#modules

1 messages ยท Page 508 of 1

limber dock
#

what?

rustic sage
#

@muted kite You are going to notice that all subdomains that aren't active return an error message of identical size/word length etc. Right?

limber dock
#

just search virtual box and select your os

vague axle
limber dock
#

and click install

livid pier
#

well a hard part

limber dock
#

but ik how to set up virtual box

muted kite
limber dock
#

but the main problem is installing kali in it

vague axle
#

does anyone know any videos for it??

livid pier
#

There is a pdf on edx from nyu on penatration testing that is a good walk through

#

ill see if I can find it

vague axle
#

k thx

livid pier
#

its gonna take me like 15 mins

#

ill be back

limber dock
vague axle
livid pier
#

are you on a mac?

vague axle
#

no windows

livid pier
#

google that

#

im on mac

rustic sage
limber dock
#

here is your video for installing kali virtual box @vague axle

muted kite
# vague axle does anyone know any videos for it??
vague axle
#

k thank u ๐Ÿ™‚

muted kite
rustic sage
#

@muted kite Once you figured out that parameter, you can exclude all those domains with like -fs <filesize> or other flags.

muted kite
#

problem is I dont see a file size

#

it shows progress, job, duration, errors

muted kite
#

I think I will just wait and see what the end results return this time and than include the -fs XXX

rustic sage
muted kite
#

ffuf assessment

livid pier
#

This is the full course, it is free.

#

Its a nice starter with some videos if you are super fresh

livid pier
#

everything else is the same tho

rustic sage
muted kite
#

last

#

my point is the commands are not giving me the output they are supposed to

rustic sage
muted kite
#

yes

limber dock
#

hey did anyone of you finished fundamentals of linux?

limber dock
#

i haven't and i am still learning it not fully finished yet

#

but i have completed networking

muted kite
limber dock
# livid pier nice

hey can you tell me what more interesting things are there in fundamentals of linux??

muted kite
#

thats a confusing question

limber dock
#

lol

vague axle
muted kite
limber dock
livid pier
muted kite
vague axle
#

its really weird every website is working for me but when i try to access kali it says it took to long

#

are their servers down?

#

because i could access it a minute ago

limber dock
#

hey i have a 8gb ram pc with no graphic card ?? can i install kali too

limber dock
#

no i can access it

#

you are talking about the download page right?

muted kite
#

scroll down until you see this

rustic sage
muted kite
#

see where my cursor is?

#

click that download link

vague axle
#

no like it wont even let me on the flipping website

muted kite
vague axle
#

but i can get on any other

muted kite
#

thanks for pointing that out

#

new exersize, new machine

muted kite
vague axle
#

nope cause it works on my phone

rustic sage
# muted kite thanks for pointing that out

Cancel your scan, add academy.htb with it's IP to your file and run it again. Once you are going to see a list getting longer and longer once your scan started, you know that you did it right.

muted kite
#

I can't believe I didnt realize I had to change that again

vague axle
#

i finally got virtualbox downloaded what now

muted kite
#

now you need the iso image with the latest link i sent you

muted kite
livid pier
vague axle
#

i am but i cant get on kali

#

on my laptop juyst my phone

muted kite
#

show us a screenshot

vague axle
#

how do i put an image on discord?

livid pier
#

drag + drop

muted kite
#

or you can click the addition symbol to the left

vague axle
#

k

#

omg it finally loaded

livid pier
vague axle
#

after years

vague axle
muted kite
#

which one do you want kali linux on? which did you download?

vague axle
#

virtual box

#

shakll i click the download on it

muted kite
#

yeah

#

-mc 0

#

thanks

rustic sage
#

Spoiler alert :)

muted kite
#

should i delete?

rustic sage
muted kite
#

ok done

#

wow it feels so good when you do it right and see the results though

#

user error

#

was the only error taking place

vague axle
#

i downloaded the kali thing now what?

muted kite
#

show us a screenshot of the iso image in the download folder

#

copy and paste it to your desktop

vague axle
#

where is the iso image?

muted kite
#

in downloads

#

internet downloads

vague axle
#

k

muted kite
#

@stardew can you do a discord call and share your screen?

vague axle
#

sure

#

call me

#

is that right

muted kite
#

thats virtualbox I believe

rustic sage
#

OVA image.

#

As you downloaded an OVA image.

#

:)

vague axle
#

??

rustic sage
#

100% right :)

vague axle
#

lets call it will be easier

livid pier
#

Anyone finish

#

? Wanna help?

lethal atlas
lethal atlas
#

LOL

#

My God Network Traffic analysis is BORING

livid pier
livid pier
#

I didnt have fun with that one

livid pier
upper vault
#

@lethal atlas lol

muted kite
#

when you enroll in a path, are you supposed to do all the modules in a particular order?

rough pelican
muted kite
#

well some are easy and some are hard

#

im torn between bug bounty and junior pen tester

#

I mean some are easy and some are medium

livid pier
#

spoiler alert

muted kite
#

okay I can't find the parameter-names.txt

#

theres no spoiler, it failed

#

I need help locating the filepath

livid pier
#

lol I was jk

muted kite
#

must have elp

#

I dont have seclists/discovery/web-content/burp-parameter-names.txt

rough pelican
muted kite
#

ah yes, thank you. I forgot about that

#

git clone?

#

this one?

muted kite
#

i still cant locate the file im looking for

#

certainly a big help in the right direction thanks for that

#

but im still having trouble locating the burp parameter-names.txt

livid pier
#

what file you looking for?

muted kite
#

I just found it by using find

slow ruin
#

Hey everyone, I am currently stuck on Hacking Wordpress - Directory Indexing. I did a wpscan and found some "stuff" however I am trying to use the html2text and it doesn't seem to work for me. I am working in the pwnbox. Would appreciate a nudge in the right direction

muted kite
#

find / .type d -iname burp-parameter-names.txt

muted kite
#

home/anonymous/SecLists/Discovery/Web-Content/burp-parameter-names.txt
/home/anonymous/SecLists-master/Discovery/Web-Content/burp-parameter-names.t

#

huge list showed up, bad news is the command isnt responding anyways

slow ruin
muted kite
livid pier
#

?

slow ruin
feral gyro
#

on pwnbox or ur machine ?

muted kite
#

Im on OS

#

machine target

feral gyro
#

DM

muted kite
#

its installed now

#

but for whatever reason, the command gave no output

feral gyro
#

show me the command

livid pier
#

:rainbowwizard:

#

anyone here have nitro?

