#modules

1 messages Β· Page 488 of 1

autumn pilot
#

that is way better

#

now find the microsoft documentation and search for a cmdlet which will narrow down to the only services which are running

brave kindle
#

This should give the current services that are running

autumn pilot
#

the command is correct

#

now use the hint and go through the output of the command and you will find it

#

please remove the command as others who are doing the module would not want to stumble upon a potential spoiler

brave kindle
#

sorry

autumn pilot
#

dont pipe it to search for an exact name

clever crow
#

Can someone help me?

autumn pilot
#

the key is service

clever crow
#

With this

brave kindle
#

Resolved

tribal fog
#

Hello im new. Currently doing Web Requests module..Stuck at POST section..pls help..i dont understand what to do...
What ive done so far : login as guest:guest, start burp and intercept..sent it to repeater..changed content type header to application/json...wrote json code as follows {"usernam":"guest","password":"guest"}..hit send..get back 302 ok..how do i login to admin..do i need to use curl??..hint says to manipulate cookies..pls help:'(((

tribal fog
lavish glade
#

and then what?

#

uuuuu
How did I write here so everything was decided, how so ??
I've tried this ...

#

thank)))

#

I decided

tribal fog
#

bro ive no idea what this is..i assume its cpied from repeater..im trying out curl functions from the cheatsheet..will post if i find anything

lavish glade
#

I decided

tribal fog
#

curl -H 'Content-Type: application/json' -d '{ "username" : "admin", "password" : "password" }' cURL specify content type

might be useful

lavish glade
clever crow
lavish glade
#

catch cookies and redo them to admin

tribal fog
# clever crow I pressed it but nothing happened

1)open firefox turn on proxy which is an extension on top right
2)open burpsuite, go to proxy tab, intercept on
3)load the page u want to load
4)see some info pop up in intercept tab under proxy tab
5)click anywhere inside the intercept tab and then Ctrl+R or just right click and send to repeater

lavish glade
#

can I write here in Russian?

tribal fog
lavish glade
burnt stone
#

@lavish glade Sorry, we only allow English here.

#

Also, for ease of reading you should put your HTML in a code block

tribal fog
#

@burnt stone pls can u help/guide for the web requests module

burnt stone
#

Sorry, I have not done it.

lavish glade
burnt stone
#

could have just edited the formatting, all good!

lavish glade
tribal fog
#

yes im sorry i still need help with the POST method @mint lava @lavish glade

mint lava
#

have a closer look at the coockie

grave marten
#
console.log("Hi i'm portuguese!")
tribal fog
#

i dont get it maaan..i got the cookie when i sign in as guest:guest..tried to change parameters in burpsuite and send to repeater but response is 200 @mint lava .

mint lava
#

the cookie that you get as guest is in base64 right?

#

so try to think what can you to to login in as admin

tribal fog
#

decoding base 64 gives me guest_7f6d0d7e91747bba926f7..meaning everytime login as guest a cookie is generated which gives the string guest_7f6d0d7e91747bba926f7. I can modify this cookie in order to login as admin but i dont have admin password and i dont know how to modify this cookie and send post request

sick trench
#

I am struggling with Skills Assessment - File Inclusion/Directory Traversal can someone DM me please πŸ™‚

tribal fog
#

ALSO in the tutorial/lesson the cookie param is PHPSESSID whereas when i login as guest the cookie has param auth instead..is this of any significance?

tribal fog
#

YEESSSS I DID IT 😭 thank you soo muc @sick trench @lavish glade

#

AND @mint lava XD

mint lava
#

@sick trench how can I help ?

tribal fog
#

Although the module requires an answer...what should i answer i mean im already in

#

is there a FLAG somewhere im missing?

tribal fog
#

Do i curl to get the flag once im on admin page?

mint lava
#

@tribal fog I just got it form the webpage or form Burp suite

tribal fog
#

ohk got it

#

gonna learn russian soon..thnx mah man @lavish glade

#

πŸ‘

lavish glade
#

=)))

tribal fog
#

i was setting cookie : auth=admin..but instead of admin i had to write the base64 version of it..after sending that to the repeater it gives flag

lavish glade
#

yeeeeeeees

tribal fog
tribal fog
#

so PUT and DELETE module...task is to make flag.php and get it..i made it..but when i use GET /flag.php i get 500 internal error..pls help

#

i cant even DELETE/flag.php

mint lava
#

@tribal fog what is the question?

tribal fog
#

why do i get 500 internal error when i send GET/flag.php to repeater..i should get the flag instead

#

my php script is <?=cat /flag.txt;?>

#

should i instead use '<?=cat /flag.txt;?>'?

#

i removed single quotes

#

@mint lava

mint lava
#

are you trying log poisoning?

tribal fog
#

Create a file named "flag.php" with contents '<?=cat /flag.txt;?>' and request it to get the flag.

#

is what the question says

mint lava
#

can you DM me?

steel venture
#

h

civic jungle
#

I need help with windows fundementals

rustic sage
civic jungle
#

Ok im a student going for my bachelors in cybersecurity i feel very passionate about cybersecurity but no experiance im stuck 0n the RDP section of windows fundementals. Im using and ipad pro for all of this

civic jungle
# rustic sage yes?

Ok im a student going for my bachelors in cybersecurity i feel very passionate about cybersecurity but no experiance im stuck 0n the RDP section of windows fundementals. Im using and ipad pro for all of this

rustic sage
#

hmm

#

i have no idea about it

#

so sry......................

civic jungle
#

Connect via Remote Desktop (RDP) using the following command:

xfreerdp /v: /u:htb-student

#

Where do i enter this at

harsh pine
random swan
#

Need help in Linux fundamental module
What is the path to htb-student home?
I need help

pearl birch
#

FInally, finally, just completed the Nmap Module. I learned tons of good stuffs. Big thank you to the creators of this module.

foggy lake
#

Does anyone here familiar with installing necessary packages to run xerosploit tool on parrot OS !

random swan
#

I try all the possible answer but all of this is incorrect

mint lava
#

@random swan take a closer look on which command returns working directory name.

random swan
#

Pwd

mint lava
#

great

#

@random swan Dm me so we wont spoiler to anyone

fierce warren
#

#modules #774040372966981644 i have no idea what this means srry im dumb "What is the index number of the "sudoers" file in the "/etc" directory?"

tired perch
#

first change the directory

#

then try the ls command

fierce warren
#

ye ive changed to many directorys and i did ls -la

tired perch
#

look at ls --help again

#

look at it carefully

#

index number is also known as inode number

fierce warren
#

where do you think i should cd into bc ive cd'd into alot

tired perch
#

its in the question

fierce warren
#

ik etc but i cant find it

#

its in a diffrent directory

tired perch
#

The command is ||cd /etc||

fierce warren
#

oohhh it was that easy?

