#modules

1 messages · Page 494 of 1

pearl nymph
#

really really @flint moth you gave a too good guidance! Thanks

pearl nymph
#

Bro where you are practising?

marsh hollow
#

@silk grail DM

rustic sage
#

@celest elbow im having the exact same problem, did you solve it?

#

im having the same issue even with PwnBox or my Kali VM

#

tried US + EU VPN servers, made 0 difference. I think this issue started occurring yesterday?

torpid ermine
#

use this command in the target machine

rustic sage
#

@pearl nymph already solved it + the challenge. misunderstood the challenge

floral coral
#

Can anyone give me a hint about the question " Which Windows NT version is installed on the workstation? (i.e. Windows X - case sensitive)"? I know the version but I don't think Windows NT is installed. Windows 10 is installed.

maiden kiln
#

Hi, I'm learning the "Getting Started" module, in the section "Pentesting Basics" , at "Service Scanning" there is a question where it tells me to do a nmap scan and answer this question: Perform an Nmap scan of the target. What service is running on port 8080? (two words)
As you can see on the screen the service running on port 8080 is http-proxy. However when I entered my answers it says wrong answer.

#

Am I missing something?

urban sage
#

You can probably find more detailed information through with some scan options.

urban sage
#

@maiden kiln Nice job! Just removed the messages because spoilers. 🤫

dull orchid
#

goodnight 2 all

tawny plume
#

On getting started/Privilege Escalation I have found an exploit to gain root but I can't get it to run

dull orchid
#

explain better the issue and someone will help you for sure

tawny plume
#

I don't know how to explain it without spoiling it for someone else. I found a vuln that will let me gain root but I can't run the exploit properly

tawny plume
#

I tried running the exploit again a few hours later and it worked

tawny plume
#

I don't know if there are different ways but I barely touched user2

topaz zenith
#

You need to pull that id_rsa to your machine and ssh in with that key. That's where I'm stuck. I keey getting "invalid format" and it asks for a password. I've been trying to figure this out for days and I just can't seem to figure it out.

tawny plume
#

I managed to get root without using ssh keys

topaz zenith
#

now i can't even get the target to spawn 😩

burnt stone
topaz zenith
#

@burnt stone copy, but that doesn't seem to apply. I'm not trying to spawn a box, but a target. Is this part of the outage?

tawny plume
#

Same issue

#

You can't spawn on academy either

burnt stone
#

@versed zealot may know better.

versed zealot
#

This is a part of the issue that we are experiencing with spawning Pwnboxes and Machines. We've identified the cause of the problem and are working on resolving it. Sit tight for now!

#

The problem also affects target instances, unfortunately.

topaz zenith
#

i guess that gives me more time to figure out how to convert an openssh private key to whatever it is that I need. 🙃

#

Target FIXED!! Thanks, HTB staff!

timid gust
#

Hi, someone can I help me with this exercise? I can't understand English grammatically well yet.
In Linux Fundamentals, exercise: Filter Contents.
Point 3: use cURL from your pwdbox to obtain the source code.. filter all unique paths of that domain.

What does the exercise with unique routes refer to?

ancient oriole
#

Hi, I'm doing module where i have to exploit a website. I can access the website in web browser, but I cannot ping it or run that exploit. What am I doing wrong?

scarlet finch
#

but which module are u talking about

ancient oriole
scarlet finch
#

ok wait

scarlet finch
ancient oriole
scarlet finch
#

Ok

#

SHIT SORRY BRO. I don't have enough cube to unlock it. Can u show the question here plz?

ancient oriole
scarlet finch
#

use the cheetsheet

#

Can u send me a screen of the entire page. cause u have to use the stuff of the page to do it

#

||personally, I would use Nmap and Metasploit for that but in the page u should see some stuff to use ||

scarlet finch
#

Ok lol. So I was right u have to use metasploit

#

and nmap. And normally if u follow the intructions of the page u can do the thing. U have ti use google, exploit-db etc.

#

or searchsploit

#

just a thing. if u do ping <ip of the machine> there is no response ?

ancient oriole
#

when i try to use metasploit and do check, it says this:

ancient oriole
scarlet finch
#
set RHOSTS 138.68.182.108
ancient oriole
#

only one left

scarlet finch
ancient oriole
scarlet finch
#

yep so what. It's fine.

ancient oriole
#

thank you, it looks like it's working now

scarlet finch
#

👍 noice

maiden kiln
#

Hi, I'm learning Getting Started, in the Priv Sec part , there is a target that I'm trying to download the linpeas script from my vm via http server, but it keeps saying connection timed out

#

Is there anything wromg? I switch to another wifi and still got this problem

urban sage
#

Double check your firewall rules. sudo ufw status

maiden kiln
urban sage
#

Hmmm... Might try checking with ping and or netcat to try and reach back to your box. You might need to find another way to transfer the the file.

maiden kiln
#

Don't know how to say this but recently my home network has silly problem, I cannot ping google, it says destination unreachable, same for hackthebox.eu, but if I ping exploit-db it just fine. Traceroute works by the way

drifting glacier
urban sage
maiden kiln
urban sage
#

Maybe. Something is odd. I still don't think that would affect the VM itself though. Communication between your VM and the target should be in the VPN.

maiden kiln
maiden kiln
#

Tomorrow I will try again on pwnbox, if the samething happen I will ask later

#

Thank you for your dedicated support man!

urban sage
#

No problem. Hope you get it figured out. You could also try reaching out the support team.

drifting glacier
maiden kiln
drifting glacier
#

well i had tried that before, but this time in my kali box i decided to add sudo to the beginning, and go figure im in

drifting glacier
#

i'm more angry than relieved that it worked lol

#

but i guess it's a good lesson on KISS

maiden kiln
drifting glacier
# timid gust .

I didn't really understand that question either, just guess until i got the right answer so i could move on lol

harsh pine
tawny plume
#

@celest elbow Have you found the "Upload files and/or images" button? What happens when you click it?

#

Nothing happens when I click on it. I think it might be calling a flash file

tawny plume
#

I used metasploit myself. I'm going to try and work out how it did it after. I'm just looking for root at the moment

drifting glacier
#

I've also got a question on the knowledge check for getting started. I'm pretty sure I know the idea for the priv esc vector, but I'm having trouble finding a php one liner that should work. does anyone having any they can share?

quiet vault
potent moss
#

Hey everyone. I am working on the getting started module. Finished the nibbles section and on to the 'Knowledge Check' where you exploit a box in a similar matter without the guide.
I've clearly missed something. I have located and identified the services, identified the services being used and an exploit. However, I need an admin login and I can't seem to crack it. I tried brute-force with hydra but it was saying it would be over 24 hours - clearly the wrong direction.

Anyone have some suggestions for me?

rustic sage
#

Hi everybody, i am currently working on the Linux Fundamentals and stuck in the "Services and Processes Management" section.
the goal is: "Use "systemctl" command to list all units of services and submit the unit name with the description "Load AppArmor profiles" as the answer."
My command does not get accepted: ||systemctl -l --type=service | grep "Load AppArmor profiles"||

potent moss
#

Have you tried a more vague grep search? Maybe just one specific word

rustic sage
#

i tried "|grep Load"

potent moss
#

What about armor?

rustic sage
#

still no success

#

i found no option to search with systemctl directly for the description

#

the HTB hint is: Systemctl has an option to list particular units defined as "--type=<type>"

#

@potent moss any ideas?

potent moss
#

you could try --type=profiles???

rustic sage
#

┌─[user10381@htb-lh2hzpmdgb]─[~]
└──╼ $systemctl -l --type=profiles
Unknown unit type or load state 'profiles'.
Use -t help to see a list of allowed values.
┌─[✗]─[user10381@htb-lh2hzpmdgb]─[~]
└──╼ $systemctl --type=profiles
Unknown unit type or load state 'profiles'.
Use -t help to see a list of allowed values.
┌─[✗]─[user10381@htb-lh2hzpmdgb]─[~]
└──╼ $

potent moss
#

Hmm sorry - I don't have access to my HTB right now. I am pretty sure I used service for my command...

something like 'systemctl list-units --type=service | grep armor

rustic sage
#

okay, thx for the guesses

potent moss
#

You ssh'd into the target too right??

rustic sage
#

HTB Academy, Firefox vnc on the Target

potent moss
#

you have to ssh into the target IP with the login provided... htb-student or something?

