#modules

1 messages Β· Page 501 of 1

high zinc
#

ah πŸ™‚

#

Yeah the T0 modules both cost 10 cubes and award a total of 10 cubes upon completion, so they are practically free granted you finish them

#

some of the paid ones are really good like a 🐍 certain 🐍 module 🐍 about 🐍 snakes 🐍 that I may or may not have made

#

:)))))

raw remnant
#

exactly. seeing that this could be a way to unlock more difficult modules I was like awesome, by finishing higher tier modules I'll get the cubes needed for more difficult ones to further play around

#

but now I understand that

high zinc
#

ah yeah that would be awesome though

raw remnant
#

it would for sure

mild kettle
#

Hey could anyone help me out? I'm in 'Intercepting Web Requests' on module 'Using Web Proxies' trying to complete this problem, "Try intercepting the ping request on the server shown above, and change the post data similarly to what we did in this section. Change the command to read 'flag.txt'" I've intercepted the ping request but not sure where to go from there. Here's a picture

main vapor
#

@mild kettle DM me.

old birch
#

anyone around for a nudge on windows privesc: credential hunting? I've found 4 passwords for "Search the file system for a file containing a password. Submit the password as your answer." and none of them are working - wanna make sure its not a bug

jovial pivot
#

Im still having the issue of being able to ssh/rdp in from the parrot web browser vm to the target machine, i am pretty sure the password i am using is right, so i am not sure what i am doing wrong

#

terminal looks like this

#

[htb-ac56594@htb-ivdjwmpxyg]─[~]
└──╼ $ssh htb-student@10.129.42.254
The authenticity of host '10.129.42.254 (10.129.42.254)' can't be established.
ECDSA key fingerprint is SHA256:2C7i8PSisiFhZU6hKnk/uezTXBHtFMnXLJvuzKghmBU.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '10.129.42.254' (ECDSA) to the list of known hosts.
htb-student@10.129.42.254's password:
Permission denied, please try again.
htb-student@10.129.42.254's password:

#

im trying this password for ssh

#

HTB_@cademy_stdnt!

tight glen
#

Hey could some1 help me with NTA Module? im currently filtering with tcpdump and im stuck

inner breach
#

Start HTB Academy

main vapor
#

@supple rampart Start with these two modules within the Academy.

novel matrix
#

What are you here for?

#

What for?

high zinc
#

Yeah I did πŸ˜„ happy to hear you enjoyed it

mint karma
#

for this question last part in the nmap module anybody knows how to find the version of the dns

agile torrent
#

oh damn we're both still on the grind

#

lmao

jagged zenith
tepid ermine
#

πŸ‘€

oblique cypress
#

someone help please
I run command "nmap -sV -n -Pn 10.129.239.172 -p8080" to complete module "Getting Started/Service Scan"
But result is missing version info?

novel matrix
atomic river
#

Following #modules message.... I tried all the following combinations: tcpdump -c 1 -X icmp, tcpdump icmp, tcpdump -n icmp, and all that combination with sudo... but it does't work, could you give me a hint, please?

oblique cypress
oblique cypress
#

I can't send image 😦

humble kestrel
#

Hey, I'm also stuck with the skill assessment

#

Is it okay if I DM you? thanks

nocturne turtle
#

anyone have issues with academy targets failing to start? I'm trying to finish one with a docker target (i think? <public ip>:<port>) and can't even ping it. I've tried on and off the vpn, from a local parrot vm and from pwnbox. I've reset the target a couple times as well, nothing.

knotty flare
zenith schooner
frosty nacelle
#

Need some help with "LOGIN BRUTE FORCING - Skills Assessment - Service Login" , I obtained the user from the second question in "Skills Assessment - Website". I used NameGenerator to create the possible user names and cupp to create a wordlist (refined results with company policy) but still havent been able to get the correct set of credentials. Any hints that yall could provide would be greatly appreciated

main vapor
#

@frosty nacelle DM me.

hollow dust
#

Target spawning doesn't seem to work on the phishing section for the XSS module, been spinning for ten minutes at this point, I've refreshed the page 20 times now

manic moat
#

Can someone give me an advise (not an answer) how to made that, i checked kernel vulns, checked cron as that was written previously, but found nothing pepehands

hollow dust
#

Perhaps indeed

#

πŸ˜ƒ

rustic sage
#

hi all - can anyone explain me what are they asking about - since the answer is not: MAC
"What addressing mechanism is used at the Link Layer of the TCP/IP model?"

#

It's from the "Networking Primer - Layers 1-4"

hollow dust
#

oh wait link is a combination of both data link and physical mb

#

Link layer is also sometimes called network interface layer

#

If you understand OSI you will understand TCP/IP

#

Just a condensed version of OSI

rustic sage
#

yes, because Link Layer is != network layer

#

it's TCP /IP not OSI

#

only 4 layers are in this model

hollow dust
rustic sage
#

ok no problem

hollow dust
#

Had an interview for soc positions recently

#

I will hear back next week on whether i got the job

#

They asked me some crazy questions for an undergrad in CS

rustic sage
#

sometimes it's just to much to digest πŸ˜†

hollow dust
#

I think they were just gauging my level of knowledge

#

HR woman said I got good feedback so might be gud

#

Pray for me brothers

#

I will need it

rustic sage
#

ok - fingers crossed πŸ™‚
getting back to my struggle

hollow dust
#

struggle bus leads to good places my friend

primal forge
#

Hello Friends, I'm on the Setting Up Modulus in HTB Academy and I'm having a hard time setting up my VPS on Vultr. I followed all the step but whenever I tried to ssh using my parrot vm to the vps server I keep getting "ssh: connect to host IP port:22 Connection refused.

#

What should I do?

hollow dust
#

you are using open vpn?

primal forge
#

No, I don't see any step mentioning that

hollow dust
#

mb nevermind

pure vector
#

does anyone know where I can ask for help? im submitting a flag for a module's question but it says that its wrong.

agile torrent
pure vector
agile torrent
#

oh sorry mb, I haven't done that one yet

pure vector
#

thanks

icy snow
#

Any nudge on this section?

#

Anyone able to gimme a nudge on the DNSAdmins section of Windows Privilege Escalation? Getting the DLL to work but no access to the flag…

urban sage
icy snow
small atlas
#

anyone with some books of ffuf

novel matrix
small atlas
brazen saffron
#

How can I send a request with two arguments?

unreal crescent
#

The vulnerable parameter doesn't change per target on the Session Hijacking of XSS does it?

unreal crescent
#

um so my cookie keeps disappearing when I try to add it in

#

um nevermind... I was trying to change the domain to match, but i didn't have to

primal forge
#

Has anyone completed the Setting up Module? I'm having a hard time setting up my VPS.

unreal crescent
#

Yay I did it lol

#

If anyone needs help on the XSS module I just finished it so its fresh in my mind lol

knotty hemlock
#

Hi CarniGamer, I solved it, but it's a bit tricky to give hints. try to put console.log to all return values and integrate the unused functions

forest gorge
#

Hi I find the answer for a module question (I am in the ASsembly Intro course) But i don't know tthe format to validate my answer

wind aurora
#

Bufferoverflow linux .. Unable to read /root/flag.txt

knotty hemlock
#

I'm stuck at the Secure Coding 101:Javascript module at the Patching task... Can anyone help me?

chilly lichen
#

What’s this server abt?

warm bobcat
#

hi, im on linux fundamentals->navigation, using the pwnbox, i tried to ssh to my target, but am not connecting.. any help please?

main vapor
#

@warm bobcat Try doing it from your host machine and see if there is any luck.

warm bobcat
#

it didnt work on my main machine, the error is related to compression on config or something, but am talking to htb help chat already thanks @main vapor ! πŸ™‚

jovial pivot
#

In the Getting Started module on the Service Scanning section I am having issues with this problem:

#

Perform an Nmap scan of the target. What service is running on port 8080? (two words)

#

β”Œβ”€[htb-ac56594@htb-utlfbka3dn]─[~]
└──╼ $sudo nmap -p8080 10.129.42.254
Starting Nmap 7.91 ( https://nmap.org ) at 2021-10-15 15:27 UTC
Nmap scan report for 10.129.42.254
Host is up (0.0031s latency).

PORT STATE SERVICE
8080/tcp open http-proxy

Nmap done: 1 IP address (1 host up) scanned in 0.20 seconds
β”Œβ”€[htb-ac56594@htb-utlfbka3dn]─[~]
└──╼ $

#

those are the actions i took in the terminal, based off the question i would assume that the service on port 8080 is http-proxy; however, it states it is incorrect

#

i am a tad bit confused, can anyone tell me what i am doing wrong?

