#modules

1 messages Β· Page 516 of 1

lofty kindle
#

Hi, maybe can you help me? I have a question about cracking common hashes of module Cracking Password with Hashcat

rustic sage
#

If I'm doing the modules, should I write the important parts in a notebook or should I use the softwares provided in the learning module of the Academy?

west canopy
#

@lofty kindle DM me πŸ™‚

lofty kindle
#

@west canopy ok, inbox

unique valve
# rustic sage If I'm doing the modules, should I write the important parts in a notebook or sh...

I agree with @livid pier. Everyone has their own thought process as they take notes. Id save links, tools mentioned and be sure to download the cheatsheet for each module. These can help you in the industry and on other parts of HackTheBox. At some point it may be challenging to keep everything in your head, so you can keep a document that you can easily search through to find tools you need for a given situation.

#

It can also be good to practice doing formal writeups, and attempting to explain what you did from the offensive and defensive side.

west canopy
lethal atlas
balmy creek
#

hi guys im stuck at this question "Once you gain access to 'user2', try to find a way to escalate your privileges to root, to get the flag in '/root/flag.txt'." in Getting started privilege escalation, i use the linpeas.sh, i get the ssh private key but i cant conect with it

#

i check the id_rsa with vim many times but i don get it what is wrong

#

if anyone can give me a hand please

west canopy
#

@balmy creek Try SSHing as root instead of user1 , using the id_rsa key. The first time it will give an error. Then do a chmod 600 on the id_rsa key, and try to connect again

balmy creek
west canopy
#

after chmod 600 it should be -rw------

#

I will say however the last time I tried this section I was not able to get it work , despite reproducing what was in my notes .

balmy creek
#

i had tried with 600 but it gave me an error and I tried to imitate it with 644, which is how it came out in the linpeas

stark atlas
#

Anyone able to help with the Footprinting module, IMAP/POP

hybrid fable
#

Hello

hybrid fable
#

Can anyone help
I have been trying to install kali linux on my MacBook

But having issues virtual box

Always showing this
''Unsupported hardware
architecture detected!
The installer has detected an
unsupported architecture. VirtualBox
only runs on the amd64 architecture.''

And i have also tried VMware it's saying i can't install because my Mac is not running on Apple silicon.

I will be very happy if anyone can help me out on this i haven't try to install for so long

Thank you all and God bless you all

#

What my VMware is saying
''This version of VMware Fusion is
for intel-based Macs, but is
being run on an Apple silicon
based Mac via Rosetta-2.
A
See KB-84273.''

#

@here

astral siren
#

that error is telling you that your mac is not x64 or x86, and so you need a version of virtualbox or vmware that is compatible with apple's processors

#

at least, that's my interpretation

raven cairn
#

I am having problems with the login brute forcing module , skill-assesment website section. I've been stuck on this module for some time.

#

Specifically because the password hydra gives me doesn't work

raven cairn
#

What is wrong with my second command?

urban valley
#

can someone explain the difference between kerberos and LDAP? they both seem similar since they are used to authenticate for AD

west canopy
#

@urban valley Kerberos is more or less "single sign on" for AD environments

#

@raven cairn DM me πŸ™‚

raven cairn
#

@west canopy I will. I have to do some college stuff and then I will dm you.

unreal sigil
#

somebody plz help lol

#

how is this wrong

#

I realize that's not the flag but I feel I did exactly as the instructions stated and that's the only response I got

west canopy
#

@unreal sigil Assuming you went through all the steps in the section, you will need to delete HTB_City and HTB_New_City

#

Then after renaming a city to "flag" you should be able to curl it and find the answer

unreal sigil
#

Okay I added that now too, still no flag 😭

#

oh , new city

#

got the flag lol ty

trim solar
#

hey, has anyone done object machine?

#

i need help

west canopy
#

@trim solar This channel is for HTB Academy modules . Is "object" a live box?

west canopy
#

Ah gotcha. Not sure if there is a Discord channel for retired content. You could probably find a write up online somewhere though πŸ™‚

trim solar
#

ohk thanks

lethal atlas
#

dm me and I will help you

rustic sage
#

Hi guys

#

is this the right channel for questions about tier 0 machines?

west canopy
#

@rustic sage I think that's going to be the "starting-point" room

broken saffron
#

Hi everyone, I am doing the final skills assessment of web services & api Attacks, someone who could give me a hint or what should be used to find the flag i'm traying with sqlmap but i'm not sure how perform there isn't hints ...πŸ˜…πŸ€”

rustic sage
#

Thanks for the help! @livid pier @west canopy @unique valve @lethal atlas I learned to use both Flameshot and Cherrytree and downloaded the cheatsheets for the modules I've done, and I'll follow this for other modules too.

tall saffron
#

hi guys!!!

#

just wanted to know if it is a mandatory to use pwnbox to make labs? because i cant ping the "target"

#

i used the vpn file, and since there is a VPN file i must be able to contact the "target" and use smbclient to list the share (im doing the windows module)

#

and now target is down 😒 so maybe it was that, i retry

#

....

#

and again the target disconnect...

#

i remember why i stopped using academy

#

cant even make a shared folder without the rdp session disconnect and cant reconnect

#

30min and cant even make this simple stuff due to connection reset every 2min... i pay stuff for nothing...

#

this is a VPN issue... i must stop and restart the VPN to make it work...

#

and even when target is up we cant connect to list SMB with the command provided xD

#

even with smbclient -L \\\\IPofTarget -U htb-student

hollow widget
#

So, I'm doing Linux Fundamentals, and module Working with Web Services. Question one is to find a way to start a simple HTTP server, and there is examples. Only thing wrong is, whenever I try to start one, I get permission denied. When I use sudo apt install apache2 I get a password prompt, but was never given one earlier?

unique valve
# tall saffron

Consider the firewall on the Windows target. The section reading mentions this. Part of the exercise is considering what might block connections over smb.

tall saffron
#

i know about the ping issue, but we must list the smb share without making anything else than smbclient

unique valve
#

Try disabling the firewall on the windows target.

tall saffron
#

with being disconnected every 2 min from the target it will be hard to do that on every lab where we must make "external" connection

unique valve
#

You wont have to do it on every lab but it’s important to consider the firewall always because in the real world its a factor whether you are an IT admin or pentester.

tall saffron
#

nothing changed

unique valve
tall saffron
tall saffron
#

the lab doesnt work

#

and im disconnected every 2min...

unique valve
#

So we dont spam the channel. The lab does work as others have completed it.

tall saffron
#

lol nope it doesnt mean it worked for others

#

i was able to answer all the questions

#

you dont need to have it work for that

unique valve
#

Is htb-student in the permissions list of the shared folder?

tall saffron
#

yeah

#

read for everyone

#

like it is the default

#

that's the default lab, if i needed other things to be changed why it isnt mentionned πŸ˜‰

fickle glade
#

hello world

tall saffron
#

tried with smbmap and said port 445 not open...

tall saffron
#

the connectivity is a nightmare, i must CTRL+C every 2min to be able to reconnect via RDP to the target so it doesnt help too

unique valve
#

Its working on my end.

tall saffron
#

so why it doesnt work on my end?

#

like the connectivity

#

i reset 3 times the target, the pwnbox...

#

you just created the folder and share it like in the "tutorial"??

unique valve
#

Yep

#

Then either disable the firewall or enable rules that allow smb

#

In Windows their are 3 firewall profiles that can be applied. Domain, Private and Public. Each considers what network connections originate from.

tall saffron
#

already did

#

i first disabled it like you can see in the screenshots

#

after that i created a rule for smb to allow all inbound/outbound

#

i gave up

#

with the disconnect every 2min it is a nightmare to troubleshoot too

unique valve
#

You sure you tried disabling all 3 firewall profiles?

tall saffron
#

thanks for your time πŸ™‚

#

yeah im sure πŸ˜‰

#

but even with all of that, it is normally isnt needed, it works for you by following the tutorial and nothing must be changed

#

i reset the target 3times and did extra steps but didnt worked and like i said it takes me 10min to just make a simple firewall rule with this connectivity problem (and i have only problem with academy)

#

im just the type of guy who want to do it because i wanted to follow it but i already did some boxes with smb pentesting

#

anyway, thanks a tons for helping

unique valve
#

DM me if you would like to troubleshoot further. My RDP session is staying connected as well so it may be worth looking into a few other details.

tall saffron
#

now my keyboard doesnt work on the RDP session xD

#

i will stop htb for some days lol thanks

#

i tried a last time and now i have a stable connection (idk why...) and it works without any change @unique valve

dusky moat
#

hey guys, i was doing the 'using web proxies' module and i dont understand what this question is asking of me

#

from the zap fuzzer section

#

the hint told me to ||fuzz the cookie with md5 hashes with usernames in a wordlist||... i think i did but idk what im supposed to look at

tall saffron
#

you must fuzz the cookie you found previously with the top-usernames-shortlist.txt but dont forget to md5 every username

#

lol i just saw the hint is what i said xD

dusky moat
#

im so confused right now

#

no idea what i did wrong

distant stream
tall saffron
#

and kerberos used ticket and it is used to not pass any sensitive info on the network

#

and ldap is a way to communicate with AD when kerberos is "only" an auth service

#

LDAP and AD is like apache and http where LDAP=http and apache=AD

#

if i can make the parallel

tall saffron
dusky moat
#

yea

#

the worlist only had 16 usernames

tall saffron
#

and you fuzz the cookie previously found?

dusky moat
#

yessir

tall saffron
#

so idk what you did wrong ^^

dusky moat
#

lmao

tall saffron
#

wait some people who has access to it because i dont lmao

#

did you visit the /skills/ before fuzzing??

