#modules

1 messages ยท Page 509 of 1

celest cipher
#

verdammt

#

VERDAMMT

#

AH T

#

h.

#

as many times as I have looked at it!

#

whelp, all good, appreciated, thank you millions.

livid pier
#

I think it will explain it more later on in the module

celest cipher
#

alright

#

appreciated

#

was doing this explained in the module?

celest cipher
#

it's alright

#

i guess they give you docs, that's nice of them

#

:3

#

but, i did discover how to use cat and some other funky stuff to grab server files

#

so that's chill

livid pier
celest cipher
#

shroog

#

ahwells, problem done, i can continue

hollow hinge
#

-sC used for defualt scripts enumeration, and -sV used for the versions of the services on the target

celest cipher
#

i see

#

thankyou

hollow hinge
#

Yeah always welcome

hollow hinge
#

Hey listen

#

How could i get permission to Pwnbox Room? In this server?

livid pier
#

I think you need to verify your account

livid pier
muted kite
#

Im stuck on LFI, I followed the instructions and im still stuck on Remote Code Execution

#

I did everything it said to do and I am still not seeing the same results as the screenshots on Page 3 of Local File Inclusion

muted kite
#

no worries, im skipping it

#

i dont want to touch it right now or im going to shoot a hole in my browser

#

lol

hollow hinge
livid pier
hollow hinge
#

Sure why not

#

hey Vivis ghost

#

i am up to learn on hackthebox

#

but not sure what to do

#

cuz i am a beginner in HTB

#

could you please guide me ?

#

@livid pier

#

btw i dont have premium account

livid pier
hollow hinge
#

yes i did

#

i am on room called Dancing

livid pier
#

which one did you sign up with?

hollow hinge
livid pier
#

ok

hollow hinge
#

pk?what?

livid pier
#

typo, in the app.hack website go to the top and click settings

#

scroll down and you should see this

hollow hinge
#

okk just a moment

#

well dont mind i am unable to find it

#

where it is exactly

livid pier
#

profile settings

#

click your icon

hollow hinge
#

yes

#

i am on profile setting

#

next what?

livid pier
#

do you see you account identifier key?

hollow hinge
#

yes i do

livid pier
#

k, get that and dm the Noahbot

#

top right of this page

hollow hinge
#

means dm the key right?

livid pier
#

yes

#

send it the ++ verify (no space)

#

just like in the picture

#

it will walk you through the last step

#

then you should have access to the other rooms you were talking about

hollow hinge
#

thanks a lot man

#

he said you are registerd

livid pier
#

nice

#

try it out see if it works

#

your name changed colors

#

you should be good

hollow hinge
#

yes

#

so now what to do next on HTB

livid pier
#

I recommend either academy(that other site) or starting point

#

academy is a grind you will learn alot and it is free to start

hollow hinge
#

i am ready to grind

#

so i should i go to academy

#

?

livid pier
#

Yes

#

you will have to make another account

#

on that site, they dont cross over

hollow hinge
#

ohh

livid pier
#

discord will be the same, you wont have to do that again here

#

but it is good to have both accounts

hollow hinge
#

ohh

livid pier
#

think of academy as the training grounds and htb as the battle ground to practice what you have learned

hollow hinge
#

thanks a lot my brother

livid pier
#

Last piece of advice take good notes

#

every module has questions at the end to test your knowledge, keep notes of the process and commands you used to solve them

hollow hinge
#

bro can i see some of your notes

#

to get some qualitive idea?

livid pier
#

My one regret is I didnt take any!

#

I wish I would have

hollow hinge
#

ohh no worry

livid pier
#

Whenever I help someone I have to go back and redo the whole problem

hollow hinge
#

HAHA

#

listen again

#

i see cyber security courses

#

?

livid pier
#

? in academy?

hollow hinge
#

yes

#

where to go in academy

#

to grind

livid pier
#

start there

hollow hinge
#

ohh

#

bro is it free one?

livid pier
#

you have 50 cubes?

hollow hinge
#

no i dont have

#

i only have 30

livid pier
#

oh ok, start with the modules that cost 10 and you get 10 back, I forget which ones they are

#

I think that might be one of them

#

that +10 cubes is how many you get back once you finish it

#

there might be some that dont cost any cubes and will give you some back too

hollow hinge
#

to start this couse you need to signup

#

even though i logged in

livid pier
#

with the new acadamy account?

hollow hinge
#

yes

livid pier
#

oh, I guess try logging in with those same credentials

hollow hinge
#

when i click on signup it get me to the dashboard

#

bro bro

livid pier
hollow hinge
#

its asking to pay 10 cubes

#

to get inside the module

livid pier
#

ya that is normal

hollow hinge
#

should i pay for it?

livid pier
#

you will get the 10 cubes back if you finish it

hollow hinge
#

damn i am in

livid pier
#

Ya keep doing the cheap ones that give you the amount of cubes back that you put in.

hollow hinge
#

โค๏ธ

livid pier
#

Should get a bunch of modules done

hollow hinge
#

yeap

livid pier
#

Alright get to work, let us know if you get stuck

hollow hinge
#

yes thanks a lot dude

muted kite
#

I'm going to tryhackme for a little bit. I'm tired if struggling on hack the box. I want a more guided experience. I'll come back soon if it's not what I expected

#

Thanks for all the help

hollow hinge
#

@livid pier bro do you have some free proxies?i want to add them into my proxychains

#

and bro how FI could lead to RCE?

livid pier
muted kite
#

Will do

livid pier
hollow hinge
#

i meant to say how File inclusion can give us remote code execution

livid pier
#

Which module and section?

#

or is that just a general question?

hollow hinge
livid pier
#

If the website hosts files you can upload a shell to it to get an RCE

languid dawn
#

Don't randomly ping members please

real epoch
#

@languid dawn

#

@languid dawn

#

@languid dawn@languid dawn

#

GO SUCK YOUR MOM

livid pier
#

lol bruh

livid pier
frosty glacier
#

I'm stuck on Getting Started/Basic Tools.

#

The Optional exercise at the bottom isn't working. Using SSH, netcat, ping, etc.

#

Nothing works

livid pier
#

are you on pwnbox? free version?

frosty glacier
#

I am, yes.