rustic sage
#

i use the Spawn VM from the Academy with the "integrated" remote desktop

quiet vault
potent moss
potent moss
rustic sage
#

@potent moss
i am on the Target VM
htb-student@nixfund:~$ systemctl -l --type=service | grep "Load AppArmor profiles"
snapd.apparmor.service loaded active exited Load AppArmor profiles managed internally by snapd
htb-student@nixfund:~$

quiet vault
#

It's the hash not the actually password, you need to crack the hash first

potent moss
quiet vault
#

You're welcome

sinful jetty
#

Hey guys I'm doing the getting started module but have ran out of instances to use the pwnbox, is there some way I can continue doing the lessons by using my own kali linux to scan the attack machines in the lessons or can I only use the pwnbox provided?

lethal swift
#

Hi,
Sorry for this message but..
Where can I ask for help for a ctf?

drifting glacier
#

is it related to anything on HTB?

drifting glacier
#

strange, earlier today i was able to get user on the "knowledge check" machine in the starting point module, but now the metasploit script keeps failing at the authentication check

formal sphinx
#

Can someone help about "Getting started" module

maiden kiln
#

Hi, can someone give me a hint, I'm learning Network Enumeration With Nmap, in the section Service Section, I use nmap with the flag -sC and -sV but I found nothing seems like a flag too me

pearl nymph
maiden kiln
#

here is what I find

pearl nymph
#

then try to connect one by one to them

#

and then if you can't find the way then please search about it

maiden kiln
#

thank you for the hint

pearl nymph
maiden kiln
#

lmao I found it, also found another key for later section

late cedar
#

can anyone help me out with "Privilege Escalation"? (Getting Started)

late cedar
#

yea one sec

rustic sage
#

is it recommended to do tier 0 modules before moving onto easy HTBs or just the fundamental modules? Not sure how essential Ffuf will be when doing HTB (haven't used it thus far)

ancient oriole
#

Hi, could someone please give me a hint? I'm doing Cracking into hack the box, getting started module and I am at Knowledge check, the question is "After obtaining a foothold on the target, escalate privileges to root and submit the contents of the root.txt flag". The hint for this question was to run LinEnum or LinPEAS, I've used LinPEAS but found nothing interesting.

unkempt sonnet
#

i got the flag.txt contents on Public Exploits, but it wont accept it as an answer [Solved] = Certain misconfigured settings

unkempt sonnet
#

It is but idk what in, ive tried so many decryption things

ancient oriole
unkempt sonnet
#

it says hexadecimal

#

then i decode it

#

and it comes out with invalid characters

formal sphinx
#

Can someone help me about "Public exploits" section in "Getting started" module. I have problem finding right exploit. I can't use full nmap scan bcs it takes more than 12 hours, and there is nothing on first 1000 ports.

potent moss
#

I'm working on getting started - knowledge check. It's to crack the getsimple web page.

I've got the admin login and access to the page settings. I can't seem to figure out how to execute php or python code to gainshell access. I've tried several exploits on seachsploit but have not tried metasploit.

I wanted to manually try to figure it out vs using metasploit. Can anyone offer some guidance?

potent moss
formal sphinx
potent moss
#

You could also do a fast scan to see what ports are open, then do specific tests on the ports discovered vs all 65535 ports

ancient oriole
formal sphinx
#

@potent moss I ran scan on specific port and i know the version of wordpress (but i can't find exploits). And when i clicked on hint, it said "Search for plugin exploits" so it have to do something with plugin. I tried yesterday to find some plugin exploits, but everything i found didn't work.

potent moss
formal sphinx
potent moss
rapid bramble
#

Hi :^)/

potent moss
# formal sphinx 5.6.1

Check the site in your web browser for your target ip:port

You will see what you need to exploit there. It's not WordPress

formal sphinx
potent moss
#

Did you try metasploit?

drifting glacier
#

The way in for me was indeed metasploit, I feel like although they mentioned a manual way of doing it, it's a rabbit hole

#

Where I'm stuck is the priv esc portion

formal sphinx
potent moss
formal sphinx
#

@potent moss On exploit-db i found this as a soulution: http://127.0.0.1/<WP-path>/wp-admin/tools.php?page=backup_manager&download_backup_file=backup-2016-02-21-111047.tar But the problem is that i don't know file name.

ancient oriole
#

Can someone give me a hint for knowledge check in getting started module? The second question. I didn't find anything useful in LinPEAS.

rapid bramble
#

So you're stuck on enumeration? Could you tell us more about the output?

ancient oriole
#

I have netcat reverse shell on www-data@gettingstarted and have to get root shell

#

or I mean i have to open file with root access

rapid bramble
#

Alright, gimme a few.

#

I am pretty new myself.

#

Do you already have the user flag?

ancient oriole
#

yes

rapid bramble
#

Ok good

ancient oriole
#

I only found one file in LinPEAS, that was about saving passwords and there was location where they save passwords, but the location didnt exist when I tried to open it

rapid bramble
#

What box are you on?

#

I'll take a crack at it myself

ancient oriole
rapid bramble
#

The name of the module?

ancient oriole
#

getting started

rapid bramble
#

Trying to figure out the htb website myself, I have only ever really done reverse engineering.

#

But I'mma learn alongside ya

drifting glacier
#

anyone have the issue of metasploit working previously on the knowledge check machine, but not working the next day?

formal sphinx
#

@rapid bramble Did you finish "Public exploits"?

rapid bramble
#

Nope...

#

I literally joined yesterday. I'm not gonna bs you, I am exceptionally new.

#

However I have been taking notes and am a huge fan of John Hammond

#

Could you send a link?

#

Cause when I search for that, I get no results,

#

Do I have to pay for it? I'm on a free account.

formal sphinx
#

@rapid bramble Its in getting started module

pearl nymph
#

Hey guys i am in privilage escallation tab in getting started i got flag of user2 but now u can not understand what to do

drifting glacier
#

see if you have read access over a certain directory in root. the last portion of that section will show you the way!

#

@pearl nymph

#

and be very careful when copying over what you find, I was stuck for a bit trying to figure out the exact format

maiden kiln
#

Hi, I need help with the module Network Enumeration With Nmap, the final section: Firewall and IDS/IPS Evasion - Hard Lab . I tried many times to scan the target provided but still not find any flag, can someone gave me a hint?

#

I use this command: sudo nmap -sC -sV [target] -T 2 -D RND 5

maiden kiln
#

Can someone give me a hint? I stuck at this part for like 3 hours

lethal swift
#

Anyway thanks

rustic sage
#

Hello, I have a problem with the web request module, POST section. I log in as admin by changing the cookie, but the flag is still not there.

#

someone has an idea?

white basin
#

@rustic sage I’m having the same issue. So frustrating.

quiet vault
#

I had trouble with that one. Think of guest_... as an identifier

white basin
#

admin

forest wyvern
#

Hey guys. I'm starting out in HTB academy but i've come into a fundamental issue. For some reason in the Interactive Section with Terminal it wont let me spawn a new instance
when I try to start the instance is says
Error There are no available instances. Please try again later.

#

It says I still have a spawn that I can use today as well

#

Any help would be greatly appreciated. Thanks!

novel matrix
#

We are aware of the issue. Please be patient.

topaz zenith
#

Are targets acting wonkey again?

versed zealot
#

We are aware of an issue with spawning Pwnbox instances and are working on resolving it as soon as we can.

topaz zenith
versed zealot
#

Target systems may be affected, though the issue is intermittent and you may be able to spawn one successfully.

topaz zenith
#

I was able to spawn it. I just can't connect. I'm just trying to figure out if it's because of the issues, or because I'm a ignorant noob. 🤦‍♂️

quiet vault
uncut field
#

has the issue with instance spawning been resolved?

uncut ivy
#

how can i look up for the npm commands when it's not installed?

urban sage
#

Google. fingerguns

mint lava
#

@fallow mesa instead of != try to use NOT

fair narwhal
#

Hi everyone :). Im trying to find a .ovpn file in the academy to use, but i cant find it. There is a possibility to find it in website?, Or we only can use the pwnbox ??. Thanks (btw im in "Getting Started" module)

quiet vault
#

@fair narwhal

fair narwhal
#

But that doesn't appear

#

Maybe "Getting Started" module dont give vpn key

urban sage
#

If there is no VPN key provided the target instance will be a public facing docker container. You can access such without being connected to a VPN.

urban sage
#

No problem. Happy hacking!

topaz zenith
#

I'm running into a metasploit issue on the final portion of "Getting Started". Getting the following error:

"10.129.81.22:80 - Exploit failed [bad-config]: Rex::BindFailed The address is already in use or unavailable: (0.0.0.0:9443)."