#

:rainbowwizard:

proper edge
#

Noob here looking for help with the NTFS vs Share permissions of the Windows fundamentals module. Hope this is the correct place to seek help. If not please point me to it.Specifically

livid pier
proper edge
#

Specifically i'm having trouble mounting the windows machine from the Pwnbox. I successfully used xfreerdp to connect to the windows machine and created the folder on the desktop. But getting the following error after attempting to mount the directory from pwnbox.

#

im using the following "sudo mount -t cifs -o username=htb-student,password=Academy_WinFun! //10.129.201.57/"Company Data" /home/htb-ac397918/Desktop/

#

error(115) operation now in progress Refer to the mount.cifs(8) manual page and kernel log messages

livid pier
#

is /home/htb-ac397918/Desktop/ the file path for the windows machine or the pwnbox?

proper edge
#

pwnbox

#

also installed the cifs-utils per module troubleshooting suggestion

livid pier
#

lol so that is one option to wait it out

#

try to wait it out

proper edge
#

i have retried but not sure waited the full ten minutes ๐Ÿ˜‰

livid pier
#

can you reach it by smbclient?

proper edge
#

that is the next step, i tried it last night after failing with mounting. it didn't work but i thought it could just be related

livid pier
#

smbclient -N -U 'user%pass' \\IP\Company data

proper edge
#

including % but not quotes? correct

livid pier
#

wuotes too

proper edge
#

space between ' and \ ??

livid pier
#

yes

proper edge
#

appear to get > prompt

fossil crescent
proper edge
#

this is the smbclient command in the module "smbclient -L IPaddressOfTarget -U htb-student"

livid pier
#

smbclient -N -U 'user%pass' \\IP\Company data

#

discord is altering the command my bad just notcied

#

should be 4 and 2

proper edge
#

the module smbclient command still fails "(Error NT STATUS IO TIMEOUT)

#

but your command appears to work, i get what appears to be a > prompt

livid pier
#

hmmm

proper edge
#

don't know what to do while there

#

neither windows ro linux commands work

#

ctrl C to quit

livid pier
#

hmm I really dont know, this is outta my league

proper edge
#

i appreciate the effort

#

are the moderators that i can dm ??

livid pier
#

Ya I would start buy trying to find who made the box

#

or module

#

mods and staff are to the right

#

scroll down to staff

proper edge
#

is it appropriate to dm them

livid pier
#

Anyone around that can give a hint to the 'Web attacks - skill assessment'?

livid pier
#

try to get an answer with us then ask them

proper edge
#

thanks for the help

livid pier
#

always good to ask them if there is a technical issue

unique valve
proper edge
#

finished the module, but will go back and look at firewall to see if i can then mount the share

#

thanks for the tip

limber dock
#

hey can anyone of you help me ? my question is that if we use kali linux can we use this in all of our htb task? cause i dont want to use the lab that is provided by htb

#

can anyone help

#

??

proper edge
#

itnbob, r u still here

lament hollow
#

Anyone online completed the Linux x86 buffer overflow module?

#

I'm on the very last question and I've exploited the vulnerability to give a reverse shell but it spawned as the htb-student user and I am not sure what I'm doing with this suid bit on msg.txt to get the flag.

limber dock
lament hollow
#

Nevermind, figured out my issue, had to call the binary from the shell directly instead of running inside GDB because GDB doesn't have SUID, just the C program itself does.

vestal spruce
#

Question for the HTB academy room for Sedebugpriv on the windows privesc course. It's asking for this hash and I've ran mimikatz and procdump but can't see that listed hash from my dump. Any idea why?:

livid pier
#

:rainbowwizard:

livid pier
honest flower
#

Hi guys. Someone knows how to find the right tool's folders for exemptions in windows defender like suggested in setting up modules?

frank zenith
#

Hello, I have a problem with pinging given IPs by HTB academy. I have successfully connected to vpn, but if I type ping โ€œsome ipโ€, I get request timeout. Who have stumbled upon same problem?

shell flume
#

a

#

hi

unique valve
latent haven
#

Hi ! Quick question : in the information gathering module, I'm being asked Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer. however the command nslookup -type=NS inlanefreight.htb does not find anything for that domain. Is it broken ?

atomic river
#

Anyway I am stuck in the same module... in particular in the question "What is the FQDN of the IP address 10.10.34.136?". Can I DM someone for any hint? Thank you

livid pier
#

Why do you think you need to do that? What question are you stuck on?

#

Ok I am stuck there too.

#

I need to apply for jobs then I will get back on that. I was unable to log into the admin page and the other explits didnt work I was thinking wtf mate? From your comment maybe first need to enumerate better.

#

:randowwizard:

#

:rainbowwizard:

livid pier
#

Maybe not, idk, The ghostcat exploit works, nothing interesting on the page, maybe we would use it on different pages, is that what you were suggesting?

latent haven
grand gull
#

Hello I am on the linux fundamentals mod -- Here is the Question "How many files exist on the system that have the ".log" file extension?"
I have tried multiple variations of this command: find / -type f -iname "*.log" 2>/dev/null | wc -l
and the answer is wrong -- what am I missing or doing wrong

latent haven
rustic sage
#

hi, i'm stuck on "introducing to networking" module at the subnetting part

rustic sage
rustic sage
#

slit the network 10.200.20.0/27 into 4 subnets and submit the broadcast address of the 2nd subnet as the answer.

acoustic owl
rustic sage
#

thank you got the right answer

grand gull
#

@rustic sage I reset everything and it works now-- thanks!

livid pier
#

Anyone do sqlmap essentials? How did you get the json format for flag 4?

limber dock
#

can anyone help me i am unable to install the iso file for kali

#

idk why but other files are getting downloaded but the iso file is not downloading

#

can someone help??

rustic sage
livid pier
#

I see this, but i dont know how to get it as a json

shadow verge
#

I'm stuck on broken authentication module section weak bruteforce protections, question 2. I think I need help, anyone? :3

rustic sage
#

"Network" tab, find the POST request, open the "Request" tab and switch it to "raw"

#

@livid pier

livid pier
#

Is that what the whole file will be ? just the {'id':1}?

candid sandal
#

Hi ! Quick question : in the information gathering module, I'm being asked Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer. however the command nslookup -type=NS inlanefreight.htb does not find anything for that domain. Is it broken ?

