#modules

1 messages · Page 514 of 1

wary saffron
#

IPMI module can someone who knows the answer dm me

carmine quail
#

If you can use the metasploit module, it’ll run the hash through a known IPMI wordlist. Probably root:calvin. But use the metasploit module if you can.

wary saffron
#

its admin and it does nt find the password

livid pier
livid pier
#

then run it in hashcat it will crack in 5 seconds

slow venture
#

hey, where does secrestdump.py sit in the windows boxes? I can't find it to run the command

livid pier
slow venture
#

windows priv esc module

#

its not in tools

west canopy
#

@slow venture its part of the impacket suite

slow venture
#

um.. could you explain more? When i run it in cmdline is says that its not recognized as a command. Do I need to be in a certain directory? in PS? Running as admin?

#

oh wait

#

no still confused

west canopy
#

@zenith schooner for flag #5 you will need to upgrade your shell, and then use the busctl GTFOBin

slow venture
#

oop got it

#

key word 'locally' lol

west canopy
#

@slow venture yes you would run it from your attack machine

#

@silk niche

slow venture
#

where am i able to use crackmapexec locally @west canopy ? Getting command not recognized for that one

silk niche
#

but thank you anyway 🙂

west canopy
#

@slow venture you might need to install it if your terminal doesn't recognize it as a comman

lunar stirrup
#

My native language is also not english and it's not that easy to understand everything in HTB Academy but I'm trying my best. Personally I think, English is one of the importants skills if you want to learn hacking

raven cairn
#

English is hard and it is my first language :/

#

So many dumb rules

livid pier
livid pier
raven cairn
#

@livid pier Random question. My pwn box isn't working . Is it working on your end?

raven cairn
#

Me too but I don't have my laptop with me :/

livid pier
#

i can check tho

#

looks good

raven cairn
#

Cool. Got it to work on my end. It was probably not working because of all the security extension I have on firefox 🤣

slow venture
#

How do you change directories in an smbexec shell? I get the error 'You cant CD under smbexec. Use full paths."

#

and not sure what syntax it wants 🙂

dense wolf
#

i used

#


ERROR 1222 (21000): The used SELECT statements have a different number of columns```
#

and questions is

#

Connect to the above MySQL server with the 'mysql' tool, and find the number of records returned when doing a 'Union' of all records in the 'employees' table and all records in the 'departments' table.

#

and ive tried this ```UNION SELECT * FROM employees AND departments;

ERROR 1064 (42000): You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near 'UNION SELECT * FROM employees AND departments' at line 1

stiff stream
#

Has anyone done the windows privilege escalation - vulnerable services module? I have used the Set execcution command but it still restricts, can anyone help me with this? 🙂

west canopy
#

@stiff stream not sure if this helps but this is what I have in my notes

slim lagoon
#

can someone help me here ? I dont get it 😄

rustic sage
#

You have 95% of the answer right on your Desktop actually :p

primal sundial
#

you found the flag :-p

rustic sage
#

I'm faster pepegun_hand

dense wolf
#

corey

slim lagoon
#

yeah but whats the once like xD

dense wolf
#

can u help me out with SQL?

west canopy
#

@dense wolf try this:

rustic sage
#

(tips : it's a condition to use the UNION operator)

dense wolf
#

thank you

#

for helping me outž

#

out*

rustic sage
#

Jared gave a pointer you must thank him instead of me prayge

stiff stream
#

@west canopy mind if I dm you?

west canopy
#

sure

slim lagoon
#

Finally got it haha should have double clicked on it to see it 🤣

opaque marlin
#

Question is there any particular order to start the modules on the path

west canopy
#

@opaque marlin If you check a module before unlocking it, it usually says what the "recommended" completed modules are before you start it.

rustic sage
rustic sage
feral gyro
rustic sage
feral gyro
#

they will help u

rustic sage
#

thanks

vivid hawk
#

Hi I new too

slow wing
#

Hi, for Word Press Assessment, does anyone get this error when trying to update the theme? Unable to communicate back with site to check for fatal errors, so the PHP change was reverted. You will need to upload your PHP file change by some other means, such as by using SFTP.

digital olive
#

hello , i hope you're all doing well so...

i have and issue with the module "Getting Started" specifically with this "Knowlage check"

which i could pass this login page i found a user
and i hashed the password but after i loged in there's a problem with upload files button in the page so why can i solve this?

otherwise i did and i suppmeted the flag using a metasploit module . but i'm still wondring how to do it manually

cold monolith
#

Hey!

#

has anyone here done the LFI/RFI module ?

#

i'm struggling to accomplish the final assessment

#

could anyone gimme some help?

feral gyro
slow venture
#

my rdp session for the windows server is too big and i cant get to the start bar, but it won't let me resize. How do you fix that? lol

#

ah ha found a work around

stiff tiger
viral slate
#

Hi all, I am completing the DNS footprinting section in HTB Academy and I cannot seem to get what they are looking for. I have tried enumerating subdomains using a variety of wordlists and a variety of command line tools. I can't seem to find the A record for the host that ends with 203. The hint states that not all wordlists are the same. I am stuck. Can anybody help me?

acoustic owl
#

Once you have found all the zones, you can play with the word lists to find the right one

viral slate
#

Thanks for the hint

acoustic owl
#

Have you found what you were looking for?

raven cairn
#

I need a nudge on a module. I've been stuck on the skill assesment for the linux priv esc module. Trying to get the contents of flag2.txt

#

The hint is "Users are often the weakest link..."

#

_< dont make fun of me for being stupid lol

west canopy
#

@raven cairn try looking at the .bash_history file for a clue

raven cairn
#

Now i just got to get flags 4 and 5 😭 . This module has many tricky questions.

slim lagoon
raven cairn
slow bluff
#

PowerView Module > Skills Assesment > Find a non-standard share on the ENUM2-DC01 host. Access it and submit the contents of share.txt. any help pls

slim lagoon
ruby sapphire
#

hey anyone mind giving me a hand with the 'hashcat' module question???

raven cairn
#

What section?

ruby sapphire
raven cairn
#

I dont have access to a computer right now but I am very familiar with the module so I will try to help

raven cairn
#

@ruby sapphire Yeah.

raven cairn
#

@livid pier @west canopy @rustic sage I’ve been trying to help this poor child on the hashcat section but I dont have access to a computer. Could you possibly help him out? I have to go to work : (

sullen hill
#

really stuck on the file upload assessment. straight up don't even know where to start. i've fuzzed file extensions and content-type headers but they all return the same page that says "Thank you for submitting your feedback". prettu sure it has something to do with the fact that these are GET requests now and the whole module was using POST requests, but honestly i'm missing something here or don't know that a technique i need to use is possible.

sullen hill
#

yep 0 progress so far.

feral gyro
rustic sage
west canopy
#

@ruby sapphire

ruby sapphire
#

Awh I didn’t have that rule set when I ran it

onyx wasp
#

hey can any one help me i m not able to connect to hack the box

lethal atlas
#

as long as you have an IP for Tun0 you should be good when you spawn a target

onyx wasp
#

i respawn my target many time but it's still not working

lethal atlas
#

what do you get when you run ip a

onyx wasp
#

ip or my local ip

lethal atlas
#

what module are you working on?

onyx wasp
#

Windows Fundamentals

#

this one

lethal atlas
#

which section?

onyx wasp
#

i was trying to conecte to windows target but ip is not working i respawn it many times and download vpns many times but still not working

lethal atlas
#

YOu have to use a remote desktop program

#

I used xfreerdp

onyx wasp
#

i used bro

#

but ip doesn't even not replying

lethal atlas
#

no it doesnt reply but xfreerdp connects just fine

#

xfreerdp /v:<Target-IP> /u:htb-student /p:Academy_WinFun!

west canopy
#

@onyx wasp on some targets ping will be disabled. Particularly on Docker targets

onyx wasp
#

docker

#

ooh yeahh i have docker in my system

#

should i stop it ??

west canopy
#

No, basically whenever you spawn a Target in a module, it will be either a VM or a Docker instance.

#

You can usually tell because it will be a five digit port number.

