#modules

1 messages · Page 477 of 1

feral patrol
#

Could somebody please help me for a minute with one part of the Salma essentials module?

neon viper
#

i tried, took me 4 hours but i got nothing

#

so i cam ehere for help

fathom pendant
neon viper
#

maybe some shortcut

fathom pendant
#

no shortcuts

neon viper
fathom pendant
#

i gave you enough info to figure out where to look in the reading to figure it out on your own

feral patrol
#

I’m attempting the sqlmap essentials final assessment. I’ve found the entry point on the website but I just can not get the databases, tables or the flag. I’m totally stuck. Can anyone help please?

quasi wave
#

for the skills assessment for the Using Web Proxies module, for the first question with lucky.php web page, I intercepted the response to the request but my modification of the response won't enable me to click the button to get the flag

#

I know I am supposed to enable the button by removing the "disabled" part but I did that and it still won't work. I also tried changing it from a post request to a get request

#

both in form method and in method

#

what is my issue here?

pale island
cerulean grail
#

Can anyone help with the PHP Webshell module on the Pentester job path?

I can't seem to get the webshell up and running despite following the isntructions. For example, it already shows a vendor named NetVen with a torn piece of paper as its logo.

brave creek
#

I have connected to the vpn server but I get "Unable to connect" when i try to visit the target ip

empty mesa
#

Hi everyone, I'm having troubles with the skill assessment SQL injection fundamentals. Could anyone give me a hint?

trail forge
#

Hey all, I feel like I found the solution some time ago for this phishing lab (https://academy.hackthebox.com/app/module/103/section/984), but none of the payloads I'm trying are causing the simulated user to submit their username/password. When rendered the page looks right, and if I manually enter my username and password my listener definitely sees it. Is the user just being picky about how it submits URLS? Any help appreciated.

Note: The user will directly navigate to my page if I send them THAT url, and that works, it's just not working for my payload URL.

sterile solstice
#

Can I get some help on the Bypassing Captive Portals - MAC Spoofing. I'm following along, and I can't seem to get the flag. If someone has done the module, i'd like to know where I'm going wrong.

quasi wave
#

But thank you

#

It was a minor thing I wasn’t getting

quasi wave
#

You should use /spoiler

fathom pendant
#

@mossy bay be mindful not to share flags from the module; and that module reuses targets a fair bit so you might have found a flag for a different section

sudden cloud
#

Hey guys, I can't rdp in the lab "Windows Priv Esc> Windows User Privileges>SeImpersonate "

pliant cedar
#

ok hi, i currently need help, im doing ssh right now and im connected to ssh not with VM but my own pc witht the vpn, but i need help to find the path for the htb-student mail

acoustic rivet
#

Hi, anyone having issues with starting Pwnbox? I'm currently doing my CWES labs on HTB Academy.

fathom pendant
#

if this persists contact support

#

have you tried doing that?

#

general question being is did you try changing pwnbox regions

acoustic rivet
brittle geyser
#

am I able to change my payment method for academy in the future?

acoustic owl
jagged jasper
#

Hey, can i dm u about this ?

rain wyvern
#

can anyone explain why, my macOS can not using HTB VPN

#

while my linux can @@

fathom pendant
rain wyvern
#

my linux can 🙁

brave field
jagged jasper
brave field
fathom pendant
rain wyvern
#

i saww the problem, it's HTB issue, change server fix it

brave prawn
#

Can i dm someone on WiFi Penetration Testing Tools and Techniques - Skills Assessment?

mighty wyvern
#

hello guys, actually i wanted to know how you guys use htb academy, i recently enrolled in cpts path, i am ejpt certified and thinking of go for cpts next but the information on htb academy is overwhelming, maybe because until now i learn mostly from video lectures that i found modules little overwhelming but i found it difficult to make notes out of it. so i would really appreciate to know how you are using htb academy?

swift swift
#

Hey! My old Academy VPN file stopped working today. I wanted to download a fresh .ovpn, but the VPN tab next to the Pwnbox button is completely gone. Did they move it in the new UI? Where can I find it now?

winter rampart
#

hello , you friend is new here , i just want to know , from your experience , how much "2 days" takes to comlete a module ?

brazen marlin
brazen marlin
#

in my experience

heavy sluice
# mighty wyvern hello guys, actually i wanted to know how you guys use htb academy, i recently e...

I made myself a Book of cheat sheets in Obsidian on what to check when testing a service, common vulnerabilities, tools etc.
When I read a module I add that to my book if I think that it might be a good addition but I keep the structure my own. for example I structure my notes on Services like this:
Enumeration & Reconnaissance
Initial Access & Brute Force
Attacking & Exploitation
Post-Exploitation
References

gray yacht
flint rapids
#

i cannot connect to htb vpn, what happen?

hexed tartan
#

AI Module 4 task 5 (Malware image classification) any help?

cosmic vine
#

anyone having issues spawning targets?

swift swift
willow lintel
willow lintel
cosmic vine
#

win priv esc. i actually managed to get one to spawn shortly after sending that message but it's been like 2+ hours of constantly clicking "spawn" and nothing happening

willow lintel
cosmic vine
#

it'll frequently take a few tries for me to get a target to spawn but today has been unusable

vast cairn
#

hey all. I'm having an issue with the PtH section of Password Attacks. I'm trying to establish the reverse shell in question 6, and I have all the correct parameters in my command... but it just doesn't work. Does anyone else have serious issues with trying to work with the Windows VMs on htb, or is it just me?

vast cairn
# willow lintel i've got this problem since monday

I honestly have given up on completing win priv esc because I can't get stuff to spawn correctly or work correctly. I'm about to run into the same issue with password attacks too, because these windows RDP sessions just don't like me for whatever reason.

rustic geode
#

Hi i need a help in AD Enumeration & Attacks - Skills Assessment Part II
Q:Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.
i dumped the hashes using meterpreter but i can't do pth with evil winrm

#

i dumped the amdministrator hash

gray yacht
terse elk
#

Hi, i think there are some connection problems for the CPTS Password Attacks Module : section Network Services.
The 4 questions ask to bruteforce login credentials given their username and password lists.
But the machines keep crashing after some careful bruteforcing and multiple machine resets, also tried the others questions with different protocols (rdp, ...) all crash at one point.

hydra -t 2 -L username.list -P password.list ssh://10.129.43.185

[STATUS] 44.00 tries/min, 44 tries in 00:01h, 21068 to do in 07:59h, 4 active
[STATUS] 28.00 tries/min, 84 tries in 00:03h, 21028 to do in 12:32h, 4 active
[ERROR] all children were disabled due too many connection errors
0 of 1 target completed, 0 valid password found ```