rustic sage
#

Keep it simple :)

livid pier
#

THank you

livid pier
candid sandal
#

It seems that the command I used is indeed to identify the name server of a domain

livid pier
candid sandal
#

However it does not work as I get the result ** server can't find inlanefreight.htb: NXDOMAIN

livid pier
#

did you add the domain to /etc/hosts?

candid sandal
#

No I did not, and I believe this is the missing piece of the puzzle

#

I don't understand that

#

I have to add the target IP as my DNS server, is that correct ?

livid pier
#

If i am not mistaken, you need to open up /etc/hosts and add that to the list. IP inlanefreight.htb

#

on kali it looks like that. I use sudo nano /etc/hosts to access it

candid sandal
#

I'll try that, thanks

#

It seems not to work (same error message) even when I add the line 10.129.24.134 inlanefreight.htb to the hosts file :/

winged roost
#

Hey all, is sudo ever required in the Academy modules ? Reason I ask: i wish to edit the /etc/resolv.conf however it requires sudo but ive no password it, and I cannot see another way to set the name server to the target machine to carry out the tasks

livid pier
#

in the credentials file

winged roost
#

thank you very much! my fault for the oversight, ive gone back to it after so long.... shortcuts clearly dont work

livid pier
#

no worries happy hacking!

winged roost
winged roost
#

im still in process of doing that otherwise would have helped, sorry, but wish you luck with it

#

think it would be great if the mods could split the academy section by category as opposed to having it all in one place which gets abit polluted.

livid pier
#

If anyone wants to try out our new skills on some medium boxes let me know

rustic sage
livid pier
#

Now? you finish sqlmap?

rustic sage
neat kindle
#

Hey, does anyone know what this question wants from me? I'm unsure of what the correct answer format is.

#

It's from "DNS Enumeration Using Python - DNS Records and Queries"

muted kite
#

Im in Javascript deobfuscation. I found the flag for this 'secret.js' question, but it's not being accepted by the platform

#

I know for a fact it must be the answer

#

Im going to post the flag in here to confirm it's correct...

#

whose ready?

rustic sage
#

@muted kite The format mostly used in HTB Academy is:
HTB{flag}

livid pier
#

must be a troll

muted kite
#

okay let me try that

#

that format is not working either

livid pier
#

:rainbowwizard:

upper vault
#

Hi all. Working on the active infrastructure identification section of the info gathering -web edition module. Anyone here know how to resolve vHosts from the spawned target machines in something besides a cUrl dump? I have the ip, and the vHosts are "app.inlanefreight.local" and "dev.inlanefreight.local". I tried altering the /etc/hosts/ but doesnt seem to matter. For obvious reasons i cant use public enumeration tools to scope it out, as its not DNS accessable.

#

oh also, fun little tidbit i found out, wappalyzer will record and send up false 'positives' if you spam a site in browser with .asp / .js / .php, and show those services in use

#

do a *.com/index.asp and all the sudden your ubuntu server seems to run ISS, .NET and Windows

livid pier
#

you try nmap?

rustic sage
#

The tool you used did not do the right job

muted kite
#

this one didnt work either

#

function generateSerial() {
var flag = "HTB{flag!}";
var xhr = new XMLHttpRequest();
var url = "/serial.php";
xhr.open("POST", url, true);
xhr.send(null)
}

#

that is the full output

upper vault
#

@livid pier nmap the server? I could but it doesn't really solve my issue

rustic sage
#

@muted kite You are doing something wrong then. Go to secret.js, copy/paste the whole text

livid pier
muted kite
#

i did paste the whole text, it says flag!

upper vault
#

@livid pier really? huh guess im a dunce

muted kite
#

but it doesnt show it as the actual flag

upper vault
#

@livid pier I've got the answers, well except for CMS, but I can tell that the vHosts are actually serving content, I just cant seem to get it to display in a browser

muted kite
#

But I figured it out

#

thanks

#

it worked this time with the deobfuscation tool you sent me

rustic sage
muted kite
#

oh thanks, thats good knowledge

upper vault
#

@livid pier you could see the CMS from an nmap scan?

devout cliff
#

hey guys im on the skills assessment section of the login brute forcing module. im on the 2nd question but still coming up empty. this is my current command input for hydra, am i using the wrong password list or wrong POST field for failures for hydra?

#

hydra -l user -P /home/user/SecLists/Passwords/Leaked-Databases/rockyou-50.txt -f 159.65.53.42 -s 30302 http-post-form "/admin_login.php:username=^USER^&password=^PASS^:F=<button class='btn block-cube block-cube-hover'"

livid pier
#

hide the spoiler tho

upper vault
#

@livid pier holy cow really? I needed the bang at the end? lol

#

@livid pier thx for the help dude. I'm gonna keep playing with this vHosts thing to get it to do things for me

upper vault
#

@livid pier I figured it out, thought I had added the ip to the vHosts file correctly, <ip> app.inlanefreight.local dev.inlanefreight.local , but I mustve done a .com somewhere. Pulls the page fine now

#

when i changed the header 'host:" to pull a specific subdomain, it dumped the index.php, but couldn't route it in browser

#

whew

livid pier
#

That module was a pain for me, I made similar errors

carmine quail
#

Disregard my msg above. Just so happens I got it. 40th time's a charm I guess....

carmine quail
muted kite
#

Im not in that module yet, last time I was missing an exclamation point at the end of my flag

#

I mean it was stupid

#

it didnt show it in every deobfuscation tool

livid pier
#

:rainbowwizard:

upper vault
#

just me or does htb disable icmp on their targets in the vpn?

#

ok nvm, still sometimes yes, sometimes no

steel flume
#

i got a weird question. i got the answer for a module question but it wont accept it. what do i do?

vestal spruce
#

Got a few dumb questions.

  1. Why is it when I do a whoami /priv from cmd when not ran as admin vs admin I see more privs?
  2. Why is it when I run the token enablement script in powershell I see all privs enabled but in the same cmd (ran as elevated) it does not?
obsidian hornet
#

Hello got a question about the Linux PrivEsc module if anyone is around.

steel flume
#

i am on the getting started module. anyone able to answer ยจa question to help? rather not spoil it in here

upper vault
#

@steel flume if its a flag, make sure you submit it like HTB{answer}

steel flume
#

i fgured it out in time. weird spelling but thanks

upper vault
#

np

steel flume
#

had to google for a alternate spelling

upper vault
#

@vestal spruce if you find out id love to hear why

vestal spruce
#

I've been googling, no clue

upper vault
#

@obsidian hornet I probably wont have an answer but what was the issue?

steel flume
#

i got a question regarding using the smbclient

#

got a moment to assist me? its likely i am doing something dmb

obsidian hornet
upper vault
#

@vestal spruce don't know about #1, but I'd guess #2 is related to what Powershell is allowed to do over cmd. They don't have the same abilities over the system, even with similar instructions...pretty sure

#

@obsidian hornet oh good, grats!