#

Connected over the browser

#

I prefer having money

livid pier
#

so you cant connect to the internet with that

#

what are you trying to ping?

frosty glacier
#

... the optional exercises target..?

livid pier
#

I dont have them all memorized

frosty glacier
livid pier
#

thank you

frosty glacier
#

It'd be kinda counterintuitive if I could use a pwnbox... but my tools were useless

livid pier
#

you can use it to complete most things

frosty glacier
#

It's almost like I can't reach out

livid pier
#

Either way I recommend getting kali

frosty glacier
#

nc, ssh, ping

#

they all freeze up

#

I'm running Kubuntu as my dual boot but I can't AFFORD a pwnbox

livid pier
#

i understand

#

kali is free

frosty glacier
#

Wdym "get Kali"

#

I've already got Kubuntu set up

#

and, also... how would that help me with this issue

livid pier
#

because you are going to be limited with the pwnbox

frosty glacier
#
โ”€[eu-academy-2]โ”€[10.10.14.172]โ”€[htb-ac407040@pwnbox-base]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ nc 167.172.56.232:32199 -v
167.172.56.232:32199: forward host lookup failed: Unknown host
frosty glacier
#

Because this isn't HTB proper, this is the academy, in-browser

frosty glacier
#

Then how would getting Kali fix the in-browser connection to pwnbox

#

I just want to do this module

livid pier
#

because you dont need pwnbox to do academy, you can complete the acadmey anyway you want

frosty glacier
#

??? How?

#

The targets are

hollow hinge
#

bro

#

i got stuck

frosty glacier
#

The Academy targets aren't open to the internet, are they??

#

I can't ping them

hollow hinge
#

If you wanted to inject a malicious link to "http://www.malicious.com", and have the clickable text read 'Click Me', what's the HTML code you would use?

#

what would be the answer

livid pier
hollow hinge
#

its wrong

hollow hinge
#

and connected to the server too

livid pier
frosty glacier
hollow hinge
livid pier
#

what module and what section?

livid pier
hollow hinge
#

introduction to web app

#

and in the HTML injection

livid pier
hollow hinge
livid pier
hollow hinge
#

yes i did

#

but its still showing incorrect

livid pier
#

http://

hollow hinge
#

what

#

you mean to say

#

add http to it

#

or remove www?

#

or what

livid pier
hollow hinge
#

damn

#

workeed

#

its correct now

#

now i can move ahead

frosty glacier
#

@livid pier I figured out what you meant.

#

I don't need to use the pwnbox at all??

frosty glacier
#

BASED

#

if nmap wants to work, that is

livid pier
#

You can run kali on a vpn like virtual box and use a vpn to connect to HTB

frosty glacier
#

I don't need Kali lol

#

Kubuntu is set

livid pier
#

that will let you do all the modules without using pwnbox

frosty glacier
#

I already set up Kubuntu for HTB

livid pier
#

Whatever works for you

frosty glacier
#

target isn't responding to pings

livid pier
#

openvpn?

frosty glacier
#

Yes

livid pier
#

initialization sequence complete?

frosty glacier
#

Yes

#

It was working

#

167.172.56.232:32024

#

Apparently, that's not a valid IP?

#

I removed the port and it just eats the pings

autumn pilot
#

how do you ping a port?

livid pier
frosty glacier
livid pier
#

target*

frosty glacier
#

I am, and it's not working

autumn pilot
#

have you gone through intro to academy module dreamingazzy

frosty glacier
#

it's literally mandatory to use the academy

autumn pilot
#

ok, if you remember what you have read there

#

what the targets could be

frosty glacier
#

???

autumn pilot
#

there are two kinds of targets, this is a small hint

frosty glacier
#

Yes, I know

#

"Once this image spawns, you can choose to interact with it from the provided Pwnbox, your own VM, etc."

#

I am using my own machine

#

It is not working

autumn pilot
#

it doesn't matter

#

i'm referring to targets

#

and if you know the two kinds of target, what are they

frosty glacier
#

VM and Docker?

autumn pilot
#

good

frosty glacier
#

Yes, I know that

autumn pilot
#

and to which group your target corresponds to

frosty glacier
#

Yes, I know

autumn pilot
#

that was not a yes or no question

frosty glacier
#

My target is a Docker target.

autumn pilot
#

ok, if so how could you ping a port

frosty glacier
#

? Why do I need to do that?

haughty moat
#

Stuck over the same question.

autumn pilot
#

you are trying to ping the machine right, if you have a port how could you ping it

#

you are currently on an autopilot, think more

frosty glacier
#

But I don't need to ping a port

#

I can just ping <target_ip> without a port

autumn pilot
#

and you are saying that you cannot reach the target like this

frosty glacier
#

I need to see if I can connect to it before I even do anything

#

Yes

#

I'm connected to the Academy network with OpenVPN

autumn pilot
#

please, re-visit "Intro to Academy" module

frosty glacier
#

What am I missing?

livid pier
#

@autumn pilot Welcome I have never seen you here before. Are you part of the night crew?

autumn pilot
#

you are missing the part that you can't ping a docker instance

frosty glacier
#

? It has an IP

#

It has an existence on the internet

autumn pilot
#

you are trying to ping the main docker hub, rather than the container which is impossible

#

with ping

frosty glacier
#

I can connect to it

autumn pilot
#

i give up

haughty moat
hollow hinge
#

@livid pier bro

#

i had completed the module

livid pier
#

nice

hollow hinge
#

but

#

i didnt get any extra cubes

livid pier
#

You didnt get cubes as you answered the questions?

hollow hinge
#

i got

#

i thought i will get extra 10 cubes over 10

livid pier
#

no, just 10 back

hollow hinge
#

yes

#

bro how can i earn more cubers

#

cubes*

livid pier
#

there should be two modules that you can do for 0 cubes and get 10 back

#

you will have a total of 50, but thats all you get for free

hollow hinge
#

which are they?

livid pier
#

Im not sure I cant see the cube prices anymore since ive done them,

hollow hinge
#

are you a premium user?

livid pier
#

even if im wrong you can do alot of modules with those 30

livid pier
livid pier
hollow hinge
#

how much did you pay for it?

livid pier
#

8 bucks a month

hollow hinge
#

ohhkk great!

frosty glacier
#

Now I'm stuck on Public Exploits in Getting Started

#

oh

rose crest
#

Could someone help me in skills assesment 1 - Attacking common applications? I figured that I will need to use a certain exploit to get RCE , but for this exploit to work I need the path to a CGI file. I have been fuzzing using a few Seclists, but got no result for the file. I think this is the route and can't see what I am doing wrong or what I should try differently?

errant sleet
#

Hello everyone! Could someone help with module Footprinting / DNS last question

#

"What is the FQDN of the host where the last octet ends with "x.x.x.203"?"

rose crest
#

Going to look into it!

acoustic owl
sand yoke
#

hey

#

can anyone help me

#

which is more severity attack

#

XSS LFI RCE or phising

shrewd bolt
#

Hello, I recently started going through the "Hacking Wordpress" skill assessment; I answered the first seven questions without any problems and found the credentials I need to obtain the RCE but when i try to modify and save the newlt written theme i get the error Unable to communicate back with site to check for fatal errors, so the PHP change was reverted. You will need to upload your PHP file change by some other means, such as by using SFTP.. Is this an inteded feature or am I having problems with my connection to the webapp?
I'm connected with the VPN file using openvpn and I added the right domanins to the /etc/hosts file with 10.129.2.37 blog.inlanefreight.local inlanefreight.local.
Thank you in advance for your help.

rustic sage
#

Good morning. I'm stuck on network enumeration specifically "Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer. " . i have no idea what i should be looking for also I'm kind of confused on what NSE script to run. can someone point me in the correct direction?

dry pumice
#

I'm also looking for this answer (and I try to google it several time)

rustic sage
#

for the network enum?

dry pumice
#

just for the name of the service on port 8080 on two word

#

I know it's stupid but I don't understand what they want

rustic sage
#

dm me. i might be able to point you in the right direction. i did that one yesterday.