Then trying to restore the session:
`hydra  -t 2 -L username.list -P password.list ssh://10.129.43.185 -R`
```[DATA] attacking ssh://10.129.41.15:22/
[ERROR] could not connect to ssh://10.129.41.15:22 - Timeout connecting to 10.129.41.15

Have you any tip so that it can work properly ? I'm already making the bruteforce from the PwnBox with US vpn
Thanks
edit: I'm gonna try switching the machines and the pwnbox on europe server , will see

sly knot
#

Hi Guys, please advise in v2.0 were i can download the VPN file

terse elk
sly knot
quasi wave
#

so for Using Web Proxies module's skills assessment question 3, I am trying to fuzz the MD5 hash to get the completed hash and then try to decrypt each result automatically. The thing is I want to add the two payloads together (the incomplete hash + the last character to complete the hash) to make a third payload and then decrypt the third payload each time. The problem is I am not able to figure out how to do that.

#

can someone help me out here?

quasi wave
#

I tried making two payloads: one for the incomplete hash and one for the remaining single character at the end. I wanted to combine the two payloads but I don't think there's a way to do that. I fuzzed it and got a bunch of 200 OK HTTP status codes. however, I don't think that's the right way to do it.

empty mesa
#

Hint: you can add a prefix to your payload

sick meteor
#

Has anyone recently done the 'Abusing HTTP Misconfiguration' https://academy.hackthebox.com/app/module/189/section/2022 module ? I'm stuck on the 'Common Session Variables (account takeover). Managed to reset the admin password to a known value but now its asking for MFA. Is the expectation to brute-force / fuzz the MFA value? Any nudge or direction would be appreciated

quasi wave
marble kraken
#

Good evening everyone, today I posted about 6 screenshots divided into 2 parts and I was muted. Is that normal?

fathom pendant
marble kraken
marble kraken
fathom pendant
#

Be mindful of sharing things though from modules, especially those above tier 0

marble kraken
#

There wasn’t anything sensitive, just the Sliver session, my Windows OS build, and proof that all Defender protections were enabled.

#

I mean, I carried out the procedure on my own machine.

fathom pendant
#

So... it doesnt really involve academy modules 😉

marble kraken
#

I think I fried my brain a bit today 🤣

#

I mean, I didn’t think it was normal to bypass the latest version of Windows. I sent a vulnerability disclosure to Microsoft. Maybe they’ll make fun of me..

dapper scarab
#

my target machines are not spawning with the port number what should I do?

terse osprey
#

(In the maldev sense of things)

#

Can even do it without Sliver.

marble kraken
#

I do want to learn, but first I need to master my skills with Linux boxes and Windows AD. Then in a few years I’ll start down that path… assuming I still have a brain left…

brazen marlin
dapper scarab
#

can anyone help with getting the CEO banned exersice in COAE, ive done everything asked and still not getting the flag, to the point his data is off the system

terse osprey
random quarry
#

Hi, I have a question about the XSS Session Hijacking question - I am going through PayloadsAllTheThings and using the different remote script XSS provided, updating my IP and including the /<field> in there to identify which blind XSS triggers. I can't seem to find the right payload to use. Would anyone be able to point me in the right direction?

rain wyvern
ancient coyote
#

RDP and SOCKS Tunneling with SocksOverRDP
https://academy.hackthebox.com/app/module/158/section/1439

when I unzip SocksOverRdp on the pivot machine the .dll dissapears? I tried copying out separately, looks like its there then I run regsvr32 and its gone again? is this Defender, I assume AV bypass is out of scope for this module

autumn pilot
#

You can stop Defender

ancient coyote
#

I know but I wasn't sure if it was meant to be completed with defender running or not

#

definitely meant to stop defender first I guess

azure scroll
#

Heartbleed Bug
https://academy.hackthebox.com/app/module/184/section/1950
I am trying to complete the exercise section in the Heartbleed Bug module. To do this, I first start the machine. After waiting for a while, when I run the scans as described in the module, I receive a message stating that this server does not contain the Heartbleed vulnerability. Unless I have done something wrong, I think there is a problem with the system.

marble kraken
sick meteor
bitter sequoia
#

Did you ever figure this out? I'm currently having the same issue.

weak tiger
#

Nvm

Restarting both target and pwnbox fixed it 🚶‍♂️

potent linden
brave field
#

Target spawning issues anyone?

brave field
viral lotus
#

is there still a network issue? spawning targets and interacting on ssh sessons is really janky for me (connected to the us servers)

uneven ore
brave field
#

now it's working on EU2

uneven ore
#

its not working...

leaden island
#

yo guys, im on linux privesc, skill assesement
im having a strange issue, is there anybody i can dm ?

tribal rain
#

Hey all, with the intro to C2 with sliver, using my own sliver server I am finding a problem with generate stager it is stating that --lhost is not a recognised command and also when I save to txt it is not a txt file

#

any thoughts?

gray yacht
tribal rain
#

That might be the problem I am using the latest

upper haven
lyric shell
#

im new to the htb

can anyone explain me what it does ?

clear roost
#

Module: Using CrackMapExec
Section: Skills Assessment
Question 1: What's the password of the account you found?

hello everyone, need a little bit of help , i already got the list of users , but when i try to find password policy i get nothing

command used:

proxychains nxc smb 172.16.15.3 -u '' -p '' --pass-pol

output:

ProxyChains-3.1 (http://proxychains.sf.net)
|S-chain|-<>-127.0.0.1:1080-<><>-172.16.15.3:445-<><>-OK
|S-chain|-<>-127.0.0.1:1080-<><>-172.16.15.3:445-<><>-OK
|S-chain|-<>-127.0.0.1:1080-<><>-172.16.15.3:135-<><>-OK
|DNS-request| INLANEFREIGHT.LOCAL 
|S-chain|-<>-127.0.0.1:1080-<><>-4.2.2.2:53-<--timeout
|S-chain|-<>-127.0.0.1:1080-<><>-4.2.2.2:53-<--timeout
|S-chain|-<>-127.0.0.1:1080-<><>-4.2.2.2:53-<--timeout
|DNS-response|: INLANEFREIGHT.LOCAL does not exist
SMB         172.16.15.3     445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:INLANEFREIGHT.LOCAL) (signing:True) (SMBv1:None) (Null Auth:True)
|S-chain|-<>-127.0.0.1:1080-<><>-172.16.15.3:445-<><>-OK
|S-chain|-<>-127.0.0.1:1080-<><>-172.16.15.3:445-<><>-OK
SMB         172.16.15.3     445    DC01             [+] INLANEFREIGHT.LOCAL\: 
|S-chain|-<>-127.0.0.1:1080-<><>-172.16.15.3:139-<><>-OK
|S-chain|-<>-127.0.0.1:1080-<><>-172.16.15.3:445-<><>-OK
fathom pendant
quasi wave
#

hi so for question 3 of the skills assessment for Using Web Proxies, I am fuzzing it and trying each combination with the prefix and the wordlist, and then I try every combination from the wordlist and encode the result but the problem is I don't get any 20X HTTP status codes in the result, or ANY status codes whatsoever.

#

so how do I know which one is the answer or when I've gotten the answer?

#

I'm doing it in Burp. Should I use ZAP instead?

fathom pendant
#

Burp will work

#

You're on the question that has you decode then re-encode yeah?

#

The wordlist attack has a 'prefix' option that you select before having it run through the payload

quasi wave
#

but its still not working

#

I'm gonna use the bathroom but @fathom pendant can I DM you?

#

when I get out of bathroom?

fathom pendant
#

Im not at my computer rn but sure

quasi wave
pseudo mango
#

hey guys, im pretty new to HTB, so my doubt is probably very beginner level but i would appreciate any help i recieve T_T

Module: Linux Fundamentals
Section: 6 System Information
Question 6, What is the name of the network interface that MTU is set to 1500?

i tried ifconfig and ip and i noticed there were three interfaces with MTU 1500 (no idea what that is) and all three answers i input into the answer box were wrong. (also took help from ai, didnt work.)

pseudo mango
fathom pendant
pseudo mango
fathom pendant
#

do ip a

#

MTU is the speed of transmission for the interface

#

but there should only be one interface with 1500

pseudo mango
#

thank you, i think already tried ip a but ill try it again.

steady light
#

Can someone help with LLM Output skills assessment? I found a vulnerability, but there is nothing there :D. I already had a similar issue when the LLM was hallucinating I guess

pseudo mango
fathom pendant
#

¯_(ツ)_/¯

#

it's just the standard way to list interfaces

#

ifconfig has long since been deprecated but i'd have to see the output it's giving you to tell you where you went wrong

sick meteor
#

@fathom pendant Any chance you can help me ? "Has anyone recently done the 'Abusing HTTP Misconfiguration' https://academy.hackthebox.com/app/module/189/section/2022 module ? I'm stuck on the 'Common Session Variables (account takeover). Managed to reset the admin password to a known value but now its asking for MFA. Is the expectation to brute-force / fuzz the MFA value? Any nudge or direction would be appreciated"

pseudo mango
sick meteor
fathom pendant
fathom pendant
sick meteor
fathom pendant
#

i will say discord's search feature is lackluster

sick meteor
#

Indeed - there doesn't seem to be a way to search for responses to specific posts

steady light
brave creek
#

I'm connected to the vpn server with openvpn and can ping the target ip in the terminal, but when I try to visit it in the browser I get "unable to connect"

clear roost
gray yacht
plain coral
#

Is anyone else having issues with pwnbox?

vale tusk
#

Hi. Is anyone use sliver v1.7? I have problem with Intro to C2 Operations with Sliver. Stager didnt work. Msfvenom payload is knocking to stager-listner but session wasnt created

frosty tide
#

Is anyone having issues with can't connect to target? I can't connect to target on both my vm and pwnbox

#

Module HTTP Attacks, Section HTTP/2 Downgrading

#

Hmm nevermind, it use HTTPS insdead of HTTP, I can access now

ancient coyote
#

in the skills assessment for PTPF, can ligolo be used to double pivot? I assume its cabable just trying to wrap my head around how exactly I would do it

cloud urchin
#

Not sure what PTPF is, but Ligolo can double pviot yes

ancient coyote
#

pivoting, tunneling, port forwarding

#

just 2 proxies ? simple as that?

#

each network hop needs a new proxy right?

cloud urchin
#

You can use whatever tools you want

#

It's great for practicing ligolo

ancient coyote
#

yeah I knew we arent restricted but just checking my thinking

#

so just add a proxy to my original agent to double pivot?

cloud urchin
#

You need to setup a listener on your agent but that isn't really covered in the module. May be better to ask in another channel for Ligolo help.

ancient coyote
#

I over complicated it I dont think I even need a double pivot

ancient coyote
#

Am I 1337 yet? 😂

night shale
#

Hi guys I need help in the module “Introduction to NoSQL injection” skill assessment 2, I’m trying to get the reset token but I can’t seem to get the script to work

cold pilot
#

I've just completed the SID Filter Bypass (CVE-2020-0665) section in the Trust module on CAPE. I ended up having to use mimikatz and kekeo for forging the inter realm tickets like shown in the course as I didn't manage to do it from Linux with ticketer.py and getftST.py from Dirkjamn's forest-trust-tools repo 😕.
Curious if anyone has done this from Linux before to help me troubleshoot what I'm doing wrong, I can't figure it out...

dim hound
#

Currently I am doing ADCS Attacks (CAPE Path), can I dm someone regarding question one?

magic forum
visual forge
acoustic owl
radiant jolt
#

I just found that the annoying next button is removed from showing all the time while reading the sections, its now at the end of the page. 🤗

visual forge
#

Also does anyone know why do I sometimes see the option to use VPN in academy and sometimes just the pwnbox?