#

@vestal spruce I imagine the differences between cmd and powershell are similar to different shells in linux, bash, csh, ksh, all provide a terminal but have big differences

livid pier
steel flume
#

okey i can't figure out why i keep get a NT_STATUS_NOT_FOUND

livid pier
steel flume
#

getting started

#

been trying to follow along but i feel like i am missing something just not sure what.

#

supposed to try get access using smbclient but everytime i attempt i get that

livid pier
#

what section?

steel flume
#

service scanning

livid pier
livid pier
steel flume
#

its about the last question

#

but i can't figure out why when i make the attempt i get that

#

and not a prompt or anything

#

onlytime i get a password prompt is when i use the -L flag

livid pier
#

what command are you using to connect?

upper vault
#

@livid pier have you done the active subdomain enumeration section on the info gathering web edition module yet?

upper vault
#

@livid pier hang on can I dm u? I can't figure on how to ask this w/o spoilers

livid pier
#

ya

swift carbon
#

did you figure this out? running into the same problem

west canopy
#

@swift carbon yea i was able to fix it by running: apt install python3-ldap

swift carbon
#

sweet that worked, thanks mate!

west canopy
#

np ๐Ÿ™‚

fierce pewter
#

Hi everyone! I'm stuck on a question from the module "Attacking Common Applications". I'm in the "WordPress - Discovery & Enumeration" section stuck on this question:

"Perform manual enumeration to discover another installed plugin. Submit the plugin name as the answer (3 words)."

At first sight, it seam to be clear and easy but all plugins I found are wrong... I'm test manual enumeration, wpscan, ffuf fuzzing WordPress Plugins (13k) but nothing i find is correct.

Can somebody help me?

fierce pewter
atomic river
muted kite
#

I have four modules unlocked: SQLI Fundamentals, File Inclusion, File Transfers, Intro to Network Traffic. Which should I do first?

#

Probably doesnt matter, I'll probably get stuck on all of them

untold kiln
muted kite
#

Sounds good

atomic river
#

Hi ! Quick question : in the information gathering module, I am not able to find the FQDN of the IP address 10.10.34.136. Can someone give me an hint? I found the DNS zones but this IP is not in this list.

lethal atlas
atomic river
lethal atlas
#

sounds like you are really close

lethal atlas
muted kite
#

Thank you, I will do that one. But man it's mighty long

untold kiln
#

what section of getting started ?

muted kite
untold kiln
#

remove the space after -u and -p

#

so, rdesktop -uhtb-student -pAcademy_student_AD! IP

#

or else try xfreerdp like
xfreerdp /v:10.129.247.44 /u:htb-student /p:Academyxxx

#

try without password, and type it at the login

#

DONT PRESS THE LINK !!!

fair meteor
#

I have some questions about a couple of the questions on the OSINT course. Thank you in advance ๐Ÿ™‚

radiant heath
#

where do i start

muted kite
#

What addressing mechanism is used at the Link Layer of the TCP/IP model?

#

Ive tried every possible answer

main vapor
muted kite
#

Second Page

main vapor
muted kite
#

I tried that already

main vapor
#

Yeah just tried it also

#

Give me a sec

muted kite
#

I even typed it out in full

#

Theres no point in making it any more difficult than it needs to be imo

#

Okay, I got it. I knew the answer, but it wants a particular variant

main vapor
#

@muted kite ||Yeah, I should have asked you what is the address of your favorite Mac restaurant instead|| ๐Ÿคฃ

upper vault
#

test test | test test |

#

so how do we block out text?

#

asdfasdf asdfjasdfj

#

asdf ||asdf||

#

aha got it

muted kite
upper vault
#

you can use double pipes on either side, or highlight the text and click the rightmost selection

#

(| | boooo | | )

#

but without the spaces between the pipes

#

and no parenthesis

#

||Boooo!||

muted kite
#

|| Pika-BOO||

upper vault
#

nice

muted kite
#

alright learned something new today

#

how to write spoiler alert of the top though

livid pier
#

||:ranbowwizard:||

livid pier
#

||wizard ||

upper vault
#

||๐Ÿ˜„||

fluid owl
#

Hi, I am interested in the htb academy subscriptions. But, they are quite costly for me. So, I was wondering how much cubes will be needed to unlock tier4 from tier1. Please give me a suggestion on which subscription should I take.

muted kite
livid pier
lethal atlas
#

I agree with VivisGhost. If you can get the student plan like I did, you can complete up to tier 2 which will take you some time. after that you can just buy cubes instead of the subscription and keep moving up.

fluid owl
lethal atlas
#

the base subscription is only 18 a month and will get you as far as the student plan.

fluid owl
#

will 3000 cube be enough till tier 4?

lethal atlas
#

1000 is enough to do 1 at a time

#

that will allow you to do everything.

gleaming knoll
#

Hi Guys, I am Bash

lethal atlas
#

$100 will get you enough cubes to unlock any module. However at tier 4 you will only be able to unlock one at a time

gleaming knoll
#

I codde on advanced python, in Computer Visiona nd GUI

#

i am new to this gropu, would anyone like to see my content ?

lethal atlas
gleaming knoll
#

HMM, so where should i go ?

lethal atlas
#

maybe programming or general

gleaming knoll
#

I can't message in that

#

for some mreason

#

reason*

lethal atlas
#

strange. Have you completed the intro stuff?

fluid owl
lethal atlas
#

you just get the 1000 back

#

you never earn more

gleaming knoll
fluid owl
#

for the tier 4 ones

gleaming knoll
#

ooh alr let me make in that

lethal atlas
#

tier 3 is 500 cubes

fluid owl
fluid owl
lethal atlas
#

and it looks as though I may have been incorrect in saying you never earn cubes. Looks like in the higher tiers you can earn some.

fluid owl
lethal atlas
fluid owl
#

Yes exactly, that is why I am so confused.

