#modules

1 messages · Page 489 of 1

twilit sphinx
#

The question is "login with the credentials (guest:guest), and try to get to the admin user from what you learned in this section and the previous section"

mint lava
#

let me look at my answer real quick

left charm
#

Thank you dude

vital yew
#

thanks, I got it, damn

mint lava
# left charm Thank you dude

Before you run your page fuzzing scan, you should first run an extension fuzzing scan. What are the different extensions accepted by the domains? is that the question?

twilit sphinx
left charm
#

Yup

mint lava
mint lava
twilit sphinx
#

Ok

mint lava
#

delete it so we wont spoiler anyone, but that is the right answer

left charm
#

Did it

#

So am i right about that answer?

mint lava
#

yes

#

that is what I submited

left charm
#

Ok so it’s some client issue, or network lag

#

Don’t know

#

Ok the important thing is the answer is right

mint lava
#

that is the only one you didnt answert?

left charm
#

Thank you a lot

left charm
mint lava
left charm
#

The others are dome

#

Done*

mint lava
left charm
#

This one is the only one that miss

#

Soo weird 🤣

twilit sphinx
rustic sage
#

👍 got it (finally) thank you

mint lava
rustic sage
mint lava
rustic sage
ivory bough
#

Hello! Could some one give me some advise on the Linux Fundamental Module, I am only missing the Filter Contents part

#

I think I have an idea, but not quite right

bronze ruin
#

hi,guys. in Learning Progress module, i want to get the cubes back from this module. What is the difference between the two numbers of the learning progress mentioned above? does anyone know the answer?

#

i know the meaning of the two numbers, but what is the right answer?

dreamy geode
#

hello

#

im new

#

i will need help

tropic latch
#

Welcome @dreamy geode

dreamy geode
#

hi

#

how do i do a module

tropic latch
#

On the Academy?

dreamy geode
#

yeah

tropic latch
#

Well, without buying Cubes

#

you can only do a couple

dreamy geode
#

cause obvi it will be my first one

#

where do i do them

#

or buy em

tropic latch
#

you should be able to click on "Intro to Academy"

dreamy geode
#

ok

tropic latch
dreamy geode
#

thx ill be back

tropic latch
#

Goodluck

dreamy geode
#

this is free signing up right

#

or na its ok either way but just curious

tropic latch
#

Its free to sign up and do a couple of things yes,

dreamy geode
#

ok thx

tropic latch
#

once you move past the fundamental content you pay $$

dreamy geode
#

ok

#

ill just do that

devout crown
#

Sorry never mind, I managed to resolve the problem! Thanks anyway!

astral cloak
#

Who ever finished the linux module.. I need ur help please

#

I've never been so stuck like this before

autumn pilot
#

ask your question, and do not copy the question from the section/module

astral cloak
#

I'll just skip it and comeback to it later

#

Thx anyway

topaz barn
#

I'm confused as to what answer the question wants for Web Requests GET methods

#

does it want the output?

#

or the command

#

or something else

astral cloak
#

a flag

topaz barn
#

hmm

astral cloak
#

try to find it

topaz barn
#

do I need to use burp for this or can it be done with the terminal

#

just to check I'm on the right track

astral cloak
#

It's been a while since I finished that module, but I think u need to use burp

topaz barn
#

ok, thanks

astral cloak
#

welcome

topaz barn
#

yay I did it

rustic sage
topaz barn
#

indeed it is

rustic sage
topaz barn
#

So, in the POST requests part now, when I follow the instructions that return the PHPSESSID cookie, I get an auth cookie instead. Is that the same thing or did I do something wrong?

#

it shows this

#

but I get this

#

I also might be doing it completely wrong

astral cloak
#

decrypt and make some changes then encrypt and send

topaz barn
#

what does it want as an answer? does it want (adminuser):(adminpass)?

#

still confused

#

@astral cloak are you still there? can you give some more hints?

astral cloak
#

I really forgot

topaz barn
#

oh that's ok

astral cloak
#

I’m afk rn, u got this

rustic sage
topaz barn
#

hmm

wind violet
topaz barn
#

ok, thanks

wind violet
topaz barn
#

yes please

wind violet
#

A hint actually...

topaz barn
#

mmhm

#

did that

wind violet
#

@topaz barn soo did you made it?

topaz barn
#

nope

wind violet
#

how far did you get?

#

im pretty sure your are so close...

topaz barn
#

to the part where it tells you to change the application thing to json and put the code in

wind violet
#

ignore the JSON. just stick to the cookie

topaz barn
#

right

wind violet
#

follow the given hint

#

i mean the hint given with the question

rustic sage
#

Hello

#

<@&486603600085123073>

autumn pilot
#

Hello @rustic sage

rustic sage
#

i am from spain

#

upsssss

#

sorry

high zinc
#

Hi @rustic sage from Spain

wind violet
#

hello from the "other side"

west rampart
#

@rustic sage Hello, i'm not from Spain

lucid wyvern
#

Linux fundamentals.... I feel silly asking this but why is this the incorrect answer? It is the only command i know to fire it up on port 8080 or am I being stupid :// :EDIT: Sorted that could be worded better that question.

raw lynx
#

Can someone takes few minutes to help me with this exercise and explain me what I do wrong maybe ?

Currently I've done a ffuf with recursion on .php but I receive a lot of pages and one with flag.php but I don't understand what kind of answer they expect. I'm sorry but english is not my native language.

midnight sable
#

going crazy with it, tried grep in almost every possible way but it seems that something is missing

rustic sage
#

Hey

rustic sage
#

hi

rustic sage
#

I block to this question Which option needs to be set to execute a command as a different user using the "su" command? (long version of the option) ( Linux Module)

rustic sage
#

yes im stupid is not possible ! Xd

#

especially since the other modules are complete

ivory bough
#

Have you tried checking the possible flags ?

rustic sage
#

no flag no target on this module

ivory bough
#

I mean '-b' for example

#

Maybe they are not called flags in English, sorry
But there is a way to look at the options you have

rustic sage
#

i tried a lot of command

ivory bough
#

You are really close to the answer I think
Want to dm me ? Not to spoil the answer for others, i can help you to figure it out

rustic sage
#

yes thx renega

ivory bough
#

Np 😄

sudden pivot
#

hello

ivory bough
#

Hi1

midnight sable
#

Hi, windows vm's are not working right?

#

"There are not available instances try again later"

shrewd sorrel
#

I am not getting instances either,i wonder if their is a specific time for instances,i was still able to answer the questions tho and used my live tools for the example.

wind violet
#

same problem here. is it happening when like servers gets crowded?

lucid wyvern
cerulean vine
lucid wyvern
#

Cheers

cerulean vine
#

you're from london?

#

@lucid wyvern

lucid wyvern
cerulean vine
#

friend me?

lucid wyvern
oak dove
#

Hi guys we need your help with something related to the hacking

novel cairn
#

what is this group about

#

pls help

trim arrow
#

hi , is there anyway to get a help in one of the questions of web requests module , the one related to escalating the web user using cookies manipulating ,,so its either i am not understanding the question or there is something wrong, i dont think that there is more than bsae-64 decoding the cookies in the request and modify the guest to admin and re encode it again .. please help

drowsy jewel
#

nee help

#

Im struck on the same module @trim arrow

trim arrow
#

it kills me and i dont exactly know what the question required ,, i have escelated the guest to admin and i can see that in the web page but what the answer should be ?

drowsy jewel
#

yup I tried the same

#

and got Welcome admin_####

trim arrow
#

thats it ,, what else we have to do 🙂

#

i even tried to view the source of the page in case they hide some flag there but nothing

drowsy jewel
#

yes

#

Hope someone could help

trim arrow
#

i hope so ,,thats the first time i ask for a help

rustic sage
#

If you're stuck on the cookie manipulation message me and ill try and give you relevant hints (dont want to put spoilers in main chat)

#

and just so you know, the flag in the response will be preceded by "The flag is " <-- thats how you will know you have correctly manipulated the cookie

raw lynx
#

Can anyone help me with the ffuzzing module ?

lapis stump
ivory bough
#

Hello, I am stuck on the Filter Contents part of Linux Fundamentals, could someone give me some advise pls

ivory bough
#

I am trying to filter all unique paths of the domain (Filter contents part)

#

using curl, I've tried to use curl with a variation of grep filters but at this point i am not sure what am I looking for

simple onyx
ivory bough
#

Thanks! I will look at it!