#

I have docker running on my own workstation too . it shouldn't affect anything 🙂

onyx wasp
onyx wasp
#

so wt should i do now

#

it's still not working

west canopy
#

Are you trying to connect with xfreerdp?

onyx wasp
onyx wasp
west canopy
#

Yea that doesn't look good lol

onyx wasp
onyx wasp
west canopy
#

First I would probably try and connect through the pwnbox to see if the error persists. Or maybe try respawning the target if you haven't already.

onyx wasp
#

and now it's not even pinging

#

it's stuck here

cobalt rose
onyx wasp
onyx wasp
#

and it's not it won't do anything spacial

#

but i tryed it and still same problem

lethal atlas
onyx wasp
#

i tryed

#

bro

#

i knew that command before u told me and i saw that command in that module too and i tryed it too many times

lethal atlas
#

and? you have never shown output from that command.

onyx wasp
#

this is the output of xfreerdp command

lethal atlas
#

ok sorry I missed that.

#

what IP do you have for tun0

onyx wasp
#

and yeahh one more thing

#

see this y docker is not getting uninstalled

#

??

#

docker command is working even docker is working but it is not showing any thing about docker if i use dpkg -s o dpkg --list

#

but when i locate then it shows docker files

#

even i purged it

lethal atlas
#

I dont mess with docker. but does apt remove docker not work?

onyx wasp
lethal atlas
#

you used auto-remove

onyx wasp
#

i think there is something wrong in kali 2021.3

#

yeahh i m still useing old version lol

lethal atlas
#

I havent experienced any issues.

onyx wasp
lethal atlas
#

well, I dont get a response from ping but I can connect with rdp soooo

onyx wasp
#

that's wired

#

i m not able to connect to rdp and not getting any responce from ping

lethal atlas
#

not really, its common for servers to disable icmp responses

west canopy
#

This might sound silly but I would try restarting your router. I had problems on Windows Priv Esc where it wouldn't let me download files to the target, but restarting my router fixed it.

lethal atlas
#

man if nothing else try it from pwnbox. I just did it there and it worked fine.

onyx wasp
sullen hill
#

dude this file upload attack module can kick rocks. either don't have the mime right, or i get a 500 error.

#

aaaaaand the server just timed out for the 4th time tonight... time to call it before this PC goes through the window.

onyx wasp
#

??

west canopy
#

@sullen hill I have notes on that module so if you're stuck feel free to DM me

lethal atlas
rustic sage
#

Good morning everyone ☕

summer lake
#

Hi is anyone done with Using Web Proxies module?

rustic sage
frigid summitBOT
#
zorder#7441 has been warned

Reason: Mass mention

#
zorder#7441 has been warned

Reason: Mass mention

signal topaz
#

Hey 🙂 I am doing the 'Web Attacks' module and I am kinda of stuck on the second question 'Bypassing Security Filters', it seems that in order to bypass I should change the http method, I've tried them all and only 'HEAD' does not return 'Malicious reqesut denied!' , but when I reopen the page the injection ('file; cp /flag.txt ./' ) is not working and there is no flag? any ideas

summer lake
#

I'm not sure how they manage to display the html content

rustic sage
summer lake
#

sure man

frigid summitBOT
#
zorder#7441 has been warned

Reason: Mass mention

#
zorder#7441 has been warned

Reason: Mass mention

astral siren
#

I am working on the file upload module, and i seem to be stuck on the content filter section. i can upload files, but none are interpreted as php code
edit: turns out it was working the whole time, i was just not trying the right thing to get a response

silk aspen
#

I'm working on the labs of the privesc module, in credential theft, I've found the file for the first question I think but it's not working, I'm pretty sure it's the right password tho, altready tried a reset

slender kayak
#

Hi all. I realize I'm asking this in a HTB discord, but is the academy worth it? I'm new to the site and HTB itself has been pretty good for me.

heady nova
#

you can enroll all fundamentals module for free (cost 10 blocks and unlock 10 blocks after finished and you have 40 blocks when you create your academy account)

slender kayak
#

Nice 🙂

rustic sage
west canopy
#

@slender kayak Definitely worth it

#

@signal topaz Dm me brother 🙂

#

@silk aspen feel free to DM too!

silk aspen
west canopy
#

Heck yea!

raven cairn
#

@sullen hill Verify bro :/

slender kayak
olive gorge
#

hi i working on the htb Academy modul http Request so the Question is "Send a GET request to the above server, and read the response headers to find the version of Apache running on the server? (answer format: X.Y.ZZ)" the answer must be 2.4.29 is in the get requst but it dosent accept it any idears?

west canopy
#

@olive gorge

olive gorge
humble trail
fathom bay
#

yeah, thm teaches the basics a bit better in my oppinion but htb academy goes more in depth

west canopy
#

THM is Super Mario Brothers, HTB is Dark Souls

slender kayak
#

😂

#

Is THM paid as well?

west canopy
#

Anyone have any ideas on how to troubleshoot this? I'm not able to import data into bloodhound.

graceful coyote
west canopy
#

@graceful coyote Ah Gotcha. Thanks for getting back to me. I was able to import it into Bloodhound on the Pwnbox, so only a minor obstacle 🙂

opal vapor
#

I have a question about the "Linux File Transfer Methods" part in the " File Transfers" Module. I have uploaded the .zip file to the target mashine with the following command: curl -v -F filename=upload_nix.zip -F upload=@upload_nix.zip http://<tatget IP>
After that I SSH to the target mashine, but I didn't found it. I looked up in the /var/www/html folder, but there wasn't anything and it looks like that the file isn't on the mashine. Has anyone any idea?

plucky nimbus
#

Anyone got time to help me out with the Shells & Payload module? Metasploit is throwing me errors and i wan't to see if its from my end or the exploit is just not working.

jagged zenith
#

Hello everyone any hint login brute force skill assessment service login

west canopy
#

@jagged zenith question 1 or 2?

jagged zenith
west canopy
jagged zenith
west canopy
#

Oh my bad

jagged zenith
west canopy
#

DM me

jagged zenith
#

I don't understand name user of an employee

west canopy
#

That confused me too. It's from the previous section:

#

You will want to create a custom username list, a custom password list with cupp, and then enforce complexity rules using sed

distant cradle
#

Why is the answer not correct?Module--> INTRO TO NETWORK TRAFFIC ANALYSIS
Section--> Interrogating Network Traffic With Capture and Display Filters
Questions--> What are the client and server port numbers used in first full TCP three-way handshake? (low number first then high number)

#

My answer: 80 53 443

kind turret
#

@distant cradle Isn't it supposed to be two ports only instead of three?

kind turret
#

The question reads so

distant cradle
#

doesn't work either

#

I think is bugged

west canopy
#

@distant cradle They are looking for the Port numbers used by the specific two machines that are connecting with each other. So one of them is going to be an ephemeral port, and the other would be something like 80 or 443.

ashen flower
#

I'm losing my mind here. I cannot use sudo because I do not know my password. I might just be straight-up stupid but I can't continue with these modules if I can't use sudo. Any idea where to find the password?

west canopy
#

@ashen flower Check the desktop for a credentials.txt file

ashen flower
#

@west canopy Thanks, brother

pearl torrent
#

anyone solved the nmap module hard lab can DM me and help me figure out what it is I am missing?

west canopy
#

@pearl torrent DM me bud 🙂

astral siren
#

anyone else stuck on the brute forcing assessment on the website portion:?

#

i've set the parameters and what should be the failure indicator, but i'm not getting anything

west canopy
#

Question 1 or 2?

astral siren
#

2

#

the one with the admin panel

west canopy
#

Check what I highlighted in burp suite, for the username and password the parameters are "user" and "pass", and then fail statement will be "log-in"

astral siren
#

yeah, that's what i have

west canopy
#

Does your command match mine more or less?

astral siren
#

ugh...i had the wrong url

manic zealot
#

Guys I need help.