#

maybe it isnt the previously cookie you must fuzz but a new one

#

GL πŸ˜‰

distant tide
#

(Subnetting): so if I want to create 8 subnets, = 2^3, should I change 26 to 29?

#

Also, I'm using IP Calc to help me on this, I hope it's not considered cheating, I wouldn't know how to do that with pencil and paper

#

OMG I think I figured this out I can't believe it

lethal atlas
distant tide
#

I read somewhere that you could create tons of subnets in your home network to protect yourself from attacks

#

because it'll take a lot of time to scan every single one of them

lethal atlas
#

it would also create latency on the network

lethal atlas
#

feel free to dm me

maiden slate
#

Quick question guys, I'm doing manual credential enumeration and everytime i enter the command to post I'm getting a bash error that no such file or directory. But that's how they showed it in the examples, any idea what I'm doing wrong?

#

curl -X POST -d "<methodCall><methodName>system.listMethods</methodName><params><param><value>admin</value></param><param><value>CORRECT-PASSWORD</value></param></params></methodCall>" <IP>/xmlrpc.php

astral siren
#

Has anyone done the bug bounty methodology module? I'm either not understanding the question, or the question answer is wrong edit: i did not understand what it was asking

jagged summit
#

Module: File Inclusions

#

Section: Automated Scanning

#

Can anyone help me with this one

#

Its cleared... Thanks

maiden slate
#

Can anybody tell me what I'm doing wrong? I'm doing it just like the module (hacking wordpress) says to do it.

feral gyro
#

it will work

#

first u need to find a valid param

twin gulch
#

Hey guys. I need help at password attacks module. Can anyone help me?

jagged summit
maiden slate
#

Can anybody help with hacking wordpress?

lethal atlas
oak ether
#

Hi! Unsure if this is the right place to ask, but recently i reedemed a htb academy gift card and currently have some money in my account balance. Is it possible to redeem that into a subscription purchase? Whenever I try to buy a subscription it prompts me to pay again

maiden slate
#

DM?

#

@lethal atlas

lethal atlas
#

sure.

lethal atlas
oak ether
#

Ah definitely, should I contact a staff member directly?

lethal atlas
#

I would not. They tend to frown on that.

#

You might just tag them with "@red obsidian"

twin gulch
#

Can anyone help me at fuzzing module?

#

Fffuf on web application

lethal atlas
urban sage
oak ether
#

Great, thank you :)

quaint marsh
#

maybe ip=url?

acoustic owl
#

no, it needs an IP address

lethal atlas
quaint marsh
lethal atlas
quaint marsh
lethal atlas
quaint marsh
#

Weak Bruteforce Protections

#

change 10.. 127... 192... in basic_bruteforce.py

livid pier
#

Anyone here good with python?

maiden slate
#

Sorry, no.

lethal atlas
#

me either bro

maiden slate
#

You may want to check the community help channel.

livid pier
#

Well anyway, I got invited to do some google coding problems, I have finished the first couple levels and they asked me to refer a friend, if anyone wants to try them

acoustic owl
lethal atlas
livid pier
#

I am hoping if i can finish them it will lead to an interview 🀣

#

I need a job so bad πŸ˜‚

maiden slate
#

lol

#

You're trying to get a job at google?

#

please see:

#

πŸ˜›

livid pier
maiden slate
#

nice!

livid pier
#

I didnt orignally plan on doing this, seemed like it could be a cool oppurtunity tho

maiden slate
#

GL brother, I really hope you land it, I hear its a great company to work for.

livid pier
#

Lol ya I dont even know if it will turn out to be anything

#

Thank you tho

maiden slate
#

Your only limited by how much you want something, if you want it, you will take those measures to achieve it. If you want to work at google, you will work there.

lost kayak
#

Lol thanks, its not the most useful change log PES_SusThink

alpine summit
#

Hi, has anyone connected finished the final assessment for the File Upload Attack module. I think I'm near the end but I can't read the file. MP please.
EDIT: Got The Flag, thanks to @west canopy πŸ™‚

west canopy
#

@alpine summit I got you dawg πŸ™‚

scarlet mirage
#

Where i can get the root password for the htb vms? Or do I need the root privileged for nmap?

west canopy
#

@scarlet mirage check the desktop for a my_credentials.txt

steel summit
#

hi everyone! I'm in HTB Academy on Getting Started module in service scanning. When i try to do an smbclient using 'bob' username with the password mentioned along this page it give me a logon failure

#

i try manually writing the password and copy and pasting the pass and i cant acces

glossy oxide
#

any hint? Please

west canopy
#

@glossy oxide in your URL make sure it includes: index.php?language=languages/

#

after that try and use some of the techniques shown to read the flag

stark atlas
steel summit
#

smbclient -U bob \\<port>\users

#

then it ask me for the password but i cant login due a logon failure

#

is not <port> is the <ip> target the i enter the pass but i cant login

#

then i*

stark atlas
#

I will dm you

steel summit
#

okay!

obsidian oracle
#

Hey everyone Im learning linux fundamentals but I am having trouble finding the shell.

raven cairn
#

In all seriousness

#

echo $SHELL

glossy oxide
stark atlas
#

Anyone able to help with the Easy Lab on footprinting?

unreal sigil
#

Can anyone help me figure out why this isn't working

steel summit
#

try HTB{<flag>}

stark atlas
#

HTB{b7skjr4c76zhsds7fzhd4k3ujg7nhdjre}

^^^ That is how a flag should look

#

mostly...

unreal sigil
rustic sage
unreal sigil
#

HTB Academy > Cracking Into HTB > Java Deobfuscation

steel summit
#

do u copy and paste the flag or text it manually?

unreal sigil
#

copy/paste

west canopy
#

@stark atlas DM me if you need a nudge on footprinting easy lab πŸ™‚

stark atlas
rustic sage
#

You might have found a flag from an upcoming section.

unreal sigil
#

wow, yeah lol looks like you're right

#

got it now, ty

mellow ember
#

i'm also having trouble with this section. I got the S** user but i can't find anything else

faint locust
#

A bit oot, but still relevant, i have question regarding cube, i believe i finish around 5 modules and 2 in progress but why my cube only left 20 ? While 2 in progress is only 10 cubes each

west canopy
#

@faint locust It might have to do with the cost/refund ratio of the modules you did. I think "fundamental" modules cost 10 but refund 10. But a 50 cube module also refunds 10 I believe. My math could be wrong though

faint locust
west canopy
#

I think so . Cube return is 1 out of 5

#

so 100 cube module gives 20, 500 cubes gives 100, etc

faint locust
#

Okay thanks

severe birch
#

I was stuck on Windows Privilege Escalation > DnsAdmins. I have found a solution differently but want to know how the section intended it to be done. I was able to get the netadm account to show up as Domain Admin (when running 'net group "Domain Admins" /dom'), but am unsure how to grab the flag after this point. Any help is appreciated, thanks in advance!

west canopy
#

@severe birch I had to use a reverse shell DLL file in order to get the flag

severe birch
#

That is what I did as well

west canopy
#

But i think you might be able to right click on CMD, run as administrator, and then select the recently added Admin user

#

Like i think it needs an elevated CMD shell

wicked gazelle
#

hi! Need some help with command injection skill assessment, i think i already have the enter point but no clue how continue

broken saffron
#

Hi someone already finished the web service & api attacks module? There is no hints and i'm stuck any hint would be a great help! πŸ™Œ

limber dust
#

hi guys, I'm stucking in a htb-academy beginner module (Windows OS Fundamentals)

#

with a Linux VM (from htb) I establish an RDP connection to a Windows OS. There is a shared folder there. The Windows firewall is off. I should create a mount point on this Windows shared folder with Linux. This worked. Now I should display a list of the shared data with the command net share. But here I get an error message...

