#modules

1 messages · Page 475 of 1

coral lion
#

you could just reply to yourself to make it easier

hardy jacinth
#

you can give me the flag (:

fathom pendant
#

especially for modules above tier 0

coral lion
#

😂

hardy jacinth
#

i stuck on this for a week

fathom pendant
#

best guess is that your shellcode is a bit too big

#

it says under 50 bytes

coral lion
#

code optimization 😄

hardy jacinth
#

it 41

coral lion
#

daym

#

yea idk shit in this

#

imma go do my bash

hardy jacinth
#

what can i do hate the monitor?

fathom pendant
#

@hardy jacinth module is above tier 0; don't share code from the module please

hardy jacinth
#

fine

#

even this ?

fathom pendant
#

can we not

hardy jacinth
#

ok

fathom pendant
#

just wait for someone to offer to dm and assist you

hardy jacinth
#

i guess i should lock for another module

hardy jacinth
#

but i got another problem I need my page for SOC Analyst Prerequisites

granite sandal
#

copy ghostrider, thank you

#

that worked. its always the simplest things. Thank you!

grizzled schooner
#

Does a student subscription give me full access to the CAPE job role path? Please @ with replies

#

Nevermind - found it ^

polar crescent
#

hi, having an issue in the AI data attacks, evaluating the Trojan attack section. In the last cell of the notebook where the file needs to be submitted to get a flag, I keep getting the error read timeout while submitting. Have tried respawning, increasing the timeout, but still the same error - Error submitting model: HTTPConnectionPool(host='154.57.164.79', port=32104): Read timed out. (read timeout=120)

silk ice
#

I'm working on https://academy.hackthebox.com/app/module/116/section/1165 and have a question.

When running medusa -U users.list -P passwords.list -h $IP -M ftp -n 2121 I don't get any hits but when I run hydra -L users.list -P passwords.list ftp://$IP:2121 -q -t 45 I get a hit (which is the expected outcome).

Why do they end up with different results? Aren't they essentially performing the same bruteforce?

cloud urchin
#

@granite sandal @sick meteor Please take care not to reveal content or spoilers for modules above tier 0

jovial walrus
#

in lxc/lxd section on linux priv escalation they ask to unzip alpine image but never tell what is alpine and where to install it from ?

brave field
untold orbit
#

Hi all,
Can anyone please help me with this?

brave field
coral lion
#

Can anyone help me with a Bash Script? (Can't send the code here cuz the module is above Tier 0)

dusk holly
grand veldt
#

someone plz tell me that is this HTB subscription is available in coursera ?? i am a student and cant afford this plz tell me thanks

#

guys also tell me whats the diff between monthly and anual subscription ?

dusk holly
grand veldt
#

yeah i knew abot that this is a lab subscriptiion

#

any discount for students ??

dusk holly
grand veldt
#

oh i think i have no choice either thanks btw can you plz tell me if a bought thiis does it unlock all the vip labs ??

dusk holly
#

those have separate subscription

grand veldt
#

so the vip labs in these are all unlock after buyinh subs???

mighty matrix
#

Hi, it's been saying target spawning on the Analyzing Evil With Sysmon & Event Logs module for the past 10 mins. I have tried to refresh the page numerous times. Is HTB functioning as normal or are there issues?

final cypress
#

Question. I'm trying to connect to the spawned target, however it keeps telling me I have the wrong passkey.

I am copying and pasting the one that is there.

#

Any idea why it's doing that?

#

This is for Linux Fundamentals, section 8.

autumn pilot
#

You need to use the htb-student username to SSH into the target

thick beacon
#

?

final cypress
untold orbit
#

I would spawn shell through meterpreter and do some enumeration

coral lion
#

my bash script found the condition and printed the last 20 characters

#

but its somehow not the correct answer

iron ether
#

I have the same problem any answers?

cosmic jay
#

Having trouble on Windows Event logs and finding evil, the sysmon section.

I set sysmon to run with the provided config file, and perform the dll hijack, getting the text box indicating hijack was successful, however no Event ID 7s are recorded in the sysmon event logs, and I couldn't find other events related to loading dlls.

sour ether
#

Hello everyone,
I am doing the Broken Authentication Module from Web Pentester Path and in the content Brute-Forcing 2FA Codes, I done the lab, but I am curiously, because the ffuf do not returned a token to insert, but, do the direct bypass. Its the correct?

#

I thinked that the code will be returned on console to insert in browser 😛

cosmic jay
iron oar
#

Does anyone actually prefer the new academy UI to the old one?

heavy sluice
# iron oar Does anyone actually prefer the new academy UI to the old one?

I do. I have a big screen and it was hard to read the text in the old UI. But while I like the design and concept I do not like that functionality got worse. (Code blocks, revisiting of modules, showing modules of the path in the small box where you only see the green checkmarks and have to scroll to visit the module you want to do next, and so on)

quick cloud
#

i stuck at the imap and pop3 module labs please help if anyone know how to do this

dusk holly
quick cloud
#

@dusk holly can you please share the command i stuck for almost for 1.5 hours

dusk holly
halcyon sparrow
#

Hey, on the old UI, there was a link to the youtube video walkthrough for the course labs. Do you know if this option has been removed or moved? I can't find it anymore

fathom pendant
fathom pendant
#

Maybe for the tier 0 modules, but no video guides (should) exist for modules above tier 0

dusk holly
fathom pendant
halcyon sparrow
#

if i remember well yes, there was the written walkthrough and a video (only for the labs such as "Fingerprinting lab - medium" for instance)

#

but nevermind

#

ty

fathom pendant
halcyon sparrow
#

oh okay

fathom pendant
#

Yeah its a tier 2 module, so any video guide/walkthrough would be stricken down by copyright claims due to ToS

keen zephyr
#

Which VMs you guys use daily?
I have been using virtual box for the past few months, but I gotta figure a new one because vbox always burns CPU cycles despite being idle, like 8% of total CPU usage when vbox is open idle vs 0.5% when box is closed

brave field
fathom pendant
#

You can put anything as the prefix

heavy sluice
cosmic vine
#

is there any way to see what changes to the new ui are being worked on based on feedback which has been submitted? i'd like to know if i need to start creating my own workarounds to make the new ui easier to use or if the bugs will be fixed sometime soon

fathom pendant
sour ether
fathom pendant
#

you specifically pinged me about a random question you had regarding what you're asking about. see #rules

glad flicker
#

nvm

hardy jacinth
#

hola

tidal steppe
#

Is there any code review modules? I don’t know that much about code review but I wanna learn

cloud urchin
hardy jacinth
#

it similar to duolingo

tired olive
#

Is there a way to go back to the classic academy layout?

#

i really preferred it over the new one haha

hardy jacinth
#

which is better focus on attack or DEFENSIVE

#

if any one have an idea about that plz told me

tired olive
hardy jacinth
#

i study right now network

fathom pendant
swift carbon
#

More jobs in defense, if that matters to you

hoary herald
#

Hello

#

I need help with a module; I've been trying for a long time.

#

Can someone help me privately or should I send my question here?

fathom pendant
#

People cant help you if you dont at least say what module and section you're working on

#

Asking here is fine just be mindful to avoid spoilers for modules above tier 0

fathom pendant
hoary herald
#

Help me for dm.

fathom pendant
hoary herald
#

Ok.

fathom pendant
#

The question says "directory" check common places where an admin might tell scrapers not to look

hoary herald
#

I tried with several dictionaries.

#

List subdomains and directories. I'm not getting anything.

#

Neither subdomains nor directories appear. I tried with other dictionaries and they didn't work either.

jovial walrus
#

how is privileged groups section diff from lxd in linux priv esc module...seems pretty much same except diff container image ?

#

why is it that we skipped the lxd initialization process in lxd section but we did it in privileged groups section before importing image?

little terrace
#

im doing AEN, and i cannot RDP at all. ive tried rdesktop, xfreerdp3 and remmina and it all doesnt work. i dont want to use the pwnbox to do this. im pivoting using ligolo too so it shouldnt be that hard

any help?

fathom pendant
fathom pendant
little terrace
#

so even if a bh scan says that the account can rdp, and nmap shows that the rdp port is open on that machine, there is an extra config stopping me from rdping in?

fathom pendant
#

like i said i'm not gonna spoil too much about AEN as I generally advise people to do it blind, I suggest as well trying to reset the lab, changing vpn regions, etc

little terrace
#

nvm turns out /timeout:100000 needed to be added because it took too long each time

burnt thorn
#

Hello, I’m sorry if this isn’t the correct channel to ask this. May I know if it’s possible to transfer or donate a cube from one account to another?

autumn pilot
#

nope

burnt thorn
silver fable
#

Hi, I'm working on question about cracking hash of Mark's password. I tried multiple ways to generate wordlist, cupp only, cupp + rules, words + rsmangler, but I'm still not successful. Can anybody help me with that? Steer me into right direction?
Module: Wi-Fi Password Cracking Techniques
Section: Generating Wordlists

stuck hollow
#

In module Introduction to Malware Analysis section Interactive windows internals, I am unable to keep RDP open; it constantly closes on its own, preventing me from working on the questions. Any help please? im using xfreerdp3, cant move forward

stuck hollow
#

Any help please?

regal gust
#

Hi all. Stuck on command injetions, section 3 (filter evasion), subsection 3 (bypassing other blacklisted characters), question 1.