#

nevermind I think we might be on different modules. my bad

west canopy
#

@sand yoke i would say RCE is most severe

unique valve
#

Hey awesome people. Today we applied some changes to the Windows 10 target in the Windows Fundamentals module. These changes are in place to work towards solving the RDP connection dropping issue we have been getting feedback on. Ive tested this quite a bit and it seems like the RDP connection is staying connected from Pwnbox and a personal VM, the connection is even a bit more responsive now in my experience. If you have spawned a Windows target in Windows Fundamentals today it may be good to respawn it just to make sure you get the updated target. Feel free to reach out if you are running into any technical or content related issues. Keep learning!

frigid quail
#

Shells & Payloads Where is the Antak webshell located on Pwnbox? Submit the full path. (Format:/path/to/antakwebshell)?

unique valve
green siren
#

Ok ...I feel super dumb, but I'm looking at page 7 of the getting started module, the final question of which has you connect to an SMB share to retrieve a flag. I'm pretty sure I'm doing the SMB connection part right, but it asks for a password, the hint for which indicates that user bob likes to use weak passwords. I've been trying several weak passwords I can think of, but none of which seem to take which makes me wonder if I'm mesing up somewhere else ๐Ÿ™‚

unique valve
#

Lets go to DMs to avoid any spoilers

frigid quail
#

ofc

livid pier
green siren
livid pier
#

I think they should provide it again

green siren
#

on second glance it's super obvious; the shares listing is exactly the same as the one you get in the scan, but the hint actually sends you down a rabbit hole as weak passwords are more things like "admin", "password", "1234"etc, not so much what the actual password is. Maybe the hint should just be "look up" xd

livid pier
#

๐Ÿ˜‚

rustic sage
lethal atlas
rustic sage
#

naw i decided to walk away for a min. ive been at it for the past 1.5 hrs

dry pumice
abstract cradle
#

hi

dry pumice
#

i don't know what I'm missing, it's a basic question

abstract cradle
#

what the server

#

can i learn to hack?

#

hmmm hii

lethal atlas
lethal atlas
dry pumice
#

Basically

lethal atlas
#

what command did you use to scan? did you do a service scan?

gleaming gate
#

someone remind me how to run a php file through curl please

sand yoke
#

u probably right

west canopy
#

remote code execution is generally like a 10/10 in terms of criticality

sand yoke
#

yea

#

i just didnt know what xss is

gleaming gate
#

Can someone help me a bit

#

How can i run a php file with wget

sand yoke
#

no idea

gleaming gate
sand yoke
#

@west canopy can i ask 2 more questions?

#

or just 1

#

which node do you think reports such packets?

west canopy
#

@gleaming gate wget is for downloading files

sand yoke
#

and this packets hint towards attack?

west canopy
#

to run a php file locally i think its: php -f script.php

gleaming gate
#

oh ok

west canopy
#

@gleaming gate not certain but it looks like 194.187.248.62 is trying to access the /etc/passwd file

#

looks like a trigger from a SIEM or something

#

so i would say yes it looks like a possible attack

sand yoke
#

he tagged

#

wrong person

#

he meant me

#

๐Ÿ˜„

gleaming gate
#

o

#

LMAO

west canopy
#

oh my bad, sorry

#

lol

#

yea that was for expell haha

gleaming gate
#

i freaked out for a second lmfao

west canopy
#

Yea you're not under attack jim lol

#

at least i hope not

gleaming gate
#

cool

#

lol

sand yoke
#

ty @west canopy

#

sql injection is related to WAF right?

west canopy
#

i believe so

#

web application firewall should protect against it

#

by sanitizing user input . I could be wrong though

gleaming gate
#

how do i block system() in php

#

i did what the section suggests and it doesnt work

#

:)

#

:):

languid dawn
#

restarted apache as well?

west canopy
#

Anyone give me a nudge on the first question in the "Credential Hunting" section of Windows Privilege Escalation? I've already found three passwords and it's not accepting any of them.

Edit: Disregard, literally just found it!

stiff tiger
#

I am doing the LDAP module and struggling with extremely long responses to clicks on the remote desktop from both the pwnbox and using a vpn with Kali. The delays are making this totally unusable. My internet seems stable and fast enough. Anyone had this problem & know of a way to improve it - are the certain times of the day or just hit or miss?

hollow verge
#

I had a similar issue. Support had be terminate the the target, then the pwmbox, refresh the page, start the target and once it is fully loaded, then start the pwnbox. That fixed the issue for me the majority of the time. Sometimes you may have to repeat the process twice.

Hope this helps ๐Ÿ™‚

stiff tiger
#

Thanks - I tried various resets of pwnbox and target (with wait of 3+ minutes) - I will try your exact sequence. Thanks.

hollow verge
#

Yeah I think the key is on a refreshed page, start the target and when fully loaded then start pwnbox.

west canopy
#

@stiff tiger i experienced technical issues on that module as well

stiff tiger
#

Refreshed page, restarted target, waited 5 minutes, connected with pwnbox => still deadly and frustratingly slow ๐Ÿ˜ฆ

slow bluff
#

windows priv esc module > weak perm section > i cant access the administrators folder after being member of administrators group any one can explain why thanks ! solved

hollow verge
#

@stiff tiger send a msg to support

raw steeple
#

@stiff tiger When I have connectivity issues, I refresh the target ip (sometimes twice) then it works fine.

stiff tiger
#

Thanks - I will message tech support and try refreshes and reboots.

devout cliff
#

can anyone help me on the Cracking Passwords with Hashcat module? Im stuck on the second section where it asks for you to make a XOR ciphertext via python3. In the section it shows using python 3 to do this but when i mimic the method it errors out: >>> xor ("opens3same", "academy")
Traceback (most recent call last):
File "<stdin>", line 1, in <module>
NameError: name 'xor' is not defined

#

i have very very little experience with python3 so im kinda lost how to fix this. im guessing its something easy

livid pier
#

Can anyone help with any of these?

