#modules

1 messages · Page 505 of 1

unique star
#

You can DM if you want

prime meadow
#

@unique star thx !

real nebula
#

Can i ssh to htb target from my pc?

#

or need to boot htb istance?

#

because if i run :

#

ssh htb-student@target

#

it doesn't connect

languid dawn
#

if you're on the vpn yes

real nebula
#

what do you mean? should i connect to the same instance vpn?

languid dawn
#

you should have a vpn file in the downloadables of your module iirc

real nebula
#

yes, get vpn key

#

and i have downloaded it

#

should i configure it in my openvpn service?

#

Did it, nothing changed

#

used :
openvpn --config /path

Started the configuration

#

Ok, got it. was just :

sudo openvpn /path

real nebula
#

how do i get root access in ssh sessions?

#

there is no txt file where su password is written

#

because if i try to list .conf files it says permission denied

#

got it...

royal echo
#

first question on linux fundamentals is kinda confusing.. it asks about what options to select when creating home directory using useradd command..what is the correct answer to that? tried using useradd -m but didn't workl

rustic sage
misty remnant
#

hi short question to INTRODUCTION TO WEB APPLICATIONS, where i can spawn a target😂

rustic sage
#

It depends on the questions you're given to answer

misty remnant
#

and can someone recommend the Bug Bounty Hunter Path, so the full cource

#

i have to say the value of something, but for this i need a target

rustic sage
plucky crown
#

HTB Academy Module 35 : Web Requests > Post Method

#

I don't understand what to do now

#

I have logged in

cunning token
#

@plucky crown I'm stuck at the same part. I swear i've tried every combination possible

plucky crown
#

without this random string

muted kite
#

im stuck in nibbles

agile torrent
muted kite
#

well I closed it all down and going to start over just incase I missed something.

agile torrent
#

👍

muted kite
# agile torrent 👍

so I get lost after it's revealed what the password is, nibbleblog/admin.php doesnt take me to a login screen

#

after that, on the next page it says to save a code, but doesnt say to what or what I should name it or what folder

#

alright, im going to revisit it tomorrow, logging off HTB for the night

shadow verge
#

I'm stuck on LFI last section and I've tried to use php filters and I know how the LFI payload is sanitized, but I still don't know how to get shell. Need help.

muted kite
#

I kept on trying, got further, but still got lost again

storm summit
#

Hi all

is somebody there and can give me a little hint for the last question in the Footprint Module -> SMB

"What is the full system path of that specific share?"

I only have one path but does not match as answer..

unique star
storm summit
#

this is my issue, i know it is in a linux -> Ubuntu machine but have an windows path

fierce pond
#

😖

#

Submit the size of the stack space after overwriting the EIP as the answer. (Format: 0x00000)

#

how to calculate the size of the stack depending on the EIP you have >

#

?

grand locust
#

were you able to get root? Got first flag with ease, but cant get root. I've tried everything. Can you help with privesc? I'm not able to do anything with gtfobins.

fierce pond
#

well i know that i need to use the info but i really dont know what flag with that

unique star
#

DM

sweet scaffold
rustic sage
#

What username ultimately works with the remote management login prompt for the target?

#

i think root ryt

grand locust
sweet scaffold
#

no problem men, keep it up

#

gtfo bins is useful so much

wary forum
#

Stuck on SA shells & payloads host 2. Can anyone assist ?

rustic sage
#

What is the name of the share we are able to access in the end?

grave stream
#

Hi

#

Can i ask a question which is not about ethical hacking. asking due to I've been kicked once

copper creek
#

If someones thinking about taking the Footprinting Module, I can really recommend it. Do it! One of my fav. modules so far on academy!

crimson path
grave stream
crimson path
#

What exactly are you trying to ask?

grave stream
crimson path
#

<@&861185840277487616>

languid fjord
#

sup

grave stream
high zinc
#

@grave stream you cannot ask about illegal things and especially not in a channel meant for the HTB learning Academy

rustic sage
high zinc
#

It summons all the admins and moderators

#

because someone's being a bad boy

rustic sage
#

<@&861185840277487616>

grave stream
#

sorry i didn't know about that

#

i'm not gonna do that again!

little whaleBOT
#

mr.rex got the boot!

high zinc
#

One would have thought you would know not to do it again after having been kicked from other servers

grave stream
#

my apologies

high zinc
surreal rain
#

👀

coarse inlet
#

Got a "simple" one

Doing the Active Infrastructure Identification part of Information Gathering.

The second question states Which CMS is used on app.inlanefreight.local? (Format: word)

I've ran a scan using Wapplyzer and identfied Joomla is the CMS but Academy says thats incorrect thinkw

Anyone got any ideas?

#

^ I've done the other two questions on this section, just not sure why Joomla isnt liked

rustic sage
#

Maybe it wants the version of the CMS with it, run whatweb and see if it tells you Joomla aswell

#

whatweb -a3 <target>

coarse inlet
#

Nice... without spoiling for others, the whatweb output is slightly different from the output of wappalyzer

Nice, cheers dude! @rustic sage

little whaleBOT
#

Please see your DMs for instructions on how to verify your HTB account.

#

Please see your DMs for instructions on how to verify your HTB account.

alpine vault
#

Hi All! I am stuck on finding a version for a service in "Firewall and IDS/IPS Evasion - Hard Lab", I have not been able to find a version that it likes as a solution, is it true that the solution doesn't work on the HTB VM?

rustic sage
uneven ivy
#

i have questions about the Stack-Based Buffer Overflows on Linux x86 module. Some things are not clear to me.

#

for instance why the payload becomes 124 bytes at the end. the total buffer is 250 and the shellcode 94!

#

also the question about the stack size is not explained anywhere in the module. even when i found the answer i was wondering how it was calculated.

crimson crown
#

Stuck on Intro to Web Applications - HTML Injection

#

it won't accept the correct answer

#

have tried multiple links

blazing bridge
#

At Learning Process i got confused because 36,7 was wrong and 36.7 was right

west canopy
#

@crimson crown about to send you a DM brother 🙂

crimson crown
#

thank you

west canopy
#

@alpine vault gonna DM you too dawg!

#

@wary forum check DMs if you still need help brother

low vine
#

Hey guys just started / signed up for the academy, I see alot of stuff im interested in learning that are coming soon, do we have rough estimations on timelines for those?

#

(plenty of content to go through before i get there, but just curious

slow kayak
#

Can anyone give me a nudge on gaining foothold in Windows Privilege Escalation Skills Assessment - Part I?

west canopy
#

@slow kayak Sorry brother I haven't gotten to that module yet

slow kayak
#

@west canopy all good. its been a struggle. I can execute commands on the host using burp just cant get a reverse shell command to work sadglas

mild grove
#

hello,

I have question regarding Web Request Post method what is correct answer please ? What should I submit ? Base64 encoded string or ...

#

"Submit your answer here ..." and answer is what ? random strings or ..

main vapor
#

@mild grove DM me.

mild grove
frigid vector
#

Guys need little nudge in Stack-Based Buffer Overflows on Linux x86 module (Determine the Length for Shellcode chapter)

grim raft
#

I'm stuck ...

#

It is the Getting started module about Public Exploits

#

Ping is not working...

quiet spindle
#

on getting started, im on the msfconsole command and i cannot get it to check or run/exploit, im stuck

#

i dont know what im doing wrong, im following the commands etc... but it dont work, im also new, hiya everyone

quiet spindle
grim raft
#

yes

shrewd sage
#

Hi im a noob 🙂

little whaleBOT
#

Please see your DMs for instructions on how to verify your HTB account.

quiet spindle
grim raft
#

Yeah for sure

rustic sage
#

Hi

#

how do I verify?

quiet spindle
#

& follow instructions

quiet spindle
rustic sage
#

ightt

coarse inlet
#

Vague one on
Anyone got any ideas on Active Subdomain Enumeration questions inside Information gathering - Web Edition

What is the FQDN of the IP address 10.10.34.136?

and

What FQDN is assigned to the IP address 10.10.1.5? Submit the FQDN as the answer.

I assume I need to use nslookup/dig but whenever I do a reverse proxy it doesnt work. I am missing something relating to zones?

Any help would be appreciated 🙂

dusk bronze
#

I've gained the cookie that lets me to log as admin in the web requests's POST METHOD section, but as I'm submitting it I'm getting a incorrect answer no matter what I try.
Why is that? seems like an overcomplicated challenge for just a cookie manipulation

muted kite
#

alright im back to give nibbles another try, this will be my fourth attempt, I literally have no clue what im doing wrong, perhaps not even what im doing right

west canopy
#

@muted kite get it big dawg!