#

At that rate you need to spent a lot of cubes.

lethal atlas
#

Ok, so I looked at the FAQ and went back thru modules I finished and I was completely wrong. If you just buy cubes, you will not get back what you spent so you will eventually run out. With subscription you get a monthly allotment of cubes and whatever is left over at the end of the month rolls over.

fluid owl
lethal atlas
#

So I recommend starting with the free stuff. then get the silver sucscription and work thru as much as you can before upgrading your sub.

fluid owl
lethal atlas
#

work thru as much as you can for as little as you must spend

fluid owl
#

Thanks for the help!!!

lethal atlas
#

yw

swift carbon
#

I was having this problem earlier. xfreerdp seems to have very low tolerance for packet loss. if you're using wifi i would suggest moving closer to your router. you may also have to run the command several times before it works

#

nice, hope they fix it for ya

limber dock
#

guys i am unable to install the iso file for kali linux can anyone help my internet connection is good all other files are getting downloaded but the iso file is getting stuck in between

#

pls help!!!

muted kite
#

Given the capture file at /tmp/capture.pcap, what tcpdump command will enable you to read from the capture and show the output contents in Hex and ASCII?

#

I've tried -rX capture.pcap

#

and other variations

#

like -DXr capture.pcap

#

so confused

rustic sage
muted kite
#

whoever said traffic analysis is easy is kind of lying. Most of it is, but there are parts I just cant find the right answer too

lethal atlas
#

LOL I said it was easy

muted kite
#

sudo tcmpdump -Xr /tmp/capture.pcap

#

that doesnt work either

#

What TCPDump switch will increase the verbosity of our output?

#

this question I also cannot figure out

#

I know -v -vv -vvv doesnt work

untold kiln
#

what section are you at ?

lethal atlas
untold kiln
#

Cool ๐Ÿ˜„

muted kite
#

What TCPDump switch will allow us to pipe the contents of a pcap file out to another function such as 'grep'? If i wished to filter out ICMP traffic from out capture, what filter could we use?

#

for the first one I dont know for the second one I typed 'proto'

#

im sure its right in my face

untold kiln
muted kite
#

okay got the first one

#

-l

untold kiln
#

If i wished to filter out ICMP traffic from out capture, what filter could we use? ( word only, not symbol please.)
read it carefully ... filter out ICMP

muted kite
#

oh literally type it out

#

NOT+traffic

#

I feel so stupid

untold kiln
#

filter out as in not show it

burnt forum
#

hello guys
i have an issues that make me can't connect on any server even i changed the tool it can't connect on the server ip and port

valid forge
#

Looks like the SQL server I am trying to login to for SQLi is down.

clear turret
#

for javascript Deobfuscation - JSNice is down for me, can anyone confirm this? I tried other web res. to Deobfuscate the flag, though they keep it as is. Is anyone able to advise on Deobfuscation task? Many thanks

#

is that recent or has that been for a while? Is there anything that actually replicates the JSNice output?

sudden summit
#

Anyone available to help on the webshell skills assess? Importing the module gets "NoMethodError undefined method 'split' for nil:NilClass'. Tried some port forwarding to get it to work from my attackbox but cannot seem to load the module from there now.

#

This is for box 2 on the skills assess

sudden summit
#

Ok I got it. For anyone else having the same problem in the future in the shells and payloads assessments, your msf is not broken. Be specific in the modules options. Minor error on my part sent me on a rabbit hole thinking ruby had some missing gems or something.

rustic sage
#

can anyone help with the network enumeration module? im just starting out and having trouble with this question "Find all TCP ports on your target. Submit the total number of found TCP ports as the answer." im trying to use sudo but it wont let me.. is there something im missing?

livid pier
rustic sage
#

running nmap -sS <ip> and getting "You requested a scan type which requires root privileges."

livid pier
#

use sudo

rustic sage
#

now it wants a password... fml

livid pier
#

bruh

rustic sage
#

thanks

livid pier
naive sinew
#

Good day
I started HTB academy and at linux fundamentals first interactive session to to ssh to an ip address and get some basic system information,
I can use pwnbox or vpn key
I prefer vpn key ,pwnbox isn't that responsive for me,
The problem is after connecting to the vpn, i pinged the target ip but destination host unreachable,
I tried reconnecting to the vpn but i still can't connect to the IP, what am i doing wrong
Using vpn in htb machines as always been easy and i never had this issue

naive sinew
#

Yes

livid pier
#

and it says its connecting?

naive sinew
#

No it's connected initializing sequence completed

livid pier
#

ok well thats good

#

a first step

naive sinew
#

Yh

livid pier
#

and you spawn a box like this?

naive sinew
#

Yes I have 26 minutes left

#

I evens reset the target just in case but i still couldn't ping the provided ip

livid pier
#

is the opvn file academy?

naive sinew
#

Yes academy.ovpn

livid pier
#

loll idk. restart your computer?

naive sinew
#

Was trying to avoid that, thanks I'll do thay, i hope it works

novel sage
#

where i start ?? Anyone Answer please

steel flume
#

got a question regarding using metasploit

novel sage
#

you also New to Hack The Box ??

steel flume
#

yeah

novel sage
#

Mm How Many Modules YOu Finish ??

steel flume
#

a couple am at getting started at the moment

novel sage
#

Modules Name ??

steel flume
#

getting started

novel sage
#

Its Easy or not ???

steel flume
#

it's more about mindset and looking at things

#

you are better of focusing on the fundementals like i am before anything else

novel sage
#

Are You studying Or working ??

steel flume
#

studying

novel sage
#

same Are U from ?

steel flume
#

wont answer that

#

i am looking for assistance regarding metasploit

final ridge
#

hey

#

i cannot chat in other channels

final ridge
#

hey

urban sage
dull bear
#

the forgot password doesn't seem to work on HTB

#

academy

deft trellis
#

hi

limber dock
#

guys

slow ruin
#

Hey everyone, currently stuck on Hacking WordPress - Skills Assessment. I found the plugins I am able to enumerate though and look at files. However, can't seem to find the flag. Can anyone give me a nudge in the right direction?

rustic sage
#

Goodmorning

livid pier
slender lynx
#

Why is it that every dam time i spawn a target on the Academy plattform, it just works when it wants to work? I respawn, i try to connect, nothing. Suddenly it works, and the next time again it doesn't work. It's like it is completely random when it is working and not. Honestly not worthy of my time

brave hatch
#

Hey all, fairly new to HTB, went through the first couple of courses and was feeling good, and did the "crocodile" module the way that i thought it should be done, and couldnt retreive the files from the anonymous FTP server. I looked at the walkthrough and it said to do the exact steps that i had already done, so i retried it, and again i kept getting permission denied when trying to GET the files from the anonymous ftp server. what would cause this, or how would i circumvent this? I'm sure its user error but i'm trying to learn! thanks in advance.

