#modules

1 messages · Page 519 of 1

raven cairn
#

You can.

#

Both should work

rough radish
raven cairn
#

@rough radish I will warn you, this module is difficult haha

#

Especially the skill assesment

#

But you can do it

rough radish
#

@raven cairn all is to me, but, the measure of which I have learned something is whether or not it was obvious to me at first glance. (stole that quote from somewhere, lol)

coral saffron
#

.

red obsidianBOT
#

There is no flag here. Get back to hacking!

rough radish
#

so, this seems like cheating... i assume these are all in the same module i am learning

root@NIX02:/root# locate flag.txt
/root/cron_abuse/flag.txt
/root/kernel_exploit/flag.txt
/root/screen_exploit/flag.txt
root@NIX02:/root#

blissful verge
rough radish
blissful verge
#

ya I figured the majority of people would be here to practice and not just submit flags 🙂

sweet heron
#

I really like the File Inclusion module. I'm working on the final lab rn and it's really well done!

proud sparrow
#

hello everyone

#

THIS QUESTION: " Before you run your page fuzzing scan, you should first run an extension fuzzing scan. What are the different extensions accepted by the domains? (Write the extensions as '.ext', in alphabetical order separated by spaces ".ext1 .ext2 .ext3")"

#

but return with zero results ,why?

west canopy
#

@proud sparrow Try running that same scan but against the other vhosts you found from the previous question. One of them should work.

proud sparrow
#

i did man but its the same

#

listen i watched video on youtube i did the same as he did he was solving the same section same question but for me didnt find results like zero

#

now i tried to restart my pwn but now its worse its fucked up

#

i tried to start from the first question and nothing shows...i wanna show you

weary forum
#

Hello, everyone. I am having trouble understanding the error messages that I am getting on the Web Requests module. I am trying to update one of the api entries to "flag", but I get either the "unknown field entry" error message or the ">"

#

It is supposed to be self-explanatory. I first tried: "curl -X PUT http://SERVER:PORT/api.php/city/flag because I assumed that the answer wanted me only to change the "city_name" field in the table. However, I got the "unknown field entry" error message. I don't know what that means. lol

west canopy
#

@weary forum Can i see your command?

sweet heron
#

LFI module completed! Done the last assignment without help! Altough I'm still unsure when exactly the RCE worked. I can't reproduce it.

#

Is it one at the time command like with a php session poisoning?

hallow otter
#

Hi all, I am struggling to find the password for the first account of the broken authentication final module. I filtered out rockyou.txt based on the password requirements and got 40 password but none of them is allowing me to access that user. Could someone lend a hand?

west canopy
#

@hallow otter DM me 🙂

rotund gust
#

Has anyone finished the Command Injections skills assessment? I'm at the point where I get a "Permission denied" error for my command and I'm not sure how to bypass this

west canopy
#

@rotund gust it will take several techniques to effectively cat the flag. Maybe try first running a simple command like ls. I think if you just add some apostrophes it should work, i.e. l's'

rotund gust
rich sequoia
#

Hello guys

#

I have just completed the Hacking wordpress module, i am the skill assesment( final test)

#

The target box generated is not wordpress though, it looks more like bootstrap.

west canopy
#

@rich sequoia try exploring the website, you should find a link to a vhost that is using wordpress

uncut stratus
#

Hi guys,

Broken authentication, skill assessment.

Can anyone please give me any hints.
I found only two users(s** and g**) from message.php, i tried using all the different username wordlists.

I tried tampering session cookie, for support user, it gives me error that role is incorrect for the user.

I tried brute forcing registration form, i got few mores users that gets message, invalid usernames. I’m not sure if invalid username means they are existing users or not, i tried them on message page, does not work

I tried brute forcing password, after applying password policy to rockyou.txt. No password match for any of the user. Filtered pass list has about 18-20 passwords.

Could anyone point me to the right direction.

Thanks in advance.

serene rain
#

@uncut stratus Did you use country codes to found usernames ?

maiden slate
#

Hey, I'm in the information gathering module attempting to enumerate the vhosts of www.inlanefreight.htb, I used the dnsrecon/namelist.txt file as my word list and it returned '1910' lines, I'm pretty sure I'm getting off on the wrong track, any guidance?

final salmon
#

Hello all. Looking for some general guidance on Skills Assessment for Broken Authentication. I have escalated from ‘nobody’ and now attempting to escalate to the proper person to get to the admin panel. Have tried several different things, just curious if I am doing the right things or if I have generally missed the mark on what is expected. Anybody willing to help, DM me and I will let you know where I am at and what I have attempted thus far. Thanks!

broken warren
#

I need assistance with sqlmap essentials case #3 cookie value (Id)
I run sqlmap -u "http://157.245.46.51:32390/case3.php" --cookie="I'd=1*" and I get some payloads but none of them show flag. I get one that dumps the entire table (32 rows) and another value at the bottom that I've tried to use as a cookie and i get error.

rustic sage
#

fuff

solar zodiac
#

hi everyone! Is anyone having connectivity problems with the VPN for the new AD module? I get disconnected every 10seconds and can't interact with the machines

#

im not sure if the problemis on my end

#

i tripped over my ethernet cable the other day and im not sure if I messed up my hardware

#

speedtest seem to run fine ...

iron tartan
#

I'm struggling with the first question of the skills assessment for Using Web Proxies. It says I need to enable the button on the /lucky.php page. I have tried modifying the HTML with my inspect element tool, and that seems to activate the button, but I don't get any flag returned. I'm not sure how to utilize my web proxy tools for this question if they're relevant

lethal atlas
lethal atlas
iron tartan
lethal atlas
#

I think there is a way in repeater to automate it.

sudden barn
#

i tried to connect but it says resource temporaly unavailable

#

what should i do?

tight mesa
#

@lethal atlas can I ask u some?

lethal atlas
#

of course

static ember
#

hi

#

hello

#

hello

#

???

lethal atlas
static ember
sudden barn
#

ssh root@host

lethal atlas
sudden barn
#

i close my academy tab, i think its bug

static ember
#

is there anyone

#

Where's everybody

#

@everyone

#

hey

#

Where's everybody

#

@here

#

@here

#

@here @here @here

#

@everyone @everyone @everyone

lethal atlas
#

what do you need friend?