#

Hashcat module, Working with rules section

#

I tried cracking the hash with correct rules and rockyou.txt but hashcat response with "exhausted" everytime.

astral siren
#

welp...i am not in the mood to do the password profiling part. so i'll pick this up another day.

west canopy
#

@manic zealot

manic zealot
#

@west canopy

west canopy
#

Yep your rule is a little off. You want to append 2020 to the example rule provided earlier in the section. So it's not just "2020".

manic zealot
#

Oh I see, thanks a lot man

limber elbow
#

pwd

limber elbow
#

nc

rustic sage
#

hello, I have some troubles with **SHELLS & PAYLOADS **, on the section Infiltrating Windows

#

and I have done 1/3

#

this are the questions

stiff tiger
#

Anyone help me with last question on BloodHound skill assessment: find the percentage of users with a path to Domain Admin? Thanks.

lethal atlas
rustic sage
livid pier
lethal atlas
#

and to get the answer for the third question you had to use the answer for question 2

#

so what exploit did you use to get the flag?

rustic sage
#

I closed my pwnbox, and I forget which one. Can I send you in dms later? @lethal atlas

lethal atlas
#

Yes

west canopy
vernal dagger
#

looking for a bump with intro to bash > Conditional Execution. Please DM me if you can and want to help.

plucky nimbus
#

Can anyone help me with this question on the Information Gathering - Web Edition module, i tried what the module says about nameservers but the servers im getting are not the answer

plucky nimbus
west canopy
#

@plucky nimbus

plucky nimbus
#

🤦‍♂️ 🤦‍♂️ 🤦‍♂️

#

I was just messing with nslookup and dig, thanks yet again xD

lethal atlas
ashen flower
#

I sent this to a friend of mine but I figured you guys could help as well.

#

What's going on with me unable to use vimtutor?

west canopy
#

@ashen flower try running: sudo apt-get install vim-runtime

ashen flower
#

Installed (properly?)

west canopy
#

Honestly i've never used vimtutor so I'm not sure what it's supposed to look like

ashen flower
#

Eh, its whatever I already completed the next module.

gloomy tangle
#

Hi there. Has someone finshied the module "FOOTPRINTING"? I am stuck in a few sections. Now in the section IMAP/POP3 with the question "What is the admin email address?" and find for a flag inside IMAP. any help? thanks in advance

acoustic owl
swift trench
#

Beginner level university student here; Working on the 'paper' box and have a few questions if anyone has any spare time to lend an ear. Much love!

west canopy
#

@swift trench you probably want to check out the "Boxes" room on HTB Discord if you haven't already (this room is primarily for discussing modules on the Academy platform.) Also I would suggest checking out the forums, there should be an official thread there for the Paper box 🙂

short viper
#

Hi, i'm sure this has been asked but I can't find it. Is there any roadmap detailing the timeline for when modules are targeted to be released? I'm looking into the job paths and I see a few interesting modules that are listed as coming soon but I'm not exactly sure what soon means in this case.

livid pier
#

like really really soon

short viper
#

Awesome, thanks

livid pier
molten cove
#

hi, can anyone give me a nudge for the following questions in the module, Active-Directory LDAP:
Credentialed LDAP Enumeration - What is the password history size of the domain? (How many passwords remembered.)
Skills Assessment last qn: What non-default privilege does the htb-student user have?

severe kernel
#

I love learning hacking, I didn't knew about htb academy but i recently found out they have courses...

#

I am already learning the Linux fundamentals course even though I know 60% of it...

#

What course should I do next?

feral adder
#

i am new to hacking i got this while i was roaming in discord. so, which courses should i do as a free user?

languid dawn
#

All the Tier 0 courses are free basically, so take your pick

signal topaz
#

yo 🙂 can someone check if I got the correct password list for the 'Skill Assessment - Broken Authentication' ?

slim lagoon
#

Hey guys, hows it going ? Can someone help me out with this? So Im trying to get the 'flag' folder from the user bob but when connecting I get this error message... can someone explain me what Im doing wrong ? 😄 thx

signal topaz
# slim lagoon Hey guys, hows it going ? Can someone help me out with this? So Im trying to get...

hey 🙂 you can check this video:
https://youtube.com/watch?v=tDbVw6uGx8g&t=345

00:00 - Intro
01:00 - Showing why we should run NMAP as root or sudo.
04:40 - Running nmap to see only SMB is open, start a full port scan and move on
05:45 - Enumerating SMB (Port 445) with CrackMapExec, SMBClient, and SMBMap to explore how each program works
08:20 - Running SMBClient to mount the share
09:20 - Installing CIFS-Utils so we can m...

▶ Play video
stiff tiger
slim lagoon
livid pier
west canopy
#

@molten cove DM me if you still need help with AD LDAP 🙂

rustic sage
#

hi to all/ Who can help me with module Cross-Site Scripting (XSS) - 'Try to use XSS to get the cookie value in the above page' I can't figure out what the link should look like. There is no example in the module itself, there is only a phrase that the task is similar to the previous module. But I don't have enough knowledge.
For a week now I can't find examples or resources where it is explained in a simple way. What is in the mind of the course developers if they give a task on tier0 that assumes knowledge of html, css, syntax?
http://64.227.39.88:31820/index.php?task=img src=/ onerror=alert(document.cookie) - how to connect it all without knowing the syntax?

west canopy
#

@rustic sage which Section is that from?

rustic sage
west canopy
#

Yes but which section

#

Stored, Reflected, DOM?

raw hornet
#

Hi, can you please help me with a question regarding the Academy Windows Priv Escalation section, in the SeDebugPrivilege exercise, the exercise is simple, but apparently in order to practice it, SeDebugPrivilege rights must be enabled for the user "jordan" and the guide indicates how, but to do it you must change the account to administrator, but I don't have that password, I should have obtained it from the previous numbers or something like that? Thank you.

west canopy
#

@raw hornet you should be able to use mimikatz to find the password hash for the sccm_svc account. It took me a few tries, i think i had to make sure procdump.exe , lsass.dmp, and mimikatz.exe were all in the same directory

raw hornet
# west canopy <@!753382900463829052> you should be able to use mimikatz to find the password h...

jarednexgent thank you for your answer, you are very kind, can you please clarify I understand that the idea of the exercise is to log in with the user "jordan" and of course you have that password, then run the whoami /priv command to verify that you have the right " SeDebugPrivilege " and continue with Mimikatz or am I wrong? because when running whoami /priv I only have "SeChange... and SeIncrease..." enabled

west canopy
#

@raw hornet Let me check it on my end. Give me a few minutes 🙂

west canopy
#

@raw hornet Try right clicking CMD and run as administrator

raw hornet
# west canopy

Correct I must assign as administrator, but I do not need a password for that?

west canopy
#

just use jordan's password

#

when you launch an elevated CMD shell you will see the SeDebugPrivilege

raw hornet
# west canopy just use jordan's password

oh with Jordan's ok, I'm going to try it, I really appreciate it, I was stuck so I thought I should have an administrator password for the exercise apart from Jordan's, again thanks for responding and helping.

#

You were absolutely right jarednexgent, thank you!!!!

#

bye I will continue with my exercises !

west canopy
#

happy hacking 🙂

rustic sage
west canopy
#

these things lol

rustic sage
# west canopy these things lol

Introduction to Web Applications. it has a theme about XSS injection. I'm sorry that I'm being stupid, I've just started studying, I haven't figured everything out yet

livid pier
west canopy
#

@rustic sage No worries dawg! I was confused too because there is a whole module just for Cross Site Scripting.

#

@rustic sage sent you a DM 🙂

slow venture
rustic sage
#

I am having problem with the module **SHELLS & PAYLOADS ** on the section PHP Web Shells and when i am changing the network proxy settings, I cant reach the targets ip

#

anyone that can help me?

#

i am using pwnbox

dapper flare
#

could anyone help me with the skills assessment in the SQL Injection Fundamentals module? i found a ||db.sql|| file with credentials in it but they won't work in the login page

#

i am on my kali machine

low vine
#

kinda driving me nuts been on this question for an hour Information Gathering - Web Edition Active Discovery And I'm Supposed to find CMS used for app.inlanefreight.local. I cannot for the life of me firgure out how i'm supposed to check that. I've tried whatweb etc and i just get nothing

#

someone kick me in the face and point me in the right direction but fuck this one has been so frustrating but i know this shits so easy

#

tilts me

astral siren
#

did you check the page manually?

low vine
#

cant connect to the page

astral siren
#

did you set the ip address in the hosts file?

low vine
#

do i have to?

#

(no)

#

what a waste of fucking time

#

im retarded

#

still not able to connect

astral siren
#

can you elaborate?

#

can you ping the host?

low vine
#

host unreachable

astral siren
#

you are trying to open web.htb. is that defined in your hosts file?

low vine
#

yes

#

thats what its defined in my host file

astral siren
#

does it match what's listed in the module?

#

are you connected to the vpn?

low vine
#

connected to vpn

astral siren
#

can you ping the ip address listed in the module

low vine
#

ughh i can try

#

but the "target' is what im trying to work with?

