#modules

1 messages · Page 513 of 1

tulip jetty
#

exist a difference?

rustic sage
#

yeah ... thanks it seems like I can read ....

#

my question was, what exactly would a component be in the scheme ? is one server serving the front-end and passing the requests to another server that's running the back-end etc .... ?

acoustic owl
#

And you want to open the page in the browser in the pwn box?
You may have to specify http:// before the IP.
Like this: http://10.10.10.10:1234

rustic sage
#

or would all 3 servers do it all, front and back, key signing and such things ? If yes, the question would be what's the added value of having these, strictly speaking about security and not redundancy

balmy creek
#

Hi guys i have a little problem, web request module>HTTP methods>PUT &DELETE just i can't connect with curl, it show me "(7) failed to connect to 64.227.39.88 port 31175: connection refused"

balmy creek
#

I use $curl http://ip:port/api.php/city/london

livid pier
hazy grotto
#

Did you get the answer? im trying to figure this out

tulip jetty
tulip jetty
balmy creek
acoustic owl
rustic sage
rustic sage
acoustic owl
livid pier
#

component is a word, this word is a noun. See the thing is, everything has a thing, this thing can be this, or that

#

Its all nouns or verbs

#

sometimes adjectives

#

The thing or the process. But underlying each thing is a set of processes and you cant have a process without the things that make up process

#

Its pretty simple really

ashen swift
#

question about the Introduction to Academy - On the interactive section with target, I spawn the target but can not connect to http://<ip>:<port> in a web browser from the workstation. I have refreshed the target but each ip/port combo gets a connection refused, any idea what I could be missing?

balmy creek
ashen swift
rustic sage
#

They are experiencing an outage. Was told so by the HTB support team.

#

Update: I just managed to connect to a Docker target.

hazy grotto
#

remark: InFreight SMB v3.1
path: C:\home\sambauser
password:
type: 0x0
perms: 0
max_uses: -1
num_uses: 1

#

I am having an issue in Footprinting. SMB. Last question: What is the full system path of that specific share?

#

I believe it's asking for the InFreight SMB share full system path. Ive spent hours on this questions and ive tried everything? Why isn't the path above i posted the right answer?

acoustic owl
#

Take a look at the hint:
„Remember that Linux-based operating systems do not have a "C:" drive.“

rustic sage
#

Guys i tried a little bit but i can’t find my first lesson, i have some logic but that’s it. How can i start, any tips?

lethal atlas
rustic sage
#

Actually I’m still new no one yet, but the question is how what should i do as a first step

lethal atlas
#

sign up with academy and start with the tier 0 getting started

slow venture
#

Hey, is there anyone who can help me with Academy - linux priv esc - miscellaneous module?

west canopy
#

@slow venture sent you a DM bud 🙂

hazy grotto
summer pecan
#

Hello all, I'm trying to figure out what's going wrong on the first exercise with ffuf. I'm 95% sure i'm using the right wordlist based on the hint

#

did anyone else run into an issue on this?

feral gyro
summer pecan
#

Directory Fuzzing, this seems silly. I would think I'm using the right word list

modest moth
#

am i going crazy or is the Parameter Fuzzing - GET room in the attacking web application with ffuf module not working? i added the ip to /etc/hosts

#

it i cant reach the subdomains found with ffuf

#

like, when i run the ffuf command, it returns 200. when i try to go to the page in a web browser it says "we cant contact to the server (FQDN)"

modest moth
#

i think im doing every thing correctly. i can dm to keep spoiler free

cedar elbow
#

hi can someone help with joining this academy

livid pier
cedar elbow
livid pier
rustic sage
#

im doing the web request module. what is the domain im supposed to input in the /etc/hosts/ ?

rustic sage
#

curl

#

the first section

feral gyro
rustic sage
#

yea

feral gyro
#

this one

rustic sage
#

yes

feral gyro
#

u don't need to enter anything on /etc/hosts

#

just use curl url

rustic sage
#

ahh ok

#

thank you for the help

acoustic owl
acoustic owl
hazy grotto
hazy grotto
#

i got it to work

deft parrot
#

hello everyone can anyone help me with this

#

im not getting this part

dapper flare
wary saffron
#

can anyone help me with the last question for the DNS aspect of the footprinting module?

#

so far ive done a zone transfer on the internal.inlinefreight.htb domain

#

just need the last host FQDN with the 203 end octet

acoustic owl
#

You have to find all zones

Note that you can configure DNS servers to allow zone transfer only to certain servers.

acoustic owl
wary saffron
#

Footprinting

#

What is the FQDN of the host where the last octet ends with "x.x.x.203"?

#

i cant find .203 subdomain anywhere ive tried using dnsenum with various wordlists

#

dnsenum --dnsserver 10.129.42.195 --enum -p 0 -s 0 -o subdomains.txt -f /home/michael/SecLists/Discovery/DNS/subdomains-top1million-110000.txt inlanefreight.htb

#

i tried this command

rustic sage
#

Hi, can somebody give me a hint on the last section with finding the upload folderin the file upload attacks ? the hint on the page tells me that i should look on the source code but i cant find anything useful, did i miss sth ?

feral gyro
wary saffron
#

can someone dm me i need help

slow venture
#

hey all, im having trouble with the miscellaneous techniques in the linux priv esc academy module. The mount seems to work, but when i run ./shell nothing happens. Can anyone help me? Please Sad_Squidward_Pepe

#

the instructions aren't clear on how they go from their local user to htb@nix02

wary saffron
#

has anybody done the Footprinting module?

acoustic owl
distant aspen
#

Hi everyone. I am new here. Just wanted to ask if anyone here has completed the OSINT: Corporate Recon module?

rustic sage
#

Hi! I bought a VIP+ subscription on HackTheBox, but when I went to spawn a workstation in the academy it warned me that I only have 1 a day. Does it take a bit to register the payment, or do I need to tie it to my HackTheBox account of something?

acoustic owl
rustic sage
#

is this the right way to make a fuzzing extension scan?

#

does anyone knows?

stiff tiger
acoustic owl
acoustic owl
rustic sage
#

ok ty

wary saffron
#

Hi has anyone done the SMTP module im trying to find the valid user account i am using the Resource wordlist that they have provided however running it just seems to crash the server

#

does anyone know the valid account name? if so please dm me the answer

#

ive used msf -- smtp-enum

#

but it crashes the machine

slow venture
#

hey everyone, for the linux priv esc - skills assessment , flag5, does any one have any hints? I've got an interactive shell. Looked at sudo -l, root has nopasswd for /usr/bin/busctl but the gtfobins doesn't seem to work... any clues?

livid pier
acoustic owl
# wary saffron Hi has anyone done the SMTP module im trying to find the valid user account i am...
west canopy
#

@slow venture try upgrading your shell with python3 -c 'import pty;pty.spawn("/bin/bash")'

#

then the gtfobin should work

slow venture
#

i've got it upgraded, i think im getting the gtfobin command wrong. is it sudo /usr/bin/busctl --show-machine?