#

any help in understanding what i am doing wrong would be very appreciated

jovial pivot
wind aurora
#

Skill assement bufferoverflow linux .. Got reverse shell but unable to read /root/flag.txt says permision denied. But the program has set suid ..after executing binary it saves ist argument in text file.

pure vector
#

hey guys, anyone did BROKEN AUTHENTICATION > Predictable Reset Token ? im having a hard time creating a valid token but im not sure what im doing wrong.

raw remnant
naive elbow
#

h i guys I just finished Meow, Fawn, and dancing, what should :I do next

high zinc
#

@pure vector @fleet moth feel free to DM / explain in here

raw remnant
#

try playing some of the retired machines

naive elbow
#

I dont have the money for VIP

#

and i think that requires VIP

raw remnant
#

the easy ones

#

some are free

naive elbow
#

After the tier 0 ones should I move to tier 1

raw remnant
#

for T1 modules you also need money

#

not sure if you've gone through academy yet but yeah...

#

next up you can go to labs/machines/retired

#

should be 3-5 recent ones that are free

#

@naive elbow

#

retired machines give you a walkthrough through them as well

pure vector
#

i have my python code which I believe its self explanatory

#

can I post it here or dm?

high zinc
zenith schooner
knotty void
#

Been stuck on an NMAP module for 4 days. It asked to find the total number of open TCP ports on my target. Tried and tried but couldn't get it until a new target was assigned today which gave me a clear answer.

small atlas
#

anybody complete fuzz model

unique star
#

Hi, I've have problems with the xxe spawn machines on the "web attacks" module. I have finished the Skills Assessment but I'm stuck cause although the containers do start I can't reach them. I've tried ping it even nmap it but it looks like the container doesn't work. I don't know if I'm doing something wrong.

knotty void
#

I don't want to get too specific here but, when making reference to a flag in the modules(NMAP). Are they referring to a segment of code in a page or to a returned value in a TCP scan such as SYN/ACK/RST? I'm confused because I tried multiple options but it doesn't work.

#

there's also the NMAP flag so I'm not sure which one to refer to.

high zinc
#

@loud sparrow

Are there any plans for a Nessus module?
Good question. My guess is no since it's a paid product IIRC. There's an nmap module though if that helps

vast nymph
#

Hello, I have a problem with the spawn machine while using nmap ( telling me all ports are filtered) also while using smbclient (saying Error NT STATUS IO TIMEOUT)

cerulean garnet
#

Anyone else have a problem with the starting point where you've pawned tier 0 but it doesn't show it?

#

I've done dancing and meow but the last flag task just says 'this machine is already pwned' but it doesn't actually complete 9/9

inner breach
#

Hey there ! I badly need help in academy's Bug Bounty Hunter Path

#

Anybody up?

#

There's a button that's disabled. And i need to enable it with burp and get the flag. Idk how but i played with the source code and somehow i got the flag. But tht was unexpected

#

I'm curious to know how the procedure is!

lilac quail
#

Anyone available to give a hint about Web Attaks skills assesment?

mint karma
mint karma
#

any ideas on what wordlist to use for this task

#

logΔ±n brute forcing module

tight glen
#

if i recall correctly i created one with cupp

mint karma
#

cool thanks

brazen saffron
#

How can I send a web request with 2 arguments ?

#

I know how do the method GET but no with arguments...

west rampart
#

@brazen saffron you mean POST?

#

or GET with 2 args?

brazen saffron
#

GET with 2 args.

#

I know I can use curl URL but with args...

brazen saffron
#

Wait I don't understand, I can do : curl http://inlanefreight.com/?param1=669&param2=668 ?

west rampart
#

yup

high zinc
brazen saffron
#

Because I have it so...

brazen saffron
# west rampart yup

Then I did it with my exercice but I don't know what I need to send in the answer :

cedar light
#

If u send the curl, what do you get in response?

brazen saffron
#

I send it.

#

The "code source" and a answer : + done with the ip, etc.

cedar light
#

Check the content of the answer

brazen saffron
#

I said to you...

main vapor
#

@brazen saffron Why do you have a / before ?

cedar light
#

I'm trying to help without giving you the answer πŸ‘€

brazen saffron
main vapor
#

no my man your are doing this /flag.php/?param1=668&param2=669

#

why not ||/flag.php?param1=668&param2=669 my pardons to @brazen saffron but both work||

#

And are you sure they are called "param1" and "param2"?

#

||The author said "num1" and "num2".||..

raw remnant
#

oh nvm I see it now

brazen saffron
#

I try.

#

I did it and..

main vapor
#

@brazen saffron Are you sure that the target is up and running?

brazen saffron
#

I re did and he send to me something.

#

Can I send to you in DMs to don't send an answer here?

main vapor
#

@brazen saffron Sure.

inner breach
#

Hey there ! I badly need help in academy's Bug Bounty Hunter Path
There's a button that's disabled. And i need to enable it with burp and get the flag. Idk how but i played with the source code and somehow i got the flag. But tht was unexpected
I badly want to know how the procedure is!

cedar light
#

Use spoiler tag πŸ‘€

main vapor
#

@inner breach Which module is that?

inner breach
inner breach
#

there u go! last section

main vapor
#

@inner breach I am still to do that last section. So someone else might be able to help πŸ˜„

main vapor
#

@inner breach I have solved it on the fly just for you. DM for instructions.

knotty flare
#

I'm having trouble with the "Web Attacks"/"Advanced File Disclosure". I've tried to reproduce step by step the examples shown in the lesson, yet I don't get the same output. Plus I don't get how we should point to a specific file in the xxe.dtd . Anyone willing to offer help ?

zenith schooner
#

yo should try with a known page as index. I found them but I require to reescan all possible folders because my findings miss something.

zenith schooner
#

I think there is an option to retake module.

finite nymph
#

Hey guys, I am not sure how they connected to the bob user in the getting started module for smbclient

#

it keeps asking me for password but I obviously I cant write anything

agile torrent
#

for that employee, try starting with very little info + leet/nums etc then working up if those don't work

tacit matrix
#

how do I get into hacking?

novel matrix
red obsidianBOT
west stratus
novel matrix
zenith schooner
marsh laurel
#

DM Message me and I will point you in the right direction.

finite hull
#

In the Results section of the "Setting up" course, is there a CLI alternative for the tools mentioned?

tidal compass
#

I'm stuck. Log in brute forcing module. Second question on the skill assessment. "Once you are in, you should find that another user exists in server. Try to brute force their login, and get their flag.". hint is to use the wordlist in the home directory. Which is rockyou-30.txt. I've tried it and I just get a server time out error. Any clue what I'm missing?

rocky cedar
#

Maybe I'm being blind but in HTB Academy "Introduction to Python 3" "Word Extractor" "The First Iterations" the question at the end is "What is the 3rd most used word on the exercise target website?" The sample code uses 'http://target:port' which seems wrong, but I can't find a reference to any specific site in the module. I have working code, but without the correct URL I'm stuck. I assume that since others have made it through the module this is not a bug and I'm just missing something.
Can someone tell me the correct website and where I should have found it?

urban sage
#

I haven't done that specific module but is there an option to "spawn target"?

rocky cedar
#

@urban sage Thanks. I was being blind. I knew it was going to be something stupid.

urban sage
#

No problem. Happy hacking!

cedar light
#

Hello, i just started the "Attacking Web Applications with FFUF" module. In "Directory Fuzzing" section, it says:

#

But if i try this command, i get:

#

So i can't bind the "FUZZ" keyword to use it whenever i want. Is that normal?
(i'm using the wordlist of dirbuster, is that a problem?)

EDIT: yes, dirbuster's wordlist is the problem πŸ˜‚

high zinc
faint trout
#

Can i get some help with the SQL module on HTB Academy por favor?

#

What is the last name of the employee whose first name starts with "Bar" AND who was hired on 1990-01-01?

#

This is my question I am trying to answer^

#

SELECT * FROM table_name WHERE <condition>;

#

I am not sure how to properly use the syntax

#

I need to use the AND statement the hint says

main vapor
#

@faint trout DM me.

old birch
#

anyone around for a nudge on windows privesc assessment 1? I've got my shell but cant seem to find the ldapadmin creds

urban flume
#

Web Attacks - Skills Assessment

mint karma
#

anybody doing login brute forcing

vernal reef
#

Bro I am there

mint karma
#

how am I supposed to get the employee name

vernal reef
#

@mint karma the comments said that in the pass exercise we found a user

#

But I am there too

#

:(

mint karma
#

lol I am confused

vernal reef
#

Yeah because there is not a clear explanation

mint karma
#

xD

mint karma
#

pretty vague

#

but got it

haughty fractal
#

hey on the intro "What is the abreviated name for a tunnel interface in the output of your VPN boot-up sequence output? "

#

i'm not underatanding

#

i tried eth0 or tun0 no luck

#

not sure i understand the question?