acoustic owl
acoustic owl
night shale
#

Hi guys I need help in the module “Introduction to NoSQL injection” skill assessment 2, I’m trying to get the reset token but I can’t seem to get the script to work

sick meteor
#

Has anyone recently done the 'Abusing HTTP Misconfiguration' https://academy.hackthebox.com/app/module/189/section/2022 module ? I'm stuck on the 'Common Session Variables (account takeover). Managed to reset the admin password to a known value but now its asking for MFA. Is the expectation to brute-force / fuzz the MFA value? Any nudge or direction would be appreciated

dreamy beacon
magic forum
fathom pendant
dreamy beacon
vale pulsar
#

Im having problems connecting to the HTB VPN via openVPN from my Kali Linux VM on my Windows 10 computer

acoustic owl
#

Change the VPN server/region and then try again

vale pulsar
#

Already changed it from Aus-Eu1-Eu2-Us1-Us3 including UDP and TCP, openVPN never gets past and constantly restarts

acoustic owl
#

In that case, please contact HTB Support

fathom pendant
vale pulsar
#

Oh no for Labs I tried academy and labs VPNs

fathom pendant
#

well for all intents and purposes: academy vpn servers and lab vpn servers are separate

clear roost
clear roost
#

finally after lot of errors and trials found it , thanks a lot

harsh tulip
#

Hey guys, is this feature gone in Academy 2.0? I remember that after each module, you used to get a lot of machines related to those specific modules

cedar yew
#

Hello guys i need help

Module :Linux Privilege Escalation
Section:Service-based Privilege Escalation, logrotate

I run payload and make the necessary settings, but it doesn't work.

waxen totem
cedar yew
#

It doesn't teach much technically since you're just escalating privileges through a vulnerable version, but I've been grinding on it for 24 hours straight. I’d really appreciate any help

fathom pendant
#

the reason it's inconsistent is because it's a race condition

cedar yew
#

Is there something I missed?

fathom pendant
#

generally i wouldn't recommend trying to get a revshell out of it

eternal vigil
#

Hey guys in the module Attacking Common Applications:Exploiting Web Vulnerabilities in Thick-Client Applications i am not able to compile the Java code from souce and getting alot of errors even though the required files and paths exists.

waxen totem
eternal vigil
#

aight thankyou

cyan veldt
#

is it because the target doesnt have port or smth

frozen hinge
#

hii

#

i cannot do the target from Getting Started

#

is it skill issue??, im with the vpn

cyan veldt
#

@frozen hinge can u check dms? i wanna ask u abt smth

cyan veldt
frozen hinge
#

type shi

tough blade
#

Working through the HTB Academy Footprinting module (Section 9 - DNS). Question 4 asks for the FQDN of a host where the last octet ends in 203.
My approach:

Ran dig any against the target to get initial records
Ran dig axfr against the root domain and discovered subdomains: app, dev, internal, mail1, ns
Successfully zone transferred internal.inlanefreight.htb which gave me dc1, dc2, vpn, workstations etc
dev.inlanefreight.htb zone transfer failed so I fell back to brute forcing
Ran dnsenum with subdomains-top1million-110000.txt against every discovered zone — nothing ending in 203
Tried dns-Jhaddix.txt — threw thread errors and returned nothing useful

My question is around methodology — is there a logical process for determining which wordlist to use against which zone, or is this genuinely trial and error? In a real engagement would you just systematically run every available wordlist against every discovered zone until something appears? Is there a smarter approach I'm missing that the module doesn't make explicit?

fathom pendant
#

@tough blade that module is above tier 0 be careful with spoilers

potent adder
#

hi, i have a question and id like to upload an image but theres no option to when i click the '+'

potent adder
#

ill ask my question anyways:
I'm working through the Linux Fundamentals module and Im trying to spawn my VM. I'm on Windows 11 so I downloaded openvpn and launched my vpn through it. I pinged the IP address from target and I got the 'apache2 ubuntu default page' (it works! this is the default welcome page used to test the correct operation of the apache2 server installation on ubuntu systems...). Does this mean I launched the VM correctly? I'm not sure what to do next, how can I open the terminal and run commands

cold zinc
#

Hey guys, I'm currently stuck on the Exploitation of PDF Generation Vulnerabilities
section.
I managed to find the exact flag path via SSRF, but when I try to read the .txt file using the file:// wrapper, it's still not working for me. Could anyone give me a small nudge?

finite crypt
#

Hi everyone
I'm currently in the login brute forcing module and I want to ask about the difference between hydra and medusa.
which is better and when to use each ?

night shale
#

Hi guys I need help in the module “Introduction to NoSQL injection” skill assessment 2, I’m trying to get the reset token but I can’t seem to get the script to work

tidal kelp
#

anyone who can answer to a q on the topic of SCF from WindowsPriv Esc module?

leaden island
#

Yo guys, i came across this in the windows privilege eecilation:

#

I confirmed that I had the SelmpersonatePrivilege, which can be leveraged for local privilege escalation. I downloaded a custom compiled version of Juicy Potato to the host to assist with privilege escalation, and was able to add a local admin user. Adding a user was not ideal, but my attempts to obtain a beacon/reverse shell did not work.

#

If i understood, that is a case where he did get command execution through the mssqlclient.py using the xp_cmdshell

#

Actually at this point you can spin an http server hosting a reverse shell, ans download it from the mssqlclient with wget, and run it from there, you will get a reverse shell

#

Without the need to add a new user

#

Dunno if the above case had constrains behind this not working

fathom pendant
dapper scarab
#

can someone help with the skills assessment for Applications of AI in InfoSec, my model keeps coming back with 0 percent in the red teamer AI path?

quasi wave
#

hi for the Digging DNS Section of Information Gathering - Web Edition module, I am trying to do a reverse domain lookup for the IP address or to find the PTR record of it, which is supposed to map back to the original address that was the answer to the previous question but its not doing that. Here's some of my terminal output:

greg@Windows:~$ dig  @134.209.24.248 inlanefreight.com
;; communications error to 134.209.24.248#53: timed out
^Cgreg@Windows:~$ dig 134.209.24.248 NS

; <<>> DiG 9.18.39-0ubuntu0.24.04.3-Ubuntu <<>> 134.209.24.248 NS
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 19923
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 65494
;; QUESTION SECTION:
;134.209.24.248.                        IN      NS

;; AUTHORITY SECTION:
.                       30      IN      SOA     a.root-servers.net. nstld.verisign-grs.com. 2026041101 1800 900 604800 86400

;; Query time: 93 msec
;; SERVER: 127.0.0.53#53(127.0.0.53) (UDP)
;; WHEN: Sat Apr 11 15:30:50 PDT 2026
;; MSG SIZE  rcvd: 118

greg@Windows:~$ dig +x 134.209.24.248
Invalid option: +x
Usage:  dig [@global-server] [domain] [q-type] [q-class] {q-opt}
            {global-d-opt} host [@local-server] {local-d-opt}
            [ host [@local-server] {local-d-opt} [...]]

Can someone help me out? I know how to do the next question. So that's not a problem. I'm sure this is some stupid minor detail I'm not getting.

#

I also think for the next question when I do it right it gives me a different answer actually.

#

So if I could talk with someone about this soon that would be great.

waxen totem
night shale
#

can i get help on a module from CWEE? its called "Introduction to NoSQL Injection" the skills assesment part 2, no one seems to be helping me

acoustic owl
quasi wave
past barn
vestal cairn
#

I've been trying to solve it for 2 hours and I just have no any ideas how to fix it

#

It displays 'filtered'. But why if the article tells me to connect via rdp ...

nmap -Pn -p 3389 10.129.36.73
Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-04-12 12:12 EEST
Nmap scan report for 10.129.36.73
Host is up.

PORT     STATE    SERVICE
3389/tcp filtered ms-wbt-server
dim hound
#

Do you have with student subscription access to AI path?

vestal cairn
#

No I don't

#

I've tried to change HTB VPN server, reset remote machine
I've successfully connected the first time, After that I disconnected and tried one more time - get an error again

#

I've found the problem! Multiple openVPN. I though If I click Ctrl+C I stop VPN. But it doesn't work like that Just needed to killall

ebon pebble
#

Hi can someone help me with this module: https://academy.hackthebox.com/app/module/80/section/772
The first exercise for Broken Authentication Vulnerabilities in the Web Penetration tester Job Role Path. I tried to fuzz for a correct username based on the difference in the size of the response when a username is correct or not.
The command: ffuf -u "http://154.57.164.68:32683/index.php" -w SecLists/Usernames/xato-net-10-million-usernames.txt -X POST -H "Content-Type: application/x-www-form-urlencoded" -d "Username=FUZZ&Password=invalid" -fs 3264 -ms 3271

ebon pebble
ebon pebble
fallen trail
#

Hello, in cwee module 7 skill assessment, i cannot receive the email, even copypasting the solution, may anyone be able to help?

cloud urchin
#

best to just name the module no one knows what 7 is

fallen trail
#

Apologies, http attacks

quasi wave
#

hi so for the DNS Zone Transfer section of Information Gathering - Web Edition module, I am trying to get the zone transfer for the IP address and tried to do a reverse lookup on the IP and it didn't give me a domain name. I then tried axfr on it it but the transfer failed:

┌──(kali㉿kali)-[~]
└─$ dig axfr 172.20.10.1 zonetransfer.me

; <<>> DiG 9.20.20-1-Debian <<>> axfr 172.20.10.1 zonetransfer.me
;; global options: +cmd
; Transfer failed.
; Transfer failed.
                                                                                                                                                                              
┌──(kali㉿kali)-[~]
└─$ dig axfr @10.129.42.195 zonetransfer.me
;; Connection to 10.129.42.195#53(10.129.42.195) for zonetransfer.me failed: timed out.
;; no servers could be reached
^C                                                                                                                                                                              
┌──(kali㉿kali)-[~]
└─$ dig axfr 10.129.42.195 zonetransfer.me 

; <<>> DiG 9.20.20-1-Debian <<>> axfr 10.129.42.195 zonetransfer.me
;; global options: +cmd
; Transfer failed.
; Transfer failed.
                                                                                                                                                                              
┌──(kali㉿kali)-[~]
└─$ dig -x 10.129.42.195                  

; <<>> DiG 9.20.20-1-Debian <<>> -x 10.129.42.195
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 11849
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;195.42.129.10.in-addr.arpa.    IN      PTR

;; AUTHORITY SECTION:
10.in-addr.arpa.        3542    IN      SOA     prisoner.iana.org. hostmaster.root-servers.org. 1 604800 60 604800 604800

;; Query time: 11 msec
;; SERVER: 172.20.10.1#53(172.20.10.1) (UDP)
;; WHEN: Sun Apr 12 16:20:55 EDT 2026
;; MSG SIZE  rcvd: 132

What do I do here?

acoustic owl
quasi wave
#

or anything like that

#

and I am assuming that's what the section wants me to do?

#

I know this works:

┌──(kali㉿kali)-[~]
└─$ dig inlanefreight.htb                      

; <<>> DiG 9.20.20-1-Debian <<>> inlanefreight.htb
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 26437
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;inlanefreight.htb.             IN      A

;; AUTHORITY SECTION:
.                       3226    IN      SOA     a.root-servers.net. nstld.verisign-grs.com. 2026041201 1800 900 604800 86400