#

cause that just opens the info but when its done it closes and goes back to tomcat

west canopy
#

sec let me check my notes. I'm on super spotty hotel internet

slow venture
#

thank you vvvvvvvvv much

west canopy
#

looks like its just: sudo busctl --show-machine

slow venture
#

BALLER

#

thank you, i got confused, it worked. You rock!!

distant aspen
#

@rich heron did you sort out your question with the corporate recon osint room? I have answered all but one question so far I might be able to help

rich heron
deft parrot
#

I was using curl to get this but dont understand

#

Or do i have to use burp for this

rustic sage
#

on module **Attacking Web Applications with Ffuf **

#

i cant find the right word list for the last section, the last question

#

the hint is:

#

the question is

#

can anyone help?

stiff tiger
#

hi - I made a progress on this but I am stuck on this after trying everything I can think of - if you figured it out, could you help me - or want to DM to compare notes and try to work on this together?

west canopy
#

@rustic sage try this command:

#

@stiff tiger If you need a nudge on windows priv esc feel free to DM me 🙂

distant aspen
#

@rich heron thats awesome! Would it be ok if I asked you for help with the one question I haven't completed?

distant aspen
#

can I DM you... not sure if we are allowed to post questions on here about rooms?

rich heron
#

Yes

fresh void
#

Hi

west canopy
acoustic owl
livid pier
gusty leaf
#

sooooooo how do i hck

#

hack

livid pier
gusty leaf
#

thx

haughty kiln
#

Hey, can somebody give me a hint at "SQL Injection" "Writing Files"?
Im lost rn :/

rustic sage
#

Are the docker instances down again?

molten epoch
#

Module : Web request
Section : GET
I have no idea what I'm supposed to do to answer the only question there is

molten epoch
#

this is all i think I'm supposed to do but i don't know hoe to get the flag

#

i also did this way but still no flag

rustic sage
#

from le to something else

molten epoch
#

perameter means change my search?

rustic sage
#

yes, the search=XX

#

@molten epoch

#

@molten epoch Got it?

molten epoch
#

i changed it

#

but same thing just different citys

rustic sage
#

Well, are you looking for ar?

molten epoch
#

i have no idea

rustic sage
#

Read the question again

molten epoch
#

im so ned im just copeing the examples

#

new*

rustic sage
#

It's simpler than you think

molten epoch
#

i dont understan the question at all

rustic sage
#

and use cURL to search for 'flag' and obtain the flag.

#

search for flag

molten epoch
#

yea ik but it wont give me a flag

rustic sage
#

Show me what you tried

molten epoch
#

thast all i have done

#

just with different citys

rustic sage
#

you are searching for ar and not for flag

#

you are over-thinking it...

molten epoch
#

got it!!!

#

but how in the world was i suposssed to know to search for flag?

#

How did u know ????

#

ty tho !

rustic sage
#

read the question again

#

it says clearly

#

search for flag :D

molten epoch
#

yea it says search for flag but i imagened like search for flag idk ig i just overcomplicated it

rustic sage
#

np, glad you got that

molten epoch
#

i dont know how but yea i got it

rustic sage
#

🥳

modest moth
#

any ETA on when the bug bounty career path will be finished? im excited about taking the HTB certified Bug Bounty Hunter exam.

frozen peak
#

hey im new

#

can u help me coding cuz im new

#

i wanna be a game developer

#

thats why

livid pier
frozen peak
#

ik

#

For hacking we need to know coding thats why

livid pier
#

Why mention game developer then?

rustic sage
#


Good morning everyone

livid pier
#

@rustic sage good morning!

lethal atlas
#

good morning

formal magnet
#

Hi. Any idea why it is Welcome1?

leaden vapor
# formal magnet Hi. Any idea why it is Welcome1?

Sorry it has been ages since I did that but I added:
(The ls command resulted in an access denied message, indicating that guest access is not permitted. Let us try again using credentials for the user bob (bob:Welcome1).)

leaden vapor
#

(I think it was part of the description maybe)

lethal atlas
#

Are we having issues with servers again today? I keep spawning the target but cant reach it

molten epoch
#

Moduel JavaScript Deobfuscation Section Decoding is this not what the answer is i did everything correctly right i cover what i think the answer should be because i don't know if we can show that but it says my answer is wrong what am i doing wrong??

lethal atlas
#

well your curl is incomplete

#

@molten epoch dm me

zenith parcel
#

has anyone done the sqlmap module and issues with the flag in case 5? I got the flag HTB{700xxxxxxxxxxxxxxxxxxxxxxxxxx7} but it says incorrect when I submit. I'm curious if I am overlooking something obvious.

lethal atlas
#

let me check.

#

which sql module?

#

sqlmap or sql injections?

zenith parcel
#

sqlmap page6 'Attack Tuning'. Case 5 - 7 are the exercises for this page.

lethal atlas
#

make sure you dont have a space at the end of your flag when you paste

#

happens fairly easily

zenith parcel
#

i just verified no leading or trailing space

lethal atlas
#

dm me what you have

#

cause the part you posted is right

slow venture
#

does any one remember the applocker command for windows priv esc - situational awareness question "What executable other than cmd.exe is blocked by AppLocker?" the one in the instructions is just from cmd.exe

west canopy
lethal atlas
#

What up Jared

west canopy
#

chillin at the airport in las vegas

#

Lost my wallet as soon as i flew in on Tuesday so it's kind of been a disaster

shadow verge
#

Why the explanation about DNS servers differ so much on DNS enumerating with python module and Footprinting module?

#

It feels like 2 different concepts 😅

acoustic owl
#

What do you mean? Where do you see differences?
A zone transfer is attempted in both modules.

shadow verge
#

For example server explanation

#

DNS enumerating with python explains 4 servers where one is root dns server and one TLD server.. But footprinting module is explaining about 6 servers and telling root servers are responsible also about TLDs

#

also DNS enumerating with python directly says there is 4 types of dns servers

#

not 4 or more

slow ruin
#

Having some trouble in the Windows Escalation Privileges - Interacting with Users. I am trying to do the SCF on a File Share exploit but only getting htb-student hashes while launching responder. Needing the SCCM_SVC user hash and not sure how to proceed

#

... did not realize there was a hint that I was completely missing... nvm I got this lol

haughty kiln
#

Can somebody give me a hint in "Broken Authentication, Default Credentials"?
Having trouble with the Bruteforce

zenith parcel
#

did you get past it or are you still stuck? I finished the module, so happy to help with any parts.

onyx wasp
#

@raven cairn

#

yeah

#

so how can i enroll in university ??

raven cairn
#

@onyx wasp Go to your profile in htb academy

#

Are you already using htb academy?

onyx wasp
#

yahh

#

i just started with htb acamdy i have completed some of tired 0 mobules and some others

raven cairn
#

You are going to go into your profile and click billing

onyx wasp
#

but now i need more cubes for other modules

raven cairn
#

The student subscription is pretty affordable and grants you a lot of content

#

Once you click on the button it should be very straightforward

onyx wasp
#

but should i enroll in it ??

#

and i don't have that option

raven cairn
onyx wasp
#

student* $8

#

now wt should i do

onyx wasp
#

@raven cairn hello r u there ??

raven cairn
#

Weird

#

Didnt happen to me. I would reach out to HTB support maybe

#

?

onyx wasp
raven cairn
#

Don't know where to help you from there 😦 . You can still accomplish quite a bit without a subscription tho.

onyx wasp
acoustic owl
# shadow verge DNS enumerating with python explains 4 servers where one is root dns server and ...