The question is asking me to find the user in the / home directory, using env variables to avoid the blacklist. Not sure why me command isn't working? Also found that only ls is accepted, all other commands fail, which is whacky.

ip=127.0.0.1${LS_COLORS:10:1}%0als${PATH:0:1}home

#

And full BURP output:

#

Any help would be much apprechiated

#

Also tried adding another %0a between the ls and the /home

#

This just provides ls output for the present directory

#

Ah, solved my problem haha. Turns out just typing my thoughts out helped

#

Thanks for being an inadventant rubber ducky :3

#

Insne lab haha

short vigil
#

Question on file transfer module section 2 question 2:
‘upload the attached file named “upload_win.zip” to the target with method of choice. ‘
Where is this attached file? No resource tab within the module

short vigil
plain hare
#

Hi All, quick question has anyone done the skill assessment for the Advanced XSS and CSRF Exploitation? im currently 75 in the exploitation, but have a question, anyone that could help?
i dont want to spoil so DM would be prefered if anyone has completed it

short vigil
brave field
#

dm please

keen zephyr
shell panther
#

Hi, can some1 assist me in the info gathering module, i cant set up the enviroment

cosmic radish
#

Hello ! Is there anyone that's finished the skill assessment on linux forensics that can help me with question 4 :

What is ParentProcessId for a sh command which sends a password using echo to the sudo python3 process?

I found a log that has the exact field and matches the description to a T but the answer isn't accepted.

plain hare
#

Hi could i get some help with skill assessment for the Advanced XSS and CSRF Exploitation?

keen zephyr
#

Finally, I've solved the 'Information Gathering - Web Edition' assessment challenges hahaha

#

Thanks @brave field for helping me out, you rock

worn pine
#

hi, i'm currently working on "Evil Twin Attack on WPA2". i tried using my own vm but the vpn config keeps refreshing every 5 minutes, so i tried pwnbox. But i got stucked here.

rare ether
#

Hi! In regarding of AI Data Attacks: Execute the Attack (Section 24 / 25), the host cannot connect target:

#

same problem there

gray yacht
worn pine
silk ice
#

Hello, can I ask why the rockyou.txt on HTB pwnbox doesn't automatically come as .txt instead of .txt.gzip? Like is there a particular reason it is shipped this way?

fathom pendant
#

should be able to use the wordlist from the reading

tawdry goblet
#

Oh. I was trying to slov5 it with5 the worldlist file

cloud urchin
cloud urchin
plain hare
#

Hi, all, could i get some help on the skill assessment for the Advanced XSS and CSRF Exploitation? has anyone completed it?

normal fiber
#

Who can I dm help for windows lateral movement assessment on HTB

cloud urchin
#

You can DM me

fathom pendant
silk ice
silk ice
fathom pendant
#

as super said, filesize, if you need the space leaving it zipped is fine

jovial walrus
#

can someone help me with logrotten on linux priv esc module ? I have heard how horrible this section is with multiple attempts requried to get a connection back and I am stuck at the same step

autumn pilot
#

if you can't get a connection simply get the flag, in either situation you are tasking the root user to run a command

lusty terrace
#

currently doing AD skill assessment I just finished Question 4 - Submit the contents of the flag.txt file on the Administrator desktop on MS01 however I don't think I got the answer how the question wants me to

#

can I DM someone?

jovial walrus
#

this lab needs to be changed ffs

vale trail
#

academy v2 bug?
my dashboard keep showing completed modules instead of the module i'm currently going trough
already tried going trough the module again by clicking "mark complete & next" and "finish" at the end

vale trail
#

i dont have this banner ... might have closed it earlier

silver fable
#

Module: Wi-Fi Password Cracking Techniques
Section: Skills Assessment
I'd like some hint on enterprise network. I think I have problem with getting right wordlist. Anybody for a DM?

gray yacht
plain hare
#

Hello, who can I dm for questions about the skill assessment for the Advanced XSS and CSRF Exploitation on HTB?

charred crest
#

hello

silver fable
#

somewhere I made mistake, I don't know where. Had to revert everything and do it again

heavy sluice
wind forum
#

yo is question 4 web archives in information gethering - web edition cooked?

#

im pretty sure i have the correct answer

#

nvm

vestal birch
#

Hello, for the Introduction to Malware Analysis module I’m having trouble accessing any of the target systems. I’m using openvpn and it’s successfully connected on my Linux vm. Any suggestions on how to remedy this?

sick meteor
#

Module:Http Attacks
Section:Log Injection
I'm not finding how to evade or bypass the filters. Maybe I'm misunderstanding the question? From what I understand I need to inject PHP code to rce to get the flag but I'm stuck. Characters like < are either stripped out or the encoding I'm attempting isn't decoded. Any hints?

sick meteor
#

Nevermind

plain hare
#

Who from HTB team can I ask for help?

fathom pendant
#

well the answer is support on the website, but it depends on your question

compact patrolBOT
plain hare
fathom pendant
#

i haven't done that module

edgy crystal
#

Can someone offer help for Comparison Operators? It is part of the "Introduction to Bash Scripting" and I'm worried that because of the recent update there is a problem with the question.

For refrence, this is the question:

Create an "If-Else" condition in the "For"-Loop that checks if the variable named "var" contains the contents of the variable named "value". Additionally, the variable "var" must contain more than 113,450 characters. If these conditions are met, the script must then print the last 20 characters of the variable "var". Submit these last 20 characters as the answer.

hexed oyster
#

Been banging my head on 'Attacking Common Applications -> Final 2'. Would really like some feedback if anyone has the time. I've got notes.

tired olive
#

any ideas on how to correct a 'no rdp scan code' error ?

#

i keep resetting the target but am getting that when i try to rdp to it

fathom pendant
edgy crystal
# fathom pendant try the last 19 characters

Thank you for the reply. My challenge wasn't printing the last 20 characters, but rather finding var when it contained value and was over 113450. I can send you my code if that's alright.

fathom pendant
#

not avail for code review; but the question tells you what it wants. you have part 1; you just need part 2 -- getting the last 20 chars

tired olive
fathom pendant
edgy crystal
quasi wave
#

hi I'm doing the automatic modifications section of web proxies module and I have had some issues with automatic modifications. I can't tell you what I am supposed to do without spoiling because its step by step instructions that I am supposed to follow. Is anyone available today for a DM?

#

preferably someone who uses web proxies such as Burp Suite?

#

My issue is I am trying to intercept a request and responses to it but its not letting me select which request to modify

#

And I need to intercept a specific request automatically

quasi wave
#

hi now requests are SOMEWHAT being intercepted automatically but not really

#

because I forward the requests and they don't always perform commands automatically

#

but the user agent modification was made automatic successfully

#

hold on I think I got it working

#

now doing burp repeater section

#

never mind I solved the next section on my own

#

it took a little bit of thought

#

I don't need help with this after all

faint gulch
#

Is anyone free to a DM regarding the NTLM relay attacks assessment (Q2)?

rustic geode
#

hi i need a hint for the Skills Assessment - File Upload Attacks
i got the source code of upload.php
but i can't to upload the webshell even if i use the file name that can bypass the filter

fathom pendant
white vale
#

Its so confusing that Skill Assessment

white vale
fathom pendant
tired olive
#

what to do if a section is stuck on target spawning?

fathom pendant
white vale
fathom pendant
white vale
tired olive
fathom pendant
white vale
#

Also I dont see any videos of this new skill assessment is it because is tier 0?

#

Can I create my own video but using a mock up page similar? Or is this not permitted

white vale
#

Sorry, I meant File Upload attacks

fathom pendant
#

file upload attacks is tier 2 that's why there's no writeups on it.

ornate wigeon
#

Why is the publickey timed so fast?

lusty terrace
#

Anyone can give me a hint on AD Enum & Attack Question 6, I tried recursively searching for "password" but it gives too much information that I couldn't process them

lusty terrace
#

the module didn't say search....

#

I read it as search for cleartext

#

what kind of dumbness is this

ornate wigeon
#

I can’t log into bash NotLikeThis

foggy monolith
#

Just ran into this same problem myself. Literally always hangs and times out.

#

There was only like one instance where it didn't hang and time out and in that case the remote result was radically different from local evaluation.

#

If there's a problem parsing a model, the server should send an error message. It shouldn't just hang.

ancient coyote
#

Issues with the DC in PTPF: Port Forwarding with Netsh? Or just me

#

Ran test-net connection from the pivot host and it failed on 3389 and 445, I’ve restarted the lab 3 times

left lintel
#

oh lol

#

i didn't realize

#

but did that solve the issue lmao

tribal lark
tired locust
#

Hi guys!
I'm trying to perform RDP tunneling in pivoting module.
Firstly I downloaded SocksOverRdp.zip file into my attack host,after extracting I transferred the dll file to my target windows machine,however when I run it,I encounter this error.How can I fix it?

dusk holly
tired locust
tired locust
dusk holly
shut wraith
#

Hello, in the kerberoasting module, it just shows this but doesn't show the creds to connect to the windows machine...

brave field
tired locust
dusk holly
tribal lark
shut wraith
#

Thanks guys found it

topaz tundra
#

How ican it be fixed ?

brisk drift
#

Hey guys, for the course Antak Webshell in the shell & payloads module, i did everything i should, but i just don't understand the format of the flag x), may someone help me pls !

#

The question : Establish a web shell with the target using the concepts covered in this section. Submit the name of the user on the target that the commands are being issued as. In order to get the correct answer you must navigate to the web shell you upload using the vHost name. (Format: ****\****, 1 space)

#

what mean the 1 space ????

dusk holly
brisk drift
#

I tried everything

#

May i just dm u to send my answer and u just tell me if the format is wrong or the all answer

hexed oyster
#

OK, I feel like I'm officially stuck on 'Attacking Common Applications -> Final 2'. I've foot printed and enumerated everything I can think of. I've found several vhosts. Fingerprinted what I could about them, which wasn't a lot. Attempted to brute force the password on them but I'm coming up goose eggs. Any advice?

native socket
#

Hello everyone. I am working on the SOC Analyst module. In the first section, Incident Handling Process. I am trying to access The Hive so that I can answer the question. As far as I know I am doing it correctly to connect. I have started the target, and I have put http://10.129.13.2:9000 in firefox and it will not connect. I was hoping to receive some guidance, am I not doing something correctly? Thanks a lot, looking forward to any advice.

fair zinc
#

Need help on wifi passwords cracking techniques, found all passwords except ClyraCloud-ORT. Ik i need to focus on netgear passwords here but generating them didn't help either and I've exhausted most of my options

ancient niche
#

ey guys I need you help please. I canno't get it the reverse shell and i don't know why

#

module stack-buffer overflows on windowsx86

tulip knoll
#

hello im just a begginer im currently on the linux module the q was How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)
but i had to exclude locals and ipv4 for the response im pretty confused about it, its not like they are asking for all of them?

white vale
#

finally, learn a new skill on that assessment !