livid pier
west canopy
#

@livid pier I haven't attempted any of those modules dawg ๐Ÿ˜ฆ

livid pier
#

Then I am free to be a noob on the machines

devout cliff
rustic sage
#

Hello

#

Can anyone help me

#

My second discord account got hacked

#

It says something is going worng over here

#

I logged out and then logged in clicked on forgot password

#

And changed the password

#

Still I can't login

#

@livid pier @devout cliff sorry for pinging

#

I can chat only in this text channel

#

@mystic shoal sir can you please help me out I'm worried I had many old friends in my account

#

I thought people here must be knowing how to recover accounts can someone pls help me I would be grateful

livid pier
livid pier
rustic sage
#

Bro can you help me out in recovering my account

livid pier
#

I have no idea how to do that

rustic sage
#

Ok np

livid pier
#

I can recommend not to click on links

rustic sage
#

Oh

west canopy
#

Sage advice ๐Ÿ™‚

rustic sage
#

I wish I could recover my account

#

Wait lemme try logging in again

rustic sage
#

It didn't work

sudden shard
#

what is a root flag

#

@urban sage

urban sage
#

The contents of root.txt. Usually on the Administrator Desktop on Windows or /root on Linux.

sudden shard
urban sage
#

C:\Users\Administrator\Desktop

sudden shard
#

@urban sage

urban sage
#

Where is this from?

sudden shard
urban sage
#

Right but on what machine?

sudden shard
#

Windows?

urban sage
#

Windows is an OS. Is this your machine? The flag isn't there. It's on target boxes.

sudden shard
#

what do you mean?

#

Where can i get the root flag at?

#

I can't open the place you told me to open

urban sage
sudden shard
#

What box?

#

This laggy thing?

livid pier
urban sage
sudden shard
#

Then where do I run C:\Users\Administrator\Desktop

#

Do you mean run the thing on here?

urban sage
#

Yes. On a target box. You need to gain access and escalate privilege's first.

sudden shard
#

How do i connect to it?

#

The guide doesnt help

urban sage
#

The walkthrough definitely helps. Read it.

livid pier
#

Nightwolf can you run the :rainbowwizard:

sudden shard
#

Mk

livid pier
#

?

sudden shard
#

@urban sageThis is all linux things

#

I can't install openvpn or whatever it is, I can't install linux because of that stupid errro

livid pier
sudden shard
urban sage
sudden shard
#

Pwnbox is laggy af.

#

Every action I do is delayed for about 10 seconds

livid pier
sudden shard
#

How am I supposed to learn to hack and things?

urban sage
#

You can try picking a closer server for pwnbox. Based on the screenshot you sent in #583613644294717453 you picked US.

How am I supposed to learn to hack and things?
Again, you will problem need to setup your own system.

urban sage
#

That's just networking at this point then. Not a whole lot else I can suggest I haven't already. ยฏ_(ใƒ„)_/ยฏ

unique wharf
#

I am having issue with the Module: Shell&Payloads -> Reverse shell: The PS shell code is giving me errors after I run the PS cmdlet to disable the AV. I am not that great with PS syntax, and would like to make sure I am not missing anything. Any help would be appreciated.

urban sage
#

Generally, helps to post the error.

unique wharf
#

is there any particluar way to post the issue? Text, screenshot, what is recommended way?

rustic sage
#

A screenshot with the command & what's going on exactly on the screen I believe

runic rampart
#

Good day! Could you give a "Server-Side Attacks - Skills Assessment" hint. The only thing I found interesting is <"'converts HTML.

vital horizon
#

@woeful oxide did you get the firewall evasion medium and hard?

devout cliff
nova topaz
#

Hello everyone
I am in the Linux Fundamentals in System information, but I am stack

#

I cannot find the paths for htb-students mail, or home directory

#

I have tried it with env command, by checking the directories with ls, and ls -al

#

if you have any hint I will appreciate it

rustic sage
nova topaz
#

I found 2 paths
/var/spool/mail
and
/var/mail

#

none of the 2 were accepted

rustic sage
#

^

nova topaz
#

I didnt check for directories specifically

#

but with ls -al there were 3 entities inside, files or dirs

#

but If they were dirs, I wrote them incorrectly

#

Ok, at least I am looking to the right place. Thanks!

rustic sage
#

It asks for a specific user in the question, so look for a sub directory that could have the same "name"

#

as your user

rustic sage
#

can't say more than that ๐Ÿ˜„

nova topaz
rustic sage
#

The first character of each line indicates what it is. d = directory

nova topaz
rustic sage
#

Don't overthink, iti's very very straightforward

#

Just look carefully into each directory you found

#

and you'll be good

dry pumice
lime raft
#

Hi, I don't know if I'm asking in the right place, hope you can point me in the right direction if not: I'm going through the linux fundamentals course in htb academy and have realized that all of a sudden introducing sudo plus something requests a password from the default user which I don't have. (it didn't before, not sure what I've done to trigger this behaviour change). How do you guys solve this, or how do you reset the machine (or connect to another one)?

hushed osprey
#

@lime raft - password is in text file on your desktop in pawnbox

lime raft
alpine summit
#

Hi all, someone to help me on LOGIN BRUTE FORCING Assessment Service, I don't understand at all how to pass it.

grand locust
#

yo jared. I'm stuck on flag4 at the moment. I have the tomcat credential. Not sure how to proceed

west canopy
#

@grand locust check DM's brother

alpine summit
# livid pier Hey what dont yo yet?

I created a list of usernames for Harry Potter. I created a list with cupp with his first name the fleet and the symbols at the end of the word

livid pier
#

If anyone could give adive/help on any of these modules it would be apperciated

main vapor
acoustic owl
dusk terrace
#

Hello everyone, is there a way to debug answers to module's questions?
I'm on taking the Web Requests module and am on the GET Method part of it. I'm unable to figure out what is wrong with my answer. I tested my answer on the parrot terminal in my workstation and it worked there.

untold kiln
dusk terrace
dusk terrace
# untold kiln what url are you using ?

I tried a bunch of combinations, right now i'm using
curl -u admin:password 'http://159.65.53.42:30584/flag.php?num1=1330&num2=7' after checking out the cheat sheet.

untold kiln
dusk terrace
#

No luck there.