surreal rain
#

++kick 871555635840446474

little whaleBOT
#

『ғʟʏ』Tuấn Anh ✈ got the boot!

static ember
static ember
#

i am sorry

surreal rain
#

That's not the way to do it. Do it again and you'll be banned from the server.

surreal rain
#

@high zinc

high zinc
#

Yeah... that's one way to get yourself banned 😂

solar zodiac
blissful verge
solar zodiac
#

the new AD module is so good :)

tulip plinth
#

Hello, has someone has a problem to find the FQDN of the nameserver on the "Active Subdomain Enumeration" (module INFORMATION GATHERING - WEB EDITION ). Any admin could help me? I already put the IP of the box on my hosts but I am not allowed to find the nameserver of inlanefreight.htb

blissful verge
# solar zodiac :D

glad you're liking it! how far are you? strap yourself in for the 2 skills assessments, they're like doing 2 full mini AD-focused pentests 🙂

civic merlin
#

Is there any specific order I should do the modules in?

dry pumice
#

for the last exercice of the hydra module ||the one with Harry Potter||
How long is it suppose to take ? I use the username generator and cupp with only the Name and Lastname and reduce the wordlist according to the rule but I just take way too long...

lethal atlas
lethal atlas
tribal linden
#

Hey. im in the web attacks module at the bypassing encoded references section and abit stuck.
Im trying to follow along with the steps in the module but when I do, I dont get a post request as expected, I get a GET request instead without the info in to replay? any ideas what im doing wrong?

blissful verge
# civic merlin Is there any specific order I should do the modules in?

if you're an absolute beginner i'd start with Learning Process, Linux Fundamentals, Windows Fundamentals, Intro to Networking, Intro to Web Applications, Web Requests, Introduction to Python3, Setting Up, Information Gathering - Web Edition, Getting Started, and then the Junionr Penetration Tester path from start to finish. a few modules aren't done yet in that path but will be released soon. If you have fundamentals down and want to learn AD then Intro to AD followed by AD Enumeration and Attacks and then the AD Enumeration skill path. If you want to learn web and have fundamentals down then do the Bug Bounty path. it really depends on where you are starting from. hope that helps

#

i'm sure others can weigh in on their own journey too 🙂

civic merlin
#

Thank you very much 😄

blissful verge
#

any time!

livid pier
lethal atlas
knotty falcon
#

For the Command Injections - Identifying Filters Module ("Try all other injection operators to see if any of them is not blacklisted. Which of (new-line, &, |) is NOT blacklisted by the web application?") every answer I submit is rejected as invalid even though I've verified that the operator is correct multiple through Burp. Is there a particular format the answer needs to be submitted in? I've tried URL encoding it as well, but that still doesn't work.

west canopy
#

@knotty falcon Yes , it is in the format of xxx-xxxx

dry pumice
knotty falcon
lethal atlas
livid pier
knotty falcon
west canopy
#

Sure

rustic sage
#

Can anyone help me "Windows Privilege Escalation" module, "Interacting with Users" section?

The hint says "Look for interesting shares that are writable by our user.". I run "net share" command, saw shares and found out that "Department Shares" is writable. Double checked that with "accesschk" tool.

However, when trying to create a file @Inventory.scf in the root of the share it says I don't have rights. I'm stuck with the section 😦

west canopy
#

@rustic sage my memory might be wrong, but i think there is a directory on the share called IT or something like that. Basically it's the only shared folder that you allowed to write to

#

Once you put the .scf file there you should be able to capture the hash with Responder

rustic sage
#

@west canopy when running "accesschk -s -w C:\Department Shares" it says that the only place where "htb-student" can write is the root of C:\Department Shares.

I'll try manually to create a file, but if that works out then it is strange why accesschk didn't show that

west canopy
#

I actually just used file explorer to search through the shares

rustic sage
#

I'll try your way and will respond in few minutse

#

You were right, Public/IT is writable by htb-student, thanks 🙇‍♂️

#

However, the open question then, why accesschk -s didn't show that big_think
That's the output for the folder where I was able to create a file by htb-student

.\accesschk64.exe -s -w 'C:\Department Shares\Public\IT\'

C:\Department Shares\Public\IT
  RW BUILTIN\Users
  RW WINLPE-SRV01\Administrator
  RW NT AUTHORITY\SYSTEM
  RW BUILTIN\Administrators
  RW WINLPE-SRV01\sccm_svc
hallow remnant
#

Requesting assistance with "Predictable Reset Token" module, specifically confirmation of the +-1 second aspect of challenge 1

tribal linden
lethal atlas
west canopy
#

@hallow remnant DM me 🙂

broken warren
#

Did you ever figure out the flag for case5 I also got the same result as you where it looks like another flag got mixed into also, is that supposed to be like that?

alpine summit
#

Hi all, tell me I'm on the Active Directory Enumeration and attack module, on the Privileged Access section. I have a problem with the Cypher Raw code. Is anyone blocked too?

west canopy
#

@broken warren feel free to DM me I might be able to help

alpine summit
tight mesa
#

anyone I can ask some about sql?

sweet heron
modern glen
#

Hi

tight mesa
sweet heron
#

yes

tight mesa
#

did you do the question?

sweet heron
#

yes

tight mesa
#

ok.

hallow remnant
#

Careful about posting too much explicit work; this might be more appropriate as a DM

tight mesa
#

sorry

#

agreed

hallow remnant
#

Requesting assistance on the "Broken Authentication" -> "Bruteforcing Cookies" part 2; my understanding is that this question implies we leverage CyberChef. However, I don't recognize the schema that the cookie is employing (and presume that there are layers of encoding taking place to obfuscate the cookie's contents). Welcome guidance.

solar zodiac
# blissful verge glad you're liking it! how far are you? strap yourself in for the 2 skills asse...