The [bad-config] tells me that I'm probably doing something stupid, so I'm reaching out to you guys. Search engines are offering no good help.

quiet vault
#

Do you have a listener on port 9443?

topaz zenith
quiet vault
#

Metasploit has it's own listener

#

You can kill netcat, that's what's causing the issue

topaz zenith
#

ah, thanks!

quiet vault
#

You're welcome

plucky cave
#

hi

#

my name is lakshith and im new to hacking, anyone who can help me in here?

tough fjord
#

++academy

red obsidianBOT
tough fjord
#

Go to that and to the getting started module

plucky cave
#

ok

grand arch
#

Can anyone give suggestions on " What non-standard application is running under the current user? ( case sensitive)". I have tried all manner of Get-Service calls and have tried all running processes related to RDP or remote connections

#

ah Sorry, Windows Fundamentals Module, Windows Security section. Ty'

#

I have solved it. TY

late cedar
#

can anyone can help out? why is it the wrong format

novel matrix
#

@late cedar did you assign the correct permissions to the id_rsa

#

and is it priv?

late cedar
potent moss
#

Hey everyone. I'm working on getting started - knowledge check to escalate privileges.

I'm stuck on the sudo -l command and finding a way to upload an exploit shell.

I think I'm not understanding the sudo -l results or don't understand it enough. Or am I in the totally wrong direction?

drifting glacier
#

take a look at gtfo bins on how to use that binary to escalate

#

I'm following along the POST method section in the Web Request lab, but when sending the request to repeater, my cookie isn't showing the cookie as phpsession:

#

anyone else run across this issue?

white basin
#

You have the cookie.

drifting glacier
#

hmm, so i guess my next question would be why burp is showing it as auth instead of PHPSESSID

white basin
#

That I don’t know but you are on the right track.

drifting glacier
#

cool cool, thanks man!

white basin
#

You’re welcome.

potent moss
tight glen
tacit osprey
#

Hey dudes, please can someone give me a pointer with the first part of the skills assessment - website part of login brute forcing, i have brute forced both b.gates and m.gates users using personalised wordlist aswell as rockyou word lists but still no luck

ancient oriole
#

Hi, i'm doing the linux fundamentals module - Find Files and Directories, I cannot find this answer. I tried all of those commands, but I still cannot find it. What am I doing wrong?

white basin
#

Read the question more carefully

ancient oriole
#

yes

ancient oriole
late cedar
#

wtf am i doing wrong

quiet vault
#

What module is it?

late cedar
#

Setting Up

#

last section

ancient oriole
#

||add "s" at the end||

late cedar
#

thanks

ancient oriole
#

np

late cedar
#

btw ig you should mark that as spoiler

ancient oriole
#

i did it, thx

copper vine
#

.

rustic sage
#

I don't get it

quiet vault
#

You can see the different sections of the module you are doing on the left

rustic sage
quiet vault
#

That is the name of the current section

urban sage
#

It's listed on the side bar of the page.

#

There should be a button to spawn pwnbox.

urban sage
#

No problem. Just takes time. Reading everything really helps.

topaz zenith
#

Some sections have the cubes icon, but they don't offer any questions at the end to earn any. Is this just a bug, or am I missing something?

ancient oriole
#

Isn't there optional question? Or idk what is it called.

slate arch
topaz zenith
#

Does that earn cubes? If so, how do I know I've earned them?

slate arch
#

They dont earn cubes

umbral arrow
#

Hello everyone, I want to ask you, have you had any problems with Foxy Proxy on firefox and Burp suite in the pwnboxes recently?

#

When I open firefox, it appears as disabled and I have not been able to get it to work properly 🥲

rapid bramble
#

I don't use the pwnbox, I just installed the OS to its own drive. They've been acting wonky lately.

#

In the long run I think that is better.

brittle spoke
#

Could you please tip me off as well, I finally got the flag, but to be honest not sure why I had to do what I did to get it 🙂

rustic sage
#

anyone having issues with the SQL Injection Fundamentals lab? I'm in the last page. But the spawnbox is really slow ( i think it cant load from googleapifonts.google.com ) but doing the attacks from my own kali box will result always in this.

urban sage
#

Can you curl the page maybe? Double check it's going to the right place.

muted mist
#

Hi people!
Does anybody face issue with FoxyProxy in the Web Requests module/"Request and Response" page? FoxyProxy is disabled in Firefox and it doesn't have Burp in it's list like in tutorial described.

rustic sage
#

i did have this with every challenge btw

urban sage
#

It's possible that your input is making it unstable. 🤔

rustic sage
#

i was thinking about it aswell , but that doenst explain why in the spawn-box the same input does work correctly

eternal elk
#

i'm really stuck on getting started:Privilege Escalation

#

any tips for how to escalate to root?

#

currently trying to use sudo -u user2 /bin/bash -c

#

but i think i lack knowlege somewhere

drifting glacier
eternal elk
#

thanks will do

wicked wolf
#

can someone help me understand how apply the robots.txt method to solve this Web Enumeration question?

fair narwhal
wicked wolf
fair narwhal
#

For example, in the section explanation, when it do the gobuster, it appears a /wordpress, and it visit its page 👀

wicked wolf
#

what am i doing wrong

fair narwhal
wicked wolf
#

i changed the target IP in the example to the target IP we are supposed to target

fair narwhal
#

mmm weird, i did the same and it works

wicked wolf
#

maybe the file location

#

are you adding the port number or just the IP

fair narwhal
#

both, ip and port

#

with the http too

wicked wolf
fair narwhal
#

yes

fair narwhal
wicked wolf
#

yep

fair narwhal
#

you write the flags correctly?

#

dir -u for ip:port and -w for .txt location?

wicked wolf
fair narwhal
#

it works for me

wicked wolf
#

Keeps giving me an error and saying unable to connect

fair narwhal
#

Mmm weird sadglas

fair narwhal
#

Sorry, i dont know why you have error, but i wait too if someone knows why

wicked wolf
#

thanks for trying!

#

can someone explain why im getting an error?

white basin
#

Can you ping the machine?

wicked wolf
white basin
#

Are you connected to the vpn?

wicked wolf
white basin
#

Oh you’re doing it the the instance

#

Through *

#

Hmmm

wicked wolf
#

your not supposed to do it that way lol

white basin
#

Try running it with -v see what errors if any come back

wicked wolf
#

i cant even get a ping response...

white basin
#

Huh. Strange

muted mist
#

sorry, guys. Does anybody know why FoxyProxy does not contain Burp in the list? And it is kind of "disabled"?

maiden kiln
scarlet finch
#

and then configure manually the proxy in firefox in settings

pearl nymph
#

Hey guys

#

i am in nibbles lesson right now in getting started module.... i can not get that how they found out that site is enabled blacklisting protection for avoiding brute-force attacks??

#

hoe they got to knwo this?

#

know*

deep wave
#

Hi, so I used searchsploit and msf to search for plugin related exploits as hinted on this Public Exploits module, and the plugin based exploit requires a wordpress username and pass.. which I've been trying with no luck to get on this particular module. Is there something I'm missing, or I am perhaps not using the right exploit?

pearl nymph
#

Guys I aqm getting one new issue

#

i can not get my reverse shell in netcat after adding php payload in my image plugin and browsing it on firefox....it reloads nirmally but not showing anything

#

or not giving any listening port to netcat

modest vector
#

Yo guys

#

In the Getting Started module, they ask me to do this

#

add a DNS Server such as 1.1.1.1 to the /etc/resolv.conf file.