;; Query time: 12 msec
;; SERVER: 172.20.10.1#53(172.20.10.1) (UDP)
;; WHEN: Sun Apr 12 16:26:06 EDT 2026
;; MSG SIZE  rcvd: 121
acoustic owl
quasi wave
#

ok so it mentioned zonetransfer.me in the section. when I dig -x the IP given from the host I had started, it showed this:

┌──(kali㉿kali)-[~]
└─$ dig -x 10.129.42.195                    

; <<>> DiG 9.20.20-1-Debian <<>> -x 10.129.42.195
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 4093
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;195.42.129.10.in-addr.arpa.    IN      PTR

;; AUTHORITY SECTION:
10.in-addr.arpa.        3542    IN      SOA     prisoner.iana.org. hostmaster.root-servers.org. 1 604800 60 604800 604800

;; Query time: 11 msec
;; SERVER: 172.20.10.1#53(172.20.10.1) (UDP)
;; WHEN: Sun Apr 12 16:31:56 EDT 2026
;; MSG SIZE  rcvd: 132
#

yet this doesn't work:

                                                                                                                                                                              
┌──(kali㉿kali)-[~]
└─$ dig axfr inlanefreight.htb prisoner.iana.org

; <<>> DiG 9.20.20-1-Debian <<>> axfr inlanefreight.htb prisoner.iana.org
;; global options: +cmd
; Transfer failed.
; Transfer failed.
                                                                                                                                                                              
┌──(kali㉿kali)-[~]
└─$ dig axfr inlanefreight.htb hostmaster.root-servers.org

; <<>> DiG 9.20.20-1-Debian <<>> axfr inlanefreight.htb hostmaster.root-servers.org
;; global options: +cmd
; Transfer failed.
; Transfer failed.
#

it said in the section zonetransfer.me is used to test transfers unless I'm misinterpreting the section

acoustic owl
#

Read through the entire chapter again and try to understand how DNS works. You're mixing up a lot of things here.

quasi wave
#

ok I'll reread

#

thanks

acoustic owl
acoustic owl
acoustic owl
quasi wave
#

ok I am gonna YouTube it I know CloudFlare is credible but I want to practice finding my own sources

#

ah ok

#

I'm about to watch 30 minute YouTube video on DNS

#

since that's probably the smarter move here

#

I'll talk to you in 30 minutes

shut wraith
#

Wifi Pentesting Basics

Why is the answer for interface modes "5" when as you can see in the image there are "9" modes

quasi wave
#

Hi ok so there are issues connecting to HTB VPN. It won’t download VPN file in my Kali box. When I download, the file won’t run in host OS.

#

Which is one issue.

#

Can someone help with that?

karmic osprey
#

Hey, working through Linux Fundamentals module. The curl exercise for inlanefreight.com is timing out from the Pwnbox. Site is up but curl returns empty. Anyone else hit this and know a workaround?

hexed oyster
#

I have completed the course work for the cwes: What's the best way to start preparing for the test?

heavy sluice
chilly night
# acoustic owl Read through the entire chapter again and try to understand how DNS works. You'r...

Hey, im doing the AD enumeration and attacks skills assessment 2.
i managed to log into the SQL01 machine and dump the administrator hash as shown. after many attempts trying to rdp/winrm into the MS01 machine with the administrator hash i decided to find a guide...

the guide posted a hash and i decided to try that hash instead and it worked. but the hash on SQL01 is different?

is there an explanation?

waxen totem
fathom pendant
fathom pendant
#

similar to the fact that buying stolen goods is still illegal, even though you weren't the one that stole it

heavy sluice
fathom pendant
#

"i decided to find a guide" doesn't sound like a guide by their team

heavy sluice
fathom pendant
#

if it was a private guide made by their team, then perhaps they would have said "a guide i followed written by a team member" or something like that

#

I get you're trying to play the devil's advocate, but come on dude

pseudo kiln
#

Anyone around here completed the android pentesting path? It seems to have good reviews on the platform, but no review/article on it so far.

heavy sluice
pseudo kiln
heavy sluice
pseudo kiln
#

Yeah for sure, in engagements typically an APK without protections is also provided, in case root detection bypass is not possible for example.
Thanks for the info though, seems much more in depth than other offerings on the market
I have a feeling the Android half is done, with the iOS one being in development prayge

silent scaffold
#

i looked at the first modules, there are not worth the tiers 3 and so I consider them at tiers 2 ; they are better options out there for android pentesting . Maybe the path is in dev/extend but i don't know

heavy sluice
steel snow
#

hey!

#

excuse me

#

for the password attacks skll assessment

#

i have gotten the hash

#

however the website is saying it's incorrect

verbal ivy
#

Hey guys !
If anyone require help with any module please let me know 🙂

steel snow
#

Yes

#

I want please!

verbal ivy
#

which one ?

steel snow
#

password attacks

#

skill assessment

#

not particularly a help, i finished it

#

however for some reason

#

my answer is

#

wrong?

verbal ivy
#

what ur ntlm hash start with ?

#

and end with

steel snow
#

31cc1-------------------0cceb

verbal ivy
#

wrong hash

steel snow
#

hmmmmm

#

but i am pretty sure

#

that's the Administrator hash

#

of Nexura

#

not the local

verbal ivy
#

keep looking it should start with 36exxxx6d23

steel snow
#

Thank you very much!

#

hmmmmmmmm

#

thing is i don't know what to look for more

verbal ivy
#

You welcome !

steel snow
#

i dumped the NTDS

#

the system

#

sam

#

and security

verbal ivy
#

i ll nudge u a bit let me look at my notes

steel snow
#

everything is done now

#

Sure thing :)

#

i appreciate you!

verbal ivy
#

u suppose u doing this from the DC01?

steel snow
#

correct

verbal ivy
#

u logged in with rdp ?

steel snow
#

yes

#

after editting the registry

#

DisableRestrictedAdmin

verbal ivy
#

u probably looking at the wrong NTDIS

#

maybe think where the AD NTDIS is stored

steel snow
#

ehh? those are topics i have not yet encountered

#

we haven't gone in depth in

#

password attacks

#

we learnt the method of vssadmin

#

then copy NTDS/NTDS.dit

#

that's what i did

verbal ivy
#

send me in dm what u got

steel snow
#

Sure!

#

sent!

pseudo kiln
tidal kelp
#

Anyone else having issues running Powerview?
I've downloaded the latest I can find in powersploit, but unable to import it and run it from a windows host where rather sure it should work from?

silent scaffold
#

@pseudo kiln it depend on what you are looking for : practical training or certification or pure theory

vale pulsar
#

I still got VPN problems tho I switched to bridged but it's still not working

brazen marlin
pseudo kiln
heavy sluice
tidal kelp
#

no disabled it

#

the problem is more of importing the module

#

I'm missing functions

heavy sluice
tidal kelp
#

I'll try. to problem isn't that I get any error message

#

the problem is more that that the function just isnt there

heavy sluice
tidal kelp
#

Get-DomainObjectACL

ebon jasper
#

Hello everyone

#

I need serious help with ADCS attack module I promise I do not take long time

heavy sluice
# tidal kelp Get-DomainObjectACL

PS C:\Users\bh> Import-Module .\PowerView.ps1
PS C:\Users\bh> Get-DomainObjectAcl [parameters]
works for me with the version I provided to you

tidal kelp
#

Ok, I'll try

hollow ivy
#

I'm new to this journey, I'm getting certified by the national cybersecurity association but I want to deepen my knowledge, and I decided to do the academy and then the labs. However, in the academy I'm in the Linux module, as shown in the attached image, and I can't find it, even though I've already done a lot. Can someone help me solve this, please, and explain how they did it so I can learn and master this technique?

Regards

primal needle
#

Hi, I have an issue with "Android Application Static Analysis - Reversing Hybrid Apps" exercises. I found debug key in both apps (also decompiled Hermes), but when I try using it with curl as a debug_key parameter, I always get "Invalid credentials!". Am I missing something? Thanks 🙂

shut wraith
unreal crane
rare condor
unreal crane
#

yeah academy is not usable any more no more slide bar terminal

#

thats rough

magic forum
pine knot
#

Hi, to do kerberos relay with RBCD attack we need service account with an SPN, the ability to add computer accounts, and a target with no LDAP signing and find a coerce method ?

fathom pendant
#

@knotty gulch dont dm people without asking

near sedge
#

I just got the student subscription for the academy, should i jump right into a certification track like CPTS, or should I start off with the modules in CJCA?

#

i'm like pretty brand new to practical cyber security, however, I do have some basic knowledge about like attacks and stuff

#

nevermind, found the prereqs for CPTS, not there yet at all lmao

#

lock in on CJCA time

full echo
#

you can dm me.

#

you can dm me if you're still stuck

#

You're almost there. Look at the hint and change the way how folder is represented in Windows

#

Did you get the path yet?

agile torrent
#

Hello all! Trying to do the 'attacking windows credential manager' section of password attacks. I've used runas to impersonate the other user and moved mimikatz onto the machine. When running privilege::debug I get the RtlAdjustPrivilege error, which I'm pretty sure means I don't have the right perms.

I managed to solve the challenge by doing token::elevate then vault::cred, but I don't think that's the method they were trying to teach.

Any ideas why the privilege::debug command is failing? tyty

agile torrent
#

gotcha, i guess my question then is how would I get to an admin shell from the mcharles user?

rdp as sadams -> impersonate mcharles w interactive creds/token -> ? -> run mimikatz from admin shell

lusty trench
#

Please, can anyone help me? Lateral Movement lab in Attacking Enterpise Networks.

cloud forum
#

then dump the credential manager.

#

thats how htb wants you to solve the lab

agile torrent
#

ohh gotcha, i don't think i've stumbled onto that yet. will do some research, thanks 🫡

cloud forum
fathom pendant
#

btw

#

a baked pasta will also do the trick

agile torrent
fathom pendant
#

:)

cloud forum
fathom pendant
cloud forum
#

oh

fathom pendant
#

they want you to solve it in whatever way works

#

i forget what the solution guide has you do, but i don't recall if it does the bypass

cloud forum
#

Work through the examples in this section to gain a better understanding of ACL abuse and performing these skills hands-on. Set a fake SPN for the adunn account, Kerberoast the user, and crack the hash using Hashcat. Submit the account's cleartext password as your answer.

i resetted his password😭

agile torrent
agile torrent
cloud forum
fathom pendant
cloud forum
#

hmmmmmm i hear u

lusty trench
#

Hi guys, has anyone finished the Lateral Movement lab in Attacking Enterprise Networks yet?

proper haven
#

Is anyone experiencing problem spawning target machines?

tiny plaza
#

Yes

verbal ivy
#

anyone need some nudgies?

sterile harness
#

Which kernel release is installed on the system?
It’s showing error with this answer 6.12.32, I used command “uname -r” for getting kernel release pls help

gray yacht
gray tulip
#

Hello guys , the targets failed to spawn and even the pwnbox don't launch . Is it just me or is the site down ?

quaint cliff
#

Hello. does anyone did the "Application of AI in infosec" module? they provide us at some point with a function to check for invalid ip adress, but it returns an error " expected string or bytes-like object, got 'float'". Which is strange since the column type is "str", and there is a method to enforce the type in the function

quaint cliff
cloud urchin
#

@drifting heron Please take care not to post content from modules above tier 0, like attack paths etc

drifting heron
#

@cloud urchin where should I ask?

cloud urchin
