 100%

candid juniper
# feral trench

It's a bug in the new UI, can't really do anything about it for now

waxen totem
gray yacht
brave field
gray yacht
finite crypt
#

Hi everyone, the new UI in the academy is a bit strange, I can't find where can I download the ovpn file.

finite crypt
#

only the pwnbox option is here

severe inlet
# finite crypt

Ive had this problem from the old ui aswell some modules you can download it and some of them you cant

I always went for the AD Module in CPTS for the section kerberoasting and always found the option to download it

spring trail
#

I saw from previous messages, there are many people encountered an issue with Signature Wrapping Attack in SAML section. I wonder if anyone know the solution? cause' before SAML raider there is a RAW MODE which we can tick and get the payload working properly, but now it removed. I wonder if anyone know the solution for that?

fallow sable
#

I'm working on "Windows File Transfer Methods", Question 2. It says RDP to MS2 using the credentials on the page. I can ping the VM, nmap says 3389 is open but I am unable to connect via xfreerdp or remmina. Before I troubleshoot further, I am meant to be connecting via RDP, right?

fallow sable
#

^^ I can RDP from the attack box. My local Parrot OS cannot. Perhaps because it is running the latest OS. Should I find a fix, I'll post it for your reference.

primal ginkgo
#

What in the skin slayer is the new UI theme doing? I got these completed months ago.

primal ginkgo
fallow sable
primal ginkgo
fallow sable
#

I run VMware Workstation Pro. Not bare-metal. I can RDP using the HTB attack box (Pwnbox) - no issue. The attack box is running Parrot 6.4 and xfreerdp 2.10.0. I'm guessing it is a compatibilty issue.

primal ginkgo
dusk holly
#

HTB Academy recently updated their UI and now copying code blocks into Obsidian is a mess — no language tag, broken formatting. Made a Chrome extension that solves this with a one-click hover button and right-click menu option, giving you a properly formatted Markdown code fence every time.
https://github.com/serenity646/HackTheBox-Markdown-Clipper

GitHub

A Chrome extension to copy HackTheBox Academy code blocks as Markdown fences - serenity646/HackTheBox-Markdown-Clipper

fallow sable
sly lagoon
brave pasture
#

i am unable to understand well this section

brave pasture
#

?

fathom pendant
# brave pasture ?

Don't overthink things, sometimes a version scan reveals more information than you think

brave pasture
#

Nice Hint SIr

#

Our client wants to know if we can identify which operating system their provided machine is running on. Submit the OS name as the answer.

is it gonna work for the above quiz ?

fathom pendant
brave pasture
#

Thnx

rich wraith
#

can I switch to the old Academy somehow?

sly lagoon
#

dashboard panel was great

solar arch
#

and why is the big "Congratulations Exam Passed!" the main dashboard? i dont care about my done certs, why would this be anyones main focus when logging in

left lintel
#

idk

#

None of the logic makes much sense same with the overall profile

#

Not even hating bcuz it’s new

pseudo rivet
#

hey, i started the windows fundamentals skills assessment target, but its been spawning for the last ~15m anyone can reset this?

fathom pendant
#

/feedback

mossy epoch
#

Secure Coding 101 : Javascript , skills assessment, anyone with a hint on the /Patching task ?

#

i deofuscate vuln.js and patch de vulns but when I upload the file but I get errors.

opaque dew
#

who thought that this was a good idea for the UI? a bunch of unlabeled icons and a table of contents that takes up as much space as the entire old one while hiding most of the information?

#

i warned you about all of these issues exactly during the beta, and you didn't listen, so i'm no longer going to assume that private feedback will be taken under consideration anymore. this will affect my recommendations to other people going forward.

plain charm
#

How do you guys make notes for the Documentation & Reporting module? I seem to find little to zero stuffs to include in my notes! All I am doing is read along the module

cloud urchin
#

Make a report

finite crypt
keen cliff
#

┌──(unknown㉿kali)-[~/odat]
└─$ ./odat.py all -s 10.129.205.19
15:54:20 ERROR -: Impossible to load local configuration files in conf/ and to set driver_name: DPI-1047: Cannot locate a 64-bit Oracle Client library: "libclntsh.so: cannot open shared object file: No such file or directory". See https://cx-oracle.readthedocs.io/en/latest/user_guide/installation.html for help
Traceback (most recent call last):
File "/home/unknown/odat/./odat.py", line 798, in <module>
main()
~~~~^^
File "/home/unknown/odat/./odat.py", line 792, in main
logging.debug("Oracle Client Version: {0}".format(cx_Oracle.clientversion()))
~~~~~~~~~~~~~~~~~~~~~~~^^
cx_Oracle.DatabaseError: DPI-1047: Cannot locate a 64-bit Oracle Client library: "libclntsh.so: cannot open shared object file: No such file or directory". See https://cx-oracle.readthedocs.io/en/latest/user_guide/installation.html for help wtf