I really like the module. I´ve read through most of it but haven´t done any exercises. I was playing around with CME though, because it is a tool I need to be better acquainted with. So far, the content is incredible :)! I also really like the stories about irl pentest attack paths. I didn´t know you could use an SCF file with responder to capture an NTLMV2 hash! I think the module also complements the PEN-300 and CRTO really well. Knowing how to enumerate paths for lateral movement is something I wasn´t too well versed in( I always just clicked stuff on bloodhound and hoped the attack path would be in the graph)

#

Academy is my favorite learning platform for IT stuff, and I think this is my favorite module

#

:)

sweet heron
#

Did not try other alternatives as I don't know them yet, but i'm kind of addicted to complete all modules right now.

blissful verge
#

Y’all are burning through them! We’ve got loads more coming though

sweet heron
blissful verge
sweet heron
#

thanks!

rustic sage
#

can someone help with the web proxy module ive been lost for a few now and cant seem to move forward.

vital bough
#

active subdomain enumeration been stuck on question one for toooo long anyone help?

sweet heron
#

?*

rustic sage
#

i found the high level vuln i just cant seem to figure out how to use it

sweet heron
rustic sage
#

ahh okk

west canopy
#

@rustic sage DM me 🙂

#

@vital bough I got you dawg !

vital bough
sweet heron
#

I'm stuck right at the beginning of sql injection final skills assessment. I'm trying to trigger an error to have a hint about the vuln to exploit, but nothing gives. This is surely not a blind injection. Any tip?

west canopy
#

@sweet heron EDIT: I'm a doofus, I was thinking SQLMap Essentials. Sorry

sweet heron
#

I've red source of index.php and check every other file available. Even fuzz the /pages but nothing.

#

Ok, np

rough radish
#

OMG does anyone thing they made the Linux Local Privilege Escalation final assessment too hard? I cant even get flag #1. Only a reference in the .bash_history file I'm pulling my hair out here

west canopy
#

@rough radish Try searching for hidden files and folders inside /home/htb-student 🙂

rough radish
sweet heron
#

I've been spoiled in finding a hidden webpage, but I can't access it. I can't found any hosntame to add to /etc/hosts and I also found it with ffuf. I can access the code just fine in burpsuite, but I'm only getting a white page on firefox (with no source-code). Resetting target doesn't work. What am I missing? (sqli module skills assignement)

sweet heron
#

yes. But further.

feral gyro
shadow verge
#

Is it on purpose that on the DCSync section the AD enumeration and attacks module, the host is not running ADWS, I did managed to do the tasks on the host, but I was not able to anything with the linux host where I was able to ssh in.

#

and also built-in ad cmdlets did not work

rustic sage
#

Me again with "Windows Privilege Escalation" module and "Miscellaneous Techniques" section 🙂

I've managed to get the SYSTEM shell and using lazagne (I tried mimikatz as well) I get the hashdump of passwords. When trying to decrypt it with both john and hashcat, I'm not getting the cleartext password.

So the question is:

  • what must be the user to which I need to grab the password? (it says nothing about username in the question there)
  • am I missing something and I need to do something else?

P.S. there are some troubles with understanding the "Windows Privilege Escalation" course 😦 Would be great to have the content more "explained" there.

winged roost
#

anyone here having a similar issue ? im trying to do the XSS session hijacking room and when entering IP all im getting is a black background

lethal atlas
lusty vigil
#

hi, i’m stuck on Login brute forcing Module in last section “skill Assesstment - service login” I try all combination of user and password with hydra but nothing I can’t find the credential I use cupp for generate password and username-anarchy for generate users. Any hint? Thank you

lethal atlas
lethal atlas
lusty vigil
#

I use that options but with only name and surname I have more than 70000 login tries, and I use regex for reduce the length of the wordlist

#

And username-anarchy generate me 15 usernames

tight mesa
#

hello everyone

#

who can give me a hint about how treat this question from SQL fundamentals module:

We see in the above PHP code that '$conn' is not defined, so it must be imported using the PHP include command. Check the imported page to obtain the database password.

#

basically, I need to understand how import what I guess is a variable {$coon} with PHP include command?

muted rampart
#

you need to find out which file is imported by looking for "include" or "require" and then get this file from the server and look into it. in there you will find your answer

muted rampart
lusty vigil
#

ok, thanks

lethal atlas
sudden barn
#

hi guys i need help

#

i cannot connect via ssh

#

im on htb-virtualmachine

livid pier
sudden barn
#

its MYSQL - query results

#

i reset the target but same result

lethal atlas
sudden barn
#

i tried on htb-cloud where vpn is already connected

#

im leaving the course i think, gonna try another

lethal atlas
sudden barn
#

its bug i suppose

blissful verge
#

that's MySQL not SSH

#

swap for the IP of your target

sudden barn
# blissful verge

that mean i tried to connect via ssh, but it was just connecting through MySQL right?

#

i feel stupid xd

livid pier
sudden barn
#

Thank u dude

blissful verge
#

no dumb questions, purpose of Academy is to learn. even the module authors are constantly learning new stuff as we work 🙂

wary cairn
#

Alguien que me ayude con cuentas de Facebook?

sweet heron
#

no hay modules sobre facebook aqui.

livid pier
#

jajaja

rough radish
#

Hi guys,
The hint for the 4th flag in the LLPE skills assessment is not enough for my thick skull. It feels like I have tried everything for the last 24 hours
Any nudges' in the right direction would be a massive help.
Logging into the host-manager seems like a rabbit hole.
I have nmap scanned everything, including the barcode of the can of Pepsi on my desk!

#

wait no hints i may have figured this out

#

It's amazing what a bit of sleep will do.... got flag4

tiny ledge
#

How am I supposed to do the phishing part of (XSS MODULE), when I cant listen to port 80, anyone have tips? - sudo nc -lvnp 80
retrying local 0.0.0.0:80 : Address already in use

modest moth
#

kind of disappointed in the Server side attacks module skill assessment. spent about 3 days doing that module and i was able to grasp all the information. I love the part with the python exploitation. The module itself was amazing, def my second favorite one behind the file upload one.

#

im just a bit disappointed in the skill assessment. was able to finish it in like 5 minutes.

drifting knoll
#

everything is easy if you know the solution

modest moth
#

haha true, i feel that. i guess i am leveling up even though i still dont feel it

winged roost
modest moth
#

going to try and take my knowledge onto the mainsite now

drifting knoll
modest moth
tiny ledge
# drifting knoll change the port

I'm not getting any traffic there since the code defaults for the port 80 as http, I'm unable to add the new port (let's say 21043) xss injection

lethal atlas
lethal atlas
rough radish
livid pier
lethal atlas
#

yes

livid pier
#

And instead of having the walk through, point people back to the mod, so if they needed to crack a password it would send them back to the module and section

tiny ledge
#

Is there a simple way to force firefox not to add the http(S) there, I keep getting disconnected as it forces the S part

livid pier
#

do you add the http yourself?