#

damnit I always overthink everything

#

||so it said 18467 in sudoers and 18468 in sudoers.d but neither work||

tired perch
#

Have you spawned the target

fierce warren
#

it wasnt a ssh problem it was a in this machine one

#

oohh not yet im an idiot

tired perch
#

after you fix the ssh prob, try the command again.

fierce warren
#

thx

#

i got the number πŸ™‚ *of sudoers *

fierce warren
#

#modules #774040372966981644 so I completed like 4 more challenge things and I now have " Determine what user the ProFTPd server is running under. Submit the username as the answer." and i have no clue what to do

flint moth
#

Check for processes which are running it might help

tribal walrus
#

Can someone help me with the linux fundamental user management module "which option needs to be set to execute a command as a different user using the "su" command " I tried with the --login and other commands but none is working

flint moth
#

Do problem require you to do ssh with target?

tribal walrus
#

No

#

It's like finding which option does what for su

flint moth
#

Read manual for su

fierce warren
#

i still dont understand ....... i did pwd it was just home dir

flint moth
#

Check running process and find proftp

#

Or similar

fierce warren
#

ps aux to check running process?

mint lava
fierce warren
#

ohh nvm i accually got it by doing ps aux

#

i just went through it and found the user ||proftpd||

brave kindle
#

hi guys I am doing Windows Fundamentals: windows security section.
It ask: What non-standard application is running under the current user ? (The answer is case sensitive).
I think I have to find an application that it isn't included in the windows standard application.
I have searched in the task manager but I have no idea what do to do and there isn't a hint.

urban sage
#

You got another piece of info. It's not just non-standard. It's running under the current user. That should help you narrow down the list a bit.

glossy yacht
#

is dpgg online i need help with somethin

#

or any other person online

#

i will ask on medium actually

midnight sable
#

Hello! i'm having troubles with Web Request modules, i tried to change session cookie using base64 and replacing guest--->admin, and i got a new cookie but still is not working. I need to gain admin user login in with guest user. Does anyone has a clue?? sumW

harsh pine
#

If you did everything correctly, ||when enter the page as admin, you should get what you are looking for||

midnight sable
#

Thanks Lanasso, still not working but i'll get it, in a year or two sadglas

heavy pelican
torn iris
tribal walrus
#

Can someone help me with the web services module in linux fundamental "find a way to start a simple http server using npm" and we are to ssh to htb student but the htb student does no have npm Installed I can't understand what I am suppose to do?

tired perch
#

Try to make google your friend...πŸ˜€

tribal walrus
timid grove
#

how do u start a server with the npm ?

#

and then enter the answer without the npm

tribal walrus
timid grove
#

if u want more understanding then yes

#

i install npm on my vm and try all sorts of things

#

till i got it

#

but the answers can also be found in the internet

#

u just have to know what u searching for

flint moth
#

If I remember right we don't really need to install a npm server

delicate urchin
#

im doing this now too lol

delicate urchin
#

.listen maybe?

tribal walrus
#

Ok thanks for the help I'll try to figure it out πŸ‘ πŸ‘

delicate urchin
#

read the hint. no need to specify package name

tribal walrus
#

Nice πŸ‘πŸ€Ÿ I'll try to figure it

tribal walrus
loud dew
#

OMG this was so easy, I was trying to figure it out since yesterday πŸ˜†

rare narwhal
#

Hi all, I am new here so apologies if I am posting to the wrong place. I am stuck on the "Login with the credentials (guest:guest), and try to get to the admin user from what you learned in this section and the previous section." it's going over my head and I seem to be unable to get the cookie as shown in the screenshot on the exercise. Is there any sources i could use to do a bit more reading to get a handle on this concept? or if anyone is will in to ELI5 to me?

tough fjord
#

the example shown is just an example. the web app the exercise on is different - hence the different credentials

#

cookies can have different names

#

look into what the cookie is and what it represents it. if it doesn't look readable maybe it has been encoded, if so decode it or try to with common encoding methods.

#

then look at what happens if you modify the cookie

rare narwhal
#

I'll give it another go a bit later. Thank youfingerguns

low citrus
#

hello

#

am new here

urban sage
#

πŸ‘‹

real cloak
#

Hello people! I'm stuck in a question and I am 200% sure I am in the "good" path of doing it....

#

can anyone give me a hand?

#

The question is: "examine the registers and submit the address of EBP as the answer"

#

so i run into gdb, start the program, look into the frames, and just print $ebp (or info registers)... no luck

low citrus
#

well guess he doesnt need helpcanymore

#

help anymore8

#

**

low citrus
drifting knoll
real cloak
drifting knoll
real cloak
#

tried resetting the machine too

mint lava
real cloak
mint lava
#

Always remember to think outside the box.

real cloak
#

@drifting knoll I didn't even had to open the instance, it was talking about the stack in the theory explanation (but not specifying it...)

#

thanks a lot, own u a beer to both of u! @drifting knoll and @mint lava ❀️

mint lava
#

No problem man, glad I could help

midnight sable
glossy yacht
#

also dm me

midnight sable
glossy yacht
#

i asked cause u said "u would solve in a year or two?"

midnight sable
glossy yacht
#

ight just making sure πŸ‘

midnight sable
# glossy yacht also dm me

sorry, didn't see this!! i used GET and POST methods (both) using responder in burp. POST is the default method and tryied using GET in order to see what was the server response, but i didn't find anything. Also tryied injecting JSON request as in the example, but nothing. That means i am a little bit close hugthebox

glossy yacht
#

no clue why they teach it and has nothing to do with module

vale carbon
#

yo can anyone help me with connecting to a target ssh in linux fundementals

lyric echo
#

hey whatsup Bsteezy

pallid inlet
#

can someone please help me with the question: "Send a GET request to flag.php with two parameters num1 and num2 such that their sum is 1337." ?

harsh pine
urban sage
#

Please don't post direct answers to Academy questions. πŸ™‚

midnight sable
#

Sorry, does somebody knows if Web Request-->PUT and DELETE section is broken? After creating the file and bla bla bla, server returns datetime and a two digits number, it doesn't look like a flag at all. I even tried hashing that info, but got nothing.

harsh pine
brave wigeon
#

i feel like my brain is fried on Linux fundamentals....

rustic sage
brave wigeon
# rustic sage lol. why what happened?

staring at the how many services on target system on all interfaces for awhile now...hoping that if i stare hard enough the answer will jump into my head lol

brave wigeon
brave wigeon
#

is anyone else having trouble with the vm on windows fundamentals. I'm in power shell and its lagging pretty badly

sour otter
#

HI guys i am stuck at this question can anyone help me Use "systemctl" command to list all units of services and submit the unit name with the description "Load AppArmor profiles" as the answer.

#

i use this command systemctl list-units --type=service ANSWER apparmor.service Load AppArmor profiles managed internally by snapd What should i do ?????

brave wigeon
rustic sage
#

any hints on this one ?

#

I am doing everything correct its just not working

autumn pilot
#

try explaining more your methodology rather asking for the asnwer on a x,y,z question

#

you and the others will benefit more

rustic sage
#

I thought I might spoil it for someone

#

I tried

#

and few other combinations

autumn pilot
#

you are almost there

rustic sage
#

do I write whole html ?

autumn pilot
#

nope, just the command

#

look at the eaxmple above and see the structure of how the code is written

rustic sage
#

does formatting of code matter in answers ?

autumn pilot
#

maybe

rustic sage
#

okay I'll try

#

Thanks for your response

sour otter
sour otter
#

Thanks @brave wigeon you guidence really help me with the question i really appericate.

rustic sage
mint lava
#

DM me

fathom nacelle
#

Can someone DM me an approach or even the solution I am stuck at this question for more then 1 week now. - Login with the credentials (guest:guest), and try to get to the admin user from what you learned in this section and the previous section. - I tried "admin" and also "welcome admin", but nothing works.

timid grove
#

can u read the cookie ?

fathom nacelle
#

I dont know if i got it right the cookie tells me Welcome admin

#

but the user is apparently not admin

#

I need to do this with Burpsuite, right?

fathom nacelle
#

@timid grove I dont know, its not working. I am doing something wrong here.