#

this has been a pain in the ass to download, pip was bugging out and i had to use the force command for it to work and now it still tells me something is missing

cloud urchin
keen cliff
#

any idea about my problem

#

did yall download the necessary oracle enumeration tools on a vm or just used pwnbox

cloud urchin
#

start a virtual environment:

python3 -m venv venv

source it:

source /venv/bin/activate

then install it with:

git clone https://github.com/quentinhardy/odat.git cd odat/
git submodule init
git submodule update
wget https://download.oracle.com/otn_software/linux/instantclient/2112000/instantclient-basic-linux.x64-21.12.0.0.0dbru.zip
unzip instantclient-basic-linux.x64-21.12.0.0.0dbru.zip
wget https://download.oracle.com/otn_software/linux/instantclient/2112000/instantclient-sqlplus-linux.x64-21.12.0.0.0dbru.zip
unzip instantclient-sqlplus-linux.x64-21.12.0.0.0dbru.zip
export LD_LIBRARY_PATH=instantclient_21_12:$LD_LIBRARY_PATH
export PATH=$LD_LIBRARY_PATH:$PATH
pip3 install cx_Oracle
sudo apt-get install python3-scapy -y
pip3 install colorlog termcolor passlib python-libnmap
sudo apt-get install build-essential libgmp-dev -y
pip3 install pycryptodome
pip3 install pyasyncore```
fathom pendant
keen cliff
#

I’ll try it out thanks

opaque dew
#

oh, and the new UI breaks itself if it can't load google analytics?

#

how did this possibly pass QA?

cloud urchin
opaque dew
#

i've already sent feedback

cloud urchin
#

Then you can rest assure your concerns have been heard by the right people

keen cliff
#

cx_oracle

#

does not wanna be downloaded

#

error: subprocess-exited-with-error

× Getting requirements to build wheel did not run successfully.
│ exit code: 1
╰─> [20 lines of output]
Traceback (most recent call last):
File "/home/unknown/venv/lib/python3.13/site-packages/pip/_vendor/pyproject_hooks/_in_process/_in_process.py", line 389, in <module>
main()
~~~~^^
File "/home/unknown/venv/lib/python3.13/site-packages/pip/_vendor/pyproject_hooks/_in_process/_in_process.py", line 373, in main
json_out["return_val"] = hook(**hook_input["kwargs"])
~~~~^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/unknown/venv/lib/python3.13/site-packages/pip/_vendor/pyproject_hooks/_in_process/_in_process.py", line 143, in get_requires_for_build_wheel
return hook(config_settings)
File "/tmp/pip-build-env-e_jufslg/overlay/lib/python3.13/site-packages/setuptools/build_meta.py", line 333, in get_requires_for_build_wheel
return self._get_build_requires(config_settings, requirements=[])
~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/tmp/pip-build-env-e_jufslg/overlay/lib/python3.13/site-packages/setuptools/build_meta.py", line 301, in _get_build_requires
self.run_setup()
~~~~~~~~~~~~~~^^
File "/tmp/pip-build-env-e_jufslg/overlay/lib/python3.13/site-packages/setuptools/build_meta.py", line 317, in run_setup
exec(code, locals())
~~~~^^^^^^^^^^^^^^^^
File "<string>", line 6, in <module>
ModuleNotFoundError: No module named 'pkg_resources'
[end of output]

note: This error originates from a subprocess, and is likely not a problem with pip.
ERROR: Failed to build 'cx_Oracle' when getting requirements to build wheel

spare terrace
#

Been around 2hours, can't wrap up w this question What is the FQDN of the host where the last octet ends with "x.x.x.203"? IDONT UNDERSTAND

#

the hints dont help me guys

opaque dew
#

oh yeah i also couldn't get that

#

i've just been ignoring it until i'm done with the rest of the module

#

and dns scanning is so horrifically slow

cloud urchin
keen cliff
#

yea

#

everything went fine

#

except this one

#

which doesnt let me run ./odat.py all -s 10.10.10.10 without it since it splurts out an error message about needing it