#

I am connected via openvpn to the machine, on tun0 looks like? not sure what the correct answer would be or how to move toward it

#

oh

#

it wanted "tun" not "tun0"

#

weird

#

i think i misunderstood the question but shouldn't the interface be technically tun0 not tun? there is no interface called just "tun" in ifconfig

#

anyways for the intro is it intended the initial box has all ports filtered? I tried a -Pn scan and just got told all ports filtered but the next question asks about specific ports being open? (I tried dropping the -A flag and just doing nmap -Pn -v [ip of box] with no luck, but vpn is connected

#

like not even sure if the host is acting normally, is there a way to verify? can anyone give help?

#

not sure how to move towards solution

primal forge
#

Is htb vip+ worth it? Trying finish all the module in academy before I considering it

cedar light
haughty fractal
#

thanks you're right

#

now stuck figuring how to nmap the box usual tricks aren't working :/

high zinc
cedar light
high zinc
#

If you're into learning on the Academy, you could also look at some of their Cube plans

primal forge
#

Thanks, will do

haughty fractal
#

err hold on running it

#

oh weird now it gave results

#

but looks like all filtered

#

yeah no matter how i try it says up but all ports filtered

dusty prawn
#

In the Web Request - Request and Response module, is there a way to have the FoxyProxy extension not be disabled?

#

Or at least get it to activate using burp?

vernal reef
#

Hi bros i stuck in the LOGIN BRUTE FORCING-Skills Assessment second question " Once you are in, you should find that another user exists in server. Try to brute force their login, and get their flag." could you help me out?

#

I already have the other user and I have the list that is in the home (rockyou-30.txt). My question is how do I brute force from there which port should I use? I tried hydra -l useretc -P rockyou ... -u -f ssh: //127.0.0.1: 22 -t4. Or what IP and port should the attack launch? All my attempts mark my connection refused.

#

Thanks

zenith schooner
mint karma
#

thats the machine

vernal reef
#

Thanks for the response (Y)

torpid ermine
#

anyone please give me a nudge in XSS skill assessment

tight glen
#

please careful with spoilers, might censor certain information in this picture next time πŸ™‚

cedar light
torpid ermine
cedar light
#

Yeah

pearl birch
#

Anybody... Doing File Inclusion/Directory Traversal module. Currently on the Skill Accessment exercise. I have tried things like URL Brute using Gobuster and a few php wrappers. The one that worked for me is php://filter before I could use this wrapper I need to find the config file or something Gobuster could not locate any config files. I have tried different wordlists hoping to find a config file on the webserver nothing turn out. Please I need help.

Skill Accessement question is; Assess the web application and use a variety of techniques to gain remote code execution and find a flag in the / root directory of the file system. Submit the contents of the flag as your answer.

main vapor
#

@pearl birch DM me.

thorny crow
#

Need a sanity check in Windows Binary Exploitation: "Try to search the 'cdextract.exe' binary for the 'PUSH ESP; RET' instruction as pattern '54C3'. What is the address of the first result you get?" -- I have the three addresses where this is located, but it's not taking it.

main vapor
#

@thorny crow DM me.

inner plover
#

i want to learn hacking can anyone tell me from where to start

#

i have some knowledge on html

#

and javascript

urban sky
#

hey guys, i'm stuck on a pretty simple skills assessment for ffuf module. I'm on "Parameter Fuzzing - GET" and can't get the paramter to come through from the command: ffuf -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u http://167.99.202.9:31395/?FUZZ=key

#

Can someone give me a nudge

wind aurora
#

@thorny crow your are searching outside cdextract.exe . Double click cdextract.exe to find instruction inside it . Use pattern 54 C3 and u will get address

thorny crow
wind aurora
#

@thorny crow Submit this 00457418 i will explain u

cedar light
#

(admin.academy.htb, with academy.htb = 167.99.202.9, also admin.academy.htb)

urban sky
#

hmmm, i added the ip to etc/hosts(sudo sh -c 'echo "167.99.202.9:31395 academy.htb" >> /etc/hosts') and ran this but still no luck:
ffuf -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u http://167.99.202.9:31395/admin/admin.php?FUZZ=key -fs 968

cedar light
#

You're adding only academy.htb to /etc/hosts

#

You need to add admin.academy.htb also

urban sky
#

yeah, ive added both. running ffuf on admin.academy.htb and 167.99.202.9:31395 either return error or nothing

cedar light
#

U're using in a wrong way the command sudo sh -c

#

From cheatsheet: "sudo sh -c 'echo "SERVER_IP academy.htb" >> /etc/hosts'"

#

Without the PORT. But now u need to access /etc/hosts and remove the wrong entries

urban sky
#

Both return no results

#

Sorry about this. really appreciate the help

cedar light
#

Missing PORT in ffuf command
From cheatsheet: ffuf -w wordlist.txt:FUZZ -u http://admin.academy.htb:PORT/admin/admin.php?FUZZ=key -fs xxx

urban sky
#

@cedar light helped me figure it out. I was adding http:// to the hostname in /etc/hosts

wind aurora
#

@pearl birch Hint : Use php wrappers on index file and u will find some interesting stuff

strong spruce
#

Hi
I am currently doing the Linux Fundamentals Module and the web machine doesn't seem to working

#

I am not able to ssh into the target machine, it displays connection timed out

#

Anyone who maybe be able to help me with this one ?

#

I did try downloading the vpn key but it seems to be showing some authentication error

rustic sage
#

Anybuddy have ark mobile hack tools

zenith schooner
# urban sky I removed the entries. Added the IP with http://admin.academy.htb and http://aca...

When it comes to catch subdomains / vhosts in this exercise, the first part is editing the /etc/hosts and add the suitable entries such as <ip> academy.htb <subdomain>.academy.htb <vhost>.academy.htb, etc. I guess you'll try several tries on each exercise. All of them are around academy.htb. So, add a line per each new IP with the same subdomains found. As I remember admin was not part of the subdomain. your first goals is ffuff by using any word list from dns folder of seclist.

cedar light
loud sparrow
#

Some on finished Attacking Common Applications-Attacking osTicket

mint karma
#

mine took 5 mins to crack xD

knotty flare
#

Does anyone know when will the new Bug Bounty Hunter modules be published ?

rustic sage
#

hi

tulip jacinth
#

is there a python pwntools module planned?

manic moat
#

Hello there again! Two days earlier i asked to give me a hint, but now i`m completely feeling dumb... I understand how to gain access to root from user2, but i cant reach user2 FeelsBadMan

manic moat
#

Privilege Escalation

pine sable
manic moat
#

Thanks

#

I got that)))

manic moat
pine sable
#

Your welcome πŸ™‚

raw saddle
#

I cannot ping the target system in the FFuf module, any ideas? I can access other sites like google from my workstation

#

nvm

knotty flare
#

Thanks, can't wait πŸ™‚

#

Of course !

faint trout
#

Hey guys, Accepting DM's for help

#

I am looking to solve the HTB Academy SQLi fundamentals final assessment question.

#

I am stuck on creating a webshell and executing the search for root directory

weary locust
#

I was running though the Intro to python, and during the managing libraries in python part, the question was #2 The type of foo from question 1 is <class 'set'>. What is the type of x_coordinate? Now i put made a text.py and put the code it and it came out tuple. But that isnt the correct answer... can anyone give me some help or a push in the right direction

main vapor
#

@weary locust|| How about you use the type() function on the variable instead?||

zenith schooner
urban heath
#

hi

weary locust
#

@main vapor i did and that is how I got the answer tuple but it does not accept that answer

main vapor
#

@weary locust Check DM.

wicked gazelle
#

Hi! i'm trying Linux Local Privilege Escalation - Skills Assessment (the note: obtain a shell on the box instead using the ssh) anyone can send me a hint??

weary locust
#

ty so much... im soooo slow.

pine sable
#

Hi.
Some problem to spawn the vm ?
Target: Target is spawning...
Am alone ?