So the question is to get the source code of a website and filter all unique paths of that domain, submitting the number as the answer

Thanks again for answering!

simple onyx
#

yea you can pipe the path and then using the uniq command you can see unique paths

ivory bough
#

Thanks a lot! I will try it

rustic sage
#

Just looking at the "Find a way to start a simple HTTP server using "npm"." question ... but when I try anything I get this: "Command 'npm' not found, but can be installed with:
apt install npm
Please ask your administrator.
"

Does the spawned instance not allow us to install npm?

ivory bough
simple onyx
ivory bough
#

If you try sudo at this part it would give you a warning

rustic sage
#

Just got a warning 😆

ivory bough
#

I memorized it as it took me ages to solve it

ivory bough
rustic sage
#

it says "using npm" how can I use it if its not installed ... im confused

simple onyx
#

have you tried apt install npm?

rustic sage
#

yeh it literally doesnt let you install it

simple onyx
#

ok, thats what i thought

#

I would do it with python then or you can wait for somebody smarter to come here and give you a answer

ivory bough
#

Yes, it won't let you
You have to use the command "like if you have it"

ivory bough
ivory bough
#

First, do you know which flag do you need to use to set the port ?

rustic sage
#

if im honest, im not sure

#

I assumed it would be something like this:
||npm install -g http-server||

ivory bough
#

Noo

#

So.. the way I understand it
You have it already ("supposedly")
What command would you use to change the port ?

#

Btw, how did you covered the command ? that´s cool

#

did you cover *

rustic sage
#

Highlight the text and a little menu pops up with an eye icon

What command would you use to change the port ? - I dont know... im completely lost with it

terse pasture
#

hack the box sign in

ivory bough
#

i am still stuck on the very last question, filter all unique paths of a domain :/

rustic sage
#

I'll let you know when I get there 😆

tame ermine
#

What is tha HTTP method used while interception the requested?

brittle crest
#

Anyone that is still stuck on WEB REQUESTS > POST METHOD because you found the flag and it says its wrong. Delete the exclamation point at the end of the flag or just don't copy that part. For those still stuck on finding the flag. If you Base64 decode the cookie from Burp, you may notice that you get the user presented in the browser, guest_xxxx after successful guest login, is the same as the decoded cookie. The objective is to modify the cookie in such a way that it escalates privilege's to that of the admin user. For some reason the %3D URL enconding doesnt decode to = in burp . So if you decode with %3D instead of = , you get a slightly different value (ie. guest_xxxy instead of guest_xxxx) .........maybe this is how it is supposed to function??? Im not sure, still new to this. But this is just some stuff I learned over the last couple hours I spent on this section

rustic sage
#

Thanks for the hint!

rustic sage
candid sparrow
#

In the Post Method in "Cracking into HTB" i was able to get a welcome message to admin by changing the cookie in base64

#

But i don't seem to get a flag

copper sand
#

Hi 👋 everyone, can you please help me with a problem I have in the module Linux Fundamentals? The questions I don't know how to answer are 1️⃣ "What is the path to the htb-student's mail?". I tried ./var/mail, but didn't work. Another question is on 2️⃣ how to find the kernel version. When i type uname -v I get #1 SMP Parrot 5.5.17-1parrot1 (2020-04-25) and I tried to submit 5.5.17 but didn't. I also tried with the kernel release. Another problem is with 3️⃣ "the name of the network interface that MTU is set to 1550". I can get some information related to network with the command ifconifg, but can't figure out what is the name of the interface. Sorry for the long message.

rustic sage
drifting knoll
rustic sage
copper sand
autumn pilot
#

SSH or Secure Shell is a cryptographic network protocol for operating network services securely over an unsecured network. Typical applications include remote command-line, login, and remote command execution, but any network service can be secured with SSH.
SSH provides a secure channel over an unsecured network by using a client–server archite...

copper sand
#

Ok, I read the wiki page on ssh, now I think that I have to connect via ssh with the ip address that shows, but I don't know how. I looked on internet and it says to use ssh ip_address, but then I put the password shown in red and it says Permission denied, please try again.

copper sand
#

Okay thanks, I am connected!

loud dew
#

Hello, I need a nudge on ffuf module skill assessment, anyone available?

midnight sable
#

anyone was able to connect recently through RDP in Windows Fundamentals?

#

thats given me LOGIN FAILURE -.-

vital yew
#

I connected yesterday successfully in other module with remmina on file transfers -> windows file transfer methods

#

I tested again and still working @midnight sable

midnight sable
#

allright!! thanks for that info! (:

topaz barn
#

Can anyone help me with the SQL Injection fundamentals module?

#

Specifically "Union Injection"

topaz barn
#

we should probably go in DMs

mint lava
#

ok

lyric iris
#

Hey all, I bet this is asked all the time...I just finished Linux fundamentals, should I continue doing other Fundamental Modules before I move on to more Offensive/Defense HTB modules?

topaz barn
#

I would recommend that

lyric iris
#

@topaz barn any particular heavy hitting modules you would recommend?

topaz barn
#

sql injection fundamentals

lyric iris
#

@topaz barn thanks!

topaz barn
#

Can anyone give me some hints on the webshell part of sql injection fundamentals?

#

I'm in a webshell, but I don't know how to get the flag from there

topaz barn
#

found it

rustic sage
#

hello

topaz barn
stable pagoda
#

nmap

rustic sage
#

Im stuck at "What is the alias set for the ipconfig.exe command?" (windows fundamentals) i tried some cmd and got Get-NetIPConfiguration and its wrong

tropic latch
#

I have not done the windows fundamentals

#

@rustic sage

#

But there is Get-NetIPAddress command

#

which sounds more likely for ipconfig

brazen zealot
#

Hey all, need a hand figuring out what I'm missing with the POST Method in the Web Requests module...
Can anyone confirm if the PHPSESSID cookie that is shown in the guide acts the same as the "auth" cookie that is retrieved with the intercept? I'm so very lost right about now.

rustic sage
brazen zealot
#

Lol, I might have to - gonna try a couple more things but 'm probably stumped 😦

tight zodiac
#

assess the web application and use a variety of techniques to gain remote code execution and find a flag in the / root directory of the file system. Submit the contents of the flag as yourAssess answer.

I need a help can some one give a hint

severe brook
#

Hi, I'm stuck in the web request module, in the POST request exercise. I get it to welcome me as admin_xxx but I don't see any flags, any help?

tight zodiac
#

@severe brook please try to decode the session and think a little out why the random no are coming in guest

#

@severe brook done??

severe brook
#

no 😦

#

ohh

#

i get it

tight zodiac
#

@severe brook good

severe brook
#

it's easier than I thought

tight zodiac
#

@severe brook yupp

severe brook
#

thank you very much, I'm sorry I can't help you with yours.

#

^^

tight zodiac
#

@severe brook 😂 np

severe brook
tight zodiac
#

assess the web application and use a variety of techniques to gain remote code execution and find a flag in the / root directory of the file system. Submit the contents of the flag as yourAssess answer.

I need a help can some one give a hint

errant agate
#

Can anybody give me a nudge on uploading the file in file transfer , im stuck on windows

rustic sage
#

hello, im on Linux fundamentals and ive stuck on where to find the htb-student mail, i've used the cat /etc/passwd and got /var/mail and /var/spool/mail but none of them were correct, can anyone give any helpful tips

errant agate
#

Are you using the find command?

rustic sage
#

when i do i get over 150 areas that contain the words mail

drifting knoll
errant agate
#

NVM i got it

errant agate
teal verge
#

I tried to manipulate the Cookie but i dont know what to put in there. Has anyone an Idea?

autumn pilot
#

Put data

slow salmon
#

Hi there, I've got a problem with "ATTACKING WEB APPLICATIONS WITH FFUF" module, there is a question " One of the pages you will identify should say 'You don't have access!'. What is the full page URL?"

I've found that page, but when I try to submit the full page URL it keep saying "Incorrect answer"... how comes that?

slow salmon
#

I'm sure that the url is correct, because I've found the parameters asked in the next question "In the page from the previous question, you should be able to find multiple parameters that are accepted by the page. What are they?"

visual spade
slow salmon
slow salmon
# visual spade Do you give the answer including the port number you use? Then that would be the...

Ok using PORT it worked! Thanks again. Another issue regarding the second question "Before you run your page fuzzing scan, you should first run an extension fuzzing scan. What are the different extensions accepted by the domains?"
I made a fuzz scan on all domains found, and I've found some extensions. Pasting those with return code 200 does not work, I'm sure they are in alphabetical order... Am I missing something?

ivory bough
#

Hello

#

I was wondering if someone could explain a little bit different smth to me
I get the idea of it, but I am looking to get it a little bit better

#

The sentence is the next
Typically, the transmission medium is accessed sequentially from station to station using a retrieval system from the central station or a token. A token is a bit pattern that continually passes through a ring network in one direction, which works according to the claim token process.