#

the only time i see id automatically add it is while using zap

lethal atlas
tiny ledge
livid pier
lethal atlas
sweet heron
#

For some reason, the flag I enter in sqlmap case 5 is not working (even after --no-cast with -T flag5). Any help?

tiny ledge
lethal atlas
west canopy
#

Hello friends

livid pier
sweet heron
#

yo!

tiny ledge
#

I'm hosting a php server and when I connect to it throught he /phishing/send.php, I get this error while listening, what am I doing wrong?
10.129.118.57:58680 [404]: (null) /phishing/index.php - No such file or directory
10.129.118.57:58680 Closing

#

And why is the port changing from the original command? - sudo php -S 0.0.0.0:21304
[Tue Apr 26 20:56:16 2022] PHP 7.4.21 Development Server (http://0.0.0.0:21304) started

west canopy
#

So in the 10:129:118:58680 , the 58680 is the ephemeral port coming from the target I believe. It's just a random port number that the target is using, but it is still trying to reach your PHP server

#

Do you have an index.php file in your PHP server?

tiny ledge
#

Even if I host as: sudo php -S 0.0.0.0:21304/phishing/index.php | I keep getting the error

livid pier
tiny ledge
#

─[eu-academy-2]─[10.10.14.201]─[htb-ac395349@pwnbox-base]─[/tmp/tmpserver]
└──╼ [★]$ ls
creds.txt index.php

#

If I set the page -> /phishing/send.php | and put 10.10.14.201/index.php | I get 200 okay, put nothing is written in creds.txt | if I put 10.10.14.201/phishing/index.php I get the error above

livid pier
west canopy
#

I remember this section took me a few tries to get it to work properly

rustic sage
#

I dont know what any of you guys are talking about.

livid pier
rustic sage
#

I mean im trying to get in to hacking or coding but have no idea how to

livid pier
#

thats a good start, probably a better way to start that convo tho

rustic sage
#

whats convo

livid pier
#

The attempt to get help or ask a question

west canopy
#

its short for "conversation" 🙂

rustic sage
#

ok, thanks

#

ok

sweet heron
#

How are we suppose to know a vulnerable parameter uses non-standard boundaries like in sqlmap case 6? Without the hint which tells what prefix to use, how could I find out?

hallow remnant
tough dragon
#

hey, does anyone know the release date for any of the Coming Soon modules?

hallow remnant
wary cairn
#

how can i get into a lost facebook account

livid pier
restive frigate
#

wont let me unlock a module wtf

#

screen just resizes

livid pier
#

could be a browser problem, a cube problem, is the mod completed? Which mod is it?

manic zealot
#

Need some help in web attacks module, advanced file disclosure section question. Couldn't get the flag using provided dtd file (I changed the file entity to "file"///var/www/html/flag.php").

sly grotto
#

hey can u help me please?

#

i also get stuck in Blacklist Filters / File Upload Attacks

#

can anyone help please?

sly grotto
gloomy tangle
rich wharf
#

I am trying to do the Skill Assessment in the Broken Authentication module. I have identified the (only?) other account and how to log into it using a cookie. How can I progress from here?

#

Fuzzing directories/accounts results in nothing new

#

could anyone provide advice/point in the right direction

frigid vector
#

Hey guys need hint on SHELLS & PAYLOADS (reverse shells chapter)

lethal atlas
meager lynx
#

I need some help with Burp Intruder, im stuck on the two last parts of assessing 'Using Web Proxies'-module

lethal atlas
meager lynx
#

Can I DM you so I dont spoil anything?

lethal atlas
#

sure

lethal atlas
#

I need someone to help me with buffer overflow in linux skills assessment. I am missing something. I can get a reverse shell but only as htb-student.

severe birch
#

I am trying to do the windows priv esc skills assessment 1, but I am having issues with the command injection. It is only letting me execute certain commands and not those that I need to use.

urban sage
urban sage
west canopy
#

@severe birch were you able to get a foothold?

lethal atlas
#

37 modules complete.

livid pier
urban sage
west canopy
#

@lethal atlas what's next? 🙂

lethal atlas
#

gonna run thru the windows buffer overload and finish out tier 0

#

then back to HTB to work on another machine.

livid pier
lethal atlas
swift cove
#

Were you able to get this to work with just curl IP:port -H 'Authorization: Basic YWRtaW46YWRtaW4='? I am having the exact same problem you reported, but trimming the Copy as cURL request to only have this info didn't give me a flag

west canopy
#

@swift cove Feel free to DM me if you're still stuck 🙂

stiff tiger
#

I am stuck on last question of attacking web applications with ffuf -Try fuzzing the parameters you identified for working values. One of them should return a flag. What is the content of the flag? - I have used lots of wordlists - found many possible values - but all of them are returning "You don't have access!" - anybody DM me and give me a hint on what I am doing wrong and confirm the wordlists I have used are not good one? Thanks

west canopy
#

@stiff tiger last question of the skills assessment?

stiff tiger
west canopy
#

@stiff tiger DM me 🙂

sweet heron
#

Any little hint on the sqlmap skills assessment? I didn't find any attack vector yet. I've intercepted all requests with burp and clicked a lot. No parameters found. Same with ffuf for pages, params, extensions, etc. I checked HTML code too. Search bars aren't working.