#

you guys are very sneaky lol hats off to the creator

#

@mortal basin

shrewd locust
#

Hello, SocksOverRDP module, the second target on the internal network is not working - not responding to any ping or any rdp connections

cloud urchin
cloud urchin
#

yeah you're not on that subnet

#

you need to pivot

shrewd locust
#

I tried many times, the host does not even respond to rdp

#

Ok i got it, the masks made me confused 😅

fresh moth
#

Hi team im stuck at something im in an ad enviorment i have a list of usernames i got from ldapsearch , how to i check if any of the users are valid with a list of password ? the thing is the password file is rockyou will take forever .. so is there an easy method?

Im at the ad "AD Enumeration & Attacks - Skills Assessment Part II"

Q4:-Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.

vagrant canyon
vagrant canyon
fresh moth
#

ok il try

fresh moth
warm pumice
#

where is the integrated terminal in academy 2.0?

cloud urchin
#

The pwnbox? It's just above where you spawn the target.

#

It won't be shown in sections that aren't interactive

weak patrol
#

I have a question concerning the 'Attacking Windows Credential Manager' module...
How do you transfer mimikatz to the windows account you're working on?

fathom pendant
cloud urchin
#

ahhhh that

vestal geyser
#

dacl

autumn garnet
quick granite
#

The new academy GUI is so frustrating....

#

I really hope they revert it with so many people disliking it

jovial walrus
#

Recent 0 days sudo section CVE-2019-14287 in linux priv esc module
how are we getting a root shell when we r trying to fetch id as root ?
just couldnt understand this cause the priv is that we can run id as all users

lusty terrace
#

everything takes like a billion second to move

cloud urchin
#

@dense pawn Please take care not to post content from modules above tier 0

dense pawn
cloud urchin
#

Here. Just ask without spoiling content or posting content. If you feel like you need to reveal more info you can ask to DM someone. Anyone who has done the module doesn't need all that context because they already know the answer.

dense pawn
#

For Question 8 of AD Enumeration & Attacks - Skills Assessment Part II, how do they retrieve the plaintext credentials? it says the "hex can be decoded", but i dont understand how, the data returned for the service account in question is a dcc2 hash.

lusty terrace
dense pawn
autumn gulch
#

Anyone here to help me

mint cargo
#

Hey all, was wonfering if anyone could give a nunge in the right direction, been working on the Attacking Wi-Fi Protected Setup - Skills Assessment: What is the WPS PIN for the WiFi network named HackTheBox-Corp?

Ive generate a list of possible pins using wpspin, utilized the bash script with reaver, its been running for a few hours now and i dont know if ive gotten myself in a rabbit hole or not

Any help hints or tips would be appreciated! cheers

pale island
autumn gulch
elfin patio
autumn gulch
#

I run same command like 5 times after i get correct flag .. 😪

radiant jolt
#

I'm silver annual, i don't think i will study this week, will my steak be lost, there was a message before tha it will use one of the blue icons, but i don't see it anymore, not sure if something changed, anyone can give me some insight on this?

tender nimbus
#

if needed: password attacks - Pass the Ticket (PtT) from Linux
Hey guys, it is not really a module related question but can someone explain to me what happens here? I understand the proxychain part, it is like to execute tools from our attacker, the packets will be send to 1080, but I don't understand the chisle part? We launch a server, the target connects to us, but when we execute a command on our attacker with proxychians, how does chisel or proxychains know that it has to go to the target? proxychains is on port 1080 and chisel 8080?

stark hedge
lusty terrace
crude grove
#

Reversing Hybrid Apps
Android Application static analysis

please I need help I don't understand the question, do I have to actually login to the app or just find the message in the code?
I'm confused and stuck here

sharp fog
#

"Hi everyone! I'm currently stuck on the Linux Fundamentals module (Question 6 about the MTU 1500 interface).

I've run ip link | grep "mtu 1500" and my terminal shows three interfaces: ens3, lxcbr0, and tun0.

I've tried submitting all of them (ens3, tun0, lxcbr0) using copy-paste, and even tried 'eth0', but the platform keeps saying it's incorrect. I'm connected via SSH to the target.

Is there a known bug with the instance htb-hpxhpmruoz or am I missing something specific here? Thanks for your help! (Attached is the screenshot of my terminal)"

sharp fog
#

I thought the answer was ens3, but the platform won't accept it. Any idea why? Thanks for the help!

verbal ivy
sharp fog
verbal ivy
#

ip a | grep 'mtu 1500'

sudden cloud
#

Hey! It's a bit hard to explain but I can't figure this out. I was trying the lab in the academy module "file upload attacks>type filters" and I got the flag. But I was wondering how are we able to execute the final file shell.jpg.phar (also shell.jpg.phtml worked) on the server if I uploaded the web shell with a different name (shell.jpg.inc)? basically how is it possible that the web shell that I uploaded with a name gets executed with another name?

crude grove
stark hedge
# crude grove Why does it have to be so confusing?

I haven't done this specific module but since it's a about static analysis, I assume you don’t actually need to run the application or log in to any live service, but instead you should decompile the APK and look for the logic inside where you will likely find the key.
But again this is just my assumption.

verbal ivy
#

Anyone have the link where you can input the student ID and track his progress? , looks like it's broken in the new version .

crude grove
stark hedge
crude grove
stark hedge
cloud urchin
#

Yes, it's a requirement to complete the path before you may start the exam.

crude grove
#

yes

cloud urchin
#

No need to try and ping admins/mods/staff.

#

Just be patient and maybe someone who has done the module will help.

silk lagoon
still coral
#

Anyone done the Bufferoverflow module? I don't understand the question "How large can our shellcode theoretically become if we count NOPS and the shellcode size together?" Can anyone help me out?

clever rapids
hardy jacinth
#

Examine the registers and submit the address of EBP as the answer.

0xffffd598

#

The answer you provided is incorrect ???>???????

#

(gdb) info registers ebp
ebp 0xffffd598 0xffffd598

fathom pendant
verbal ivy
#
Student ID

Your unique Student ID lets others view your progress in HTB Academy.

Learn more here
HTB-9ECXXXXXX
#

someone can't track my progress using this ID ?

fathom pendant
#

Due to my own reasons ive had this conversation

verbal ivy
#

that's actually very unfortunate as would be nice to add it in my c.v as progress etc ..

fathom pendant
#

You.... you can... not sure which institutions have it

verbal ivy
#

instead of exporting the whole progress via a pdf it can be availalbe online using the ID

fathom pendant
#

Institutions being companies and schools

fathom pendant
#

No

#

About the lack of transparency overall about it

verbal ivy
#

it's only there for tracking students who actually have the subscription through there Institution* if i understand

#

i saw something before to check the status i think it was for prolabs and i mistaken it for academy spent half an hour looking for the endpoint FeelsBadMan

quasi wave
#

I just did another section on my own. Gonna do yet another soon in like ten minutes. I'm psyched.

#

Maybe in a couple months I'll be helping other people with CWES modules.

#

This is gold.

#

I don't have a section I need help on today but just letting you guys know.

trim flint
#

i have question in nmap lab ask here ?

cloud urchin
#

Yes this is the right spot, just take care not to spoil content from modules above tier 0.

trim flint
#

the medium lab

cloud urchin
#

if you need to reveal more info you can ask if someone can dm you about it

trim flint
#

of Firewall and IDS/IPS Evasion i get answer witcg is the domian server

#

if anyone can help dm me please

#

🫠

#

can i send my expected answer only ? and for the method to get the real answer

cloud urchin
#

@verbal ivy It applies to all subscription levels of HTB. They don't want the content to be leaked, understandable. The writeup in the higher tier subscriptoin is still part of their content.

verbal ivy
viscid bolt
#

Can anyone give guidance on Active Directory Trust Attacks - Skills Assessment Q1: Gain access to the "Inlanefreight.ad" domain and submit the contents of the flag located in "C:\Users\Administrator\Desktop\flag.txt"

|| Found foreign group stuff but that is about it, haven't owned the child domain yet, a little stuck ||

verbal ivy
#

Hope i helped without helping so we don't get mutedwaz

viscid bolt
verbal ivy
#

Yes you are , just check which group your user belongs to and it should ring a 🔔

hardy jacinth
#

sws

tired olive
#

am i allowed to be making writeups of skills assessments if im not including answers

cloud urchin
#

It's against ToS to post anything over tier 0.

tired olive
#

okay thank you

tired olive
#

I know you can make writeups of retired boxes but wasn’t sure if there was any flexibility with Sherlock’s

cloud urchin
#

I don't know

plain hare
#

Hi, all, has anyone completed the skill assessment for the Advanced XSS and CSRF Exploitation? im currently stuck and looking for some help

lusty terrace
#

i'm doing AD enum and attack - skill assessment II question8 I got a reverse shell on metasploit and uses the "auto" PE and tried to dump sam, which got a hash but couldn't connect to any others, but in a writeup I saw they did the same except they did smth different but ultimately dumped sam as well but their hashes could be used to connect..... what am I missing?

#

we both did lsa_dump_sam

fathom pendant
quiet halo
#

im having trouble with taask 4 in pillaging from windows priv esc module

#

I checked the env and also history file and I found the password but htb is not taking it

turbid mulch
#

I am working on the 'Host Discovery' section of the 'Network Enumeration with Nmap' #module but find the wording of the question a bit confusing. "Based on the last result, find out which operating system it belongs to. Submit the name of the operating system as result." In this context does 'the last result' refer to the previous Section or the last operation carried out in the Pwnbox? This Section is about using Nmap to discover what services are running on a server so my presumption is that the question is attempting to ascertain what operating system is running on the Pwnbox but when I enter this as the answer to the question is comes back as incorrect.

untold orbit
fathom pendant
#

it gives a sample SENT/RCVD set of packets with various bits of info in them

stark hedge
# weak patrol Anyone?