#

Can anyone help?

#

Normally, this should come out.

#

Solved:
ok i was blind. This command is to be executed on Windows. *slap

.

#

Ok, then I have another question based on that. Next in the module it says:

"We have not shared C: manually. The most important drive containing the most important files on a Windows system is shared via SMB during installation. This means that anyone with the appropriate access can remotely access the entire C: drive of any Windows system on a network."

#

But when I look at the property of C:\, it is not a shared.

#

How is that possible?

unique valve
# limber dust How is that possible?

Its a default setting in Windows operating systems. For some reason its not reflected in the properties you are looking at but its shared as seen from the net share command output. Theres a service called Remote Registry that when started, with the right local admin credentials allows remote connections to C: over the network. Can make administrative work easier but also create quite a security issue.

limber dust
#

So C:\ is a hidden share, but is shown as "Not shared" as shown in the picture above. Confusing πŸ˜„

limber dust
#

If I create my own hidden share on the same host, it is not visible to the others, as desired. However, under Properties it says "Shared", unlike C:.

limber dust
#

thanks for the answer πŸ™‚

unique valve
#

No problem. Hidden shares cant be as easily discovered remotely. Its an effort by Microsoft to try to make sure connections to shares come from people who know the exact name of the share. But all one must do to connect to one is know the share name followed by $

limber dust
#

Okay, I understand

#

Only the host can see the shared folders simply by using net share or Computer Management. Remote users cannot do this, they need to know the exact name. All right.

unique valve
#

With hidden shares yes, but like most things in Windows theres probably a way to get around this remotely. Would be worth doing some research on.

limber dust
#

Thanks πŸ‘

broken warren
#

@west canopy did you use xsstrike to find the payload that would work or did you use the other two resources given in the previous section? My login form shows up but the document.write is showing and the image url form is still showing with my ;document.get.elementbyId showing after my login form.

heady nova
#

Hello, for module "Attacking Web Applications with Ffuf", in the last section, i need to put all extensions in alphabetical order, but doesn't work...Anyone can help me ? Thanks πŸ™‚

blissful verge
#

hey all, just in case you haven't noticedd we introduced global search functionality on Academy. if you search you will be shown both modules and sections that contain your search term. should be useful for anyone working thorugh the content, exams, using Academy as reference on a pentest, etc

severe birch
west canopy
#

@broken warren I tested each one the examples provided in the section manually

#

@severe birch Not sure. I don't have anything in my notes about it

open spruce
#

Hi, I'm stuck on nmap enum Firewall & ids/ips Hard lab.

Objective: submit version of service client was talking

Hint:they were forced to add vital service for customers as they require large amounts of data

But when I type the answer it's not correct...

maiden slate
#

If you need help DM me

open spruce
#

I did: nmap -sV -sC ip address found port 22 and 80

#

Then nc -nv ip address

#

Found the answer but not accepted

maiden slate
#

What trusted port did you discover in the previous lab?

#

There is a trusted port that will allow you to get packets through that you should have discovered earlier.

open spruce
#

Don't even remember πŸ˜…

maiden slate
#

You got the easy and medium labs done, correct?

open spruce
#

Yes

#

I cannot attach pics :/

maiden slate
#

ok so you don't remember what source port you got? Do you remember all the ports you discovered? p22, and 80 are not involved in the hard lab

open spruce
#

Will have to re-do the medium then --'

maiden slate
#

redo some of the steps and use notepad to keep some notes on your process and discoveries, hit me back when you've gotten the trusted port that will allow you to pass TCP/IP packets.

west canopy
#

@open spruce try doing -p- for all ports, there might be a "hidden" port for you to find

open spruce
#

@west canopy already done

maiden slate
#

try 'namp -sS -sC -sV -p-'

open spruce
#

@maiden slate You requested a scan type which requires priviles. Quitting

#

I tried with sudo vut ofc it asks for the password

livid pier
#

it is on the desktop

#

credientials file

open spruce
#

God I did not realized 🀣

livid pier
abstract charm
#

How does the Windows OS academy module expect me to smbclient into the target machine if it's on a different network...?

maiden slate
#

@open spruce Figure it out?

open spruce
#

Same result and @maiden slate I found the screenshot of my answers from medium lab

#

My teminal jobs

maiden slate
#

you used the sudo su command and input creds and you still got an error?

open spruce
#

No error but it displays the same only 22 and 80

maiden slate
#

Alright try 'nmap -sS -sU -V <IP> --disable-arp-ping ( I can't remember the trace command)

#

Mabye not the -sS, can't remember if you can do that and -sU together or not.

torpid ermine
#

anyone please give me a nudge in information gathering module

open spruce
#

I did sudo nmap -sS -sV -sC -sU ip --disable-arp-ping

Platform x86_x64Linux
Available nsock epoll poll select

maiden slate
#

@torpid ermine Fully Qualified Domain Name

maiden slate
#

@open spruce So did you remember what trusted port you used? It should be in your lesson.

severe birch
#

Just to reiterate my question from earlier, I am trying to do Windows Privilege Escalation > Server Operators and I have been able to have the user show up under "net localgroup Administrators", but I am unsure of how to retrieve the flag.txt with these new privileges. Any help would be great.

torpid ermine
#

inlanefreight.htb

open spruce
#

@maiden slate I don't remember but I have the screenshot with the nmap I did to find the answer for the medium if you want I can send it privately

maiden slate
#

Go ahead

lethal atlas
torpid ermine
torpid ermine
lethal atlas
#

your command is missing ne thing

torpid ermine
#

also tried adding vhost

lethal atlas
#

can someone give me a nudge on broken authentication > session attacks > Bruteforcing cookies > question 2? I am struggling to find what it is encoded with

swift trench
#

Yoooo whats up everyone. I'm working on Bike, and can't get past displaying one [object] in the output of my Repeater. Checked all the code but no joy. I know the output i'm shooting for is "root". I did do the walkthrough but I'm thinking maybe something is awry with either foxyproxy or burpsuit

heady nova
lethal atlas
livid pier
#

Story of my life

lethal atlas
severe birch
#

If I am able to get my currently logged user into the localgroup domain admin or administrator, how can I use to view directories like the /Administrator directory? I keep getting access denied and I am assuming I am missing a step or something

pine sable
#

I just completed it 100% as well πŸŽ‰
(Btw, someone know why i can't share screenshot in the channel ?🧐 )

livid pier
#

Congrats!

#

and no

#

mine works

#

did you register your account?

pine sable
livid pier
#

Talk to @little whale

pine sable
#

Finally πŸŽ‰ 🍺

pine sable
swift trench
livid pier
acoustic owl
#

I still need some time

pine sable
pine sable
acoustic owl
#

Yes, still two modules

gritty isle
#

Could someone please help me. I'm stuck on the network services challenge of the password attacks module on hack the box academy. All of the challenges start with the phrase "find the user" but I have no idea how it expects you to find the user. I've tried running nmap scripts and banner grabs but provides no actionable information. Right now I'm brute forcing the WinRM service with nmap nselib password and username lists but it's not getting me anywhere. Is it another one of those stupid ones where you have to nc connect to a random port and sit there for 30 seconds?