#

!rank

novel matrix
pine sable
#

Yes sorry 😦

chrome jewel
#

hi

mint karma
#

anybody did this

#

hashcat module

knotty hemlock
#

hi, i have a rather general topic, i have both python2.7 and python3 installed on my kali linux machine, and it seems pip doesn't work for the 2.7 one. I can't find a way to manually install it. It always says: "/usr/bin/python2.7: No module named pip", but "sudo apt-get install python-pip" says: replaced by python3. Anybody knows what to do?

knotty hemlock
#

ensurepip is disabled in Debian/Ubuntu for the system python.

Python modules For the system python are usually handled by dpkg and apt-get.

apt-get install python-<module name>

Install the python-pip package to use pip itself. Using pip together
with the system python might have unexpected results for any system installed
module, so use it on your own risk, or make sure to only use it in virtual
environments.

#

and when i try "sudo apt-get install python-pip" it says:

#

Package python-pip is not available, but is referred to by another package.
This may mean that the package is missing, has been obsoleted, or
is only available from another source
However the following packages replace it:
python3-pip

E: Package 'python-pip' has no installation candidate

high zinc
#

Python 2.7 is End Of Life - why do you need it still?

knotty hemlock
#

i want to run some PoC. actually i'm doing the "Common Web Applications" module now, and for example the Drupal section has some scripts i can't execute

loud sparrow
#

some one on Common Web Applications: Skills Assessment I ?

tight glen
#

Module: Network Traffic Analysis
Section: Interrogating Network Traffic With Capture and Display Filters
Question: What are the client and server port numbers used in first full TCP three-way handshake? (low number first then high number)

Where can i find the .pcap file that is necessary for this question?

high zinc
#

it should be among those files

fiery swallow
fiery swallow
cunning nacelle
#

was wondering if anyone wanted to study the Linux fundelementals module with me? just dm me if you want to (no voice chat). The reason for this is that I heard studying with someone else helps you remember info better.

forest fog
#

anyone from philppines?

inland wigeon
#

Hi

#

I am doing the web requests module

#

POST one

#

but I can't finish it

#

so can someone help me?

inland wigeon
#

some random strings made me reach till here

#

I jus need the n

#

ant idea how to get it?

#

what is the encoding ?

wary nymph
#

@inland wigeon

inland wigeon
#

yea

inland wigeon
wary nymph
#

@wary nymph

inland wigeon
#

.

wary nymph
#

@cunning nacelle

inland wigeon
#

-_-

#

why ping

tawny delta
#

i cant see burp in foxyproxy

inland wigeon
tawny delta
#

i dont see it in the extension menu

inland wigeon
#

hmm

#

restart firefox ?

tawny delta
#

i did

#

and burp

inland wigeon
#

hm

tawny delta
#

nothing

inland wigeon
#

options

tawny delta
#

ok

#

then?

inland wigeon
#

enter a name

#

ip: 127.0.0.1 port 8080

tawny delta
inland wigeon
#

click add

tawny delta
#

add proxy?

inland wigeon
#

yea

#

click the add button

#

like this

#

the ip is 127.0.0.1

#

port 8080

#

give it a name

#

click save

#

it should work then ig

tawny delta
#

yea i got it thanks

inland wigeon
#

np πŸ˜„

urban flume
#

Web Attacks - Skills Assessment i'm stuck anyone can help please?

tight glen
rare jackal
#

does anyone know whether zap is installed by default on this instance?

#

I don't seem to find zap at all

cedar light
#

Read again the previous sections, u didn't understand something

#

Just think about how the backend knows you are "admi"

pine sable
#

Hello ! πŸ™‚
Since yesterday, i can't spawn target VM.
message: Target: Target is spawning...
Am alone with this issue ?

inner breach
mint karma
#

the hashcat module was fun

#

is there a wireless attack module coming to HTB?

knotty flare
mint karma
#

In the hashcat module it says there will be

#

Mabye a matter of time

main vapor
#

Anyone requiring help/hints for the Hashcat module I will be at your disposal.

tranquil steppe
#

I want to join, but no idea where to start πŸ˜‚ Sorry

mild kettle
#

Is there VMware for mac? I'm on the 'Setting Up' Module and not sure which VMware to download

stable sinew
mild kettle
#

Hey could someone help me out I keep getting this message after having installed and reinstalled openvpn but I still get an error message that openvpn command not found

knotty hemlock
#

or try to start the service like it suggests: sudo brew services restart openvpn

#

but to me it looks like your system doesn't find the correct path

mild kettle
#

tried the restart but it didn't work. How would I write that with the whole path, 'openvpn /usr/local/opt/openvpn/sbin/openvpn file.ovpn'?

#

'openvpn /usr/local/opt/openvpn/sbin/openvpn file.ovpn' didn't work

knotty hemlock
#

no need for the first openvpn, just this: /usr/local/opt/openvpn/sbin/openvpn file.ovp

#

your shell will find out that that this is a binary file πŸ˜†

burnt cosmos
#

hey guys

#

anyone did the Intro assembly module stuck on the first task at the last section !!Thanks:)

desert sedge
#

try using which openvpn as a normal user

mild kettle
#

I tried which openvpn and that seemed to work

desert sedge
#

what was the output?

#

also, it isn't good practice using sudo su, you'd rather use sudo $command

#

(afaik)

mild kettle
#

This is what I got

#

Ok whats the difference between sudo su and sudo $command

desert sedge
#

basically everything you do with while in su mode is executed with root privileges

#

you could execute something by accident idk

#

i've always heard that i shouldn't do that

desert sedge
mild kettle
#

oh ok

desert sedge
#

try instead of reinstalling removing it and then installing it again

mild kettle
#

how do I remove it?

desert sedge
#

or download openvpn's binaries and add them to your path manually

desert sedge
#

or brew uninstall openvpn

mild kettle
#

I got this, not sure where to go for that though. I'm on a mac

#

I ran that

desert sedge
#

do as the error says, type that command

#

now open vpn should be removed

mild kettle
#

Now not sure where to install openvpn too now

#

How do I get it downloaded onto the system not the root

desert sedge
#

extract it and add then link it

#

with ln -s path/to/openvpn /usr/bin/openvpn

mild kettle
#

I downloaded it. How do I add and link it?

#

are those two separate commands?

#

And I am trying to get it to work with ParrotOS, I am in the setting up module in the Linux section

sudden summit
#

Anyone available to nudge me for the command injection skills assess? Iv got an injection up to the point I get permission denied when moving the flag.txt. So im close!

sudden summit
#

Nevermind i got it. Soon as i post i get it....

sudden summit
#

Anyone finished the Broken Authentication skills assessment that can give me a nudge?

#

I know the cookie algorithm but kinda hit a wall now

odd basin
#

Noob question -
I am doing the skills assessment on the web fuzzing module. I found the vhosts and the extensions just fine, but I am having trouble finding the page that says 'You don't have access!'. I've only found two pages, /server-status and /courses/ . Server-status gives me a 403 and the default message, 'You don't have permission to access this resource'. I assume the hidden page is under /courses/ since 1) the hint tells me to do a recursive scan and 2) /courses gives me a 301 to /courses/ , so I assume there are some sub dirs somewhere under that.

Here are some of the things I've tried -

  • added the vhosts to my /etc/hosts
  • run recursive searches on all vhosts
  • searched for all the extensions (w/ -e option)
  • used the medium and big dir list

Example of a search that would turn up this hidden page-
ffuf -w /opt/useful/SecLists/Discovery/Web-Content/directory-list-2.3-medium.txt:FUZZ -u http://faculty.academy.htb:$PORT/FUZZ -recursion -v -e .php,.phps,.php7

Question -
Am I on the right track thinking this hidden page is under /courses/ or am I barking up the wrong tree there? Any hints would be greatly appreciated.

edit: I should also mention that pages like http://faculty.academy.htb:30538/courses/index.phps exists and is forbidden but again gives the default 403 error and not the specific message in the question, 'You don't have access!'. Plus that isnt the answer :p

odd basin
#

Nevermind, found it! It was there all along, I was just overlooking it.

inland wigeon
cedar light
jade seal
#

Hi all, I'm currently 3/4s the way through the 'Cross-Site Scripting (XSS)' module. On the 'Phishing' section, it requests that I start a netcat server to listen and capture the usernames and passwords on the phishing page. Trying to start the nc server fails (using the supplied command in the section) as the 'address is already in use'.

It's trying to listen on the tunnel address, and doing a netstat reveals that python is currently using port 80. Inspecting in 'ps aux' reveals it's running something called 'websockify' and unfortunately, killing the process terminates the attack box connection (which makes a lot of sense).

Has anyone seen this issue before? Is it a known problem? Or am I supposed to change the port that my payload uses for the phishing page? That seems like it shouldn't be the case for a 'beginner' module.