#

sec

astral siren
#

are you on the correct vpn?

low vine
#

yes

#

academy.ovpn

astral siren
#

did the target die? if it doesn't have the remaining time, you need to reset it

low vine
#

98 minutes left

#

i reset it like 15 minutes ago

astral siren
#

if you can't ping the ip address listed as the target, then idk what to tell you to do.

#

you could try disconnecting and reconnecting to the vpn

low vine
#

yea host is unreachable

#

okay lemme kill everything again

#

and rerun it

#

new ip still dwon

#

reconnected to the vpn as well

#

no connection

astral siren
#

what is the output of ip a

low vine
astral siren
#

why do you have 3 vpn connections active? that may be the source of the error

low vine
#

idk ive killed it a couple times

#

other then that no clue

#

how do i kill them?

astral siren
#

is this on pwnbox or your vm?

low vine
#

my vm

#

pwn box didnt work either though

#

so switched to my vm

astral siren
#

the same issue or something else?

low vine
#

same issue though I didnt put in etc hosts

#

in pwn box

astral siren
#

sudo pkill openvpn i think

#

or reboot

low vine
#

ok retrying

#

pings working

astral siren
#

so the rest should work if you fix the hosts file. make sure the ip address you have matches the target on the page

low vine
#

yea just changed and trying

#

still unable to connect through firefox

#

ip addresses both match

astral siren
#

is web.htb the dns entry it expects?

low vine
#

i thought that was just like our own labeling

astral siren
#

isn't it supposed to be something inlanefreight?

low vine
#

oh i thought it was just a lableing thing

astral siren
low vine
#

<

#

fuck im really good at wasting hours

#

on nothing

astral siren
#

yes, that's usually how this works

#

waste hours on something simple

low vine
#

so when you have multiple vhosts

#

how does it differentiate between the 2? So like we have 10.xx.xx.xx linked to both app.inlane and dev.inlane

#

how does it differentiate between naming

#

or its just like a reference to the "section"

#

you're supposed to be?

astral siren
#

when you send a web request, there is a host header that is sent. The http server (apache/nginx) routes that request to a different virtual host.

#

virtual hosts let you have separate web roots for discrete apps

#

you can't access websites with just the ip address when it is using a vhost. sometimes they might route 10.10.x.x to some sort of "default" host, but not always.

#

in this case, the server didn't respond because you were asking for web.htb and that isn't defined on that server. it's like getting mail without a "to" address

low vine
#

okay that makes sense

#

i just wasnt fully grasping what was going on thanks for the explanation

astral siren
#

yeah, no prob. i totally get where you got that idea, because sometimes it does work like that, but not when there are multiple sites on a single host

lavish needle
#

Hey can anyone give me a nudge for the Footprinting model - dns section? I'm on the last question for the section

signal topaz
signal topaz
dapper flare
signal topaz
dapper flare
signal topaz
acoustic owl
signal topaz
#

Can someone verify the password list that I am using for 'Skill Assessment - Broken Authentication' ?

signal topaz
#

Skill assesment

#

final one

acoustic owl
signal topaz
#

Does anybody have more info on this?

west canopy
#

@dapper flare

dapper flare
#

now everything works

calm hound
#

Hey guys, first time here for me, I was working on the sqlmap module and i found the flag of the skills assesment. The flag has the right format and is in the right place but is not accepted by htb, what should i do?

signal topaz
#

check for spaces or extra chars

calm hound
#

yeah already did

signal topaz
#

should have length of 24

calm hound
#

it has

#

the flag i found has a ) before } but there is no ( in the string, i don't know if its s typo, i tried to remove it or add a ( but does not work

signal topaz
#

hmm there are no ( or )

calm hound
#

i can send you a screenshot in pm

signal topaz
#

sure

#

send it

midnight dagger
#

hello hackas

junior steeple
#

I am stuck on the question "Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer." On the network enumeration module and I cannot get passed it. I am so confused how I am supposed to find the flag.

slow ruin
#

Having some trouble with Windows Privilege Escalation Skills Assessment - Part 1. I have the initial foothold on the target and was able to upload the exploit. Was also able to run the exploit but I am not receiving a shell with Admin privileges. A bit confused on where this shell is opening and how can I access it

frigid summitBOT
#
commander keen#7441 has been warned

Reason: Mass mention

#
commander keen#7441 has been warned

Reason: Mass mention

#
commander keen#7441 has been warned

Reason: Mass mention

languid fjord
#

nice

pine sable
#

Hii.
I have one little problem on Cracking Miscellaneous Files & Hashes.
I "reverse" the hash, but incorrect answer. Someone can help ?

#

||1########a||

livid pier
#

👋

tiny ledge
pine sable
dapper flare
#

hi i'm on the Skill Assessment on SQLi Fundamentals, i managed to bypass the login and now i'm trying to upload a webshell, the problem is that i don't seem to have permissions to write files despite the SECURE_FILE_PRIV value being empty. what am i doing wrong?

raven cairn
#

I've been having trouble with the skill assesment of the linux privilege esclation module. I need some help with the fourth flag.

#

The module says for me to look at the external services on the box. When i do a ps -aux, I see that tomcat is running.

#

But I don't know what to do from there. I am still a little inexperienced at some of this pentesting stuff unfortunately.

west canopy
#

@raven cairn

#

Once you log into Tomcat you will want to use a file upload attack to get a reverse shell 🙂

raven cairn
#

Wtf i haven't done the file upload attack module before

west canopy
#

Have you ran nmap against the target?

raven cairn
#

No. But I will.

#

Ok. So I ran an Nmap scan on the target and port 8080 is running tomcat.

#

I found out how to login to tomcat. I have never done a file upload attack. Could I have a little help with that?

dapper flare
dull robin
#

I'm having trouble using nmap with the spawned IP:Port for the getting started module. Do you guys know what sort of command I need to run to just be able to get nmap to work successfully?

dapper flare
dull robin
#

Okay yeah, that worked

#

Thank you

dapper flare
raven cairn
#

Could i still have some help on the file uplod atracj if anybody is availible?

west canopy
#

@raven cairn use msfvenom to generate a WAR file and then upload it

raven cairn
#

Ok. I will try to do that 🙂 . I’ll see how it goes

#

Also thank you @west canopy for always helping out : D

west canopy
#

of course brother 🙂

dapper flare
#

but it doesn't work

raven cairn
#

I was able to get flag4! Pretty difficult since I have never done a file upload attack, and because I had little familiarity with tomcat : D

west canopy
#

Heck yea, nice work!

dapper flare
#

could someone help me

#

pls

dark sandal
#

Any idea when Session Security will be released?

upper haven
#

hello,

im on the Attacking web applications with ffuf module > DNS Records, where im supposed to add a DNS record for academy.htb, although im confused on how to get hold of the IP?

could someone help me get me going? might be self explanatory.... but not for me atm

theres no target to spawn on this page

dull robin
#

I'll wait a few seconds to ask my question till this one gets a response

west canopy
#

@upper haven That section is mostly just explaining the functionality of the /etc/hosts file. You will be using it later in the module.

dull robin
#

I'm still stuck on the "Public Exploits" section of the Getting Started module, it seems.

I'm supposed to determine what services are running on the given IP & Port, find a public exploit, use it to gain access, and find the flag.

Well, the service for this appears to be "Apache httpd 2.4.41".

Msfconsole does not return any results for either 'apache 2.4.41' or 'httpd 2.4.41'. It returned results for unrelated Apache/http services I couldn't use. There was only one specific Apache exploit for 2.4.49 which fails to work ofc.

I turned to searchsploit, and I've found a handful of C or Python exploits for either Apache 2.4.41 or httpd 2.4.41, but they ended up not working. Mostly because the C programs I cloned to my working directory were absolutely riddled with compilation errors. xD

#

I'm left feeling like this spawned machine doesn't have any specific exploit I was supposed to find, with which it was tailored to be exploited.

west canopy
#

@dull robin try navigating to the target in your browser. You will want to target the wordpress plugin that is being used.

dull robin
#

I see. I'll try that then, and maybe try using some of the...um...