#

I would add a picture but it won't let me

heady nova
#

No images in academy, just for me ?

mortal basin
kindred prism
#

Hi there, I am looking for some assistance in [Attacking Web Application with Ffuf] Module, Parameter Fuzzing - GET section. I have the answer already just by guessing (lucky in that regard) but what I can figure out is how I would actually get the answer. Appreciate any guidance: The question asks Using what you learned in this section, run a parameter fuzzing scan on this page. what is the parameter accepted by this webpage?" What page? I have tried the base (index.php included or not) and the various subdomains and directories with no success on the parameter fuzzing.

west canopy
#

@kindred prism you want to fuzz against /admin/admin.php?FUZZ=key

severe birch
#

Have left this going for 5 minutes, refreshed, now its been 10 more, anyone know how I can fix this?

rustic sage
#

Really frustrating

severe birch
#

Yikes, guess its time to call it a night lol.

vital bough
severe birch
#

Footprinting

vital bough
#

ahh I'm getting weird responses with ffuf module on spawning

red obsidianBOT
#

There is no flag here. Get back to hacking!

round sky
#

@rustic sageYes! Thank you!

hollow obsidian
#

.

glacial blaze
#

Need help for module "Login brute forcing", section "skills assessment - service login".
Can you confirm the website we need is on the same target IP ?

rustic sage
#

Hi! I've a question about the module Information Gathering and the host gear.githubapp.com. I have to find the servername but when I submit it it's not accepted. Am I wrong, or has it changed?

unique saddle
#

Got struck

#

How to find capture the flag

rustic sage
# unique saddle

Spawn the target and use cURL to send an HTTP request to http://<ip>/download.php

rustic sage
#

This answer is refused, can someone confirmed it's normal? I was pretty sure about it.

night prairie
#

Tried removing the dot at the end?

rustic sage
night prairie
#

I've not done the module, friend, I can't help, sorry

rustic sage
#

Ok, thank you anyway. There is no hints so I guess it should be simple.

night prairie
rustic sage
muted rampart
#

Which module are you talking about?

rustic sage
night prairie
#

Nope. Different module

muted rampart
glacial blaze
#

Still no luck in Brute Forcing module, Skill Assessment last two questions. Anybody here already did that module and could help ?

main vapor
#

@glacial blaze DM me.

glacial blaze
#

Thank you @main vapor !

rustic sage
#

I'm in need of help. I've been trying to solve Network Enum w/ Nmap: Final section (Hard Lab) for weeks. I've (finally) discovered a new port 50,000. It's an IBM DB2 service.

running db2-das-info.nse returns me nothing. Tried both the custom "50,000" port. Tried the default (523) port. Changed my source port around. Tried all types of scan-types.

I don't know what else to do. I recieved bad information from someone last week, led to believe (foolishly) that I was supposed to enum DNS... and only today have found this "hidden service". I'm still unable to enumerate a service-version.

any help or hints at all. I am very fresh to this. I've been here only a month and this one is really causing me a lot of pain. I feel like I've exhausted all of the research that I could

#

Couldn't enumerate the DNS, either *(I don't know if that's the correct service, or the db2)... either way, I am stumped and can't crack either one.

I'm not sure where I'm going anymore. I feel like this is a bit too advanced for any newcomers.

glacial blaze
#

@1emur Keep it simple. You just want to find a way to get this port in an opened state.

torpid ermine
#

anyone please give me a nudge in information gathering module

rustic sage
#

@torpid ermine I did it on yesterday, do you want we DM? When you'll be in a next section I will ask your help too πŸ˜… .

rustic sage
rustic sage
#

tried removing --disable-arp ("well, maybe it needs to resolve something").

dns resolution... no dns resolution... with ICMP, w/o ICMP (obviously, the IDS prevents that one, but I thought "crazy, but at least try it")..

#

with and without changing my source-port.. I don't know what else is wrong. I've been trying everything

glacial blaze
#

You are overthinking this and may have not tried something simple learned in the module

rustic sage
#

I've even stripped it down to just "--script" and nothing else

#

tried no script at all. I'm down to just "-sV" (and of course -Pn)

distant cradle
#

Some help about -->STACK-BASED BUFFER OVERFLOWS ON WINDOWS X86-->Page 5 Identifying Bad Characters
When im creating the new array, i get this:
Invalid value: "Bytearray"!
Unknown command/expression: "--Bytearray"

glacial blaze
#

Anybody else not using browser based pwnbox and having problems reaching targets from VPN ?

distant cradle
glacial blaze
true sundial
#

hey guys, I have problems with an answer in INTRODUCTION TO ACTIVE DIRECTORY

#

basically this is the question: What role ensures that objects in a domain are not assigned the same SID? (full name)

#

the answer seems pretty easy, but no matter how I write it, it is wrong

severe birch
#

Full name, no acronym for that one

#

Is anyone else having issues spawning targets for the modules? Trying to do Footprinting module but last night and today the machine just keeps saying "Target is spawning..."

rustic sage
#

i do on occasion and often my scans are unacceptably slow, to the point where it goes beyond the time-limit. i don't understand it.

#

other days, it's fine

severe birch
#

I have been doing these for maybe 2-3 weeks without issues, but last night and today it is far too slow to accomplish anything.

warm quiver
#

In the Session Security module, the Cross-Site Request Forgery (GET-based) section - I had to change method from GET to POST in the attached html code, to get the result. Anyone else had it? Surely it was supposed to work with get method as per section title.

muted rampart
#

I think that it has something to do with the weekend. Most people have a full time job and have only time for learning on the weekend. Therefore, the servers are working quite hard, which leads to delay.

strong tide
#

In the Web Attacks module - Bypassing Security Filters, the text of exercise says "To get the flag, try to bypass the command injection filter through HTTP Verb Tampering, while using the following filename: file; cp /flag.txt ./". It's not clear if I should use directly as input "file; cp /flag.txt ./" (that the browser already encodes as "file%3B+cp+%2Fflag.txt+.%2F" or I should also try to encode ; and / in different ways. Because for both strings I tried all the HTTP methods (https://github.com/danielmiessler/SecLists/blob/7a42879a4687429778fea78067d075d4616ba83f/Fuzzing/http-request-methods.txt) with no results

warm quiver
# strong tide In the Web Attacks module - Bypassing Security Filters, the text of exercise say...

Without giving too much info - this question is way easier to do using burp than manually. Different methods may require some additional fields https://developer.mozilla.org/en-US/docs/Web/HTTP/Methods
And I spent way too much time on that one trying to do it by hand.

HTTP defines a set of request methods to indicate the desired action to be performed for a given resource. Although they can also be nouns, these request methods are sometimes referred to as HTTP verbs. Each of them implements a different semantic, but some common features are shared by a group of them: e.g. a request method can be safe, idempot...

naive aspen
#

Hey, quick question, can someone ping me the wordlist to use for the 3rd question in the skills assessment in the Attacking web apps with Ffuf (find the 'you don't have access page')? I understand the process but my scans are taking over 90mins to complete and the server is only up for 90mins so I have to re-start the scan so it's a catch-22. It's frustrating to put it nicely.

naive aspen
warm quiver
warm quiver
naive aspen
alpine summit
#

Hello, I wanted to know if I subscribe to a plan. Can I stop it at any time or is there a commitment period?

rocky sedge
#

could i trouble some one for a nudge pls Cracking Common Hashes question been stuck for months keep coming back to it but can't see wood for trees somewhere
the hash
7106812752615cdfe427e01b98cd4083

west canopy
#

@rocky sedge DM me brother πŸ™‚

rocky sedge
upper niche
#

Hello, can someone help me to better understand something in :
module : network enumeration with nmap
section : Firewall and IDS/IPS evasion - Easy Lab

west canopy
#

@upper niche I can certainly try, what's up?

upper niche
#

@west canopyi don't want to spoil anyone can i dm you ?

west canopy
#

of course πŸ™‚

muted rampart
#

Does somebody know why the right answer is not the version number of the dns server as the question states?
module: network enumeration with nmap
section: Firewall and IDS/IPS evasion - Medium Lab

west canopy
#

@muted rampart its actually in the format of a flag i.e. HTB{something}

red obsidianBOT
odd shore
#

could someone help me with 'Shells & Payloads' - 'The Live Engagement'. I'm on Host-1 found many ports and services open with nmap, but no ms exploit that works. Also the creds ' tomcat | Tomcatadm ' do not work for the manager access, not sure where those came from...

odd shore
#

nvm, it was a webshell exploit

tight mesa
#

I am supposed to be finding a network request to a flag... I have clicked through every single request but I can't find any request to a flag. Can someone help me understand?

west canopy
#

@tight mesa try refreshing the page, eventually you should see something like this

tight mesa
west canopy
#

I've heard from other people that they had trouble getting the flag to show up, but personally i never ran into this problem. I guess if it doesn't load maybe try respawning the target.

sly grotto
#

hey guys does anyone solve File Inclusion LFI and File Uploads ?

#

when i go to setting.php and press upload it gives me file not allowed error

tiny ledge
warm quiver
sly grotto
pine sable
unique saddle
#

Any one please answer this

#

@rustic sage it's not working

frigid summitBOT
#
Ramadan_Kareem#0336 has been warned

Reason: Mass mention

#
Ramadan_Kareem#0336 has been warned

Reason: Mass mention

#
Ramadan_Kareem#0336 has been warned

Reason: Mass mention

languid fjord
#

nice

rustic sage
#

module : WEB APPLICATIONS
chapter : Common Web Vulnerabilities
I have read and tried several words that according to me could be categories of public vunerability but I did not find, is that somebody could define me what he understands by category or give me the answer?