#

@dusk bronze about to send you a DM brother

shrewd sage
#

Hey, someone know what they want to be submitted? Module Web Requests in the academy:

Login with the credentials (guest:guest), and try to get to the admin user from what you learned in this section and the previous section.
coarse inlet
#

Heyo @shrewd sage

I'll DM you! 🙂

patent sinew
#

Anyone done the footprinting dns module? I am stuck on the last question.

#

What is the FQDN of the host where the last octet ends with "x.x.x.203"?

drifting knoll
#

pay attention to the "dangerous settings" part

timid juniper
#

Getting no packets when pinging my target machine for Getting Started-MEOW??? any help??

muted kite
#

in nibbles does anybody know why when i run the gobuster dir -u target link wordlist filepath its literally going through every single file? out of 63,088 i was under the impression it was supposed to do this quickly

#

instant

#

i mean I only have so much time for the target link before I have to spawn another target machine

grand grove
#

Hello all, I'm stuck on IMAP POP3 part of the module Footprinting someone in PM to help me ?

muted kite
#

anybody around to hold my hand through nibbles?

#

Ive made progress

#

but need more guidance

#

Im to the part where it wants me to add script to the myimage.php file and I want to know if I literally just copy and past

#

one per each line and leave the original line or replace the original line

#

I am stuck at getting the reverse shell part and could use some help

#

i ran the port listening command, but the link for reverse shell isnt working

#

i cant find user.txt there is no directory for /home/nibbler

#

i have 5 mintues left on target machine. im at a loss again

raven robin
#

Greetings, I finished the asm course today, and would like some help in re-doing the 'Shellcoding Tools" skill assessment

#

I did the easy way by generating the shellcode with msfvenom, but would like to accomplish it myself

#

Here are two hypotheticals for the task (generating a proper shellcode that reads from a file called /flag.txt)

#

Both of those give me a segfault, and I guess I must be fundamentally misunderstanding something about syscalls.

weary forum
#

Hi, everyone. I am at the "Getting Started" Module, and I am at this question: "List the SMB shares available on the target host. Connect to the available share as the bob user. Once connected, access the folder called 'flag' and submit the contents of the flag.txt file."

#

Here's what I did. First, I got access to Bob's SMB account share, and was able to see the flag.txt, so I used the "get" command for the flag.txt text. However, I don't know how to read it or open it.

#

Once you have downloaded the file, is it possible to read it once you have

west canopy
#

if its a windows box you could try using the "type" command it's like cat for windows

#

type flag.txt

weary forum
#

oh, ok. I will try that. I tried using the cat command, but it's Windows

patent sinew
#

Is the hash suppose to take a while to crack on IPMI part of Footprinting?

muted kite
#

or 'type'

stoic pebble
#

Hello, can I please ask for some help on the “Getting started, knowledge check”. I am looking at sudo -l and see any user can access /usr/bin/php. I ran LinEnum.sh on target but maybe missed info. Could you point me in the right direction for this privilege escalation part, Thanks 🙂

muted kite
#

im also stuck in Getting Started

#

wish it were a little easier, but its quite lengthy

stoic pebble
#

nibbles or the knowledge check?

muted kite
#

nibbles

#

Im about to do my sixth attempt at nibbles in Getting Started module

stoic pebble
#

reverse shell not working?

muted kite
#

it sas listening inverse host lookup failed

#

shows uid gid and groups

#

$

#

cant enter any command from there

agile torrent
#

@muted kite im available for the next couple hours if you want a hand through nibbles

muted kite
#

im currently in, Im trying to navigate the reverse shell

agile torrent
#

did you get the nc connection back?

#

maybe move this to dms tho so we don't fill this channel

muted kite
#

okay Im working on it

#

ok

low vine
#

Having a bunch of problems in the "Public Exploits" module

#

in getting started.

#

I've found the information i need and i'm trying to understand what im doing wrong with searchsploit

#

From my understanding of the module i should be able to
use php/webapps/44417.txt

coral sundial
#

@low vine Just posted soming on starting point for you

low vine
#

oh thanks looking now

tight glen
#

Module: Using Web Proxies
Section: Web Fuzzer - Burp Intruder
Question: Use Burp Intruder to fuzz for '.html' files under the /admin directory, to find a file containing the flag.

Can somebody help me? im not sure if im doing it right and burps free fuzzer is really slow

tight glen
#

But thats not the goal, i finnished the web fuzzing module already

tight glen
tight glen
#

does this work in theory?

unique star
#

See the respponse of the server

languid dawn
#

yes it works, but arguably burp is not the best tool for that

tight glen
#

Its a 404.. im fuzzing

tight glen
languid dawn
#

yeah np, I get that

#

burp is powerful

tight glen
#

If you own he professional version of burp it is as good as ffuf / gobuster.. maybe its missing recursive scanning tho?

languid dawn
#

all I know is that pro wouldn't rate limit you

frigid vector
#

guys need a little help with Stack-Based Buffer Overflows on Linux x86

ionic summit
#

Anyone for a nudge on the Windows Privesc skills assessment #1?

chrome thistle
#

How can i cat a file in a directory when i have RCE like this "...404.php?cmd="?

languid dawn
#

...cat file ?

#

cat /path/to/the/file

chrome thistle
#

sorry for confusion. I need to change the directory first with cd. I like to cd the directory assets and so i need to have a look what is inside assests. cd assets&&ls?

languid dawn
#

You don't need to if you know the path

#

And ls can take a path argument as well

chrome thistle
#

could you give me an example? i dont know the path, i need to find a file first

languid dawn
#

Well you can also grep or use find

#

Using ls every where isn't very efficient 😁

chrome thistle
#

ok, could you give me an example? i have RCE via "404.php?cmd=" and i need to find the flag.txt file and need to have the content of the file

languid dawn
#

find . -name flag.txt

chrome thistle
#

so: 404.php?cmd=find . -name flag.txt will find the flag.txt and show the content?

languid dawn
#

Just find its location if it's in the current dir or a subdirectory

chrome thistle
#

mh i get nothing out when i use 404.php?cmd=find . -name flag.txt

arctic cargo
#

Hi, is this is a correct channel for a new module request?

#

Could you add something about more advanced exploit writting, ie. rop, aslr, egg hunting etc.

livid pier
#

Hello! General question, in payments it says "+ CPE credits submission". What is that?

weary forum
#

Hello everyone. I just have a question to ask you all about sending SYN packets using the --trace-packet command.

#

In the example given for the Network Enumeration with Nmap module, they showed that the target received the SYN packet by the RCVD line with the RST and ACK flag

#

What does it mean when you send two SYN packets, but don't received a respond on that port

#

Does that mean that the port wasn't set up on the target?

#

When I tried it in the lab portion, I didn't get a response, just my two SYN packets. I sent it to the filtered port 21.

alpine vault
#

is this supposed to take this long? Did I miss something? takes way longer than target is active

hallow saddle
#

I had an answer for this question, however I could not find the correct "form" without searching here -_-
What addressing mechanism is used at the Link Layer of the TCP/IP model?

#

It would be nice and if the answer accepted in many form

ionic summit
patent sinew
#

Can someone give me nudge with the SQL Essentials Case #10?

west canopy
#

@patent sinew i got u bruh

livid pier
#

Anyone around to talk about SQL Essentials?

whole fiber
#

for the module on Web requests for POST method, anyone know what the box is actually looking for? i follow the instructions to the tee and gain admin access with the credentials just as the instructions explain, but it keeps saying the answer is incorrect

#

i have no idea what they actually want me to submit

#

idk if they're asking for the session id, or a flag or what, because they don't specify

livid pier
#

I think it is a flag

whole fiber
#

i can't for the life of me figure out what i'm doing wrong, i get admin access just as it requests, but there's no flag to submit

livid pier
#

are you using burp suite>

#

?

#

repeater?

#

If you use the burp suite repeater and enter the cookie info to get admin look over at the response

muted kite
#

I have a few questions about the nibbles walkthrough, I ran out of time so I have to do it again, but I did get the user.txt file hash, I just need to spawn a new machine and try it again

#

My question is that when I am doing the nmap scan am I scanning my tun0 IP address or the target machines?

#

In the steps and walk through, their isnt a clear distinction between the two machines such as what i do with my own machine and what i do with the target machine.

#

that confusion is hanging over my head

#

and i am prone to mistakes because of it

whole fiber
#

i ran out of time

#

i'll have to try again later

livid pier
whole fiber
#

that's so weird, i got admin access, but it never gave me any kind of response like that

frozen sentinel
#

I'm stuck on the last question of the LDAP assessment. "What non-default privilege does the htb-student user have?" It is not accepting my answer. Not sure what is wrong. Can any one nudge me in the right direction?

muted kite
#

Hello is there anybody who is available out there today?

#

I know it's a busy time of the year for everyone

#

Happy New Years Eve!