Any advice would be greatly appreciated πŸ™‚

inner breach
mortal basin
jade seal
jade seal
inland wigeon
#

it's base64 ig

#

it worked thnx

cedar light
#

πŸ™‚

wicked gazelle
#

sorry cat

#

^^

safe token
#

hey. im in the NETWORK ENUMERATION WITH NMAP module and im doing the nmap scripting engine part. i've tried enumerating with -A -sC -script=http-enum but i get nothing only that NXT-DEFAULT-SERVICE or whatever. so i just wanted to go check what is on the port so i went to <ip>:31337 port and i see the flag but i get an error when i submit

#

any idea?

inner breach
#

Module : Web Proxies
Section : Burp Intruder

i don't understand what wordlist to use. The alphanum-case.txt didn't work.

#

And the common.txt just sounds a mountain in the community editionFeelsBadMan

pine sable
inner breach
pine sable
inner breach
#

the community is just toooooooooooooo slow

#

thanks for the confirmation tho

pine sable
inner breach
pine sable
#

the 200 first words

inner breach
#

oh okay! cool ! thanks

pine sable
#

btw, i just see some bug when filtering by status code in my burp.
Better to look at the length page i think.
Maybe this bug is only available in my instance

inner breach
pine sable
inner breach
#

intruder sucks

pine sable
inner breach
#

Okay lemme see if that works fastNotLikeThis

pine sable
knotty hemlock
#

😦

worn rampart
#

Anyone who finished the Cracking Passwords with Hashcat Academy Module or is at ease with hashcat could help me ? πŸ™‚
Please Dm me if you want to πŸ™‚

quick jetty
#

Hi [Academy | Using Web Proxies] Repeated Requests - Can anyone give me a hint on how to do this? I know it is not in the same directory, but i cannot seem to find the "other flag". How was the problem solved? Thank!!!

knotty hemlock
knotty hemlock
#

can i send you a DM?

pine sable
#

You can

knotty flare
#

Hi guys, did anyone have trouble with eyewitness at the beginning of the "Attacking Common Applications" module ? I installed it with both methods presented, used the exact commands shown to generate a report but it keeps giving errors.

knotty flare
fiery swallow
rustic sage
#

Good Afternoon, I am going through the ffuf module, and I am not sure if I am misunderstanding or what, but for the GET parameter fuzzing, I thought the -fc parameter at the end of a ffuf command would allow me to filter responses. But if I set -fc 401 I still get the terminal vomit from all the 200 responses. Am I misunderstanding how that parameter works?

#

OH! I figured it out, the filter parameter describes things that you donΒ΄t want to see, not things that you do want to see

unique star
knotty flare
knotty flare
knotty hemlock
#

I also had problems with this one. Put only very basic parameters in cupp, actually i think you don't even need to google.

knotty flare
umbral nebula
fiery swallow
#

Hitting a roadblock on Attacking Common Applications Skill Assessment I, found the app, version, and found a vuln but stuck there. If anyone's willing to give a hint DM me

raw saddle
#

Could anybody help with SQLMap Essentials? Stuck on trying to get flag 3 in the 4th section

#

Weird, only worked when specifiying the url and not saving the http request to a file in case anybody else gets stuck there

urban sage
#

You can shoot them an email. Other than that no. Any hacking to take it down would be illegal.

urban sky
#

Is anyone familiar with creating an html link that changes a string to something else. Its the HTML injection section under intro to web apps. I've tried variations of this but not exactly sure whats being asked: "<a href='https://46.101.23.188:31304/'><button> onclick="inputFunction()"Click Me</button></a>"

knotty hemlock
lucid veldt
#

Command Injection Module: Advanced Command Obfuscation

#

$(a="WhOaMi";printf %s "${a,,}")
is mistyping

#

should be $(a="WhOaMi";printf %s "${a}")

quick jetty
mild kettle
#

I'm on the setting up module and am setting up ParrotOS inside VirtualBox but everytime I try to run the install I get stuck on this screen ^^^^ Any help is appreciated!!

rotund otter
#

is it on the web or some software

mild kettle
#

I'm on this portion of the course in the Academy

#

In the Module 'Setting Up'

vernal reef
#

Hello friends I am making the CRACKING PASSWORDS WITH HASHCAT module, I am in the Cracking Common Hashes part. I am asking the question "Crack the following hash: 7106812752615cdfe427e01b98cd4083" someone has any advice or clue to solve hash thanks.

rotund otter
#

until you get some solutions

mild kettle
rotund otter
#

oh then you have to wait

#

for a day

mild kettle
rotund otter
#

oh great then keep trying

high zinc
urban sky
#

@mild kettle what @high zinc said. Use kali or parrot image and you won’t need to worry about the time constraint. Dm me if you can’t get it working

worn rampart
#

Anyone who finished the Cracking Passwords with Hashcat Academy Module or is at ease with hashcat could help me ? πŸ™‚
I'm stuck at "Cracking Common Hashes"

worn rampart
#

pm sent πŸ™‚

vernal reef
#

Hello friends I am making the CRACKING PASSWORDS WITH HASHCAT module, I am in the Cracking Common Hashes part. I am asking the question "Crack the following hash: 7106812752615cdfe427e01b98cd4083" someone has any advice or clue to solve hash thanks.

fervent vessel
vernal reef
#

Thanks bro with rules and identity the right hash I can :)

onyx wasp
#

hmm

manic moat
#

After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer.
Any hints? I know that it is port, but i`m not sure what to do...

tepid peak
#

@manic moat don't spoil it

#

i've just done it as well

#

did you read the nmap help pages?

manic moat
#

Better?

#

I`m losing myelf between nc and nmap

#

Not sure what to use

tepid peak
#

i used neither

#

i tried doing it your way and that works as well @manic moat

#

if you found the port you can look up ||firewall evasion|| with nmap, DM me if you're still stuck

sly nebula
#

is it normal for Joomla admin password cracking to take this long in "Attacking Common Applications"?

knotty flare
#

Same here : found the vulnerable app, but I can't find a way to exploit, even with 2 POCs found on exploit-DB. Can anyone who solved this give a nudge ?

idle kettle
#

Yo, have anyone end the Web Attacks module?

azure fable
#

I am stuck on this same spot and cannot find anything vulnerability that I can leverage to gain a shell or RCE.

rustic sage
#

Can someone help me

#

Pls

rustic sage
rancid holly
#

trying stack overflow for windows module ... skill assessment, have completed every step but after running final exploit getting "No route to host error", can anyone tell what can be the problem

rustic sage
#

Can someone help me with the Linux Fundamental module? Specifically for this one Use "systemctl" command to list all units of services and submit the unit name with the description "Load AppArmor profiles" as the answer.

I used the correct command however it doesn't seem to accept my answer as it shows incorrect 😦

vernal reef
#

Hi if someone is stuck in cracking handshakes send me a message ;)

rancid holly
gentle herald
#

any help in bypassing filters in HTTP verb tampering section in webattacks module
i bruteforced with every verb and with every injection filter

#

it still says malicious request denied

#

pls help

rare jackal
#

Just wondering if anyone can help me with the XSS skill assessment part where # comment doesn't have = so I can't add any value in...

rustic sage
floral brook
#

I am currently doing the Windows Stack-Based Buffer Overflow module and can’t get ERC to work on the Windows VM provided by the module. I keep getting error messages like this:

ERROR: Could not find a part of the path 'C:\Program Files\x64dbg\x64\plugins'.
ERC --Config
--------------------------------------------
New Working Directory = C:\Users\htb-student\Desktop\
--------------------------------------------
[PLUGIN, ErcXdbg] Command "ERC" unregistered!
[PLUGIN, ErcXdbg] Command "ERC" registered!

I already reinstalled the plugin. And I started the 32bit version, so I don’t know why it is complaining about the x64 folder.
Can anybody help?

main vapor
#

@floral brook Pardon but why dont you use the VM provided by the module maker initially? Or you want to use your own?

floral brook
#

Sorry, I just made my question more precise. I am talking about the provided VM.

#

Right after posting I realized this might be misunderstood πŸ™‚

#

Ok, I should have read the error message it printed above the help message too. It works now. You cannot use any ERC command, not even bytearray, without ERC being attached to a process.

#

One of those moments that make you feel dumb.