#

It refers to a Ring topology

native gyro
#

I dont see how im wrong. Can someone tell me if im wrong? Whats the answer?

untold carbon
#

@ivory bough Every machine sees the entire message, and then passes it on if it isn't for them. If it is for them, it acts on it, then sends an ack to the next machine in the network, for the sender machine.

ivory bough
blissful verge
#

hi all, we just published a new module called Getting Started it includes a little bit of everything but is essentially a primer on penetration testing and getting started on Hack The Box with lots of hands-on and tips and tricks to start you down a technical path

west wharf
#

Can someone help with Web Request module ?
With admin_xxxxxxx ??

#

I've tried all what i can

#

Itsn't works

loud dew
elder sail
elder sail
#

Not for me, im completly new here and started 1 week ago

#

😅

final basin
#

why doesnt it give me a IP 😂

feral lichen
#

how do you get a hashed password?

autumn pilot
#

you need to spawn the target first

broken oyster
#

I'm in the Web Requests module, on the POST page. When I spawn the target, it says I should be able to login to the application with admin:password, but I cannot. I get login failed. I can login with guest:guest.

What's wrong? I checked Burp and my server response to admin:password login is 200 OK and Login failed, and not the 302 Found that the screenshots say I'm supposed to get.

final warren
#

Hey guys can you please help me In the Linux fundamentals I’m stuck on how to start a simple HTTP server using npm any hint?

frigid dagger
# final basin

There should be a link to click that says something along the lines of "Click here to spawn the target." Once you do, the pic will be "SSH to 'ip_address' with [...]"

final basin
#

yeah got past that now 😛

#

thanks though

#

had to wait 20 minutes for some reason, when i came back the spawn a instance appeared

frigid dagger
#

Okay lol, I didn't look at the time stamp tbh 😅

frigid dagger
#

@west wharf @elder sail If you still need help, PM me and I can point you in the right direction w/o spoiling it.

rustic sage
lone shoal
#

Hello!

#

I need help with a section on windows fundamentals

#

In the one that asks you to name a proccess that is non-standard, I found what process it is but I don´t know what is the full name of the service executable

rustic sage
lone shoal
#

Thanks, I did it a while ago, I just had to search for the program in powershell and write the name with a .exe after it

sleek aspen
#

hi

cunning shell
#

i have issue with linux fundamentals

#

wit the php webserver

#

can i pm someone?

#

nvm

broken oyster
north oar
#

guys a bit help

#

after i ssh to this machine how i start http server? 😄

frigid dagger
#

@broken oyster When reading that section, it should say something along the lines of “We will login with the credentials admin:password. You can follow along by logging in with guest:guest.” I’m at work currently but if you still need help later on, I’ll screenshot what I’m talking about so it’s easier to see

#

The point of that exercise though is to gain admin access through privilege escalation from guest:guest though

north oar
#

if i try apt install apache2 -y with sudo i need pass

frigid dagger
#

@north oar Im having the same problem too lol. I need to read into that section a little more because it seems a bit confusing on my first go at it

vital yew
#

you dont need apache

north oar
#

@vital yew i need npm?

vital yew
#

you can start a server on native php or with npm

north oar
#

but same for install npm i need sudo and pass...

frigid dagger
#

I know I don’t need Apache, but I need to lookup how to use npm w/o installing it. I assume one of the commands in that section they discussed is needed to accomplish that

vital yew
#

if you search in google there are a lot of examples of both, with python you can start a simple http too if you still needing help can dm me

rustic sage
vital yew
#

@north oar happy to hear that, but I suggest you to remove the screenshoot, It's a spoiler for other students 🙂

north oar
#

sorry 😄

#

now i try to understand npm

#

i m a bit noob

#

:S

frigid dagger
vital yew
#

npm really is a package manager for nodejs as the hint says, like apt for some linux distros or pip for python

#

so if you search about npm and a basic web server you should find info about what its the proper packet for this purpose and how handle it @north oar

north oar
#

@vital yew this i do now

#

@vital yew done

blissful hare
#

inlanefreight is not opening on htb instance can anyone help me with that i am learning post method

rustic sage
blissful hare
#

thanks got it fingerguns

rustic sage
#

Who wants to test the virus I created on a virtual machine to see if it works please ? Virtual machines don't work on my pc !

outer rapids
#

what is the path to the htb-student's mail?

#

can some1 please help me with this?

karmic cloak
#

hello can you help me in LINUX FUNDAMENTALS
the question is What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?

#

why my command doent work :

#

2 hours that I'm stuck

faint yacht
#

Inb4 it's throwing bad arguments

#

That's my guess even without you actually telling us the error.

#

But having the error would confirm or deny my guess

vital yew
#

@karmic cloak check your newermt value, your value passed seems not compliant and I suggest you to add 2>/dev/null to the end to ignore the permission denied outputs

coral forum
#

hi

#

i'm new in these serveur

vital yew
#

without the word add

urban sage
#

Is this the expected output in Linux Buffer Overflows: Stack Based Buffer Overflows?
I was still able to complete the question on this section but it looked like I was supposed to be able to compile bow.c Removing the -m32 flag allowed compilation to complete successfully.

coral forum
#

pls lerne me

#

@urban sage

urban sage
karmic cloak
#

I ordered but there are a lot of files

#

@vital yew

vital yew
#

check the newermt value @karmic cloak

#

look at the examples in the page with this param

broken oyster
outer rapids
#

i did it's now accepting the answer

broken oyster
#

Finally solved the question in the Web Requests module on POST.. The solution was incredibly simply (won't spoil), but I found nothing of relevance on the GET nor POST pages. This could really be updated, incl. removing the credentials admin:password.

rustic sage
# broken oyster Finally solved the question in the Web Requests module on POST.. The solution wa...

It was tough but really gets people thinking in the right way, I thought admin:password was a relevant hint. Instructions said to use guest:guest to follow along, but knowing the other creds was useful information.
Real world hacking / pen-testing is never going to be easy or fed to us on a silver platter, it's all about thinking outside the box. I struggled but I genuinely thought it was a great learning module

ocean siren
#

any help or thoughts would be great

#

just not sure why I'm finding the same config file and it keeps rejecting my response

ocean siren
#

Is my command incorrect?

broken oyster
rustic sage
rustic sage
civic warren
#

morning/evening folks 🙂 I am having issues pinging my target (all packets are lost) or even google from the spawned machine in the academy

delicate ravine
#

@civic warren same

autumn pilot
#

@civic warren @delicate ravine terminate your current pwnbox instance and re-spawn it

civic warren
#

@autumn pilot that fixed it. Thanks 🙂

tired perch
#

Hey guys, can someone help me in this question...I don't really understand it.

#

||What non-standard application is running under the current user ? (The answer is case sensitive).
||

clever quiver
#

Thanks for the hint 🙂

rotund quartz
#

i think the extension to the flag page is .php7

#

after that im stuck

#

couldnt able to find the flag anywhere in directories or pages

#

any nudge ??

#

got the flag

mint lava
#

try without https://

restive frigate
#

... i feel idiot
thanks man!

mint lava
rustic sage
#

hey guys I'm new here and a noob too lol and I'm stuck in this question

faint mango
#

@rustic sage you need to use ssh to connect to a Target

rustic sage
faint mango
#

yea me too

rustic sage
#

so how are we suppose to solve it then ?

faint mango
#

I mean right now I am solving a different question but I need to ssh into a Target
Those 2 questions that you asked need ssh connection as well, 100%

rustic sage
#

I understand

faint mango
#

for the first question I believe you had to use 'uname' command

#

but it wont work as long as you are not connected to htb-student

rustic sage
#

yep exactly

faint mango
#

there was a problem with workstations a few days before, I think there is a problem with Targets now

rustic sage
#

yeah I believe so because I tried to ssh from my kali machine and I couldn't

faint mango
#

same

rustic sage
#

sad

#

btw thank you for your time

silk moon
#

Are you guys using the given vpns to connect to the htb networks?

rustic sage
#

I'm not !

faint mango
#

should we?

#

I connected without vpn before

#

I have no idea how to use one nevertheless

silk moon
#

Its been a little stince I used htba, theres normally a vpn to connect to but i think they changed it 🤔

faint mango
#

there is still an available VPN Key

silk moon
#

vpn is pretty to use though for htb, download vpn, install openvpn(should be installed already), run openvpn in another window with the vpn pack without closing it

faint mango
#

and I suppose I should download it in the Workspace right?

silk moon
#

Oh are you guys using your own machines or the workspace?