Generally, there are many ways to transfer files to a target. I’d highly recommend going through the File Transfers module.

weak patrol
#

I will go through it again…
Thanks

fathom pendant
spare fossil
#

where is the flag ?
Wi-Fi Penetration Testing Basics/Connecting to Wi-Fi Networks/
Connect to the WPA Wi-Fi network named "CyberNet-Secure" with the PSK "Password123!!!!!!". Once connected, locate the flag at the IP address 192.168.1.1.

i've connected, where do i find the flag ?

heavy sluice
spare fossil
#

i will try with curl

narrow elk
#

In Attacking Common Service, the "Attacking FTP" section spawns a SMB target instead of a FTP one.

heavy sluice
fathom pendant
foggy monolith
#

Why is AI Privacy § Data Partitioning and Teacher Training causing this?

wraith crystal
#

hello, im new here, im experenced with linux but i cant seem to ssh into the first machine in linux fundamentals (system information). tried both with htbs pwnbox and with my own openvpn but i get

C:\Users\(user)>ssh htb-student@10.129.16.6
htb-student@10.129.16.6's password:
Permission denied, please try again.

ip is fine, copied straight from the exercise. user is fine, password is copy pasted too. i have no clue what im doing wrong

open siren
#

Hey guys, on HTB I am currently doing a module(https://academy.hackthebox.com/app/module/77/section/726) that requires me to perform an extremely simple Nmap scan for the version of the serice running on port 8080, which should be simple. However my scan did not produce a version, in fact it was initially returned as Host down, so I have to use -Pn
Any solutions?

fathom pendant
#

Works fine for me, if you're having to use -Pn then it seems like your VPN connection is messed up

#

sudo killall openvpn then re-run the openvpn connection

#

ah with the added context, then i'd double check that you're still connected to the vpn; i generally and will always advise to do things like this from a vm. It sounds like you're doing this from wsl, which is honestly more of a headache than it's worth on a good day

open siren
#

ahh ok ill try that

#

sry i didnt reply for a while

#

ohhhhh just saw now that a vpn file was indeed available for this excercise

#

that makes sense

#

ty

compact sigil
#

Hi, I verified my student email, but for some reason it's not giving me to the student discount for HTB academy, did I do something wrong?

compact patrolBOT
fathom pendant
compact sigil
hardy urchin
#

Hello guys, i work on the skill assessment for Information Gathering - Web Version. I dont know if iam running down a rabbitwhole... i found a subdomain and extracted the api token, now i need to crawl inlanefreight.htb - The page only returns the index.html, i cant find any emails.

fathom pendant
hardy urchin
fathom pendant
#

i'm being vague on purpose so as to not spoil for others

hardy urchin
#

ill get back to recon

fathom pendant
#

just remember there can be multiple layers to subdomains

#

a.b.do.main
c.b.do.main
e.b.do.main
etc

hardy urchin
analog urchin
#

Where can I download the vpn for academy in the new version of the academy? 😭

heavy torrent
#

can I please get a nudge on the "Dynamic Analysys" section of the "Introduction to Windows Evasion Techniques" module?

#

I am able to get a reverse shell but cannot read the flag. Which seems obvious to me as I am using alpha user.

twin gulch
#

Anyone Who done ZAP Fuzzer - Using Web Proxies ?
I hate this tool and messing with the question

barren island
#

Hi guys, I'm doing the Wi-Fi Evil Twin Attacks Skill Assessment module; I am stuck on the second and third question, does anyone could help me with it?

verbal ivy
verbal ivy
weak patrol
#

I am having issues finding a username for this question, I have run some commands but they don't seem to give me the right output.
Once the command is done running I get "2026/03/17 00:47:23 > Done! Tested 21 usernames (0 valid) in 1.113 seconds"
May I DM someone so that I can show them what I did and maybe they can point me in the right direction?

weak patrol
verbal ivy
#

lm check

weak patrol
#

Okay

verbal ivy
#

which tool u used to generate the usernames?

#

am sure if you use username-anarchy it will be there

weak patrol
#

username-anarchy

verbal ivy
weak patrol
#

yes I used this tool and it generated the possible usernames but after running them through kerbrute I still didn't manage to find the right one. not sure what I did wrong

verbal ivy
#

lm verify

weak patrol
#

okay

verbal ivy
#

i tried

#

it works

weak patrol
#

can I dm you?

verbal ivy
#

just run the tool directly

#

without anything

#

you get like 15 usernames

weak patrol
#

what do you mean without anything?

verbal ivy
#

./username-anarchy John Marston > users.txt

weak patrol
#

ah okay

#

let me try it

#

what domain did you use for inlanefreight?

verbal ivy
#

run it with crackmapexec

#

do password spray

quiet halo
#

is anyone have issues with the Windows Privilege Escalation Skills Assessment - Part I machines? i restarerd a few, none work. I tried other machines and they work just fine

severe inlet
#

i just spent an hour on the medium lab on the Network Enumeration with Nmap module

Turns out the same command on PwnBox gave the flag its a bit annoying anyone knows why?

pine valley
#

guyss who know how to see password target i cant connect target because i dont know password target how to get a password target htb not provide it

tranquil crystal
#

Linux Fundamentals I assume

pine valley
#

yess of course from module operation system fundamental im choose linux fundamental

pine valley
tranquil crystal
pine valley
#

whait

#

okey here is full page screenshoot

#

section 6 still very new basic waz

tranquil crystal
#

It gives you the password

pine valley
#

why you have it

#

in my option nothing hint

#

owhh faakkkkkkk thnk youuu

#

im skip question 1

#

ty ty ty

tranquil crystal
#

Np

#

Glad I could help

pine valley
#

yess because from yesterday im so confused like wtf how

pine valley
#

thankyou @tranquil crystal finally im passed the test after 1 day im confused mwmwmwmw thank u so much may god bless u

tranquil crystal
#

You're welcome

glacial pasture
#

In this module, Active Directory Enumeration & Attacks
the bloodhound data and enumerating using PowerView gives nothing to answer this question

untold orbit
glacial pasture
#

I used multiple Custom cyphers that search for it and nothing matched any of them sadglas

wooden seal
#

where do i download vpn profile for academy in this new UI? 😭

wooden seal
#

💀

#

thanks for fixing my blindness @glacial pasture

glacial pasture
wooden seal
#

wait i am not getting anything next to pwnbox

#

i wasnt blind

#

And yea FYI i had silver sub but i am on free tier now and revisitng the completed module to do them again
incase it affects this

junior swift
#

You could've also just looked for the Remote Management Users group on Bloodhound, assuming your ingestor collected it properly.

glacial pasture
junior swift
wicked oxide
#

Hello all 🫡
Got a question, i'm trying to redo the skills assessments in the CWEE path and some modules that require to download the source code are missing the download button on the new UI.
Am I blind or ?
I saw the message on the dashboard concerning the fixes for errors in module completion but i wanted to be sure if that concerned this too or if i missed smth

I will share a screenshot of the SA of INTRO to WHITEBOX PENTESTING

Thanks for the help

twilit wind
#

Is there any way to get back the 1.0 UI it makes the page very very laggy for me and almost unusable

verbal ivy
#

first check what type of hash is it ? > use the magic decrypt in cyberchef
didn't do that course tbh

opal hound
#

Hey guys, I’m stuck on AD Enumeration & Attacks - Skills Assessment Part I
the question: (Q8) Take over the domain and submit the contents of the flag.txt file on the Administrator Desktop on DC01
what im struggling at is i run runas /netonly /user:INLANEFREIGHT\tp**** powershell to open a new powershell as tp****. then i run mimikatz.exe on that powershell window but the problem is that it doesnt have administrator privilege to run mimikatz. Can some1 help me?

verbal ivy
gray yacht
#

CyberChef sure does SHA256.

verbal ivy
#

it's a one way hash not encryption

gray yacht
#

After scrolling up a bit more, I now see the initial question. Lol

native socket
verbal ivy
#

send me the hash

gray yacht
#

So you likely have to keep using other parts from CyberChef

verbal ivy
#

can you screenshoot the question ?

#

or link the section of the module

#

link would be better

#

so i see the file

#

send me the link

#

which section on the module

#

or the name of the section you doing

#

i do have access to SOC path

gray yacht
#

Hey if this module is above Tier 0 you need to delete the content you posted and take it to DMs.

opal hound
#

so i run secretsdump on kali and manage to get the admin hash. tyvm

gray yacht
#

It's all good

verbal ivy
#

you are trying to decode the wrong value , read the question carefully .
look at the logs and > decode the command.

native socket
verbal ivy
#

you are obviously overthinking it

#

Not sure as i closed thevlab ,but please don't post them here .

warm horizon
#

Why did the gym's IP address become like this now, without the port even being opened on the gym's computer? curl -I http://10.129.234.166/phishing/index.php
curl: (7) Failed to connect to 10.129.234.166 port 80 after 21061 ms: Could not connect to server

native socket
native socket
native socket
strange needle
#

is it a sign to skip prevention module?😆

shut quest
wicked oxide
cerulean bramble
#

So, I just spawned a target system and I'm noticing that it gives me an IP but no port number. I know they recently changed the UI. Is there somewhere I'm supposed to be able to find the port number of the spawned system? I'm working on the AI Data Attacks module in the Pickles and Steganolgraphy section.

echo agate
#

I am having trouble with the machine in this module - https://academy.hackthebox.com/app/module/145/section/1295.

The machine is reachable via my Parrot attack box via VPN.