#

@main vapor But thanks for trying to help.

dreamy pecan
#

Need help

sly nebula
#

Then I think the suggested script is not working. Time to inspect the login mechanism more closely.

unique star
#

Hi, Did someone have problems with the splunk container on the attacking common applications module? The splunk ports respond with a connection reset error

main vapor
knotty flare
knotty hemlock
wind aurora
#

@floral brook Download ERC Plugins

sly nebula
#

Finally cracked the password. It took some time, I must say.

runic rampart
#

Friends, tell me, what do I need to do to fully see all these lines?(not dots)

sly nebula
#

Could anyone give me a sanity check on "Attacking Common Applications" / osTicket?

mild kettle
#

Could someone explain to me how to take a VM snapshot in/of VirtualBox?

mild kettle
#

I did. Found the solution! Thanks

safe token
#

module: network enumeration with nmap
section: firewall and idp/ips evasion - hard lab
hey. so i think i found the port i need which didn't show up with normal scans. now how could i get a flag from this port. the question says you need the version number of the service running there but the customer service or what said that i need a flag

#

could someone help me?

#

tried to connect it with nc but couldn't

safe token
#

someone pls

drifting knoll
raw saddle
#

I'm stuck on the SQLMap Essentials Skills Assessment if anybody can help

zenith perch
#

i appologize for posting this in 2 places....anyone got "user" on horizontall box and wanna DM for a quick chat?

rotund isle
#

Hello, I am currently doing the htb academy on WIndows Fundamental Module. I however got stuck at skill assessment. Any idea how can I create security group called HR? I already create the folder named Company Data and subfolder named HR.

urban flume
#

Paul

worn rampart
#

Anyone knows what we have to change between proxychains3.1 and proxychains4 ?
Because I am putting

#socks4     127.0.0.1 9050
http 127.0.0.1 8080
https 127.0.0.1 8080

At the end but I get this :

[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
error: invalid item in proxylist section: https 127.0.0.1 8080

scarlet fox
#

I am on the Linux fundaments and I can't get the target to work

urban flume
raw saddle
#

Anyone available to help with the Linux Priv Escalation? Stuck on the Privileged Groups section

jolly hound
#

Hey all I am stuck on the user management question 8 about locking an account I have tried all basic ways of typing but nothing seems to be correct any help is much needed thank you

main vapor
#

Not sure if anyone would agree with me but I genuinely think that the text color used in the modules is extremely dull and shallow, compare it with white instead!

#

The original font color, I mean it's almost a camouflage with the background.

manic moat
#

Stuck here... Not sure where , what and how should i search

manic moat
#

Ok, i found the port but after use some utility it says :Address already in use... I cant get flag

#

Ok, here is an answer || check that there is nothing on port you need to use with sudo lsof -i :and port here|| cuz i have my head blew off by this task

icy snow
#

Did you figure this one out? I’m stuck here too.

mortal basin
noble stirrup
#

Am on the SQLi module. Resetted the box many times, still no luck. This happened every time, i.e. it NEVER connected in the first time (by SQL). Is it something I am doing wrong here?

#

Can't even ping the box

#

The internet connectivity is pretty great. Not quite getting why this is happening ;-;

main vapor
#

You are not supposed to ping the host @noble stirrup

#

You are supposed to connect to MySQL on the given port.

noble stirrup
#

Obviously, thats what I did above, pinged it to check if it works,

#

In the same image

main vapor
#

Oh I did not see that pardon me

#

It might be from the VPN maybe?

noble stirrup
#

I have seen some reddits where this is addressed as well, cant seem to find anything there

main vapor
#

I would reset it and the host also

noble stirrup
#

You mean the instance?

main vapor
#

yes yes that

noble stirrup
#

Ig I'll have to do on my VM then, resetiing it would terminate

#

Tbh, yesterday, had tried this on my vm, exact same command, didn't work there either. Am gonna try dat again

main vapor
#

Yes if things dont work out in the Pwnbox just go for the host, I have never experienced any issues while doing it from mine.

noble stirrup
#

I see

main vapor
#

I did the module and everything ran sweet

noble stirrup
#

That's nice

#

Hopefully things run smoothly for me as well

main vapor
noble stirrup
#

Ah I see

noble stirrup
#

Nope, nothing worked, I was in doubt if this would work when I saw it since the stack overflow page had an issue regarding system error : 0 whilst, mine said system error:11.
And tis confirmed, HTB, do something

#

Since its extremely frustrating. This should not happen :/

hollow flame
#

what font is this?

agile torrent
#

not sure, but if you go into the dev tools and look at the css rules applied to that text, it should show it

hollow flame
undone reef
#

hi, i found a samsung A40 and i need to bypasss google check security after errasing all datta, can someone help me pls

#

?

rare jackal
#

Is it just me having an issue connecting to mysql for sql injection fundamental? It just doesn't work with right ip and port

#

Error 2002

rancid oar
#

@noble stirrup are you connect vpn buddy

rare jackal
#

so i'm just using the workstation provded for each lab

elfin valve
#

Hey. For XSS module, i can't get the target to be spawned. It just stays stuck at 'Target is spawning'.

sharp glade
#

I'm currently doing the getting started module, upto web enumeration and it seems that no matter what I do to the target IP I can't get a response. Whatweb, Nmap, Gobuster, just visiting the ip in browser to look for a webpage. I am connected via VPN from a VM. Google has been no help. Any suggestions?

#

Even when on the pwnbox I couldn't get it to give me a response.

sharp glade
raw saddle
#

is flag1.txt missing from the linux privilege escalation target? It says you can cat for it in the bash_history but I dont see the file anywhere on the system even after restarting the target

sinful gorge
#

Bash history is a tramp 🀭

raw saddle
#

Is it named flag1.txt? This still shows nothing

sinful gorge
#

Yes, it is

raw saddle
#

I'm seeing flags 2,3, and 4 but not 1

sinful gorge
#

Modify find params

raw saddle
#

Ok that helped. I found it. It do be kinda hidden tho.

warm quiver
#

Hi. Anyone able to help with Broken Authentication - skill assessment? Looks like I'm stuck.

sinful gorge
lament rampart
#

Has any done the "Attack common application" module? I am stuck at "attacking gitlab" and "skill assessment 1". I could use some help. Please DM me!

lament rampart
noble stirrup
#

Had spawned multiple times, each of the time I reset the machine, it still does not connect to mysql

noble stirrup
lament rampart
#

I run into a situation where I can connect to a target initially, but will disconnect every 3-5 minutes. It is due to I connect to my HTB academy VPN from multiple machine: my VM, VPS and Pwnbox. I am not sure whether it is what happening to you

noble stirrup
#

My situation is a bit different. I can't connect via MySQL to my Target at all

tame epoch
#

Can HTB Academy prepare you for bug bounties?

urban sky
#

@noble stirrup Still not connecting to MySQL target? Im having the same issue

raw saddle
#

Has anybody been able to get flag5 for Linux privilege escalation assessment?

raw saddle
high zinc
#

But it's not a tutorial from a-z and you don't start magically making money at the end

tame epoch
high zinc
#

Oh it contains a lot of great courses which will definitely help you with bug bounty hunting

tame epoch
#

whilst completing the academy
Not sure if that's possible on the free version though, due to the paid modules thing
Don't really have any money as a student so I can't buy more cubes, but I'm sure there's some good free resources out there

high zinc
#

some might require a small fee though πŸ˜…

tame epoch
#

Yeah 😬

high zinc
#

If your school qualifies for this, you can get your account upgraded to a student account

#

this will get you a lot of the paid modules for free if I remember right

#

@languid fjord knows ❀️

languid fjord
#

yes

#

what is up

languid fjord
high zinc
#

aah

#

my bad

mild kettle
#

I'm trying to get the Using Web Proxies, Repeating Requests section flag, but everytime I try to 'cat' into the folder/file nothing populates on my Response part in BurpSuite. Could someone set me in the right direction? Also here is a photo of what I've tried so far

rustic sage
#

i can't seem to find the link to download the openvpn profile for HTB Academy. Anyone know where that is?

noble stirrup
lament rampart
#

Yeah I was on the student plan and it was great. Now I am going to move to paid plan to get some cube for Tier 3 and 4

mint karma
#

I had no issues

#

Which section are you on

mint karma
#

That was a tough one

#

You need to use the name you found from the previous excerise

#

It Starts with an H and end with Y

#

Thats the name of the employee

#
oblique cypress
#

I'm having a bit of an issue.
I get the error that the host is down in nmap and then using the -Pn option it says host is up but all 1000 ports are filtered.