timid grove
acoustic locust
#

How did you manage to reach here? I'm stuck on the same problem for hours now. Any tips would be really helpful.

hybrid dawn
#

For this one, your current directory is /var/www/html. You need to go up one directory level and list out the contents in that directory with linux commands.

acoustic locust
red kernel
#

I am in the 3rd fundamental-module - Linux and I am stuck. I am a beginner

#

When I am doing ssh htb-student@ip

#

This is the question under System Information - Linux

#

ssh: connect to host ip port 22: No route to host

autumn pilot
#

have you spawned the target and are you using the ip from the target

red kernel
#

I am using the ip from the target

autumn pilot
#

and you are using the provided pwnbox, correct?

red kernel
#

in the my workstation area I am trying to do this operartion

red kernel
autumn pilot
#

i can successfully connect to the target from the provided pwnbox instance in the section

#

of the module

red kernel
#

I am also resetting the target

#

shell got opened and a new target ip is getting displayed

#

let me try this one

red kernel
#

Does the target ip expire after some time?

solemn tiger
#

Hey y'all I'm looking for some help on the web request module. When I utilize burp suite and set it to intercept a response, i can't navigate web pages. Problems w/ certificates and the target won't load. When I turn intercept response off the target loads but then I don't know how to get the answer. I am a super beginner and not sure if there is a workaround to getting the response I need for the module.

#

The question I am trying to answer is Send a GET request to flag.php with two parameters num1 and num2 such that their sum is 1337.

pallid inlet
#

@solemn tiger I'm stuck at the same place. I completed Linux Fundamentals on my own so I don't know how to Google.

#

@urban sage I don't want the answer. Just point me in the right direction please.

urban sage
#

Break it down pieces and research how to do them.

pallid inlet
#

Thanks

pallid inlet
#

@urban sage I did it!

#

@solemn tiger You have to do a step before what you posted

brave wigeon
#

after 24 hours i have finally figured out that im stupid and overthinking when using commands such as tree in windows fundamentals..

midnight goblet
#

help pls?

red kernel
#

stuck in Linux Fundamentals

#

This question comes under System Information

#

What is the path to htb-student's mail

#

when I am putting /var/mail it is not taking why ?

delicate urchin
#

wow I am loving the learning process fundamentals course, it's a nice break from all the technical stuff i've been doing. But extremely important and essential. Well done πŸ˜†

midnight goblet
flint moth
#

I will give you a hint ==> Environment @midnight goblet and @red kernel

midnight goblet
#

thks

flint moth
#

@falcaoo you got the answer?

rustic sage
#

eh

visual spade
#

Hey, did you ever resolve this? I get the same error as you did and haven't been able to figure it out.

scarlet shale
#

Hi All, I'm a complete noob and I'm stuck at my first hurdle. I'm working my way through the Windows Fundamentals and i'm stuck on the second question on the introduction page. The question says "Which Windows NT version is installed on the workstation? (i.e Windows X -case sensitive). I have submitted the answers from the commands in the screen shots but it's saying incorrect. Am I missing something? Thanks

frigid canyon
#

i found a bug where is instane terminating itself

scarlet shale
sour otter
#

What is the name of the last modified file in the "/var/backups" directory? guys i am stuck at this question ... i need little help or guidence .

broken obsidian
#

try readin man page of ls

sour otter
#

okay

rustic sage
#

hello people! i have problem with the flag in the Post method question. I managed to login as admin and found the flag but when i try to submit my answer i get the wrong answer message, any i ideas if it is my fault or it is from the website?

gloomy veldt
gloomy veldt
#

okay, I haven't run ssh htb-student@

visual spade
rustic sage
visual spade
visual spade
brave wigeon
#

I hate how some of these are easy enough to make you think its way harder.

brave wigeon
#

Did you ever figure this out?

brave wigeon
#

so when i use Burp suite when trying to figure out the problem for the GET section on web requests its like the internet is dead altogether. is this a result of using Burp?

brave wigeon
red kernel
red kernel
red kernel
#

@flint moth I am extremely new to Linux and my query could sound very idiotic. We use Gmail, Yahoo and other mail types. In Linux the mail that is being discussed here - Q1: Is it a different kind of a mail Q2: Is this same in concept as Windows Outlook mail Q3: Is it possible to access this inbox of mail using a browser or installing a Linux mail application. Q4: How to read the mail because when I am giving the command as sudo less /var/mail/userXYZ

/var/mail/userXYZ: No such file or directory

red kernel
#

Anybody can answer this. It would be great to get a clear explanation of this

midnight goblet
red kernel
flint moth
#

@red kernel I am also a beginning like you , I also have the same question

#

But I could think is this path could be of Linux's Inbuilt mail app or something like that

red kernel
flint moth
#

@red kernel πŸ‘

midnight goblet
visual spade
midnight goblet
#

Which option needs to be set to execute a command as a different user using the "su" command? (long version of the option)

#

help ?

tired perch
#

Try reading the || su --help|| command.

dire stirrup
#

I am doing the web requests module. Cant seem to answer the "Send a GET request to flag.php with two parameters num1 and num2 such that their sum is 1337." question.

#

Not sure what type of format is wants. If it wants the full URI

#

of just the part after the /flag.php.......

#

Have tried multiple variations none have worked so far

#

Nevermind turned out i had to spawn the target system and actually do the command to get a flag from the website.

#

by command I mean the URI

midnight goblet
tired perch
#

The question states to use the long version of the option

#

Type the option without the command

lapis stump
dire stirrup
#

So initially I was typing the entire uri that I thought would work into the answer box. Turns out I had to spawn the website actually send the get request through the website which would then result in a flag

dire stirrup
lapis stump
dire stirrup
steel cave
#

Hey, I'm doing the learning progress module, and for the question I've tried a bunch of variations, and since the answer isn't a fixed thing like a flag I'm not typing in the correct answer, I am, but not the word by word correct one

#

anyone could just tell me what it is?

urban sage
#

Nope. We can't just give you the answer. That kind of defeats the point. Keep trying. You got this.

steel cave
#

I know the anwser. I'm just not typing the word by word thing.

#

I just saw it last night and was like"Oh cool let's read this and answer it"

#

I think I'm answering correctly. but its not the exact combination of words

#

and its annoying the heel out of me

#

*hell

dire stirrup
#

What question are you talking about?

steel cave
#

The only one on the Learning process module

dire stirrup
#

Unfortunately any hint I give will give it away

steel cave
#

Man. Its just that i know what it is. Like something along the lines of: Even the smallest effort everyday makes you evolve way more than not doing anything

dire stirrup
#

See if you can type it another way. Maybe the words are the problen

steel cave
#

exactly

#

i just dont want to spend an hour typing different combinations of words

dire stirrup
#

Your answer is so different to mine that I think we got completely different questions.

steel cave
#

well then i might be completely wrong as well ahahah

#

ill figure it out eventually ig

dire stirrup
#

Might want to delete your previous comment just to be safe and just out of curiosity what is your question

#

Can you copy paste it

steel cave
#

sure

#

To get the cubes back from this module, answer the following question. What is the difference between the two numbers of the learning progress mentioned above?

#

wait

#

am i just looking at this stupidly

#

is it just the actual mathematical difference?

dire stirrup
#

Try it?

steel cave
#

well thanks

#

i shall now think how i ever finished middle school

dire stirrup
#

Yeah was confused when you were trying to use words to answer it

steel cave
#

my brain transcends human stupidity sometimes

dire stirrup
#

Our minds play funny tricks on us sometimes!

steel cave
#

thx for the help

dire stirrup
#

No problem keep at it!

last sluice
#

Hi together

hope that is the right channel...