#

as part of DNS Subdomain Enumeration

#

But the file is read-only

#

How should i edit this file?

quiet vault
#

You can use sudo to run any command as root but you shouldn't run any code you don't trust. To use nano to open and edit it would be sudo nano /etc/resolv.conf

#

use ctrl-s to save and ctrl-x to exit

modest vector
#

ay thanks

#

it worked

#

I tried the same thing but with vim

#

It didnt allow me to edit it though

odd iris
#

Hello I just joined the server and I have no prior hacking/coding experience! I completed the verification and made an account on hackthebox. Does anyone know how to identify the os system flavor (I don't even know what that means lol)

quiet vault
#

What module are you doing?

odd iris
#

I think it's the introduction

#

It's this question

#

I put in the command it said to but I don't know how to read it 🤷‍♂️

quiet vault
#

Linux flavors tend to have a name that is easy to remember. If you look through the output there are only a few actual words. One of them will be the flavor name

odd iris
#

ok

#

I'll try those words then

white basin
#

Also the man page is helpful. If you type man uname it will break it down for you. And also give you a switch for just the os.

odd iris
#

man uname?

quiet vault
#

@odd iris definitely look at the linux fundamentals after you have finished this module

quiet vault
white basin
#

Man being short for manual. Built in to linux. Has documentation for the commands. And I sencond the Linux fundamentals module.

odd iris
#

Is the linux fundamentals on hackthebox?

quiet vault
#

Yes

#

It's definitely worth taking notes on the commands and what they do.

odd iris
#

Ok

#

Thanks for your help!

#

Will try the module now

#

@quiet vault Thank you!

quiet vault
#

Just click the little cirlce icon next to the ip address

short jungle
#

how do i find terminal in the second modual

#

im very new to hacking and my coding backround is just css html and bits of python

#

nvm

late cedar
#

did you find? @short jungle

short jungle
#

yes i just didnt read carfully enough lol

muted mist
uneven breach
#

the academy is wack only letting spawn one instance a day lmao

modest vector
#

Use your own vm

drifting knoll
#

@odd iris pls be careful with spoilers

odd iris
#

?

#

what did I spoil?

odd iris
quiet vault
#

A virtual machine. It is basically a computer running as a program inside your computer

#
How-To Geek

Virtual machines allow you to run an operating system in an app window on your desktop that behaves like a full, separate computer. You can use them play around with different operating systems, run software your main operating system can’t, and try out apps in a safe, sandboxed environment.

modest vector
#

bros this machine is minfucking me

#

Getting Started

#

Public exploits

#

I dont wanna spoil it for anyone

#

so id rather dm my query

modest vector
#

solved with the help of @ancient oriole

rustic sage
#

Is there a way to do every module without paying?

#

Idk where I would ask this question but it is something I am interested in

ancient oriole
#

No, but you can get all tier 0 modules free.

rustic sage
ancient oriole
#

np

brittle spoke
#

Im on the Web Applicaiton layot section within Introducing to Web Applicaiton module - Could someone clarify what is the difference between client-server and One server models cuzz I didnt see the difference?

rain juniper
#

you guys have any tips for a slow ssh connection?

#

i can't get anything working as it suddenly freezes every once in a while

#

tried reinstalling the vpn but its still freezes a lot

fickle axle
#

opinions on the Stack-based buffer overflows with Linux x86 module

drifting glacier
#

this hard lab in the nmap module is a doozy. I think i finally have a combination that won't get me banned, but the hour might pass without results being returned smh

modest vector
#

Im stuck in Privilege escalation in the Getting started module

#

Im supposed to ssh into a server

#

Im stuck with the ssh code part

#

dm if you could help

#

thanks

drifting glacier
#

anyone available for the hard module for nmap? i've discovered the new port, but attempting netcat for version info will not work, connection just times out...

wet schooner
muted mist
#

Hi guyz. Want to clarify some point. Is author suggests to change interfreight.com to 127.0.0.1 in Web Requests Module/ GET method ?

rain juniper
#

I dont think so

#

once you click on spawn it will give you a IP at the bottem

#

something like this

#

you can then use that link

muted mist
rain juniper
#

👍👍 glad it worked

modest moth
#

so i am currently on the getting started module and im in the last section. I have ran a directory scanner and found a login page but it simply just wont load.

ancient oriole
ancient oriole
#

Hi, can someone tell me what am I doing wrong?
Introduction to networking - Subnetting

harsh pine
#

In case you want to learn more about subnetting, and a very easy way to solve subnetting problems, I highly recommend this series: https://youtu.be/BWZ-MHIhqjM

And also the channel in general for more about networking

This video will teach you the basics of subnetting. Every Subnetting problem will ask you to solve for one or more of seven possible attributes: Network ID, Broadcast IP, First Host IP, Last Host IP, Next Network, Number of IP Addresses, and CIDR/Subnet Mask conversions. This video explains what each of the attributes are.

What if there were a ...

▶ Play video
ancient oriole
#

Thank you 🙂

modest moth
maiden kiln
#

Can someone give me a hint about the second question of Skills Assessments : Website in the module Login Brute Forcing? I just need a hint of username

modest vector
#

Getting started, Privelege escalation

#

I'm stuck

#

why am i asked to input a password, I already tagged the key

urban sage
#

I haven't done that module but the key could be being rejected for some reason.

maiden kiln
maiden kiln
#

maybe it could help

modest vector
maiden kiln
modest vector
#

tell me abt it, ive been stuck for around 24 hours now

maiden kiln
#

I do the same like you

#

copy root 's key

modest vector
#

exactly

maiden kiln
#

here is how to do it when you got the key

modest vector
#

solved with the help of @maiden kiln

maiden kiln
unique valve
ancient oriole
#

I've already solved it, but thx anyway, maybe i will use it next time 🙂

unique valve
#

Does subnetting make sense now?

ancient oriole
#

Somehow yes

unique valve
#

Its a good skill to have. In my personal opinion it is most important to be able to look at the ip address and subnet of 2 or more devices and tell whether or not they are on the same network or not.

blissful mortar
#

is it bad to be using the walkthroughs for boxes if I'm just learning how to do all this

quiet vault
#

I guess it would depend on whether you can learn that way. The module getting started walks you through a box then has another for you to do by yourself. I know someone has recommended watching ippsec do a box then attempt it. (ippsec has a youtube channel where he goes through some of the boxes)

blissful mortar
#

i'm using it to learn what things i even need to google 😅

#

getting started seems like a good place to learn from

#

is that different from starting point?

quiet vault
#

Have you gone through some of the academy modules? They'll give you an idea of the sorts of tools to use and the process of hacking the box

blissful mortar
#

i haven't! but thats a good idea

#

i just jumped straight into ARCHETYPE

quiet vault
#

Starting point is a collection of 'easy' machines on htb, academy is interactive lessons on different aspects that talk you through something then have a few questions for you to practice what you just read

blissful mortar
#

that seems like a lot more of what I'm looking for

#

since for each step in the archetype walkthrough I had to go on a long google search to figure out whats going on

quiet vault
#

Look at "Introduction to Academy" first then I would recommend "Linux Fundamentals"

blissful mortar
#

yup! just pulled it up

#

tysm :)

#

excited to be learning

quiet vault
#

You're welcome

unique valve
#

@blissful mortar the cool thing about academy modules is they are really well written writeups & lessons with challenges throughout. They provide detailed guidance. Its good that you are referencing writeups during boxes, dont feel guilty about that :). Try to challenge yourself occasionally to get it without the writeup until you are right on verge of giving up then reference the writeup for motivation.

blissful mortar
#

yeah! they seem like a lot more of what i was looking for in coming to hackthebox

#

thanks for the advice :)

#

this seems like such a nice community

unique valve
#

It is. Lots of talented, gifted and caring people here.

blissful mortar
#

:)

#

it's nice that academy has it's own built in linux instance

#

don't have to switch back and forth between my vmbox now

unique valve
#

Yes absolutely. Keep in mind that when connecting to that pwnbox you are on a remote network, when you launch the target boxes it spawns another computer that your pwnbox can communicate with. Ive personally found it easier to use the pwnbox in full screen mode while reading the content on another monitor, tablet screen or smart phone screen.

blissful mortar
#

good to know! ty

#

is there any easy way to paste into the pwnbox?

unique valve
#

Yes theres a clipboard. Its a little easier in Windows to copy and paste directly into pwnbox. On most other OSs you will need to use Pwnboxes’s clipboard. It is a couple extra steps but faster than manually typing the commands.

quiet vault
#

There is a clipboard icon in the bottom right of the screen

blissful mortar
#

ty!

modest moth
#

||follow up to the getting started module "knowledge check" section. It still simply doesn't load the /admin directory i found. This is extremely frustrating, i just want to make sure i understand everything in this module. I am a completionist and really want to finish this module. Anyone know a work around or is this just how this box is? the admin page never loads.||

#

^ follow up to my previous problem.

quiet vault
#

@modest moth Pm me

red heath
#

hello

modest vector
#

whats up

severe moss
#

im trying to get the privilege escalation on the "Knowlege Check" of the "Getting Started Module" im in the server as normal user, but im not able to get the privilege escalation...