└──╼ $ping 10.129.18.90
PING 10.129.18.90 (10.129.18.90) 56(84) bytes of data.
64 bytes from 10.129.18.90: icmp_seq=1 ttl=63 time=155 ms
64 bytes from 10.129.18.90: icmp_seq=2 ttl=63 time=516 ms

nmap shows a web server running on port 80

┌─[user@parrot]─[~/vpn]
└──╼ $nmap -sV 10.129.18.90 -p 80
Starting Nmap 7.95 ( https://nmap.org ) at 2026-03-17 17:37 UTC
Nmap scan report for 10.129.18.90
Host is up (0.19s latency).

PORT STATE SERVICE VERSION
80/tcp open http Apache httpd 2.4.59
Service Info: Host: 172.17.0.2

However, i can get any data back from port 80. The browser hangs and so does wget.

└──╼ $wget 10.129.18.90
Prepended http:// to '10.129.18.90'
--2026-03-17 17:38:40-- http://10.129.18.90/
Connecting to 10.129.18.90:80... connected.
HTTP request sent, awaiting response...

I have restarted the target several times. I even read the solution which indicates it should be straightforward to access the page on port 80.

Any ideas are welcome. I am stuck.

analog urchin
#

Maann where are the vpns for academy 2.0??

fathom pendant
echo agate
fathom pendant
echo agate
# fathom pendant It is, thats the name it downloads as. Academy-regular => regular academy usage...

hmm. I was connected via the regular vpn when i posted the above message. I downloaded the vpn next to the pwnbox as you mentioned and the wget began to work.

┌─[user@parrot]─[~/vpn]
└──╼ $diff academy-regular.ovpn academy-regular2.ovpn
3,4c3,4
< proto udp
< remote edge-eu-academy-3.hackthebox.eu 1337

proto tcp
remote edge-eu-academy-3.hackthebox.eu 443
65c65
< <tls-auth>


<tls-crypt>
87c87
< </tls-auth>
\ No newline at end of file


</tls-crypt>
\ No newline at end of file

fathom pendant
near grotto
#

Hi Team, can anyone help in this ques htb cape, bloodhound mudule ques "Find the percentage of users with a path to GLOBAL ADMINISTRATOR. Submit the number as your answer (to two decimal points, i.e., 11.78)."

#

I divided the Total global aministrator / Total azuser * 100 but didn't find the anss

viscid bolt
#

Still on Active Directory Trust Attacks - Skills Assessment Q3: Gain access to the DC04 (Mssp.ad) and submit the contents of the flag located in "C:\Users\Administrator\Desktop\flag.txt" A little stick if anyone can assist!

|| Looked at Trust Account attack, but did not work, for outbound one-way it looked like the goto technique, if anyone has more guidance! ||

viscid bolt
young tinsel
#

having some trouble on the module Web Server Pivoting with Rpivot - for some reason, my proxy is just refusing to work even though i've quadrple checked my rpivot commands on the client & server + proxychains.config

gray yacht
strange ravine
#

i'm struggling with Introduction to Bash Scripting, section Comparison Operators

The question is "Create an "If-Else" condition in the "For"-Loop that checks if the variable named "var" contains the contents of the variable named "value". Additionally, the variable "var" must contain more than 113,450 characters. If these conditions are met, the script must then print the last 20 characters of the variable "var". Submit these last 20 characters as the answer." but everytime i run my script it outputs nothing and i'm not sure where im going wrong

strange ravine
quasi wave
#

I completed another section today on my own. I'm killing it.

#

later today I'm gonna do two more. I'm a little tired because I need food for fuel but I'm gonna do really well with this. I am taking a break to get some food.

cerulean bramble
#

Does anyone know where to get the port number for spawned targets now?

cloud urchin
cerulean bramble
cloud urchin
#

Always best to say which module and section you're on if asking for help

cerulean bramble
cloud urchin
#

there are a lot more parts to that section

#

best to say exactly which section not generic

cerulean bramble
#

So, the exercise is in the "Execute the Attack" section but you build the script throughout that section. The part of the script that requires the "api_url" is in the Execute the Attack section.

cloud urchin
#

did you try just visiting standard website ports

#

80/443

#

or nmap

cerulean bramble
#

I'm running an nmap scan now but it hasn't found anything yet. 80 is the one that fails. I've also tried the 5555 that's in the example.

cloud urchin
#

maybe someone who has done the module can chime in then

cerulean bramble
#

Thanks for trying. I'll keep scanning and trying things and hopefully I'll get it.

quasi wave
#

hi for the Burp Intruder section of Using Web Proxies module, I am fuzzing every file ending in .html and it says I don't have permission to access the resource. I tried changing my User Agent and it didn't help. Can someone give me a hint? I am searching in the /admin folder.

sterile solstice
#

I'm currently trying to do DACL II - Skills Assessment. Can someone give me a nudge for Q1. I'm missing something, and unsure what.

feral adder
#

Hey guys do you have any idea where's the resources tab located in the new UI of academy? in the said module of FOOTPRINT SMTP it said there's a wordlists needed to download to finish the task but I haven't seen where it was unlike before the previous UI it was at the bottom.

#

NVM, I found it.

sterile solstice
keen zephyr
#

Hey guys.
I'm solving the SQLi skill assessment challenge and I'm being unable to submit the flag I found.

The challenge says:

Achieve remote code execution, and submit the contents of /flag_XXXXXX.txt below.
I did managed to achieve that RCE and extract the flag, but again, the platform says my answer is incorrect.

I also did checked for empty characters around

earnest jacinth
#

heey, do you remember how you've solved this question ? I'm facing the same issue

lone ferry
#

Anyone else having issues with targets dropping connections? Trying to finish WinPrivEsc module but any RDP session times out after a command or two…

vocal schooner
hidden ledge
#

Hello does anyone knows why responder + smb authentication fails with ligolo ?

#

Comes from mssql xp_dirtree, reverse shell is working well but anything on port 445 seems to fail

#

Resolved.

hidden ledge
brave field
hidden ledge
#

Yes I know that I always run the proxy as root 🙂

brave field
warm horizon
#

My friends, I have a question: the gym's IP address now only works if you download a VPN, right?

white vale
#

I am surprised I am not having issues right now

heavy sluice
# white vale

Isn't that normal? Your traffic would go around the whole world if you the other servers

white vale
#

but also really happy with the content in bth academy and how some labs are build

#

for example a target with ip 154.57.x.x makes it so convenient for testing

thin hearth
#

hi, i can't access to hackthebox academy with brave browser ? anyone have same trouble ?

sick bane
#

Yes. It seems the site is not loading properly.

vocal phoenix
#

same

turbid scarab
#

Same

jolly spruce
#

Yep, same here

#

From Edge browser

final shale
#

the damn new design. I told them it sucks.. 😄 😄

vocal phoenix
#

After some time it loads

zealous fiber
#

For me it loads, but its suuuppper slow

final shale
#

They basically forced the BETA on us to test

jolly spruce
#

Even for it, it's unusually slow

mental current
#

Seems like I am not alone with the slow loading

cerulean bramble
#

Same.

thin hearth
jolly spruce
#

Ok it looks better now all of a sudden

mental current
#

Still looks unstable

wintry pagoda
#

Can someone spawn targets on the academy ?

warm horizon
#

I've been trying since last Friday, but the IP address isn't working.

mystic osprey
#

Hello guys
I am on the Attacking Common Applications module in the WordPress section.
To solve the questions I need to connect to the VPN and add a VHOST to my /etc/hosts but after I do that I can't reach the VHOST. However I can reach the main domain. Sometimes the VHOST works and sometimes not, and I don't really know why.
Does someone have any fix?
Thanks.

brazen marlin
mystic osprey
brazen marlin
brazen marlin
mystic osprey
vestal cairn
#

I have a question about the first task from linux foundation (Working with Web Services) - https://academy.hackthebox.com/app/module/18/section/74

I noticed a lot of people also were confused about this question
As I understand the main idea - I need to google
But I googled and found the answer on stackoverflow with NPM. This answer satisfies the request "Find a way to start a simple HTTP server inside Pwnbox or your local VM using "npm""

How was I supposed to think of the answer? What's the correct thinking process ?
When I realized that the system doesn't accept the answer with npm I think only about changing arguments, but not thinking about npm

brisk drift
#

Hey guys, i have an issue with burpsuite for the Module Shell & Payloads / Web Shell, it don't connect me, maybe i did something wrong, may someone help me pls ?

#

Or i just realized, that event when i'm off burpsuite... idk if it's the site or what

#

I need help for php shell, thx

trail gate
#

Could anyone spare me assistance over Nmap Enumeration Hard Lab?

brisk drift
#

I can try, let me see if i can remember it

trail gate
#

do u mind if i dm you?

brisk drift
#

do it

trail gate
foggy jackal
#

can i nudge someone for mssql,exchange and sccm skill assessment the first question?

foggy jackal
#

hey did you figure it out..i am stuck out here as well

brisk drift
#

Hey guys, i have an issue with burpsuite for the Module Shell & Payloads / Web Shell, it don't connect me, maybe i did something wrong, may someone help me pls ?
Or i just realized, that event when i'm off burpsuite... idk if it's the site or what

halcyon patrol
#

Anyone experience issues with the pwnbox in academy ?
I can interact it from the lesseon section but not when clicking the full screen.

cloud urchin
#

I had that problem before, I think I re-spawned the target, went to the Pwnbox, did full screen and then never tabbed out. I think tabbing out does it.

near grotto
viscid bolt
near grotto
#

I tried various query and graph somewhere it's is 3 or 2

quasi wave
#

hi for the burp intruder section of Using Web Proxies module, when I try to run the attack with the wordlist, I get results but the thing is I get an error saying "you don't have permission to access this resource" or whatever. I get a 403 error. I am doing what the assignment says I think I think its just not working. Can someone help me out here?

dapper moth
#

May be shooting this to the wind but... Has anyone found an actionable resolution to the error while loading symbols in the Intro to WinDBG Module?
Skills Assessment btw

#

Setting the Symbols path to C:\Symbols and reloading the session didn't resolve

quasi wave
#

hi are any moderators available for DM tonight? I need to talk to someone

cloud urchin
#

best to just ask your question

quasi wave
#

I did

#

look above

cloud urchin
#

ok you don't need a mod then

quasi wave
#

right so my issue is I think I did the section right and its still not working

cloud urchin
#

Best to include the section too

quasi wave
#

Burp Intruder is the name of the section. Its a subsection of the Web Fuzzer section of the Using Web Proxies module

#

I think I did what the section is asking

clever lance
#

hey everyone, for the past few days, the Pwnboxes have been ridiculously slow, and timing out, is it me or does HTB know about this?

steel snow
#

hey!