I am current doing the File Inclusion / Directory Traversal Learnings and I am
struggeling with the path to the php.ini, even with the Hint no chance...
Any hint on that to guide me to the right way?

lapis stump
steel cave
#

it cant all be luck based can it?

urban sage
#

It's not.

mint lava
dawn ice
#

I'm on the Linux Fundamentals Module. "Working with Web Services". I can't install npm on the remote box. I've restarted it with no luck. Any ideas?

htb-student@nixfund:~$ apt install npm
E: Could not open lock file /var/lib/dpkg/lock-frontend - open (13: Permission denied)
E: Unable to acquire the dpkg frontend lock (/var/lib/dpkg/lock-frontend), are you root?
htb-student@nixfund:~$ sudo apt install npm
[sudo] password for htb-student:
htb-student is not in the sudoers file. This incident will be reported.
htb-student@nixfund:~$

autumn pilot
#

try to find the vulnerability spot and once you do ,you will see what you need to put there

flint moth
#

@dawn ice you don't have to install , answer is which command will you use

dawn ice
mint lava
#

@subtle willow have a closer look at the hint and try to do what is explained in this module

brave wigeon
midnight sparrow
#

Hello I want to buy the Linux Privilege Escalation module, but I see that it requires "Networking Fundamentals" and a lot of other modules require this module as well, but I can't find it anywhere in academy

#

How can I get access to the "Networking Fundamentals"??

harsh pine
midnight sparrow
harsh pine
steel cave
#

Hey everyone, I kinda hit a roadblock at Linux fundamentals > Find Files and Directories.
From what I've looked at, my command is working perfectly, but instead of getting a single file, I get a bunch of them with "Permission Denied"
(This applies to the first and second question)
anyone know what is happening? (dont wanna type in the actual command cause, spoilers)

mint lava
#

@steel cave what is the question

steel cave
#

What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?

outer sequoia
#

Not sure if this counts as a spoiler, but you can avoid those "Permission denied" messages by redirecting standard error (stderr) to /dev/null

#

Those messages are part of the standard error (stderr) stream

steel cave
#

ok thx.Ill try that

outer sequoia
#

Np, happy to help

steel cave
#

@outer sequoia Thx so much. u just save a couple of hours of finding commands that wouldnt work until i went to the second page of google

outer sequoia
#

You're welcome! I'm glad it worked, I recently learned this too and it's been very useful

steel cave
#

to think i could have just went to the next module ahahha. 😭

outer sequoia
#

oh lol rip

red kernel
#

Got stuck with this Q: Which option needs to be set to lock a user account using the "usermod" command? (long version of the option)

red kernel
#

I have been able to solve

sonic kayak
#

guys, at the Windows fundamentals, how do i open the powershell at the target desktop?

fathom nacelle
#

Still stuck with this one: Login with the credentials (guest:guest), and try to get to the admin user from what you learned in this section and the previous section.

#

Can someone please help me!

fathom nacelle
#

No one?

mossy oasis
#

Hello, can someone help me with HTML Injection, I can't get any further with the question. I hope someone can help me here. The question is " If you wanted to inject a malicious link to "www.malicious.com", and have the clickable text read 'Click Me', how would you do that?". What do I have to do? thanks in advance

fathom nacelle
#

BUMP!

flint moth
#

Can we do practice on our own machine instead of HTB Virtual box?

mint lava
urban sage
autumn pilot
loud dew
lapis stump
gleaming oar
#

Someone that helps me with the question of learning process

autumn pilot
#

Ask your question

#

your question has nothing to do with the topic of the channel

red kernel
#

I am stuck with this question Q: Which option needs to be set to execute a command as a different user using the "su" command? (long version of the option). As answer when I am giving -user or -username the system is not accepting. What is my mistake

plucky nimbus
#

Can someone help me with Web Requests and the POST Method, I found whats wrong but i think im doing something wrong
@me or pm me

lapis stump
red kernel
lapis stump
plucky nimbus
#

Can i pm you? @lapis stump

lapis stump
forest marsh
#

guys

#

are we hacking this box

#

fuck

tulip locust
#

What do i do in this server

lapis stump
# red kernel It is coming under Linux Management - User Management - Q3

Ok, as far as I see it is Linux fundamentals/User Management/3rd cube. if it does not accept your current answers maybe you should try another one, you can document yourself on the internet, analyze the question well and try not to post answers here because they can delete the questions because it has already happened to me.πŸ‘

midnight goblet
#

hlp?

mint lava
midnight goblet
#

Which option needs to be set to execute a command as a different user using the "su" command? (long version of the option)

midnight goblet
mint lava
# midnight goblet -

try to use man su or su -h, its pretty straight forward and easy to find it there

midnight goblet
#

i have tried

#

i tried al the commands

autumn pilot
#

its not only about trying but understanding

mint lava
#

the long version?

midnight goblet
#

yes

mint lava
midnight goblet
#

yes

mint lava
hexed jacinth
#

Hi, im new in the server and i'm not american also british, so sorry by the spelling mistakes, but, can someone help me where I can find somone to teach me better about simple code and this type of thing, IΒ΄m new in that too kk.

tired perch
#

Can someone help me in the web request module for the GET method, i am not sure if i am doing it wrongly or is it the system

#

I tried to follow along the example steps given and it was not the same/ and i had some errors

brave wigeon
#

ok so on javascript deobfuscation when i try to visit the target ip and port its like its dead...

dire stirrup
#

@tired perch I just finished that module PM me and ill see what your problem is about

tired perch
#

ok

loud dew
neon onyx
#

I need your halp "Which kernel version is installed on the system? (Format: 1.22.3)"?

#

Have you found a solution to your problems?

keen whale
#

Hi how do we hack

#

I'm new here call me Sniper

cerulean ridge
#

it's important to start with the basics so academy is definitely a great start

#

you can do the tier 0 courses for free

keen whale
#

thank you

brave wigeon
#

@loud dew ok ill readjust and loom at it thanks!

inner falcon
#

In Software fault isolation techniques a process’s virtual address space is divided into multiple segments to ensure security. One such segment ranges 0xfeee0000H to 0xfeeeffffH. Which of the following instructions that are used to access the memory can be unsafe?

I. JMP *ebx
II. MOV r0, ffee1200H; Load [r0]
III. MOV r1, feee1200H; Load [r1]
IV. INT $0x80

vestal moon
#

how do i " SSH to {IP} with user {username} and password {password}"

#

--linux fundamentals

#

nvm

dim herald
#

ssh username@ip

vestal moon
#

ye i Googled it

#

thx tho

last sluice
#

im struck with Firewall and IDS/IPS Evasion - Hard Lab. done both udp and tcp scan with version.
Found 3 Porta but struggeling.
any hint?

drifting knoll
crimson sand
#

Hey all - I have a question on the SQL Injection Fundamentals -> SQL Operators section...

#

The problem reads in a certain table, what is the number of records WHERE the employee number is greater than 200000 OR their title does not contain 'engineer'...

#

I have laid out my query in about 20 different ways but no matter what number I get, I'm getting the wrong answer.