#

I have wasted like 4 hours trying to troubleshoot this shit

opaque dew
#

i tried using different wordlists, but it takes so long to try everything i'm not sure when to give up

spare terrace
# opaque dew okay yeah i'm now done with the rest of the module and i'm weighing if it's wort...
opaque dew
fathom pendant
#

this question is broken down into multiple steps:
step 1: Identify all the possible subdomains from a base dig
step 2: run a tool that checks something like second.sub.do.main

opaque dew
#

yes, but if only one list has the domain i want then it's an issue. how am i meant to figure out which list to use?

fathom pendant
#

start small go big

#

don't exhaust large wordlists, instead start with smaller wordlists

opaque dew
#

okay

#

well that's why i was trying that

fathom pendant
#

ls -lSr should list the wordlists in ascending size order

opaque dew
#

i figured interleaving all the wordlists while stripping out duplicates would yield okay results

fathom pendant
#

the answer will be in the format of second.sub.do.main

opaque dew
#

since they're generally ordered by frequency, no?

fathom pendant
#

no

#

that's not what I'm meaning by size

#

i'm meaning the literal filesize

opaque dew
#

i know what you meant

fathom pendant
#

but no, different wordlist authors have different methods that they create their list in, some are frequency, some are alphabetical

opaque dew
#

is there any kind of documentation regarding purpose and methodology of each list?

fathom pendant
#

no

opaque dew
#

or even where the list is from?

fathom pendant
#

most lists are generally self-explanatory, and SecLists does a decent job of segregating the lists into their various types i.e. web enum, fuzzing, etc

#

SecLists is a repository that aggregates a bunch of different wordlists I don't think it has all the wordlists, but it definitely has the most popular ones

opaque dew
#

i had good luck with top1million until it didn't work for that last one. it's really unclear besides that one what each list is meant to be good for

#

and running them sequentially is likely to have duplicates

#

so that's roughly why i chose to try that method

fathom pendant
#

you won't always be able to use the same wordlist for everything, that's why this is there to throw people off from just copy/pasting the same wordlist throughout

opaque dew
#

i guess i'll have to research where they came from to better understand

fathom pendant
#

you're overthinking this

#

you really are

#

they came from people doing enumeration and seeing hostnames and sub domain names from different locations

#

some of them are the super common ones (dev, mail, app, www ... etc ... etc

opaque dew
#

yeah that sort of context is completely missing from seclists

#

i'm not going to get good at this if my understanding of my tools is surface level

fathom pendant
cloud urchin
#

@jovial walrus Take care not to post content from modules above tier 0 please. The blacklisting section itself goes over how to find out which char isn't working.

cloud urchin
#

it explains how to do it

jovial walrus
cloud urchin
#

re-read the section then

jovial walrus
cloud urchin
#

it explicitly tellls you how to manually discover which char isn't working

#

I'm not going to spoonfeed you the answer

jovial walrus
cloud urchin
#

I gave you good guidance

#

fine then don't take my help

jovial walrus
#

for characters that are not working it print invalid input
but this time it didnt print anything

#

I added a spoiler to my image, it wasnt necessarily from the content

cloud urchin
#

yeah you're missing something pretty important

#

spoiler tag doesn't do anything

#

no posting content if you feel like you need to reveal more info you can ask someone to dm

#

I just checked, sorry, it's actually coverted in the "Interactive Identifying Filters" section

cloud urchin
#

re-read that section

gray yacht
opaque dew
fathom pendant
opaque dew
#

okay, i don't think commands are the only kind of tool but i can understand your ontology now

jovial walrus
#

urgh I keep getting rate limited

#

To check for command injection is it necessary to give a newline operator before listing contents in a directory?

cloud urchin
#

Think about the the command you're executing after the key/parameter name

#

try running that in your terminal and see why it doesn't work

#

if you have command injection you're essentially executing the command at the cli/terminal

cloud urchin
#

you have a misunderstanding of how the webserver is executing the command

#

the webserver inputs the ping command for you, that's already done

#

so start with the 127.0.0.1

#

you need to try various things until it works, follow what i told you.. re-read the section i pointed out early it tells you EXACTLY how to find out what's wrong

#

if you followed that you would have figured it out by now

#

what you typed after the ping command didn't match up at all with what you put into the terminal

#

then think about how a webserver decodes that input into the terminal

hardy canopy
#

hello - Im brazilian im sorry for a bad english
i started learning a basic commands for linux in module of linux fundamentals and a stoped in this exercise

hardy canopy
#

i try using find with a filter size

cloud urchin
#

best to say which section you're on too

hardy canopy
#

section 9 - linux fundamentals

#

i solved question 2 and 3

cloud urchin
#

what section is that

fathom pendant
hardy canopy
#

Find Files and Directories

cloud urchin
#

he said linux fundies

#

need the section name

fathom pendant
#

section numbers don't mean anything really, as they don't ascend numerically in the url anyway

hardy canopy
#

module 18 section 81

cloud urchin
#

lol cmon

fathom pendant
#

those numbers don't mean anything realistically

#

those are more backend numbers

cloud urchin
#

that section is called "Find Files and Directories"

#

Did you try the locate command?