#

If you're using the workspace there shouldn't be a problem

#

"shouldn't"

faint mango
#

I use the Workspace most of the time

rustic sage
#

same I use the Workspace

silk moon
#

The parrot machines should be fine, might just be the server

rustic sage
#

I see, thanks for the informations

faint mango
#

Thank you @silk moon !

velvet zinc
#

Anyone can help with ffuf module

silver maple
#

Man, stuck on this chall for a while in the fuzzing module. I can find two of the VHosts on the Filtering Results section but word on the the street is that there are three. Please pm if you know what I could be doing wrong.

pearl kernel
#

Hi, I've a problem with the Getting Started module, The 'Public Exploit' server seems up but isn't reachable, i've tried to wait but nothing changed, plus if I refresh firefox page it asks me again 'start the server' ( I think that's an unusual behavior )

river wagon
#

It works for me, I get a Wordpress page

#

Have you got any firewall on your network? I had an issue with my Skynet firewall banning the HTB ips for unusual behaviour (typical lol)

rustic sage
#

Hello, i have problem with sqlmap module skills assessment

maybes someone have any advice?

pearl kernel
river wagon
frail wyvern
#

hey guys i am having difficulties with web fuzzing skill assessment

#

i am getting these extensions but it is not accepting

#

ffuf -w /usr/share/seclists/Discovery/Web-Content/web-extensions.txt -u http://archive.academy.htb:30640/FUZZ

#

this is the command i used

#

nvm i found it

#

looked at the cheat sheet

#

sorry i am a noob

river wagon
#

If you are using the browser based machine there is no need to deal with the vpn key. That is only if you want to use your own machine (I use a kali VM) and need to connect to HTB network

#

I’ve had to restart a target a few times today, connection just seems to drop out

drifting knoll
#

we're working on it

river wagon
autumn pilot
#

If you experience issues reaching the targets, please terminate your pwnbox academy instance and re-spawn it

frail wyvern
#

in the wfuzz module final assessment the page is in /courses right?

rustic sage
#

I'm struggling with the following question (what is the path to the htb-student's mail?)
Can someone give me a hint

true whale
#

what moduak

#

modual

rustic sage
#

Linux fundamentals/the shell/system_information

true whale
#

so there is a locate command that may help

rustic sage
#

cat /etc/passwd ?

true whale
#

if your type "locate mail" you will be given many different paths

#

huh

rustic sage
true whale
#

just as a tip since its a mail application it will probably be easy to access(short path) if your still stuck in a few minutes dm me and i can help out more.

true whale
#

no problem

rustic sage
#

@true whale I found it, thank you again

rustic sage
#

ok

cinder sinew
#

ok i've been stuck on WEB REQUEST > POST METHOD for too long and must ask for help. How do I modify the cookie to escalate to Admin?

I've changed the content type to json and the request to { "username" : "admin", "password" : {"$ge":"0"} } and the repeater is returning login failed

frigid dagger
#

Try to figure out how modifying the cookie could escalate you. I was stuck on this for a while as well. Looking back, the answer is very easy, but just starting out it's somewhat subtle and easy to overlook/overthink

cinder sinew
frigid dagger
#

You're welcome! Told you lol. So obvious, but subtle at the same time

#

I struggled WAAYYY more than I should've with that and felt so dumb when I tried it and it worked lol

cinder sinew
#

Yeah homer doh moment but hey at least burp is not scary anymore. I tweaked some configs in there trying to get this to work too 😅

frigid dagger
#

I straight up was confused with the process of burp, but you right. Thanks to spending an unnecessary amount of time to get it to work I gained a better understanding of how it worked. So not a total loss! 👌

tropic cove
#

has anyone here done the getting started module

frigid dagger
#

@tropic cove I'm in the process of going through it now. I haven't finished it so if that's a stipulation, I would ignore me

thin roost
#

❤️ all the free tools your being pointed towards in these modules

#

pretty awesome

ocean siren
#

anyone else having trouble with the find command for the prompt: ** What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?**

#

I can't seem to enter any conf file I find

#

I could really use some help here -- last question of this module

rustic sage
ocean siren
#

yes, I'm on both, I'm tried it on the spawned instance and the pwnbox

#

I know -- I'll remove that from the log, but I'm stumped

#

@rustic sage ^^

#

I just find a single conf file on the target, but it's incorrect, everytime

rustic sage
#

is the bot broken?

#

i cant authenticate with my token neither can my friend generate a invite code from API

graceful prism
#

I've been stuck on Web Requests > POST Method for WAY too long, I really am not sure if I can figure this out myself
I would appreciate some help here pls

ocean siren
#

gr, I'm stuck

rustic sage
#

@graceful prism what you need?

rustic sage
#

hmm

#

you wanting to learn what post method is?

graceful prism
#

nah nah

graceful prism
rustic sage
#

ill take a look in a min just doing a box

graceful prism
#

that's aight

ocean siren
#

The frustrating thing is that I can ls -lah and it fits all the criteria

vapid iron
#

Hi all , I'm also stuck on the Webb request post method , anyone I can ask some questions ?

ocean siren
#

I don't think I'm being a bother, but I'm stumped... if it's not going to work on this free box, I'm kinda skeptical it'll work on other deeper ones

#

perhaps I'm being a bit of a bother

rustic sage
graceful prism
rustic sage
#

@ocean siren I just went back to that question/box and was able to recreate the query that got the answer in a couple minutes, if you want you can DM me and I can try to help see what's going wrong with the find query you're constructing. The one I just used that worked didn't even check for date of creation and still only returned one (the right) result.

graceful prism
#

hmm

thin roost
#

does parrot OS have a mysql database client?

rustic sage
#

@ocean siren also be sure you're providing the filename as the answer and not the absolute or relative path

thin roost
#

nevermind..got it 🙂

broken oyster
#

@ocean siren you can DM me if you want and I'll try to help

ocean siren
#

And thanks. Yeah, I totally missed that. Finally got it. Just had to read the question

#

Much appreciate the message

#

#fanOfHTB

jagged zenith
#

From the end of module bash script

lean flax
lean flax
#

done, I've read what was said yesterday

crude obsidian
#

@ocean siren I'm stucked at the same point (with the config file)... Did you find a way to solve that?

true path
#

Hey there guys! I need some advice 😬 im stuck to skills assessment on web fuzzing, i answered well to all questions but 1 is missing , Try fuzzing the parameters you identified for working values. One of them should return a flag. What is the content of the flag? so anyone can help me with that?

rustic sage
#

I stuck the skills assessment sqlmap.... 4 days.. I've done every technique and nothing.

void lodge
#

Hi there, I've a problem with ASSESSMENT SKILLS of the WEB APPLICATIONS/FFUF module. a question " One of the pages you will identify should say 'You don't have access!'. What is the full page URL?"

I have more than one results for 'don't have access', precisely with 403 code results. There is something that I've missing?
Tnks for help!

viscid ruin
#

Hey I got the same issue, it seems @slow salmon has solved that using PORT, but I actually didn't get the exact: You don't have access! , only the 403 code, which I believe it is not the same. I believe the question is looking for the "Authorization Required". Anyone can shed some light?

restive siren
#

Hey guys, so for Web Request > POST module. If modified the guest key, for the admin, encoded it back again, hit forward and on the browser I get the message "Welcome, admin_XXXXX!". I'm assuming that the answer is admin_XXXXX, but when I submit it = Incorrect Answer... I took note of the new key, the code I to generate it and the user, nothing works. Can someone point me in the right direction?

Solved! Thanks @cinder sinew

late isle
#

have a quick question on the web requests module. in the section headers section 2.entity headers it refers to media-type of being an actual header. I searched for this header online but couldnt find anything on it. I believe this is mixed up and media-type is part of the content-type header rather then being a header by itself. is this correct or am i missing something here ?

#

if this is really the case the way it is listed in the module is a bit confusing.

slow salmon
true path
final snow
#

Hi everyone, I'm at Knowledge Check in the Getting Started module, I ran the exploit from metasploit and was able to get the ssh connection as www-data. Now I'm clueless as to how can I escalate further and where to find the 2 flags (I looked manually through some folders but couldn't find em). I tried running a php shell but on the other ssh connection it also logged me in as www-data. Any sort of help is much appreciated

rustic sage
#

@final snow try using the find command to find the first flag. the 2nd flag will require you to elevate your privileges to root. pay attention to the hint for the second flag, if you follow it, you'll find a way.

crude obsidian
#

Can someone help me with the first answer of File and Directory inside the Linux Fundamentals module? I actually find a .conf file but it says that the answer is wrong... Thanks

crude obsidian
rustic sage
#

@crude obsidian remember to put just the filename as the answer, not the relative or absolute path.