#

can anyone help? 🙂

heady shadow
#

This is from the "Introduction to Windows" of "Windows Fundamentals". I got the Windows version using the PowerShell and CMD. But I'm unable to understand in which format I've to type the answer. I've tried multiple times but it is not working. Can anyone help please?

quiet vault
heady shadow
sage relic
# severe moss can anyone help? 🙂

as stated in the hint, use LinEnum to find for vulnerabilities, keep note at what sudo privilege do the user possess.
then try a specific method taught in the privilege escalation part 🙂

pearl nymph
#

hello

#

i a getting disconnetced with vpn often in knowledge check lesson

#

can anyone have solution?

modest vector
#

I assume this is a human mistake where the code executed is supposed to be "curl" rather than "url"

tight glen
muted mist
#

Hi ladies and gentlemen!
I've a question regarding Web Requests/POST. In the challenge I have to get admin user from guest account by manipulating with cookies. Is the main point of it to decode gifted to guest cookie and change username key in it and then put it back to GET request to /admin/dashboard.php? If it so, I don't understand what exactly I have to provide in "Submit answer" field. If I'm wrong about solving it, could you give a hint?

modest vector
#

play with the cookie

#

maybe try deleting some characters here and there

muted mist
# modest vector play with the cookie

If the cookie is unique to every user's session, so how it can be faked to convert session of user A to session of user B? Maybe I don't understand the core concept of all this stuff

modest vector
#

each account has their own cookie, storing data related to the account holder

#

think of it as a locker room in school

#

the website gives you a locker room linked to you

#

whenever you go back to the website you open your locker

#

your locker number wont change

muted mist
#

Ok, so ... I have to get access to locker of my classmate in that case. I go to my locker, open it with my locker number and then ...? What should I do to switch lockers?

modest vector
#

find the admin's cookie combo

#

for a better understanding of cookies

muted mist
#

Thank you, I will check

modest vector
#

anytime

pulsar elm
muted mist
# modest vector https://www.youtube.com/watch?v=xdH9zsW1CK0

I've figured out that cookies is set by server to the client and identifies client session or whatever it's data. It's clear. But the crucial point is that cookie is set by the server to authorized client. I mean, if I'm the 'guest' so I will have only 'guest' cookie. Of course, I can pretend to be someone else, but it seems to be useless, because in order to get 'someone else' cookie I need to authorize with his/her creds. For me it is a kind of logical trap or loop.

white basin
#

@muted mist don’t over think it. Think simple.

severe moss
severe moss
#

I got it.... it was so simple... i was thinking way to complicated... xD

rapid bramble
severe moss
rapid bramble
#

I'm not afraid to be stupid

#

It's more fun that way

strong drift
#

I'm a bit confused on the getting started module. It is telling me to type in what service is on port 8080 and I believe I am imputing it correct, but it is telling me I am wrong

#

Also for the question about locating what port telnet is on. I am scanning all ports but there is no open port with telnet

white basin
#

@strong drift you may have to stop and restart the machine. I was having issues mainly with nmap scans and that usually resolved the problem.

strong drift
white basin
#

Aah good.

slate zinc
#

wow u guys are all like me

#

i use parrot as daily

outer otter
#

Hello boys and girls, a quick one please: in the fuff module, the "Parameter fuzzing - GET". This is the question I'm getting. I ran a parameter fuzzo n this page and also on pretty much every other page on the website (after fuzzing for directories) but every parameter gives me a 200 result. What am I doing wrong? I feel like something is missing, thanks in advance

#

nvm I think I just found out. Man the explanation of how to access the correct page is not clear at all, let me just say this 😛

modest vector
#

Im tryna get a foothold in the nibbles machine as requested in the getting started module

#

I'm tryna use the msf exploit

#

but it's unable to upload the payload

#

any potential remedies?

blissful mortar
#

hi! I'm doing the linux fundamentals and I'm trying to get the number of installed packages on the system

#

I want to know why apt list --installed | wc -l

#

isn't giving me the right answer

#

i know it's wrong but I don't know in which way it's wrong

#

maybe it's b/c I'm only looking at packages installed through apt

urban sage
blissful mortar
#

dpkg gives another 10, but thats still wrong

#

adding snap packages might be it

#

hmm no

#

dpkg-query -l | wc -l
doesn't work

#

maybe I'm looking at this the wrong way entirely

drifting knoll
#

@blissful mortar check the output manually and make sure you wc is counting the packages only

blissful mortar
#

oh! ty!

#

it looks like it is?

#

well hmm

drifting knoll
#

^ solved

tough dust
#

Uh

#

I'm doing Linux fundamentals

#

It asks to use systemctl to name one of the units with a description but when I supply the name of the unit the answer is wrong?

#

Idk of I'm missing something or what

late cedar
#

in which part is the question? @tough dust

tough dust
#

Nevermind

#

Figured it out

opaque marlin
#

can i leave my pwnbox on or does it terminates by itself in a period off time?

covert rain
#

Hey there, I am kinda having trouble with a question in Linux Fundamentals

#

the only file I could find doesnt match the criteria 😞

urban sage
#

Please don't post spoilers. :P

covert rain
urban sage
#

Even if it did, avoid posting them. The point of the modules is for people to learn. If they can click block of text on Discord it kind of defeats the point. That said, I've noted the comment about the size being incorrect. I'll see if I can get someone to check into that.

covert rain
#

@urban sage do u want me to remove this too?

urban sage
#

Yeah. That would be good. And no problem. I appreciate you bringing it up.

urban sage
marsh hollow
#

someone here for Fuzzing Parameter Overflow Windows, plz dm

rustic sage
#

Hello wonderful people

So I'm stuck on module 35 on the POST method. The goal is to login with guest credentials and go to he admin then submit a flag. I'm unable to do so. Could you please help me? Thank you

#

Ping me when you answer please

modest vector
outer otter
#

Yes I did

rustic sage
#

If anyone stuck in Getting started module , PM me!!

crisp rampart
#

hello

#

any onne there

white basin
#

Yep

tacit osprey
#

hey, who has completed the login brute force section

simple cape
blissful mortar
#

i feel like I'm doing everything right in connecting to the vpn but I'm still having problems even pinging the targets

simple cape
#

For me it helps to re-dowload the vpn file and removing the old one.

blissful mortar
#

yeah just did that

simple cape
#

See if it helps out.

#

No luck?

blissful mortar
#

sadly

#

the vpn says initialization sequence completed also

#

so that sounds like it's working

simple cape
#

Had it yesterday on the linux buffer overflow that I was not able to ping or connect to the box either.

simple cape
blissful mortar
#

hmm

#

maybe some problem in their network

simple cape
#

Could be.

Also make sure you don't have any specific firewall rules that might be blocking traffic to the boxes.

blissful mortar
#

yeah thats a good idea to check again

#

it had been working earlier tho so idk what would have changed

#

is it maybe different that this target came with a specific port?

simple cape
#

Also depending on what lab your antivirus might be in your way.

For me requesting /etc/passwd from fileservers had the ip / request blocked by my ip

#

Took me a few hours to figure out my AV was blocking it.....

blissful mortar
#

I'm doing the getting started academy one

dull orchid
#

guys, i've a question that's struggling me, on PUBLIC EXPLOITS sector in GETTING STARTED module there's this question "Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)

#

the service running on that port and url is simple backup plugin 2.7.10 but the exploit is for simple backup plugin 2.7.11....is this good ?

quiet vault
#

Generally if a version is vulnerable older versions are also vulnerable

dull orchid
#

ok...

#

i found a file...it seems the flag.txt

#

but it has a long name.....anyway i opened it and i found all the etc/passw directory inside...

#

what's the real content the question ask to me ?

#

try to get the content of the '/flag.txt' file.