#

NVM - I had to include ALL instances of the string 'Engineer', not just the title of "Engineer"...

brave igloo
#

question on the HTTP module - the part we you have manipulate the cookie using POST

surreal rain
#

What is your question?

brave igloo
#

1 - The method described to replicate the escalation to admin is not very clear to me.
2 - when I refresh, I removed the cookie header and i get the 302, to the login, then I do the CTRL+Z to add the cookie header back. It still shows that I am the guess

#

(all done using Burp)

#

any ideas?

brave igloo
#

never mind I was able to figure it out

jaunty vortex
#

"How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)"

#

can someone help me? i tried this but the answer is not correct

flint moth
#

Can someone help me in Filtering result of Ffuf module , I am not getting any result after scan

loud dew
brave igloo
#

sure

neon onyx
sand arrow
#

Anyone completed Java script Deofuscation(page 9)

#

i'm stuck at the moment

true whale
#

@sand arrow what are you stuck on

#

if you want to pm me i can give some hints

sand arrow
#

@true whale I already got the decoded output but I dont know what they mean by"set the data as "serial=YOUR_DECODED_OUTPUT".

true whale
#

ok look at the cheat cheat and see how you can pass data into a post request. so you will want to do the same post request you did before but add data to it. if you need anymore help dm me.

sand arrow
#

Alright im going to test that out thank you

true whale
#

no problem!

sand arrow
#

I dont know why but my Instance is not starting?

#

@true whale Is HTB like THM where you can only get the VM a hour a day if you dont have a Subscription?

true whale
#

no you should have unlimited access to the workstations. i would try closing and reopeing your browser.

sand arrow
#

I got the same error

true whale
#

huh what dose it say.

sand arrow
true whale
#

huh ive never seen that before on the dashboard theres a support option you could try asking there.

sand arrow
#

alr

true whale
#

i just tried and got the same error. they must have a overflow of users atm.

sand arrow
#

Yeah, I'm probably going to come back later

loud dew
#

same here 😩

lyric echo
loud dew
#

πŸ’©

patent bison
#

i am gettin same error

midnight sable
#

me too

#

trying with VPN

loud dew
midnight sable
#

f*c

flint moth
#

Can someone help me in Filtering result of Ffuf module , I am not getting any result after scan

loud dew
#

it`s working again πŸ‘

patent bison
#

let's go!!

loud dew
#

Any ideas why I can`t submit the flag on web requests - Post Method??
Nevermind all sorted now

arctic horizon
#

Can anyone help with this? "Which option needs to be set to execute a command as a different user using the "su" command? (long version of the option)"

craggy kettle
#

Anyone can help me I'm in the Linux Fundamentals - Working with Web Services and in the lecture you install apache2 using apt install apache2 -y and then open localhost to see the default apache page but my service appears as inactive (dead) and when I tried to start or restart the service it just fails.

Tried a few things like looking up the syntax and its fine also created a log folder

And I'm getting this error for both start and restart
Job for apache2.service failed because the control process exited with error code.
See "systemctl status apache2.service" and "journalctl -xe" for details.

novel matrix
#

@cerulean vine

cerulean vine
#

thank you man that helped me

#

hello does anyone know about web requests?

#

Hi all, I am currently pretty bad stuck at following exercise: Web Requests - GET METHOD - Send a GET request to flag.php with two parameters num1 and num2 such that their sum is 1337. I dont really understand what it wants to know from me as I already tried following things. Burping it via Browser on: Send a GET request to flag.php with two parameters num1 and num2 such that their sum is 1337 and also with cUrl which tells me 401. Unauthorized. Can someone please point me in the right direction of what exactly needs to be done. Thanks in advance for any help. P.S. For the sake of the overview I would really prefer a DM. Thank you! P.S.S Its a copied message but i need help

dusky walrus
#

SQL server isnt really responding to any commands in the starting point box, any clues?

inner sapphire
#

hii

oak moss
#

hello everyone

#

How are you

thin gull
#

Hey all, I'm at the Web Request Module - POST Method, I'm trying to get the flag to answer the question. I've manipulated the cookie at the /admin/dashboard.php request and the system is greeting me as admin_... BUT i can't find the flag. Am I missing something?

rustic sage
#

hi folks, I'm working on fundamentals - web requests, and I'm stuck at POST request - I logged in as guest, and modified cookie to admin value, and the site greets me as admin, but no flag (I'm guessing that a flag should be there). I tried json method shown in the course text, but no success... Could you nudge me in the right direction? I'm using ZAP, and I'm using burp provided in the course machine, but the result is the same. Any hints?

mint lava
rustic sage
#

@mint lava gawddammnit πŸ™‚ had to see it in python πŸ™‚

#

Thank you

thin gull
mint lava
#

@thin gull @rustic sage No problem

dapper raven
#

hi

#

anyone down to teach me?

ancient elk
#

Hello!

urban sage
ancient elk
#

I need help on this question: πŸ‘‰ Which kernel version is installed on the system? (Format: 1.22.3)

#

I have used the command uname -r and uname -v but both results 5.5.0-1 and 5.5.17-1 are incorrect. PLZ help!

urban sage
feral halo
#

If anyone is lost at Windows Fundamentals > Introduction to Windows, use the program Remmina. Also just enter the target IP you get, the command used in the example didn't work for me but only entering the IP does the trick

chilly scarab
#

I get a blank page when I GET the flag.php file on the Web Requests module on HTB Academy. What am I doing wrong?

flat oxide
#

Can anyone point me how to complete the firewall evasion hard lab? Upto now i was able to get the port, but when enumerating the service version i see its tcpwrapped. Also i am unable to connect to it using ncat with the source port option.
Please help as i have been stuck on it quite a while.

brazen spoke
brazen spoke
night ember
#

hey i'm stuck on FILE TRANSFERS module

#

in the section windows file trensfer method

#

at the second question

#

i don't know how to upload the file

#

i tried this

#

but i got http 403 error

#

anyone?

cerulean vine
cerulean vine
# night ember

curl -X PUT -d @test.txt http://<url> -vv i just saw this on the cheat list

mint lava
bitter citrus
#

sa

night ember
cerulean vine
#

it is port 80

west quarry
#

Are There Any Turkish Members

cerulean vine
#

443 is https

west quarry
#

TΓΌrk varmΔ±

flint moth
#

Can someone help me with Get - parameter Fuzzing !!! Please

dapper raven
#

i signed up for it

#

@urban sage thank u just signed up whats next

urban sage
#

Check out the Intro to Academy and Learning Process Modules.

dapper raven
#

anyone know how to hack 1v1.lol

bright stirrup
#

Hi guys I'm going through enmap Service Enumeration and could solve the question for more than two hours :0 for some reason I can't connect to any of the scanned ports

bright stirrup
#

tcpdump doesnt capture anything when I try to connect ot the specific port or even when I run command like this one sudo nmap [IP] -p- -sV -Pn -n --disable-arp-ping --packet-trace

#

this is the command I run for it sudo tcpdump -i eth0 host [IP]

#

in two separate consoles

mint lava
#

are you using the ip of the instance box?

#

as the host of the sudo tcpdump

bright stirrup
#

target IP

mint lava
#

and did you manually connect to the SMTP server using nc

#

as the modules explains?

bright stirrup
#

the thing is there is no any smpt services has been found after a scan

#

PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.10 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
110/tcp open pop3 Dovecot pop3d
139/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
143/tcp open imap Dovecot imapd
445/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
31337/tcp open Elite?

mint lava
#

so the port is closed

#

why are you trying tcpdump in the first place?

bright stirrup
#

at the and of this page I have a question (Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer.)

#

so I wanna check the flag

mint lava
#

DM so we wont spolier anyone

dusky glade
#

guys i need help I can't understand what it means with : What is the name of the hidden "history" file in the htb-user's home directory?