#

there is only one conf file that meets the question criteria, so if you find it and submit the filename you'll be good. if you need more of a nudge i can help, but if you use the find command with the file size limitations given in the question you'll find what you're looking for.

buoyant ruin
#

Web requests module; Stuck in POST method - Login with the credentials (guest:guest), and try to get to the admin user from what you learned in this section and the previous section.
Please help me

strange aspen
#

can someone help me whats wrong with this line? if [[ $var = $value && echo $var | wc -c -gt 113469 ]]

viscid ruin
crude obsidian
slow salmon
viscid ruin
slow salmon
brittle palm
#

Hello guys is this where i can start doing some easy stuff?

gritty peak
#

@brittle palm HtB academy is great! They have fundemental introudction (greatly recommended to do first if you are new to this) after that you can buy some cubes and start on other courses. I can personally recommend the 'basic toolset' path 🙂

brittle palm
#

yeah that would be great

viscid ruin
zenith gyro
#

@timid grove hallo man, can i ask you a question from sqlinjection(writing files)??????

slow salmon
strange aspen
#

can someone help me with bash scripting pls?

mint lava
strange aspen
#

comparison operators: the syntax is wrong i guess if [[ $var = $value && echo $var | wc -c -gt 113469 ]];

rustic sage
#

@strange aspen [[ $var = $value && $(echo $var | wc -c) -gt 113469 ]]

#

you need to wrap echo $var | wc -c in $() so it will evaluate as one term that you can compare to 113469

strange aspen
#

thank you so much..

rustic sage
#

👍 bash can be tricky

umbral basalt
#

hey guys, i'm doing the Windows Services and Processes on Windows Fundamentals and for the life of me i cant find even one of the non-standard update services running on the host referred to in the section question. I've scoured the task manager processes to find any kind of updating service that's non standard (ie. not windows related). I've also checked the C drive within the computer, ran get-services in the powershell, and checked for programs in the control panel (uninstall list). Nothing. Anything i'm missing?

rustic sage
#

Hi everyone!!! I'm stuck in the LFI Skills Assestment. I have the source code of the index page. I have access to the admin console but it seems useless. Can someone help me pls??

#

@umbral basalt if you look in the Task Manager for a service with update in the name that seems like it might be an application related to what's mentioned in the hint, it's there.

#

There's not much more I can say without just giving you the name.

#

Like you, I went a bit overboard trying to find it at first but it's kinda staring you in the face, so if you go too deep too fast you'll miss it.

#

@rustic sage if I remember correctly, you need to review the techniques in the "LFI to Remote Code Execution (RCE)" page and one of those will give you the foothold you need

rustic sage
#

Guys who wants to know how to run a vuln module on a IRC Botnet

rustic sage
#

Hi, writing again

I have a problem with sqlmap module skills assisment. I have tried all possible options from the baypass module. and nothing .

Anyone have an idea?

mint lava
#

Have a closer look Authetication Bypass methods on the cheat sheet

umbral basalt
#

@rustic sage I found the updater and ive put in the full name and every other name combo i can find. Nothing. Thoughts?

rustic sage
#

@umbral basalt Did you include the file extension as well ?

jade willow
rustic sage
#

@umbral basalt because remember, the prompt says Submit the full name of the service executable (not the DisplayName)

umbral basalt
#

I did both to be honest

#

I assume they’re right next to each other in the task manager

#

(Also checked via the power shell; same thing)

#

(The exe was what i was missing, thanks!)

twilit sphinx
#

good night

#

could someone help me in the "Introduction to networking" module?

#

to the question "Submit the broadcast address of the following CIDR: 10.200.20.0/27"

#

page 10

#

I think it's some small detail that I'm missing

restive siren
mint lava
twilit sphinx
twilit sphinx
#

I solved the first question in a simple way, I thought the rest was also

void zealot
#

Hello guys, im having a hard time with the "get started module", section "privilege escalation"
I managed to get user flag but i can't get my hand on the root one. I tried to run a bind shell since it seems target machine wont connect to my vm, but it wont work and i cant see what im missing. Any tip?

vapid iron
#

Hi all,
Could someone assist me with something I'm missing in the post module?
thanks 🙂

rustic sage
#

Hi guys! In LFI skill assesment I can access to logs. I try log poissoning in http.log but it seems that doesn't work because the log do not refresh...any hint???

timid grove
#

do u still need any help ?

rustic sage
#

hello, im on request and response on web requests, i've the burp intercept on requests, but im unable to intercept the responses, can anyone help or give pointers

strange aspen
#

proxy >options>intercept server responses hit the checkbox

desert spindle
#

hi everyone
I need help, i'm trying to aces to the flag for the post method in web request module. i connect with the user guest and i modify the sessioncookie with admin_XXXXXX but it's not the admin session and Ican't reach the flag.
Someone could help me please.
Sorry for my English I'm a french guy

mint lava
#

just make it simple

desert spindle
#

Yes I have guest_a lot of character in base64. But if I change the guest by admin isn't the response

desert spindle
strange aspen
#

can someone help me with bash scripting-comparison operators?

mint lava
strange aspen
#

it doesnt work since 3 days can i pm u my code for a hint?

mint lava
#

sure

sonic glacier
#

it says wordpress, u can try the wpscan to scan for vuln

tough mauve
#

Can someone that finished the Getting Started course on page 9, help me pliz?

tough mauve
#

Someone ?

true whale
tough mauve
#

i need help to explore the target

#

I tried scan with nmap

#

and I discovered a WordPress service

#

after i scan with wpscan, but I didn't find anything

strange aspen
#

can someone help me with bash scripting-comparison operators?

true whale
tough mauve
true whale
#

ill go take a look give me a bit

tough mauve
#

ok, thank you 🙏

true whale
#

look up wordpress exploits with the tool they give you and see what you get @tough mauve

strange aspen
#

can someone help me with bash scripting-comparison operators?

tough mauve
#

@true whale ill try

true whale
tough mauve
true whale
strange aspen
last crane
#

i'm having a bit of trouble with the getting started module. i can't connect to the flag share folder in the service scanning section

pure tartan
#

hey, i'm new here, and have no idea where to start

#

any ideas

drifting knoll
red obsidianBOT
mossy perch
#

Hi, I'm working on getting started module. can someone help me for a small question?

carmine comet
void lodge
#

Hi, I need help! I'm in the WEB FUZZING skill assessment, in the last question. I trying a lot of wordlist of Seclist file recommended by the Hint, but don't have success for VALUE of the parameters that I found! Im trying using the POST method for this, but no success! I search for the wordlist based on the parameters. I don't understand why it's not working... 😟

carmine comet
carmine comet
#

In the Linux Filesystem Hierarchy what "/" stands for?

#

yup

#

pm me

inner sapphire
#

Oh I just reach this section too

inner sapphire
#

Do we need to using exploit to WP?

elfin bridge
#

Hi everyone, can someone help me unstuck from the second question of the "Privilege Escalation"

#

i don't know what to do: i got the ||.ssh|| file from the root using user2 but i don't know why it dosen't ... even if i use the ssh -i function

scarlet gate
#

"Parameter Fuzzing - GET" - "Using what you learned in this section, run a parameter fuzzing scan on this page. what is the parameter accepted by this webpage?" << Quoting "ON THIS PAGE" what page is it talking about? the spawned page or the page I'm on reading the question, which is https://academy.hackthebox.eu/module/54 ??? And when I run a parameter scan on the spawned page, am I supposed to run it as 123.4.5.6/FUZZ because that would be the spawned page and that would be doing what the question asked, but when I do that, the results are home, index, blog and forum but none of those are the right answer and when I do what the lesson is teaching and running a parmeter fuzz, I'm left to guess that it wants a parameter fuzz ran on index.php?FUZZ=key but that doesn't return anything. I feel like these questions are formed by people with so much experience, they don't know how to teach someone with no experience.

dark flower
#

I cannot complete Deobfuscation Examples - HTTP Requests. I send the request post, I get the answer, but they do not give me the answer as valid, and I do not understand the reason

frigid dagger
#

So you get an output from the command you use and you get the flag but it's not correct? Whatever the output is should be correct.

thin roost
#

if i understand correct the current htb-academy boxes use an older version of metasploit framework preventing to drop into a shell...Tried to update metasploit framework but i think i have no permissions

dark flower
#

ok i keep trying

frigid dagger
#

@dark flower If you want, PM the flag you got and I'll tell you if it's correct. Or I can tell you if the command you're sending is proper

flint helm
#

I'm stuck in the second question of Working with Web Services where it asks "Find a way to start a simple HTTP server using "php". Submit the command that starts the web server on the localhost (127.0.0.1) on port 8080."