#

Oh the "web enumeration" commands i used for the last end of page challeng

west canopy
#

You should be able to find an exploit for the Plugin using msfconsole 🙂

ruby sapphire
#

hey anyone around to help me finish they last of the SQL ESSENTIALS module?!?!?! --- nvm completed!

slow venture
#

can anyone help me with the other files - windows priv esc module? Don't understand finding bob_adm creds

dull robin
#

I was close to getting the wordpress plugin exploit working, but I had to give up for the day. I think free users have a restricted number of times that they can spawn a machine instance for the module or something.

#

I kept resetting the box thing, as I kept trying to find a way to figure it all out, and so recently my browser is no longer able to connect to the provided IP address and Port. So I think I have to wait to try again tomorrow or something.

stiff tiger
#

Free users can run the pwn box for a few hours (maybe 3) and can only start the pwnbox instance once., but I think the target machines do not have a limit. I think you could download a vpn certificate and continue from your own kali instance on your local machine via vpn.

west canopy
#

@dull robin

dull robin
#

😮

#

I think my eyes completely glazed over the filepath option. I was setting the RHOSTS and RPORT options.

#

And if I tried the searchsploit for the Simple Backup exploit, I would get a text log of folder paths that I suspected were from my own computer, not the IP address', so I was confused there lol

odd shore
#

Can someone please help me find the size of the stack space, for module "Stack-Based buffer overflows linux x86", section "generating shellcode"

west canopy
#

@odd shore

odd shore
#

@west canopy 0x000fa doesn't work

#

@west canopy oh sorry, it's a couple sections after that one

west canopy
#

Derp, my bad . I was looking at the wrong section. One sec.

odd shore
#

@west canopy Ty!! that is from the command info proc all?

west canopy
#

Honestly brother I'm not sure, I did this module a while back and this all I had in my notes haha

#

I should probably revisit it. Still need to do the Windows Stack Buffer module and Intro to Assembly

odd shore
#

@west canopy Thats ok! I really appreciate the help!

sinful flower
#

how to get permissions on HTB: SERIOUS DISCUSSIONS channel?

west canopy
#

@sinful flower No clue dawg 😦

livid pier
#

@sinful flower you need to verify your account

slow venture
#

Hey can anyone help me with the interacting with users - windows priv esc module? Just want to make sure im doing it right cause nothing is happening

west canopy
#

@slow venture you need to put the SCF file onto one of the shares. I don't remember which one though, it might have been "IT" but i'm not certain. Then you want to have Responder running and it will intercept the hash

ashen flower
#

So, just a general question... I got done with Linux Fundamentals and I took a look at machines on HTB and it's still leaps and bounds ahead of me in experience necessary to solve. I'm just getting starting on this, and I have all these other "General" "Fundamnetal" "Tier 0" modules in front of me. Do I just randomly complete these? I saw that one of the modules mentioned taking notes, how much has that helped you guys with the retention of information?

livid pier
#

Start with the starting point machines, they have walk throughs if you get stuck. The machines are tough and will take a lot of time

#

Also make sure you take notes when you do a machine, structure them like the starting point walk throughs

ashen flower
west canopy
#

@ashen flower Before you start each module there is a list of recommended prerequisite modules. For example, on the Login Bruteforcing module:

#

Lots of people like CherryTree for notes. For live boxes on the main HTB site I usually use cherrytree. For HTB Academy modules I usually just make a Google Doc and copy/paste screenshots of the steps I did for each section

#

Personally, I started with Introduction to Networking --> Linux Fundamentals --> Windows Fundamentals --> Network Enumeration with NMap

#

But I would definitely recommend doing the "Fundamental" modules because the more advance ones might be a bit too much

ashen flower
#

Well... this is a little more involved than I had originally thought, and even then I figured this would be a little more than screw-around-until-you-get-it type of learning, like one might do with Photoshop or something. Thanks for the tips, I'm installing CherryTree now and I'll go through a few more modules.

west canopy
#

I mean you can definitely screw around just to have fun, and there's not a right way or wrong way to learn

#

But generally it's a pretty steep learning curve, particularly for people coming in with no prior IT background

ashen flower
# west canopy But generally it's a pretty steep learning curve, particularly for people coming...

Yeah, we'll see how it turns out. I've got a long road ahead of me if I have any hope to do this as a career, though I am a sophomore CompSci major, I haven't experienced much of anything that has been introduced to me these past few months in class. It's a matter of finding a path that works well for me now, as I am used to seeing this being built in front of me in real time. I would use the metaphor of a maze to describe pentesting as I currently understand it, moreso than building a structure, like in programming.

livid pier
#

I think htb could do better at providing a birds eye view of pentesting

west canopy
livid pier
#

It would be nice to understand the lay of the land in pentesting and understanding there are certain obstancles and tools on this path and understanding that is the object of the modules

#

currently it does feel like a maze or dark room.

west canopy
#

@livid pier True but I feel like no matter how they do it, it's going to kind of be information overload. The baseline knowledge required just to get started is vast.

ashen flower
#

I'm just a huge hands-on learner. If I could have a question or exercise for every single little thing that is taught to me, I would keep the information very well.

livid pier
#

If you have played zelda or skyrim(prob other games too) I like to think of the boxes like those dungoens

livid pier
#

In zelda you need certain tools to get a key in a room to unlock a door in another room, the boxes are like that

#

After enough boxes you will be able to formulate a map and compass that will help guide you

#

when you are new you waste a lot of time looking in places that an experienced player knows are useless

ashen flower
west canopy
#

Once things start to click though it's incredibly rewarding

livid pier
west canopy
#

Link's Awakening on Gameboy was my jam

livid pier
#

But ya like @west canopy the information needed to start here is crazy

#

you need to know operating systems, and languages, and services

ashen flower
#

The level of quality over quantity when it comes to resourceful YouTube videos seems to be lacking as well, though I am tempted to start looking at these 3, 5, 15-hour long freeCodeCamp tutorials for linux, ethical hacking, etc..

west canopy
#

Linux proficiency is a must

livid pier
#

and use ippsec.rocks

ashen flower
#

Oh wow.

livid pier
#

Hack tricks would be a good way to structure your notes too. Everything you learn from doing a box you can put in a set of notes to refer to later

ashen flower
#

Just when I thought asking in this channel would taper some of the information overload... 😂 Im just kidding. Thanks so much for the help you guys.

livid pier
#

just take your time, set goals and be persistant, it will start to click

#

Try to reflect and not forget about the big picture either

ashen flower
#

The way I am with anything with a real learning curve is I just need to find a way to have fun with it. I'll be honest, reading walls of text on HTBAc modules is not my cup of tea, though I am in a limbo of not knowing enough to complete these easy boxes on my own yet. When I can make those connections I'm sure I'll have a lot of fun with it

livid pier
#

I think the amount of text on htb academy cant be worse than the text books in college

ashen flower
kind path
#

module: INFORMATION GATHERING - WEB EDITION
content: Active Infrastructure Identification
question: Which CMS is used on app.inlanefreight.local? (Format: word)
is there any problem with the ans, I am giving right ans but still it says wrong !!!

stark tapir
#

module: Footrpinting/MSSQL
content: Connect to the MSSQL instance running on the target using the account (backdoor:Password1), then list the non-default database present on the server.
question: Can't connect with backdoor:Password1. And can't connect by bruteforcing passwords with some common lists. Can you give me a hint about what password list should i use?

acoustic owl
stark tapir
#

i missed -windows-auth

#

thx!

livid pier
west canopy
#

@kind path sent you DM dawg 🙂

gilded palm
#

194.613.716.24

lapis canyon
#

Need help with first question in "OSINT: Corporate Recon" module. Question asks for coordinates for a city in Germany. I know the city, but can't find one specific set of coordinates for the city in Google / Google Maps. The hint didn't help.

raven cairn
west canopy
#

Haven't gotten to the OSINT module yet , looks pretty tough

livid pier
raven cairn
raven cairn
#

The coordinates that you find on google do not work.

west canopy
#

Maybe the tectonic plates of the earth shifted the geographic location of the city

raven cairn
#

Maybe. I know the coordinates for the USA location worked…

#

How should i contact staff just to double check?

cobalt night
#

Hi everybody, am I in the right section to ask about Tier 1 VIP bascis labs?

odd shore
#

"Stack-Based Buffer Overflows on Windows x86" - "Finding a return instruction"

#

76FDD627 does not work as an answer

west canopy
#

@cobalt night If that involves HTB Academy modules then yes!