#

Thanks to all who have been helping me here, I just want you to know, it's much appreciated

crystal arrow
#

Hey, am I getting insane. But shouldn't this be MAC?

#

Perhaps I misunderstood the question.

muted kite
#

I don't know, but I also need help too

languid dawn
#

from that same course:

** MAC-addressing **is utilized in Layer two ( the data-link or link-layer depending on which model you look at ) communications between hosts. This works through host-to-host communication within a broadcast domain.

crystal arrow
#

Yes, didnt work. Believe I tried different caps, Mac, mac-addressing, media access control etc.

languid dawn
#

I would go with Frame if it's layer 2

#

as it's the only addressing done at that layer

#

or does physical addressing count 🤔

muted kite
#

im in a place where I dont even know what questions to ask

#

Ive been following things people did online, but they are not working for me

#

I need a breakthrough today

muted kite
#

is rhost my tun0 or is it the target IP?

rustic sage
#

target ip

#

tun0 is your lhost (local host)

muted kite
#

okay thanks for that, im trying to figure this out

rustic sage
#

anytime

crystal arrow
#

Ok, I give up. I have tried every possible combination now in the text.

#

Where do I send a mail about this xD

muted kite
#

my reverse shell keeps timing out when i enter commands it just sits there and I have to refresh the webpage repeatedly

#

alright i stopped curl and its back

#

Nibble-Privelage escelation

#

need help please

#

I dont understand how or where to download the LinEnum script too

muted kite
#

LinEnum worked and im in but chmod +x LinEnum.sh doesnt give me any input

#

or output

#

i was so close and my reverse shell cut out

muted kite
#

I know it was listed as Easy for Nibbles. But I am so glad I finally captured the root flag

#

it took me like 9-10 tries

slow bluff
#

stuck on the broken auth Predictable Reset Token question 1 any help please

muted kite
#

not sure which module that is, but im certain im probably not in that yet

brittle lava
#

I am relatively new to these challenges and I am at the last stage of the Nibbles box, I have done everything correctly but I can't guess the root password. The walkthrough does not say anything about needing the password for root, I was under the assumption I was already root. I have read people change the password so not sure If I would ever get the password anyway. Please HELP!! I have spent a week on this last part and I do not know what else to do. See proof I am at the last part of it.

high zinc
# brittle lava I am relatively new to these challenges and I am at the last stage of the Nibble...

Happy new year! 🙂
If you verify your discord account (see instructions by typing ++verify in the #bot-commands channel) then you can post your question in the #boxes channel where more people who are doing boxes will look. I'm mentioning this so you have a chance of getting help as this is the channel for people doing modules on the learning academy. 🙂
A member notified me that the box is actually part of a module - never mind then, you're at the right place

brittle lava
brittle lava
patent sinew
#

Can I get a hint for the command injection assessment? I can't seem to find the injection site

wheat rose
#

Can I get a nudge for the public exploits question? I have creds but I can't access the service

wheat rose
#

nvm

muted kite
muted kite
#

I still have to do the knowledge test in that module, it also took me 9-10 tries before I completed nibbles

#

I read somewhere that HTB's Easy Modules are harder than other platforms Easy Modules

lament rampart
#

Hi guys, I am stuck on the skill assessment in server-side module. I have tried ssti with {{7*7}} on username, post title and body. It doesn’t seem vulnerable.

#

Can anyone give me a hint? Thanks in advance!

quick hollow
#

Also very stuck I found some information yet still need some help!

worldly grotto
#

Hey can you help me with this question please i found all other question in this section but not this. please ?
module : INTRO TO NETWORK TRAFFIC ANALYSIS
section : Tcpdump Packet Filtering

rustic sage
#

also unrelated to the question itself, if you wouldn't want to set a flag you could use a pipe to and grep to highlight it ex: tcpdump -i eth0 | grep "10.10.20.1*"

worldly grotto
#

ok

brittle lava
worldly grotto
orchid sapphire
#

cmon

worldly grotto
surreal chasm
#

Hey guys, I need help with a question from Intruduction to networking - subnetting.
Split the network 10.200.20.0/27 into 4 subnets and submit the broadcast address of the 2nd subnet as the answer.

ionic summit
#

In the "Shells and Payloads" module, on the Antak Webshell section, the first question asks for the location of the antak shell on pwnbox. I have copied the exact path from pwnbox, but it's showing an incorrect answer. I've tried multiple variations of capitalization. Has anyone run into this? Any insight would be appreciated!

main vapor
#

@ionic summit DM me.

muted kite
brittle lava
muted kite
#

Ok, I thought it was just me.

brittle lava
#

Anyone know a good daycare level how to for vim?? Not sure why it is so difficult for me to grasp but it tests my will to carry on 😂

brittle lava
muted kite
#

Sure, its what coders use. I did The Odin Project up intil Ruby and than quit.

#

I think sublime is what we used in Odin Project

brittle lava
#

I def want to understand anything I can get my hands on..do you happen to know any good, dumbed down tutorials for it?

muted kite
#

Thanks, its a Chochila from the Amazon

brittle lava
#

Oh wow, see I had not heard of a few of those. I am going to check out vscode..I have heard of that one. In module youtube tutorials, the person runs through vim in 2 seconds and I am spending an hour trying to figure out what they did. That has been one of my biggest obstacles.

#

Bet..thanks!!

muted kite
#

I just really try to be careful what links I click on nowadays, because hackers attach so many harmful files to them, especially google drive, which gives them access to your google account

brittle lava
brittle lava
ruby sapphire
#

whats up guys

muted kite
#

I'm about to start it soon. Was it easy for you @brittle lava

wary forum
#

is it me? or is the active subdomain enumeration section of the information gathering module messed up?

muted kite
#

not there yet

#

I twiddling my fingers with knowledge check

#

got a friend who wont shut up on phone, so I'm just trying to listen and be helpful

brittle lava
brittle lava
brittle lava
wary forum
#

@brittle lavado I have permission to dm you

worldly imp
#

I'm stuck on a question "Perform an Nmap scan of the target. What service is running on port 8080? (two words)" I keep trying Http proxy. I don't know if I correct or wrong. Sorry if I broke any rules. I'm new here

patent sinew
#

On the server side attack module. Can someone help me figure out how to fill the nginx.conf file so i can to the nginx reverse proxy and ajp question.

muted kite
#

or an application protocol

#

I can't remember which one

rustic sage
#

Hey guys I am new to htb and doing the Linux Fundamentals module right now. But I have since 2 days troubles to connect with ssh. I cant connect anymore.. and when I get a connection after 5 min I cant write in the console any commands

muted kite
#

Im going to start that module pretty soon, but as of right now, i'm not sure

worldly imp
muted kite
sleek scroll
#

Hi, I'm stacking on Attacking Common Applications - Skills Assessment I. I couldn't find cgi file even if use fuzzing tomcat server....Does anyone give me a nudge of this box ?

muted kite
#

just remember that port 8080 is an alternative for port 80 and you will know the answer

worldly imp
muted kite
#

I sent you a DM

#

Hope that helps

worldly imp
#

Helped alot.

solar zodiac
#

Hi could anyone nudge me on the directory traversal LFI skills assessment

#

I would really appreciate it

solar zodiac
#

I have rce but for some reason whenever i try to run dir on the root directory it zonks my log file

quick hollow
#

ZAP scanner module HELP PLEASE!

solar zodiac
#

figured it out hehe

#

had to do some traversal instead of absolute paths

worldly imp
#

is this normal? for web enumeration

#

nvm cant post photos

uneven ivy
#

i stuck with the last question from Stack-Based Buffer Overflows. can i pm to someone?

scarlet finch
topaz lodge
#

Anyone good at rpoxychaining?

noble stirrup
#

Is Academy down? When I type my answer in the module, the whole page just freezes, this however, does not happen with other questions, am on the section 'HTML Injection' on the Intro To Web Applications module. Rest everything works fine, can anyone confirm this by going to this in their browser?

noble stirrup
#

Nvm, now it started working

crimson crown
#

hello yall

#

can someone please tell about this server

sturdy shuttle
#

I'm doing Active Infrastructure Identification in the Info Gathering - Web Edition module and know the CMS but it's not accepting the answer. Does it need to be in a certain format?

scarlet finch
#

read

little whaleBOT
#

Katanø_Kushîkutø's name has been updated to Leah McVerify

muted kite
#

When performing 'Knowledge Check' in 'Getting Started' Module what key phrases are we supposed to supplement in place of words like nibbleblog and initial nibbles scan?