#

I tried the following:

thin roost
#

checkout php.net im sure its on there

scarlet mirage
#

I have some troubles with the web request module. How can I send a get request with two parameters to flag.php? Would appreciate some hints 🙂

elfin bridge
#

can someone help me with the second question of "Privilege Escalation" 🙏 i don't know what to do in order to get the flag.txt on the root

rich orchid
#

What's the correct syntax for this?
Access the SMB share folder called 'flag' and submit the contents of the flag.txt file.

#

I've been trying combinations for the past 50 minutes and have no clue

#

Dunno wtf to do with the admin:ftp@dmin123 creds found in the ftp server

#

Tried using them for the smb share but I don't know if its a cred problem or smbclient syntax problem. Im going crazy

#

Thanks

#

The creator should REALLY provide a hint for this one. At least a syntax hint..

#

Btw you guys should add how many times exercises have been solved so we can be sure stuff isn't broken

mint lava
#

hint bob

#

look at the hint

rich orchid
#

There's no hint

mint lava
#

it is literally right in front of you

#

I give you a hint right now

rich orchid
#

I've tried the anonymous user as well it doesn't seem to exist

elfin bridge
mint lava
#

did you tried to do same as the example?

rich orchid
#

I've literally tried every combination I could formulate in the past hour

mint lava
#

you over complicated it

#

do the same as the example!

rich orchid
#

Thanks for nothing

mint lava
#

I repeat look at the user bob that used in the example

elfin bridge
rich orchid
#

I'll give it another try rn

rich orchid
#

@mint lava

#

I'm not gonna lie, this exercise was a total bummer to me

#

The hard part wasn't SMB nor smbclient syntax.. And it was supposed to be, right?

#

The hard part was getting hit by "Oh, I'm gonna try the username and password used as a goddamn EXAMPLE.. Because I've lost 2 hours and tried everything else"

#

Like.... I've found credentials in the FTP server, I was 100% sure I had to use those (or none.. and just login as anonymous)

#

But I lost a large chunk of my study time today -- and got pretty frustrated in the meanwhile -- because I was supposed to use credentials that were used in an example from the theory section... Sorry but it makes no sense to me, the practice section should be about "dealing with SMB" and not "luckily guessing stuff"

patent blaze
#

I'm doing the 'getting started' module. I know that I have to use the "47187.rb" to proceed. When I google it, it says that it requires msfconsole. Alright, my question is, how do I use this "47187.rb" from within metasploit console ? Thanks anybody who heps me in advance !

rustic sage
#

Im currently stuck at "Getting Started > Privilege Escalation" question 2: I have copied their id_rsa to my pwnbox and chmod, after that i "ssh -p port user1@target_ip -i id_rsa
them it asked password for user1 which given is password1 but i doesnt have root priv. what can i do

frigid dagger
#

@rich orchid I totally agree.... I've spent about just as long as you did trying to get it and FINALLY got the dumb idea to try something from the example.... This section should've been made a bit better. Why it was set up like this when none of the others I have done have been done like this, is beyond me

slow salmon
hearty saffron
#

Hi I'm stuck on the Web Requests module in the POST Method section.
The question is: Login with the credentials (guest:guest), and try to get to the admin user from what you learned in this section and the previous section.
The hint is: Manipulate the cookie as discussed in the previous section.
I don't understand what I have to do to the cookie header

loud dew
#

I could not get the flag last night. Woke up today,fresh look at it, 3rd double espresso and BOOM.

patent blaze
#

Guys, lemme ask you something.
Once I have found an exploit through ‘searchsploit’
how do I use it in msfconsole ?
It’s important to point out that the exploit, found through searchsploit, it states that it requires msfconsole.
Does anybody know how to do it?

patent blaze
#

got it. But there's something that still doens't fit. For instance, the exploit I want to use is 12345.rb (👈 is this the name ?). I still don't get this.

silent smelt
#

i guess you do msfconsole 12345.rb in the terminal to load the file

patent blaze
#

@silent smelt I tried what you said but interestly neither trigered a error nor worked.

What I’m trying to do is that:

The following exploit (php/remote/47187.rb) it states that requires msfconsole, however I don’t know how to use that inside metasploit. But thank anyway for trying to help me !

rich orchid
#

@patent blaze As far as I know, Searchsploit uses it's own database to search for exploits (and not your /usr/share/metasploit-framework directory)

#

Are you sure the module isn't missing somehow?

#

Tell us what error message are you getting

#

If there's no error message, I'm afraid we'll have to look at the code in order to learn how to use it

last crane
#

Are you sure this is the exploit? I also thought of using it but I'm not sure how I'm supposed to get the credentials for the WordPress site

#

How did you get the username?

rustic sage
#

Anyone able to help out with the netcat part of "getting started"? ... I tried the command shown on the page but doesnt seem to work ...

last crane
#

Dm me

patent blaze
last crane
#

Huh

#

I couldn't find a comment when I checked

#

Strange

patent blaze
#

I meant recent posts

#

my bad

last crane
#

Ohh

#

Alright ty

patent blaze
last crane
#

Yeah, thanks :)

pliant otter
#

hello, i'm new at HTB Academy and got a problem to answer the question in LINUX FUNDAMENTALS. For example the question "Which option needs to be set to create a home directory for a new user using "useradd" command?" -> i tried "useradd -d" or "useradd --home-dir" but it was wrong. Can someone tell me how to answer questions like this? thanks

pliant otter
#

thanks for the reply but it does not work

hearty saffron
pliant otter
#

yeah thank you 🙂 i tried -m and it works

mint lava
rich orchid
#

And I still think that exercise is terrible

#

Because to pass it you have to GUESS CORRECTLY

#

The difficulty is in GUESSING, not in the SMB concepts or commands

#

That's why I think its simply stupid

mint lava
dusty river
patent blaze
#

can anyone help me ?

west rampart
#

With what?

#

@patent blaze

patent blaze
#

so

#

I'm at getting started module

#

to be more specific I have to find a way to exploit the simple backup plugin for wordpress

#

What I’m trying to do is that:

The following exploit (php/remote/47187.rb) it states that requires msfconsole, however I don’t know how to use that inside metasploit

west rampart
#

Which section?

patent blaze
#

public exploits

west rampart
#

Ok

#

Sec

#

@patent blaze dm me

patent blaze
#

alright

modest sail
#

Can anyone help me understand the way of thinking when it comes to cracking a hash? I’ve been stuck on this cracking common hashes for a while. I’m using the prebuilt rules for hashcat but the entire scans take hours. I imagine there must be a better way! TIA!

rich orchid
#

Lost 2 hours thanks to someone else's bullshit

#

I wonder why there is a login.txt file on the ftp server with USELESS credentials

#

Probably just to troll people

#

And waste their precious time

#

Like.. you have to EXHAUST yourself trying stuff until you think "Oh, maybe the credentials I've found on the ftp server are useless and I should try the credentials used in an example from the theory section" 🤦‍♂️

stray fjord
#

Was hoping someone could give me a nudge on the skills assessment for the File Inclusion/Directory Traversal. I've tried everything in the module without success as there is no place where the app outputs data to the user. I've directory bruteforced it to death without much success. It seems there is some sort of admin panel but I can't find it and almost everything returns a 200 response code. Please help!!

scarlet gate
#

almost like they're fishing for whom will remain persistent, given the qualifications and credentials of the organization

lilac pecan
rare linden
#

Man i love this thing

river wagon
# rich orchid I was sold on HTB.Academy.. but after that exercise I'm really starting to doubt...