#

If you feel like you need to reveal more info you can ask someone to DM

#

Anyone who has completed the module doesn't need the extra info like attack paths etc though

fiery lake
#

cracking WPA02 hash with hashcat in SAE Downgrade Attack module takes ages. Any help?

gray yacht
fiery lake
coral onyx
#

hi guys why cant i see VPN like in the screenshot next to it ?

gray yacht
fathom pendant
fiery lake
gray yacht
hollow wind
#

Is the "NetworkFoundations" SkillAssessement completable without the pwnbox?

fathom pendant
#

yes

hollow wind
fathom pendant
#

why would it be?

hollow wind
#

The Keep me in the Loop part states that it will be showcasing the pwnbox

fathom pendant
#

yeah, but it's still doable on your own machine

#

showcasing just means that they're using it, doesn't mean it's absolutelly only doable with pwnbox -- that'd be silly

steady forge
cloud forum
#

Do u guys have issue spawning machines

fierce vault
#

Hello, i would like to point to a misleading sentences in two modules, which channel is the most suitable for it ?

willow lintel
fierce vault
#

thx

white vale
#

why do I keep getting this

steady forge
raven spruce
#

Skills Assessment - Web Fuzzing

Stuck at Q3:
One of the pages you will identify should say 'You don't have access!'. What is the full page URL?

Generally the methodology for this module is simple, but can anybody tell me if I'm able to complete this module by using wordlists from this dir?

/opt/useful/seclists/Discovery/DNS

Or i need some other dir? Going through all of them would be a waste of life.

Thank you.

fathom pendant
gray yacht
fathom pendant
#

you need to filter and match a page that says "You don't have access!"

hollow wind
#

Update: i have tried 10 more times including 2 times asking ai to assist me at every step (which i really do not want to do as i dont really learn anything from using ai) still connection refused

fathom pendant
#

AI can steer you in the wrong direction

hollow wind
#

Idk how but apearently i was typing something wrong and i got it to work so i am deleting prev messages

#

Well the unansered ones

#

Stil have the problem of the passive ftp command closing itself after a few minutes tho ):

fierce vault
#

Stack-Based Buffer Overflows on Linux x86

How large can our shellcode theoretically become if we count NOPS and the shellcode size together? (Format: 00 Bytes)

Hello, I have a question about this question.

Personally, I feel like there are many misleading things in the stack-based buffer overflow and assembly module. I've done just a little programming in assembly, so I could be wrong; that's why I'm writing a question.

For example (img1), which is the question in the stack-based buffer module: I believe there is no exact number. (That said, I figured out the answer for the section, but I feel like it's wrong). If I can overwrite the last thing on the current stack, which on RET becomes the EIP, then I control the address. Since the stack (based on this question) has to be executable, then there's no limit to the shellcode size. I could write the shellcode after the ESP -> after the EIP that was popped, and then there's an unknown limit.

Or I can just overwrite the stack before the EIP, as shown in the picture, and then there's only a limit from the start of the buffer to the "future EIP," which would make the answer to the module incorrect.

could someone explain if i missed something or is my deduction wrong ?

quasi wave
#

hi for the virtual hosts section of the Information Gathering - Web Edition module, I am trying to enumerate the subdomains of inlanefreight.htb, using the IP address but I don't think I am getting the answers to the current flags.

Is this the wrong wordlist?

Here is my output:

┌──(kali㉿kali)-[~/Desktop]
└─$ gobuster vhost -u http://154.57.164.73:30583 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt --append-domain
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                       http://154.57.164.73:30583
[+] Method:                    GET
[+] Threads:                   10
[+] Wordlist:                  /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt
[+] User Agent:                gobuster/3.8.2
[+] Timeout:                   10s
[+] Append Domain:             true
[+] Exclude Hostname Length:   false
===============================================================
Starting gobuster in VHOST enumeration mode
===============================================================
#www.154.57.164.73:30583 Status: 400 [Size: 157]
#mail.154.57.164.73:30583 Status: 400 [Size: 157]
#smtp.154.57.164.73:30583 Status: 400 [Size: 157]
#pop3.154.57.164.73:30583 Status: 400 [Size: 157]
Progress: 114442 / 114442 (100.00%)
===============================================================
Finished
===============================================================
safe star
#

Why not use the domain name instead

brazen marlin
tacit fog
#

Hey so on the "introduction to threat hunting & hunting eith elastic" module, I'm on section 5/6, the bit about Stuxbot.

For question 2 I'm really stuck.

The question is "Stuxbot uploaded and executed mimikatz. Provide the process arguments."

I'm 90% sure the answer is ||"lsadump::dcsync /domain:eagle.local /all /csv" exit ||, but every which way i try to format the answer it says I'm wrong, but i really can't find another possible answer. When you search for mimikatz there's only one log entry that mentions a command line input with process arguments. Am i doing something really wrong here?

quasi wave
#

the progress bar is at like 33%

#

or would it be recommended for me to wait for gobuster to finish anyways?

#

this is for the virtual hosts section of information gathering web edition module

cloud urchin
#

@quasi wave Please take care not to post content from modules above tier 0

brazen marlin
ebon gulch
#

Guys im stuck at broken authentication skills assessment to the point that I think the lab is broken🫤

chilly night
#

all im getting is id is not injectable... i have tried level 5 aswell

cloud urchin
#

@chilly night Please do not post content from modules above tier 0, especially skill assessments. Anyone who has completed it doesn't need the details to help, and if you feel like you need to reveal more info you can take it to DM's.

chilly night
#

im stuck on the sqlmap skills assessment all i get is paramater not injectable

#

can someone dm me pls

bold sentinel
#

hello guys
I'm currently working on "Attacking Thick Client Applications" and I can't find the memory I'm looking for in the tutorial. Please help me.

supple dragon
# fierce vault Stack-Based Buffer Overflows on Linux x86 How large can our shellcode theoretic...

I don't think you have missed anything, I'm assuming it is just that they want to keep the initial introduction to buffer overflows simple and familiarize the student with the general concept of figuring out how much space you have available at your initial entry point, which is a typical task during exploit development. For sure, there are techniques for finding additional space on the stack etc., but as I recall, in this module they demonstrate a basic exploit development workflow, which may require certain things to be "oversimplified" a bit pepearoo

night shale
#

Hi there, can I get help on the path CWEE, module “Introduction to NoSQL Injection”, section skill assessment part 2, I can’t seem to be getting the reset token with the payload/script im using

heavy sluice
bold sentinel
#

You might be right... I saw in the tutorial that the memory map was opened without specifically setting breakpoints.

bold sentinel
tame shoal
#

Hi, could someone help me with the skills assessment of File inclusion module ? Can't find the page and param where LFI work

pseudo bane
#

is there any issue with password attacks skills assesment lab? i keep getting target spawning and zilch also pwnbox give error There are no available instances. Please try again later.

supple token
#

hii guys

#

I'm trying to start an Pwnbox but it's saying that there is no instance available every time that i tried, anyone with the same issue?

pseudo bane
long geyser
#

Experiencing issue in spinning PWNBOX for EU and DE in Academy. Any one else having the same issue?

supple token
gray yacht
long geyser
#

PWNBOX is working now.

young rapids
#

spawning box in academy not working for the past 30-40 mins , anyone else ? tried switching regions, not working

flint patio
hollow wind
#

I just tried as i was having really bad connectivity errors with the academy ftp client in a module yesterday so maybe the pwnbox?

#

Nope there goes my singular free spawn ):

#

Atleast i have a live usb with htb parrot os but this must be really annoying for all those paid users and free users relying on their 1 spawn per day

hearty forge
hollow wind
#

im trying this ftp connection 1 more time and if it does not work i will send a screenshot

#

IT WORKS!!! after trying the same thing for a 40th time

#

why did it work this time

#

and other times when i connect to the dynamic port it refuses conenction for no reason at all?????

#

(deleted the screenshot because possible spoilers)

hearty forge
night shale
#

Hi there, can I get help on the path CWEE, module “Introduction to NoSQL Injection”, section skill assessment part 2, I can’t seem to be getting the reset token with the payload/script im using

austere hound
#

Anyone having trouble to spawn targets? I'm currently doing the AEN module, but the target do not spawn. I'm trying the button "Spawn the target system" from about an hour, with no success. HELP

brave field
#

EU Servers are not spawning targets - US Servers are, for me at least.

young rapids
hollow wind
distant condor
#

I'm in Vietnam and every night I have problems with HacktheBox VPN, slow connection or even no connection at all

mystic osprey
#

hey guys I can't spawn machines it says:
Ooops! Something went wrong. Please try again later!

heavy sluice
mystic osprey
#

okay

heavy sluice
sly nebula
#

I confirm EU academy labs are currently broken.

mystic osprey
languid fjord
#

@rare condor what do you mean its down?

#

did you hit spawn?

#

(re: your feedback)

willow lintel
#

can't spawn target AGAIN !!!

thorny sonnet
#

Hello friends, I just signed up with the student plan after completing CS101 on THM, didn't really love it over there. I am fairly new to everything networking related, halfway through CCNA studies and been doing CTFs for about 4 weeks.
So my question; Should I start with the Basic Toolset module and run through some of the skill paths and then jump over to job role paths? Or is there a better starting point for academy?
Appreciate any help/input, thanks

#

Hope this is the right room for this question btw, otherwise lemme know where to ask instead

tidal bay
#

targets are not working, is it the same for you guys ?

mossy stream
mossy stream
#

Thanks!

heavy sluice
#

guys don't read further than 5 messages..

heavy sluice
ebon gulch
#

Anyone completed Broken Authentication Skills Assessment DM me please!

rare condor
rare condor
# tidal bay

yeah bro same I already report it and Emmax0 is talking about it

languid fjord
#

Yeah if your having troubles with EU vpns switch to US

#

theres been some issues as of late

rare condor
swift dove
#

Android Penetration Testing Automation > MobSF
So last I checked, Im pretty sure this is not "India"? LOL

swift dove
#

Thats where im suppose to raise it? Right ?

spark yacht
silk ice
#

On the pwnbox, can anyone get ldapsearch -h | less to work? For some odd reason, the less doesn't show the beginning of the help output and whenever I try to jump to the start by pressing gg, it just shows blank lines and I can't do G or anything. Is this just on my pwnbox or something user-wide? I'm just curious why less wouldn't work properly for ldapsearch unless I'm missing something...

spark yacht
#

try with the -H flag too

silk ice