#

I am doing everything correctly for metasploit module

#

the first part of the second section of the module, which is the modules subsection of the components section

#

and it's timing out

quasi wave
#

ok solved the module I needed help with

#

just needed to be more patient with it that was all

steel snow
#

i was trying to solve mine for hours

#

still wasn't fixed

#

and i am pretty sure the issue isn't from me

steel snow
#

Yeah, i fixed mine by not fixing it

#

i just used the pwnbox

#

and that

#

fixed it...

candid lily
#

is there any option to get old ui back

#

who asked for this NotLikeThis

dusk holly
viscid bolt
#

Anyone else have issues with the sliver skills assessment? Everything is super slow, can't even run commands to get the last flag

fathom pendant
#

@lusty terrace please don't reveal information from modules above tier 0; I understand that the module is essentially a walkthrough of it but please refrain from sharing such info.

lusty terrace
#

tried to be vague and thought if someone knew they might be able to help

#

@fathom pendant Could I dm you and ask about it?

fathom pendant
#

I generally don't help out with AEN as I always urge people to do it blind, especially if they're doing the CPTS path. If things aren't working as you think they should, then I suggest changing vpn regions and respawning the target and seeing if that fixes your issues

lusty terrace
#

ahh alright I will try that

#

Is it by design for AEN to be quite slow?

#

Or sometimes js unresponsive

fathom pendant
#

btw blind means not answering the questions and just focusing on trying to get to the highest domain privileges available since the questions are leading

#

I didn't have any stability issues when I did AEN a while back

lusty terrace
#

Then its my target/region

#

Pinging sometimes don’t work

#

And takes forever to load

fathom pendant
#

sounds like it's a problem on your end not on the target end tbh

#

but i'm not staff so I don't have access to any bit of logging that can confirm/deny what you're experiencing

lusty terrace
#

Possibly? But i’ll respawn and change vpn regions to see

lusty terrace
#

bruh @fathom pendant changing these helped alot

#

._.

fathom pendant
#

it happens

covert blade
#

Hi everyone. Can I acess the Academy Target machine using my own kali linux ?

fathom pendant
covert blade
#

Okay, thank you! That means it is not available for all machine ?

#

Here for example, I don't see anything

halcyon sparrow
#

Hi, is there a way to switch the theme on htb academy? Its a bit tiring to read white text on a black background

fathom pendant
fathom pendant
halcyon sparrow
#

Thank you

fathom pendant
#

most of the people that use HTB are the hackers that swear by dark mode so they built their site around the majority being darkmode users. White backgrounds tend to strain the eyes more, but everyones eyes are different so

jovial walrus
#

could you pls help me on this

#

or anybody else on Prompt inejction Attacks module jailbreaks 2 section

jovial walrus
#

nvm got it

jolly spruce
#

So, I'm at Windows Privilege Escalation.

Does anyone know of any guide for compiling UACME properly on Visual Studio 2026? I've figured out how to configure things so that Akagi and Yuubari get made with what is probably their full size in the 1st compilation (1st = before also throwing in Naka, Fubuki and Akatsuki into the mix, for re-compiling Akagi and creating its "full power" version).

But when it comes to the Fubuki and Akatsuki .dll files, I can't for the life of me figure out if I'm doing things right. I keep getting a Fubuki64.dll that is 34 KB (which might be ok according to chatGPT, but not so much according to Gemini), and an Akatsuki64.dll that is at 12 KB, which is definitely wrong according to them.

Any help? I've been struggling with this for over 5 hours at this point 😭

jolly spruce
#

Ok, I maaaay have been led into a bad rabbit hole by a certain different Gemini model

#

Play stupid games, win stupid prizes they say

lone ferry
#

It’s been a week of complete useless HTB academy. No targets for winPrivEsc assessment will even ping. Hey HTB team what is going on and when will it be resolved? There’s nothing to be found about these outages on your site and support chat is down.

brisk drift
#

i just think that as they lauch they new palrform, they are focus on smthing else

cloud urchin
primal ginkgo
#

Anyone experiencing consistent trouble connecting to Target Machines within the Academy even after download a fresh OVPN conf?

keen zephyr
primal ginkgo
silk ferry
#

On the introduction to networking module, on the first section, it gives a small scenario of a pentester not being able to reach the domain controller through ARP because of a misconfigured subnet mask... but shouldn't ARP not care about subnet masks since its layer 2 and there is also no mentions of VLAN separation or physical separation so I'm just a little confused here... if anyone knows please lmk

brave field
#

The Domain Controller is on a /25 subnet (10.20.0.0–10.20.0.127), and the pentester is at 10.20.0.252, which falls outside that /25 range.

silk ferry
#

Oh gotcha so because the pentester IP is outside the subnet range of the DC, it won't know how to send back a response to it?

brave field
silk ferry
#

Got it, thank you for that!

brave field
#

So the pentester should have set their subnet mask to /25 to match the DC's network, that way both sides see each other as local and replies come back directly.

silk ferry
#

Should I also assume that the pentester manually set the IP instead of getting it from DHCP ?

brave field
#

Yeah apparently so otherwise the DHCP would have handed them the correct subnet mask automatically, so the fact that this misconfiguration happened in the first place pretty much implies they set it manually.

silk ferry
#

Makes sense, thank you!

brazen saffron
#

I would like to do this question "Check the alert with reference 67c202 (LSASS Access) in TheHive, and provide the MITRE rule ID as the answer." in the module Incident Handling Processsection Cyber Kill Chain(2/11), it 's saying it use port 9000, http://<target_ip>:9000/ and... trying to connect but every target I spawn have not this..

indigo plover
acoustic owl
#

Have you tried a zone transfer?

native egret
#

I'm working on the Windows PrivEsc Module in the 'Weak Permissions' section. I've followed the steps in the module, but can't seem to elevate privileges to answer the lab question. Any help here appreciated.

severe inlet
#

That didn't work aswell

#

i think i will try from pwnbox because sometimes it doesn't work on my machine but it works on pwnbox

fathom pendant
#

@severe inlet module is above tier 0, please dont reveal information like that from it. A zone transfer finds the information you're looking for.

cursive wyvern
#

AD Enumeration & Attacks - Skills Assessment Part II - on middle stages in Solution for some reason appears pswd *W*** which it is correct for that circumstances, but it comes from nowhere in that solution. isn't that a solution issue? i got previous cred which hold me in a dead end at the moment

dapper moth
severe inlet
crystal lion
#

What's going on with RDP?

#

I havent been able to connect to the target since yesterday

jovial walrus
#

why can we only enroll in one path at a time ?

stable badger
#

hello guys im getting started on Cracking into Hack the Box module Web Requests 3/4 section http methods POST
and im stuck in there because i dont know why when i use the cookie that i get from the website on curl it keeps saying that the cookie is not valid

#

can anybody help me pls

stable badger
fathom pendant
# stable badger POST

how are you formatting and what flag are you using; i used the -b 'PHPSESSID=<SESSID>' http://ip:port/search.php --json <json request here>

#

if you wanna dm me your command that's fine

weak patrol
#

https://academy.hackthebox.com/app/module/147/section/1320

I am having a bit of an issue in this module. I have found some files that possibly have the password I am looking for but I am unable to transfer the files to my local account so that I can crack them and the account I am currently in doesn't have admin privileges.
Any help?

quick cloud
#

i doing attacking common services module and i stuck at my first lab i on port 21 ftp is closed and on scaning all the ports it dont get any thing can please anyone can help me

shut quest
quick cloud
#

ok i will try again

shut quest
#

Use your noodle and delete the spoilers.

quick cloud
#

@shut quest what does that means

shut quest
quick cloud
#

@shut quest i deleted it

#

@shut quest so can u please help me ?

quick cloud
#

@shut quest how

shut quest
#

I will not spell it out for you.

heavy sluice
quick cloud
#

@heavy sluice yes but i think there is something wrong with htb servers , can anyone know how to restart it or any solutions

narrow nacelle
#

Hi, I'm doing the "Web Server Pivoting with Rpivot" module and can't find the flag on the home page. I gave up using rpivot because of obvious reasons, so I used dynamic port forward with ssh and after that I also tried ligolo. Connected to the internal network but there's no flag on the home page

gray yacht
heavy sluice
elfin patio
#

i am solving skill assessment of command injection, using command ip=127.0.0.1%0a{ls,-la}${IFS}${PATH:0:5} to get user in home directory, still not getting result.. can anybody help or tell what i am doing wrong?

lone ferry
autumn pilot
#

some targets could be configured in a way that prevents icmp requests, which means you won't see any results by pinging them

lone ferry
#

I like the way you think. I broke down and read the “show solution” which kinda conflicts with the instructions. It says rdp in, test says to find a foothold gives no creds.

Edit: You are correct 👍 the rdp writeup was throwing me off. Thanks

worn swallow
#

No download button for Vpn on academy?

#

I am using phone btw

minor bear
#

I'm working through the "Attacking Thick Clients" section in the Attacking Common Applications module on pwnbox, and am having trouble with getting PowerShell to load. It opens for a brief second, then crashes. I can get command prompt to work, and if I try to open PowerShell from command prompt I get the error "Windows PowerShell terminated with the following error: The type initializer for 'System.Management.Automation.Runspaces.InitialSessionState' threw an exception."