#

Also so the target machine is a CMS homepage?

muted kite
topaz lodge
#

did it

muted kite
#

hard to find good dns servers that are free to use, just a couple free ones here and there, look up proxychains4

topaz lodge
#

and supprised I got ir to work

muted kite
#

it's so slow

topaz lodge
#

ye

muted kite
#

lol

topaz lodge
#

to run a nmap throught it

#

lol

#

well 5 nmaps at once

muted kite
#

yeah, I think it has a lot to do with the dns servers

topaz lodge
#

got a DC that need KERBEROSTING now I think

#

but not sure

#

I did SSH -D.....then added the SOCK to PROXYCHAIN

#

and all dropped in

#

never done KERROSTING

muted kite
#

I dont know Kerberrosting myself

#

did you also install tor browser?

#

or anonsurf?

topaz lodge
#

well I used the TOR entery and changed port number to 1080

#

lol

muted kite
#

yeah they work hand in hand

#

why change the port to 1080?

#

speed things up?

topaz lodge
#

ye

#

made it easier

#

lol

#

I can ditch KALI when I have done this and build a new one

muted kite
#

do you think Kali is over rated? I can't tell you how many times it's crashed

topaz lodge
#

No all seems stable

#

I also use parrot

muted kite
#

with the latest kali linux rolling. Whenever I do a dist upgrade, it crashes everytime

errant bridge
#

Hi, I am stuck in the Bash scripting Flow Control - Loops module. Create a "For" loop that encodes the variable "var" 28 times in "base64". The number of characters in the 28th hash is the value that must be assigned to the "salt" variable. also tried 1..28
for i in {0..27}
do
var=$(echo $var | base64)
echo $i
echo $var
echo $var | wc -c

done
gives me an incorrect answer. Any suggestions? Thanks.

worldly grotto
#

Hey can you help me with this question please i found all other question in this section but not this. please ?
module : INTRO TO NETWORK TRAFFIC ANALYSIS
section : Tcpdump Packet Filtering

unique star
errant bridge
#

salt=$(echo $var | wc -c)

worldly grotto
unique star
#

👍

worldly grotto
#

Hey i am on module : intro to network traffic analysis, section : Interrogating Network Traffic With Capture and Display Filters.
but i need make task but i dont find the file for do task. where is TCPDUMP-lab-2.zip ?

unique star
#

Into the resources zone

#

Up in the web

worldly grotto
errant bridge
slow ruin
#

Currently working on the Hack the Box Academy Module 'Firewall and IDS/IPS Evasion - Hard Lab' and found the hidden port. I am trying to use netcat but in the terminal it states bash: ncat: command not found. Is this a bug or am I completely off on trying to do this?

worldly grotto
#

Hey i cant solve this question , i think i understand the question but i put the answer but dont work can you help me ? i put : 80,43804
module : INTRO TO NETWORK TRAFFIC ANALYSIS
section : Interrogating Network Traffic With Capture and Display Filters

white iron
#

Hey guys! Anyone for a nudge on the footprinting module / chapter DNS -> last question: find the FQDN on the host with last octet x.x.x.203?

prisma flame
#

hey! I was looking for some help with the academy module "using web proxies"
Section "repeating requests"
I feel pretty comfortable with using the Burp repeater, I get that I'm supposed to be looking in a different directory for the flag, but the "cd" command doesn't seem to do anything.

drifting knoll
teal jasper
#

hi there

#

how can i access the modules section ?

drifting knoll
teal jasper
#

i just joined the channel

#

there seems to be an academy including modules / challenges

#

how can get there ?

drifting knoll
teal jasper
#

thank you

frosty marten
#

hey super quick question i spawned my target but when i nmap scan against that said target or even ping it comes up as down

drifting knoll
patent sinew
#

Can I get a nudge on the Web Attacks module? I am stuck on the 'file; cp /flag.txt ./' in the HTTP Verb Tampering question.

I have the correct bypass filter but I can't figure how to read the flag using the command that is given.

chrome thistle
#

Hi, i saw you helped someone else with "login brute forcing" before. Therefore im writing to you
[7:51 AM]
im working on the second question on skills assessment - website. and it takes sooo long, im wondering if have done it the right way. here my commando:
[7:51 AM]
hydra -l admin -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt -f 104.248.168.109 -s 31226 http-post-form "/admin_login.php:user=admin&pass=^PASS^:F=<form name='log-in'"

frozen sentinel
#

Is there anyone I can go about sending corrections to the modules? (dead links, typos, etc)

frozen sentinel
tight glen
#

^^

queen steeple
#

hello, i meet a problem on the module Web Request and the section Request and response, Foxy Proxy don't arrive to be connected with burp

cunning heart
#

Is it configured on the same port?

queen steeple
queen steeple
wheat shore
#

Anyone here who finished Footprinting module?

unique star
wheat shore
#

I had a question exactly for the DNS, last exercise 🙂

unique star
#

Well, that's the question i'm stuck after tried everything

wheat shore
#

the fqdn of .203 ip?

unique star
#

I Must miss something

#

Yes

wheat shore
#

Yeah I am working on it now

unique star
#

I know where to search but it doesn't work

wheat shore
#

Yeah, its obvious what you need to do, but which "file" to use

drifting knoll
#

i have to remove your message because of spoilers
read the reason why it failed

olive eagle
#

I'm picking up HTB Academy after a year and I'm still not having much luck with windows targets: I really can't get to RDP to them properly either from my Kali or from the supplied Parrot workstation.
Errors range from [10:01:25:337] [2856:2857] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation to just "failed to connect". I really don't see how this could be on my end, especially after all this time. I've tried on different networks, different computers, different VM's.

#

I'm working on the PowerView module if it makes a difference.

#

Does anyone else have any such issues? Support wasn't really able to help me much last time.

#

Best I've managed to get is connect for 30-60 seconds and then get disconnected.

acoustic zenith
#

Hi there, seams like the Skill Assessment (Skills Assessment - Using Web Proxies) with the cookie is not possible in Zap or? Seams like i don't have a hex encoder in Zap

#

well yes...but i don't have one in fuzz ?

chrome thistle
#

Hi, someone here who can help med with the last assessment of Login brute forcing?

rich osprey
#

Hi there, my cube numbers became negative after l bought a subscription, can someone help?

abstract epoch
#

Hi there! Newbie detected. I'm trying to connect to the first VM, opened vpn connection, made route to tun interface (set dhcp gw as next hop), but can't see any traffic from here. Host unreachable, try to reconnect to other - it doesn't work. What am I doing wrong?

worldly grotto
#

Hey i cant solve this question , i think i understand the question but i put the answer but dont work can you help me ? i put : 80,43804
module : INTRO TO NETWORK TRAFFIC ANALYSIS
section : Interrogating Network Traffic With Capture and Display Filters

crimson crown
#

would anyone be able to help with Privilege Escalation in "Getting Started"

stiff tiger
#

I have same problem - can you give me a hint on fixing it?

lethal atlas
#

what IP are you using for the lhost?

lethal atlas
ionic summit
# lethal atlas did you figure it out?

Yeah, I did. Thanks. One of the previous questions wanted the actual shell name with extension, and this one did not. ||Even when I tried without it, leaving the '/' at the end caused it to be wrong.||

stiff tiger
echo pond
#

Hi!, I'm doing the "Linux fundamentals", at the "File Descriptors and Redirections", there´s this question:

"How many files exist on the system that have the ".log" file extension?"

So I connect to the target and use "locate *.log -c", and I get a 24 as result on the console, but is not the correct answer to the question... any tips?

gleaming gate
#

(Module: Learning Process)
What am i even supposed to answer here

#

Like how am i supposed to express the difference

echo pond
# drifting knoll try other commands

Got it with find!, the difference between find/locate in this case can be because the local database is not "updated" prior to using locate myself?

drifting knoll
echo pond
gleaming gate
#

how am i gonna write that difference tho

drifting knoll
gleaming gate
#

Oh that

#

lmao

echo pond
#

🤣

gleaming gate
#

I THOUGHT IT WAS MORE COMPLICATED LOL

drifting knoll
gleaming gate
#

Yeah i know that

#

i am dumb lmao

coarse mango
#

hey can anyone help me with the windows fundamentals skill assessment?

coarse mango
#

nvm i finished it 🙂

crimson crown
#

bruh

#

they need to update their pwnbox

brave kindle
#

Is it just me or it is going very slow the parrot instance?

crimson crown
#

son i hate when they can't specify certain things lol

#

What is the full directory path to the Company Data share we created?