balmy radish
rustic sage
#

im fairly new to everything, but do have a sidetrack question, why is there a vpn option?

balmy radish
rustic sage
#

ahh okay, im starting with linux fundamentals

brave hatch
balmy radish
#

No need to apologize. You'll just probably be able to get help faster there.

slow bluff
#

Hi windows priv esc > DnsAdmins > any help pls i cant get this to work idk what am doing wrong thanks Solved!

hexed tartan
#

someone who has done 'attacking common application' please dm me

west canopy
#

@slow bluff does it involve loading a dll file and restarting the DNS service? I'm pretty sure something changed with the box called "Resolute" where that is the solution but it no longer works, inexplicably.

muted kite
#

Based on the traffic seen in the pcap file, who is the DNS server in this network segment? (ip address)

#

I checked the hint but the output from the pcap file is vast and I cannot find source port 53

slow bluff
west canopy
#

@slow bluff Did you have any trouble downloading the adduser.dll to the target from your machine?

west canopy
#

ok it must be a network issue on my end. Do you recall what directory you downloaded it into? \windows\temp?

#

its just hanging on "writing web request" , never finishes, file shows up in the directory but its 0 bytes ๐Ÿ˜ฆ

west canopy
#

alright thanks bud. I'm just respawning the target and restarting my vpn , hopefully this fixes it.

acoustic owl
slow ruin
hexed tartan
#

I'm stuck last question of wordpress section of "Attacking Common Application", can't get the payload to run properly, please dm me if someone has resolved this one

west canopy
#

Is anyone else unable to download files to the target from their VM in the Windows Priv Esc module? I have my python httpserver up , and from the target in powershell it just hangs on "Writing Web Request." It works from the pwnbox though ...

livid pier
livid pier
#

Anyone finish intro to bash scripting?

coarse mango
#

hello, having some trouble with File Inclusion module > skill assessment section. any help would be appreciated

livid pier
#

Anyone here that has completed: Stack based buffer overflows windows || Broken Authentication | | command injections?

muted kite
#

someone please just give me the name of the person Im supposed to find

livid pier
#

No machine is terribad

muted kite
#

yes so is xfreerdp as well

#

I cant get the answer

#

I was able to get the answer for the first question using the wireshark filters

#

but for the question that gives me 0 cubes I am spending more time on

#

ha I just manual brute forced common first names

#

and got one

#

pewpewpew

odd basin
#

Coming back to academy after some time away. I can't find the VPN for academy! Button button where is the button??

#

It used to be in each module somewhere around the button to start the pwn box. I don't see it there anymore.

rustic sage
odd basin
#

So I should be able to access the target from the internet?

odd basin
#

derp, okay thanks!

autumn pilot
#

some of the targets do not require VPN, thus you might or might not see the button for VPN download

limber dock
#

i am having some problems in performing the man in the middle attack can someone help

limber lark
#

Im very stuck on the command injection assessment. Any help would be greatly apprecited.
Im still not sure which parameter is injectable..

livid pier
limber lark
livid pier
#

:rainbowwizard:

livid pier
#

wanna give so tidbits of knowledge?

limber lark
livid pier
limber lark
#

In burp you can right click in repeater and select โ€œurl encode as you typeโ€
Keep in mind that when pasting from other sources into your request, you will have to delete some chars and retype them.
Or just use something like cyberchef

west canopy
#

Who do we reach out to for technical issues? Currently not able to complete the "Windows Built In Groups" section of Windows Privilege Escalation. Trying to RDP into the target results in a black screen followed by disconnection from my VM. And from the pwnbox , i can RDP and stay connected for about thirty seconds before it boots me off. I have tried resetting the target numerous times.

#

Also unable to reconnect via RDP from pwnbox after getting booted.

lone comet
#

Can somebody help me:
I am currently doing the moduel footprinting and i stuck at some DNS questions, e.g. Identify if its possible to perform a zone transfer and submit the TXT record as the answer. (Format: HTB{...))
So i have done the following:
dig any inlanefreight.htb @10.129.14.128
got some txt, mx, a, soa records and the ns1.inlanefreight.htb ns
so what must i do next, or what tools should i practice in order to solve this and the following questions..`?
thx for your help,
a beginner in cybersec

livid pier
#

try something like that

muted kite
lone comet
livid pier
#

any or axfr dont work either?

lone comet
#

there are the txt records but cant use them properly :/

livid pier
#

bruh use <something>.inlanefreight.htb

lone comet
#

ok thank you ^^ got with that new entries

livid pier
twin raft
#

Hi community i have some problems with SQLMap in this question, when i do my command i got a flag but when i paste it as answer it says isn't correct

west canopy
#

@twin raft i do recall when i did that module , on one section it spit out the flag but it was missing a character. Super weird

twin raft
#

Can i dm to you? @west canopy

west canopy
#

yep

lone comet
rustic sage
#

so does the hackthebox thing cost money?

livid pier
rustic sage
#

yeah

#

dont be rude ffs

livid pier
rustic sage
#

shit sake, type a few words on a keyboard,

#

no need to win every argument you start

livid pier
#

Im not trying to win an argument, im suggesting you do some research yourself, if you legit look and cant find an answer come back and ask

rustic sage
#

i cannot find an answer, may i ask, how much does the hackthebox thing cost, if it does cost money of course ๐Ÿ™‚

livid pier
#

So hack the box or HTB academy?

rustic sage
#

HTB academy

livid pier
#

you can do about 25% of the modules for free

rustic sage
#

thank you ๐Ÿ˜

untold kiln
#

All HTB academy Tier 0 moduls are free, there is 17 of them.

rustic sage
#

ahh

upper vault
#

soooo finally about to finish..

#

** Information Gathering - Web - Skills Assessment **

#

and I'm stuck on Q#3

#
  1. Perform active infrastructure identification against the host https://gear.githubapp.com. What server name is returned for the host?
#

I'm assuming they mean the FQDN?