  • The green chat bubble is not active with message "Something's wrong We're unable to load the messenger"
#

I have no way to contact the support

#

Any ideas that I could try?

undone tusk
#

hey when trying to use ffuf (like in attacking webapps with ffuf), the output looks like

:: Progress: [4614/4614] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors: 4614 ::

``` does anybody know how to make the output normal?
#

the command i used is ffuf -u http://ignition.htb/FUZZ -w /usr/share/wordlists/dirb/common.txt:FUZZ and it just spams the Progress thing on new lines

warm quiver
undone tusk
#

no, basically the same but in a bigger window

raw saddle
#

Are there any modules that teach about port forwarding?

undone tusk
pine sable
undone tusk
#

It used to output properly, but now it doesnt im going to try switching which version of ffuf i have downloaded

#

uninstalled ffuf and installed ffuf v1.3.1-dev with git clone https://github.com/ffuf/ffuf ; cd ffuf ; go get ; go build, and now it works in fullscreen/bigger window (size 93 width is what makes it work)

lament rampart
#

kali use zsh as default terminal whereas HTB pwnbox use bash. Could that be the cause?

worldly grotto
#

Hello i need help i am on the first module and i dont find this answer. I am on : NETWORK ENUMERATION WITH NMAP . can you help me because i did a lot of mp but i can't find the hostname ?

lament rampart
#

have you tried option -A

worldly grotto
lament rampart
#

It basic does -sC -sV -O and give you a lot info on the target

worldly grotto
lament rampart
#

which section is this question

worldly grotto
#

NETWORK ENUMERATION WITH NMAP

lament rampart
#

I am referring to the section name in the table of content

worldly grotto
#

Host and Port Scanning

lament rampart
#

Keyword for this question is smb, try to look through the nmap output

worldly grotto
lament rampart
#

yeah

worldly grotto
#

ok

#

good thanks

warm quiver
#

Stuck on Broken Authentication skill assessment. Anyone able to help? DM please.

vernal reef
#

Hi I am stuck in sqlmap flag#5 I got one entry but is not the flag is blank... Could someone help me out please?

hollow oyster
manic moat
#

Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www(.)inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.
All numbers i get are wrong.... Hints? Already use curl, grep, sort, wc

ADDED
Did it manualy, cuz all of those utilities gives me higher number of links than it actialy is

old birch
oblique cypress
#

I'm having a bit of an issue.
Using Pwnbox, I get the error that the host is down in nmap and then using the -Pn option it says host is up but all 1000 ports are filtered.
I can not contact the support, the green chat bubble is not active with message "Something's wrong We're unable to load the messenger" 😦
someone help please 😦

lament rampart
#

can you ping the host

oblique cypress
#

yep

lament rampart
#

that would be strange. May you can share a snapshot of your nmap command and output

keen wave
#

Hi I’am working on Attacking Common Application in Splunk - Discovery & Enumeration. I spawned the target but it turn out to be running only PRTG Service running (no splunk) please help πŸ™‚

high zinc
keen wave
#

Thank you 😊

gusty wagon
#

Getting time out while using my own VM for connecting FreeRDP to windows. Weird, it works fine in the web browser.

lament rampart
#

Packet drop could happen if your VPN is connected by multiple devices at the same time

torpid ermine
#

anyone please give me an nudge on command injection module bypassing other blacklisted characters section

torpid ermine
thorny crow
#

What's the secret to get paste to work from local PC to the PwnBox? Can copy out, but not paste in.

worldly grotto
#

Hello can you help me i dont find the answer, i dont understand the question. I do not understand what to put is the version of what services?

rustic sage
#

uhm

#

Hi im new

gusty wagon
gusty wagon
high zinc
high zinc
#

(MewTwo anyone?)

wind aurora
#

Yes

worldly grotto
high zinc
#

depends if I've done the module or not

#

which one?

worldly grotto
#

Section : NETWORK ENUMERATION WITH NMAP : Firewall and IDS/IPS Evasion - Hard Lab

high zinc
#

haven't done that 😦

worldly grotto
#

ok

wind aurora
#

Submit ur quetion

worldly grotto
# wind aurora Submit ur quetion

Hello can you help me i dont find the answer, i dont understand the question. I do not understand what to put is the version of what services?

wind aurora
#

I have't done this lab show me hint

#

Maybe i can help u

worldly grotto
wind aurora
#

Use version detection swith with nmap may b u will find something

#

*switch

gusty wagon
#

just finished "WINDOWS FUNDAMENTALS" I had to redo the last section like 3 or 4 times to get the SIDs right πŸ˜• but I had WinFun!🀣

empty forum
#

What does one needs to learn before trying the academy from Hackthebox?

high zinc
#

It's designed to be approachable by everyone regardless of skills, however not all topics are beginner friendly

#

the free ones are good starter modules (although are still of high quality)

empty forum
#

Yeah but, do you understand every bash/sed line they ask for?

#

Because copy + paste isn't learning imo

#

I saw some lines that where hard to follow

#

For me

#

So how do you do it?

#

So fast

high zinc
#

most modules will explain how some theory is and then have you apply that theory

#

some of the modules are structured such that you have to do a little Googling or reading the manual of something on the side, too, to successfully answer the question

#

but i mean...

#

it's pretty basic theory in most of the free modules

#

My own Introduction to Python 3 module that I wrote, I wrote in a way that if you've played around with programming before or have seen the "hello world" of another language, you can follow along easily

#

but if it's the very first time you touch a programming language, the learning curve is a few degrees too steep for comfort for many

#

that said, it covers all of the most basic concepts

#

...it just moves a little fast for complete beginners, and be design (I could write a book with all the things I wanted to say about it lol)

empty forum
#

It's the command line that i get stuck at sometimes. I know a little bit C and use Python a lot these days

high zinc
#

that's what some of the reviews say as well: if you're a complete beginner and have never seen a programming language before, it could be a good idea to just play around with it on something like coderank and what they're all called

empty forum
#

I'm ok using Bash, but when sed/awk comes along.. it's harder

high zinc
#

not because my module is hard, but because it assumes you have seen the "Hello World" of another language

#

right

#

Hacking is not about memorising cryptic combinations of sed/awk/grep/cat/stuff

#

I haven't had to use sed/awk every before in my life

#

lol

#

I'm sure you'll be fine

#

It's meant for beginners afterall

empty forum
#

I'll check it out again then... thank you. Btw what are you using Python for?

high zinc
#

work mostly

#

automating CI/CD configurations, test frameworks, data extraction and report generation

#

and basically anything I need to automate in Hack The Box πŸ˜„

#

My Python is 200 times better than my bash

empty forum
#

Ah cool, i have to google the definition of CI/CD though haha. The problem i've with Python is that the use of try except is not clear. Some disapprove the basic use that the documentation implies, and create error functions/methods. Also the paradigm of the use of Classes differs from opinion, while PEP can be a bit vague to me lol. What's your take on this?

#

I mean composition is good, but the use of instances should be limited.. eh ok...

high zinc
#

My first language I learned well was Java and in Java I was taught to only attempt to handle exceptions if I had no other way to verify whether or not something would go well, e.g. if writing a file to a disk would succeed (what if there not enough free disk space?). Because of that I don't use try-except a whole lot, because there are ways to work around a lot of the usual exceptions one could run into.
That said, in Java handling exceptions is very expensive, resource wise, and should be limited. In Python, trying something which succeeds is done at nearly no extra strain on the system, if any at all. If it fails and an exception has to be caught and handled, there is some overhead yes, but if it goes well, there is virtually (or literally - I forgot) no performance difference.

#

Out of principle I don't use them a lot, though

#

Need to grab a value from a dictionary, but you don't know if it will succeed? Well, you could check if my_key in my_dict before trying to get it

#

you know

#

Error functions - not sure what these would be to be honest.

empty forum
#

I'm not sure either, but they look awful

high zinc
#

As for classes, because Python is "multi-paradigm" and loosely typed, I think people use them out of habit from previous experience more so than for "pythonic" reasons

#

There was this guy Raymond who did a presentation on the MRO, Method Resolution Order, in Python (https://www.youtube.com/watch?v=EiOglTERPEo) which demos how one could use the core design of Python and class inheritance to ones advantage

#

it looks super (pun intended) cool, but besides a test case I think my old lead dev has since then rewritten, I've never actually used it myself πŸ˜„