In the "Footprinting" module, the root servers are described a bit awkwardly.
A DNS root server can answer directly if it has the corresponding data in the cache, but it also knows which TLD server is responsible.

https://www.cloudflare.com/learning/dns/glossary/dns-root-server/

In the module "DNS Enumeration with Python" the author explains which servers are necessary, while the author of the module "Footprinting" shows which types are available. These are two different approaches. But both are correct.

https://www.cloudflare.com/learning/dns/dns-server-types/

However, only four server types are necessary (Resolver, Root, TLD, Authoritative Nameserver) for a successful DNS query. nevertheless, there are other types as well.
For example, a DNS server can be configured so that it simply forwards a DNS request to another DNS Resolver. This is then a DNS forwarding server.

dull bear
#

Is there anyone who's online can give me a bit of a nudge on windows privilege escalation

haughty kiln
#

Can somebody give me a hint in "Broken Authentication, Default Credentials"?
Having trouble with the Bruteforce

acoustic owl
fervent shale
#

But make sure you use your university email for your Academt HTB account

haughty kiln
onyx wasp
acoustic owl
haughty kiln
acoustic owl
# onyx wasp i don't have university email

Does HTB Academy offer a discount for students?

Yes! You can enroll for a student subscription in the billing section on HTB Academy, https://academy.hackthebox.com/billing

If you are registered on HTB Academy using an academic email that is included in our list of valid academic domains, the student subscription will be readily available. Please note that you can change your Academy account’s email via the account settings page.
If your academic email's domain is not in our current list of valid academic domains, the student subscription will appear as unavailable (greyed out). In this case, contact us via the support bubble at the bottom right of the page. The HTB team will verify the validity of the domain you will specify. After the academic email verification process is complete, you will be able to enroll for a student subscription and enjoy Academy's modules! The process may take up to two business days.

Note: Access to Academy modules requires an active student subscription. Make sure to renew your plan monthly to not lose access to your learning material!

acoustic owl
lavish void
#

I can't be the only one that would love to see a "hide completed" button for the module overview in HTBAcademy.. Right?

onyx wasp
haughty kiln
#

Can somebody give me a hint at "Broken Authentication, Weak Bruteforce Protections, Question 2"?
||I know it's not about bruteforceing, but I have no idea what IP I should use to bypass the login or where to find the IP...||

acoustic owl
onyx wasp
acoustic owl
haughty kiln
#

I know what to do but it doesn't work, i will try further

haughty kiln
#

nvm i got it xD

acoustic owl
rustic sage
#

Hi there

#

where do i get roles

#

@languid fjord

#

@polar bough

polar bough
rustic sage
#

mid ahh server tbh

rustic sage
astral siren
#

i'm having trouble with the xss module. i'm on the phishing part, but it seems that my javascript is being cut off half way through.

astral siren
#

oh, i'm using the wrong type of payload

inner cloud
#

lil help so i can earn 10 cubes †-†

#

in the setting-up academy module, Im asked "what does the acronym Linux PAM stand for?" As far as I can see, the module never explains the acronym so I looked it up, most sites say it means Pluggable Authentication Module, which makes perfect sense

#

when i type this in though, wrong!

#

oh pfft

#

its "Pluggable Authentication Modules"

#

plural - modules 😦

#

nvm sorry!

gritty karma
#

hello everyone

#

i need some help please

rustic sage
gritty karma
#

trying to add image

rustic sage
gritty karma
#

not help with adding image. That did sound confusing. I have an issue trying to find flag using curl POST command. I tried to copy the command in here but is erased it. Now trying to copy image of what I typed in terminal but i have not figured that out either

#

In the Web Request section the task is "Obtain a session cookie through a valid login, and then use the cookie with cURL to search for the flag through a JSON POST request to '/search.php'"

rustic sage
gritty karma
#

???

raven cairn
gritty karma
#

ohhhh, ok i see

#

I cant figure out why this will not return the flag

#

thats for letting me know that i had not done the varify

raven cairn
#

@rustic sage go to bed

#

🤣

rustic sage
#

One sec, did you copy it from dev tools?

#

@gritty karma

#

@raven cairn One second, just ONE second

raven cairn
#

You need sleep!!!

gritty karma
#

yes, the curl PHPSESSID never works

rustic sage
#

I remember doing it for someone last week

#

Hm.

#

Which module is this again?

#

And section?

rustic sage
gritty karma
#

Web Request - POST

rustic sage
#

Getting a ☕ - one min

rustic sage
#

remove the query in your URL

gritty karma
#

then it tells me that the POST data is empty

rustic sage
#

exactly

#

you need to query it with "data"

#

This is POST, not GET

gritty karma
#

confused.... i dont think i understand. I query with data and it returns no flag. I query without data and it tells me data is empty.

rustic sage
#

Let's go back

#

Send a request from the website while your dev tools are open

#

Let's say request "london"

#

And copy that request then from the dev tools with "Copy to cURL"

gritty karma
#

and i get {"London (UK)"}

rustic sage
#

Great

#

Now, where in the curl command do you see London?

#

Not in the URL, right?

#

Rather in --data

gritty karma
#

in --data-raw

rustic sage
#

Right

gritty karma
#

so --data-raw is really the flag?

rustic sage
#

Now, in your curl request you are going to have many more parameters that need to get removed, otherwise you are just repeating your request

rustic sage
high zinc
#

TFW you feel like writing a blog about how to design a C2 framework

#

why, brain

#

why

gritty karma
#

so I should have used curl with ip/port, content type cookie and data-raw should search for flag

high zinc
#

me: "I don't know how to do this"
my brain: "who cares, let's go!"
me: "But it's past midnight and it's a huge project and we've never tried this before, ever"
my brain "So? We'll figure it out, come on, it'll be fun"

#

_>

#

my brain is a bully

rustic sage
#

@high zinc Are you talking to someone?

high zinc
#

no

rustic sage
#

@high zinc Happens to all of us.

high zinc
#

I do wonder how a staged payload works

gritty karma
#

@rustic sage thanks man. it could not figure this out. your instructions made sense too. you really helped me out

gritty karma
#

hey, is there something that needs to be done when the target instance ip address just opens a blank white page. Refreshing instance does same thing

west canopy
#

@gritty karma which module?

steel ledge
raven cairn
#

Can I have some help with the linux privilege escalation module?