#

I must have missed something!

west canopy
#

@sweet heron try adding an item to your cart and intercept the request , this should give you a clue as to the attack point

sweet heron
#

OK thanks a lot for the hint. Might've missed it cause I remember doing it! Once again, you save the day!

west canopy
#

np! The actual attack takes a bit of fine tuning to make it work so if you get stuck feel free to DM me

mortal basin
mortal basin
wide wasp
#

i might be stupid but i cant figure out the dang password for the Appointment
any help be great????

wide torrent
#

hellooo, im just curious if someone could help me with a http request question i have.

west canopy
#

@wide torrent sure, what's up?

wide torrent
wide torrent
west canopy
#

So if we are doing a command injection against a website, we can't really navigate around and change our current working directory. The command we inject will always be inside the webroot.

wide torrent
#

is it ok if i share ss here

west canopy
#

yea

wide torrent
west canopy
#

so you could do ls+node_modules

#

and it would list everything inside that directory

wide torrent
#

ahh that makes alot of sense ty

west canopy
#

but every command you run , you will always be at the same location

#

if that makes sense

wide torrent
#

yeah tahts where my issue was

#

i could not see how to show dir without moving

west canopy
#

it's not like a Terminal where we can move around and change our current directory

wide torrent
#

so you need that + to chain commands together im guessing

west canopy
#

yep

#

they might need to be URL encoded

wide torrent
#

no its been fine with plain text its just for the web proxies lab, the repeating requests section

wide torrent
#

@west canopy do you have a good cheat sheet or link for commands like this still having some issues

west canopy
#

Not really, in the case of the web proxies module it is mostly just using linux commands to enumerate the file system

#

cat flag.txt , etc.

wide torrent
#

so if i wanted to move into a second dir ffrom node_modules what would i use

west canopy
#

so if we found a directory inside of node_modules , we can just call it fake_directory

#

we would need to do: ls node_modules/fake_directory

wide torrent
#

ok sorry im still learning the syntax i really appreciate the help

west canopy
#

np. Also i would suggest looking in the root directory.

plucky current
#

For all of you bash experts . . .
I am performing a hashing function and then want to count the number of characters in the variable that contains the hashed value.
If I use number=${#var}, I get an error.
But, if I use number=$(echo $var | wc -c), I get the correct value.
Does anyone know why that is happening?

plucky current
#

hmm. I was working on the "Flow Control - Loop" question and when I used the ${#} it returned the following message:

*** WARNING : deprecated key derivation used.
Using -iter or -pbkdf2 would be better.
bad decrypt
139916277388672:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:../crypto/evp/evp_enc.c:610:

feral gyro
#

is this one specific to any module

plucky current
#

@feral gyro Thanks. My review of some of the literature on bash says that there are some sh implementations whose ${#var} doesn't work properly with multi-byte characters (would return the length in bytes instead of characters). Perhaps that was the issue. I guess I'll just stick with the longer function until I figure it out.

rough radish
#

I need some help with the LFI, basic bypasses question.

summer lake
#

Hi guys, anyone knows if we are able to reset our progress for a module, so that we can reattempt the challenges again?

plucky current
summer lake
plucky current
summer lake
#

ahhaa, Have to brush up those that I've not touched in months

summer lake
plucky current
summer lake
#

Ah, was thinking of attempting the challenges again without the answers

#

I was thinking they might've made some changes as some of my queries are correct but the answer is different from my previous attempted challenges

plucky current
summer lake
#

Thanks for your help @plucky current !

plucky current
west canopy
#

@rough radish Feel free to dm me 🙂

torpid imp
#

Hello guys, I am doing SQL Map Essentials as my last module to finish the BASIC TOOLSET. I am now at the first task and I have the feeling that I have to do SQL-Injection module first that I am even able to do this module , is that right ? I literallty dont know where to start at the first task. I did the scan but dont know what to do after.

feral gyro
#

it is my opinion

#

understanding how to perform manual sql injections before automating it , is quite good

broken warren
#

I need assistance on sqlmap skills assessment, I can't even find where to start. I've used dev tools and found two jQuery with parameters. But those both fail, I can't seem to intercept requests through burp for the checkout or contact entries.

weary forum
#

Hello, everyone. I am having problems with the "Web Requests" Module, specifically the CRUD part of the module. I am supposed to add "flag" to the city API, and then delete any city name, and then I am supposed to search for flag to retrieve the flag.

#

But this is what I am getting:

#

That's me searching for the flag after I updated and deleted a city

#

The question is: "First, try to update any city's name to be 'flag'. Then, delete any city. Once done, search for a city named 'flag' to get the flag."

fathom chasm
#

Any nudge on the command injection assessment? can't find the injection point!

lethal atlas
weary forum
#

oh, ok. the instructions are unclear because it says that you should delete a city, but it doesn't say more than 1

vital bough
#

so you had to remove it from /etc/hosts or did you have to change the IP everytime you reset? Was the scan fast for you when it worked?

slow ruin
#

For the Password Attacks - Network Services section is there a suggested user.list and password.list to use? Currently using rockyou.txt for passwords and top-usernames-shortlist.txt and it's already taking forever

livid pier
#

It hasnt worked for me, but im guessing we are supposed to use those

slow ruin
#

@livid pier when you say it hasn't worked for you what do you mean by that? lol
Either all these password attacks are going to take forever or I am doing something wrong because I am still waiting on a username and password combo for the first question and it has been running for quite some time

livid pier
#

I had this problem with other password cracking modules too.

subtle mulch
# slow ruin <@920003707209416714> when you say it hasn't worked for you what do you mean by ...

Hi, my first hint: you don't have to solve the questions in the given order. One attack might work faster than others. (I've solved it in the give order and it worked with the lists from resources) Second hint: when you've found a valid login, what can you do to reduce the number of tries? Update: Have to correct my answer. I have used the password.list and an other one from the seclists folder

west canopy
#

Anyone able to give me a hint on Active Directory Attacks "Attacking Domain Trusts - Child -> Parent Trusts From Linux"? I have read over the section and gone through the examples, I can get a system shell but I don't understand how I am supposed to get the hash for the BRoss user.

livid pier
shadow verge
#

@west canopy try kerberoasting

#

oh actually i rememberd wrongly what i meant to say you have admin you can do dcsync

slow ruin
shadow verge
#

Yes I've been awake so long time, I'm messing things kerberoast gives rc4 hash and dcsync gives you the ntlm straight away.. Anyway I'm going to sleep now 🙂

west canopy
#

@shadow verge just solved it, thanks so much!

subtle mulch
west canopy
shadow verge
neat snow
#

anybody available to answer a question about the command injection skills assessment?

west canopy
#

@neat snow i can try, what's up?

wide torrent
#

is there a way to run responder the tcp server other than port 80, i use the pwn boxes and it errors out bc port 80 is in use

muted rampart
#

Hey there
I am totally stuck in the Broken Authentication module, section Bruteforcing Cookies, the second question. I can't find a way to decrypt that cookie...
could somebody help me please?

delicate lynx
#

hey yall, im just getting started and dont know how to add the VPN on mac?