# spark yacht does ldapsearch -h work? if i remember properly it's an old flag that was used f...

ah thanks for the reply & info. I did some digging and it seems like the -h is not a valid flag thus printing the output to stderr and because | less takes stdout (which is empty from my command) to less, it resulted in an empty less output (which is expected). I tinkered a bit to see the available options using less by running ldapsearch -h 2>&1 | less but at that point I'm just gonna run man ldapsearch haha. Thanks for the info anyway 🙂

spark yacht
#

it should be the same as the man command, just easier to read

quasi wave
#

hi so for the fingerprinting section of Enumeration Gathering - Wed Edition Module, I am doing the questions but I don't think it is working. I am like 99% sure I am doing this right. I try to use Nikto but its not working. I pinged it first to confirm I can connect to the server. The questions are asking me to use Nikto to get web app fingerprint information about inlanefreight.local's subdomains: app.inlanefreight.local and dev.inlanefreight.local, respectively. Here's my evidence of what I have tried.

┌──(kali㉿kali)-[~]
└─$ ping inlanefreight.local 
PING inlanefreight.local (10.129.64.187) 56(84) bytes of data.
64 bytes from inlanefreight.local (10.129.64.187): icmp_seq=1 ttl=54 time=35.2 ms
64 bytes from inlanefreight.local (10.129.64.187): icmp_seq=2 ttl=54 time=36.1 ms
64 bytes from inlanefreight.local (10.129.64.187): icmp_seq=3 ttl=54 time=33.1 ms
64 bytes from inlanefreight.local (10.129.64.187): icmp_seq=4 ttl=54 time=33.4 ms
^C
--- inlanefreight.local ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3004ms
rtt min/avg/max/mdev = 33.124/34.454/36.082/1.234 ms
                                                                                                                                                                             
┌──(kali㉿kali)-[~]
└─$ sudo vi /etc/hosts          
                                                                                                                                                                             
┌──(kali㉿kali)-[~]
└─$ ping app.inlanefreight.local
PING app.inlanefreight.local (10.129.64.187) 56(84) bytes of data.
64 bytes from inlanefreight.local (10.129.64.187): icmp_seq=1 ttl=54 time=37.2 ms
64 bytes from inlanefreight.local (10.129.64.187): icmp_seq=2 ttl=54 time=28.2 ms
64 bytes from inlanefreight.local (10.129.64.187): icmp_seq=3 ttl=54 time=32.7 ms
^C
--- app.inlanefreight.local ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2009ms
rtt min/avg/max/mdev = 28.244/32.744/37.246/3.675 ms
                                                                                                                                                                             
┌──(kali㉿kali)-[~]
└─$ ping dev.inlanefreight.local
PING dev.inlanefreight.local (10.129.64.187) 56(84) bytes of data.
64 bytes from inlanefreight.local (10.129.64.187): icmp_seq=1 ttl=54 time=42.2 ms
64 bytes from inlanefreight.local (10.129.64.187): icmp_seq=2 ttl=54 time=42.2 ms
64 bytes from inlanefreight.local (10.129.64.187): icmp_seq=3 ttl=54 time=35.6 ms
^C
--- dev.inlanefreight.local ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2011ms
rtt min/avg/max/mdev = 35.641/39.987/42.169/3.073 ms
                                                                                                                                                                             
┌──(kali㉿kali)-[~]
└─$ 
                                                                                                                                                                             
┌──(kali㉿kali)-[~]
└─$ nikto -h app.inlanefreight.local -Tuning b
- Nikto v2.6.0
---------------------------------------------------------------------------
+ Your Nikto installation is out of date.
+ [FAIL] Unable to connect to app.inlanefreight.local:80.
                                                                                                                                                                             
┌──(kali㉿kali)-[~]
└─$ nikto -h https://app.inlanefreight.local -Tuning b           
- Nikto v2.6.0
---------------------------------------------------------------------------
+ Your Nikto installation is out of date.
+ [FAIL] Unable to connect to app.inlanefreight.local:443.

I know I can ping those services so my connection is working. I tried upgrading and updating Kali but haven't restarted. Otherwise, what else can I do here?

fathom pendant
#

Its defaulting to https...

#

Ah nvm

#

I dont recall having issues with nikto

#

But pinging doesnt mean anything

quasi wave
#

ok I nmapped it and port 53 is open

fathom pendant
#

Because its the same ip

quasi wave
#

so I'm trying http but over port 53

#

seeing if that works

fathom pendant
#

That's not how that works

#

53 is dns

#

Which is where im assuming you got the subdomains from

quasi wave
#

ya but you can run HTTP on any port technically the port is the default port number for that service, no? and the instructions gave me the subdomains

fathom pendant
#

Try restarting the lab and/or changing vpn regions

quasi wave
#

wait nope didn't work tho and ya I respawned target maybe a different VPN will do it

fathom pendant
quasi wave
fathom pendant
#

The reason pinging doesnt matter btw is because its not reaching out to a port

quasi wave
#

I tried modifying /etc/hosts file it didn't do anything either

#

like to add app.inlanefreight.local or dev.inlanefreight.local and it made zero difference

fathom pendant
#

Its just asking the ip if its up, and because of the nature of vhosts - pinging a different subdomain of a vhost doesnt change anything

quasi wave
#

ah ok

#

is it possible the lab could be faulty?

#

I mean I completed the module a long time ago anyways and this is a redo so tell me am I actually doing it right?

#

I just changed the VPN and spawned a new target it didn't work

#

wait hold on a sec

#

Mullvad was on may have gotten in the way

#

trying with Mullvad turned off

#

YES

#

I MADE IT WORK

#

had to configure a bunch of stuff

#

but figured it out

silk ice
fathom pendant
#

(external) VPNs can cause some issues, it's one of the first suggestions that'll be given to disable it when doing labs

silk ice
#

cool, good to know. What other stuff is suggested to disable?

spark yacht
silk ice
#

great info, thanks!

quasi wave
night shale
#

Hi there, can I get help on the path CWEE, module “Introduction to NoSQL Injection”, section skill assessment part 2, I can’t seem to be getting the reset token with the payload/script im using

quasi wave
#

ok got all the flags finished my work for the day thanks @fathom pendant

#

I'm psyched

tall fern
#

Hi anybody have the VPN Academy section? or only me bugged?

fathom pendant
#

means vpn not required, it's a public container

tall fern
#

ready, that was because that lab are in docker container

tall fern
#

thanks!

timber gull
#

Hi guys, could you give me a few advices ? I don’t know, maybe I’m just too stupid, but I’m stuck on the topic of filtering in the Linux module. Are there any ways I can practise this? Or to learn it faster?

#

In everyday usage I don’t use any filtering commands (only grep “…”, mb here is a key 🥲

timber gull
#

Idk how to improve it

waxen totem
timber gull
#

I’ll try, thx 🫡

tawny tartan
#

anyone still having problems spawning targets?

still tartan
tawny tartan
#

nope

#

i think there nothing we can really except waiting :/

vale trail
#

Hi, im currently on the section "Creating Our Own CME Module" in the "UsingCrackMapExec" module
But as i'm using nxc instead of cme, i'm looking for information on building custom modules on nxc.
I found one article, but does not seem to work

fathom pendant
#

i wouldn't worry too much about it unless you absolutely need to do the thing

tawny tartan
#

its starting to get annoying 🙁

#

maybe is it a problem with the 'Password Attacks' module ?

still tartan
fleet spear
#

im on paswords attacks seems to be a problem spawning one time it spawned but it dident respond

tawny tartan
fleet spear
#

yeah it is proably some real issue have not experienced anything quite like this before

narrow ledge
#

Ehi, if i post my script in here can some of you guys explain to me what is wrong with my code or is it aginst the rules? I'm stuck at the loops modules for bash script

fathom pendant
#

it's against the rules

#

because the module is above tier 0

narrow ledge
#

Oh, sorry

fathom pendant
narrow ledge
#

Got it

fathom pendant
#

which section is it?

narrow ledge
#

Flow control loops

#

I'm freaking losing my mind

fathom pendant
#

you're likely off by one

#

the module expects echo $var | wc -m not using ${#var}

narrow ledge
#

Nope doesn't work, I'm trying to solve this for over a month

spark yacht
#

just include the question and what you have so far

fathom pendant
signal chasm
#

i am doing the network enumeration with nmap module. Trying to solve the "Nmap Scripting Engine". The question at the end is: Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer.
How should I know, that I need to specifically scan Port 80? If i scan everything, I have various Ports open. According to the solution, I need to dig deeper into the Port 80. How should I know that?

arctic remnant
#

did you get the Skills Assessment 2 solved?

signal chasm
#

ok got it... so port 80 is always nice to look into. gona put that to my "first things to do with nmap" list. thhanks for the help

spark yacht
viral lotus
#

I tried posting a module question yesterday but it timed me out. are there any flagged characters that can cause this? it was just a specific error message thats in the question in a NTLM Relay attacks subsection

elfin elm
#

can anyone helpme in response splitting http attacks been stuck since 24 hours not able to get it work

red echo
#

can someone help me with module hacking wordpress, directory indexing part?

#

i cannot access any other folders except wp-content, and it doesnt contain the flag

fathom pendant
red echo
#

can u help me marcie 🙁

#

i got stuck for 3 hours

fathom pendant
red echo
#

i cant find the flag.txt file anywhere

#

i have tried everything

#

wp-content, wp-includes, wp-admin

buoyant birch
#

I’m having trouble with a question from Network Foundations Module. I’m on section 7/12 Domain Name System. I’ve tried every answer for question 4, which is, “What type of DNS server is typically provided by an Internet Service Procider?” I believe it is Recursive, but it won’t accept any answer. Does anybody know if I’m right?

fathom pendant
fathom pendant
red echo
#

Wont take u too long

#

I just doubt that something happened to the server

fathom pendant
loud harness
#

Hey everyone!

  • Module Name - Pentest in a nutshell
  • Section Name - Windows Vulnerability Assessment
  • Question you're struggling with -
    Only question in the section
  • Generally what you've tried (while avoiding spoilers, i.e. logged in as j* and couldn't find anything) - I found the file it’s referring to, and copy pasted the asked for line from my powershell window, when it didn’t work I went through the windows gui and opened the file, and copy pasted from there. Still saying it’s not right
buoyant birch
fathom pendant
arctic remnant
loud harness
arctic remnant
cloud forum
#

can someone help me in AD enumeration & attacks in module 9 privileged access.

#

i have solved it but i had a weird problem. i could do this query in bloodhound on the windows attackhost from hackthebox. but on my machine it didnt work.

#

MATCH p1=shortestPath((u1:User)-[r1:MemberOf*1..]->(g1:Group)) MATCH p2=(u1)-[:CanPSRemote*1..]->(c:Computer) RETURN p2

gray yacht
night shale
#

Hi there, can I get help on the path CWEE, module “Introduction to NoSQL Injection”, section skill assessment part 2, I can’t seem to be getting the reset token with the payload/script im using

fleet spear
#

the new query system seems abit hard to learn

steel snow
#

Excuse me, in the medium skill assessment for common services attack

#

because first time i saw it

#

next time i spawned a machine