#

but the content is huge !!!! Maybe i wrong something : or the exploit or the flag file

quiet vault
#

I think there should be a file in the root director called flag.txt (/flag.txt). The contents will be something like HTB{h@ck_Th£_B0x}

dull orchid
#

in the root directory of the target machine ?

quiet vault
#

Yes

dull orchid
#

i could not access to it

#

maybe i wrong setting the exploit...

quiet vault
#

Do you have a remote shell?

#

The exploit you use doesn't matter. You want to get a shell regardless of the exploit used

dull orchid
#

no i didnt have a remote shell

#

it told me the host is scanned completely but i didn't have anything..............

#

have i to write the exact path in the " FILEPATH" section ?

quiet vault
#

Once you scanned the host you need to find an exploit that would work. Work out how to use the exploit to get a shell on the machine

dull orchid
#

the default is "etc/passwd"

#

i did not get a shell

#

so i've to set the payload ...imho

#

Module options (auxiliary/scanner/http/wp_simple_backup_file_read) ----this is the exploit

#

it means that can read a file...in the path i give to it

quiet vault
#

You want to set the the FILEPATH to be /flag.txt

dull orchid
#

OMGGGGGGGGG

#

I CANNOT BELIEVE...ahahaha

#

i setted the filepath wrong

#

it was : /root/simple-backup/flag.txt >>>>>>> instead of : /flag.txt

#

how they could make such an error like this ? the plugin talks about a directory called : simple-backup inside the root dir....anyway i did it ! Thanks a lot and good night

worn ridge
#

This might be a silly question but the number after the colon in <target>:<#> is the port of the target, correct?

quiet vault
#

Yes

worn ridge
#

I think i need some more... In depth help with the getting started module if anyone is free to pm 🤦‍♂️

#

Actually possibly the same part you were talking about above, which i will skim, but still doesn't solve my general problem which i think is just a lack of understanding i need to talk my way out of

glad notch
#

struggling with the medium IDPS section of the HTB academy.... can anyone help please. Im really unsure how i can have the port not show as not filtered.

glad notch
#

i got there in the end, but thankyou!

wet schooner
edgy kite
#

Module: Web Requests
Section: Post Method

Guys, I am stuck on it. Any clue is welcome
||
The response contains no PHPSESSID cookie, but an auth cookie and the /admin/dashboard.php just print anything base64 encoded in the auth cookie with anything inside html tags stripped.
||

white basin
#

Think super simple.

edgy kite
#

I think I may be too smart for this that I don't know what to include in the answer box

edgy kite
#

I really think that the answer is misleading for a task that just want you to train cookie manipulation

||Just changing the cookie from guest_<..> to admin_<...> should have returned the flag, the current answer make it more a guess than a task||

worn ridge
#

@mint lava offered to help me earlier but i don't think he's around anymore if someone else is available to help on getting started

white basin
#

@worn ridge what’s your Question or what do you need help with?

worn ridge
#

Anytime that i try to run nmap on a target it tells me that the host may be down and anytime i try netcat, it just hangs

modest vector
#

are you connected to the vpn?

worn ridge
#

I don't think there is one for that module cause it usually has the download link if it is

#

Err not module, but section

#

It happens in the pwnbox also

modest vector
#

anything to do with scanning or htb machines need a vpn

#

theyre on their own network

#

not the internet

worn ridge
#

Okay well i get the same thing when i open the virtual instance on site as well

modest vector
#

The Getting started module has a page for common pitfalls

#

VPN issues are included

#

check it out

worn ridge
#

So that just seems to tell me how to change my VPN stuff when I'm on the actual htb website, but it still doesn't help with academy. It just tells me how to change my VPN if I'm on the main site

worn ridge
#

I got it, but i didn't need to be on a VPN. I just needed to visit the IP in a browser

rustic sage
#

So I've got to the admin panel on the task from module 35

#

Now what should I put in the answer Field?

#

ASAP help needed

#

Ping me please

modest vector
rustic sage
#

POST method@modest vector

modest vector
#

everyone is getting stuck there

#

modify the cookie

#

try to make it show "welcome admin"

#

not "welcome admin_fn3h3489rh34fi34n" nor "welcome guest_doeffrfrfef32..."

rustic sage
#

Then what?@modest vector

#

What am I supposed to give as the answer?

modest vector
#

in the response tab you will see a flag

rustic sage
#

Owwwww

#

Thanks @modest vector

modest vector
#

anytime

edgy kite
#

Every other host is unreachable and will be down

dull orchid
#

i usually use as best performing state these options : -sC -sV -A -Pn

kind geyser
#

can i have some help for the academy privilege escalation

#

for the second part of the challenge getting from user2 to root

#

i feel like it's something to do with the id_rsa file but i have no idea how to use that

flint moth
#

@kind geyser dm I can help

torn sonnet
#

hey could someone help me with this i put right version but somehow it not accepting it

white basin
#

Take the hyphen out maybe

torn sonnet
grim scarab
#

Can you show me the scan result

torn sonnet
white basin
#

Reset the target and run nmap again

kind geyser
#
[-] Handler failed to bind to 0.0.0.0:1234:-  -
[-] Exploit failed [bad-config]: Rex::BindFailed The address is already in use or unavailable: (0.0.0.0:1234).
[*] Exploit completed, but no session was created.```
#

i'm getting this error trying to do the nibbles box

#

using the exploit

#

i've got a listener on port 1234 on my ip

#

everything seems to be done as it should be

#

but it still isn't working

rustic sage
#

Hi I have the same problem as @torn sonnet I reset the target and re-run nmap but the service name is still http-proxy

white basin
#

What module are you doing @rustic sage

rustic sage
#

getting started

white basin
#

I don’t remember what scan I ran to get the answer. Probably-A and -vv

#

You need to enumerate that port more and get as much info as you can @rustic sage

rustic sage
#

Yeah, you have to give the name of the service of this port ?

white basin
#

Yes. But it’s not http proxy

rustic sage
#

OK thank you I just understood the question and I found it thank youuu

white basin
#

😎

abstract hollow
#

@ebon wigeon

grim scarab
#

Anyone?

#

Do I have to submit the admins cookie?

wet schooner
grim scarab
#

I had been stuck for an hour

strong drift
#

So I am finishing up the getting started module... I was wondering if anyone had any recommendations on which courses I should take next?

white basin
#

@strong drift basic tools or web enum

winged sluice
#

Somebody can help me with this? idk what i need to do exactly

wet schooner
strong drift
#

How do you copy a file from an ssh connection to your local machine?

quiet vault
#

Look up how to use scp

mortal lichen
#

I have subscriptions at INE (eLearnSecurity) and LinuxAcademy, and HTB Academy is hands down the most interactive and engaging one. Good job guys!

muted mist
#

Hi people.
Can somebody tell me where can I get the password for spawned vm (not target machine) in the Linux Fundamentals/Service and Process management page?

mortal lichen
twin solar
#

Hi y-all, I'm currently doing the Linux Fundamental Module, Section File Descriptors and Re-directories. I'm stuck at the How many total packages are installed on the target system? question.

||I am using both dpkg and dpkg-query to find/list the packages and wc to count all the outputs, however, I still getting an incorrect answer.||

#

Any help/advice would be appreciated? 😁

mortal lichen
#

ah no, a different one regarding listening processes

#

i misread, my fault

#

for that one, you may want to use the package manager, and list the packages

#

if you read the man pages, there might be a parameter to list the packages, and in your case you can specify to list only the ones which are installed

twin solar
mortal lichen
#

you are very close with the approach you followed. You just need to filter out the result a bit

#

Did you get it, @twin solar ?

muted mist
mortal lichen
distant oxide
#

Can I DM someone about the web module? About sending a GET request to flag.php

mortal lichen
#

Is it a requirement for the module?

muted mist
mortal lichen
#

this is the task I get. Is it the same?