Edit: Tox helped me figure it out, i thought i had to type in the bash command into the answer box. Typed in the flag and the world spins once more. lol

acoustic owl
#

Is there anyone who can help me with the SQL Injection Fundamentals module?
I am a little confused. I can bypass the login, but only as admin and not as tom.

wild delta
#

Thanks for the nudge in the right direction - didn't understand what the question was asking...

short birch
acoustic owl
acoustic owl
#

But then I am logged in as admin. Not as tom. Why?

untold kiln
acoustic owl
#

Can I send you a printscreen via DM? I do not want to spoil here

rustic sage
acoustic owl
rustic sage
#

You can still login, because 1=1 is TRUE, so you end up with TRUE OR FALSE which is TRUE, but not as a user, rather as admin because it did not fetch any username

acoustic owl
#

Okay, let me get this straight. Tom does not exist in the database. That's why my SQL statement returns false.

rustic sage
#

Username AND password OR 1=1 is in your case TRUE AND FALSE OR TRUE which equals to FALSE OR TRUE which is TRUE

rustic sage
#

Exist

#

But Tom AND pw returns false. Because there is no Tom with the password pw

#

@acoustic owl You can DM me, as I am afraid I am spoiling here

acoustic owl
#

Yes, now I understand. A logic error in my SQL statement. The password returns false before I can query 1 = 1.
So I have to end the statement before I get to the password query.

#

I found the error. Thanks to you and ToxDK for your help.

rustic sage
stray rivet
#

Hey People i could need some help. Iยดm stuck in the Module File Inclusion / Directory Traversal on the last chapter skill assesment. i already found the admin panel and since the server uses nginx i guess i have to some how Poisin the Log files but i tried every Path i found(/var/log/nginx/access.log; /var/log/nginx/error.log) but it doesent seem to work. Do you have any hints for me by any chance๐Ÿ˜… ๐Ÿ™

unique wharf
#

Aloha, needing some help: Module: Shells & payloads/Reverse Shells - I am unsure of the syntax issue I am having with the reverse shell on the target box. I have set the IP in the shell code to my machine. any help would be appreciated

west canopy
#

@unique wharf try putting that command into windows CMD rather than powershell

olive canopy
#

Hello please need help: What is the name of the first section of this module?

west canopy
#

Can anyone give me a nudge on Windows Privilege Escalation "Miscellaneous Techniques?" For the life of me I can't figure out what I need to do. I found a creds.txt on a file share, but I need to escalate privileges to access it, and none of the techniques in the section are working.

livid pier
#

How do we know what 'this module' is?

olive canopy
#

Have tried all possibilities I know, like "Sections" "Interactive" "introduction to academy" unfortnlly does't work

livid pier
#

Where are you? what module?

#

It doesnt matter, whichever module you are in scroll to the top and look to the right, under the table of contents you will see the sections

olive canopy
#

Okay thank you

livid pier
unique wharf
olive canopy
#

"Interactive Section" is what am seeing on the top by right. Not working

livid pier
#

do you know what module you are in?

rustic sage
#

Focus on your question :)

livid pier
#

Bruh

#

You got this

#

Additionally when you ask for help please let us know what module you are on

#

in this case you are doing introduction to academy

olive canopy
livid pier
#

That is the module, not the sections

#

think of a book, that would be the title

#

you are looking for the chapter, the first chapter

#

also called the section

olive canopy
# livid pier

yes thatt is the section, but not working "Interactive Section"

livid pier
#

interactive section is the 3rd section

#

"sections" is the second section

#

what is the first section?

olive canopy
#

Yes Introduction

rustic sage
olive canopy
#

Thank you

#

Answ: Introduction

devout cliff
livid pier
#

I thought it said from pwn import xor, that would mean the libary is call pwn

devout cliff
#

i found it. it was pwntools

#

mfw

livid pier
#

oh nice

devout cliff
#

i just wish the module talked about that step

#

since it has a question requiring you to do that

#

and neither the HTB academy box or parrot has that library as part of their builds

#

but i got it ๐Ÿ˜›

torpid latch
#

Excuse me

devout cliff
#

the module has 0 pointers as to how to fix that also

torpid latch
#

I an very new here

#

And I need help

livid pier
livid pier
torpid latch
#

So

#

Uhm

#

I am very confused here

livid pier
torpid latch
#

And I barely know what anyone is talking about

devout cliff
livid pier
#

in the credientals file

devout cliff
#

nani

livid pier
devout cliff
#

mfw i couldve installed the universe. alright thanks.

torpid latch
#

And one thing

#

What is this place

#

I got a invite from a friend

livid pier
#

This is the matrix

torpid latch
#

๐Ÿ˜ฑ

livid pier
#

This is the acadmey channel for HTB

torpid latch
#

What is HTB

livid pier
#

HAck the Box

torpid latch
#

Ok

livid pier
torpid latch
#

This HTB place is too complicated for me

#

I'm leaving

livid pier
#

Ok

wise nimbus
swift carbon
#

is there a roadmap somewhere for when the "coming soon" modules will be released?

feral gyro
#

still need help

raw steeple
#

Quick question: when you gain shell access, can the user see what you are doing on the exploited side.

west canopy
#

if they were to run netstat, they might see an active connection on whatever port you used for your shell

raw steeple
#

@west canopy great, thanks

steel flume
#

anytips what one can do with a bin/bash ?

west canopy
#

Not sure what you mean. That's just the binary for a bash shell. I suppose in the privilege escalation sense, if you're logged in as a user that has sudo rights to run anything, you could do sudo /bin/bash and get a root shell.

#

Or if you're connected via a shell without TTY functions you could use python to invoke a bash shell , to improve functionality

feral gyro
feral gyro
#

i need some alternatives for deobfuscating javascript

livid pier
#

whats wrong with it?

feral gyro
#

is it working

#

it's not loading for me

livid pier
feral gyro
#

ok i will check with some vpn

feral gyro
# livid pier

it's working now on chrome but on firefox it's still buffering

#

don't know why

novel matrix
#

disable any extensions you have running

unreal bear
#

anyone help me with Skills Assessment server side attacks

soft grotto
#

I've been reading though several threads on this and I'm still having trouble.

When I run a whatweb or nmap scan, neither of them return a CMS. I know I'm missing something...is this syntax correct?

whatweb -a 3 <ip>/<vHost> -v?

Appreciate any help.

livid pier
soft grotto
#

How are we directing that IP to the vHost? Are we doing that via the /etc/hosts file?

livid pier
soft grotto
#

Yeah, sorry...

This is Information Gathering - web edition.
Section: Active Infrastructure Enumeration
Question: (2nd question) Which CMS is used on app.inlanefreight.local? (format: word)

livid pier
#

Thank you let me run it real quick

soft grotto
#

i appreciate the help!

soft grotto
jaunty kindle
#

Hey, if I unlock a module (tier 4) do I keep the module access forever even if i dont have a subscription or do I need to maintain an active subscription for this tier?

rich heron
#

Need some help with the OSINT: Corporate Recon module. I'm 99.9% sure my answer is correct but somehow it won't accept it.

jaunty kindle
livid pier
#

Anyone around to lend some guidance on broken authenitcation or command injections?

shadow verge
#

I'm doing broken authentication weak bruteforce protections, but can't think of anymore wordlists i have tried all seclists wordlists with username,password combination.. what should i try next?

autumn elk
#

For your fail string why did you use โ€œF=<button class=โ€˜btn block-cube block-cub-hoverโ€ ? My string looks different and I still canโ€™t crack it.

shadow verge
#

question 2

feral gyro
shadow verge
#

yes this one

feral gyro
#

try to understand the section carefully

#

it's not about bruteforcing it's bypassing

shadow verge
#

can i dm?

feral gyro
#

ok

paper crag
#

Anyone completed the Broken Authentication Skills Assessment? Tried lots of things but I've hit a wall...

shadow verge
#

Thanks @feral gyro I got it now :3

devout cliff
devout cliff
#

yeah i completed the module

#

i just dont remember if i ended up using that string or changing it

#

which section was it?