I think this is just the nature of the game. The course writers have been doing this a long time. I know it’s frustrating but HTB Academy is basically training you to play HTB, while it is teaching you the fundamentals it’s also trying to impart the mentality that goes along with this sort of thing I guess. This is very much a “think outside of the box” course, in the getting started it says as much. Just try to keep going forward but keep in mind this is trying to teach a mentality as well as skills

rustic sage
#

If sysadmins do their job and rotate credentials, yeah, you're going to find stale credentials in files like "passwords.xlsx". Welcome to the real world 🙂

#

To all the ranters: Keep in mind that Tier0 on HTB academy is essentially a free learning resource. I completely agree that the quality could be better (typos, odd sentence structures, lack of consistency between exercises) but unless HTB hires a QA/UX team to come in and fix those, this is as good as it gets. If you can't find it in your heart to be grateful for the time and energy someone spent to create this the best they could with the resources they had without meeting your quality standards: instead of labeling it as "stupid", just go elsewhere or create your own free cybersecurity training platform.

autumn pilot
#

Woody1130 has the idea of it, you have to do researching and develop the skill of researching, you have to strive away from spoon-feeding. If you ask someone from the industry in which he has many years in, he will tell you the same that you need to develop the skills of researching and others as well. Spoon-feeding is until one point, after that you have to teach yourself things. No one is born with the skills, hard work is the key.

dusty river
# autumn pilot Woody1130 has the idea of it, you have to do researching and develop the skill o...

well in this case it was the very opposite. since we are not used to spoonfeeding, we failed to solve this one. we were spoonfed the credentials and found ftp credentials as well. so naturally we go for the cred which weren't spoonfed. to actually use the ones out of the example is something that only happens in this module. i've done a bunch of academy modules now and this never happened again.

autumn pilot
#

which model and section is that, and what exactly is the issue

gilded loom
#

Hey I need help with the first question the "Find files and directories" lesson from linux fundamentals. here is my code: find /etc -type f -iname ".config" -size +25k -size 28k -newermt 2020-03-03. pls help

dusty river
#

ofc it is for startes, and i already did some (retired) boxes on HTB. it just seems to be very out of character for HTB. I do those modules for funsies and the completionist in me commands it. 🙂

sage vine
#

Im wondering if somebody can help me in the very last question in getting started (knowledge check)..
Ive managed to run an getsimple metasploit to gain access and read out the first flag. However im still in the Meterpreter pseudo-shell which has limited commands. Ive been able to upload a LinEnum.sh script to the host but the execution doesnt work properly. Im looking for tips on how to escalate Privilege from here..

novel flax
#

Hi

#

Any brazillians here ?

zenith gyro
#

@timid grove hello man! tankyou but i did 👍 now im stuck in something different 😆

rich orchid
#

🤦‍♂️

#

I'm complaining because I want it to be better and if I could improve stuff, I'd happily do it myself

wheat grotto
#

Hello everyone im new here I was just trying the intro to networking and on subnets and I’m stumped on the last two questions could anyone help me??

rich orchid
#

I was expecting comments like those already, but I really don't buy into that crap and that's it. That's just my opinion.

vestal moon
#

I have installed Apache2 and started it on my VM but I'm unable to connect to http://localhost fixed

wraith walrus
#

hey guys

#

i cant undrestand

#

in the fundemental modules, linux fundementals > find command

#

the question, What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?

#

all files are Permission denied

true whale
#

all you need is the name

zenith gyro
#

@timid grove Hey can i DM you?

wraith walrus
#

ya

#

ik

#

all i need is the name

#

there are millions of files

#

on the scren

tough mauve
#

hi everyone, can anybody help me in Privilege Escalation ?

tough mauve
#

I understood the first question, but i don't know how i do capture the flag of the root user, can anybody help pliz?

west rampart
#

which section?

humble hemlock
#

hey all, i just reached the final step in the pentesting module
site cant open properly tho

#

stuck on "connecting to [ip]" forever....

north oar
#

who can help me with this

open sable
#

At what point in the academy am I ready to tackle easy machines?

zealous meteor
#

I'm not sure if it's the website or if i'm doing something wrong but i'm doing the Linux Fundamentals on HTB and i'm trying to ssh to a target with the user and PW they provide but it keeps telling me permission denied

zealous meteor
#

@zenith vigil

zenith vigil
#

of the terminal (you running the command)

#

@zealous meteor

zealous meteor
#

It's in the screenshot

#

Through their lil web thingy

zenith vigil
#

ohh

zealous meteor
#

The Instance

#

I tried doing it through my MATE terminal but it wouldn't work

zenith vigil
#

yeah you dont have to put the curly braces

#

do it without the curly braces around htb-student

zealous meteor
#

Oh shit

#

I was using the Bash terminal

#

And I just used Powershell and i think it worked?

tall elm
#

I am stuck on the Nmap scripting engine. I have done a -p- scan as well as a -A / -sV scan and am happy that i have all the ports, I looked at the hint and assume that i means port 80 due to the http. after reading some hint and suggestions on reddit on what to look for have tried to insert some scripts on the port but due to the amount of 'http-*' script dont really know what one. I feel like i am in the right area but am missing something i just dont know what.

tall elm
#

After reading a looking at a few other questions and answers about this, notice i was looking at the right request but the wrong answer and found the flag

frigid dagger
#

Anyone able to help with the Linux Fundamentals module, Section: File Descriptors and Redirections, final question: "How many total packages are installed on the target system?" I have tried to check against dpkg and apt, but can't seem to get the right number... I've looked up online other methods for looking up total # of packages installed but none of the #s I've found are correct.

tired perch
frigid dagger
#

I have done that. According to a suggestion I saw made by Tiro in another thread, he mentioned that some of the lines that get counted are usless. So I need to now figure out which those are. I know what the command to count the lines are and the count given, I just need to figure out how to filter out the useless info. If you could hint to that, it would be appreciated! Otherwise, I appreciate the response! I should've specified a bit more about what I have done

zealous meteor
#

Hey guys. I'm on the Linux Fundamentals module. I'm on the question "What is the name of the network interface that MTU is set to 1500?"
So I use ifconfig -a
But none of the names I use are working?

tired perch
#

you just used the wrong option, that's all

#

try ||-s||

zealous meteor
#

Breh... I swear I used that before and it didn't work. But it did now. Thanks for you're help @tired perch

#

@tired perch Jesus I feel like some of these answers have to be so technical good god. So many options

#

@tired perch Do you mind if I DM you? I feel like i'm close but there's something i'm not quite understanding here.

hearty saffron
#

MODULE: Linux Fundamentals
SECTION: Filter Contents
QUESTION: Determine what user the ProFTPd server is running under. Submit the username as the answer.
i tried nmap and i found ProFTPd on port 21 but how to see user?

tired perch
hearty saffron
tired perch
#

not sure, have you ssh into the machine?

hearty saffron
#

no

tired perch
#

you actually should do that, First ssh into the machine

#

then you enter the command

hearty saffron
#

ok

#

nvm i found now it was something else

tired perch
#

ok then

frigid dagger
#

For me, what is being shown on that same question says it is wrong. I'm actually struggling with all of the questions tbh. That same L.F. Module, same section. The last one I'm filtering out, but only a few seem to show and its not correct

frigid dagger
#

I ended up just guessing the first and last questions' answers, but I'd like to know how to actually solve the problem legit. Googling hasn't yielded any answers yet, but hopefully I get some kind of hint

heady plank
#

MODULE: Web Requests
SECTION: POST Methods

i am not able to login with "admin:password"! so how can i solve this course without getting the cookie from the admin user ? had anyone else this problem ?

autumn pilot
#

the valid credentials are in the exercise

#

below, where you spawn the target

heady plank
#

there are now credentials below where i can spawn my target

autumn pilot
#

use them to get to the admin

heady plank
#

oh, sry i had a typo:
i mean there are NO credentials!

autumn pilot
#

Read the question then

#

i'm 100% sure that there are

heady plank
#

there are the guest:guest credentials.
but in order to answer the question i need the admin auth cookie. and to get them i need to login with admin:password!
but this does not work

autumn pilot
#

@frigid dagger good call, but let him try to find out the way by himself

frigid dagger
#

Okay, sorry, I was starting to think that was too much. Apologies 🙂

autumn pilot
#

No worries

#

This is what Erobus said: Those are the creds you need to use. You have to escalate your privileges to admin from those creds

frigid dagger
#

Could you point me in the right direction for the Linux Fundamentals Module, Filter Contents Section questions? I'm right there for all of them (1st one I'm furthest from), but I just can't seem to get to the last steps. I thought I had the second question, but the user I grep'd from the service list was not correct. And for he final question, I just guessed the answer, but I can't seem to get matching results. I want to actually know the processes. I can post a pic of the questions if needed

autumn pilot
#

try with the network statistics command

frigid dagger
#

Okay, I’ll give that a shot later today. I just realized it’s 4AM here and I’ve got work at 2pm 😅 gotta get at least some sleep

#

Thank you

maiden thistle
#

Hiya, I'm getting stumped at the first exercise for deobsfuscating javascript. I have parsed the js and found a var flag = "HTB{.....}" but it is incorrect. I have also decoded it using base64 and trying that, as well as encoding it again and trying that

Edit: NVM, I need to read through things before jumping through hoops

north oar
tired perch
#

Tbh, if you read the page properly you could have found the answer cause the command is just there.

rustic sage
#

hi

loud dew
#

Question: Nibbles box - is there any other way to get the password for admin user, or guesing it is the only method. I`m just curious. I looked at numerous walkthroughs and could't find it.