Does anyone know a fix for this?

green mulch
minor bear
wintry pagoda
#

Hello guys

#

How can i fix this ? Waiting for 10 mins now

green mulch
green mulch
minor bear
fathom pendant
#

@ashen nova be mindful not to share things from modules above tier 0; especially since it contains answers for several questions.

Start with a dig of the base domain (don't use automated tooling); then move on from there

pseudo kraken
#

Hey guys, im in the Active Directory module in the CPTS Path, in the Attacking Domain Trusts - Child -> Parent Trusts - from Linux .

I dont know what the password for the htb-student_adm is in order to use secretsdump, any help? i tried going through some previous modules but didnt find anything

pseudo kraken
#

i tried using secresdump with the credentials provided and it fails, in the path it is using this command 'secretsdump.py logistics.inlanefreight.local/htb-student_adm@172.16.5.240 -just-dc-user LOGISTICS/krbtgt' so probably its the htb-student_adm user, but i dont have the credentials for the user

pseudo kraken
#

i tried, the module is about golden ticket, the account in order to authenticate to collect the info needed is htb-student_adm, but the password is unknown

#

idk what to do, ive searched past modules to see if i cracked such a user but no luck

warm horizon
#

Could someone tell me why my IP address isn't working? It won't open URLs and it doesn't work in the terminal. I've been having this problem since last week.
Unable to connect

Firefox can’t establish a connection to the server at 10.129.234.166.

young tinsel
#

need some help on the RDP/SOCKS tunneling module - I've got the SocksOverRDP client/server established & proxifier running, but every time i try to run mstsc to connect to the target box, I'm getting an error that the host is unreachable

verbal ivy
#

heey guys am here if ssomeone need help with some module just ping me

sick meteor
#

@verbal ivy I am stuck on something. May I DM ?

verbal ivy
sick meteor
#

I'm on http response splitting in the http attacks module. From what I can figure out I need to get the payload to execute in the admin browser but I'm out of ideas (and knowing it's tier 3 not sure how much I can ask / explain what I tried)

verbal ivy
#

oh that one is a tricky one

sick meteor
#

Yeah there was a very similar question about 10 years ago on the CTL app exams

verbal ivy
# sick meteor I'm on http response splitting in the http attacks module. From what I can figu...

you’re on the right track thinking about getting JS to run in the admin’s browser, but the tricky part isn’t just injecting HTML… it’s controlling how the response is interpreted. play a bit more with CRLF to mess with headers, especially anything that affects how the browser renders the body. also think about how the redirect behavior might prevent your payload from executing and how you could break that flow. 🙂
if it seems hard u may dm after trying that .

sick meteor
#

Thanks I'll go do something odd to clear my head

verbal ivy
#

Gl mate

#

If anyone need help ping me 🙂
cuz i refersh my memory too 😄
gl everyone .

trail gate
sick meteor
# verbal ivy Gl mate

Got there. sigh i did overthink it and forgot about something fundamental to response headers

verbal ivy
trail gate
#

@verbal ivy hey man could i ask you some questions over DM?

verbal ivy
#

Sure , Go ahead.

cursive wyvern
#

okay, peopee, in AD Enumeration & Attacks - Skills Assessment Part II there is a password comes from nowhere 'W***', according to solution. Should we guess it or it could be retrieved somehow else?
Question: "Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain."
PS: btw also facing 'Can't talk to KDC' issue with kerbrute
PSS: from domain joined machine (win) it works either way, with --dc flag (dns/ip), or without it: *kerbrute_windows_amd64.exe passwordspray -d INLANEFREIGHT.LOCAL <userfile> <pswd> *. on non-joined machine (linux) --dc is obligatory and it should be IP

amber bane
#

hi all, is there a way to reopen a completed course/module after we have completed it?because I wanted to look back the questions.

verbal ivy
# cursive wyvern okay, peopee, in AD Enumeration & Attacks - Skills Assessment Part II there is a...

that password isn’t coming from nowhere, it’s just one of those super common defaults you’re expected to try in a spray. no need to ‘find’ it somewhere, think more along the lines of what orgs lazily set for users. ( I just password spray that one when i did it as the question mentioned "weak creds")
for the KDC issue, that’s usually not the tool itself… check connectivity to the DC (port 88), DNS resolution for the domain, and make sure you’re targeting the correct domain name. if any of that is off, kerbrute will FeelsBadMan .

verbal ivy
fathom pendant
cursive wyvern
fathom pendant
#

and it is a 'guess' but it's an educated guess. It's not a random string based off nothing

cursive wyvern
cursive wyvern
verbal ivy
verbal ivy
#

(cuz u just saying a name and linux says wtf are you talking about)

fathom pendant
#

if you approach it from a blank slate perspective, it's still 'guessing'; it's just an educated guess based on a common weakness

halcyon flume
#

Hi all, I have a question on the Kerberos Attacks module Kerberos Authentication Process section in the Active Directory Pentester path. I'm trying to understand who does the authentication of the user vs who does the access control (authorization of what the user can access on the service). I'd like to clarify the paragraph on Ticket-Granting Service (TGS). It says that the KDC "checks their authorization to access the requested resource before issuing a service ticket". Is this correct? Or does the KDC only check that a user has a valid TGT and issues a service ticket if so, leaving the service to do the authorization checks?

green mulch
lusty trench
#

Help! Citrix Breakout is driving me nuts!

lusty trench
#

Can you clarify where the SMB share should be run from? I've been stuck on this for days.

fathom pendant
#

@grave rain module is above tier 0, be mindful of posting things from it

amber bane
#

hi, i'm on the vulnerability assessment module and on the nessus assessment section.
my question is, if we don't want to use the browser-based-box and instead using our own nessus and linux machine connect via htb openvpn, how do we scan the target? I try to scan the 172.16.x.x but failed (I guess because not the same ip range), so what is right approach?

untold orbit
ruby kettle
#

Hey there, anybody got the AI Red Teamer module, and can help me with course reviews. Looking to buy it.

verbal ivy
gray yacht
amber bane
verbal ivy
amber bane
mortal wharf
#

I am currently doing the CPTS path with the student subscription. Do I still have access to my finished modules when I cancel the subscription or do I need to have an active subscription in order to access the modules ?

verbal ivy
mortal wharf
cobalt vector
#

what does that mean

cobalt vector
#

ohhhh its a sex thing

worn ferry
#

Dear, how can I purchase the blocks more cost-effectively? I only plan to take the courses of CAPE and CWEE.

acoustic owl
worldly gull
#

I’m doing cpts too, can you guys wish me luck, I wonder if I’ll finish the path before summer

nimble oasis
#

godamn.. returned to academy today and.. how is it possible to change something and turn it into something this terrible ??
It's designed for phone over desktop (who the fuck study cybersecurity on a phone first ?), it's bulky, less user friendly, unclear to a point when i'm just wanting to give up on trying to read the text, block of code are fucked, size of text is too big, space on each side that is as large as the text, table that give no info and is wide for nothing and bulky for nothing, it just feels like i landed on something vibecoded with ai.

I'm not really here to trash talk, just wanna give constructive feedback;pls don't takes words to heart.

Buttons act weirdly (dropdown gives hover effect box, while other give underline bar, but those on the right give hover ??)
Top bar and end bar are uncorrectly sized (top one is bigger than the end one), ui is slow and unresponsive, cheatsheet is ten times worse than before, colors don't hilight properly, stuff just feels bulky, space wasted and not clean, "note" button (okay why not, even if i'm pretty sure everyone got a osbidian) however why does it move the text ?? same for "Get unstuck" button.

Dashboard take 5s to load, list of enrollment is bulky, doesn't feel clean, same for the profile box on the dashboard, why is it not correctly sized ? why the gap between name/pp and the status ?

Btw the edgy progression bar are in the same state the / get cutted cause pixels ig and it just feels trashy. And in dashboard same problem text to big, cards bulky for no reason.

Gonna share the same message in feedback, but dunno, is this really the way to sell ur platform to schools and people that like cybersecurity ? by giving a platform designed for phone over desktop, bulky, space wasted, and not user friendly? Sad change when last ui was perfect. This one just doesn't make me wanna study on academy when i know perfectly well the quality of the content..

sry for the rnt, just sad and wanna give some feedback

cursive wyvern
#

back to AD assessment II: at point of using 'mimikatz sekurlsa::logonpasswords' under nt/authority on MS01 i faced the issue that there is no password for user

kerberos :    
     * Username : m*****
     * Domain   : INLANEFREIGHT.LOCAL
     * Password : (null)    

but 'lsadump::secrets' has it(but it is not obvious that it was a password)

Secret  : $MACHINE.ACC
cur/hex : <SNIP, not required> 
    NTLM:031fc31a8ec7c4484dd4c8badc58fbeb
    SHA1:a0f5f5c233b7a629fb4788450f5f992243c58dba
old/text: ;6bu^ur;mJ&ES&#Iu)CQZeckLZsyN >AgIv4DZ^&EX,Wu.ahRkT%c3)R+c&xcu_:]n#V1V.j[=+GTjk?l)z OaU8!c^\#`s?8/E!xy^itE>kYiBcSgohVb$P
    NTLM:6991907663e3f68922d24ac9a573e2c3
    SHA1:33058b24d5882f1dd18ce81988aa64226e2879b5

Secret  : DefaultPassword
cur/text: <password here>

CME also shows it
SMB 172.16.7.60 445 <machine> INLANEFREIGHT\m*****:<pswd>

problem: where did i screw up or it is intermittent issue? as a result, not clear to trust mimikatz or not

verbal ivy
cursive wyvern
verbal ivy
#

lm hv a look

cursive wyvern
# verbal ivy which qs?

Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.
you probably looking into solutions to navigate. Question 8. After some msf exploit setup

verbal ivy
#

if it is qs 8 just run cme with adminsitrator pass
it took me so much time that one idk maybe a problem with it or in me

cursive wyvern
verbal ivy
#

i did it with cme don't really know

#

seems easier mimi always gives 20k ouput i need to read with my laziness pepecoffee

cursive wyvern
verbal ivy
#

Good luck with the path it's very heavy prayge

trail gate
#

@verbal ivy can you help me on this?