#

This is on the shared libraries section

#

I don't understand the error that I am getting.

west canopy
raven cairn
#

@west canopy Thank you very much. SSH'ing into htb-student fixed my problems

#

Which is stupid because I literally followed the instructions 😦

west canopy
#

Yea i'm not sure. This is just what I had in my notes

round sky
#

Working on Linux Fundamentals > Service and Process Management. How do I get the password?

silk niche
#

Split the network 10.200.20.0/27 into 4 subnets and submit the network address of the 3rd subnet as the answer.

acoustic owl
astral siren
#

did you figure this out? everything i see is empty

#

oh, it's not the domain i was trying

raven cairn
simple merlin
#

Hi someone can help me the location in the moule "OSINT :Open-Source Intelligence" ? I got coordinate as mentionned in the hint, but not working, really frustrasting

astral siren
#

i am really struggling with this last question on information gatheing - active subdomain enumeration

rancid sinew
#

Has anyone does the Chase lab in Intro to Blue Team track?

slow ruin
#

Did you ever end up figuring this one out? I have been trying the techniques it has listed in the module but none seem to work. Do you remember what technique you used to get the contents of the creds.txt?

west canopy
#

@slow ruin yes it's actually super simple but not something you would expect. Look for a powershell one liner provided in the section

west canopy
slow ruin
#

wow I did that earlier and it went right past me lol

west canopy
#

@astral siren i think I just manually bruteforced the answer on that one haha

spiral quiver
#

hey can someone helo me with under constuction from beginner track

#

im stuck at the sql injection and its not working

mild grove
#

Do we have here some moderator who can give us some hints ?

west canopy
#

@mild grove i was able to find the solution using google

mild grove
dapper flare
#

Module:SQL Injection Fundamentals
Section:SQL Operators

for some reason mysql won't do anything, after i log in it won't give any output. (Yes i am connected to the academy vpn)

i'm using this line: || mysql -u root -h (target ip) -P (target port) -p||

does anyone know what i'm doing wrong?

west canopy
#

@dapper flare what happens when you run the command: use employees

#

does it just hang? I know a couple weeks back there were some technical issues going on with that module and people were unable to connect to mysql

west canopy
#

Maybe respawn the target if you haven't already. I am working on Hacking Wordpress and I just had to respawn the target twice before it would load.

west canopy
#

Let me know if it keeps acting up and I can test it on my end

astral siren
astral siren
#

I solved all of it

rustic sage
#

Good.

astral siren
#

The active dns portion I guessed and managed to get it

rustic sage
#

So you did not "solve"

#

:)

astral siren
#

I was getting 29 a records, but that was too high

#

I am not sure why that wasn't the answer

#

The correct number was less

rustic sage
#

@astral siren Because if you would have tried to zone transfer those 29, you would not have succeeded, just with X of them

astral siren
#

That wasn't the question that was asked

#

The question was how many of these return a records

rustic sage
#

Which question exactly? I thought the second Q in Active Subdomain Enum @astral siren

astral siren
#

No, the last question

rustic sage
#

Oh, sorry. One min...

rustic sage
#

in th dns enum with python, where do i put an ip address in the script to make it work ?

#

i mean i dont know what to do with it but i know i need it

raven cairn
#

Guys I am not a Noob anymore : )

raven cairn
#

Hacker here I come : D

west canopy
#

@raven cairn Awesome work bud!

twin raft
#

Some help with Broken Authentication skill?

gritty karma
west canopy
woeful stone
#

Hello, I'm a band new user at the Academy and am starting from square 1. I'm starting off in Linux Fundamentals. One of my first interactive modules/quizzes has to do wit ssh login which i was able to do with no problem, but now the quiz is asking me the path the users home directory, I used "cd /home" and that worked and brought me there, but it the quiz isn't accepting that as the correct answer. Any tips as to what I'm not getting?

woeful stone
#

pwd

#

thanks

acoustic owl
rustic sage
#

for example when i use dig i write something like dig inlanefreight.htb @ip

#

and i dont know what to do with the ip, should i put it in /etc/hosts or specify it in the script

rustic sage
zenith gyro
#

guys please im stuck here """""Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer""""" i get ** server can't find 128.165.129.10.in-addr.arpa: NXDOMAIN i try dig $target @10.129.165.128 fqdn but i dont get nothing

#

help

rustic sage
zenith gyro
#

Information Gathering - Web Edition

#

Active Subdomain Enumeration

rustic sage
#

@zenith gyro added inlanefreight.htb to /etc/hosts?

zenith gyro
#

yes

rustic sage
#

@zenith gyro And what is the command you tried?

#

without vars

zenith gyro
#

nslookup -type=ns

#

and dig

rustic sage
#

|| dig ns inlanefreight.htb @white rock || should work @zenith gyro

zenith gyro
#

tankyou

#

i did the wrong dig command

sudden cloak
#

Hello, I am stuck in the Web attacks - skills assesment. I already found the IDOR vulnerability and the administrator user. The problem i have is that i cant find a way the reset the password of this user. I keep getting access denied

lilac ore
#

hi

feral gyro
sudden cloak
#

I've already thried that

feral gyro
rustic sage
#

Can anyone help?

#

module WEB REQUEST

#

last section

real hare
#

I am in the linux section, there is a question that I cannot answer, which says: Which shell is specified for the htb-student user?
I tried with bash, shell bourne and many names, but I don't know what the question refers to
could you help me with this please? I looked at the photo and it doesn't appear either

#

I'm a newbie, sorry

rustic sage
real hare
real hare
feral gyro
feral gyro
rustic sage
real hare
feral gyro
real hare
#

is bash?

feral gyro
real hare
#

ahhhh, nice

feral gyro
#

u don't need to use env instead u can use this command

real hare
#

Many thanks!

#

sorry

real hare
real hare
solid river
#

Hi, someone can tell me why i cant send or see msgs in most chats?

shadow mist
#

LINUX PRIVILEGE ESCALATION --- Miscellaneous Techniques

Review the NFS server's export list and find a directory holding a flag.

I have no idea what he want , tried mount but access denied to mount on target server

summer lake
#

hi guys, anyone knows if you can reset a module and do it all over again?

acoustic owl
west canopy
#

@shadow mist I don't believe you actually need to mount anything, just navigate to /var/nfs/general and the flag should be there

silk niche
#

To get the flag, use cURL to download the file returned by '/download.php' in the above server.

lethal atlas
#

Good day everyone.

silk niche
#

curl http://target/download.php dosent seem to work

lethal atlas
#

@silk niche you do realize you have to change the part where it says "target" to the IP and PORT of the actual target?

#

and to download the file you have to pass along the flag -O and give it a name. i.e. -O download.php

#

-O, --remote-name Write output to a file named as the remote file

livid pier
#

@lethal atlas top of the morning

lethal atlas
#

@livid pier how are you today?

raven cairn
#

Good morning : )

#

Who's ready to finish some modules sunglas

silk niche
#

thanks 🙂

lethal atlas
#

yw

livid pier
#

Ready for a new mod to drop

#

@lethal atlas How you doing?

lethal atlas
#

Im good. Working on file upload attacks. Im 3/4 way thru the bug bounty path.

livid pier
lethal atlas
#

hope to.

haughty helm
#

hi can someone please help me with Active Subdomain Enumeration

west canopy
#

@haughty helm sure, which questions?