#

i've tried any command

#

all*

flint moth
#

I don't remember exactly but I guess that file could be hidden in home directory

loud dew
#

Good luck and see you in the Easy ModulesπŸ‘

mystic sentinel
#

can any one help me with this please>?? can i use the above command to do the following """ What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?

#

nvm i solved it. thkns

regal cove
#

it is required/recommended to do all fundamental modules before diving to Labs?

lofty ingot
#

hi yall ive been struggling for a while with this question

#

Which Windows NT version is installed on the workstation? (i.e. Windows X - case sensitive)

#

like ive been trying all the cmdlets and yet the answers still wrong

gleaming sedge
fluid charm
north oar
#

why i can't ssh?

#

i try many times and same result

loud dew
north oar
#

yes

#

done

jolly bough
#

In the linux fundamentals you get asked to find the kernel version i do the uname -r to get the version and it give me the wrong answer, i have tired every possible way i can think off and google to none of them working. Also next question is "which MTU is set to 1500" - there's multiple MTU's set to 1500 none of these are the correct answer i used ifconfig to find the MTU. Any ideas what im doing wrong?

visual spade
jolly bough
#

the format is not making any sense to me

visual spade
#

Ok. What answer does uname -r give you?

loud dew
#

Who is on the modules tonight?

tepid apex
#

hi just wondering what the answer is to the web request module where you have to elevate from guest to admin, because i did it, got to admin panel by changing the cookie value....

green mason
#

@tepid apex dm me

jolly bough
visual spade
jolly bough
#

nvm

#

i figured it out

visual spade
#

Good

jolly bough
#

Just gotta read the question properly.. thx alot tho

visual spade
#

np

rustic sage
#

can some one help me one this one

north oar
#

a bit help?

loud dew
lyric iris
#

All,

lyric iris
#

Hey, how do you paste images in this channel? My message bar doesn't have the plus sign to add files

lyric iris
#

Nvm. Apparently i was filtering "-name *.config" when i should have filtered "-name *.conf" so dumb...i wish the Academy lesson would have indicated that .config and .conf are configuration files that exist

cerulean vine
#

guys can someone help me with the javascript deobfuscation

loud dew
gleaming oar
#

Can someone help me with a question?

loud dew
gleaming oar
#

I have to send a get request to flag.php with parameters num1 and num1 and their sum has to be 1337

loud dew
gleaming oar
#

When I come back to desencript base 64 it doesn't appear the admin password

rustic sage
#

can some one help

ivory bough
#

Maybe ? what do you need!

rustic sage
#

i am one Linux fundamentals

#

the question is What is the path to htb-student's home directory?

autumn pilot
#

Don't just seek for the answers, try to formulate a logical question or methodology

ivory bough
#

agree

autumn pilot
#

it will take less than a second to give you the correct answer, but what will you learn from it

ivory bough
#

I havenΒ΄t done that module but, is there any command that might help..?

rustic sage
#

i tried to switch the ssh but when i put the ip that it gives me it takes me to a different user

autumn pilot
#

you have to ssh into the given target

rustic sage
#

thats what i did but when i put the password that they give me it dose not work

tranquil epoch
#

hello i have a question, im trying the command: find /etc/ -name *.conf 2>/dev/null | grep systemd | wc -l, to get all .log files in the system but always returns 0

autumn pilot
#

the password is between the double quotes

rustic sage
#

when i put the target instead of the user being htb-student it is user64304@

tranquil epoch
#

you have to ssh htb-student@ipofthe server

autumn pilot
#

have you gotten the first two answers @rustic sage

rustic sage
#

there was one question but i got that one

#

it was Find out the machine hardware name

autumn pilot
#

it requires to ssh in the target

#

if you have done that steps successfully you can proceed with the others

rustic sage
#

SSH to 10.129.185.187 with user "htb-student" and password "HTB_@cademy_stdnt

#

but when i put the target 10.129.185.187 it say user 64304@

#

instead of htb-student

tranquil epoch
rustic sage
#

i dont know

#

thats what it was thanks

tranquil epoch
#

np

rustic sage
#

how would i find the path to the htb-student's mail

loud dew
rustic sage
#

i am new to this so i have no clue what that means

tranquil epoch
tranquil epoch
loud dew
rustic sage
#

i need help

loud dew
rustic sage
#

no one answered my question

unborn obsidian
#

Im trying to do Web Requests, im on page 6 and i need to make a request to http://inlanefreight.com but its a normal website when the academy shows it should ask for a password.

lyric iris
#

Anyone completed Linux Fundamentals - Filter Contents? I'm currently on the questions and they're pretty nasty

#

First question reads: "How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)"

#

Any help or pointers would pretty stellar!

keen whale
#

Hi, how do I do the invite challenge in Hack The Box , can you hack this box?

#

Can you guys teach me

tough fjord
#

++academy

red obsidianBOT
tough fjord
#

Do the cracking into hackthebox path

keen whale
#

Thank you and noted

wanton knot
#

Hello, I've tried this for some time, but now i'm not sure what it asks for. I get the services running on host on powershell, but i cant find which one I need to enter

open sable
#

Hello new here as well, going through linux fundamentals

open sable
#

Currently going through linux fundementals: find files and directories

#

having trouble with the first question finding a file in config with a certain time created and is smaller than 28k but larger than 25k

#

I thought I found the file as it fulfills those requirements but it is rejecting my answer.

#

got it

quiet depot
#

How many total packages are installed on the target system?
I run:

dpkg-query -l | wc -l

But the answer is incorrect. What's wrong?

visual spade
quiet depot
#

sry

wanton knot
#

i did, there's one that pops up, but when i type the name in (not the display name), it's not right

open sable
#

I got that one thank you Vos

#

Currently on how to find all files with .log extension in the system

#

having trouble figuring out the right command

quiet depot
open sable
#

How many files exist on the system that have the ".log" file extension?

quiet depot
#

(I don't want to make spoilers, we are all learning here)

open sable
#

corret and thank you

quiet depot
#

Briefly read man find

open sable
#

will do

#

can you use grep for file extensions or just file names?

#

This is what I am using now with 0 results

#

What module is that aquas?

#

!rank

wanton knot
open sable
#

Nice. is the instance that runs one with windows on it instead of linux?

wanton knot
#

instance is linux

dim herald
#

omfg im having a hell of as time finding the kernal ver Linux Fundamentals i see the format its asking for and im pretty its parrot 5.5.17 any direction??

autumn pilot
#

make sure that you have ssh'ed in the target

dim herald
#

oh yeah thats right i came back to this module so i right thx ill try

pallid reef
#

Greetings all. If someone could give me a hint I'd appreciate it. I'm on the question "What is the path to the htb-student's mail?" located under the System Information portion of the Linux Fundamentals module. I can see where the mail directory is located but that isn't the answer. I'm SSHd in. Thanks πŸ™‚

drifting knoll
worn kite
#

Hello guys, I am new to HTB, but I have been enjoying it.. Im stuck on this question right now, you can find it in the web requests module under the POST method section, I have literally tried everything, but I cant seem to figure out how to solve it. The hint says that I have to use the information from the previous section, but I also cant manage to find anything helpful there. If someone could help me out, it would be appreciated.. (btw, I dont need a huge explanation, but just a hint or at least some instructions on what to do)..