Thx ☺️

west canopy
#

@rustic sage DM me πŸ™‚

onyx zenith
acoustic owl
#

No, you do not need to modify any config files.
Try a zone transfer on the found subdomains.

lethal atlas
#

I think you do need to have inlanefreight.htb in your /etc/hosts though.

rustic sage
unique saddle
unique saddle
unreal sigil
#

acadamey > cracking into htb > java deobfuscation > http requests

#

it's saying the flag in the response is not the answer and that the answer should start with an n and end with a z

#

I have no idea what that means, I don't see anything like that from the response

rustic sage
#

Hello guys. I have trouble solving the module HACKING WORDPRESS on the section **Directory Indexing ** for some reason i cant find the correct directions

#

can anyone help me?

unreal sigil
#

nvm got it lol

acoustic owl
rustic sage
acoustic owl
#

There are many directories. Some are "misconfigured" and you can list the contents.

rustic sage
#

how can i find them

#

i have done that

acoustic owl
#

open each directory and look at the contents

rustic sage
#

should i search php as well?

acoustic owl
#

No, only directories and subdirectories

rustic sage
#

ok

#

also do i need to search it through shell or i can search it on firefox

acoustic owl
#

You can use both, whichever you prefer.

rustic sage
gritty isle
#

I'm doing the starter module and the question is "Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file."

I think i already found the right exploit(auxiliary/scanner/http/wp_simple_backup_file_read

) but this exploit requires the filepath. I set the filepath to /flag.txt and metasploit gives me this:

[*] Scanned 1 of 1 hosts (100% complete)

[*] Auxiliary module execution completed

Did it work? When yes where is the content? am i even using the right exploit?

i tried to change the depth to 0 to 1 and to default 6, but im getting the same result

elder pendant
#

Starter Question:
I am working on Pentesting Basics > Basic Tools.
The module is asking for the header with an IP address. I am trying to use Netcat to do it.
However, I cannot install Netcat without the Sudo password on the pwnbox (through HTB). Is it already installed and is there a way to check?
Any help on how to proceed with this is greatly appreciated. Thank you in advance!

gritty isle
#

@elder pendant You should have access to netcat... πŸ€” What happens when you run "nc -h"? Maybe try resetting the box

modest moth
#

anyone finished with the file upload attacks module?

#

kind of stuck on the whitelist chapter

rocky sedge
#

how many times are you gonna sanity check me ? xD Thanks again buddy

unreal sigil
#

not sure what i'm doing wrong

#

acadamey > cracking into htb > java deobfuscation > skills assessment

rustic sage
unreal sigil
#

I visited the link but still don't understand what I'm doing wrog

#

wrong

rustic sage
# unreal sigil wrong

In your screenshot, you sent the data in the URL like a GET request. The task is asking for a POST request

unreal sigil
#

would that be more accurate?

rustic sage
unreal sigil
#

I didn't receive a flag with it tho 😭

rustic sage
#

@unreal sigil Let me try it out, please...

heady nova
#

u forgot the -d before data no ?

unreal sigil
heady nova
#

not on index page

unreal sigil
#

it's literally the very last question of the whole module . i don't know how i got this far just to get stuck here lol

unreal sigil
heady nova
#

if i remember correctly...

rustic sage
unreal sigil
#

ugh i swear i tried that but must have had something wrong. ok i'll try it thx

unreal sigil
#

oh

#

nvm lol

heady nova
#

πŸ˜‰

unreal sigil
#

not serial

#

lol

#

geese, finally got it lol
thanks for all the help

#

I don't agree with what the flag says

#

I'm obvi not ready lol

rustic sage
#

Does your pwnbox have access to the internet at all? I thought it was only for VIP users

#

@lament crag ping paypal.com

heady nova
#

strange

#

try

echo $TARGET

rustic sage
#

Never used pwnbox...

#

But I can try now :)

#

Same issue here... ://

#

Or whois.exe in Windows. Whatever you need

#

For tasks I need to connect to HTB's VPN I use a VM and if not I do it from my host OS (Linux)

#

Nope. Fedora VM on Fedora host :)

#

@lament crag Yep.

#

I prefer not to connect in my host OS to a network where people learn how to hack :)

#

Yep, but at some point, you'll need to use a VM.
And for this task, you do not need to connect to a VPN, and PayPal has an official bug bounty program with paypal.com in the scope, I don't see a reason for concern

kind forge
#

good, where can I make a query about a subject of the FFUF module?

slow ruin
#

Working on this question currently and wondering if you ever got the answer to this and was wondering if you had to make a complex query to figure it out

acoustic owl
topaz crag
#

Hi! can someone please give me a hand with this, I am doing NETWORK ENUMERATION WITH NMAP, and on the Service Enumeration question I think i got it but the system keep saying is wrong... but i am pretty sure that is a flag... any ideas ?

#

the question is: Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer.

tiny ledge
#

Anyone done: Getting Started - Public Exploits ? | Should there be a VM in there?

#

Got it

distant cradle
#

The connection to the target MySQL usually fails a lot
#mysql -u root -ppassword -h 134.209.28.38 -P 30750
#ERROR 2002 (HY000): Can't connect to MySQL server on '134.209.28.38' (115)
Anyone knows why?🀨

kind forge
#

Amy working in Module Hacking Web aplication with FFUF

#

I have a problem with VHOST Fuzzing

uneven mortar
#

come for anweres to questions instead you will get children decsribing the water your drawning in. yeh I'm to old for this.

uneven mortar
lethal atlas
fleet moth
#

Anyone finished the broken auth module? could use a hint with the final assessment.

slow venture
#

anyone got any hints for windows priv esc skills assessment 2?

#

trying to find left over credentials for iamtheadministrator

#

i can see the files its in but access denied for most, not sure if i have to escalate before

#

oh found it

#

nvm

misty remnant
#

i need some help with information gathering at Active Subdomain Enumeration. pls dm

rustic sage
#

@acoustic owl can I dm you for help?

acoustic owl
unreal sigil
#

tried asking in general chat but only got trolling responses lol

#

which os would you recommend I run on my vm

#

windows or linux

#

and which version

#

installing vmware rn and it's asking me what I want to run

#

I was thinking linux but then do I choose ubuntu, fedora, oracle, debian, etc.

steel summit
wintry gorge
#

Hi, i need some help with the broken authentication skill assessment module

stark atlas
#

Anyone able to help with Footprinting Lab - Easy? - Sorted now

weary forum
#

Hello, everyone. I am having trouble with the Web Request Module.

#

More specifically, the Get Method of Curl.

stark atlas
#

@weary forum what part are you stuck on?

storm lagoon
soft jolt
#

Hello, anyone finished the SQLMAP Essentials?

west canopy
#

@soft jolt what section did you need help on?

idle cliff
#

When checking the response, it says "Please use cURL"

#

Is there some way of searching using cURL that I'm unaware of?

trail leaf
#

Having some trouble with the Phishing challenge in the XSS module, I got the creds, but the flag I see when I log in isn't being accepted

#

aaand it just worked even though I did nothing

west canopy
#

@idle cliff you want to curl http://ip:port/search.php?search=flag -H 'authorization token'

carmine hill
carmine hill
#

Has someone here finished the brute force login module? πŸ˜•

west canopy
#

@carmine hill i can help πŸ™‚

carmine hill
west canopy
#

so you're not having trouble actually bruteforcing credentials, just getting the target to load?

carmine hill
#

Yup, haha there are two assessment parts. I completed the first one (website), but now I cannot even start the second part (service login), cause I can’t get to the website

west canopy
#

maybe try respawning the target a few times?

carmine hill
#

I did that several times, from my virtual machine and personal computer and no luck. I could notice that when I tried to load the ip:port it tries kinda authenticate to SSH, so I thought maybe the website was on port 80, or another port but no luck yet

west canopy
#

right for Skill Assessment Service Logon, you want to hydra SSH credentials

carmine hill
#

But it says to gather info about employees, so I guess there is a website, isn’t it? Or I just need to use the info discovered in the previous part? If this is the last one, then I guess I got it

idle cliff
#

So having a slight problem with Web Requests POST section. I'm at the end, successfully completed all tasks but as I'm trying to search for the flag, I'm using a valid authentication token / cookie but as I run the curl command it's telling me I need "A valid authentication cookie is required!"