#

That section was pretty difficult. Like the way to actually solve the questions was not mentioned at all in that section

haughty helm
#

qn 2,3,4,5,6

#

@west canopy yeah i tried a lot but couldn't figure out the answers

west canopy
#

So basically all of them? lol

haughty helm
#

yeah

west canopy
haughty helm
#

but how did u find the internal.inlanefreight.htb subdomain? @west canopy

west canopy
sudden zenith
#

Hey I'm looking at the Active Directory Bloodhound module, I've started my pwn box and additionally am on the vpn on my kali box, neither of the two seem to be able to reach the supplied domain. Also, it reads as if there should be a Windows environment supplied to run a collector on yet I cannot locate a reachable IP in any of the modules pages?

haughty helm
# west canopy

like how did u know that txt is present in this specific subdomain

west canopy
#

I had to run the "dig txt" command against every subdomain

haughty helm
#

ohhh right

west canopy
#

Yea. No pretty way of doing it lol

haughty helm
#

and what about the identification of zones

#

i guessed the answer as 2 but

#

i dont know how to identify it

west canopy
#

Yea I ended up guessing it too. But i asked my instructor about it and he explained it like this:

#

So the presence of an "A" record (or multiple "A" records) is one zone. The presence of an "NS" record makes it two. If there was an "MX" record, then it would be three.

haughty helm
#

alright !

#

next is to find the number of A records

#

from all zones

west canopy
#

Anyone able to give me a sanity check on Web Attacks "Bypassing Security Filters"? It looks like the verb to use is HEAD, but I am still unable to create a new file called "file;" let alone copy the flag over.

Edit: Solved!

haughty helm
#

@west canopy ?

west canopy
#

@haughty helm was that the last question in the section?

haughty helm
#

yeah

west canopy
#

Yea so I just manually bruteforced that one too. I don't have a good explanation as to why the answer is what it is 😦

haughty helm
#

also i want to know how to find the FQDN for the given ip address

west canopy
#

so you will want to try doing a zone transfer against all of the subdomains you found initially. It turns out the one you want is going to be "internal.inlanefreight.htb"

haughty helm
#

fine got a lot of info Thank You soo much for helping me out , I spent lots of hours on this @west canopy

west canopy
#

NP! I was losing my mind on this section too until my buddy helped me out 🙂

#

Fortunately the sections after this one are pretty straight forward

haughty helm
#

Great !!

haughty helm
west canopy
#

Ah gotcha

#

that makes sense. So when you add them up does it come out to 27?

haughty helm
rustic sage
#

i need help on **JAVASCRIPT DEOBFUSCATION **

#

on section Skills Assessment

#

what do i have to do now?

#

i have found the javascript code, but i dont understand what i have to do with it

#

after that i tried to decode it but i found this

lethal atlas
rustic sage
rustic sage
rustic sage
#

hey can anyone help with the assessment in ffuf im kinda stuck

#

do i need to add the domains found to the /etc/host/ file?

raven cairn
#

@rustic sage what is your problem? I can try to help

rustic sage
rustic sage
#

cant seem to navigate to the pages i found.

#

they all end up blank or a google search

gritty karma
west canopy
gritty karma
#

thanks alot. I tried that, but I did not use curl -s

west canopy
#

NP. I had to delete the two HTB cities that I made earlier too before it spit out the flag

hazy grotto
#

You figure anything out? im on the NFS. I can't mount or configure the config file

#

I was stuck on this for a long time. did you figure it out? someone on here did.

lavish needle
#

Hey @hazy grotto ! I did figure it out hahaha thank you : )

hazy grotto
#

I had tried like 5 different answers tried using reversed slashes. But somehow I had missed it. I spent about 2 days in that question

lavish needle
#

Right so I actually had the right answer in the right format - that's why I was really confused because I knew I was right. I'm confident it was something messing up on htb - after refreshing the website - it finally accepted my answer

slow wing
#

Can any one help with Broken Authentication- Bruteforcing Cookies- Question 1?

slow wing
#

Need some help with Skill Assessment - Broken Authentication 😄

narrow wasp
#

need some help on "Advanced File Disclosure" section from Web attacks

honest breach
#

can somebody help me i tried to connect to the windows target using xfreerdp but its not working

slow venture
#

whats the command you're using?

leaden venture
#

Good Morning, I am in need of some help with Web Requests - GET exercise

leaden venture
#

*I think

signal topaz
#

Hey can someone help with the 'Skills Assessment - File Upload Attacks' I've managed to bypass the filters, but can't get code execution, since the request is returning <img> with base64 encoded source. I've tried to find the upload location so I can access the file directly, but that did not also work?

rustic sage
lunar timber
#

Hello there, guys does anyone have information about email-subscribers plugin vulnerability for Wordpress task?

zenith gyro
#

Find and submit the contents of the TXT record as the answer..... Any help???

zenith gyro
#

can i dm you

lethal atlas
#

yes

acoustic owl
slow venture
#

hey, for the windows priv esc, how did you all get accesschk to work? Looks like it doesnt come on the box

#

and my windows machine through HTB can't connect to the internet

lethal atlas
#

I am still having an issue on file upload attacks myself. I am on "Type Filters" have found an extension that I can upload, and I have removed the whitelist filters but after uploading and browsing to the page I get an error that the file cannot be displayed because it contains errors.

leaden venture
#

Question: Is there a reason why after 10:30am Eastern Time I start having issues with spawing the targets? I have seen this happen for the last 3 days.

I have refreshed my browser and I have refreshed the page but I still am not getting through to the target. I even do a simple curl -v http://<target ip>:<target port> and I get "trying" followed by "failed to connect"

#

I have even tried to refresh the target and still no luck

lethal atlas
west canopy
#

I've been having some trouble with Docker targets, typically i have to respawn them a few times

leaden venture
#

Something that is popping into my mind: Is there a preferred browser that we should be using?

lethal atlas
#

I use strictly firefox

leaden venture
#

Ok that I will try and see, I appreciate the help!

#

Ok so I have the Docker target spawned and I can communicate with it, now I am having issues with one of the commands in the Web Requests exercises

curl -s http://139.59.167.115:31487/api.php/city/london | jq
which returns:
bash: jq: command not found
(23) Failed writing body

#

Am I doing something wrong

west canopy
#

looks like you need to install jq

#

i think its just: sudo apt install jq

leaden venture
#

ok thank you for that tidbit

#

ok so what is the password

livid pier
#

password = ||Never gonna give you up
Never gonna let you down
Never gonna run around and desert you ||

#

jk password is in the creds file on the desktop

leaden venture
#

thank you can you tell I am a newbie to this

livid pier
#

lol no, that question gets asked all the time

leaden venture
#

thank you so much, now I can keep working on the Web Requests exercises

PS: Might someone think about putting that piece of information into that exercise - ensure you install jq on your terminal

lethal atlas
#

@livid pier did you get your scan done last night?

lethal atlas
#

holy cow

livid pier
#

Ya it is ridiculous

#

@lethal atlas you still stuck?

slow venture
#

is there a windows cmd line command to download accesschk? Its not on the machine i spawned and need it to get the flag

#

but also don't have internet access on this machine

lethal atlas
west canopy
#

@slow venture which section is that?

slow venture
#

windows priv esc!

#

sectionnnn

#

communications with processes

west canopy
#

try looking in the directory C:\Tools\

slow venture
#

thank you 🙂

livid pier
#

We back!

raven cairn
#

@livid pier hello

livid pier
lethal atlas
#

woohoo

raven cairn
#

Ngl I thought it was a Russian cyberattack

livid pier
#

Not yet

#

its coming tho

#

What are we gonna do during the dark ages?