#

there was no FTP

#

so i wonder if i should restart it

#

okay, there is actually

#

it was glitched

cloud urchin
steel snow
#

just an nmap

cloud urchin
#

it was a reveal

limber owl
#

Hello everyone. I have been trying to do LLM Output Attacks Skill Assessment but am stuck. I confirmed it is SQL Injection with the bot, but struggling with actually performing it. I would get operational error or invalid syntax. Any help please?

opal crater
#

goodmorning from japan

#

hello admin i am a hack the box begninner , i have been stuck on academy labs for a long time, i can connect to windows host and create file share but i am not able to connect to the smb server through smbclient , what is the issue i tried using pwn box and i also tried to connect using my own kali vm. please help me resolve ths and move ahead

#

note: i did not try both pwn box and my kali vm at same time i tried them seperately one at a time once the first did not work i tried my vm the next day

fleet spear
#

smbclient //ip/sharename -U domain/user -L //ip to just list what shares are available @opal crater

steel snow
#

i think this is a baiter

#

botpandaa

fleet spear
#

and if you anyway connect with xfreerdp u can aswell mount the files directly with /drive: path,sharename

opal crater
#

so the insturction on the course is outdated

#

shoot

steel snow
#

the command you used is wrong

#

like the syntax

opal crater
#

you mean this

#

this is wrong or

#

my command

#

?

#

what will the begennier understand with this

#

?

#

if we were pro why would we take the course

steel snow
#

to learn searching :>

opal crater
#

so the course provided steps might be wrong please search

#

i think this would be a apropriate note to be sticked then

#

why promote you teach better and put wrong steps there

#

its not that i cant search i can but i am just worried about why put wrong steps and dont notify user what might be wrong

fleet spear
#

did it work with -L //ip ?

opal crater
#

smbclient //10.129.72.79/"Company Data" -U htb-student
do_connect: Connection to 10.129.72.79 failed (Error NT_STATUS_IO_TIMEOUT)

#

💀

opal crater
#

i think academy labs is not ment to be accessed by smbclient i guess

opal crater
near sedge
#

what am i doing wrong here on the skills assessment box in network foundations? i am following the instructions on the box step by step, and its not doing what it should be doing

#

also please pardon my not using a screenshot tool, i’m stuck on my computer i use for school, and I don’t have discord on it

steel snow
#

it's pasive mode

#

passive off to remove it

near sedge
#

ahh gotcha

steel snow
#

Yosh!

swift carbon
#

anyone for a nudge on Windows Lateral Movement Skill Assessment WSUS part ?

untold orbit
#

4 times \ and space should be escaped with \

waxen totem
waxen totem
untold orbit
#

I have been using \ lol 😅

waxen totem
#

As long as you know that \ need to be escaped

mild glade
#

Can I DM someone regarding the Kerberos Attacks skills assessment ?

autumn pilot
#

sure

lethal kayak
#

Hello guys. I'm stuck on the live engagement of the shells and payloads module. If anyone could help 🙇‍♂️

eager ledge
lethal kayak
#

question 2. I'm trying to gain shell access to host 1

#

I tried msfconsole but didn't work and now i'm trying the script in the laudanum folder. I created a new war file (i remembered to change the ip address) and then uploaded it with the manager app. i feel like this should work but it's not. It's almost like the file isn't really being uploaded but I can't tell even with burpsuite and don't have any other ideas.

gray yacht
swift dove
#

Hey there, the entire module on Objection in the Android Penetration Testing Automation seems to be broken, the app doesn't trigger the same way the lesson explains, I get a flag and it doesn't get validated. Has anybody finished it?

wide pasture
#

How to find the mail of an user?

#

the module is telling me to find the path to the mail of htb-student over ssh but I don't see any useful information?

viral lotus
#

module: NTLM Relay Attacks - Authentication coercion - Q2: Use Coercer in 'coerce' mode against 172.16.117.60 and submit the name of the first RPC call resulting in the message ERROR_BAD_NETPATH for the SMB named pipe '\PIPE\lsass'.

I ran the tool but I wouldn't get the error message, I am obviously doing something obviously wrong but I have been stuck a while

thank you

viral lotus
#

figured it out

fresh ingot
#

Regarding module OWE Evil Twin Attack:
I think there is a flaw in either the theory, or the target (or in my understanding 😇 of the subject).
The idea is to spin up a 'cloned' fake AP, and do an evil portal attack with nagaw.
The theory clearly states to duplicate essid, bssid, and channel
However, when duplicating the channel as well, this leads to a DoS condition with the legit AP due to all the collisions, and the attack will not succeed.
Switching the fake AP to broadcast on a different CH will lead to instant success.
Can anyone with more experience share their PoV?

waxen totem
#

Of course it'd be very difficult to simulate the exact network especially if there were network services that were in use other than the portal but one good thing to have would be forwarding rules so that your targets could access the internet through your evil-ap (and of course DHCP).

fresh ingot
#

and after like 6-7mins successful connection

waxen totem
fresh ingot
#

but indeed, the fakeAP shows -29 power in airmon, the legit one -47. This explains migration.

#

can i send a DM?

waxen totem
#

I haven't done that module so I can't really help in DMs but in my limited experience, you can vary at least one of the parameters such as the *bssid *to avoid getting deauthed.

fresh ingot
median bolt
#

hey guys

#

how'd you fix it mate?

#

i can't netcat

#

on vpn it says this

#

and this on the box

uneven prism
wide pasture
#

I am kind of stuck in linux fundamentals, it says what is the path of htb-student's mail, but NO ONE HAS A MAIL ADDRESS except root, which I cannot use..!

#
What is the path to the htb-student's mail?
#

But no one has email addresses saved except root (not sure as I don't have priviledge)

median bolt
fierce otter
#

Linux Fundamentals

Introduction to Information Security

Network Foundations

Introduction to Networking

Windows Fundamentals

Web Requests

Introduction to Web Applications

Setting Up

Introduction to Penetration Testing

Pentest in a Nutshell

Vulnerability Assessment

Introduction to Active Directory

Web Fuzzing

Attacking Web Applications with Ffuf

JavaScript Deobfuscation

Using the Metasploit Framework

File Transfers

Getting Started

Intro to Network Traffic Analysis

Android Fundamentals

MacOS Fundamentals

Stack-Based Buffer Overflows on Linux x86

Stack-Based Buffer Overflows on Windows x86

Fundamentals of AI

Applications of AI in InfoSec

Brief Intro to Hardware Attacks

Intro to Academy's Purple Modules

#

that is a right order to finish tier 0 ?

sudden cloud
#

it's the lab in AD > Stacking the deck > Privileged Access

gray yacht
sly kelp
#

Why there are no new modules ?

gray yacht
hardy urchin
#

hello guys, is the "File Upload Attacks" (web pentester path) working for you?

#

for me the upload button isnt doing anything

gray yacht
hardy urchin
gray yacht
hardy urchin
#

if i click on the upload file button nothing opens

hardy urchin
#

Client-Side Validation

gray yacht
hardy urchin
#

thank you

gray yacht
# hardy urchin thank you

I have a green upload button on my end. That isn't the button for adding the file. Click on the grey person in the circle above it. That should launch a pop-up to select a file. Then use the upload button.

hardy urchin
#

ill check and give you feedback

hardy urchin
gray yacht
proper pollen
#

Login Brute Forcing : Web Services
Can someone help me with this please , I am trying to get the user password with medusa with this command " medusa -h <IP> -n <PORT> -u ftpuser -P ./Desktop/rockyou.txt -M ssh -t 30 " but the proccess toke al long time and still cant ind the passwood is this usual ?

gray yacht
proper pollen
gray yacht
cyan veldt
pseudo current
cyan veldt
#

So what I dont get it. It's just a lot of fields

#

It's better to learn the basics then dive into the paths

#

it is not about the difficulty

#

it is just a lot of fields. Would you actually take all those fields?

#

AI, web, binary (if im not mistaken), etc

rain rivet
acoustic owl
rain rivet
fathom pendant
#

that's intended behavior... it first looks for a file with the argument, then tries the name as a word, to get around this use quotes

sudden cloud
#

hey guys, where can I ask questions about the AD module?

acoustic owl
sudden cloud
#

I was told to refain from posting content above tier 0

acoustic owl
#

Ask your question in a way that doesn't reveal any content from the module

#

For example:
I'm working in Module X, Section Y. I'm stuck on the first question. I was able to log in as user Z, but I can't figure out what to do next. Can anyone help me?

sudden cloud
ember veldt
#

Is someone able to sanity check for Model Evaluation (Network Anomaly Detection) - Applications of AI in InfoSec.

Whenever I upload the model I'm getting an 'Internal Server Error'. I've tried both the Pwnbox and my local machine and haven't had any luck. I've been able to upload the other models fine for the other sections, but this one appears to just be giving me a server error.

rustic matrix
#

Hi

opal nexus
#

Hello everyone, I would like a reminder if the principal is still valid - ANY pdf (including not complete report) is considered valid for a second attempt, correct?

restive marsh
#

hello can any one help me

#

i am currently in api attacks Broken Authentication
i try to bruteforce opt but it does not work

leaden island
#

yo guys, im stuck on windows priv esc -> SeImpersonate and SeAssignPrimaryToken
i tried to run printspoofer but it didnt work
im trying to run rougepotato, but i cant get it to work; it requires some setup. ive read articles on it, but still not getting it to work

uncut verge
#

Module: Introduction To Splunk & SPL
Question 2:

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the count of distinct computers accessed by the account name SYSTEM. Enter it as your answer.

My SPL query:

index="main" sourcetype="WinEventLog:Security" EventCode=4624
| stats dc(ComputerName) as Unique_Computers by Account_Name
| sort - Unique_Computers

SYSTEM account is accessed by 0 distinct computers but this answer is incorrect.Time range is set to "All Time" from the drop down menu Can someone please assist?

drifting heron
#

Hello , could someone help me with the Model Deployment Tampering in attacking ai application and system , I've done exactly as the lab says but can't get the flag?

golden drum
#

i have been trying to do this for 3 days

fluid yacht
#

Hello everyone! I was completing the Attacking Common Application's osTicket lab and I tried everything but I cannot get it right. I did what I presume I had to do, I created a ticket, then went to the ticket's thread and registered an account on the osticket's site with the support email address (format is <numbers>@inlanefreight.local), now it told me that an email was sent, but in the thread for the corresponding ticket nothing appeared. The same happened when i tried registering on gitlab. I have a feeling, that the lab has a technical issue at the moment as I also checked the htb lab where we had to exploit the same issue and there it worked. Is there anyone who could confirm to me whether the lab has an issue or I am doing something wrong?

haughty sinew
#

Help needed:
I am doing the pivoting skills assessment. I have pivoted to first one with the credentials found on the web shell. But after that for for 2nd network also mamaged to get creds and pivted to 3rd machine in that there is one more network and i need to get into DC but could not find any solution for that

barren minnow