#

oh the skills assessment right

autumn elk
devout cliff
#

what string are you using

autumn elk
#

I did everything your doing but at the end I did F:<form= โ€œlog-inโ€

#

I did that because when you inspect the page thatโ€™s the html code

devout cliff
#

right, so you are using that as your pass/fail indicator

#

i think there was something else i changed

autumn elk
#

Yeah

devout cliff
#

i would double check your parameters

#

just in case there is misspelling or a different spelling. or try a different string.

autumn elk
#

When I get back home Iโ€™ll send what I have

vivid onyx
#

Friends i need help with working with web services section in Linux fundamentals module

#

Someone help me pls

devout cliff
#

fyi my string did not work, LOL

autumn elk
# devout cliff fyi my string did not work, LOL

hydra -l ******* -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt -f 138.68.182.108 -s 31844 http-post-form "/admin_login.php:user=^USER^&pass=^PASS^:F=<form name='log-in'"

#

I essentially did something like this

#

Iโ€™m not driving anymore but thatโ€™s what it was

mild grove
#

Hello does anybody work on XXE ? I mean using CDATA or Error Based XXE because none of this examples work

blissful verge
#

Hi all, quick announcement. We've gone and made some fixes in our labs. These fixes will affect Windows Fundamentals AD LDAP AD PowerView and AD BloodHound module boxes that require RDP + using tools like AD Users and Computers. If anyone was having trouble with disconnects or general slowness in any of those modules can you please check and see if things are improved? If issues still persist for in just those 4 modules please DM me . Also if you notice a marked improvement It would be good to know so you can DM me as well. We are constantly striving to put out top quality module content and make our lab experience as good as possible so thank you all for your continued feedback and support!

livid pier
#

Hey Guys I remember doing a module that in the first couple sections had a tool that went through an nmap output and organized and ranked the attack vectors, I cant find what module it was in, anyone remember>

#

Nvm I found it. attacking common applications, eyewitness

runic rampart
vivid onyx
#

Friends i need help
Doing working with web services section in Linux fundamentals module
Didn't know answers for those two questions
How to start a http server using php and npm

lament rampart
#

For PHP, it's ||php -S 0.0.0.0:8000||

livid pier
vivid onyx
#

Thanks guys I will let you guys know after checking tomorrow

rustic sage
#

riotusss

vivid onyx
#

It's 12.45am here
Time to sleep

#

Yes bro

#

?

rustic sage
#

nothing man have a good sleep

vivid onyx
#

Mm

livid pier
#

!flag sus @sterile hawk @languid dawn

languid dawn
fair ginkgo
#

Hello

#

Can someone help me?

livid pier
lone comet
#

Hey i stuck in the smtp section within the footprinting section:
Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.
Can sb tell me where i can find the right wordlist on the htb client?

rustic sage
#

hey

#

in the windows fundamental module at the Windows Security section when i spawn a target i dont get bob.smith user

#

to find his SID

stiff tiger
acoustic owl
lone comet
acoustic owl
muted kite
#

You know what, there is almost no free stuff on tryhackme

livid pier
muted kite
#

well I never left, I started doing free stuff and didnt get far before it said that the next step is for paid members

livid pier
#

I heard the same thing tho, someone here was like Im gonna go try THM and a week later they said the free content is quite limited

muted kite
#

It's super limited

#

you get more free learning here

livid pier
#

Did you feel like you had a good grasp of what they wanted you to do there?

#

AKA you feel like the lessons here are working?

lone comet
#

mtp-user-enum -M VRFY -U footprinting-wordlist.txt -t 10.129.174.188 -w 10
Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )


Scan Information

Mode ..................... VRFY
Worker Processes ......... 5
Usernames file ........... footprinting-wordlist.txt
Target count ............. 1
Username count ........... 101
Target TCP port .......... 25
Query timeout ............ 10 secs
Target domain ............

######## Scan started at Fri Feb 4 21:09:13 2022 #########
######## Scan completed at Fri Feb 4 21:12:27 2022 #########
0 results.
quite not sure where i might have the error, no results though :/

muted kite
#

Its far easier over there

#

THM is easy compared to HTB

livid pier
#

Thats what I like to hear. When I was trying to figure out where to train thats what I heard

#

HTB is where the professionals practice

#

Its been hard in the beginning I think it will make for a better end tho

lone comet
#

yeah i got the answer but only through stupid testing 1 by 1 in the list. The smtp-user-enum ouput showed nothing :/

#

maybe i got the wrong syntax?

livid pier
#

I noticed in what you showed us the target domain was empty

#

I dont know if that was it

lone comet
#

yeah i see, ok, i try it with inlanefreight.htb

livid pier
#

But if you got it all is well that ends well

lone comet
#

thanks a lot mate, i will try and tell you then

livid pier
#

I would think that if that was the problem the program wouldnt even run, so idk

unique valve
lone comet
ruby sapphire
#

Need some help with academy module 'Hacking Wordpress' -- send me a DM if you can lend a hang

crimson crown
#

For the NTFS vs. Share Permissions on Windows Fundamentals

#

Has anyone had to install cifs-utils?

west canopy
#

@crimson crown i went through it again on the pwnbox a few days ago , i believe i installed cifs-utils but i still couldn't mount the drive like in the example. I didn't look into it too much though because it wasn't necessary to complete the section

crimson crown
#

gotcha

#

i tried to install the cifs-utils but don't remember the root password

west canopy
#

are you on pwnbox?

crimson crown
#

yeah

west canopy
#

there should be a document on the Desktop with the user's password

#

for when you need to sudo or switch to root

crimson crown
#

got it

#

thanks

#

i keep inputting the full path

#

but it's not working

livid pier
#

wizard Good evening HTB fam

devout pelican
#

Windows Privilege escalation - Skills assestments 1

Could someone give me a little hint with searching the password of the ldapadmin please?
I've tried all of the techniques of the module. But did not find it.
Thx ๐Ÿ™‚

west canopy
#

@devout pelican i am stuck on this too

unique valve
#

Theres a really helpful tool that looks like its named after an Italian dish that might help. @devout pelican @west canopy

#

At least thats what I think of everytime I use the tool. Feel free to DM me for further assistance as well.

west canopy
#

thanks bud ๐Ÿ™‚

#

much appreciated

dusty atlas
#

Hello, I'm currently trying to work through the linux fundementals, and whenever I attempt to start ssh it prompts for authentication, but when I enter in my password or the HTB_@cademy_stdnt! password I keep getting authentication failed. I'm not sure if I missed something before.