#

I've been typing in the full path

solar zodiac
#

Hi everyone! I was wondering if anyone had a bloodhound query for finding interesting potential ACL abuse

#

here is what im working with right now:

#

it doesn't seem to be returning any output for groups with things like ForceChangePassword

#

was wondering if anyone could advise 🙂

slow kayak
#

anyone available to give me a nudge on windows priv esc assessment part 2?

solar zodiac
#

htb academy is awesome! I would love to see a module about deserialization

#

advanced sqli would be really cool too 🙂

livid pier
#

Anyone around to help with a question with 'Intro to bash scripting'? I am getting an error on the Loops section.
*** WARNING : deprecated key derivation used.
Using -iter or -pbkdf2 would be better.
bad decrypt
140615492281728:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:../crypto/evp/evp_enc.c:610:

worldly grotto
#

Hey i cant solve this question , i think i understand the question but i put the answer but dont work can you help me ? i put : 80,43804
module : INTRO TO NETWORK TRAFFIC ANALYSIS
section : Interrogating Network Traffic With Capture and Display Filters

livid pier
weary canyon
worldly grotto
weary canyon
#

Look at the capture more precisely

worldly grotto
#

ok

young osprey
#

Hi folks. I am stuck on this Windows Fundamental/File System question:

What system user has full control over the c:\users directory?
I'm pretty confident that I have the right answer ||NT AUTHORITY\SYSTEM|| as I use the exact same method as described on that page, but it does not accept my answer.
I've tried various permutations to no avail.
I see someone else asked the same question back in April, but did not share the solution.
Any help would be appreciated 🙂

weary canyon
worldly grotto
young osprey
# weary canyon I've check my notes, and you don't have the right answer. You don't have to try ...

Thanks for checking.
I must be missing something obvious here. From what I understand, there are only two entities here that have full control over the directory, but neither of them work as the answer.
C:\Users\htb-student>icacls c:\Users c:\Users WS01\bob.smith:(F) NT AUTHORITY\SYSTEM:(OI)(CI)(F) BUILTIN\Administrators:(OI)(CI)(F) BUILTIN\Users:(RX) BUILTIN\Users:(OI)(CI)(IO)(GR,GE) Everyone:(RX) Everyone:(OI)(CI)(IO)(GR,GE)
Can you perhaps give me a hint on what I am missing?

#

oh wait

weary canyon
young osprey
#

/facepalm

rustic sage
#

Morning!

I'm at Linux Fundamentals/ System Information

I'm a bit confused what I'm doing wrong here 😅

I also tried root, but I have no access there

weary canyon
rustic sage
#

thanks 🙂

fallen hemlock
#

I just confused to the SSH Attack in login brute forcing module. in the example code ssh port is 22 but in the target machine i got <IP>:30504. so I'm confused what should I attack with hydra?

weary canyon
fallen hemlock
weary canyon
novel wigeon
#

yo

woeful dove
#

hi can anyone tell me what is happening here and what have i to do?

fierce pond
#

can i ask about the vpn here

#

im having a problem connecting to academy through the vpn

#

should i use port forwarding to allow Udp connection ? or is it just something im missing here? cause i can connect to HTB without any problem but academy vpn is not working

fierce pond
#

i did

#

same

scarlet finch
#

use the pwnbox

#

what are u using right now ?

#

a vm, windows with openvpn gui ?

fierce pond
#

im using the Pwnbox now yeah

fierce pond
scarlet finch
fierce pond
#

all is working but the vpn from academy , its definitely because of the UDP

scarlet finch
#

can u send the output when u run it then

fierce pond
fierce pond
#

and the mouse is going crazy sometimes

fierce pond
scarlet finch
fierce pond
#

yeah already did , i dont know if all the academy members share the same ip they connect to , i mean the credentials are different but ..... u know i was just worried

subtle mulch
#

Hi, could anyone give me a hint on how to find the member of the Remote Management Users group on WS01 for module Active directory powerview - Enumerating AD groups? When I execute Get-NetLocalGroupMember nothing is somehow related to Remote Management Users.

fierce pond
#

BOF help with the last task of the module

#

at first it was really smooth and i had a connection but i didnt do what i should do after and the user i got was htb-student and not the root

#

and then the code stopped working after trying to open the msg.txt

#

i reset the machine and now the code just wont work idk why

#

anyone ?

fierce pond
#

ive been into this since long time , its all because of the stupid flag !!!!

muted kite
#

im trying to get into my linux virtual machine, it's just showing a black screen

fierce pond
#

what mode you trying to open the machine , did you try to just resize the window or the screen

#

?

scarlet finch
#

outside

fierce pond
#

what does outside means lol am i connecting this wrong ?

scarlet finch
#

😉

fierce pond
#

it doesn’t matter where i run the program

#

does it matter ?

scarlet finch
#

yes

fierce pond
#

i mean you running the same program right ?

#

okay

#

lol

muted kite
#

I still need to do knowledge check in GS Module. After these upgrades to my machine finish, I'm gonna start on it

#

I wish I was as far as some of you

muted kite
#

maybe you have to go through htb-student in order to get to root

#

perhaps you need to have access before you can upgrade perms

fierce pond
muted kite
#

so you finished?

fierce pond
#

I got the flag and finished the module, it was the BOF in Linux, fun stuff you should try to learn

muted kite
#

linux advanced?

fierce pond
muted kite
#

I need to do one last thing and I will start the linux fundamentals module

fierce pond
#

And I finished half an hour ago

muted kite
#

Man, it took me 9-10 tries to get through nibbles

#

i need to do the knowledge check today

fierce pond
#

There's some real shit going around there , specially with the assembly language

fierce pond
fierce pond
#

But at least you got it after 10 times , so hurrah 😀

muted kite
#

yeah, it was ugly but i did it

#

im only confused about doing it without nibbles now

#

it should be easier though right?

fierce pond
#

Idk what you mean by that

#

But since you started with the academy then continue on this path , you can finish all the tire 0 modules

#

And then start a path

#

Or .... make your own path as you would prefer to , but I recommend sticking with the paths they have if you are not using the Academy for oscp kinda training lab because you ran out of lab time lol 😅

muted kite
#

I ran out of time until the last time everytime

#

i dont know what i mean either

#

lol

#

Im just finding exuses not to do the knowledge check

#

cause I dont want to go in blind

muted kite
#

can anybody help me with knowledge check in 'Getting Started'?

#

I cant seem to find any expoloits

#

I also dont know how to gain admin access to the target machine even though I found that there is supposed to be direct access through robot.txt file and index.php

quaint marsh
#

set user ID?

#

what's wrong?

untold kiln
#

It needs to be the full name

quaint marsh
#

set userS ***** id?

untold kiln
#

||It needs to be the full name "Set owner User ID"||

quaint marsh
#

thx

muted kite
#

gues imm on my own

river juniper
muted kite
# river juniper Hey do you need some help ?

I'm getting lost in the Getting Started Module with Knowledge check, losing variables and the assurity of nibbleblog admin user and pass. I don't seem to know what to do without knowing those credentials and I cannot find any exploits for that apache version 2.4.41

fierce pond
#

let me check

#

oh god you are on that last section

muted kite
#

yeah viviv helped me through half of it, now gonna work through the rest later

fierce pond
#

god be with you brah , you need help from someone who has some Experience

fierce pond
#

someone will always help here

#

to be honest im happy to be here

#

its really good community

muted kite
#

awesome community

rocky grove
#

I provide cyber security training on Udemy. Can I share one room that Hackthebox publish for education in my classes? Are there any copyright agreements with Hackthebox?

muted kite
#

Im trying LinEnum to try and gain root privelages, I need a little help with next step please

#

i see root.txt but when i try to to cat it goes back to terminal

hushed cape
#

I need help trying to figure out the correct format for the hosting provider and the location coodinates answers of the OSINT: Corporate Recon module. Tried a lot of different variations but no luck so far. Thank in advance!!

muted kite
#

ive had enough for the night, will try to seek help tomorrow

fallen hemlock
#

the most interesting part of Login Brute-force module skill assessment is guessing what wordlist do you use lol. and I'm stucking because it's take a long time when I used rockyou.txt and until now I have no idea about the wordlist.

subtle mulch
muted kite
worldly grotto
#

hey, can you help me because i am blocked on this question please Can you say what to do because I have the file but I don't know what to do with this file and I don't really understand the hint?
module : CRACKING PASSWORDS WITH HASHCAT
section : Skills Assessment

rustic sage
#

Good morning 👋

I've got a general question about the way you solve the questions at the end of some sections. Do you use Google frequently?

Yesterday, when I was at Linux Fundamentals/ System Information I got the question below (attached) and it was very much outside of what I could do or even understand at that moment.

Even tho I was able to solve it with Google, I didn't like that I had to resort to that. I'm trying to understand and study the information that I'm given so well, that I can solve these questions without using Google.

Do you think this is unrealistic? Do you think these questions are sometimes meant to be so "complicated" that you need to do extra research to solve them? How are you doing it?