#

which i found to be || aquatic-cucumber-a8v3wu9jbll2hidkklzjvzc0.herokudns.com||

#

what'd i miss?

acoustic owl
#

No, they mean the server name, not the FQDN.

upper vault
#

Aha, whoops

#

yup had it all along

#

Feels kinda funny running any 'active' tools against a public service, like githubapp.com

muted kite
#

anybody else having fun with file inclusion?

muted kite
# livid pier

Once I've completed all the free modules I will have to visit this. Appears the price went up a little

untold kiln
muted kite
#

lol

untold kiln
#

ha ha ha , true

muted kite
#

lmao

#

what a complicated sequence

untold kiln
#

well... a sequence is a series of something. So a complicated one, must be a difficult one to spot...

acoustic owl
#

You only need ||whois, dig or nslookup, curl and sublist3r ||for Information Gathering - Web - Skills Assessment.
Other tools are not necessary.

muted kite
#

'GET /index.php?language=/var/log/apache2/acess.log/var/log/apache2/access.log&cmd=cat%20/exercise/flag.txt HTTP/1.1
Host: 159.65.53.42:32630
User-Agent: <?php system($_GET['cmd']); ?>'

#

Im in Local File Inclusion module. I think everything above looks correct, but I cannot see the flag.txt

livid pier
#

user agent?

livid pier
lethal atlas
#

I see the error

lethal atlas
muted kite
#

Ill come back to it with a fresh set of eye

livid pier
livid pier
#

Scooby?

quaint igloo
#

Hi guys, could someone give me a hint on where to search for attack vector in sqlmap skills assessment section? Can't really figure it out.

livid pier
#

you will notice one request is different from the rest

quaint igloo
#

ok gonna try rn

west canopy
#

Anyone here able to complete the "Server Operators" section of Windows Privilege Escalation? I am following the directions and have successfully added the server_adm user to the local administrators group, but I still do not have permission to access the flag.

livid pier
west canopy
#

Save your cubes brother. This thing is riddled with technical issues.

livid pier
west canopy
#

Yep

livid pier
#

When its all said and done I think I will be able to get 1 500 cude module

#

I want to sepnd them wisely

west canopy
#

I mean, i didn't have to deal with being disconnected from RDP every thirty seconds , which is an improvement.

livid pier
#

That is so frustrating

west canopy
#

And the skills assessment requires using techniques that aren't covered in the module

livid pier
#

There have been a couple modules using no machine that made me want to jump off a bridge

west canopy
#

Yea I remember having to use NoMachine for shells and payloads

livid pier
#

Im hoping they can iron out some of these issues soon.

#

IM starting to not be able to connect to servers too

west canopy
#

Yea I have to use pwnbox also. Trying to RDP from my VM results in a black screen followed by an immediate disconnect. And in the few sections where i could RDP from my VM, i'm not able to download files onto the target from my python http server.

livid pier
west canopy
#

Glad it isn't just me then haha

muted kite
#

@livid pier I see you're color has upgraded, whats that mean?

muted kite
#

how do you prove yourself?

livid pier
muted kite
#

Nice Job! ๐Ÿ‘

rose crest
#

Could anyone give me a hint on the last question of attacking tomcat in the attacking common application module? I have RCE, but am looking for the flag everywhere, but can't seem to find it

rose crest
#

Got it! Just needed to try some other ways to get RCE

mint chasm
#

Hey guys

#

How can i start?

#

Pls tell

winged smelt
viral meteor
#

Hello,
has anyone a hint for the skill assessment of the Broken Authentication module? I think I'm almost done just the last step is missing. || I can craft a valid token and login as a privileged user but i have no clue how to proceed now ||

rustic sage
#

hi

tawny umbra
#

Hi

limber dock
#

hey guys i am having problem in submitting the flag

#

in getting started

#

i got the flag but not able to write it

#

its showing wrong

#

can someone help

tawny umbra
#

Yes

#

I can

limber dock
#

ok

#

go on

#

ayo

#

XD

#

nice

tawny umbra
#

I do a little hacking

#

I can change my whatsApp number

limber dock
#

WOW

#

sir i inspire you

tawny umbra
#

Nice

limber dock
tawny umbra
#

I wish more kids get inspired by me

limber dock
tawny umbra
limber dock
tawny umbra
limber dock
#

what

#

what is this

tawny umbra
#

Idk

#

No

#

Dont

limber dock
#

looks like a bald guy

tawny umbra
#

Write

#

Anything

limber dock
#

ohkk

tawny umbra
#

Yea boi

#

@limber dock

limber dock
#

oh

#

wow

tawny umbra
#

XD

languid dawn
#

can we not do offtopic chats here

tawny umbra
#

Sorry brah

#

You deleted my hard work

languid dawn
tawny umbra
#

I can't chat there

limber dock
#

sad

#

get verified

rich heron
#

I'm working my way through the OSINT: Corporate Recon module and need some help with the cloud storage section. I feel like I've tried everything, but I bet I'm overlooking something obvious. Would anyone be able to point me in the right direction?

lethal atlas
livid pier
lethal atlas
#

quiet today..

livid pier
lethal atlas
#

monday blues i guess.

livid pier
#

Anyone around to give some broken authentication hints?

hollow hinge
#

Heyooo

#

Is there anybody present on DC?

livid pier
hollow hinge
#

Bro can you suggest me some linux priv esc techniques?

livid pier
#

The new one is legit, only working on old boxes, its a linux skeleton key tho

#

by onld boxes I mean like 2 months old

hollow hinge
#

Do you about binaries?

livid pier
hollow hinge
#

Like escalate privileges with binaries?

livid pier
#

You wont learn what the box is trying to teach with that one, but it gets the job done

hollow hinge
#

Ohh thanks a lot dead

livid pier
#

with binaries you are looking for something that you can use that has sudo privilages

hollow hinge
#

Dm i was doin on THM

#

Do you know THM?

#

And recently joined HTB

livid pier
#

Ive heard of THM, heard good things, never used it tho

hollow hinge
#

Ohh thats fine

#

So can i get to know you? If you dont mind?

livid pier
hollow hinge
#

I mean to say about cyber security

#

How did you get into hacking, red teaming

#

And stuffss

#

Becuz i also wanna get into this stuff

livid pier
#

I am super fresh too, I started in december, I took the IBM cert on coursera and now im here

#

Well you are in the right place, start with some academy modules, the HTB starting point boxes

hollow hinge
#

Have you done masters in any prog. Langauge

livid pier
#

there are alot of resources here

hollow hinge
#

Yes i have seen

livid pier
#

I came from data analysis, i am good with python

#

machine learning, that stuff

hollow hinge
#

I am just a beginner in python

hollow hinge
livid pier
#

My advice while here is take notes while doing boxes and modules, then after you finish try to help people, it will solidify the knowledge

hollow hinge
#

I always do

#

A shit happened to my parrot

#

Its going into read only file system randomly

#

And i had to reinstall the OS again and again

#

Do you have any permanent solution for this?

livid pier
#

No, I use kali and have never had a problem like that

hollow hinge
#

Ohh i see

#

Kali lagged in my pc(low specs)

#

Parrot runs much faster

#

And smooth

west canopy
#

VM's tend to just crap out in general from my experience. The drive for my kali VM randomly gets corrupted and I have to restore to a snapshot. Also it's not able to get an IP when i try and do a bridged network adapter.

hollow hinge
#

Oh

rich heron
hollow hinge
livid pier
hollow hinge
#

:

muted kite
#

I may also switch to parrot, at least try it on a vm

austere wigeon
#

Hi everyone some one know why when i want to take the cheatsheet i get a .md instead of a beutifull pdf like in the photo?