#

Or is that the Starting Point labs on the main site?

past glen
#

hi, i get a trouble in a module of web request

#

can i post it here to get help?

covert tusk
#

I'm stuck on the skills assessment for sqlmap essentials. I think I found the attack vector but everything I throw at it isn't working. Can anyone find what I'm missing?

west canopy
#

@covert tusk DM me brother 🙂

simple merlin
#

Module : OSINT
Question : What is the hosting provider for the inlanefreight.com domain?
I'm struggling with this one, I guess that I have the good hosting provider, but I don't have the good format ? Help would be appreciate

past glen
#

im the module "web request", i get stuck here bc when i execute cURL, theres no flag that i can see

#

i use the devtools to see the "search.php" but when i open it with cURL, i dont find any flags. i "login" with the credentials btw

west canopy
past glen
#

in my devtools doesnt appear that flag, idk why

#

imma try again rn

west canopy
#

Yea try refreshing it

raven cairn
#

I am so close to finishing the linux privilege escalation module. I am needing help on the fifth flag.

#

I've been trying to exploit this command on GTFO bins and it hasn't been working for me. If i could have some hints it would be greatfully appreciated since I am getting very frustrated with the module.

#

Am i looking at the right thing?

west canopy
#

@raven cairn You need to upgrade your shell first

#

After that the GTFOBin should work 🙂

raven cairn
#

@west canopy tysm

#

Lol that was a very easy fix. 🤣 I kinda forgot about upgrading the shell

west canopy
#

I like how the terminal spazzes out once you run the command

raven cairn
#

Yeah I was not sure I was running the command right lol

west canopy
#

Terminal has a stuttering problem

rustic sage
#

Could anyone help me with the proxy section of the bug bounty course. The instructions say to use https in the configuration file for proxychains. That isnt possible, it doesnt accept https. If I just use http I get the following, Im stuck. Google search isnt helping. Found the same issues, but only suggestions when using TOR with proxychains

west canopy
#

@rustic sage Which module is that? It doesn't look familiar to me.

rustic sage
#

Using web Prroxies for the bug bounty course

west canopy
#

This module?

rustic sage
#

yes

#

under the proxying tools section

west canopy
#

Sorry for the dumb questions . I don't remember using proxychains at all so just wanted to double check my sanity

rustic sage
#

No worries, if you can figure this out Id owe you one lol

west canopy
#

I think on this section I mostly looked over that part and just went straight to the question at the end of the section

rustic sage
#

I could do that, but I really wanna be able to route nmap/curl/ etc through zap Dx

#

Wait, how did you route metasploit through burp without proxychains?

west canopy
#

This is one of the modules I did before I decided to start taking good notes. I actually have no idea lol

rustic sage
#

Dx lol

west canopy
#

I think I actually just ended up guessing, based off the Options shown for the exploit in msfconsole

#

I'm also not understanding how to route the traffic through burp 😦

#

Maybe something with the "Proxies" option for the exploit. Like route it through 127.0.0.1:8080.

rustic sage
#

In the older version of proxychains we could just put https 127.0.0.1 8080. The new version of proxychains doesnt allow https. Just http socks4 and socks5. Im messing with the connections options in zap, but I really dont know what I am doing lol

#

Think I need a refresher on networking xD

rustic sage
#

ok I figured it out, and Ima make a guide on this tomorrow. Its a certificate issue. Even though I have zaproxy cert setup with mozilla, that isnt enough for curl. I can bypass it using -k, but Im going to symlink the cert tomorrow. I am tired now. I did manage to get the request to show up in zap though. Thats enough progress for me tonight. Im going to sleep, gn everyone!

#

Ill figure that out later xD... gn

west canopy
#

Later dawg!

raven cairn
#

Anybody still here? I am almost finished with the linux privilege escalation module and I have been having some troubles!

#

In the module the C code that they give does not work. I am not super familiar with C so I do not know how to fix this.

#

Obviously the problem is that the function 'system' has not been declared.

west canopy
#

Which section is that?

raven cairn
#

It is under miscallaneous techniques

west canopy
#

Oh you actually don't need to do that. You can just navigate to /var/nfs/general to find the flag

#

I actually had problems on the very first section "Kernel Exploits", i had to remove a line of code at the bottom of the exploit to get it to compile. GCC is weird.

raven cairn
#

Yooooooo. I FINISHED THE MODULE

#

I AM GOING TO CRY

west canopy
#

I am proud of you bro you're doing awesome

raven cairn
#

The instructions on that section were a bit confusing lol.

raven cairn
west canopy
#

Now you gotta do Windows Privilege Escalation

raven cairn
#

Is that one gonna be hard?

west canopy
#

Not gonna lie to you dawg lol

raven cairn
#

Why didn't this module teach me linpeas

west canopy
#

It's a beast

#

like 30+ sections

#

two skills assessments

raven cairn
#

I really need to start taking better notes so i can help out people more : (

west canopy
#

Honestly with LinPeas i can maybe understand like 5% of the output it gives lol

modest moth
#

need a little nudge on the SQLMAP essentials module. im currently at "bypassing Web Application Protections"
I am trying to run the --csrf-token flag with sqlmap but i am stumped on how to retrieve a token

west canopy
#

@modest moth which Case #?

modest moth
#

#8

west canopy
#

So unfortunately this is another module I did before I decided to start taking good notes. But here is the command:

modest moth
#

omfg

#

im so mad

#

so i intercepted the requests

#

and i got t0ken

#

i thought i was looking for a fucking value

#

i used burp to intercept it and i knew i had t0ken, but i thought i was looking for an actual token to throw into --csfr-token flag

west canopy
#

I rode the struggle bus hard on this module. I should probably revisit it. I think this is the only module I left a negative review on.

#

I felt like I was just copying/modifying examples in order to find the flags, and I really had no idea what was actually happening

modest moth
#

super hard for me to get all the info while just reading. i might just read the rooms out loud and record it

#

to relisten to them

#

i do a lot better with audio vs reading

#

i literally had the entire command right, but for --csrf-token flag, i was entering a token value form the previous request.

west canopy
#

Yea you were right there man

mortal basin
tiny ledge
#

Is the answer not an IP-address here? Hmm cant post a pic here

#

Utilizing the output shown in question-1.png, who is the server in this communication? (IP Address)

#

This is the TCPDump fundamentals module

rustic sage
#

how to get on topStonks

shadow mist
#

Need direction for Nmap enumeration course: Firewall and IPS/IDS Evasion - Hard lab
I found the sun-answerbook port , it seems like a database that fits the hint by HTB, but I have no idea how to reveal the version even using -sC, -sV, -sS

slow ruin
#

Working through Windows Privilege Escalation - Part II and stuck on trying to find a NTLM hash of the disabled local admin user. Is there a way to check in windows what systems a user is able to interact with?

acoustic owl
shadow mist
stiff tiger
acoustic owl
west canopy
#

@tiny ledge

errant sleet
#

Guys, need help with lab 2 (medium) footprinting module

eternal rover
#

Dumb question but how do I unset proxies in metaaploit used "set proxies" but can't seem to undo it

misty remnant
#

hi, I have a problem with the Information gathering module. I am on the Active Infrastructure Identification page. Can anyone help me there please? So for the questions

west canopy
#

@eternal rover I think it's just "unset proxies"

eternal rover
#

Tried that but still flags as unable to run the exploit as the proxy is set, I think I'll restart metaaploit and force it through and see how it behaves, thanks

west canopy
west canopy
#

@misty remnant Feel free to DM me 🙂

balmy creek
#

hi guys i have a problem with the end of web enumeration

#

i use ping to check the ip target and i dont have response

#

i made it!!! hahaha its a problem with the ip target

simple merlin
distant cradle
#

Module--> INTRO TO NETWORK TRAFFIC ANALYSIS
Section--> Interrogating Network Traffic With Capture and Display Filters
Questions
Answer the question(s) below to complete this Section and earn cubes!

  • 1 What are the client and server port numbers used in first full TCP three-way handshake? (low number first then high number)
    My answer is 80 43804
#

🤔

west canopy
#

@distant cradle

#

the 80 / 43804 conversation is not a complete three way handshake

distant cradle
west canopy
#

New module out boys!

raven cairn
#

Let’s gooooooooooo

astral siren
#

I'm trying to do the broken authentication module. I am stuck on the predictable token part, and i had a working script, and validated that the user level token worked, once, but stopped

#

unless by some miracle i got an md5 hash collision

west canopy
#

Haven't done that module yet 😦

astral siren
#

ok, i ended up getting it. resetting the lab seemed to fix it? bizarre that my script worked once, then failed for > hour, then started working again

west canopy
#

I was having problems with Attacking Common Applications, there was a section where you had to use a script to bruteforce Gitlab users but the target kept disconnecting.