#

is anyone on that can help me, I am doing the Windows Privilege Escalation Interacting with Users module but it feels like the script for the SCCM_SVC account never runs, I have done all of the steps in the module and all 3 solutions to pull this hash just doesn't work because it looks like the script never runs in the first place

opaque gulch
#

Hello, in the module "Password attacks", I am not being able to transfer the system.save file

#

the other two sam and security are transferred easily but

#

somehow, this file always gets corrupted otw

barren minnow
opaque gulch
#

i used smbserver from impacket

cunning canopy
#

xfreerdp <SNIP> /drive:tf,<HOME DIRECTORY>.

#

Then, in the RDP session, copy sam.save //tsclient/tf/.

spark yacht
haughty sinew
vestal geyser
#

failed to run: This program is blocked by group policy

barren minnow
arctic mason
#

hello, ive been doing the CPTS path- Shells & Payload modules where ive had couple of issues:
First, the laudanum issue where i upload the .aspx file but it does not seem to work weather i edit the file and put my ip or reset my target
Second, in the last file the first thing i noticed was there was an upload dir so, i tried upolading which worked but upon opening it - it doesnt work again as the first issue - 404 so could this be the AV? since the module talked bout removing ASCII letters which i did not- assuming its just a lab or did i stray off somewhere else
In the end i looked at other's posts and found some people used eternalblue based on windows 2016 but at least for me just cause the version is 2016 does not guarantee its 2016 while i did use aux scan later - and figured it is vulnerable indeed

🙂 just need some help with the aspx part

gray yacht
long ferry
#

guys there have kali setup for htb edition !

cloud urchin
#

no, only parrotos

barren minnow
#

Is anyone able to dm about the windows priv esc box, I am having an issue with the user interaction module and it is the only thing keeping me from starting the CPTS test

mental current
#

I wish the Android Fundamentals module can be updated at least for the environment requirement of Android Studio pepehands

fathom forge
#

I just noticed my +60 weeks weekly streak reset, and I don't know why; I've been doing it every week to my knowledge and I as well do not have any streak ending email notifications (first image)

was there an update to how modules' sections get recognized as done? what happened? I was really motivated by it and I would very much want to recover it if possible and it was outside my control

fluid yacht
#

Could anyone help me with the OsTicket lab from attacking common applications? Shouldnt it be just me issuing a ticket, then registering a user with the <number>@inlanefreight.local and get the confirmation email in the thread of the osticket i opened?

gray yacht
topaz locust
#

in API Attack - Broken Authentication / Improper Restriction of Excessive Authentication Attempts
how are we supposed to know the correct format of the thing we brute force?

gray yacht
topaz locust
leaden island
#

yo guys, im on windows priv esc -> windows built in groups section, which is about abusing SeBackupPrivilege.
at first, the privilege is disabled and im supposed to get it enabled.
i transfered the required libraries to import into the powershell session and i got it enabled.
however, im still unable to copy files, even after creating a shadow copy of C: and exposing it as E:

leaden island
icy tangle
#

Hello everyone! I have a question about Linux Fundamentals module Section 18 "Task Scheduling". Why there said that we need to create a directory to store timer file but don't put it there? i can't post an image, i can't find where the button to send it

gray yacht
icy tangle
gray yacht
stray arrow
#

Is it normal that the Targets I spawn often just last 2 minutes and then just don‘t work? Or should I contact support in that case? (Even after resetting and Terminating and Spawning again, it still has a Life of 2 minutes max)

gray yacht
stray arrow
gray yacht
stray arrow
gray yacht
swift dove
#

Anyone has done the Medusa - Bypassing Security Mechanisms by any chance 🙂

#

Hey there, were you able to find all your solution to this module?

barren minnow
#

Has anyone done the Windows Privilege Escalation Interacting with Users module, I am unable to get the SCCM_SVC user to contact me

narrow merlin
quasi wave
#

hi so for the skills assessment for Information Gathering - Web Edition, for question 3, it asks what the hidden admin directory is that I have discovered on the target system. the module didn't cover how to use gobuster or dirbuster I don't think but I tried finalrecon, curl, and nikto and it still won't tell me the hidden admin directory. I am doing it the way I am told to in the module and even also tried multiple variations of finalrecon commands and nikto commands as well as curl -I and it doesn't want to tell me the API key. the problem is it won't tell me the directory on the target system to begin with.

#

can someone help me out here?

swift dove
swift dove
quasi wave
#

hi is anyone available for DM regarding the third question of the skills assessment for the Information Gathering - Web Edition module?

#

I need to DM someone if I give away output I may or may not spoil incidentally

#

I need help with the third question, which is What is the API key in the hidden admin directory that you have discovered on the target system?

#

I can't get the hidden directory to appear to begin with and I don't think the module taught how to use gobuster or dirbuster

#

so unless that's something I'm supposed to look up I don't see it because I tried nikto, finalrecon, AND curl and none of those work

#

please let me know

fathom pendant
vale pulsar
worthy pecan
#

could sum1 help me with an nmap enumeration hard lab been stuck on it a while, im new to cybersec

ancient veldt
#

Anyone who is on AEN or have completed AEN im looking for a little assistance on the dev.inlanefreight.local upload portion

potent pier
rain rivet
#

The file is owned by a particular user, and permissions locked down. It's an attempt to get you to gain access using the 'ALG' service (which if you check the config you will see which account runs this service, and also owns service).

median relic
spare kindle
#

Hi, I am doing an module (Nibbles - Web Footprinting) and I foun that the website http://<ip address>/nibbleblog not working. Anyone else see the same error? Thanks.

halcyon yoke
#

Hi ,
I'm currently working through the Getting Started module on HTB and I'm stuck on one question.

It involves connecting to an SMB share as the user bob, but I’m not sure which password I’m supposed to use. I’ve already tried the following without success:

empty password
admin
password
bob

I also understand the hint says that Bob uses weak passwords, but I’m not sure what else to try or if I’m missing something in the approach.

Could someone point me in the right direction?

Thanks in advance!

rain wyvern
#

i have a question, can I i still acess my completed module and start the academy lab to practice, although my subscription has gone ?

autumn pilot
fathom pendant
vast mica
#

can someone help me, i'm working on footprinting modules and stuck on the DNS section. DM if someone can help me pls!

vast mica
#

i can't find any host with octet ends with "x.x.x.203"

fathom pendant
#

Also seeing your erratum post; look for subdomains of subdomains

cerulean prism
#

I'm looking for a nudge on the Footprinting Lab - Hard. currently feeling like im blocked i thin i've found all the services but im trying to figure out if im going down a rabbit hole of brute forcing

dusk hatch
#

Could anyone give a nudge, i'm at the final skills assessment of the “LLM Output Attacks” module. I can see the type of attack i'm meant to perform and i even get an error message and am able to get past that but now the llm just returns an image "none" instead of the output i hoped for...

cerulean prism
vast mica
fathom pendant
# vast mica I already tried but still stuck😭

take a look at my second suggestion based on what you posted in erratum... you've missed something... a subdomain; for some reason the bruteforcing always misses this but a dig axfr doesn't miss it on the base domain

zealous sandal
#

anyone know why is this happening to me? In the Pwnbox and with my kali with vpn, I can reach the ip or something is wrong

fathom pendant
#

NEI what module is this?

zealous sandal
fathom pendant
#

API attacks skill assessment? Does the question give you an endpoint to start with?

fathom pendant
#

maybe https?

#

i haven't done the module so idk

zealous sandal
#

no, I dont have an active subscription maybe is that?

fathom pendant
#

that would not be it

#

btw that's a public container and port, so it wouldn't require the vpn anyway

potent blade
dusk hatch
faint geode
potent blade
worthy pecan
graceful sand
#

Hi !! I'm on the "Attacking Common Appplication" bloc and my target loses connection every 3 minutes, so I can't do anything because I have to connect to it via RDP. Is this just for me ? (i use the pwnbox not the VPN)

fathom pendant
fathom pendant
worthy pecan
fathom pendant
#

don't share flags

tame sky
worthy pecan
soft mason
#

Hi guys, i am currently facing some problems when trying to start the Skills Assessment - SQL Injection Fundamentals. I am trying to get to the login interface(IP:PORT/login.php) of the application and i am not able to get thru 400 Bad Request error. I tried with and without proxy on Firefox and burp chromium. Is it a issue with the module or i am missing something?

fathom pendant
gray yacht
# zealous sandal

Using /swagger should get you to here: /swagger/index.html, but if that isn't working, you can provide that instead.

onyx halo
#

Hey everyone, could anyone dm about Windows Lateral Movement module SA question 5?
||Trying to: .\SharpWSUS.exe create /payload:"C:\Users\rossy\PSExec64.exe" /args:"-accepteula -d powershell.exe -exec bypass -enc <b64> to Support host which has chisel forwarding internal traffic (revshell) on 443 to my kali.
Tried doing powershell IWR in b64 from backup to support (with nc.exe listening) on ports 443, 8080 as sanity check - nothing. Payload with just PSExec64 and same powershell arguments works from suport to my kali, althought doesn't from support to wsus host (there is probably FW between)
Update is getting in i think on backup since after 10 minutes status says backup accepted it.||

autumn pilot
#

Look at the user context of the reverse shell

scenic stump
#

Question for Academy, I see that I can start it with 60 cubes. How far does that get me assuming that I complete the modules in order to continue getting more to go further? lovethebox

#

Like, do I always make it back + more or is it a slow fade to a paywall? thinkpad

fathom pendant
scenic stump
#

Like can I complete entire modules with just 60? The FAQ says you get more as you complete them but doesnt specify how much. Or will the cost slowly drain you down to a paywall even if you complete everything?

scenic stump
#

"To some extent, yes. Upon registration, we grant you several cubes that help you take the Fundamental modules. What’s more, upon completing each module, you are rewarded with additional cubes that you can use on the next Fundamental level modules. However, if you want to go straight to Easy, Medium, or Hard modules, you will need to buy cubes or purchase a subscription plan."

fathom pendant
#

Look under the - academy cubes - section of the help article

scenic stump
#

"you are rewarded with additional cubes" - No amount

fathom pendant
#

It explicitly gives the break down

scenic stump
#

Maybe Im on the wrong page then.

fathom pendant
#

Its on the page I shared

spark yacht
fathom pendant
#

They provide a table of the breakdown

scenic stump
fathom pendant
#

Just under the paragraph you quoted

scenic stump
fathom pendant
#

Ah nvm you're quoting faq

spark yacht
fathom pendant
#

Which really isnt gonna have all the details

scenic stump
fathom pendant
#

But thats also why I shared the help article