#

Read over the Locate section I believe it tells you how to find this

#

There's also a "find" command you can use

fathom pendant
#

find is the expected command but there's NEI to tell where the issue lies

cloud urchin
#

Find will probably work better

fathom pendant
#

is it a simple syntax error, is it the classic case of not being connected to the target, is the man on the moon all out of cheese

hardy canopy
#

i can filter a date with find ?

hardy canopy
#

running local vm

fathom pendant
hardy canopy
#

my page in this question just say off Vim and nano

fathom pendant
#

?

#

nothing to do with vim or nano

#

just as a note, the -size command has you specify + for greater than and - for less than, so a filesize in the range of 5-10k would be -size +4k -size -11k

#

the question gives you a size range; smaller than 28k but larger than 25k

viscid bolt
hardy canopy
#

is literaly my page and exercises

tiny cave
#

is anyone facing issue with "Intro to C2 Operations with Sliver: Probing the Surface"? The web application is not loading but the source code can be read

fathom pendant
#

but it looks like your thing may be messed up, i suggest logging out and logging back in to see if that fixes it

fathom pendant
tiny cave
hardy canopy
#

worked, now have a examples to resolve the questions

brave field
hardy canopy
#

i just spend 1 hour in this exercise

#

kkkkk

gray shoal
#

how to upload pics here

#

like others

dusk holly
gray shoal
#

ah nice

#

oops

pseudo gull
#

application of AI in InfoSec Section 14 Model Evaluation (Spam Detection) i am getting a File not found error.. can smeone help?

jovial walrus
pseudo gull
jovial walrus
#

thats how I did it

pseudo gull
#

where do i get the file?

jovial walrus
#

they taught how to create a model and get the corresponding joblib file

pseudo gull
#

i fly through it asking copilot to explain the content to me like i am 5.. i think i have to redo the whole module lol

pseudo gull
jovial walrus
#

and claude is miles ahead for coding related tasks, use that instead..u will notice the difference

jovial walrus
gray shoal
#

by chaton?

gray shoal
#

i just downloaded it and tried it. it doesnt have system integration like cursor ai, it isnt as good

cyan orbit
#

can anyone help me with
module: Attacking Web Applications with Ffuf
section: Skills Assessment - Web Fuzzing
question: 3
I've ran this scan on all of the sundomains but didnt get any results
ffuf -w "/home/kali/word lists/DirBuster-2007_directory-list-2.3-small.txt":FUZZ -u http://subdomain.1.1.1.1:PORT/FUZZ

jovial walrus
cyan orbit
#

ok

vivid gate
#

Hey people, I don't use an adblocker at all, however, when I open the HTB academy website it immediately tells me to turn off adblocker, what is going on?

rustic sage
south drift
#

Yeah you can try metasploit

#

Or burpsuite

waxen totem
#

Some browsers come with a built in ad-blocker

dusk holly
#

miss the old UI

tribal lark
jade shoal
#

For how long are you temporarily blocked? I refreshed a couple of times as the new design was not loading properly

#

Good news is that it's not for very long, bad news is that I just get ratelimited a few seconds after again

faint hill
#

Oof. That Dacl II attacks skill assessment was nasty. Glad I survived the ordeal.
Question: in the new HTB UI where is the student transcript? Or has that been phased out/obsoleted?

twin portal
jade shoal
#

The "Streak" interface in the new design. It clearly states that I have not completed this weeks streak, however I have (with the good old UI). And the api call to the streaks interface says I have as well (image attached).

Does the streak interface not work at all, or does it operate with logic disparity? Such as the first day of week was Monday, but has now been set to Sunday?

echo fog
#

Hello, I’m new here and I have a question. Service Scanning module the first question about Nmap on port 8080. I see tomcat but no version is showing. Any help greatly appreciated. I already tried -sV. I dont get what im doing wrong

coral lion
#

hey guys

#

I got a question. In linux fundamentals, they asked to get the type of service of dconf.service

#

i ran systemctl show -p Type dconf.service and got this

brave field
coral lion
#

why didn't the type command work?

brave field
coral lion
#

it's path is in the user directory

brave field
#

yes

dreamy gust
#

Hi guys, I'm having some trouble with the module Attacking Common Applications > Attacking Thick Client applications. When I run the Restart-OracleService.exe at first, it works. But after I change the permisisions for the "Temp" folder as the lab says to, I run the .exe and I get an error message:

"Windows PowerShell terminated with the following error: The type initializer for 'System.Management.Automation.Runspaces.InitialSessionState' threw an exception."