#

It would be awwesome if this is a pdf and not a md

livid pier
#

@muted kite you finish web traffic?

muted kite
#

LHI is what it's called, and no, I'm taking a break. Tired of getting frustrated

#

LFI

#

File Inclusion

livid pier
#

did you get this answer?

#

from tcp dump? and where are you stuck? I am about to finish it

muted kite
#

i cant get the flag

#

yeah i found that one

livid pier
#

what format does it want to separate the numbers? i found the two ports it wont accept anything tho

livid pier
muted kite
#

do you want the ports?

#

just a space

livid pier
#

|| 80 43804||

#

is that not it?

muted kite
#

close

#

very close

livid pier
#

arrgh

#

lies!

muted kite
#

i thought that too

livid pier
#

Why must they trick us like this!

muted kite
#

thats what I want to know

#

it actually doesnt really make sense

livid pier
#

lol

muted kite
#

Submit the contents of the flag.txt file located in the /exercise directory.

muted kite
#

I input the code that it asked for in Burp. But the flag didnt appear after the new GET request and I got tired of messing around with it

#

LFI to Remote Code Execution (RCE)

#

Im not working on it right now though

#

so not a big deal

livid pier
#

So close I cant taste it

#

Last 4

muted kite
#

After that you still have lots of boxes to crack

livid pier
#

This is true

muted kite
#

I think I started this in December, but you are way past me

#

ive completed 12 modules and I have 4 unlocked as well

#

Once I complete the free ones, I will buy a subscribtion

#

But no point in paying if I cant finish the free ones

livid pier
#

Ive been doing this all day every day for the past 2 months lol

livid pier
#

With that account you get the courses for free but get to keep the cubes

#

the earlier you get it the more cudes you an accumlate

muted kite
#

I will look into it, and see if I can qualify,

rose crest
#

Can anyone help me with a powershell command? I am not sure how I can make it into a one liner to get a reverse shell. I tried a bunch of things, but non of them seem to work

#

Its from the attacking common applications module

acoustic owl
rose crest
#

The last one from the other notable applications

#

Can I DM you perhaps?

acoustic owl
#

yes sure

cinder mortar
#

Hi, can someone help me with the SQLi fundamental module? I can't connect to the database. Does anyone know this problem? I get the message: "ERROR 2002 (HY000): Can't connect to MySQL server ". Thanks to you

wild prairie
#

Hey! can someone help me with a simple GET request with two parameters?

#

Send a GET request to flag.php with two parameters num1 and num2 such that their sum is 1337. This is the question I'm stuck on

lethal atlas
wild prairie
#

Can't believe I looked over that. I took it literally and entered num1 and num2 for the parameters...๐Ÿคฆโ€โ™‚๏ธ

slow bluff
#

windows priv esc > server operators > questions : why we cannot read and access the flag even after being member of administrators group and can by using crackmapexec ? thanks

crystal oracle
#

So... I am not super unexperienced, but I can't even get the root password lmao, anyone know where to find it? I can start the instances perfectly fine, but as soon as I want to do some sudo comamnds well.. I don't know my password

livid pier
#

In the credientals file

crystal oracle
#

Wow, thanks a lot! I was just dumb for a few days...

west canopy
#

@slow bluff i had to log out and log back in after , once the user was added to the group

#

@slow bluff also not sure if it matters (i dont think it does) but i navigated to the flag using windows File Explorer instead of command line or powershell

slow bluff
#

@west canopy thansks i will try it!

livid pier
#

Roll call

#

Anyone have any broken authentication help?

swift carbon
#

hey did you figure this out? could use a nudge

frozen sentinel
frozen sentinel
red obsidianBOT
#

There is no flag here. Get back to hacking!

livid pier
#

Anyone finish broken authentication?

celest cipher
#

hiyes

#

this is the place for asking questions probablyโ„ข๏ธ
I'm having issues with
NETWORK ENUMERATION WITH NMAP: HOST AND PORT SCANNING.

I've tried damn near everything and I simply cannot find the hostname.
Am I overthinking this? Is there something broken?
I could give you a list of all of the commands I used-

#

wiz
nice.

livid pier
#

You are in the right place

celest cipher
#

ohgod

#

ohgood, rather

#

both-

#

alright, where do we begin

#

uh- i'm just simply unable to find the hostname

livid pier
#

ok let me pull it up and take a look

celest cipher
#

ty

livid pier
#

alright what commands have you ran?

celest cipher
#

one sec

#
sudo nmap <ip> -p <port> -A
//I did dumb things with other programmes, tried to ssh into the ssh port
//Wget on the files I could, I'm probably horribly overthinking this 
//Used the script below on the http
sudo nmap <ip> -p 80 --script http-enum
nmap -v -A -sn -Pn <ip>
//Used arp, used -v, -A, -O, -sn, -sU -Pn, -F
#

am i just

#

overthinking this horribly?
not noticing something apparent?
was i born prematurely

livid pier
#

my two favs are -sC and -sV

#

try those

celest cipher
#

alright

livid pier
#

nmap -sC -sV -v IP

celest cipher
#

hmh.
it's hanging up.
lemme try again.

west canopy
#

@celest cipher DM me if you get stuck

celest cipher
#

sure

west canopy
#

not sure if you're there yet but there might be some funkiness in the medium lab / hard lab section. Like for medium lab I had to use pwnbox to get the answer, and on hard lab I had to use my VM

celest cipher
#

this say's it's easy-
this is at the beginning of a path

#

it's taking a bit of time again.

#

perhaps I just need to learn patience.

livid pier
#

the -sC and -sV will take more time

#

they are running scripts to get more info

#

It will give you the right answer, I just ran it again

celest cipher
#

alright

#

wow

#

that's a lot to take in

#

what do -sC and -sV do, anyways?