#

in "Service and Process Management"

muted mist
mortal lichen
twin solar
mortal lichen
twin solar
rustic sage
#

Hey guys! I was just wondering whether its good to start using Parrot OS to do HTB Academy courses or stay with Kali Linux which I'm using now

mortal lichen
ebon wigeon
#

@abstract hollow

west rampart
#

@rustic sage i deleted cause it contains spoiler

rustic sage
west rampart
#

no

#

you provided the answer

graceful prism
#

Can someone help me with the Services and Processes section? I've been stuck for about a week and I feel so dumb considering that I've been able to finish the Web Path. Please someone aid me, I asked this same question, literally no one replied. If someone can dm me, then that would be very much appreciated

#

TL;DR I need help with services and processes, dm pls

rustic sage
west rampart
#

You can

#

Just don't include the answer 🙂

strong drift
#

This might be a dumb question, but what does the word "enumerate" actually mean? I tried googling around for a concise answer, but I am still a bit confused.

astral crow
#

Anyone else having issues with the target ssh freezing for several minutes following each command?

rustic sage
#

A few months ago, though I don't experience it now

astral crow
rustic sage
# astral crow Did it just go away?

Well, its hard to say exactly. I didn't use HTB or my VM for a while so I forgot my password and had to create a fresh Kali installation. I'm not sure if that made it go away or whether it just went with time 🤔

astral crow
#

cool, ty

rustic sage
#

np

astral crow
#

this could be it since others on my lan are using academy as well

sharp meteor
#

In pwnbox ssh user@10.10.10.10 hangs.
In my vm with vpn running ssh user@10.10.10.10 gives ssh: connect to host 10.10.10.10 port 22: No route to host

I'm not sure what I'm doing wrong. I have the vpn from https://www.hackthebox.eu/home/htb/access https://i.gyazo.com/4255ccc5c22d539490b47ac29148e02e.png

In pwnbox 10.129.0.0 10.10.14.1 255.255.0.0 UG 0 0 0 tun0 appears in netstat -rn
While in my vm none of the destinations are 10.129.0.0,

instead the 10.10.14.1 gateway is
10.10.10.0 10.10.14.1 255.255.255.0 UG 0 0 0 tun0

Does anyone know what trivial mistake I'm making?

white basin
#

Try a different vpn

jagged zenith
#

Hey

#

I need help for this question ⁉️

#

Moudel bash script

white basin
#

@jagged zenith well do you know how to creat a for loop?

jagged zenith
#

*** WARNING : deprecated key derivation used.
Using -iter or -pbkdf2 would be better.
bad decrypt
140671661004096:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:../crypto/evp/evp_enc.c:583:

#

Error

#

for i in {1..28};do var=$(echo $var |base64);done

viral orbit
#

I need to find out how many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only) Help plz?

white basin
#

@jagged zenith are you using mac?

viral orbit
#

oh wait nvm I got it.

jagged zenith
white basin
#

hmmm

jagged zenith
white basin
#

Yeah give me a few i will try and simulate

#

Well actually I can't

jagged zenith
viral orbit
#

I need to Determine what user the ProFTPd server is running under and I am SO stuck. Can someone PLZ help?

mortal lichen
viral orbit
mortal lichen
#

let me open up that challenge. Is it services and processes?

viral orbit
mortal lichen
mortal lichen
#

if you check the current running processes, usually one of the columns tells you what user is running each process. The point of the exercise is to filter that output so it shows you only the relevant one

#

in that module you will have been told about tools like more, less, grep, awk, head, tail

#

so if you concatenate the command to check current running processes with the filtering command (read Pipes on the previous module), you may obtain the desired output

viral orbit
#

*ProFTPd

mortal lichen
#

are you connected to the target machine?

viral orbit
#

ya

mortal lichen
#

one sec, let me run it

viral orbit
#

FOUND IT!!

mortal lichen
viral orbit
#

jeeez

#

the reason it wasnt working is because i used uppercase in my search

mortal lichen
#

yep

viral orbit
#

@mortal lichen als btw how do you search for partial words? like if there is a user listed as "proftpd", how do I search for "ftp" and "proftpd" still come up?

#

*also

mortal lichen
#

you can use regex for example

#

which allows you to define search parameters, like "starts with"

#

or "contains an unknown character in this position"

#

I believe you will see regex in following modules, in that same course

viral orbit
#

ok, thanks for the help 👍

mortal lichen
#

anytime!

#

you can "man grep" to find out more about the regex thing

#

in "Pattern Syntax"

mortal lichen
#

regex can help you in more complex situations like... instead of grepping ftp, you know between the F and the P there is a letter, but you don't know which one, so you can define a wildcard in that specific character for example.

viral orbit
#

ok, I see

charred stream
charred stream
#

naughty parents, there supposed to be encouraging. humph!!!

viral orbit
#

Ok so I'm stuck again. "Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer." is SO hard. can someone plz help?

mortal lichen
maiden kiln
#

Hi, I'm on the Skill Assessments of Attacking Web Application with ffuf and I'm stuck, really need some hint

#

Can anyone give me some advice?

rustic sage
#

where it goes ?

white basin
#

@rustic sage it will be on your computer

rustic sage
#

yes I just found it in /home/ while I was looking for it in the download

#

th😋

white basin
#

Yeah if you don’t specify a directory it goes to /home

young sleet
#

hey i'm new here! and i'm stuck at a particular question from Windows Fundamental Module. anyone who could help me

#

i tried looking for guidance under the htb forum and tried all the methods kept case sensitive answers in mind but there's something i'm missing

pallid yacht
#

Hi team, when using NMAP, we can identify if ports are being blocked on the firewall at the destination. However, when issuing an NMAP scan at the source, how do we identify if a firewall at the source could be blocking? This would effectively fudge results, because whereas the ports might be open at the destination, they could be getting blocked by the firewall at the source. Therefore, how do we identify the list of "allowed" ports at the source using NMAP. Hope my question is clear. Thank you 🙂

wet schooner
surreal rain
#

Out of curiousity, who all have done the LDAP module. Have you used the knowledge on a machine or real engagement

fair coral
#

Hello, someone here who also hates Windows?

#

On HTB

tacit osprey
#

Hello dudes, i am currently on the Brute forcing section, skills assessment - service login, seconds question, i have brute forced ssh for the first question then used the wordlist on the server as advise to brute force the second user to no avail, please can anyone point me in the right direction

mild hamlet
#

@everyone Hi guys, I'm not looking for the answer but perhaps someone can give me a clue. I am currently using HTB Academy and I'm on the POST method section. It wants me to login to the guest account and manipulate the cookie to gain access to the admin account from there. I managed to manipulate the cookie and elevate but I have no idea what to submit as the answer. I have tried submitting the cookie itself.

jagged zenith
#

Hey guys please 🥺 please i need help you

#

Moudel bash script

rustic sage
#

Module : getting started , chapter : public exploit

I have tested a lot of exploit with the keywords apache, tomcat, wordpress but I can't find the right one

white basin
#

what does nmap show?

analog folio
#

Hello, I'm in the "Intro to Assembly Language" course and I'm on the skills assessment, "loaded_shellcode" question. I know that I've properly decoded the xor'd shellcode because when I run the shellcode using pwntools, it pops a shell on the system. But after pasting the shellcode into the form to submit the answer, it doesn't do anything other than the Submit button darkens. I've tried with both Chrome and Firefox browsers.

jolly glen
lunar sierra
#

can someone give me a hint on the easy machine Cap

#

i am stuck

west rampart
wet schooner
rustic sage
tribal linden
#

Has any one done the windows buffer overflow module and installed x32dbg localy?

analog folio
# jolly glen i haven't done that module yet, but on other modules usually the copy-paste does...

I heard back from support this morning. Evidently I needed to submit a flag, not the shellcode. It's confusing because all of the course submit buttons have a flag icon on them, but some exercises require submitting a flag, and others shellcode, and others are specific numbers or other found in the debugger. That question didn't say what to submit, only that you are to edit the code to recover the shellcode by xor'ing the values on the stack with the key. It doesn't tell you to submit a flag. I was thinking that my shellcode was correct because it pops a shell character "$" when you run it using pwntools, but then I later discovered that even faulty shellcode results in that output when run with pwntools.

frank vigil
#

has anyone completed + confident on the FFUF module. im stuck on the Filtering Results part...

west rampart
#

@tribal linden what's up

#

@frank vigil think I did it

frank vigil
#

correct me if i am wrong... if had a list of results with a HTTP response size of 798 after running a ffuf command, by using -fs 798 would this show me every result apart from the ones with a response size of 798?

white basin
#

No

#

Ls list directory contents. For file specifics use grep.

hasty iris
#

I’m doing the JavaScript deobfuscation. The first section titled source code. Now I’ve found the flag after using jsnice however it keeps rejecting my answer. I’ve retyped it, copied and paste it multiple times even restarted the machine as well thinking something was going wrong. Has anybody have had my problem before or is it just me?

wet schooner
hasty iris
wet schooner
hasty iris
hasty iris
hasty iris
wet schooner
#

Ignore the secret.js for now

hasty iris
#

Oh okay

wet schooner
#

Navigate to the IP ctrl÷U and have a read

hasty iris
wet schooner
#

sure

#

Anyone that's done intro to bash scripting is it worth doing some wider reading first or does the module cover what you need to know?

novel yoke
#

Hey guys, I'm new to the HTB discord, I have ParrotOS natively installed on my machine and have no need for VM's or the Pwnbox, I can connect to the Starting Point VPNs to pen test machines, but I can't seem to get it working on HTB Academy, any links or info that might help?

wraith creek
#

Not all of the modules have the VPN key, but you only need it once.