EDIT: Or do you think these questions indicate your level of understanding you should have after finishing the section?

weary canyon
drifting knoll
# rustic sage Good morning 👋 I've got a general question about the way you solve the questi...

the questions are designed in such a way that you need to think about what you've learnt, create the connections, and understand the technology behind it
all questions are easy to solve if you know what you need to provide
digging into the questions you struggle to solve is part of the learning process independent of the topic and this also helps you to identify the "parts" you need to work on to improve your understanding
you can compare it to driving a car where in this case every service & tool is a different car that uses different mechanics - if you want to drive that specific car you need to understand how it works otherwise you won't be able to drive

rustic sage
weary canyon
rustic sage
#

cheers 🙏

drifting knoll
# rustic sage Thanks Zgwyx and Cry0l1t3, so I don't need to expect myself to know or understan...

no, you don't need to understand everything directly
after all, knowing the necessary components doesn't mean that you can make the connections between all of them
this often requires personal effort where you automatically train your analytical skills to make those connections faster in the process
with time and this type of training you will find that you will discover those connections faster and faster and that is one of our goals at HTB academy to help you develop these skills

grand grove
#

If the guy create the course : Cracking Passwords with Hashcat can ping me in MP there is an small update on the lesson

drifting knoll
#

btw, creating such connections based on information you obtain of the systems that have been setup by a company is critical

prime meadow
unique star
#

Hi, Can anyone give a hint on broken authentication skill assessment . I'm stuck, I kown how to change to another user but I need to enumerate other users and everithing I've tried was useless

unique star
outer palm
unique star
#

yeah, I wa stuck there now I've found other users. DM if you want

wheat shore
#

sup bois

#

Who completed the Server-Side Attacks?

unique star
lethal atlas
#

can anyone tell me another way to extract a zip file without using unzip?

unique star
#

7z

main vapor
lethal atlas
torn meteor
#

Hello mates, Is there anyone passed the live engagement of shells & payloads module ?

acoustic owl
#

Can I DM you about this?
I am also stuck and need a hint. The hint, find all zones does not help me. I have found two zones.

subtle swift
#

Hello. I need some help with the Service and Process Management Section in the Linux Fundamentals Module. Should I post my question here?

torn meteor
# lethal atlas I have.

Regarding the second host, more precisely the 50064.rb exploit, have you got the shell without any errors from the first try ??

lethal atlas
torn meteor
wheat shore
#

Anyone who completed the Broken Authentication, token part? I am struggling with this all day long and can't seem to generate the right token...

main vapor
#

@wheat shore DM.

past trout
#

Is this where I can post a question regarding the "Basic Toolset" module?

river juniper
unreal grail
#

Stuck at the same spot, did you found?

unreal grail
#

Hey everyone 🙂 Information Gathering - Active Infrastructure Identification - The question about the CMS used. Does someone got the cube? I have both tried with Wappalyzer and WhatWeb but nothing came out! 😐

acoustic owl
patent sinew
#

@acoustic owl No I didn't. I have came back to it yet

unreal grail
#

Have you found? Got the same issue :/

ionic summit
subtle mulch
# white iron Hey guys! Anyone for a nudge on the footprinting module / chapter DNS -> last qu...

Hi, I had problems with this question too.
I'll try to recap and rephrase the question and hope it is ok without giving to much information.
When you look at the first picture on the DNS page, you can see the hierarchy of DNS with TLD, Second Level Domain, Sub-Domains and Hosts.
What you need to look for is a host, with an ip ends with 203. So, check your previous search results, which sub-domains you've already found earlier and then try to find the missing host.

acoustic owl
acoustic owl
dry reef
#

isn't it correct path to store user's mail ??
/var/spool/mail/$USER ??

ebon ember
#

I am sorry that I am being dumb.
I am on the getting started module and Public Exploits. I have figured out that the plugin is vulnerable to the file read thing but I just cannot find path to flag.txt

#

When I try to use msf it cannot validate the vulnerable website

#

Figured it out

#

I needed to set RPORT

subtle mulch
#

Is anyone there who has finished the "Active Directory PowerView" module and can give me a nudge on how to find the member of the Remote Management Users group on WS01?

dry pumice
#

hello, I'm new to the academy

#

I'm on the Linux fondamentals course and I try to answer all the question

#

but seriously, how are we supposed to find the path to the mail of the user ?

#

and why the answer for the shell question is not bash ?

main vapor
dry pumice
#

danke

gleaming gate
#

(Module: Linux Fundamentals)
Ive been searching for an hour where tf is the students mail

#

NVM I FINALLY FOUND IT

#

LMAO

drifting knoll
gleaming gate
#

Oh it wasnt correct

#

LOL

drifting knoll
#

check the PATH variables

gleaming gate
#

Wdym

drifting knoll
#

read the section again

rustic sage
#

hi

#

{
"ns": "yt",
"el": "embedded",
"cpn": "t4tRSMotns-vlDcJ",
"ver": 2,
"cmt": "245.744",
"fmt": "396",
"fs": "0",
"rt": "897.861",
"euri": "https://robeson.instructure.com/courses/64017/assignments/1825811?module_item_id=3904315",
"lact": 9,
"cl": "419703423",
"mos": 0,
"state": "4",
"volume": 100,
"cbrand": "google",
"cbr": "Chrome",
"cbrver": "96.0.4664.111",
"c": "WEB_EMBEDDED_PLAYER",
"cver": "1.20220104.01.00",
"cplayer": "UNIPLAYER",
"cmodel": "chromebook",
"cos": "CrOS",
"cosver": "14268.67.0",
"cplatform": "DESKTOP",
"hl": "en_US",
"cr": "US",
"len": "527",
"fexp": "23983296,24001373,24002022,24002025,24002923,24004644,24007246,24080738,24082661,24094607,24102119,24129402,24141079,24143691,24146886,24149308",
"feature": "oembed",
"afmt": "251",
"size": "640:480",
"inview": "0",
"muted": "0",
"conn": "3",
"docid": "L2baeF2Bp9E",
"ei": "P_fWYaKbMtqXsfIPiPa8-Ao",
"plid": "AAXU6l46Q52t40Tf",
"referrer": "https://www.youtube-nocookie.com/embed/L2baeF2Bp9E?feature=oembed&rel=0",
"of": "99NLO3Is0TlMnLqZm7_3-A",
"vm": "CAEQARgEOjJBS1JhaHdCV1I4QXRKTlUxSUgxbXZkeG5LWU15b0lhUDhBNTVaT01JUjloaDJqODdlZ2JYQVBta0tETGFzOU5paGVBNmxmTkZpd0JXemllaE5nVm5ibUhkdXJfeGJ1Mzl2NkJUNGRvUHZkdGItMEJ1R0lpZ21OTm9wNVBFVDd0X0RTYkJwUkJKc19qaQ",
"vct": "245.744",
"vd": "526.801",
"vpl": "0.000-245.744",
"vbu": "0.000-368.368",
"vpa": "1",
"vsk": "0",
"ven": "0",
"vpr": "1",
"vrs": "4",
"vns": "2",
"vec": "null",
"vemsg": "",
"vvol": "1",
"vdom": "1",
"vsrc": "1",
"vw": "640",
"vh": "360",
"lct": "245.744",
RapidIdentity

gleaming gate
#

what

gleaming gate
#

Bruh

drifting knoll
#

be careful with spoilers..

gleaming gate
#

Wait it was correct?

drifting knoll
#

try it and you will see

gleaming gate
#

I tried it and it wasnt

drifting knoll
#

stop guessing and try to understand the environment

gleaming gate
#

Okay

drifting knoll
#

maybe the folder doesn't exist yet because the user didn't receive an email yet

gleaming gate
#

Oh bruh

#

So i have to wait or what

drifting knoll
#

ofc not

#

there are ways to find the folder where those emails will be stored

gleaming gate
#

I am very dumb from birth

drifting knoll
gleaming gate
#

yea im just asking how will i learn it

#

Like where do i have to search

drifting knoll
#

everything you need is provided in the section of this exercise

gleaming gate
#

And about the environment?

drifting knoll
#

read the section again

#

giving you the answer won't teach you anything

gleaming gate
#

True

#

Btw did you make the module?

drifting knoll
#

yes

gleaming gate
#

Nice

#

OH MY GOD FINALLY LMAO

#

Found it and it is correct lets go

woven copper
#

hey I am on Footprinting Module on the DNS part, What is the FQDN of the host where the last octet ends with "x.x.x.203"? I just dig all zone and subdomains i found but no info for the host that ends with 203.

subtle mulch
#

Hey, scroll a bit up. I've commented this today. Hope it helps

acoustic zinc
#

Does anyone know if there is an error when capturing the answer to the following question, the number does not accept me.: Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

#

the question is in the linux fundamentals course.

drifting knoll
acoustic zinc
#

ok then can you tell me if within these options 50 and 51, is any correct?

acoustic zinc
#

thanks

wheat shore
#

Hey guys, anyone here who completed the final assessment of broken authentication?

main sapphire
#

why cant I talk in general??

sterile hawk
main sapphire
#

I did the things to get in

#

it aint working

sterile hawk
#

Did you DM @little whale

main sapphire
#

Yes

sterile hawk
#

DM me and show me what you're trying

muted kite
#

I need some helps please

#

Getting Started Knowledge check, trying to get root.txt

wheat shore
#

Man, this broken authentication is just killing me

muted kite
#

im just going to move on without touching that until a later time

unreal grail
#

Shout out to the person who can help me with this! Information Gathering Web Edition - Active subdomain Enumeration Q: Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer. 🙂

unique star
woven copper
vapid hamlet
#

Can some Help me with Web Requests and Burp Suite?
Im having a bit of Trouble catching the Request and forwarding it with the credentials for the website..

vapid hamlet
summer lake
#

you can send it here

vapid hamlet
#

first of all, i thought in this exercise the authorization is BASIC user:passwd is this encrypted?