#

Imagine spending a year to learn cyber security then we lose the internet for a year

raven cairn
#

If I can't survive without discord and Spotify for one hour, then I would be screwed in an actual cyber attack

west canopy
#

Anyone able to give me some assistance on Web Attacks Skills Assessment? I'm able to enumerate all of the Users and their Tokens but not sure what to do next. I believe I need to reset the password for an Admin user, but I can't figure out which user is an Admin.

livid pier
#

Sorry just read the second half

#

You are right, read that list close there is an admin there

west canopy
#

I haven't. I was using a list of numbers 1-100 for the UID's in burp intruder , so in the response I can see usernames, employee full name, and company

#

But nothing stands out as to which user is an Admin 😦

livid pier
#

All of my pictures wont load

raven cairn
#

@livid pier 😭 same

west canopy
#

NOOOOO!!!! lol

raven cairn
#

:/ stupid Putin

livid pier
#

initals AC

west canopy
#

Hmmm for #42 I'm seeing an "Asaad Yin"

#

Derp i found it.

#

You da man Vivi ❤️

livid pier
#

It happened to me too

west canopy
#

@livid pier Is it cool if I DM you?

mild grove
#

Hi do we have some moderator who can I ask DM about one module ?

livid pier
lethal atlas
#

ARGGHHHH

#

I just am not seeing what the hell Im missing on this damn question.

livid pier
#

lets do it

lethal atlas
#

lol ok

clever sun
#

hi

balmy creek
#

Some one knows there is any problem with the plataform? I try to "curl http... -X POST -d "serial=you_decoded_output"

#

And i get curl (28) Failed to connect to IP Port

devout galleon
#

Yo you got any tips for getting the tomcat part.

lilac halo
#

hi evryone + 0 What Group Policy Object is created when the domain is created?
any one have solved this in INTRODUCTION TO ACTIVE DIRECTORY module

west canopy
dense hearth
#

anyone doing Secure Coding 101: JavaScript assesment?

honest breach
formal mica
#

Hi
I'm currently at Module 35 at Web Requests (GET)
This shouldn't look like this, should't it:

#

Tried both chromium and firefox with no success

rustic sage
formal mica
formal mica
#

Ok then it seems to be just me... strange. But thank you for the image

formal mica
#

yeah that worked

#

thx

rustic sage
#

I am currently on the brute forcing skills assessment (website). i got the first flag and im trying to brute force the admin login form. I understood that the user there is not admin but a user I discovered before (there are not many in this module anyway, so I added them all to a user.txt for hydra). I adapted the fail string and the user/pass fields but I still don't get a matching login anywhere. I would be happy for some pointers 🙂

signal topaz
reef hinge
#

oi eu sou do brasil

livid pier
raven cairn
#

💪 Who is ready to pown some modules today?!

hazy grotto
#

Anybody explain the host client to me?

#

Im doing NFS install

#

on fingerprinting module

#

On the Host

On the host server, install the nfs-kernel-server package, which will allow you to share your directories. Since this is the first operation that you’re performing with apt in this session, refresh your local package index before the installation:

sudo apt update
sudo apt install nfs-kernel-server

Once these packages are installed, switch to the client server.
On the Client

On the client server, we need to install a package called nfs-common, which provides NFS functionality without including any server components. Again, refresh the local package index prior to installation to ensure that you have up-to-date information:

sudo apt update
sudo apt install nfs-common
#

Is PWNbox the host or the client?

jovial sun
#

I belive the PWNbox is the host

hazy grotto
#

hroughout this tutorial, we refer to the server that shares its directories as the host and the server that mounts these directories as the client. You will need to know the IP address for both. Be sure to use the private network address, if available

#

Ok i just spotted this.

#

This leads me to think its the opposite.

hazy grotto
tribal linden
#

Can any one tell me the password for the parrot box ?

feral gyro
olive void
#

help

#

i just spawned my linux maschine but it didn't start

#

so i realoaded the page

#

and now i have 0 spawns left and the machine didn't start

#

why))):

feral gyro
olive void
#

ik ik

#

but i had on bc i didn't use mine today

#

but it never starded and my spawn is gone

#

wwhyyyyyyyy)):

feral gyro
olive void
#

oke :/

hazy grotto
olive void
#

no i won't

#

bed

#

why would i wan't to pay

hazy grotto
#

Footprint Module NFS tip

The first code to run before you start the lesson.
sudo apt update

sudo apt install nfs-common

olive void
#

why

#

like you mean my mashien might be broken?

stiff tiger
#

Hi, I tried several different ways to find users in the Remote Management Users group and failed. Did you manage to find a solution? - anyone else out there find a solution to this one? (PowerView - enumerating groups task 2)

raven cairn
#

@hazy grotto How you doin 😁

paper python
#

Hey there, I'm a lil stuck in Getting Started -> Public Exploits. Is the search via nmap supposed to take like 45+ Min? I need to add the tags "-Pn" "-p-", or else it tells me that the host website may be down. Any info on this?

versed iris
#

I'm in Linux Fundamentals Module 18: Filter Contents and I was doing the cURL question for finding unique paths. I wasn't able to figure it out so I looked around and found a line that went like this: curl https://www.inlanefreight.com > . . .| cut -d"'" -f2 | cut -d'"' -f2 | . . . (I cut most of it for spoilers) while I was able to find the correct answer with this line I found I cannot for the life of me figure out why would " be the -f2 in href="https://www.inlanefreight.com/" can anyone shed some light on this?

west canopy
#

@paper python Yes, adding the -Pn option might be required if the target is blocking your pings. And adding the -p- option makes it scan all 65,000+ ports so it typically takes a very long time.

west canopy
paper python
west canopy
#

@paper python You actually don't need to scan all ports. For a typical nmap scan most people just use -sC -sV. For the "Public Exploits" section in particular, you will just want to try and exploit the WordPress plugin that is displayed when you navigate to the target in your browser

paper python
west canopy
#

Yes if you wanted to nmap scan that specific port. But I don't think its even necessary. Can just copy paste the target:ip into your browser and then go from there

lost kayak
#

@mortal basin Hey I was wondering if there had been any word on the completion of the Bug Bounty pathway / Certification. Loved the current material and am eager to jump into the last 3 modules. Thanks!

mortal basin
west canopy
#

we want MOAR CONTENT!!!

paper python
west canopy
#

I don't think so. I was able to get the flag using Metasploit.

paper python
#

well damn, got stuck on the filepath...

hazy grotto
hazy grotto
raven cairn
#

@hazy grotto I am doing good! Seems like you have become much better at hacking recently!

paper python
west canopy
#

Well the plug-in on the wordpress site was "Simple Backup" so I figured I would try a corresponding metasploit exploit

paper python
#

been stuck here for 2+ hours, thanks!

errant ivy
#

Firewall and IDS/IPS Evasion - Medium Lab & Hard Lab don't seem possible

west canopy
#

@errant ivy Actually this is probably too spoilery , feel free to DM me

raven cairn
#

Noob question: what am I doing wrong here?

#

"Perform a WHOIS lookup against the paypal.com domain. What is the registrant Internet Assigned Numbers Authority (IANA) ID number?"