patent blaze
#

actually I was able to find the password in one of the directories, but I didn't really need that. The "TOOL" a used didn't require neither password nor username

mint lava
#

anyone has problem with the Nibbles box target ? cant even PING the target

patent blaze
#

have tried to respawn the targert ?

mint lava
#

yes multiple times

#

it seems there is problem with the vpn

#

for the instance box it seems to work

#

slowly but at least can ping

loud dew
#

I have exactly the same problem

patent blaze
mint lava
#

did it several times

#

still not seems to work

mint lava
#

Is there any staff member that confirm that the target is live?

loud dew
#

I deleted the ovpn and downloaded it again and it works now

mint lava
#

did it but still have some issues

rustic sage
#

Hello, i'm blocking on a question in [Path] Web Requests -> [Module] POST Method. I don't know what to do. (I try manipulate the cookie, intercept with burp ...).

rustic sage
#

Ok

loud dew
wild spire
#

Hey, I have a question regarding the Getting Started Module... I'm on the question where I'm required to use the 'smbclient' command to login to the targets network shares and find the contents of the flag.txt file. I listed out the shares with 'smbclient -N -L \\ip address' and it is listing out a non-default users share. I have attempted to login to the users share via the 'smbclient \\ipaddress\users' command to no avail. That is the syntax that was given under the Shares section of the Module. Does anyone have any pointers?

mint lava
#

this is worried I had some problem with the vpn in the past where the Initialization Sequence couldnt complete but never where the Initialization Sequence Completed and couldnt enage the target

#

it seems that also form the instant box I could not ping the target

#

anyone had some problem with the vpn key? for the Nibbles box target form the Getting Started module?

west rampart
#

@mint lava what kind of problem ?

#

@mint lava

mint lava
#

now it is up

#

but after sometime is down

#

now it is down

mint lava
#

@west rampart ?

rustic sage
#

guys

#

im new here

#

what is this server exactly

west rampart
#

@mint lava did you restart the target ?

mental kindle
#

I’ve got logins.txt from ftp but those creds doesn’t match neither smb, nor telnet

tidal mango
wild spire
#

I just got in. I'll pm you in a sec

#

@tidal mango Thanks I finally realized I had to use those creds in the example, but the syntax was different

rustic sage
#

what is this server?

mint lava
tidal mango
rustic sage
#

please answer my question

#

guys

fallow remnant
#

anyone know where to find compilation of many breaches (comb) 3.8billion (public)

sage vine
#

Im wondering if somebody can help me in the very last question in getting started (knowledge check)..
Ive managed to run an getsimple metasploit to gain access and read out the first flag. However im still in the Meterpreter pseudo-shell which has limited commands. Ive been able to upload a LinEnum.sh script to the host but the execution doesnt work properly. Im looking for tips on how to escalate Privilege from here.

rustic sage
#

Hi I'm stuck in the Learning Progress module I can't find the question answer "To get the cubes back from this module, answer the following question. What is the difference between the two numbers of the learning progress mentioned above?"

tidal mango
#

Pretty sure it is a number...

rustic sage
# tidal mango do the math

Thank you. But I don't understand why you have to change the decimal separator ... perhaps to get out of the box

high zinc
#

Is a Site-to-Site VPN advisable from a security perspective?

#

Perhaps between two heavily restricted subnets?

proven jay
#

hey all, working on the getting started module, and im getting a weird error. anyone up for helping

#

?

high zinc
#

@proven jay what's the issue? Not sure if I know the answer but I can try

proven jay
#

where IP is the ip address of the target host

high zinc
#

if you want to browse the content you need to use this format:

smbclient \\\\IP\\sharename -U 'username'

then enter the pw when promted

proven jay
#

shouldnt it work with the guest account when no -U is specified?

#

also with -U I get the same error

#

I know that the IP and share names are correct, because the share name comes up when I run

smbclient -N -L \\\\IP
fresh karma
#

Hey everyone, I'm working on the introduction to networking module and questions 3 and 4 have me stumped. Split the network 10.200.20.0/27 into 4 subnets and submit the network address of the 3rd subnet as the answer. I thought .64 was the correct network address but it's not accepted. Can anyone shed some light on how to figure it out?

radiant kettle
#

can someone help me with the Windows Fundamentals first interactive puzzle

#

i cant seem to get it

#

it wants me to connect to a workstation via Remote Desktop

#

to find the build number and what Windows NT version is installed

#

ive tried the Linux they give you and ive even tried my own Windows 10 VM

tired perch
#

if you wanna connect it just follow the command that is given

#

they have given an example on how to connect it

radiant kettle
#

Pastery@htb[/htb]$ xfreerdp /v:<targetIp> /u:htb-student /p:Password

#

which i have tried in different forns

#

such as [/htb]$ xfreerdp /v:<targetIp> /u:htb-student /p:Password

#

and xfreerdp /v:<targetIp> /u:htb-student /p:Password

#

of course replacing password with what is given and targetIp as the given IP

tired perch
#

its actually just xfreerdp /v:<targetIp> /u:htb-student /p:Password

radiant kettle
#

hmm thats what i thought

tired perch
#

then fill it in

frigid dagger
#

Not related to a specific module per-se, but I am trying to use this argument in grep I saw someone use that does exactly what I wanted, but I can't seem to find any literature on the command in this way. The command I would like either some help understanding or pointed to a resource to read about it is " grep -oP 'f="(.*?)"' ". Specifically the part of "(.*?)". I know what it does, but Idk WHY it shows me the output it does. I can't use more detail here as the module I'm using it on, could be counted as a spoiler.

radiant kettle
frigid dagger
#

What's the problem in Python? I'm not amazing at it, but I know some stuff

tired perch
#

in powershell

radiant kettle
#
or operable program. Check the spelling of the name, or if a path was included, verify that the
path is correct and try again.
At line:1 char:1
+ xfreerdp /v:10.129.203.131 /u:htb-student /p:Academy_WinFun!
+ ~~~~~~~~
    + CategoryInfo          : ObjectNotFound: (xfreeedp:String) [], CommandNotFoundException
    + FullyQualifiedErrorId : CommandNotFoundException```
#

wait

#

i typed it wrong

#

yeah it gives me this error

frigid dagger
#

In Python, double-quotes don't allow you to span multiple lines. Use """YOUR_TEXT""". These are triple-double-quotes

radiant kettle
#

you can use \n aswell

frigid dagger
#

^^^ this is true

radiant kettle
#

print('one \ntwo \nthree')

#

will work

frigid dagger
#

I personally like the triples so I don't have so many \n's but, it also depends on how many lines I'm spanning

radiant kettle
#

the triples are easier

frigid dagger
#

His code, it could go either way imo really

frigid dagger
#

You're welcome 🙂

radiant kettle
frigid dagger
#

Yes

radiant kettle
#

yes

tired perch
#

I know for sure that it works on the machine that is provided by htb

radiant kettle
#

lemme try that then

#

may be your laptop

#

i have no issues with VS Code

frigid dagger
#

You could use it after "star," or before "How", e.g.: "star,\n" or "\nHow", and both would yield the same effect of "How" appearing on a new line

radiant kettle
#

been stuck on this since last night

frigid dagger
#

Anyone able to help me with the Linux Fundamentals module, Section: Filter Contents", on the third question? I can't seem to get the proper number of unique paths. I have tried several things, but can figure it out

tidal mango
#

anyone?

split elk
#

Hi ^^

#

well I just started the windows fundamentals, no clue where to start but I figured starting anything is good enough, lol 🙏

bold frost
rustic sage
#

hi im new

rustic sage
#

can i teach how to hax here?

#

???

rustic sage
#

hi all, I'm new here in HTB and I'm stuck on skill assessment on file inclusion/directory trasversal.. Can someone DM me please🙂

split elk
#

Oh my gosh, ha, I am actually struggling on the first part of windows fundamentals.

#

how utterly embarrassing is this. 😢

#

time to re-read it all. 🤣

atomic light
#

can someone please help me with this?
GETTING STARTED
Page 9
Public Exploits
i found an exploit on searchsploit but i cant find the exploit in msfconsole

rustic sage
#

hi, can someone help me how to determine a path of a certain directory?

rustic sage
#

im currently studying the "Linux Fundamentals Module" and im only at the second question and im already confused

rustic sage
# tidal mango pwd?

oh my, thank you, i just tried it, sorry if the question sounded so dumb im really new to the field, thanks again for responding

tidal mango
tidal mango
rustic sage
tidal mango
split elk
#

hmm I am confused! the first part with intro to windows