Any help would be appreciated, thank you!

feral ferry
#

I cant seem to find where to download the VPN file for the academy in the new view can someone point me in the right direction please ?

gilded socket
#

Anyone can help me with Advanced SQL Injections (Skills Assessment) second question? I used correctly lo_put to insert data but I have no permission to use lo_export. Someone help me or explain me how to write this data to file?

cloud urchin
untold flint
#

Hi all,

For the AD ENumeration and ATtcks Bleeding Edge Vulnerabilities PetitPotam (MS-EFSRPC), Petipotam works but ntlmrelayx says "No route to host". How did you solve this, please?

cloud urchin
fathom pendant
untold flint
untold flint
sterile solstice
#

I am having the same problem if anyone can help. I've used my privs to get access to the right group and machine, but haven't been able to move forward. there's something im missing ...

sterile solstice
#

Has anyone completed DACL1 and can help with Q3 of the Skills Assessment?

jaunty kraken
#

I have a question regarding the module progress display on the new dashboard. (I apologize if this is not the right place to ask.)

Some modules are showing as "100% (In Progress)" instead of "Completed," despite the fact that I’ve finished all the exercises (all marked green) and clicked the "Finish" on the last page. I would like to know the difference between these two states.

acoustic owl
jaunty kraken
gray shoal
#

good morning everyone

rare lava
#

Hey, I'm on File Inclusion module- Log poisoning;
Currently doing RCE via Apache Logs to execute "pwd". Problem is the output is too long and i can't figure out how do i filter it.
Need some help pls.

shadow carbon
#

Morning I'm quite new to hack the box and got cyber security cousera, working on boot dev and well hope we can be friends and help me within the community.

gray shoal
#

why is it like this, that after i finish the module, i cant view it? those that marked completed are not clickable anymore

acoustic owl
gray shoal
#

hope we get the fix of the new UI before GTA 6

heavy sluice
ocean nexus
#

Hi guys, that one maybe can be a stupid questions, during the academy modules studying im forced to use the pwnbox where its not possibile see the VPN tab to connect my own Vsystem?
Or i can just connect anyway my Vsystem to the academy VPN i already have downloaded and ping/scan the target spawned?
Or also i can without using the VPN cause its an exposed dedicated istance? Was thinking about that cause the ip of the target is 154.57.164.82 ummmm

stuck epoch
#

For some reason the windows fundamental module says its still in progress when I completed it weeks ago

#

Its at 100%

gray shoal
#

same

feral thicket
#

how can i enter as user3?

gray yacht
sly kelp
restive marsh
#

hello everyone

#

i have a question

sly kelp
restive marsh
#

I am solving
Skills Assessment - Broken Authentication and i get the username and password

#

can i brute-force OTP?

feral thicket
#

how can I conned to the target

#

i need password

restive marsh
#

i solved it

red shuttle
dim hound
#

I have a question related to NTLM Relaying SA, who can I pm ?

gray yacht
tranquil breach
#

has Gold annual subscription two exam voucher now ??

tiny cave
#

academy having issues?

dim hound
#

app.hackthebox works fine.. just academy not

tiny cave
dim hound
#

just very slow

sly kelp
reef frost
gray shoal
#

same , the "start learning" button in academy hangs

#

come on revert this last UI update already

azure aspen
#

I'm having difficulty loading Academy, it's awfully slow...

heavy edge
#

swear to god, none of this happened this often before academy V2

shut quest
#

it still happened, we're all super sensitive now because of change.

feral adder
#

hi does anybody also having an issue accessing the academy platform?

worldly briar
#

yeah can't get to anything at all atm

feral adder
#

I hope they would add an option to which Academy UI to use.

delicate hinge
#

Yeah they might now be discovering load issues after switching everyone over. Hopefully it will get smoother as time passes

feral adder
#

I miss the feature of the previous version where I could click the module and just open it in the new tab :<

pseudo kiln
#

anyone running into issues with the academy web app ?

reef frost
quaint perch
#

Yeah, I asked in the general also, it's down

feral adder
#

Can't proceed to the module itself

pseudo kiln
#

yep same here

reef frost
#

Why is there no search function on enterprise sadglas

halcyon patrol
#

Everyone is facing Academy issues, too, right?