#

I've even respawned the target and repeated to make sure the authentication cookie matches up with current session and get the same thing

west canopy
#

@carmine hill yes it's the employee name after you find the last flag from the previous section

#

A certain wizard πŸ™‚

carmine hill
#

Oh got it then, thanks, I thought it was a whole new exercise πŸ˜…

west canopy
#

yea that threw me off too

raven cairn
#

I need some help on web requests decoding/encoding

#

I know how to decode in burp and zap, I just have not been having success

west canopy
#

@raven cairn do you mean Web Proxies?

raven cairn
west canopy
#

try decode base 64 a few times

#

then i think it's ascii hex -> url decode

tiny ledge
distant stream
#

yes. dm if you still need help

tight glen
#

dont use zap LUL

random osprey
#

hello

#

how can I make money from virtual

raven cairn
#

Zap is FOSS tho 😎 .

lethal atlas
#

I like burp better as well, It just seems easier to use to me. But to each their own

west canopy
#

B U R P B O Y S

vital bough
#

when I use firefox it keeps trying to make my ips go to https, how can I avoid that?

west canopy
#

@vital bough you might need to specify http when entering the URL into the browser

#

Not sure if there is a firefox setting or anything like that

tiny ledge
#

Can anyone help me with the Nibbler part of the 'HTB Academy - Getting Started'

rustic sage
#

Is there anyone that have done the HACKING WORDPRESS?

acoustic owl
stark atlas
#

Anyone able to help with Footprinting Hard Lab, I am on the last step I think and just need a pointer

tiny ledge
#

I did all the steps, but every time I try to run ./monitor.sh, I get: nibbler@Nibbles:/home/nibbler/personal/stuff$ sudo ./monitor.sh
sudo ./monitor.sh
'unknown': I need something more specific.

west canopy
#

@tiny ledge i get that same 'unknown' error but i am still able to catch a root shell

#

not sure if it matters but i did the entire file path to monitor.sh

tiny ledge
stark atlas
#

Anyone able to help with Footprinting Hard Lab, I am on the last step I think and just need a pointer

unreal sigil
#

halpppp

acoustic owl
#

Try nc 167.172..52.221 32339

severe birch
#

Could someone help me with question 2 of footprinting SMTP? I believe my command should be correct or close, but it returns no results.

acoustic owl
#

without :

unreal sigil
acoustic owl
#

nc 167.172..52.221 32339

unreal sigil
#

you da man, thx

severe birch
#

I am guessing my scan parameters must be wrong

raven cairn
west canopy
#

zap is for gigachads

lethal atlas
#

Burp -gt zap

odd shore
#

For 'Password Attacks' - 'Network Services' could someone give me some good username and password lists. I'm using some from SecLists and am unable to get anything.

raven cairn
#

Web attack, bypassing security filters. I have intercepted the requests and have tried every HTTP method but am still not having success. I don't know what is wrong.

west canopy
#

@raven cairn try right clicking in burp and changing the request that way

slow ruin
#

Working on File Inclusion - Basic Bypasses and I feel like I have tried all examples in the section. I see how the current path is functioning but my commands still do not seem to be working for me. Any hints would be great

west canopy
#

@slow ruin make sure your url includes index.php?language=languages/

slow ruin
west canopy
#

using two slashes and four dots should do the trick

slow ruin
#

holy moly idk why I was adding an extra slash which was goofing it all up?! lol thanks @west canopy

raven cairn
unreal sigil
#

ugh what im doing wrong 😭

west canopy
#

@unreal sigil

#

When you run the smbclient command to connect as the Bob user, is it prompting you for a password?

odd shore
west canopy
#

@odd shore That's probably it. Nice catch πŸ™‚

unreal sigil
#

omg lol yeah it was the slashes lmao thx

rustic sage
#

can someone help me with SEToolkit?

#

specifically the cred harvester

odd shore
#

Has anyone completed 'Password Attacks' - 'Network Services'??

strong ruin
#

im on modules doing linux fundamentals under Service and Process Management, when i enable the ssh.service its says its running fine then when i reboot and do systemctl list-units --type=service it says sslh.service active: failed sub: failed. What did i do wrong

maiden spindle
#

I'm doing Getting Started. Trying to connect to smbclient as the Bob user, I do not know what the password is. I tried Welcome1, was I supposed to learn how to hack passwords somewhere else?

burnt sky
#

@maiden spindle did you ever get any help with that one?

maiden spindle
#

no

#

@burnt sky would you be able to lead me in the right direction?

rustic sage
#

is HTB good for general computer learning ie. Linux etc or just hacking

sly grotto
#

hey guys does anyone solve the 2nd question of [Information Gathering - Web Edition][Active Infrastructure Identification]?
the question is Which CMS is used on app.inlanefreight.local? (Format: word)
it is joomla but when i submit it , it gives me wrong answer

acoustic owl
tiny ledge
#

Can anyone help me with the port I need to use in - Getting Started - Knowledge check, I'm trying to use Metasploit to get reverse shell to Getsimple site

#

Started reverse TCP handler on 46.101.2.213:4444

#

10.129.42.249:80 - Exploit aborted due to failure: unknown: 10.129.42.249:80 - Upload failed

paper crag
rustic sage
tiny ledge
acoustic owl
tiny ledge
acoustic owl
#

Run a script such as LinEnum or LinPEAS to assist with finding common local privilege escalation vectors.

tiny ledge
acoustic owl
#

shell

tiny ledge
manic ermine
#

Hi all, I've just noticed that I now have to re-do some of the LFI module as it's been updated. I've gotten completely stumped on the "basic bypasses" page...I have tried everything mentioned in this section including the new content. Anyone got any tips?

#

To be more specific, I've tried bypassing simple removal of path traversal, url encoding, starting with the languages path to get around the Illegal path issue, and truncation...and mixtures of all of the above
EDIT: figured it out after several hours...my hint for others is to keep it simple and make sure you include plenty of upward file traversals to get to root!

tiny ledge
#

Can someone give me a heads-up what to do with this information: [+] Possible sudo pwnage!
/usr/bin/php
It's supposed to help me escalate to root privileges, but cant seem to understand how πŸ™‚

#

comparing this to the example in the instructions, we last used the same tactic, but the file was monitor.sh where we wrote it to /bin/bash, but does not seem to work here

tiny ledge
# rustic sage Have you checked GTFOBins?

Thanks both, I'll take a look @acoustic owl @rustic sage, got the flag! The GTFObins was a real eyeopener, haven't checked this one before, this will help so much in the future

knotty hemlock
#

Hi, has anyone finished the final assessment of the server side attack module? can't find where to start..

acoustic owl
distant cradle
manic ermine
#

Start with the allowed path, then traverse up a bunch...I think I used ....// also. Don't need any of the truncation stuff. Don't think I needed url encoding either

manic ermine
#

Yep

quaint marsh
#

Broken Authentication Bruteforcing Passwords
If I understand correctly, grep '[[:upper:]]' rockyou.txt | grep '[[:lower:]]' | grep -E '^.{8,12}$' is not correct and needs to be padded? since the password policy includes numbers that the grep command does not include. That is, the policy allows the word "qW1, Qw1,1qW", but this filter incorrectly selects words from the list?!

#

is this filter correct?
grep '[0-9]' rockyou-50.txt | grep '[[:upper:]]' | grep '[[:lower:]]' | grep -E '^.{3,12}$'

#

Broken Authentication Bruteforcing Usernames /question2/.
I can't figure out where to look!

alpine summit
alpine summit
#

yes or in the developper tools network

quaint marsh
#

and how to filter a word in a burp from an outgoing request for thousands of words?

#

watch manually one word at a time?

acoustic owl
weary forum
#

Ok, everyone. I am having problems with the Web Requests Module. More specifically, I am having trouble with the GET request part of the module

#

Here is the question: "The exercise above seems to be broken, as it returns incorrect results. Use the browser devtools to see what is the request it is sending when we search, and use cURL to search for 'flag' and obtain the flag."

#

I used the browser devtools and I looked at the request tab in devtools, but there wasn't anything interesting to see there.

acoustic owl
#

Did you read the Hint?
Don't forget to set the user credentials when you send the 'search' request

weary forum
#

I authenticated in my web browser. admin:admin@Server IP:Port

acoustic owl
#

ok, if you are searching for anything, what is the URL?

weary forum
#

Do you mean the Get request?

acoustic owl
#

yes

weary forum
#

I mean: http:// server ip: port/search.php?search=Manchester

#

Manchester is just the term I search for.

acoustic owl
#

Correct

Now look for which term you need to search and build the cURL query.
Remember that you have to log in first.

weary forum
#

Well, I have the filename /search.php, which is the backend server that searches for the results. My search item is Manchester. This is all in the Get Request

acoustic owl
#

Yes, that's all you need.