#

If the request from the website while signing has to be captured, i turn on the proxy 127.0.0.1:8080 and then it will show up in burp or do i have to configure burp to directrly intercept it from the website?

summer lake
# vapid hamlet

eh.. if you're trying to use burp, why is it turned off though?

vapid hamlet
#

that works fine, but i dont really get behind the logic of why the website stopps working when foxproxy is turned on

summer lake
river juniper
#

it's not the website stop working but he's waiting the request blocked by burpsuite

#

If you forward the request it charge the page

vapid hamlet
river juniper
#

It's the scope of burp, (Intercept>Modify>Forward)

#

I don't understand where is the problem sorry

vapid hamlet
#

I think what im struggeling with is what the settings have to be in firefox what settings have to be in burp and what settings i need in foxyproxy

river juniper
#

DM ?

vapid hamlet
#

Solved

fallen hemlock
#

I have some stupid question for HTB Academy. Some HTB Academy modules can be unlocked by Student subscription then what if I didn't renewal the subscription but the modules is not finish? is it became lock because it is only be unlocked if i have the subscription or it is still unlocked because I have been unlocked that when I have the student subscription? Thanks.

spice dagger
#

no you just can complete the module when u want subscriptions is for earning cubes cubes unlock modules if sub is expired your cubes keep in your account ready to be spent when you want

summer lake
#

Hi guys, I am stuck at the WordPress RCE via theme Editor Portion, how do you execute commands? It seems like I can't put spaces in between, for example :
curl -X GET "http://<target>/wp-content/themes/twentyseventeen/404.php?cmd=cd .."

subtle mulch
dry reef
#

Which option needs to be set to execute a command as a different user using the "su" command?

I tried some options but not getting the right one . Could anyone help with little hint or anything ??

umbral hemlock
#

hello, im new to HTB academy and im not sure which module i should start with, is there a sequence of modules that i can follow or it doesnt matter on which modules i start with?

weary canyon
#

And if you want to focus on some specifics skills, you can checks the Skill Path section

weary canyon
weary canyon
#

You're welcome 😉

gray cypress
#

Hi my friend
Please help me to solve tcpdump fundamentals challenge.
This question:
Were absolute or relative sequence numbers used during the capture? (see question-1.zip to answer)
I can see seq number but i don't know how to answer the question

weary canyon
# gray cypress Hi my friend Please help me to solve tcpdump fundamentals challenge. This questi...

Hi, in the course page, you have some informations about sequence numbers in a tcpdump capture. If you want more precisions about the differences between absolute and relative, you can try to google it, for example in this site : https://www.howtouselinux.com/post/understanding-tcp-sequence-number.

TCP Sequence Number is a 4-byte field in the TCP header that indicates the first byte of the outgoing segment. It helps to keep track of how much data has been transferred and received. The Sequence Number field is always set, even when there is no data in the segment. For example, the sequence number […]

#

I'm not sure if the course integrate a deep explanation of this subject. If it's the case, I can delete the link above.

fierce pond
#

So if i have a student subscription and I want to buy cubes to study some stuff on tire 3 wouldn't be easier and cheaper if I just subscripe to the gold or platinum plan?

gray cypress
weary canyon
fierce pond
dry reef
#

I used several answes like --login but didn't find correct one

weary canyon
#

check the man page, or try su -h to see the options

dry reef
#

Okay...I will check again but I tried most of them from help

weary canyon
dry reef
#

Great thank you zgwyx....ryt now m outside will dm you .

manic zealot
#

Hey guys! I'm new here. I'm starting now with ctf, does anyone out there know of an easy challenge for me to start training?

fossil cloak
#

Anyone provide guidance on the Live Assessment portion of "Shells & Payloads?" Currently stuck on the first box and assuming I need to obtain || a reverse shell via uploading a war file || However, I am not obtaining it and wondering if it is an issue of the Foothold having access to the internal network?

weary canyon
#

You'll find the easiest challenges, with step to step indications, and well explained writeups

stark jolt
#

hi. iam noob. how can i install openssh on internal HTB VM if i have no sudo password? where i can find it?

weary canyon
#

My bad, it seems there is an update on the PwnBox

stark jolt
#

hmmm. I learn linux fundamentals -> Service and Process Management ... and if i try to install openssh , i need sudo password

#

on my workstation

weary canyon
#

I'm not sure to understand the problem. When you say "on my workstation", you're talking about the web access to you PwnBox Desktop, or your actual computer ?

#

If it's the PwnBox instance, you have a Desktop file called "my_credentials.txt", with your personal password

dense marsh
stark jolt
#

yea, thanks a lot

weary canyon
stark jolt
#

stuck in empty place

torn meteor
#

Hello mates, I'm stuck on the sixth page of the network enumeration with nmap (service enumeration), can anyone help me ?

torn meteor
#

I couldn't find any flag !!

#

They said in the hint : Remember that Nmap does not always recognize all information by default.

#

But I've tried everything and i find nothing !!

torn meteor
weary canyon
tropic seal
#

Hello

#

is anyone online?

weary canyon
#

Just a hint : nmap scan for active ports, but you may want to interact with the detected ports

weary canyon
fossil cloak
#

With this statement - "Keep in mind that the Foothold host has access to the Internal inlanefreight network (172.16.1.0/23 network) so you may want to pay careful attention to the IP address you pick when starting your listeners," I am assuming I need to somehow modify the IP address that my listener is to be listening on? Any further clarification would be awesome. Thanks!

dusty mulch
#

hey, did someone finished getting started? i managed to upload the php shell disabling js, but cant run it, and metasploit seems to fail for different reasons each day. please dm ❤️

scarlet finch
#

Imagine that you want to have a platinium sub for 1 years. You will have to pay 868$

#

if you buy directly 5000 cubes. It s gonna be 450$ but on 1 year you save the half of ur money

#

And you have access to the modules for life

#

forgot to mention

#

plat sub in the end you will have 12 000 cubes. But 12 000 cubes is more than all the modules

#

so

#

dumb to take lol

#

anyway...

#

I am dumb

#

well

#

it really depend for what time

rustic sage
#

Got a spare 25% off on VIP+ if anyone want it, @ me

muted kite
rustic sage
#

U got this prayge

woven copper
#

hey someone could give me a hint on the Footprinting Lab-Hard, I'm stuck

neat kindle
#

Hey everyone,

I would love some help trying to solve SQL INJECTION FUNDAMENTALS - Skills Assessment.
The goal is to get the flag in the /root folder.

||I got RCE via sqlmap --os-shell but now I'm stuck because I believe I need a better more interactive shell to switch to the root-user. I believe I have the credentials, but I can't input them when I call su

  1. Do I need to spawn a Reverse/Bind-Shell?
    1a) It tried a lot of Revshells from https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology and Resources/Reverse Shell Cheatsheet.md
    but somehow they all don't seem to work. How can I debug to find out why they don't work?

  2. If it is possible without Reverseshell: How?||

GitHub

A list of useful payloads and bypass for Web Application Security and Pentest/CTF - PayloadsAllTheThings/Reverse Shell Cheatsheet.md at master · swisskyrepo/PayloadsAllTheThings

weary canyon
muted kite
wanton garnet
#

Hi! I've searched through these threads and google hoping to find a hint but I think I'm stuck or missing something on the academy "Login Brute Forcing - Skills Assessment Website." I got the first question, but I'm stuck on the second part. I don't want to give away too much in chat, but I'm pretty sure I have both the hydra syntax correct and I'm running burp intruder parallel hoping one of them would work. If someone familiar to this could DM me I would appreciate it. Thanks!!

unreal grail
#

Does someone understand the awk part of this command? I do not understand the 1 at the end that is outside the curl bracket, but inside the single quote. What does it means?curl -s https://crt.sh/\?q\=tryhackme.com\&output\=json | jq . | grep name | cut -d':' -f2 | grep -v "CN=" | cut -d'"' -f2 | awk '{gsub(/\\n/,"\n");}1;'

woven copper
#

Just can say that you are on good direction.Try all techniques.👍

muted kite
#

for my remaining fundamental modules, which one should be next: Web Request, Intro to Web Apps, Windows Fundamentals

#

??