worldly briar
#

yes

manic lantern
#

ask*

quaint perch
#

Time to touch grass 🙁

worldly briar
#

insane suggestion

manic lantern
#

I just sat down after being busy all day haha

halcyon patrol
#

I thought it was my ISP acting up again kek

worldly briar
#

im just going to sit here and refresh for hours until it comes back

quaint perch
worldly briar
#

tried in different browser and somehow got page loaded

#

weird

feral adder
#

Was about to blame mg ISP lol.

halcyon patrol
worldly briar
#

main broser still trying loading the hompage

quaint perch
feral adder
#

I'm about to finish my nmap module I am afraid to click next coz that would be another 10 minutes of loading lol.

drowsy wyvern
#

are there any announcement about this issue? my subscription will end this week and i need to finish several modules lol

manic lantern
#

Noticed it has been on and off since the new interface (not very fond of it tbh)

regal gust
#

Site dead?

#

Just got the flag :(

halcyon patrol
#

The audactiy to keep the status page in "operational" :kekw:

manic lantern
#

Let's postpone my CWES exam with a few weeks 😛

feral adder
#

Take it and blame it to the site

quaint perch
manic lantern
regal gust
#

Well, good excuse to pack it up and go home early

manic lantern
#

Well I was doing the introduction to AI Red Teaming, which is a bit dry anyway 😛

regal gust
#

I was doing XSS and just got that phishing payload working

pseudo kiln
#

it seems lately there are more and more operational issues with academy, few days ago I had to switch VPN servers as nothing would spawn on EU, now this

pseudo kiln
#

this never used to happen, it makes you wonder what could be causing this

manic lantern
worldly briar
quaint perch
#

This happened to me but I want getting any response from the spawned hosts

manic lantern
worldly briar
#

same on labs well

#

just have to randomly swtich adn regenerate sometimes becauese things stop working

manic lantern
#

@languid fjord any updates? Seems like academy still has some issues?

halcyon patrol
tribal lark
#

is there something wrong with academy its taking ages to load like 10minz almost labs works fine

shut quest
pseudo kiln
tribal lark
worldly briar
#

standard

minor laurel
#

HTB academy is slow

drowsy wyvern
tawdry swallow
#

the academy is definitely not working

tribal lark
tribal lark
tawdry swallow
#

all other websites work great

worldly briar
tawdry swallow
#

it worked all day yesterday

tribal lark
#

it was working at 3pm

dim hound
#

It worked till few hours ago

jaunty orbit
#

Hi everyone. Does anyone know what's happening with the academy? It's not working.

queen ingot
#

yo, who decided to force the change of academy?

you realize this is just a straight rip of hackviser and that it's not a good change

#

please htb community. I know I don't talk much but you have to stand up for something man

shut kelp
#

Hello,

Is there any maintenance planned for HTBAcademy? It's unusable. I've been struggling with it all day.

queen ingot
#

Dear HackTheBox,

I know I never talk here, and my opinion probably means nothing to you. But, please don't go completely soft and never release insane machines again.

At least make another subscription role to allow for people who want harder content to get it (although I doubt people will be happy about this).

Also, your absorption of Vulnlab should mean something. I don't know how the transaction worked, but I assume you also kept most of the people who worked there. Please use their talents correctly, and allow them to make good difficult content.

I have never solved an insane machine without help. It requires writeups and community brainstorming to solve this types of machines. You have to steer into that collaboration rather than taking it away.

I want to believe that you didn't make this vulnlab purchase to axe competition, and you made it to make your platform better. So do that, by making the change that is neccessary, which is allowing more dynamic decision making at the machine level. You are a big company, and you can afford to release greater than one machine a week.

assuming that the difficult machines are reserved for only multi machine labs at the prolab level feels like a bit of a cop out as well. I don't know the exact solution, but as community it should at least be discussed.

Can we get a petition or something going?

rare condor
queen ingot
#

support me, I can't stand this AI slop. Don't fall down this path, do something with the companies your buying out.

acoustic owl
pseudo kiln
#

and now almost half of vulnlab chains are beyond enterprise wall with no plans to add them to the pro labs platform 😂

rare condor
rare condor
queen ingot
#

I'm not one to complain, but I don't even want to use the platform anymore? Let's get like a signing thing going, because this is ridiculous. I am not going to sit back and watch I platform I genuinely love, turn into a shell of it's former self real time bro

acoustic owl
rare condor
#

It's been a long time since I wrote feedback. I've written twice. And here, it would be better if we encouraged other users to do the same.

pseudo kiln
#

maybe I will get hate for this, but I think academy 2.0 is fine, and in some aspects superior, much less clutter

acoustic owl
pseudo kiln
# acoustic owl Which Vulnlab Chains can you play on Enterprise, but not with the ProLabs subscr...