Now you only have to search for the word that was given to you in the task.

alpine summit
#

Can anyone help me with the BROKEN AUTHENTICATION module? I'm stuck on Bruteforcing Cookies. I tampered with the cookie, but the flag doesn't appear.

quaint marsh
#

It's unclear! I want to manually create a list, which I will then encode in md5 and compare with the token. $token = md5($username . $time); total we know name= htbuser. and the time is known=13:31:33. $time = intval(microtime(true) * 1000); how do i turn time into $time ?

#

Predictable Reset Token

#

do you just need to multiply seconds by 1000 (33*1000) or is microtime hours+minutes+seconds?

sly nebula
sly nebula
#

Aaaand back it went.

distant cradle
kind turret
#

@quaint marsh DM me.

quaint marsh
severe birch
#

I am having issues with Footprinting MYSQL, the prerequisites mentioned do not download, the nmap scan will not work, and I cannot use mysql command at all. Does anyone know what I could have wrong? I have found workarounds, not sure why what was suggested does not work.

dense ferry
#

I'm trying to work through the SQL Injections module, but I can't connect to any of the docker instances which spawn. I've tried resetting at least 10 times, and connections are either refused or timeout.

runic rampart
#

Good afternoon! Can you please tell me where to go?πŸ˜€
Password attacks:Finding Credentials in Linux

rustic sage
mortal basin
dense ferry
mortal basin
tight mesa
#

hey guys, who can help me with Web Request Module?

#

I'm having some troubles with PUT API Method

glad orbit
#

Somebody help me about "DnsAdmins" module. I upload the dll and add the netadm user in the correct group, but I have not access to the flag file.

west canopy
#

@tight mesa that's the final section right? I had to go through all of the steps. Rename a city to "flag", delete HTB_City and HTB_New_City, and then i was able to curl "flag" to retrieve the answer

#

@glad orbit I had to use a reverse shell dll in order to get the flag. I still need to try it but you might be able to right click and launch CMD as as administrator and use the netadm user and get the flag that way (after it's been moved to the administrators group)

tight mesa
#

yes it is

#

ok., I will doing that, ty @west canopy

brave kindle
#

Hi, I have currently finished the introduction to networking module, I was trying some stuff on my own and I am having some doubts.
Could I ask anybody?

rustic sage
#

Hey I have some trouble solving PHP Web Shells on the **SHELLS & PAYLOADS ** module

#

I cant use correct the burpsuite

#

anyone that can help me?

hollow hinge
#

hey i am stucked at LFI module can anyone correct me?

lethal atlas
slow venture
#

guys, im losing my mind. has anyone else had mad problems with downloading crackmapexec on the htb machine

#

im getting so many errors with every method i try

slow venture
#

wow

#

wow

#

just wow

#

thank you

unique saddle
#

Any help

west canopy
#

@unique saddle

unique saddle
west canopy
#

You're very welcome πŸ™‚

unique saddle
#

Is it hard HTB

#

Or should I try Tryhack me

#

I stuck so many times

west canopy
#

HTB is typically very difficult for beginners.

unique saddle
west canopy
#

I think THM has a lot of information but isn't as "hands on" or as challenging as HTB. Personally I have not used THM but i know it's popular.

unique saddle
#

I stick to HTB

fierce atlas
#

Hello in the module Command injections and the sections Detection we must answer the question with a english phrase(the error message).
it's cool but not all of the users of HTB use a browser in english.. it's not a really important problem but i think it can be improve !

west canopy
fierce atlas
#

@west canopy yep i move my message

late beacon
#

Are we supposed to find a hash first?

#

(Password Attacks)

#

If so, I can't seem to find it.,

unreal sigil
#

I keep trying the password I use to log into my HTB account but it's not working

#

Is it supposed to be that or something else

late beacon
#

Check the credentials file on your desktop

unreal sigil
#

desktop meaning the pwnbox?

late beacon
#

Yea

unreal sigil
#

got it, i see it
thx so much

proud sparrow
#

hey, i have problem with submitting the answers in HTB academy, im now in WEB REQUESTS module in bugbounty path and i have the correct asnwer but keep returns with WROG ASNWER , what should i do in this case?

late beacon
#

Make sure you don't have extra spaces before or after your answer. The web app isn't designed to strip them when you press submit

broken saffron
late beacon
#

Anyone complete the question for this section? Need help

proud sparrow
#

Send a GET request to the above server, and read the response headers to find the version of Apache running on the server? (answer format: X.Y.ZZ)-------------- this is the question as we see we have e.x also for the answer so i tried to put in different ways and looked for youtube but still gives me WRONG ANSWER

knotty hemlock
#

Hi, has someone finished the final assessment of Session Security? I think I managed to do what is suggested in the hint, but i can't verify because i don't know the admin mail address... Am I on the right track?

alpine summit
#

I'm stuck on the question 2 of Predictable Reset Token. Request a reset token for htbuser and find the encoding algorithm, then request a reset token for htbadmin to force a password change and forge a valid temp password to login. What is the flag?
I've found the correct algorithm but after i'm stuck.

west canopy
#

@knotty hemlock I was able to solve it by using the exact same technique from the "Session Hijacking" section of Cross Site Scripting module.

#

Once you get XSS set up on julie rogers profile, you can use the API endpoint to make the admin user visit her page, which lets you steal the admin cookie.

unreal sigil
#

anyone having any issue getting to their target on pwnbox? I've tried on firefox and bash, I've tried closing reopening and trying again, I've tried resetting, terminating, I even restarted my computer

unreal sigil
#

web enumeration

#

cracking into htb

#

oh not me my b

west canopy
#

@unreal sigil I think it's an issue with Docker targets, usually i have to spawn them four or five times before they actually boot up.

proud sparrow
#

bug bounty path , web requests section

unreal sigil
#

ok thx

proud sparrow
#

its not the first time and im loosing cubes and when im done with moudle it cant be submitted as done!

west canopy
#

@proud sparrow

proud sparrow
#

i know how to get the version and for me its 2.4.29

west canopy
#

Hmm maybe there is some variation with the Docker targets. I was having a similar issue on the LFI module and they ended up changing the question because different docker instances would give different results.

proud sparrow
#

yo also for me in LFI i had issues also

knotty hemlock
swift trench
#

My Chrome browser has been having no luck accessing htb websites. What could be the reason for that? Is it because I'm using chrome and should be using firefox? Thanks everyone!!

west canopy
#

@swift trench Are you not able to access spawned targets, or not able to get to the HTB website period?

proud sparrow
#

i need help im done tried alot but there is no way i can know,,,,any one? thank you.

#

The server above loads the flag after the page is loaded. Use the Network tab in the browser devtools to see what requests are made by the page, and find the request to the flag.------------i coudnt solve this one,what to do?

west canopy
#

@proud sparrow you might need to refresh the page a few times. But it should load a flag which you can then curl

proud sparrow
#

how did you get this flag file?? explain a littile bit

#

@west canopy

west canopy
#

navigate to the target in your browser, right click and inspect element, select the "Network" tab and press reload then you should see it

proud sparrow
#

@west canopy i was doing right but with domain in the examples not spawn ip, thank you tho , still i dont know how to put the answer the way it should be written

west canopy
#

It's in the format HTB{something}, you can get it by navigating to the flag in your browser or use curl

proud sparrow
#

wow! thank you man for directing me πŸ™‚

covert shoal
#

help, with a step I can't get past because I don't know how to get the flag it asks for

#

Obtain a session cookie through a valid login, and then use the cookie with cURL to search for the flag through a JSON POST request to '/search.php'

#

I did everything, but I don't get

lethal atlas
covert shoal
# lethal atlas what module, section, question.

module: HTTP Fundamentals, section: Post and question: Obtain a session cookie through a valid login, and then use the cookie with cURL to search for the flag through a JSON POST request to '/search.php'.

lethal atlas
#

http fundamentals???? THats not a module

west canopy
#

@covert shoal you will want to do something like this, but search for "flag" instead of "london". Your session cookie might be different so replace it with whatever your cookie is after logging in as admin:admin

lethal atlas
#

Web Request im guessing since it has a section named http fundamentals

unreal sigil
#

when performing an nmap on target do you leave it like this "161.35.47.235:30450" or change the numbers after the ":" or what

#

cause I'm not getting anything when I run it

#

It opens the page on firefox tho so I'm not sure why my nmap isn't giving port results

west canopy
#

it would be like: nmap 161.35.47.235 -p 30450

#

but usually docker targets don't usually have any other ports open so nmap typically isn't necessary, at least when it comes to Academy modules