openvpn isnt a command in macos so i cant add the configuration

west canopy
#

@delicate lynx you're probably going to want a Kali or Parrot VM

delicate lynx
#

if i cant use virtualbox, what should i use?

west canopy
#

could try VMWare

#

or the browser-based Pwnbox

distant stream
# wide torrent

Have you tried with sudo responder? You can turn off in responder.conf , but I’m not aware of any option to change the port….

wide torrent
#

responder.conf**

distant stream
#

Should be under /etc , or /usr/share/responder/Responder.conf …

wide torrent
#

yes that worked appreciate it

wide torrent
distant stream
#

Not really, the only possibility would be use https for inclusion?

sudden lotus
#

Hello I'm stuck on the loop Flow control question of the bash scripting module the loop i made works but i keep getting a decrypt error

#

error being :*** WARNING : deprecated key derivation used. Using -iter or -pbkdf2 would be better. bad decrypt 140546881238400:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:../crypto/evp/evp_enc.c:610:

west canopy
#

@sudden lotus feel free to DM me 🙂

sweet heron
#

Pretty sure no, but does someone know if you can tell sqlmap to "import" scan results from another ip/port (the box run out before I finished the scan). Changing the dir name maybe?

frozen lily
#

Working the Bloodhound module... trying to import the new data from ILF_BH.zip - not working out so well. There is no bloodhound.dump file. Help please!

rough radish
#

Hi guys, I have a comprehension issue with the Automated Scanning of the File Inclusion module question. When using FUFF utilizing the example provided, I only get things like " </avg>," etc. What in tarnation am I to do with that? Can someone give the command to scan either with FUFF or go buster so I can understand this?

rough radish
vital bough
sweet heron
#

Good to hear, good job!

swift cove
lethal atlas
#

case matters lol

proper sedge
#

Hi guys. I have a problem with unlocking modules. I have enough credits but when I click "unlock" nothing happens. Any help?

shadow verge
#

Is it on purpose I can't run SharpHound at AD Enumeration and Attacks Skills assesment, I noticed ADWS is not running?

proper sedge
muted rampart
#

Still stuck in broken auth bruteforcing cookies.... Could somebody help me? can't find that magic byte

winged roost
#

hey all on the XSS session hijacking module.... my script.js is bang on, same with index.php... as per the information in module, but when im sending the request im just not getting the cookie....tried various times, even tried doing as a curl request, same thing.

gloomy sigil
#

Hi guys, I'm about to finish the Active Directory Enumeration Path. There is left just one question from the Active Directory LDAP module, which is "What non-default privilege does the htb-student user have?"
This was supposed to be the easiest question but nothing worked, I tried from simple "whoami /priv" to using BloodHound (which is not covered in the module) but I don't what else I need to do.
Could anyone help me?

gloomy sigil
crude imp
#

Hello all, im just starting out in the academy and im in the setting up module, specifically the windows section and trying to run the command "choco install pkg1 pkg2 pkg" however it always seem to fail:-

Everything has been successful up until this point, can anyone help please 🙂

gloomy tangle
#

Server-side Attacks

frozen lily
gloomy sigil
frozen lily
frozen lily
merry anchor
#

ok

jagged zenith
#

I want change my name Suddenly I had this message

tribal plinth
novel matrix
leaden quail
#

but my browser decode it to:

#

i cant open it

#

if i encode %20 with %2520 and use it in the link

#

i dont work

#

how can fix this

unreal patio
#

Can someone dm me about intro to assembly?
I'm stuck at skills assessment first question.

frozen lily
#

Still working the bloodhound module... having a hard time figuring out how to query groups with high privileges outside of Domain Admins. The question is: "Using the attached data find the most privileged group after the Domain Admins group."

sweet heron
leaden quail
#

this is a command Injection against a Whitelists from Webserver which just allow specific file extensions

knotty hemlock
#

Hello, could somebody give me a little hint on the .zip-file decryption tasks in Password Attacks? I'm stuck at section "Protected Files" as well as on " Password Attacks Lab - Medium" and I wonder if I'm stuck at both for the same reason, because both involve zip-file cracking.

devout cliff
#

if anyone is available to assist me with the session hijacking portion of the XSS module please let me know

sweet heron
knotty hemlock
sweet heron
#

If I remember correctly, you need to use the mutated list. I'll confirm when I get home

west canopy
west canopy
west canopy
dry pumice
#

hey, I'm kinda stuck at the Directory Indexing of Hacking WordPress module.

#

I have to locate a flag in the enumerable directory of the site

#

but the only one I can enumerate is wp-includes which is just... huge

#

very huge

#

Am I doing something wrong or the flag is really hide in this mess ?

west canopy
#

@dry pumice Yes it's hidden in the mess . Feel free to DM if you need a hint

west canopy
rough radish
#

Word to the wise, I downloaded a wordlist and did not check the contents. It had the HMTL code of the www it was on and not the word list. Caused me two days of headache. Check your downloads!
@sweet heron This is why I was pulling my hair out.

devout cliff
#

figured out XSS module yay

jagged zenith
#

My account was suspended because I wanted to change my name, I sent a message to support and to whom there is no response

naive ravine
#

Can someone shed some light on log poisoning via php web shell?

#

Cannot understand what I am doing wrong when I try to change the User-Agent to a php web shell, it is not showing up in the logs.

jagged zenith
#

@languid fjord hey

severe birch
#

Hey I am trying to work on Windows Privilege Escalation Skills Assessment - Part II - I am on the last question and need to find the ntlm hash of the disabled local admin user but I am having trouble when dumping hashes the way I know. Can anyone give me a nudge on this? Thanks.

west canopy
#

@severe birch I was able to get it using pwdump

severe birch
#

Ok I'll give that a go - thanks

devout cliff
#

any have issues sometimes getting mysql database login to work on a pwnbox? doing sql injection fundamentals right now and not being able to login

#

nvm, reset both boxes and it works now 🤷‍♂️

west canopy
#

Anyone able to give me a hint on Active Directory Attacks: Skill Assessment 1? I've solved the first three questions but I'm really not understanding how to pivot to MS01 or DC01.

late beacon
summer lake
#

Is it me or is the SQL map hard :/

sweet heron
summer lake
#

I guess the SQL injection has an overwhelming load of text/information

sweet heron
#

Yeah, but it is a well done module. I learned a lot. Take your time

summer lake
west canopy
#

@summer lake sure, which section / question?