#

Oh, this might be handy to know, in the cookie header, I dont get a 'PHPSESSID', but it just says 'auth'. I dont know if this prevents me from finding the solution, but I figured it might be handy to add real quick..

pallid reef
drifting knoll
drifting knoll
cerulean vine
#

can someone help me please

tired perch
#

Hey guys, can someone help me in this question ||" Find the non-standard directory in the C drive. Submit the contents of the flag file saved in this directory"||, i have already ssh into the machine

urban sage
#

Find the folder that isn't there by default.

tired perch
#

I am not really sure with the commands though..

smoky yarrow
#

HI, I'm new to Hack the Box and have less experience in penetration testing. Unfortunately, I don't know whether I have the necessary skills or knowledge to solve the challenges posed. Can you give me tips what I should can / know?

rustic sage
#

Hi everyone I'm stucked on the POST requests section of the web request module, I've tried everything that I thought of but I still can't get the admin privileges

jolly yacht
#

?

#

bro how to use this app

#

?

#

im stuck

pallid reef
#

Good morning/day all. I'm on the question, "Use "systemctl" command to list all units of services and submit the unit name with the description "Load AppArmor profiles" as the answer." I have all services showing, and the unit name for the answer. Apparently it's not that service name because it's wrong. Any pointers?

#

oh wait I'm assuming I need to tunnel into the target box then do it there I'll try that real quick

#

wait ok no lol I'm stuck I suppose, thanks in advance for any hints

#

oh ok I was right the first time about being SSHd in, nvm!

bright stirrup
#

may I speak with someone about brute force module?

rustic sage
rustic sage
bright stirrup
#

is any admin here?

autumn pilot
#

what is the issue

bright stirrup
#

I got a question about brute force module Skill assesment - website I would like to make sure that I'm doing everything right

#

cause I couldn't brute force the login param for the second part of the assesment and maybe I gor some wrong params

rustic sage
#

I don't do the acedemy stuff

#

are you trying to brute force a hash

#

a common tool is hashcat

#

oh login brute forcing

#

then it's not hashcat

bright stirrup
#

Im using hydra

rustic sage
#

try using the wordlist in hydra

#

in weak passwords, there are common words

#

like for example "shadowpotato"

#

if you don't use a wordlist, you'd end up using random combinations like "38JF##88fn3!ffe"

#

@bright stirrup

#

that's the best I can help

#

cause I don't use the academy

bright stirrup
#

I use list of common passwords but the thing is that it takes ages πŸ™‚

rustic sage
#

are you trying to crack a hash

#

or is it remote authentication

#

well anyways the lesson instructions tell you to attack with a wordlist

#

good luck

bright stirrup
#

it's remote authentication, the thing is that non of the passwords from the wordlist was right, anyway thank you

last sluice
#

I am doing the sql Injection Fundamentals, any hint with the id 5 login?

mint lava
blissful verge
#

Hey everyone, if you haven’t seen yet we released a new module β€œIntroduction to Networking” first in a series of networking related modules that will be released at a later date. Thanks to ippsec it’ll have you subnetting in your head like a pro in no time!

digital hornet
#

Hi everyone, I got a basic question about linux fundamental. When I try to ssh into the target (ssh htb-student@ip) and put the password (no typo error) I can't access to the server : "Permission denied (publickey, password)". Is that related to publickey ?

mint lava
digital hornet
west coyote
#

hi, i was doing the "windows fundamentals" module and i got stuck at "Windows Services & Processes"

#

i have looked the services around 10 times already

#

through powershell

#

cmd

#

task manager

#

looked the hint

#

and the only thing that seemed to me like the solution wasnt it

#

ps: i didnt use the display name

#

πŸ₯²

wanton knot
#

im also stuck in this for days

west coyote
#

you still are? xd

wanton knot
#

yea, not sure what im looking for anymore

west coyote
#

despair

#

the funny thing is

#

"ok let's just look the hint"

#

"related to a pdf editor?"

#

sees the name of the same service i've been inserting

#

and it still isnt it

wanton knot
#

my experience exactly

rose barn
#

did you manage to solve it?

wanton knot
#

i sure didn't

mint lava
#

@wanton knot @west coyote well guys the answer need to include service name and .exe

vast siren
#

I stuck at linux fundamentals, filter contents , i cant find the no of services listening, i tried ps -aux , ufw , netstat, what m doing wrong?

slim flicker
#

"Why did a porn scan originate from the printer network?" What is this printer scanning for pika

mint lava
west coyote
#

oh

#

thanks xd

#

oh well at least that problem is over XD

mint lava
#

@wanton knot happy to help

bright stirrup
#

hi guys could somebody help me to finish brute force academy task, could ind proper login credentials for the second day πŸ™‚

rustic sage
#

hello there is somebody spanish language in this module

bright stirrup
#

guys did somebody complete brute forcing module?

frigid dagger
#

Hello everyone, I was wondering if someone could give me a nudge in the right direction on the "Web Requests" module, POST section?

small sand
#

So how to start hacking

ivory bough
#

Hello!
I am a stuck on the "Working with web services" module, it says to start it with npm but not to install npm..

#

I feel like I am missing smth on the instructions but I am not quite sure

fading briar
#

Hey y’all. I am working on the web requests module, stuck on the GET method. Could someone point me in the right direction?

ivory bough
#

Or with what do you have doubt*?

fading briar
#

@ivory bough I think I got the answer right to the question, but maybe my syntax is slightly off and I can’t seem to get past it. I can PM what I put down.

ivory bough
#

What do you mean with PM?

fading briar
ivory bough
#

aahh yess sorry

#

Write mee

#

I didnΒ΄t know the abbreviation sorry

sick trench
#

anybody about to give me a bit of help with the last question on Skills Assessment - Web Fuzzing?

vast siren
ivory bough
vast siren
#

yeah? Where u at?

ivory bough
#

Starting Find Files and directories

vast siren
#

Hurry up, thenπŸ˜‹

ivory bough
#

I will try πŸ˜„

vast siren
#

πŸ‘

thin bloom
frigid dagger
#

Are you wondering how to get to the modules on HTB Academy?

novel matrix
red obsidianBOT
tame blade
#

Stuck on POST Method 😦

frigid dagger
#

For Web Requests?

tame blade
#

Yea

frigid dagger
#

Same

tame blade
#

Able to login to the admin account from the guest guest but I'm assuming a flag is supposed to show up but doesn't

#

One of the times I did it I saw something different but my target timed out not sure if that was the issue.

frigid dagger
#

I am actually stuck in the escalation portion just before that. I think I'm improperly using Burp.

tame blade
#

What step are you at?

#

PM me real quick

small sand
#

need help at something

#

Based on the commands you executed, what is likely to be the operating system flavor of this instance?

#

im stuck at this question

tame blade
#

Halp

tame blade
#

Anyone on?

west rampart
#

Where you stuck?

small sand
#

in the question i dont know the answer

tame blade
#

I'm stuck on the Web Requests POST. I'm still trying though.

#

Like 8 hours I've been scratching my head. Only hint I have is there is a difference in the HTML code.

#

Don't think that's right though.

west rampart
#

@tame blade @small sand DM me

sick trench
#

anybody about to give me a bit of help with the last question on Skills Assessment - Web Fuzzing?

fleet charm
#

oi

#

im the newbie here

#

where should i start?

rustic sage
fleet charm
#

ok this is fun

rustic sage
#

good luck!

fleet charm
#

thank you

timid grove
#

@sick trench DM

fleet charm
#

hell man should i use linux console?

#

ok i did what now?