Sadly, I do not have enterprise access so I cannot be 100% certain. I know Trusted chain and Shinra pro lab are only on Enterprise, from reading the chats here and there.
The thing with VL chains, many of them are not suitable for multi access, they were designed as a single player experience, so I get why they get released on EP, and not on the pro labs platform.
But still a single guy managed to offer private instances for chains for a fraction of pro labs sub cost for a while, and a multi million (or billion?) dollar company cannot figure it out? It's just strange, I really like HTB, but they could have handled the merger much better imo....

shut kelp
#

I much prefer the academy's UI before; I'm nostalgic for it.

pseudo kiln
acoustic owl
languid fjord
#

and i guarantee you, we are no where near a billion dollar company lol

#

But i've noted all y'alls feedback and will pass them along to the appropriate team.

cloud urchin
languid fjord
#

(this is a joke)

dusk holly
sly kelp
#

had same issue and support said

it is working fine on our end

but they are aware of the issue and trying top fix it.

languid fjord
dusk holly
languid fjord
#

Our last funding round was 50m

#

(Public info)

queen ingot
#

also why do we lose the ability to see the path properly when we complete it 100%

I do not like this view for the CPTS

#

this is why I haven't completed the CWES path

#

because this view feels nicer to use when trying to learn

#

even if I am 100% done a pathway, I want to be able to hit continue learning and go into the modules

#

Like I am not able to actually see this view for the CPTS because I have completed the path which doesn't make any sense

#

add this button back to when you complete the path 100%? I don't care to share my achievement 😭 💀

manic lantern
#

ah right I see what you mean now haha

wintry pagoda
#

Hello guys, I need some help on this section on pivot module, im trying to use ligolo to solve this, I cant connect to the target that is on the question, already did the pivot and added the ip route :/

fathom pendant
#

Start -> a is the initial target
a -> b is the first hop
b -> c is the second hop

#

Theres a machine in between a and c (c being the 172.16.6.155 addr)

compact patrolBOT
unreal berry
#

Ok, i'll contact via email thanks

sterile solstice
gray yacht
tribal lark
stark hedge
#

Could anyone help with Sliver C2 please? I'm getting constant implant timeouts in the 'Intro to C2' module. Sessions connect, but I can't execute any commands. Has anyone encountered this?

shut quest
#

Seems to be really missing. Can't find the SA.zip for the Active Directory BloodHound Skills Assessment. Which is required to complete the module.

urban forum
#

hello, in SQL Injection Fundamentals - Writing Files
any one was able to retrive interactive rev shell insted of web shell?

rare ether
#

Regarding 'AI Data Attacks: Evaluating the Trojan Attack (Section 19 / 25)',

I am experiencing the following connection issue. I have already reset the target, but I keep getting this error. Does anyone know how to fix this?

swift carbon
#

anyone around for a nudge on Windows Lateral Movement WinRM section?

swift carbon
#

hey can I DM you about this?

harsh gorge
honest crane
#

Is this module stuck on 100% for anybody else?

heavy sluice
honest crane
unique valve
cloud urchin
unique valve
#

This could block many people from attempting several different HTB certification exams because it blocks path completion.

cloud urchin
#

That might be part of CJCA idk, but it's not a part of the others as far as i'm aware. those are prerequisite modules

scenic parcel
lapis umbra
#

Hi, I am connected to the pwnbox - i believe the VPN is connected becasue I see it in the toolbar at the top.

I tried completing the module/19/section/101 which is basically to run

sudo nmap 10.129.2.18 -sn -oA host -PE --reason

But I get

Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-03-10 02:17 CDT
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 2.07 seconds

So it states its not there, and the task is to get the TTL so that I can detect the OS that is being used.

lapis umbra
autumn pilot
#

Are you using the IP address of the target you've spawned

#

To get the TTL in this particular exercise you need to refer to the command outputs in the section

lapis umbra
autumn pilot
#

so, for this particular section and question you don't have a target, I mispoke (apologies)

#

focus on the TTLs present in some of the outputs in the section

lapis umbra
autumn pilot
#

As you can see in the walkthrough and please do not share steps and the walkthrough itself. It is not a typical terminal as you see in the workstation. It is just an image from the section

lapis umbra
autumn pilot
#

You are not supposed to test the TTL, you are supposed to use Nmap's output in the section

lapis umbra
autumn pilot
#

yup, in the sections you will be able to spawn the target and practice the commands

surreal chasm
#

hey, is academy up rn?
for somereason its not loading content

sturdy ivy
surreal chasm
#

cant use the academy that way :\

gray shoal
#

who wants to do modules and learn together with me?