summer lake
#

Yooo

#

Thanks man

#

I'll pm you

devout cliff
#

im working on the sql injection fundamentals atm and enjoying it actually. i did sqlmap module first and then going back to this and im having a decent time at it. the module so far is well done.

agile bloom
#

Hello @west canopy I am trying to update it to enabled in the browser inspector and then click on the button to get the flag and it is still not working after 20 tries. I am wondering if I am doing something wrong?

west canopy
#

@agile bloom keep trying, it took me a bunch of tries

agile bloom
west canopy
#

there is probably a better way to do it using burpsuite but eventually it will spit out the flag

west canopy
#

np 🙂

agile bloom
#

I tired the burpsuite route, but was finally able to do it through the browser

cinder meteor
#

if this is agaist the rules then can someone plz tell me but i want someone to try to pull my ip, i would be impressed.

sweet heron
#

you from turkey?

prisma jewel
#

hey dudes i need late room hints ? pls

sweet heron
#

Any tip for using sed to delete sections of text between ":". I'm trying to find out the most common password in a list of this format: user : hash : password (no space) for final hashcat skills assessment. I believe sed could help, but it's hard to use.

west canopy
#

@sweet heron I did it using a combination of cut, sort, and uniq

sweet heron
#

I'm looking at cut right now. It's promising!

#

I've got 84.25% of the hashes for now.

#

Got it! Ok, cut, now that's a lot more easy to use than sed XD

west canopy
#

yes sed is obnoxious lol

slow ruin
#

Has anyone finished the Password Attacks Module? I am starting to think that most of these password attacks are built to take an obnoxiously long time...

sweet heron
slow ruin
sweet heron
#

yup! It takes a bit, but you'll get to it.

slow ruin
#

at this rate may even run longer then the box has time left for

devout cliff
#

SQL Injection Fundamentals CRUSHED in simple hours

#

muahaha

#

10/10 well explained module

sweet heron
#

I agree, really fun too.

summer lake
#

Hi can anyone give a nudge on the command injection skills assessment? Can't seem to find an attack vector

west canopy
#

@summer lake try moving to file to the TMP directory and intercept the request

summer lake
#

sorry i don't see any move button..

#

oh ok

#

got it

#

Thanks! @west canopy

languid fjord
summer lake
#

wow this is exhausting.....

primal salmon
#

Hello all, I'm working on the Information Gathering - Web Edition module and I'm stuck on the Active Subdomain enumeration section question that asks for a TXT record "Find and submit the contents of the TXT record as the answer." Been using dig and nslookup with no luck. Could someone DM me or give me a nudge on this? Think I've been stuck in a rabbit hole for a while now. 😅 I'm able to perform the zone transfer but I don't think I'm looking in the right place for the TXT record.

west canopy
#

@primal salmon DM me 🙂

summer lake
#

hello can anyone nudge me for the command injection skills assessment? :/

summer lake
#

anyone?

#

oh nvm 🙂

tacit topaz
#

Hello all, I want to crack a pass and I know he must have at least one special char so I want to delete the lines without special ?

gloomy sigil
feral gyro
summer lake
viscid maple
#

can anyone suggest me best VPN software for Windows (Free) with easily hand able.

#

Also Safe....

summer lake
#

For the file upload attacks: blacklist filters:

why is it all are 200 success with the same match length?...

rustic sable
#

I'm doing the Web Service & API Attacks module, and have been having major issues with intermittent connectivity to the target host. It happens when connecting from both the provided VDI instances, and my local workstation over the VPN. It will work for a while, then I won't be able to connect at all for a few minutes. Resetting the target doesn't help.

feral gyro
summer lake
feral gyro
#

dm

devout cliff
#

anyone around thats done the command injections module? i think im stuck on the last section before the skill assessment

devout cliff
#

no its the Advanced Command Obfuscation section

sweet heron
#

oh oops, haven't done it yet.

devout cliff
#

F

civic merlin
#

Im having trouble copy and pasting inside the workstation :(

#

I dont know why but whenever I try using ssh it wont let me type or paste anything in the password part

devout cliff
#

in bash?

civic merlin
#

yeah

devout cliff
#

does it give you a seperate password field after you input the other ssh information?

civic merlin
#

ssh htb-student@ip
htb-student's password:

#

it wont let me type anything after that

devout cliff
#

ok it will not show you the password for security reasons while you are entering the password

rustic sage
#

^^^^

civic merlin
#

so its there?

#

and its just invisible

devout cliff
#

yup

civic merlin
#

ahhh that makes so much sense

devout cliff
#

bash is nice that way

#

for security

civic merlin
#

thank you :D

ornate canyon
#

Hello guys, can anyone help me? I'm stuck in last question of the File Inclusion module

vital bough
#

what wordlist you use on ffuf assesment? I've tried a couple and can't get the third question, so stuck

sweet heron
sweet heron
west canopy
#

@rough pelican Try recreating the example "Viewing Sticky Notes Data in Powershell"

west canopy
west canopy
sacred arch
#

Hi! Literally I can’t answer the first question on debugger path- 🤦‍♀️I got an output with curl but it just says it’s been moved in the output. Am I just misunderstanding what they are looking for??? SOS.

west canopy
#

@sacred arch which module / section?

sweet heron
#

Tadaa! Basic Toolset completed!

shadow verge
#

@west canopy did you get the MS01 access? I'm stuck..

west canopy
#

@shadow verge not yet. I am reading through the module again. I feel like it's going to be something from these sections:

shadow verge
#

I think there was no trusts regarding bloodhound

#

I'll check with powerview too, this is hard assessment

west canopy
#

Right, to run a local bloodhound collector we need to be connected as a domain user. I also tried running Bloodhound-Python with the sql user's credentials but that didn't work either.

shadow verge
#

I ran bloodhound on system, but there was bug first

#

so i can't run it

#

but then i mentioned it to mrb3n and now i can run sharphound there

#

locally with system privs

west canopy
#

ohhh interesting

#

i thought that was intended

shadow verge
#

yes it was because active directory web services was not running

west canopy
#

Yea the Import-ActiveDirectory powershell cmdlet was not working for me either

#

or whatever it's called

#

But PowerView was working fine

shadow verge
#

yep

west canopy
#

I'm a little confused. Because the initial target does not have LDAP enabled. For stuff like bloodhound , does it gather data via querying the domain controller?

shadow verge
#

Yes I think it does, not sure tho

#

Get-DomainTrust and Get-DomainTrustMapping does not give any output on powerview

#

I found cached credentials for administrator@INLANEFREIGHT.local domain account but can't crack it

#

with mimikatz

west canopy
#

ah

#

i was thinking it had to be password re-use or something

#

maybe use Enter-PSSession to access the other machines with a different domain account but re using the sql user's password

shadow verge
#

Yes it is hard to use the pssession without fully interactive shell

west canopy
#

I still need to try it. I'm not using the web shell though, first thing I did was upload a netcat executable so i could have a terminal based shell

shadow verge
#

I used meterpreter

#

but it did still not function properly

west canopy
#

does meterpreter hashdump command work?