#

I feel dumb, it was on the desktop

hexed tartan
#

is the pwnbox vnc down rn?

rustic sage
#

hey, i'm currently stuck at the windows fundamental module Windows Security section i cant get the answer to the two question for the first one i dont know how to get the sid of bob.smith as i cant do whoami bob.smith

#

and the second one i will try to do it right now i think its like the previous questions

unique valve
hexed tartan
#

im stuck on 'common applications' on section 'attacking drupal' I want to run the druppalgeddon3 exploit but it's not available in metasploit and I dont know how to add it, please help if someone knows this

unique valve
dull bear
#

Hi guys, doing the windows privilege escalation module right now

#

There's this module on SeDebugPrivilege

#

but when I RDP to the user as it says on the lab

#

I'm unable to see that SeDebugPrivilege granted to this user

#

Can anyone support?

#

more context:-

unique valve
muted kite
#

This is why I don't like THM

#

they give you partial free, but you have to pay to complete the module

#

real cheap shot

slow bluff
#

Hi Windows privilege escalation > Find the password for the ldapadmin account somewhere on the system > tried lazagne but not giving anything back any hint pls

lament hollow
#

Anyone on that's completed the Footprinting module? This second SMTP question has me. I've found a couple different ways to automate the enumeration of the users but I'm not sure based on the hint if there's a txt file I'm missing or if I'm just supposed to be throwing one of the giant SecLists at it and waiting ages for it to grind through.

#

Oh god, nevermind I found the resources section after way too long

copper trail
#

/stuck on Intro to Python: The type of foo from question 1 is <class 'set'>. What is the type of x_coordinate?

copper trail
#

yes still stuck though

rustic sage
#

Focus on the example answer given in the question to get the right syntax @copper trail

livid pier
#

Good evening!

lament hollow
#

Evenin'

upper vault
#

Ohai

livid pier
#

I want to make a meta-module. It would help people understand the exploit and modules from a birds eyeview.

#

Sometimes when I do a box I know I have a bunch of tools but it has been taking me a while to realize what to use where

#

It would also be nice to have a search bar in "modules I own". There has been times that I go to a box, know its using wordpress, go to look at a module that references wp, but 3 different module do so.

unique wharf
#

Evening guys, wanted to see if anyone else has connection issues when using the 'NoMachine' platform outside of pwnbox? I am working on shell & payloads Live Engagement, and I can't seem to keep a stable connection.
Update
NoMachine doesn't like being run in root. problem solved.

west canopy
#

@unique wharf interesting. I did that module a while back and didn't have any problems using nomachine, but i've heard other people report having issues as well

unique wharf
#

As per my update, I think its because of it being run in root...so far as non root, I am not having any issues.

stiff stream
#

*Struggling at broken authentication - trying to generate the predictable reset token, can anyone help me with this? ๐Ÿ™‚*~~ Solved

twilit jolt
#

Hey
Quick question about one of the boxes I wanna hack
Am I in the right place??
Seems like I can't write anything on this server other than the module page

stiff stream
#

@twilit jolt Which module are you trying to do?

brave quail
#

Hi, I am working on the web-request module. For some reason, I can't connect to the webserver (anymore). I assume apache2 is running, but I only get 405 "Method not allowed" messages

#

It should be as simple as opening a website using the local IP-address right?

brave quail
#

The strange thing is: I get the server"WebSockify Python" as server, instead of the expected apache

tidal compass
#

Good morning everyone. I'm working on the sql injection fundamentals module. No matter what I do I still get the error "ERROR 2002 (HY000): Can't connect to MySQL server on '178.62.43.64' (115)" . It will work once, and I'll connect, then I move onto the next tab in the module and I get the same error. Anything anyone can help me with? I'm using the command: mysql -u root -h 178.62.43.64 -P 30434 -p then entering the password. This is driving me nuts.

civic wraith
#

hi

#

im doing linux escalation module

#

and is not possible from the target

#

in fact is not possible any wget in any site

#

i think maybe the target box can connect outside HTB network

#

*can't connect

true geyser
#

hello

feral gyro
lethal atlas
minor dust
#

christrc

rustic sage
#

hey

#

i'm in web request seconde section and i dont get http server response

#

ok when i go to history i got them

true geyser
#

Hello I'm a new user in this platform

lethal atlas
true geyser
#

@lethal atlas thanks

unique wharf
#

@true geyser welcome

true geyser
#

@unique wharf thanks Dear ๐Ÿ˜˜

unique wharf
#

@true geyser not sure if you're doing a European thing but I'm a dude, dude.

true geyser
#

@unique wharf I'm from Pakistan but I'm a dude, dude

final basin
echo lynx
#

Hello I am new to this group!

meager sequoia
#

Hello, I am new too

#

as you can see my role is noob ๐Ÿ˜‚, indeed I have some problem with the module of introduction

#

In the section "Interactive section with Terminal", I put the version of the kernel but it says that the answer is wrong

#

someone can help me?

#

i found the correct answer but i don't understand why it is correct

acoustic owl
meager sequoia
#

i tried to put all word of the command line's output in the questions ๐Ÿ˜‚

acoustic owl
meager sequoia
#

but why i can't put the version with all the numbers?

#

why the answer is only that word and it isn't the the word with the numbers?

acoustic owl
#

in which module and which question are you exactly?

meager sequoia
#

in this module

acoustic owl
#

Because the question refers to the operating system and not to the Linux kernel.

unique wharf
#

Gotta say "thank you to HTB for the Academy" !

unique wharf
#

Shells & payloads is a really good module, i'm on to the next one.

patent blaze
#

Is there anyone that could actually give a nudge regarding USING WEB PROXIES modulo ? I'm on the ZAP Fuzzer lesson

red obsidianBOT
#

There is no flag here. Get back to hacking!

whole cosmos
#

Hey all - just finished the nmap module and have a question regarding ACK scans. The module explains that ACKs are usually ignored by firewalls because the firewall can't determine whether the connection was established from the external or internal network. I can't see why it couldn't just track all incoming packets and hold state regarding existing connections. An ACK preceding a SYN would then be an indicator of port scanning, no? Is it just the case that doing so would be infeasible?

worthy coral
whole cosmos
patent blaze
#

Can I dm you ?