craggy edge
#

about AEN blind.. does the whole environment spawn at the "external information gathering section" (first section I could spawn anything) or just a seperate box for the current section?

gray yacht
untold orbit
#

Hi All,
I need help on Bleeding Edge Vulnerability section in Active Directory module.
Trying to get a Kerberos ticket for PetitPotam attack. But I keep Geting below error:

#

Please let me know what am I doing wrong, I am using command as below:
python3 /opt/PKINITtools/gettgtpkinit.py INLANEFREIGHT.LOCAL/ACADEMY-EA-DC01$ -pfx-base64 MIIStQIBAzCCEn8GCSqGSI...SNIP...CKBdGmY= dc01.ccache

regal gust
#

Morning all. Doing SQL injection fundementals, and picking back up on the UNION caluse section. The module dictates I connect using mysql to the provided server to follow along. Is there an issue with my syntax here, or is the box just misbehaving for now?

waxen totem
regal gust
#

Ah damn, it was upper case P

#

There we go, thanks!

viral lotus
#

when trying to copy out of a linux target I get % in the clipboard, I run them through firefox on my vm is this likely the link and I should use chromium? this is when I RDP into it. specifically the Kerberos Attack - Skills Assessment one

covert vector
#

Anyone else having issues with the file upload attacks module, the fuzzing never works…

brave prawn
#

Hey, can i DM someone on WPA3 Attacks Skills Assessment?

elder prawn
#

bruteforcing is really slow in academy when you have 250ms ping to the closest vpn region

cloud urchin
#

@vagrant wraith For boxes best to ask in #boxes, also please take care not to spoil so much info

hardy jacinth
#

Hi all

hardy jacinth
#

I have problem with Intro to Assembly Language Module Skills Assessment task 2 every time try to contact to the server it give me Failed to run shellcode!

tall geode
#

I need help with "Environment Setup" in Applications of AI in InfoSec under AI Red Teaming course. Waiting for it to complete but didn't complete at all. VM has 6 core vCPU and 16GB memory.

Stuck at this stage

Any idea, please?

hardy jacinth
#

The above server simulates a vulnerable server that we can run our shellcodes on. Optimize 'flag.s' for shellcoding and get it under 50 bytes, then send the shellcode to get the flag. (Feel free to find/create a custom shellcode)

#

that the question

thick beacon
#

Hi all
Can anyone help out with the HTB Academy - Shells & Payloads, on the infiltrating Unix/Linux section. I’m trying to answer “Exploit the target and find the hostname of the router in the devicedetails directory at the root of the file system.”
I’ve gained access but can’t find details of the router anywhere.

sharp patrol
#

Hello, can you help me? I'm going through the “Penetration Tester” Job Role Path and can't seem to complete the last task in Nmap (Firewall and IDS/IPS Evasion - Hard Lab).

The task itself: Now our client wants to know if it is possible to find out the version of the running services. Identify the version of the service our client was talking about and submit the flag as the answer.

I've tried various scanning methods, the last one being:
nmap -sS -sU -p22,80,137,139,445
--script “smb-os-discovery,smb-protocols,nbstat,http-server-header”
-Pn -n -T0 -f --scan-delay 500ms --data-length 20 --max-retries 3 10.129.2.47

But I can't seem to get around it and get the version I need.

Can you give me a hint in which direction to go, please?

gray shoal
fathom pendant
#

@coral lion moving the convo here

coral lion
#

sure

fathom pendant
#

there's 2 steps to the problem, first you need to make sure it's the 35th value, second, you need to count the characters

gray shoal
#

i remember your nickname from the first day i joined HTB Marcielee

fathom pendant
#

so you need to write a condition that checks the value of the $counter variable

coral lion
#

my error is appearing there

fathom pendant
#

then in that check, you need to tell it to spit out the information you want

#

dm me what you've got so far, not just the code that the module gives you

coral lion
hardy jacinth
#

any help plz

fathom pendant
coral lion
fathom pendant
#

yes

hardy jacinth
#

I have problem with Intro to Assembly Language Module Skills Assessment task 2 every time try to contact to the server it give me Failed to run shellcode!

hardy jacinth
#

The above server simulates a vulnerable server that we can run our shellcodes on. Optimize 'flag.s' for shellcoding and get it under 50 bytes, then send the shellcode to get the flag. (Feel free to find/create a custom shellcode)
that the question

coral lion
#

oh yea