#

Information gathering -Web edition module

west canopy
#

Looks like you are doing it right. Maybe try using sudo? Not sure if that would make a difference though

raven cairn
#

Weird. I did the same thing on my kali Linux machine and it worked fine

#

Very odd issue

rotund mountain
#

So after doing the: ATTACKING WEB APPLICATIONS WITH FFUF module I am very confused with virtual hosts. I'm looking for someone to explain or point me to a resource explaining why when I have "[ip] academy.htb" in my /etc/hosts file I can't visit academy.htb/admin/admin.php but when I append "[same ip] admin.academy.htb" to my /etc/hosts, I can visit admin.academy.htb/admin/admin.php .

Wouldn't these just resolve to the same ip and therefore trying to reach the same page? I see the line "VHost is basically a 'sub-domain' served on the same server and has the same IP, such that a single IP could be serving two or more different websites." If that's the case then how does a DNS server know what site to send you if they resolve to the same ip? Thanks

west canopy
#

Anyone able to give me a sanity check on Server Side Attacks "Nginx Reverse Proxy & AJP"? I am editing the nginx.conf file but have no idea what I am doing wrong.

Edit: Solved

bold sleet
#

have you figured out how to solve it? i could use a nudge in the right direction

rustic sage
#

how would you add a subdomain to the /etc/hosts file? like i know you sudo nano but what would the subdomain look like. im kinda confused

west canopy
rustic sage
#

thanks

#

ffuf is kicking my a**a

#

ass**

west canopy
#

I like GoBuster better #ChangeMyMind

rustic sage
#

haven't had the chance to use it yet.

west canopy
#

FFuF output looks like just a bunch of vomit in my terminal

rustic sage
#

lol yea i feel ya on that one.

livid pier
sinful hatch
#

Hi

fathom bay
#

can someone help me figure out where to inject code in the command injection > skill assignment?

signal topaz
#

look around the functionalities, specially how to copy/move files.

rustic sage
#

People, I am stuck at the Firewall evasion challenges of the NMAP enumeration modules. Is there some who did this module and is willing to help me? I don't know which commands I should use to get the right result. I already tried a lot,

fathom bay
signal topaz
#

did you found the copy file functionality? if so, try to imagine how it's working on the backend and you will get it (check the request which copies a file from one folder to another and see what query params accepts) 🙂

rustic sage
#

In the XSS skills assessment I can only post one comment (preview only), subsequent comments don't get posted at all and I have to reset the instance. Is this normal?

fathom bay
# signal topaz did you found the copy file functionality? if so, try to imagine how it's workin...

you sure copy is the injectable one? when i try to ||move a file to the tmp folder, that is already there|| i get the malicious request because of the ||/ is the url that is generated by the server||. Ive been toying with the copy and i cant get anything, i understand how it works, heck i could even write the code of it cause its so similar to the host check that was present in the module, but i cant add a command to it for the life in me

signal topaz
rustic sage
rustic sage
#

ok thanks

pulsar elm
#

hey guys. How can I find the most common password in a file (is separated by \n paragraph) ? I have searched but cant find a command that works (normally crop at a special char)

#

like this

#

as you can see the command doesn't work well

feral gyro
pulsar elm
#

CRACKING PASSWORDS WITH HASHCAT - Skills Assessment
Resolving the last question

feral gyro
acoustic owl
acoustic owl
pulsar elm
#

?

acoustic owl
#

First, crack the passwords with Hashcat in the file DC01.inlanefreight.local.ntds.
Then create a report with dpat.py.

slow venture
#

hey all, I keep getting access denied errors for the windows priv esc - windows built-in groups module. Did anyone else run into errors even if in whoami /priv, SeBackupsPrivilege is properly enabled?

#

trying to share an image but discord wont let me. the error is: Copy-FileSeBackupPrivilege : Opening input file. - Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))

#

nvm it decided to work now

fathom bay
signal topaz
fathom bay
#

ohh, ive missread it

#

thanks

signal topaz
errant ivy
#

┌──(kali㉿kali)-[~]
└─$ hydra -C /opt/useful/SecLists/Passwords/Default-Credentials/ftp-betterdefaultpasslist.txt 64.227.39.88 -s 31960 http-get /
Hydra v9.2 (c) 2021 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2022-03-10 10:34:15
[ERROR] File for colon files (login:pass) not found: /opt/useful/SecLists/Passwords/Default-Credentials/ftp-betterdefaultpasslist.txt

#

Does anyone know why this is happening?

#

Is hydra broken?

wary saffron
#

does anyone know how to get the admins email for the imap module

blissful verge
#

hi all, Long awaited (sorry!) but I've updated the wireless cracking section in the Cracking Passwords with Hashcat module to reflect mode 22000 and using hcxpcaptool vs hcxcapngtool ... if anyone else had noticed issues with this section that I missed, please DM me

rustic sage
rustic sage
west canopy
#

@rustic sage DM me if you still need help 🙂

rustic sage
slow venture
#

Hey, did anyone have this problem or know how to fix this? I got this error when doings the windows priv esc - dnsadmins module Command failed: RPC_S_SERVER_UNAVAILABLE 1722 0x6BA

west canopy
#

@errant ivy Just tested on my VM and it looks OK

#

Your command looks correct. Maybe retry spawning the target? I've had some issues with Docker targets not spawning properly.

slow venture
#

Are the instructions correct for the DnsAdmins section of windows priv esc? Everything seems to be working but when I try to navigate to the flag i get access denied

livid pier
west canopy
#

@slow venture I actually had to use a reverse shell .dll

slow venture
#

🥲

fathom bay
# signal topaz no problem 🙂

hey man can you help me a bit more, i am using this payload ||index.php?to=tmp&from=tmp${PATH:0:1}51459716.txt$(tr${IFS}'!-}'${IFS}'"-~'<<<{{)${IFS}wh"o"ami&finish=1&move=1||and i dont get any output, only a blank erorr ||Error while moving:||
When i used something like ||c"a"t%09${PATH:0:1}flag.txt|| i get a second error for cat and a permission denied for the flag.txt

fathom bay
#

command injection, skill assignment

#

the trasnform is to get ||

signal topaz
fathom bay
#

missed that, i was so foccused on the parameter i tried cause that was where i got the error firt

#

thanks, i feel dumb now haha

lethal atlas
west canopy
#

@lethal atlas It's a Pwnbox thing. They have seclists in a weird location.

errant ivy
#

Thanks

lethal atlas
signal topaz
pulsar elm
rustic sage
#

run hashcat w/o --show and you'll see that you don't get the results. you need, therefore --show. and --force is meant only for devs. @pulsar elm

pulsar elm
rustic sage
pulsar elm
rustic sage
#

maybe @paper gust can help here...

paper gust
#

sup

#

oh boy

#

@pulsar elm what runtime do you have installed?