lethal atlas
cunning wraith
#

hey guys i'm new here but i've been trying to get into exploit dev or pen testing any advice or cert, languages, etc I should focus on from you guys experience.

west canopy
#

@cunning wraith what modules have you done so far on academy? If you're interested in exploit development they have modules on assembly language and stack buffer overflows

hollow hinge
#

helloo

#

i had joined a module LFI

#

i got the flag via LFI

#

what kind of flag is this

#

when i try to submit this as a flag

#

it shows incorrect to me

#

@livid pier are you here?

untold kiln
low girder
#

Please don't post the flag

hollow hinge
#

damn thanks a lot dude

#

it worked

untold kiln
hollow hinge
#

bro i had one more question

#

how LFI could lead to RFI

#

*RCE

#

not RFI*

untold kiln
surreal gate
#

hi, I'm on the System Information Module, last two questions. I've used uname -v and ifconfig -a but, none of the outputs are being accepted as answers

surreal gate
#

Sorry, Linux Fundamentals > System Information

#

I can see the kernel version and the three i/fs but, it comes back incorrect. Not sure what I'm doing wrong

languid dawn
#

Ifconfig? Isn't that deprecated and it should be ip address

#

What's the question?

desert bramble
#

Hi, Im still new to this and was wondering if anyone could help with out with the machine driver, I know that I need to ||upload something into the website|| but I'm not sure what and how. Thanks

rustic sage
desert bramble
#

Its not, its a machine, not in the starting point section

#

I think

languid dawn
#

Ah then boxes

desert bramble
#

ok, thanks

languid dawn
#

My bad I thought driver was starting point

desert bramble
#

all g

surreal gate
#

uname -a isn't what I need here, though. Surely -v is what will give me the kernel version?

surreal gate
#

That's the release, isn't it? The q specifically asks for the kernel version. Confused

rustic sage
#

@surreal gate The question is a bit misleading. But follow the example format.

#

You won't get anything like x.x.x with -v

surreal gate
#

still incorrect when I use the output for -r

rustic sage
#

@surreal gate DM me your answer.

#

@surreal gate 1. You need to SSH into the target. They are asking for the version of the target, not of your pwnbox.
2. Follow the format (X.X.X)

surreal gate
#

Now I feel like a fool. Thanks!

dull robin
#

Don't feel bad. In my case, I'm going through the Getting Started module kinda slowly. There's a lot of content to chew through when going through an Academy module. And in my case, I got stuck on the "Share" question halfway through Getting Started.

I was stuck for over an hour, and all I had missed was the password to the user I was trying to log in as. The text had told me the password in the middle of the paragraphs, and my dumb dupa glossed right over it, and tried hacking the spawned instance at the end looking for a hidden password. xD

honest flower
#

Hi guys! I have a question about the last skills assessment of the module file inclusion/directory traversal:
SPOILER ALERT
Is there someone that can explain me why reading the source of index.php from the browser with ctrl-u and reading the source of index.php with php wrapper give me one more line in the output that help me to solve the question?

#

Shouldn't index.php have the same output also if readed with two different methods?

hasty iris
#

Hey guys I'm doing Web Attacks Module and I am on the Advanced File Disclosure section. I am trying to reproduce the results they did in the example in that section and I am unable to do so. Has anybody had this problem yet? I copied the example and still having a hard time getting the same output they did. Let alone not finding the flag.php yet. Any help would be appreciated. Thanks. The image actually cuts out the <email>&joined</email> part.

rustic sage
#

how do i start hacking?

#

:)

rustic sage
languid dawn
languid dawn
honest flower
#

@feral gyro I don't understand. On the server inside the main directory (/var/www/html) there is a file called index.php. Why if i read it using the source code function of the browser (ctrl+u) the output appears different than that if i use the php wrapper?

#

At the end the file that i'm reading is the same, right?

feral gyro
#

no

#

send me the file u got when php wrapper is used

honest flower
#

Ok... In a while.. i'm far from my laptop now. I'm using my phone...Thanks

feral gyro
#

read the section source code disclosure via php wrappers

#

that will be so helpful to solve the task

hasty iris
dry pumice
#

Hi ! I'm on the nibbles walkthrough from Getting Started module and I'm stuck on getting the reverse shell.

#

I use the script as said, and replace with the good ip but the website did not connect to the port as expected

livid pier
#

Any nudges for broken authentication final?

hollow hearth
#

good afternoon colleagues, I have a query, I am in the NTA module and in this section it tells us to install NOMACHINE, first check if the pwnbox I use has the tool but I couldn't find it, I couldn't install it either, any suggestions you can give me?

main vapor
#

@hollow hearth

#

its already installed on Pwnbox

alpine dirge
#

Does this not work on windows

hollow hearth
west canopy
#

Anyone able to give me a nudge on the final question in Windows Privilege Escalation skills assessment part two? Looking for the NTLM hash of a disabled user.

Edit: Just solved it! If anyone needs help on this module please hit me up ๐Ÿ™‚

cunning wraith
west canopy
#

Get a membership or buy "cubes" to purchase the modules. Then complete them using either the browser based Pwnbox workstation , or download the VPN to use your own machine or VM.

livid pier
upper vault
#

anyone here have any good resources on how multiple processes are stored in memory? Every source I find shows how memory is divided for a single process, or between threads of a process, but the image in my mind is that different elfs sit next to eachother in memory space, while their relevant stacks and heaps also sit next to eachother in their relative areas of memory. Or is it that say (out of 16gb) 0-2gb is for process A, 2-6 for process B, etc, so that the code section of one process picks up at the end of another process's stack space?

#

actually the more i think about it, the latter cant be right. After examining addresses in a small program, the stack is always in a super high-number location, and the code/data segment in a low one. Just amazes me that you can expand heap size, or stack sizes without smushing into something else all the time, but I guess that does happen when you max out your RAM usage, I crash all the time b/c of too many tabs open in firefox

quaint marsh
#

How did you download? post request? using jquery?

quaint marsh
sterile hawk
sterile hawk
#

All the addresses you see are virtual addresses. All programs can have exactly the same set of virtual addresses, yet they'll contain completely different data. The OS uses a series of tables to map these virtual addresses to physical addresses, which are the actual offset of the data in RAM

#

This is how the OS is able to give you petabytes of memory space to allocate within, even if you only have 8GB of RAM

upper vault
#

So that means virtual memory addressing is always used? And that physical addressing takes place in the kernel i suppose?

sterile hawk
#

The mapping is done by the CPUs MMU for the most part, but the OS sets up the data structures

#

For the most part, kernel pointers are virtual addresses

sterile hawk
#

And there's a large chunk between user memory and kernel memory addresses which is 'non canonical' and cannot ever be a valid address

#

The first 14 or so bits must either be all 1 or all 0 iirc