#

you might need to add sudo and add the -Pn option

lethal atlas
#

if you want to wait for the long scan you can do : nmap 161.35.47.235 -p- -Pn and let it scan every port.

unreal sigil
#

idk it's this im trynna do

west canopy
#

@unreal sigil you actually don't need nmap for that section. You will want to take advantage of the wordpress plugin being used by the target (you will see it when access the target in your browser)

unreal sigil
#

ok thx

swift trench
true tendon
#

on the active subdomain enumeration lesson for info gathering, doing the nslookup AXFR search doesn't give me any TXT records, and it looks like it also doesn't give me all the subdomains, considering the IPs of the FQDNs it asks for in other questions and the number of A records don't match. gobuster enumeration also didn't give me the other subdomains. anything i'm missing?

jovial sun
#

hey guys, i so stuck at the question

Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)

i have identified the exploit on msf and with searchsploit but when i try to run in msf i gett

[] Scanned 1 of 1 hosts (100% complete)
[] Auxiliary module execution completed

where is the result lacated? any ideas

odd shore
true tendon
jovial sun
#

this is getting started - public exploits

true tendon
# jovial sun this is getting started - public exploits

oh yeah, so once you have the exploit you need loaded onto msf, do show options, and that should give you a set of options. find the options you need to edit and edit them accordingly, it should have the descriptions for them, see if that works

jovial sun
#

i have tried and it says its complete but i get no output

#

[] Scanned 1 of 1 hosts (100% complete)
[
] Auxiliary module execution completed

#

its supposed to make a file with the output right?

true tendon
#

that's my hint, make sure to read all of the options

glad orbit
#

@west canopy nothing to do. The user netadm is added to the administrator group but either by starting cmd as an administrator or with a reverse shell it still gives me access denied to the flag.txt

paper crag
quaint marsh
#

I've got the same story. No matter what I send, it always says: "Check your mail"

leaden sail
#

hello there, i have a problem with the Recursive Fuzzing Task from the Attacking Web Applications with FUFF module.

I went through the website with FUFF and got an HTB code but the website tells me its wrong what should I do? Or is this just a false flag?

quaint marsh
#

this is no problem! in the ddt file specify the path to the file. but how to cause an error?

glad orbit
#

@leaden sail use HTB{CODE}?

leaden sail
#

I did

glad orbit
#

send me the flag in PM (I verify with my code)

hollow hinge
quaint marsh
#

Hi! how to trigger an error?

lethal atlas
#

I used cdata

west canopy
#

@jovial sun Yes , it should save the contents to a file

distant stream
odd shore
severe birch
#

I have finally given up the hope of getting it on my own, would someone be able to give me a good nudge on footprinting easy lab?

west canopy
#

@severe birch try connecting to the vsftpd port (2121) just like you would connect to ordinary ftp. From there you should be able to find a file that will allow you to SSH into the target πŸ™‚

severe birch
#

Would this be assuming the use of the hint? Or without it?

west canopy
#

with the hint, you won't be able to SSH in without the username

acoustic owl
#

Hi all, is there anyone who can help me with Web Service & API Attacks - Skills Assessment?
I can't find the attack point.

i think it should be the login parameters. But it doesn't work.

Can someone nudge me in the right direction

#

The service always hangs.
Yes, there is this hint that the service hangs, but how should I test if I really use the right parameter?

west canopy
#

@acoustic owl DM me πŸ™‚

rustic sage
#

hey im doing the network traffic analysis module and i have a general question. if some one has time to explain. the txt goes "By issuing the -nn switches as seen below, we tell TCPDump to refrain from resolving IP addresses and port numbers to their hostnames and common port names." my question is why is it important to refrain from resolving ip's and port numbers?

maiden slate
#

I'm just throwing a guess out there but it may cut down on the time for the program to execute.

rustic sage
#

ah... probably becomes more apparent the further you get into the course.

slow ruin
#

Having some trouble with File Inclusion - Automated Scanning.
I fuzzed the web application for exposed parameters but when testing them none seem to be working. Granted I am getting a ton of exposed parameters. Could I get a nudge on this?

west canopy
#

@slow ruin Look for FFuF outputs with a size of 3309 , as opposed to the ones with a size of 1935

slow ruin
west canopy
#

right you need to fuzz the parameter name first. It's actually /index.php?view=FUZZ

slow ruin
#

yea just found that out notice view was a different size to all the others

severe birch
#

Could someone give me a nudge for the footprinting hard lab? I feel totally lost. I've seen a hint from someone previously but I still don't know what to do with that.

stiff tiger
distant crag
#

could anyone help with the medium lab in network enumeration w nmap? thanks!

unreal sigil
#

not sure what I'm doing wrong here for cracking into htb > getting started > public exploits module

west canopy
#

@unreal sigil for RHOST you just want the IP address and no port. For the port, you want to set that as RPORT

#

@distant crag For medium lab I had to use the pwnbox to get the answer. Try doing nmap -A

#

@unreal sigil

distant crag
#

@west canopy it doesnt bring up anything that looks like dns info

west canopy
#

@distant crag DM me πŸ™‚

livid pier
west canopy
#

awww shucks

low gyro
#

Hello. I am starting the academy module "Web Requests", and I have a question about something on there. Is there supposed to be something else where I have circled on this screenie, or no? It looks like a broken link to me. TIA!

#

same here too.

west canopy
#

@low gyro Image is loading OK on my end.
Maybe try different browser?

low gyro
west canopy
#

I'm using Brave browser at the moment

low gyro
#

weird - same with chromium

livid pier
#

On another note, why build more password attacking mods?

#

So far the info isnt that different than the other two and the pain is still here

low gyro
#

gonna reboot into Windows, see if it's a Linux thang...

livid pier
#

I am only 3 sections in but 😫

west canopy
#

you like the abuse

livid pier
west canopy
#

I want to be on my death bed , waiting for a password attack to finish

#

and i will tell my grand children, when i die, i need you to try rockyou-50.txt

livid pier
#

It could be a cool drama scene a nuke is about to come in from orbit and the only way to stop it is to crack a password a divert it via satellite

low gyro
#

nope. same results as with Linux. Image links are broken - for ME only πŸ˜•

livid pier
low gyro
#

lol

west canopy
#

Yea the password attack thing. I don't know man. I don't think ive ran into a box yet where I actually just straight brute forced credentials.

#

like usually you find credentials hidden somewhere and re use a password or something

#

but never just straight using hydra

livid pier
#

while doing boxes i have used rock you a couple times, almost always on hashes that crack instantly

west canopy
#

yea cracking hashes with rockyou is pretty standard

#

but like trying to bruteforce SSH credentials never works

livid pier
#

agreed tho, i feel like if you are relying on brute forcing you are doing something wrong

livid pier
#

And how many common applications let you just try to brute force without blocking your ip?

low gyro
livid pier
#

llol that is interesting the /35 loads with images for me and /module link tells me this method is not supported

west canopy
low gyro
#

you are prolly way cooler than me, s'the only explanation I can come up with

livid pier
#

Add that picture too

#

Finally title it =ICE COLD=

mortal basin
#

This is a known issue. We're working on it

low gyro
livid pier
low gyro
#

I did forget the Ice Cold part, so they'll prolly just shitcan it anyway ;-P

livid pier
low gyro
#
  1. noticed, and 2) stolt that shit for future usages 😎
west canopy
#

lend me some suga i am yo neighbor

livid pier
#

SHAKE IT

low gyro
#

well, it doesn't seem to work as intendedwhen asking the wife to get up and make me a sanwich...πŸ€”

#

but I did get an insta-response!

west canopy
#

*sammich

livid pier
#

Then what makes, then what makes what makes, what makes Love the exception?

west canopy
#

i actually bought that CD when it came out

#

i think I was in middle school?

livid pier
west canopy
#

Stankonia

livid pier
#

no, love below

#

it was the first double cd

#

the start of the split of outkast

west canopy
#

ah yea speakerboxx/love below

livid pier
#

I was thinking wtf was this

#

Turned out to be fire

west canopy
#

didn't the other guy write all of Andre's lyrics or something

livid pier
#

big boi?

#

no

#

may have been the other way around

#

I dont think so they both had unique styles

#

3 stacks is my favorite rapper

west canopy
#

icy hot stuntaz

livid pier
#

gator boots with a pimped out gucci suit

unique valve
#

Andre 3k is very underrated. The man is a legend on the mic.

#

I feel the same about Black Thought from The Roots

livid pier
#

But ya it took a while for peopleto recognize