#

So my script never finished

astral siren
#

i didn't have any trouble with that one

#

were you able to get it

west canopy
#

I was eventually

#

Just had to take a break and come back to it later

bronze coyote
#

hey guys, probs a stupid af question but in "Web Requests", specifically the GET section, I cannot figure out how to get this answer, anyone have any like tips or what I've gotta do?

west canopy
#

@bronze coyote

bronze coyote
west canopy
#

Any time brother 🙂

glass locust
#

Hi guys, try to contact HTB via the support bubble to talk about student subscription and don't know what to choose? Can anyone help?

rustic sage
glass locust
rustic sage
#

npnp

astral siren
#

I am continuing to struggle with the broken authentication module. i'm on the skill assessment, and I found 2 different hashed values. one i know how to decode, but can't get any valid responses with the wordlist i'm using, and the other i have no idea. can someone validate whether i'm on the right path?

acoustic owl
#

@astral sirenfeel free to dm me

rustic sage
#

can somebody help meee !!!

#

???

acoustic owl
#

What do you need help with?

rustic sage
#

To get the flag, use cURL to download the file returned by '/download.php' in the above server.

#

how do you do this question

#

@acoustic owl

acoustic owl
# rustic sage how do you do this question

If you need help, it is always useful to specify the module and the corresponding question. No one here knows which module you are working on, let alone which question you need help with.

rustic sage
#

HyperText Transfer Protocol (HTTP)

#

web fundamentals

#

@acoustic owl

acoustic owl
#

You mean Web Requests?

rustic sage
#

yes!

#

can you help me or no

acoustic owl
#

yes, i can help you.

What have you already tried?

rustic sage
#

much

#

but

#

i dont now

#

i have a target and i dont now what i have to do with it

acoustic owl
#

The task is to download a file with curl.

This is how you can download a file.
curl http://10.10.10.10/file.txt

Adapt the path to your needs.

#

Maybe read the part cURL again.

rustic sage
#

ok i will try

#

what do i have to do wth teh 10.10.10.10£

acoustic owl
#

You can use any IP address or domain instead of 10.10.10.10.

rustic sage
#

but what do i have do do with the target

#

157.245.37.27:32517

acoustic owl
#

You need to download the flag.

rustic sage
#

but this is teh question : To get the flag, use cURL to download the file returned by '/download.php' in the above server.

acoustic owl
#

Exactly. You should download the flag on the given IP address (target) with cURL.

#

Familiarize yourself with cURL. You will need it again and again.

rustic sage
#

but they say you have to do it like this

acoustic owl
#

no, the question is
To get the flag, use cURL to download the file returned by '/download.php' in the above server.
HINT: The downloaded file will be called 'download.php' and it will contain the flag

rustic sage
#

yes but in the theorie above

#

it says nothing about the things you sended

acoustic owl
#

The questions want to know if you have understood the content of the chapter and if you are able to apply what you have learned.

rustic sage
#

this is the first page of the hole capter

acoustic owl
#

Here is an example explaining how cURL works

#

Exactly what I wrote to you

rustic sage
#

okay yeah true

#

Its okay thanks a lott

acoustic owl
#

Did you make it?

#

Get well acquainted with the tool. You will need it again and again.

astral siren
#

does anyone else have an issue where the docker hosts take >5 minutes before they actually respond to requests

west canopy
#

@astral siren Nothing like that on my end , typically for me a docker target will either spawn almost instantly or not spawn at all .

astral siren
#

anyone done the web attacks module? i cannot get the xxe to work on advanced file disclosure. i am recieving the request for my xxe file that i'm hosting, but i'm not getting any output

#

i've got the flag, but i don't understand why i couldn't get the page source

west canopy
#

This is what I have in my notes

astral siren
#

i was trying to do the cdata one

#

again, i got the flag with both, but i wasn't able to get the source like in the example. i was trying to figure out if that was by design or not.

astral siren
#

any details on when these modules will be released?

west canopy
#

Next week i believe

languid ginkgo
#

Hello all,
In the "Procedures" chapter of the "Intro to Assembly Language" module,
I want to respond at the following question"
Try assembling and debugging the above code, and note how "call" and "ret" store and retrieve "rip" on the stack. What is the address at the top of the stack after entering "Exit"?
I proceed at following actions:

||I launch gdb with the assembler.sh script and I write "b *Exit+0" and "run"

Is my actions bad ?||
Solved 🙂

west canopy
#

@languid ginkgo Wish I could help dawg but I haven't done that module yet 😦

modest moth
#

@west canopy just finished the skill assessment for sqlmap. Thanks for your help with that one room.

Halfway done with the big bounty path and I'm def feeling a lot more confident and comfortable. Might start doing some boxes on the main website.

tacit lichen
#

Hello All!
I'm having a problem with the last part of the "SHELLS & PAYLOADS" with the 2nd host , who has done it ?

lethal atlas
#

I have

silk aspen
#

Need a little sanity check for Windows Privesc skills exam, I'm going crazy

lethal atlas
west canopy
#

@silk aspen DM me dawg 🙂

ashen orbit
#

Hey everyone, new to the HTB world. Software engineer by day, trying some HTB at night, going through the bug bounty path at the moment

stiff tiger
ashen orbit
#

So going through the HTML injection section and the XSS injection section, when I inject the html or javascript, isn't that only pertain to your PC, how is that userful?

west canopy
#

@ashen orbit if a website is vulnerable to Stored XSS then it will affect any user who browses to the page

round lagoon
#

ok i'm losing it w/ this Recursive Fuzzing section, adding more extensions & whatnot but to no avail

west canopy
#

@round lagoon My bad, this should be it

unique valve
#

You all should know that your commitment to learning and lifting each other up in the process is inspiring.

unique valve
#

Also keep in mind that growth doesnt always feel good. Personally when im learning something new I feel driven but overwhelmed by the new information mostly. Keep studying and practicing until it makes sense. Most of this wont be easy at first until one day you’ve practiced so much it becomes muscle memory. Its also healthy to remember where you were when you started, thats often when you’ll recognize you’ve grown. Not in the process but upon reflection. I keep a learning journal that I add to on occasion to just write down what Ive learned and accomplished. Keep going, stay focused, and have fun.😁

livid pier
#

The freshie

west canopy
#

I think new modules next week too

jaunty patrol
#

My Timer is going super fast it goes from 90 minutes to 74 in 3 minutes

#

is that a bug?

coarse cypress
livid pier
jaunty patrol
#

and if anybody could help with Login Brute Forcing Skills Assessment - Website I would be really happy

languid ginkgo
kindred prism
#

Needing some help with the Web Requests POST section where the question is "Obtain a session cookie through a valid login, and then use the cookie with cURL to search for the flag through a JSON POST request to '/search.php'" I am not entirely sure what the question is asking for an answer. I have the cURL command as curl -v -X POST -d '{"search":"london"}' -b 'PHPSESSID=1uhh6r3jlcj9cuknra0da02i4v' -H 'Content-Type: application/json' http://46.101.61.42:30757/search.php thanks in advance

astral siren
#

could someone dm me about footprinting - dns? i want to check that i have found the correct zones

unreal patio
#

I'm stuck at this question in Linux privilege escalation, I found a bunch of files with a setuid bit not shown in the section command output but it are so many and the first ones werent working and I feel like putting them in all by hand is not the right approach, can someone dm me or give me a pointer?

west canopy
#

@jaunty patrol DM me if you still need help on Bruteforcing 🙂

#

@unreal patio

unreal patio
#

@west canopy Thanks for the solution but I have no clue what I did wrong

buoyant veldt
quick raven
#

on a parrot vm I use openvpn academy.ovpn to connect to academy : from there I could curl a phpfile , and execute remote code (in an uploaded php file). apparently on my vm, I don't have a tun0 interface , how can I have a reverse shell call me ?

west canopy
#

@quick raven hmmm if you are connected to the vpn then you should have a tun0 IP address.

ashen sage
#

Hi guyz, Im new to hack the box and hacking all in all, I've never done any hacking in my life and so I wanna learn but I dont know exactly where to start, can u tell me where I can learn and may it be a free site if possible cz I dont think I'll even be able to hack the first box on HTB .

quick raven
#

open hackthebox academy, and follow getting started

west canopy
#

@ashen sage Yes, check out the "Fundamental" modules on HTB Academy

ashen sage
#

Thank u guys lemme check it out right now

quick raven
#

I dont get it : not tun0 created when I invoke openvpn aca.ovpn shout I use sudo ?