#

(Something-something I was able to "hijack" a session object or similar without mocking, simply through class inheritance and careful construction)

#

It was fun, but a little too out of place in our codebase back then

thorny crow
#

Can I get a sanity check on the skills assessment for Windows Binary Exploitation?

empty forum
high zinc
#

It's a good talk and very captivating I though - it's about Pizza πŸ˜„

#

Anyway I should go to bed... have a good one and welcome on board

high zinc
high zinc
#

sure

slim stag
#

bro

#

HOW TO HAGG

torpid ermine
#

hello can you help me to solve this quetion in command injection module πŸ™‚

plucky nimbus
plucky nimbus
silver otter
#

Hello, I have just completed the flag for the Web Request POST but the flag that i get from the server does not work, anyone else facing the same problem?

#

Not working as well

rustic sage
#

The hex alone is enough but if it's still not working reset the challenge

#

like close and re open a window to get a new IP, idk

silver otter
#

Okey will try that thanks for the tip!

#

This sucks man! I have used so much time in solving the lab and now it says the flag is incorrect, I have checked it twice for not including any whitespaces

rustic sage
#

anytime, it's very case sensitive so yeah make sure to only put the flag

#

but I don't see anything other that could be a solution

silver otter
#

me neither mate!

#

Thanks though!

#

So I found the solution the flag should be submitted without "!"

#

at the end, If you find any flag and having problem with submitting it.

knotty hemlock
#

Hi, did anyone finish the final assessment of the Whitebox Pentesting 101: Command Injection module? I got the exploit working locally at my PC and it seems also working on the server., but i don't see anything... i think i'm either reading or writing the wrong file 😦

rustic sage
rustic sage
#

Hello, on the SQL Injection course in HTB Academy, the instructions ask me to connect to a mysql database. However, I don't see what password I'm supposed to use. Where might i find it?

#

nm, got it. the pw was on a previous page

#

hi there, can i ask someone a question about "web attack" module?

fossil crescent
#

On the Active Subdomain Enumeration portion of Information Gathering - Web Edition -- can anyone help nudge me on how getting finding TT record contents, along with FQDN of 10.10.34.136 & 10.10.1.5? I'm fairly certain it's all about leveraging other zone, but for the life of me, I cannot seem to get it to work. (So either [a] my presumption of what other zone is, is wrong, or [b] I'm doing something wrong.) Thx.

main vapor
#

@fossil crescent Look at #858470491676737536 because if I am not mistaken someone asked the same question as you.

knotty flare
#

Same problem here.

knotty hemlock
fossil crescent
#

@main vapor Thx for the response. Unfortunately it didn't help as I was already trying to run nslookup with the DNS server... BUT... with a bit more playing around, I did just get it solved!

EDIT: ~~I do not understand why the solution is what it is (if anyone can help educate me, would be VERY grateful)... but happy it's solved. ~~ Thx to @lament rampart for helping bring clarity on this.

knotty flare
fossil crescent
#

@knotty flare & others -- The nudge I'll give is that what I thought I should be querying (||the other SOA zone||) wasn't the right thing to query. If you ||quasi-follow the Gobuster steps (I didn't actually use Gobuster, just nslookup)|| you should get there.

If remain stuck, feel free to DM me.

glossy sierra
#

Hey can I dm someone for Intro to Network Traffic Analysis module

vernal reef
#

@plush garden you still stuck I can help you

#

Dm me

sour zealot
#

Anyone having lost connections to the target VM in the Windows Fundamentals module?

#

I can't keep that rdp connection up for more than a minute, and that if I actually get to connect

sour zealot
gusty wagon
#

@sour zealot i used the Pwnbox after trying with my own vm and it worked fine for me. couldn't find the cause for the error

lament rampart
#

I experience time out issue before, then I realized it is because my academy.opvn is connected by multiple device (my VM, VPS and Pwnbox). Once I shutdown other connection, it is back to normal

#

By the way, when using Pwnbox If you close the browser without terminating it, the Pwnbox is still connected to your VPN

sour zealot
graceful parrot
#

al ejecutar este escript
#!/bin/bash

for i in {1..10}; do
for hash in $(echo -n $i | base64 -w 0 | md5sum | tr -d ' -'); do
curl -sOJ -X POST -d "contract=$hash" http://server_ip/:PORT/download.php
done
done
me sale el siguiente error: Contract name is not defined.
Alguien tiene alguna sugerencia?

graceful parrot
#

Web Attack

#

Bypassing Encoded References

subtle heron
#

hello has anyone done ffuf module;

fossil crescent
#

@subtle heron -- I just completed it

pure vector
#

Any one done before BROKEN AUTHENTICATION > Guessable Answers ? Im little stuck with that

empty zenith
#

has anyone pass "Firewall and IDS/IPS Evasion - Hard Lab"
need some tips for this one please 😩

empty zenith
lament rampart
#

I can only remember that you need to disguise the traffic as dns packet. There is one post in the forum that has the answer

rustic sage
#

Anyone able to give me a push on the SQL Injection Skills Assessment, the last exercise?

vernal reef
#

@rustic sage o i just dm you πŸ˜‰

olive bobcat
#

Anybody to give me a nudge for last assignment in information gathering web edition? (the one about "elephants")

pine sable
olive bobcat
pine sable
lucid veldt
#

I think it's either a bug or the instruction not clear

calm plaza
#

anyone know about debian networking?
when we use iwconfig command it give result in both lo and eth0 is no wireless extension
and when we try to openvpn you must define TUN/TAP device --dev

pine sable
rare jackal
#

Hi Guys, I'm stuck with bruteforce/Service Authentication Brute Forcing part as none of those rockyou password list ever match with the user name. Can i please get some help with this? do I have to use a custom password list?

lucid veldt
#

File Upload Attacks Blacklist Filters it is filtering the payload not the extension(<?php become <!--?... I believe it's a bug.

gentle herald
#

yes phpcode is viewing as html code

#

i also stuck at that

#

its not rendering as php

lucid veldt
#

I believed the environment been mixed and messed up.

gentle herald
#

ohhh

lucid veldt
#

That one should just about Attacks Blacklist Filters.

gentle herald
#

yes

#

like finding correct extension

lucid veldt
#

yeah, I even tried obfuscate my php payload.

gentle herald
#

lets do other sections and after that we try again this

lucid veldt
#

I bought the Annual Silver plan. However, I kind of get the bad feeling recently.

#

HTB Academy are rushing now. Because of the bug bounty path and exam needs to release at Q4.

#

Please don't rush, we can wait for another deadline. But delivery fully tested modules

gentle herald
#

exam ?

#

any nudge on whitelist filters ?
i got fileupload successfully
but it says not found in browser

mortal basin
lucid veldt
gentle herald
lucid veldt
#

It ends at filtering the php payload. <? will be commented

gentle herald
#

its rendering as html

mortal basin
#

This isn't a bug. It's not the correct answer. The payload isn't affected by the filter whatsoever.

As mentioned in the module, you may be able to upload some php extensions, but not all of them may be allowed php code execution. If they aren't, you'll just get the code back.

Try to look for another allowed extension

gentle herald
#

tried php2-6
will try more

mortal basin
#

Use a wordlist+fuzzing as shown, it's the fastest method

lucid veldt
#

I tried all extension from SecList web-extensions

gentle herald
#

i fuzzed

#

will try more

mortal basin
#

You may DM me if you need any help or face any issues.

gentle herald
#

sure

mortal basin
#

Module quality has always been, and will always remain, the #1 priority πŸ˜€

gentle herald
#

will try more extensions
if failed i will dm you

lucid veldt
#

Thank you

lucid veldt
still mango
#

hai

mortal basin
lucid veldt
lament rampart
sly nebula
#

Anyone on Common Applications - Skills Assessment I?

#

Stuck at exploiting the vuln.

jagged anvil
sly nebula
#

Exactly

jagged anvil
#

I spent the whole day yesterday

#

Did u find the manager?

sly nebula
#

Nope

#

Doesn't seem to be there

#

We must be missing something

jagged anvil
#

Yeah

mint karma
lament rampart
sly nebula
#

Thanks a lot! I was just about exploring that.

sly nebula
#

Found something very interesting. Thanks again!

stiff stream
#

It's funny how you get stuck at one point, feels like you're not progressing at all, then take break or sleep for the night and next day you got it

wind aurora
#

@mint karma u got the shell but cant't find the flag due to low privileges. Is that ur quetion?

rain marlin
#

I'm not following.

mint karma
#

it is using network file sharing

silver otter
#

I am working on Webrequest PUT method, I have putted all the things correctly though now its not giving me the flag and shows me 500 internal server error.

#

In the web browser it does nothing.

patent basin
#

ffuf skill assessment Q2 ```
Before you run your page fuzzing scan, you should first run an extension fuzzing scan. What are the different extensions accepted by the domains? (Write the extensions as '.ext', in alphabetical order separated by spaces ".ext1 .ext2 .ext3")