#

Probably doesnt matter all that much

weary canyon
muted kite
#

so does that mean, they are at an equally fundamental level?

#

@weary canyon

candid sandal
#

Hi all 👋 I have a question : in the module of web proxies, there's this question where I'm asked to configure Proxychains by editing a configuration file. Problem, when I want to save it, the VM asks me for a password :/

weary canyon
weary canyon
candid sandal
#

Oh, I was not aware of that, so there's a file with credentials ?

muted kite
weary canyon
#

On the Desktop of th PwnBox yes

candid sandal
#

It worked perfectly, I hadn't seen it, thank you very much

candid sandal
#

Is this channel a community support for when we're stuck somewhere in the academy modules ?

languid dawn
#

sure but do try to avoid spoilers

turbid salmon
#

I have an issue with the module Active Directory LDAP on section LDAP Overview: For the Questions part, I try to connect to the target machine with xfreerdp /u:htb-student /p:Academy_student_AD! /v:10.129.22.173 from my pwnbox and through VPN but it fails. Can you test if one of you can use RDP for this module?

#

it seems to work now. I don't know why this didn't work but problem solved!

turbid salmon
#

I have a question for the Active Directory Search Filters of the module Active Directory LDAP. Can someone help me on private message?

acoustic owl
acoustic owl
woven copper
wanton garnet
#

Did yo ever figure this out? If so can you PM me? I’m so frustrated. ♥️

muted kite
#

In web request module whenever I use foxyproxy and turn on intercept with burpsuite. The target web IP times out and it also cuts off the other websites.

#

to the point where I cannot access the web

#

does anybody know why this might happen and how to fix this?

#

One other thing I noticed is that my version of burpsuite doesnt have all the same tabs as the one in HTB. If there is, it's not something I am finding. I have updated and upgraded this afternoon before I started this module

muted kite
#

nevermind, i turned off foxy proxy and just used burp suite and i was able to get through that part

summer lake
#

hello everyone, im doing the lfi module. I tried installing with :

apt install phpX.Y-zip

but my terminals says : E: Unable to locate package phpX.Y-zip
E: Couldn't find any package by glob 'phpX.Y-zip'

Anyone faces this problem?

warm quiver
#

Hi, in the Footprinting Lab - Medium, I keep getting error 233 'No process is on the other end of the pipe', what am I missing here? got it

main vapor
frigid vector
#

Hey all. Need help in Stack-Based Buffer Overflows on Linux x86 module (Generating Shellcode chapter)

scarlet finch
frigid vector
grizzled vale
#

Hey I am answering a question on web request in the academy but for some reason it's not working is there someone that can give me hand?

mossy onyx
#

Anyone can help with shells and payload the live engagemnt q2. Not sure why im unable to get the msf to exploit. I tried doing manually by uploading file.

tiny latch
#

Hello,
i just finished the Privilege elevation module but i have a question.
||Why i can use sudo -u to run /bin/bash but not to run /bin/echo or /bin/apt-get ?||

summer lake
summer lake
tiny latch
#

Ok thanks for this information

wanton garnet
cursive cave
#

hi guys, im doing the service scanning of the welcome module

#

tree connect failed: NT_STATUS_BAD_NETWORK_NAME

#

and i got this error

#

when i tried to enter bob's password

#

which is Welcome1

#

can someone please help me

neat kindle
# cursive cave hi guys, im doing the service scanning of the welcome module

Hey @cursive cave NT_STATUS_BAD_NETWORK_NAME is thrown when the Directory name in the smbshare does not exist.

For example:

If smbclient -U bob \\\\<Target-IP>\\users is correct

smbclient -U bob \\\\<Target-IP>\\user will throw NT_STATUS_BAD_NETWORK_NAME, since the Directory user does not exist the correct name was users.

You can check existing directories with the command smbclient -L -N \\\\<Target-IP>

bright torrent
#

Hi guys how do I use zip2john command I've tried everything it says command not found

neat kindle
#

You need to install the JohnTheRipper Tool:

#

Or you can try sudo apt install john

#

If zip2john does not work immediately, try to locate the binary via find / -name "zip2john"

bright torrent
#

thanks

neat kindle
prisma knoll
#

Hey guys, I'm stuck on Shell and Payloads module, host 2 I'm getting this error when trying to use the exploit : NoMethodError undefined method ‘split’ for nil:NilClass’ can't find a way to fix any hints to complete or solution to fix script? (Saw that some people got the same error before contacted them but I'm still stuck)

wheat shore
#

@prisma knoll I had the same error

#

double check the correct payload/target and other info is set

west canopy
#

Hey is it ok to ask a question about HTB Academy Gift Cards here?

wanton garnet
#

I would maybe check community help? But maybe someone here will know the answer, I didn't even realize they existed lol

west canopy
#

Just curious if i can just buy Cubes for someone . Trying to get some modules for my buddy

west canopy
#

@neat kindle thanks dawg!

stiff tiger
#

@prisma knoll - I had the same error. Someone helped me with it - the script does not need to be changed to solve this problem. I had a setting wrong in the metasploit settings.

#

I'm trying the Footprinting Lab easy and struggling - I have a couple of theories on how to crack this but am stuck. Please could anyone give me hint or could someone DM with me to see if my ideas are even possible. Thanks.

prisma knoll
drifting knoll
#

maybe you should take a look at what nmap shows you

spice dagger
#

@drifting knoll you think should be better keep an eye on samba than apache 2?

#

@drifting knoll really I try different kind of approach however I'll try to give more attention to the nmap result

drifting knoll
#

^ solved

drifting knoll
white iron
#

KUDOS to the author/s of the "FOOTPRINTING MODULE" !!! Best module so far. Highly recommend it to everyone! Especially the hard lab is very neatly

unique star
#

DM if you want

muted kite
#

foxy proxy sucks, it blocks my web traffic

#

what is the ip and port supposed to be in foxy procy anybody?

#

the target that I spawn?

west canopy
#

i guess you could try the built in chromium browser in burpsuite

muted kite
#

sure, but for some reason thats not working at all

#

Im on kali linux, do I need to install it perhaps?

#

what happens when i launch the chrome browser is that it just sits there and will not launch the target IP

#

in burpsuite it self it shows that the target IP launched, but I need to login and out as admin and guest in the browser and it wont allow that

#

I love this platform, but there are so many technical difficulties.

#

okay, well when I turn off intercept, I can login through the web portal

#

sorry everyone, i'm really just learning alot of this and just stumbling around

#

so why is my target machine protected by cloudfare, is that supposed to happen?

west canopy
#

Not sure about cloudfare but yes , when working with burp you may need to turn intercept on/off , or if Intercept is on you will need to forward every request. If you were to use foxyproxy it almost adds another level of this where you have to disable/enable to get certain pages to load

muted kite
#

Another module I'm stuck on, that's two of them Now. haha. It's fun, but man I need some additional help .

west canopy
#

@muted kite is that the "HTTP POST" section on Web Requests?

muted kite
#

POST Method

#

yes

urban sage
muted kite
urban sage
#

Intercepted requests are held by burp until you forward them by hand. If you don't forward a request chances are the server won't send anything back and a time out will occur.

muted kite
#

I tried that as well, but I must need a whole class on Burp. Because I know next to nothing about it, only by reputation

livid pier
#

I am doing Footprinting medium lab and the SQL server needs to be reset

#

anyone around to do that?

drifting knoll
lethal atlas
#

I need some help with Active Subdomain Enumeration.. Anyone pass this yet?

#

It touches on the zone transfer stuff from a previous module but I am missing something little trying to get the TXT from one of the zones.

vital geyser
#

in module 18 "linux fundamentals", section "system information" I cant ssh to the target. I am connected to the academy vpn and can even nmap ssh and several other ports on the target. But when I connect from my kali vm it only says Connection closed by HOSTIP at port 22

#

and Ive tried resetting the target and reconnecting to the vpn three times

untold kiln
#

@vital geyserssh htb-student@target-ip

#

does that ask for a password ?

vital geyser
#

no, just nothing and after a good amount of delay Connection closed by targetip at port 22

untold kiln
#

are you sure that you are connected to academy vpn ?

vital geyser
#

I got the vpn file from the button next to spawn target

untold kiln
#

okay, do you get "Initialization Sequence Completed" when you connect to vpn ?

vital geyser
#

yes