#

hashcat clearly doesn't agree with whichever one it is

#

hashcat -I may give you more information if you dont know

#

also, to clarify, @rustic sage is correct, you should never run with --force

#

if it's not working without it, then you need to try to solve the problems elsewhere, by fixing or installing proper runtimes for example

fathom bay
#

Google hashcat Collab

paper gust
#

that's another way to do it

paper gust
#

well

#

couple of things

pulsar elm
#

It is my laptop OS

paper gust
#

1, that version of hashcat is several years old

#

so you should definitely update that

#

2, what compute devices are you trying to use?

pulsar elm
#

There is a command to update it?

paper gust
pulsar elm
paper gust
#

yes, what hardware device are you trying to have hashcat use?

#

it needs either a CPU or GPU to use

#

and the runtime you need to install will depend on what device

pulsar elm
paper gust
#

you will need to know which one you are going to use and install the runtime/drivers for that device before you can run hashcat

pulsar elm
paper gust
#

the difference is which device is being used

#

GPUs tend to be faster

#

but you need to actually have one for it to work, and if this is a laptop that may not be the case

#

(*have a discrete GPU, integrated are often buggy)

plucky nimbus
#

Anyone got time to help me out a bit with the File Upload Attacks module? Stuck on the self-assessment

pulsar elm
paper gust
west canopy
#

@plucky nimbus Feel free to DM dawg 🙂

raven cairn
#

I am having some trouble with the linux privilege escalation module, section 'privileged groups'. Doing the privilege escalation was easy. The hard part is finding the flag because I am having difficult understanding the instructions. I have been stuck on this question for quite some time so I would appreciate the help. Where am I supposed to be looking for the flag?

wise crystal
#

what is this group for

#

?

#

@here

raven cairn
#

No. I don't know where they want me to be looking for @livid pier

livid pier
#

k i havent done it but

#

it looks like first step would be use the groups command

#

that will tell you the groups your user is apart of

raven cairn
#

I am part of the root group it looks like

livid pier
#

ok

#

one sec let me check my notes, i had to use a similar command for my last box

#

use that second command

#

find / -group root 2>/dev/null

#

maybe pipe that with grep and flag.txt

#

full command would be

#

find / -group root 2>/dev/null | grep flag.txt

#

whoops no network

west canopy
raven cairn
#

@livid pier @west canopy Thank you guys so much! I was just manually searching random locations for the longest time

#

🤣

livid pier
#

@west canopy to save the day

livid pier
#

you legit have the power to not have to do that at your finger tips

west canopy
#

Manually enumerate the entire file system? Sounds like something i would do.

raven cairn
#

cd ls cd ls cd ls cd ls cd ls

livid pier
slow wing
#

Hi, can anyone help me with FILE INCLUSION / DIRECTORY TRAVERSAL Academy Skills Assessment?

#

I got RCE, but seems like don't have permission to list /root.

shadow mist
#

LINUX PRIVILEGE ESCALATION - Skills Assessment

I am able to log in the tomcat manager with "tomcatadm" cred but did not see any useful information for me to escalate permission to read the flag4.txt in target server. Anyone can give me some direction or hints ? Currently stucking reading flag4.txt

lunar stirrup
#

Is it actually possible to play trough all modules from academy without paying IRL?

#

(paying for cubes)

shadow verge
#

In broken authentication skill assessment there is rockyou.txt mentioned in introduction, I'd like to know if my regex for the password format is correct, any hints?

paper crag
#

Anyone know what this module is that's appeared under the Junior Penetration Tester pathway? It can't be accessed whatever it is

torpid phoenix
#

Hey beautiful people: why I can't ssh into my target machine it just keep looking then say times out when I use this form "ssh htb-student@x.x.x.x"

acoustic owl
#

Are you connected with VPN?

torpid phoenix
#

I just open my terminal and typed the command

acoustic owl
torpid phoenix
acoustic owl
#

Connect with VPN
sudo openvpn academy.ovpn

torpid phoenix
rustic sage
#

LFI/RFI module - Log poising - anyone can help?

#

Please DM me.

acoustic owl
zenith gyro
#

hello guy

#

good morning

#

some hrlp

#

What is the FQDN of the IP address 10.10.34.136? /What FQDN is assigned to the IP address 10.10.1.5? Submit the FQDN as the answer.

#

for sure im wronging something

acoustic owl
#

good morning
Which module are you in?

zenith gyro
#

Information Gathering - Web Edition

#

active subdomainb enumeration

acoustic owl
#

In the question before, you had to answer how many zones there are, right?

zenith gyro
#

yes

acoustic owl
#

List the content of all zones, then you can see all domain names.

zenith gyro
#

but is not in the list this ip

acoustic owl
#

How many zones did you find?
Did you list all zones?

#

You can also search with grep

zenith gyro
#

ok i will try

#

i did whit axfr in nslookup

acoustic owl
#

List all domain names from all zones and then look at the list.
You will find both.

zenith gyro
#

i miss something

acoustic owl
#

feel free to DM me

zenith gyro
#

tanks

torpid phoenix
#

Hey heroes again, what is the initial password for my bwnbox ?

#

When I try using sudo it prompt me with password

languid dawn
#

Credentials.txt on the desktop

torpid phoenix
#

Oops!

torpid phoenix
languid dawn
#

it's fine 😄 you can't know what you don't

zenith schooner
#

anybody can help me in Linux priv esc module? It is a general question: Once you got a reverse shell, if you cannot display any shell error, how can fix it? I tried to upgrade shell via python but it is now available. thanks

shadow mist
zenith schooner
# shadow mist which section question you asking?

I am in linux priv escalation (Assesment Skills. Flag 5). I got a shell with tomcat but any command that reports an error is not showing. It is a bit harder to figure out a possible solution. Usually if I upgrade the shell the problem is fixed. But in this case I cannot. I guess I am inside a container and the features are very limited.

shadow mist
zenith gyro
#

guys some hint for information gathering-web edition on active subdomain ....the last question Submit the number of all "A" records from all zones as the answer.

zenith schooner
jagged zenith
#

Any hint skill file upload attack

#

I found bug xxe and i can read source code but i can not upload shell

zenith gyro
#

i find alone

lethal atlas
shadow mist
zenith schooner
lethal atlas
#

I used dig.

#

and your looking for a unique subdomain

#

the same one you used in question 3

silk niche
#

Try to update any city's name to be 'flag', and then delete any other city (including any cities you added). Once done, try to search for a city named 'flag' to get the flag.

wary saffron
#

admin:164e556082000000c759cca474a85915261a855dd714bcabbeb478c8b767c2785a0f0a9d41cb7e70a123456789abcdefa123456789abcdef140561646d696e:f5cbd757c21ebeeeb45297cede4503e9e4a6bd90

#

what hash type is this guys?

#

MD5?

lethal atlas
#

unkown hash type. But its too long for MD5

shadow verge
#

Why my target's time left is running way too fast?

raven cairn
#

Is this an academy module?

wary saffron
#

yes

#

im struggling to crack it its from the Footprinting IPMI module

#

i believe its sha-1

lethal atlas
#

Operation HTTP Method Description
Create POST Adds the specified data to the database table
Read GET Reads the specified entity from the database table
Updated PUT Updates the data of the specified database table
Delete DELETE Removes the specified row from the database table

compact magnet
#

slash/hello

livid pier
#

slash/hi

lethal atlas
#

hola

wary saffron
#

What is the account's cleartext password?