#

hum with sudo it seems better

#

got it this time tun0 maybe I can finally receive the callback

west canopy
#

@quick raven If i don't use sudo the vpn doesn't connect for me , so it's likely that was the issue

raven cairn
#

I need some help on the XSS module, Phishing section. The instructions aren't very clear to me of the section.

rough elm
#

@ebon wigeon google @raven cairn name

raven cairn
#

🤩

pine garnet
#

anyone else can't ping maschines even though connected to the vpn?

halcyon copper
#

Hi, what is the password for the sudo command please ?

raven cairn
#

Verify!!!!!!

#

@halcyon copper look for credentials.txt on the desktop . Then verify

west canopy
#

@raven cairn

rough elm
ebon wigeon
# ebon wigeon no

@urban sage that name should be banned from this server , fucking degernates @raven cairn

#

google what it is

raven cairn
#

You dont like Yaoi ?@ebon wigeon

ebon wigeon
#

No, im not a degen

rough elm
rough elm
hidden junco
#

hi

raven cairn
#

@west canopy Just did it! The instructions were overly convuluted so it was hard to understand lol.

west canopy
#

Nice! Yea I think it took me a while to figure out what I was doing on that section

ashen orbit
#

Going over the Introduction to web applications even though I just built a web page and api, might be a nugget of something I don't know haha

#

I did learn that firebase is a nosql solution

west canopy
#

@ashen orbit Get it big dawg!

ashen orbit
#

Sorry, for another newb question, but is hack the box login credentials different for academy and the normal hack the box?

jaunty patrol
#

Need Help With
Parameter Fuzzing - GET
if Anybody is available I would be happy

west canopy
#

@jaunty patrol

jaunty patrol
#

I had too many echos facepalm

west canopy
ashen orbit
#

I'm staying in the academy as I have no clue what is going on in Hack the box to try one haha

west canopy
#

I would definitely recommend knocking out a few modules before attempting Live boxes

raven cairn
west canopy
#

Kind of hard to say because every box is different

#

I really liked Windows Privilege Escalation , i was able to immediately use one of the techniques to beat the "Driver" box.

raven cairn
#

I am struggling on the XSS-module, section: session hijacking. They tell you to try different payloads. I have been trying a bunch of xss payloads and none of them have been working for me. I have made sure that my XSS payloads connect back to my php server.

west canopy
#

The payload will be one of these formats:

raven cairn
#

I know : ( . For some reason none of those have worked for me? Might be doing something wrong?

#

I was using those payloads

west canopy
#

I think it's this one

raven cairn
#

Do i need to specify a port number?

#

Ok i will try that

west canopy
#

Not if your php server is using port 80

raven cairn
#

Awesome. The payload worked. I tried so many of those payloads. 🤣

undone shale
#

Hi everyone, please give a suggestion for service enumeration section in nmap module. I have tried nc -nvl ... to listen to the server, but i couldn't find the flag.

west canopy
#

@undone shale you don't want to use the -l option. Try just netcatting directly into the highest port that you scanned earlier.

undone shale
#

Thank you @west canopy

west canopy
#

Of course brother 🙂

#

the -l option basically opens up a "listening" port on your own machine. But the server isn't going to connect to you automatically. Typically you will use a netcat listener in the case of a reverse shell, where you would upload a malicious file or run a command on the server that makes it connect back to you.

vital adder
#

can anyone help me with this question "What group type is best utilized for assigning permissions and right to users?" from INTRODUCTION TO ACTIVE DIRECTORY section Active Directory Groups

vital adder
#

i think this question have a bug i try every groups even Security groups

quick raven
#

I have a (text) meterpreter shell on my target, how do I get a normal shell ?

vital adder
quick raven
#

yea I used help then shell, now I have a strange shell with no prompt

vital adder
#

is your target windows or linux

quick raven
#

linux

rustic sage
quick raven
#

yes

rustic sage
#

Try upgrading it.

quick raven
#

sudo -l say everyone can use /usr/bin/php

rustic sage
#

@quick raven Yes. But do you have maybe python on the system? whereis python

quick raven
#

apparently there is python 3.8

rustic sage
balmy creek
#

hi guys do u know if the platform is down? couse i`m stuck in PUBLIC EXPLOITS, getting started module, the question is "Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)" but i ping to target ti check connection and it shows me "ping: 134.209.191.224:30130: Name or service not known" i have reset the target many times and keeps showing that error, i have 3 days trying

#

if anyone know how can i do, please help

autumn pilot
#

you are trying to ping a host with it's port which is not done with the command you have used

#

and my next question is how do you ping a port

balmy creek
autumn pilot
#

no problem

west canopy
red obsidianBOT
kindred prism
modest moth
#

@west canopy you have any recommendations for a good laptop to throw kali or parrot onto? ive been using virtual boxes for a while now but want to just throw the OS onto the hardware and have a laptop dedicated to either OS. budget is around 1100-1500.

west canopy
#

Honestly brother , literally everyone I know who has ran Parrot on bare metal has encountered all kinds of weird technical issues. Personally I just use a Kali VM.

modest moth
#

i have this beater asus ive been using as a kali machine, but it just crashes and dies every couple of weeks, ive reimaged it about 6 times in the past couple of months.

west canopy
#

I am on a windows 10 laptop and it has literally never crashed. Sometimes my VM will sh*t the bed but I take lots of snapshots so I just end up rolling it back.

modest moth
#

damn thats honestly a better idea, shouldve thought of that haha. i do that on my desktop, idk why it hasnt crossed my mind to do that for a laptop

#

just got to get in the habit of taking more snapshots.

#

how much storage you working with?

west canopy
#

You would think bare metal linux would be a more stable OS, but from my experience that simply is not the case

modest moth
#

I know! thats what i figured, but working with the asus, it isnt stable at all

west canopy
#

I have 12 Gigs of RAM , and on my VM i give it about 8

modest moth
#

ram isnt an issue, ill just steal 2 16 sticks from my job lol.

#

do snapshots eat up storage?

west canopy
#

Only 1-2 gigabytes

#

of disk space

modest moth
#

oh wow not even a lot ok. thanks. ill just look into gaming laptops. thanks

raven cairn
#

I use a lenovo T430z It is a bit big but it works like a charm.

#

Lenovo also has excellent linux support

modest moth
#

oh nice didnt know that

#

just want a laptop that doesnt keep crashing on me lol

#

its been annoying because ive lost a collection of tools ive downloaded from github

#

atleast all my notes are on onedrive

raven cairn
#

This is my opinion. Hacking is usually not going to be to intensive on a computer (unless you are cracking hashes)

livid pier
#

or if you are running an android emulator on kali

raven cairn
#

cough cough routerspace 😭

livid pier
modest moth
#

wtf happened lol. i was just about to hop on and do the routerspace machine lol

raven cairn
modest moth
#

wow, cant wait to give that a go when i get home haha.

raven cairn
modest moth
#

yea

#

that one was very easy. did it in about 30 mins

raven cairn
#

Nice!!

modest moth
#

from enumeration to hacking it.

#

rooting it was easy. im getting excited because i feel a lot better than i did 2 months ago. i dont feel overwhelmed going into a new machine

raven cairn
#

Im pretty new to htb. I started like a month ago? lol

modest moth
#

working as helpdesk right now, REALLY want to get into security. hoping to take the OSCP within a year. im down to do some retired machines together sometime.

wise pike
raven cairn
#

I’m at a university and they don’t teach anything about cybersecurity 😭

#

I Really, really, want to be a pentester.

#

I just love to test pens so much

modest moth
# raven cairn I Really, really, want to be a pentester.

Yea I was at uni for comp sci but felt like I wasn't learning as much. Got my net+ and sec+. Got an it job as a 2nd year and dropped out. I might finish it in the future but just with 2 certs, I learned more than I did in 2 years of uni