#

its over the smtp footprinting module

verbal ivy
#

sure

trail gate
#

i cant send screenshots here could i show you in dm?

#

or would you prefer just to keep it in here

#

@verbal ivy

verbal ivy
#

yes

trail gate
#

keep it in here?

verbal ivy
#

u can dm

round epoch
#

Hi, I'm on the Linux Fundamentals module in the section, File Descriptors and Redirections. I thought I was doing something wrong why I was unable to obtain the correct answer to the 10 point question of 'how many packages on the target system?'; the issue was and remains, I was never on the target system. I finally took a closer look at the terminal to see whether I was logged into the target system: I never have been because because the connection has always been rejected from port 22.

I do not know how to overcome this.

verbal ivy
cursive wyvern
# verbal ivy Good luck with the path it's very heavy <:prayge:867733100925550592>

just have finished it. well, there were unexpected places definitely. there is a zoo of tools required, and some of them too similar with some discrepancies which seems vital. glad I've figured out to spin bloodhound at the very start. well, seems a lot of AD pain ahead.
there were 15 mins left for the box and extending it returned generic error, seems I exhausted it.
thank you

verbal ivy
cursive wyvern
verbal ivy
#

rusthound is same as bloodhound-python
but taking steroids as it was built in rust

cursive wyvern
verbal ivy
cursive wyvern
# verbal ivy just follow the structure they give you would be better

looking at the structure I'm not sure if it is appropriate imo. AD for some reason in the middle when there is no intersection with other modules and I postponed AD understanding that it is huge and knowing that fat part of exam related to it not to forgot material closer to exam. only lin/win PrivEsc and attacking enterprise left for me.

verbal ivy
#

honestly doesn't matter which one linux or win priv escalation
i would say linux if u want me to chose a bit easier than the windows one as it also long and annoying

#

i finished the whole path just waiting for a voucher to do the exam waz

cursive wyvern
woeful goblet
#

Sup Guys, i just started learning about Cybersecurity but i already know Python basics. I watched different videos about how to start and it was always: Linux & Networking. Could anyone of you give me an advice in this matter where i can start?

cloud urchin
compact patrolBOT
dusk basin
#

Hello.
I am in the module "Password Attacks". Currently in section "Pass the Hash"
I'm trying to obtain the hash of David using mimikatz sekurlsa::logonpasswords, but I don't see the user david anywhere.
Looking at internet, it says that mimikatz should return the user, am I missing something?

#

oh, and of course now I try it again and it appears....
nevermind then

paper crest
#

Hello ! I'm studying the HTTP Attacks module specifically the HTTP Request Smuggling / Desync Attacks section covering TE.TE and TE.CL topics. Both modules demonstrate attacks via Transfer-Encoding header obfuscation.
In the TE.TE lab the CL.TE attack vector is used to make the admin visit a specific page. In the TE.CL lab the goal is to gain access to the admin panel directly. My question is: why can't we use the CL.TE vector in the TE.CL lab to access the admin panel? When attempting CL.TE we get a 401, but with TE.CL we get full access. What is fundamentally different about how the request reaches the admin panel between these two vectors?
And is CL.TE generally considered a user-targeted vector rather than a server-side access vector?

jaunty latch
#

Question, I've recently come back to HTB academy and started using my account that I started with. I can't see an option to reset any progress, now I have to re-read all the content that I have done in the past but forgotten. Is this by design?

jaunty latch
storm elk
#

Not as far as I know of 🙂

jaunty latch
pallid wadi
#

I can not get SSH'd in. I connected the VPN , but no login's pop after being connected.

pallid wadi
untold orbit
#

Cool

#

I think you need to mention module and section for people to help you out

pallid wadi
jovial walrus
#

I am on the skills assessment for prompt injection and I got the key but am a lil clueless on how to get admin banned now...Any help is appreciated

jovial walrus
halcyon flume
#

In the Kerberos Delegations section of the Kerberos Attacks module of the Active Directory Pentester path, under Constrained Delegation, it says that a copy of the TGS ticket the user sent to the first service is stored in additional tickets field. Is it correct to say that the SPN in this copy of the TGS ticket is that of the first service? In that case how does the first service know which service to delegate authentication to? Where is this info stored?

waxen totem
# halcyon flume In the `Kerberos Delegations` section of the `Kerberos Attacks` module of the Ac...

msDs-AllowedToDelegateTo property of the front-end server (first-hop) stores the SPN of the service it's allowed to delegate to or in the case of resource based constrained delegation(RBCD) it's in the msDs-AllowedToActOnBehalfOfOtherIdentity property of the back-end server (second hop) .The user's TGS doesn't actually have to store the SPN as it isn't directly interacting with it, all it needs to store is whether or not it's forwardable (whether or not the TGS can be used for delegation)

faint gulch
#

Is there any ongoing issue with spawing and accessing machines by any chance?

halcyon flume
#

In the Unconstrained Delegation - Computers section of the Kerberos Attacks module of the Active Directory Pentester path, under S4U2self for Non-Domain Controllers, it says that the S4U2self method is "particularly useful for scenarios where we have a ticket from a computer that is not a domain controller." But in the example shown, we had to use the Domain Controller's TGT. I'm confused by this

wise dune
#

Hey, my streak counter seems to have bugged out and I currently have 30 out of 0 streak points, anyone ever encountered that?

#

Worried I could lose my streak due to a bug

dusk basin
#

Hey.
Just wanted to say, I've just completed the Password Attacks module, and I loved the final Skills Assessment, I literally spent 3 hours to complete it, but I enjoyed every single minute of it!

dim hound
#

Hi there, currently I am working on SA of Windows Lateral Movement. I am able to login as a user with RDP but there is no flag at: What's the content of the flag located at C:\Users\Arturo\Desktop\flag.txt ?

#

can I dm someone, to provide my findings so far to check if I am on the correct path ?

silver sapphire
#

Hi, could anyone help mi with explanation of Skills Assesment part I in Advanced SQL Injections? I don't understand one thing (I was able to solve it due to solution but I can't understand where one thing come from) 🙂

fathom pendant
neat stag
lusty terrace
#

anyone know where I can learn Ligolo-ng

potent delta
#

While going through the Wi-Fi Penetration Testing Basics Overview - Section 4 and I have run into an issue where its not showing my wlan0 interface. I tried restarting the instance and that didn't fix it. When running the** iwconfig** command I receive the output lo, ens3, lxcbr0, tun0 that show "no wireless extensions". Did I miss a step? I am suppose to assign one of the interfaces as the wlan0? Any help would be appreciated

halcyon flume
patent maple
ocean rapids
#

i have completed the nmap , intro to networking , linux fundamentals , web requests module can anyone recommend me some other modules and what to do next

dusk basin
whole nexus
spark portal
#

then you can go for the Certified Unethical hacker cert

untold orbit
spiral birch
#

Hey, is anyone having issues with the Information Security Foundations in getting the VirtualBox Environment set up, as far as I've gotten is setting up the ParrotOS and the Windows Developer Set-up and I feel like i'm doing something wrong or I am missing something

torn fiber
#

i am also having some problem in academy [21:07:49:328] [9283:9284] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[21:07:49:328] [9283:9284] [INFO][com.freerdp.client.common] - Network disconnect!
i am doing the attack common application module i am getting disconnect from the server for table of context number 5 6 and 7. right now doing number 7 but rdp is getting disconnected too fast to be able to do anything. where should i go? to discuss this problem.

jovial walrus
#

kernel exploits section window priv esc module this table is messed up

fathom pendant
fathom pendant
#

As the question states, its asking for the header; formatted
Content Length: xxxxx

short oasis
#

Now solved thankyou

fathom pendant
#

@paper crest module is above tier 0; refrain from spoiling attack vectors and such

paper crest
#

Hey everyone! 👋

I'm currently studying HTTP Request Smuggling / Desync Attacks and I have a conceptual question I'm trying to wrap my head around.

I understand that TE.CL and CL.TE desync techniques behave differently in terms of where the "smuggled" portion of the request ends up and who processes it.

My question is more conceptual: is it correct to say that CL.TE is generally more effective when targeting other users/clients, while TE.CL is better suited for directly interacting with backend/server-side logic? Or is that an oversimplification?

Basically - what is the fundamental difference in how these two techniques affect request flow, and why might one give you access to something that the other doesn't?

Would really appreciate if someone could explain the distinction! 🙏

brazen saffron
#

Analyze the event with ID 4624, that took place on 8/3/2022 at 10:23:25 https://academy.hackthebox.com/app/module/216/section/2300
I'm trying to get the event using XML queries and using the "GUI", I try to look at some writetup but I have no event at this date... The first event I see it's (10/4/2022)...
Any hint 🥹 ?

random sinew
#

Speaking of the module, I would need help with the TE.CL one. I tried a lot of things, but I'm still not there.

#

and according the discord history i'm not the only one who struggle on this step

paper crest
#

Send me a message, and I'll give you some advice

jolly spruce
#

I am experiencing major glitches in the Citrix Breakout section of the Windows Privilege Escalation module

#

Not only am I not able to access my attack host's tun0 IP (which I was able to do yesterday, from a Pwnbox on another PC, for some reason)

#

But the RDP connection also keeps dying every few seconds, and I can't reconnect for like a couple minutes after that, every time

#

I know how to solve the questions; this is one of those sections where the content spills out the method

#

But I still wanna, you know, actually do it 😭 Gotta be done with this module asap

green mulch
brazen saffron
jolly spruce
#

There's still the UNC resolution problem though

#

It just isn't detecting my attack host

green mulch
green mulch
jolly spruce
#

Feels to me like this particular VM is just very problematic

green mulch
green mulch
jolly spruce
#

There have been other people to report this too, anyway

#

etc.