#

Got mine in the "Getting started" module

#

Just pwned my first box kappa

novel yoke
#

@wraith creek Ok thanks, I'll look in the first module again and try to get connected. Grats on the first pwn!

wraith creek
novel yoke
#

@wraith creek I found it, thanks again.

wraith creek
#

Of course!

misty thistle
#

Anyone have time to give a hint on the fuzzing module? I am 99.9% sure I have the right answer but it's saying it's incorrect....

Edit: nevermind I'm an idiot. it said to USE port, not replace port -_-
Reading is hard apparently

marsh hollow
#

Hi someone here for Stack-Based Buffer Overflows on Windows x86 i stuck on bad chars, and i dont know why

tribal linden
#

@marsh hollow whats up, you can dm if ya like. im working on that module too.

brittle spoke
#

Hi all I'm on the "ATTACKING WEB APPLICATIONS WITH FFUF" Q3 "One of the pages you will identify should say 'You don't have access!'. What is the full page URL?" I did what the hint suggests and ran a recursive scan with a PORT instead of the actual port number from the target we spawn and no joy. Could someone give me a hint please?

tribal linden
#

@novel yoke I found the module pretty inclusive. the module gives you extra reading as you go along.

rustic sage
#

So I have this ssh key that I want to copy to a file on my pc to connect in ssh with this key. I would like to know how to copy it because with VIM I can't and I don't know the format

north rapids
#

did you just past a private key file ?

#

This never is a good idea to share private keys with anyone, anywhere

#

you should void your key pair now and regen new ones

rustic sage
#

yeah l'il do it

#

so how can I copy an ssh key on my own machine?

north rapids
#

your question isn't clear enough

#

where is the ssh key ? in a vm ?

#

and you want to back it up to your host ?

#

your host and your vm should be in the same LAN, you can simply open a port an your host and send a the file over nc for example, you can also used shared drives, smbshares, open up a simple http.server on your vm and fetch it through your host, the possibilities are endless really

#

you could exfiltrate it through DNS records, or eveng icmp ping packets 😛

rustic sage
north rapids
#

what

#

if it's a web server just drop the priv.key in the webroot, download it and then remove it from the webroot

rustic sage
#

Module : getting started
Chapter : privilege escalation
I found the key in /root/.ssh/id_rsa but for me to use it I have to copy it to my pc, so I do a cat id_rsa it shows me the key and I would like to copy it so I can vim id_rsa in my pc but I can't copy it in.

#

to do ssh user@ip -i id_rsa

north rapids
#

i haven't done the module but you can ssh to locahost from the box if you have file read on the root ssh key ?

rustic sage
#

in fact I found a solution I have access to the cat of the key but I would like to copy the content in my pc but when I do vim id_rsa I don't know how to paste what I have copied

#

well in the end I copy and paste them with nano

rustic sage
#

sorry for the offtopic question. do I need to have a separate account for HTB academy? I cant use regular HTB acc for the academy part of the site?

white basin
#

Yes you need a separate account for academy. And support should you have any issues. Its weird.

#

@rustic sage you can use curl to get files.

strong drift
#

Hey, so I am doing the Linux Fundamentals and am on the system information module. I am stuck on "what is the path to the htb-student" mail and "Which shell is specified for the htb-student user". I feel like I am typing in the correct answers, but it is telling me I am wrong.

hot stone
#

howdy 🤠

hot stone
strong drift
hot stone
#

Im guessing htb-student is a user on the machine?

strong drift
torpid ermine
#

anyone please give me an nudge in the broken authentication skill assessment

hot stone
#

send a picture of the full page man

#

@torpid ermine

torpid ermine
hot stone
#

so you're having trouble with the privesc gotcha

#

well. im assuming you have spawned the target right?

#

id be happy to give you a fresh set of eyes. i just need to know where you are on the box yk

strong drift
# hot stone hmm. idk

Yeah idk and the system is clearly using bash but it's not accepting that as an answer

white basin
#

@torpid ermine have you reset the target? Sometimes things don’t load.

storm berry
#

Edit: Solved. I was not using the correct download zip. This is what you should be running:

hcxpcaptool -z pmkidhash cracking_pmkid_question2.cap

I'm stuck on the same issue as these two (and the third link does not fix it for me):
#774040485748539423 message
#774040372966981644 message
#774040485748539423 message

I get:

cxpcaptool -z pmkidhash corp_question1-01.cap

reading from corp_question1-01.cap
failed to read pcap packet header for packet 95415
                                                
summary capture file:                           
---------------------
file name........................: corp_question1-01.cap
file type........................: pcap 2.4
file hardware information........: unknown
<SNIP>

summary output file(s):
-----------------------
#

^^ Doh. I'm reading the wrong file, I think.

wraith creek
#

Completed all the fundamental modules djdanceparty

urban sage
#

Congrats!

viral orbit
#

Can someone plz help me with setting up Burp for web request fundamentals?

white basin
#

Yeah what do you need?

viral orbit
# white basin Yeah what do you need?

Thanks for the help. So, I am having some troubles setting up burp Suite for web request fundamentals. at first when I enabled burp on FoxyProxy, I was getting errors on firefox when going to any site. So I googled the issue and saw that I need to install burp suite's CA certificate. So I did, but now when enabling burp suite on Foxyproxy it doesnt give me the error but just loads endlessly like there is no internet connection.

white basin
#

Yep. That’s because everything is going through burp. So if you go to the proxy tab you can forward or drop request

#

And also analyze anything going through burp

viral orbit
#

sumE Wow I am such a noob lol

north rapids
white basin
#

Hey we all crawl before we walk

viral orbit
#

It's on the request and response section

white basin
#

The target url is probably the IP address of the target machine

viral orbit
#

and what about the port?

white basin
#

Should be port 80.

#

So it would look like. 10.10.1.1:80 for example

viral orbit
#

Ok lemme try that

uneven osprey
#

Anyone complete the LFI Skills Assessment? Need some help with the RCE portion, and if I'm even in the right spot to attempt it.

viral orbit
#

@white basin how do I know I am entering the correct IP and port? in the example on web request fundamentals, their's was 206.189.25.23:30147

#

or anyone feel free to help if u know

white basin
#

Which section are you on?

viral orbit
#

Request and Response

white basin
#

So you entered the ip into the search bar and pressed enter? Then looked at the request in burp?

viral orbit
#

nothing showed up in burp, so that why I think I didnt enter the correct IP and port

white basin
#

Try just the ip. I don’t think you need to do the port.

viral orbit
#

oh crap wait, it was turned off on FoxyProxy, let me try again

white basin
#

Oh yeah. Make sure burp is on in foxyproxy.

#

Burp has a browser also so you don’t have to switch foxyproxy all the time. I don’t really like it but it does make it easier.

viral orbit
#

ok so I think I got it when I enter https://165.227.239.236:8080/ I get a security warning from firefox, but I just click proceed and forward on burp and then I think I see what I am supposed to see on burp

#

GET / HTTP/1.1
Host: 165.227.239.236:8080
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Dnt: 1
Upgrade-Insecure-Requests: 1
Sec-Gpc: 1
Cache-Control: max-age=0
Te: trailers
Connection: close

#

That is what burp shows me

white basin
#

Yep. And your answer is in there

viral orbit
#

Awesome! Thanks

#

Geez this community is amazing

white basin
#

No problem 😎

wet schooner
#

Just finished hacking WordPress nice module and avoided using metasploit to get the final shell :)