#

and from now on im the greatest noob(lol)

potent wharf
#

Just completed the Java Obfuscation module on the academy, I actually didnt use any hints and just took my time and worked through the questions, I did have to reference back a few times to the material, going to do the Intro to Web Apps next, im doing these in a view to getting into Bug Bounty's is this a good track? any advice?

flint moth
#

@sick trench did you find the link of page

cerulean vine
#

Hi everyone! I'm noob on Hack The Box and I am doing the Linux Fundamentals module, and I'm stuck on chapter "Find files and directories"... On first question "What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?", I already got the file but I don't know what is the name that the question refers... I already answer the path of file and the "something".conf, and my answer is always wrong. Someone help, please?

gusty solar
red obsidianBOT
cerulean vine
red obsidianBOT
gusty solar
#

can any one tell me..academy.hackthebox.eu is free or paid

vital yew
mint lava
rustic sage
#

hi guys, can someone help me with file transfer module? I don't know how to download archive to pwnbx(

crimson sand
#

Stuck on the very start of the SQLi Fundamentals "Skills Assessment"... Any nudge welcome...

#

Like, really...

crimson sand
#

I can’t seem to get past the login... I’m not sure if it’s typos, or I am over thinking it (like I have a few exercises).

mint lava
sinful jetty
#

hey guys, would this be the place I can ask a question regarding the Linux fundamentals module?

#

I can't seem to get the path to the htb-student's mail.

zinc egret
#

How do I get back to the modules portal? I seem to have lost my way 😫

subtle olive
#

Hi! I'm a noob. Can you give advice on where I should start? Should I finish all fundamental modules first then move to easy? Or do you know a good module or lab or box that's good for beginners?

ivory bough
#

Hi, canI get some advise with the Working with web services 'npm' question ?
I've been stuck with it for so long and I have no clue

lyric iris
#

@ivory bough I recommend googling npm commands that involve "http server"

#

@ivory bough it's likely that you will need to use additional options to fulfill the questions requirements

ivory bough
#

Thanks a lot!

lyric iris
#

you bet

rustic sage
#

Hacking the WordPress, anyone wanna team up? Im on skill assessment rn

oak obsidian
rustic sage
#

@oak obsidian ill message you

oak obsidian
#

sure

rustic sage
#

Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.

I have every question from WordPress assessment, found the vulnerable plugin, but I have no idea what file im supposed to download.

smoky yarrow
#

Hey, can somebody help me? Iβ€˜m stuck by a question on in the Windows Fundamentals course.
The Question is β€žIdentify one of the non-standard update services running on the host. Submit the full name of the service executable (not the Display Name) as your answer. What should I do ??

autumn pilot
#

Read the hint and go through the processes

smoky yarrow
#

i did read the hind, but i have no idea what i have to do now

autumn pilot
#

There are couple of ways that you can use, one is explained in the section of the module

smoky yarrow
#

ok, thank you

urban sage
#

Deleted the message because of spoilers. Do some googling. :D

thin bloom
#

Oh

#

But I need help

urban sage
#

You got this. Do some googing. Based on the others that you answered you should be able to figure out this one. It isn't that different from what I can see.

fallen plover
#

Im having some issues with the GET method in the web request module

#

I think the problem is the second parameter is wrong

#

when I put in what I have now, I get "Parameters not found[1]+ done" and then it gives me an altered version of my imput. Instead of num1=1000&num2=337 at the end, it just gives me num1=1000

#

If I delete everything after the &, I get the same responce, but if I delete the actual &, it says to parameters found

tired perch
#

Dm me bro

wanton knot
#

add .exe

robust bough
#

that doesn't seem to work :

#

:(

wanton knot
#

hm not sure then, i had the same problem, and it worked, it needed name.exe

#

i believe so

robust bough
#

@wanton knot thanks so much, i got it to work! :)

rustic sage
#

hi!

astral cloak
#

Good day everyone, can someone please tell me what's the packages file extension or where to look for them in "Linux Fundementals - file descriptors and redirections"

#

Its a ridiculous question, but I can't find the quantity of files in the system

#

Help would be appreciated ❀️

marsh echo
#

Hello the community, I wanted to know if anyone can give me the answer for the last question of the learning process module so that I move on please. I've tried answers before but I don't know if it's a word to insert or a sentence :/

astral cloak
#

Click on hint ☺️

#

The answer is there

#

@marsh echo

halcyon sphinx
#

Is anyone else seeing that the time left on the target machines is drastically shorter than listed? I keep spawning target machines for the 90 minute limit, and they drop down to 20 minutes left after only 15 minutes have elapsed...

marsh echo
rustic sage
#

Some I can DM to help me ?? Working with Webservice

#

Someone ****

#

at Linux Fundamental

loud dew
#

has anyone recently done ffuf module?

flint moth
#

@loud dew yes I have done that

modern hill
#

Has anyone actually done the Working with Web Servers part of the Linux Fundamentals? Because neither the npm nor the php question work for me

flint moth
#

do someone knows how to use VPN key in my linux?

rancid yew
astral cloak
#

That’s how I figured it out

tropic latch
#

yeah,

#

I Feel like they should put npm into the instance

rancid yew
#

I almost took 7hrs to figure out the solution πŸ€¦β€β™‚οΈ

modern hill
#

I figured it out, but it took longer to answer those 2 questions than it did to answer all the other ones

astral cloak
#

Same

#

U should get used to it, bcs when u one day complete all modules u won’t have any assistance nor hints, so get familiar w doing researchs from time to time

rustic sage
#

@Bineeth I have it!! Thnks

wraith walrus
#

hi

#

guys i am stuck at this

#

β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’

#

Find a way to start a simple HTTP server using "npm". Submit the command that starts the web server on port 8080 (use the short argument to specify the port number).

feral kettle
#

Hello can someone help me please?
I'm trying to install windows exploit suggester, but get this error:

please install and upgrade the python-xlrd library

last sluice
#

Need help about the last question on Skills Assessment - Web Fuzzing, could anybody help me?

rancid yew
vital yew
#

can anyone give me a hint ...im stucking with "Skills Assessment - File Inclusion/Directory Traversal"

mint lava
devout crown
#

Hi! Someone can dm me for the sqli skill assessment?

#

I need a very little help (I think)

mint lava
rustic sage
#

I've completed the Web Requests > POST Method activity (changing from guest to admin) ... but I cant work out what gets put in the "submit your answer here" box... can anyone advise?

I have "welcome, admin..." in the server response but is it likely that I have missed something?

twilit sphinx
#

Good night guys

#

Could you help me with web requests ?

#

I'm in the post method, page 7

mint lava
rustic sage
mint lava
#

@rustic sage what is the combination you used

twilit sphinx
rustic sage
rustic sage
fallow seal
#

hey i am doing linux fundamentels and i have the question, What is the path to the htb-student's mail? so i filled in /var/spool/mail and it didnt work so i tried /var/spool/mail/htb-students. what am i doing wrong?

mint lava
twilit sphinx
fallow seal
left charm
#

Hey there guys! I need some advice 😬 im stuck to skills assessment on web fuzzing, i answered well to all questions but 1 is missing , that one who wants the extensions.
I found just .php .php7, obviously i missed something cause it says that im wrong πŸ˜“ so anyone can help me with that?

left charm
#

In did, the phps that it is 403

#

But it’s wrong πŸ˜…

left charm
#

Maybe i write the exts in a wrong syntax

mint lava
left charm
#

Maybe it s a problem of client i’ll try tomorrow 😒 thank you πŸ™πŸΌ @mint lava

mint lava
left charm
#

Yup