#

also how did you get a meterpreter shell?

shadow verge
#

no but i get the full dumps from mimikatz

#

and ran the shell with C:\windows\temp\shell.exe

west canopy
#

ah nice

shadow verge
#

I wonder if the local admin ntlm hash is reusable in the internal machines

#

I don't know how to login with NTLM from windows so I don't know

west canopy
#

right , i can't think of any way to pass the hash in this scenario

late beacon
#

PsExec.exe would work if you guys can get RDP access

#

You can try to pass the admin hash and execute cmd.exe

shadow verge
#

oh

vital bough
#

thanks @west canopy @sweet heron those little nudges help me from going completely insane. I love this stuff!

agile bloom
#

Web Proxies - Skills Assessment I am stuck trying in to set up the request to properly take the cookie and not return errors. I have mirrored the example above and my encoding is matching up to 88 characters for all entries, but I am only getting either all 200 matches or all 400 matches. Any help would be greatly appreciated

#

Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

west canopy
#

@agile bloom DM me 🙂

#

@gloomy sigil DM me 🙂

final salmon
#

Can somebody give me an example of SQL injection on an API endpoint, for example Web service and API attacks >> Information Disclosure >> Q2. I’m sure its super simple, but for whatever reason I am not getting anywhere with and my brain is friggin fried

open spruce
#

Hi, I'm doing the 'web requests' POST but I'm blocked I think I'm close to the end but do not know where to go

west canopy
#

@final salmon DM dawg i got you

#

@open spruce i got you too dawg hit me up

open spruce
#

@west canopy Thanks for the help 🙂

sacred arch
round lagoon
#

Ugh I hate this web requests section. So i'm at the skills assessment part where I'm trying to fuzz the last character of the md5 cookie but i'm going nowhere. I'm wondering if i'm not re-encoding it right or what

bronze sorrel
#

password attacks

silver laurel
#

was this a user error or problem with the module? I'm in the same boat, I've reloaded the page a few times and watched the requests

west canopy
#

@sacred arch have you tried running curl against the target?

#

@round lagoon Feel free to DM me and i can show you how to do it 🙂

round lagoon
bold forge
#

@silver laurel I did as the guide told me, but I'm not rulling out error ID-10-T lmao

silver laurel
silver laurel
junior mist
#

Thanks @mortal basin for the excellent "command injection" module, I really enjoyed it 😃

lethal atlas
proven parrot
#

hi, anyone can give me some nudges on skill assessment for broken authentication?

leaden quail
#

Hey, can someone give me some hints for the skill assessment for command injections. Stuck since 3 Days😅

crystal isle
#

Anyone able to answer an assembly question (Intro to Assembly Language - Conditional Branching)? Got the code to stop looping but my answer to the question is apparently incorrect

crystal isle
frigid ingot
#

So I seem to be banging my head against a wall here for web requests HTTP if someone is willing to clue me in on some things, I’ve already gotten further then I have been now I’m just stuck

frigid ingot
summer lake
summer lake
#

Can anyone help me with this: The above exercise employs a blacklist and a whitelist test to block unwanted extensions and only allow image extensions. Try to bypass both to upload a PHP script and execute code to read "/flag.txt"

#

I can't seem to run the bash script

leaden quail
#

just copy and paste it

summer lake
#

yeah it worked now

#

idk how i ran it...

#

suddenly appeared in my folder.

#

But thanks @leaden quail 🙂

summer lake
#

can anyone help with file uploads pls?

rustic sage
summer lake
#

still need help ):

rustic sage
#

hello in Active Directory Enumeration & Attacks
page LLMNR/NBT-NS Poisoning - from Linux
i cant crack the hashes that responder gave me hashcat keep on saying exhausted i use rockyou wordlist
my command : .\hashcat.exe -a 0 -m 5600 .\hashes\XXXXXXX.txt .\wordlist\rockyou.txt

blissful verge
rustic sage
#

yeah i am trying to upgrade responder on the vm that htb provide

#

to see if that help

#

it changed nothing

rustic sage
#

so updating responder did change something but i still cant crack it

unique valve
rustic sage
#

i will try again

gray cypress
#

Hi My friend,
I try to solve chalange "Bruteforcing Cookies" from "Broken authentication" module.
in question 2, we should try decode cookie after login with htbuser:htbuser. I can not understand, how to detect type of cookie algoritm encode and then decode it.
example cookie: 5s4539pp9etrtf6hlhg04o4ob8
plz help me.

rustic sage
#

sorry havent bought the module yet

rough pelican
#

Maybe you have more than one line? A bad copy paste?

rustic sage
#

oh shit it worked

#

it only work on 1 hash

rough pelican
#

GJ 🙂

rustic sage
#

it works

#

To fix this issue for anyone facing the same : I installed the latest cuda driver on my host, used the latest responder ( downloaded from github ) the one on the box give different hashes, make sure the hash is on 1 line after copying ( no spaces ).

#

also thanks on mrb3n, Itnbob for the response

vital adder
#

Hi, I need help with the Password Attacks module section Skills Assessment. In the first lab (Password Attacks Lab - Easy), I couldn't even brute force anything because it took me 3-4 seconds to send 1 request. I let it run for like 80 minutes, and it was able to brute force 8 users. Am I doing anything wrong? For the second lab (Password Attacks Lab - Medium), I did manage to get the zip file, but after extracting the hash, I couldn't crack it. I try every wordlist I have (rockyou, fasttrack, hashkiller-dict, ..)

rotund gust
#

Anyone I can dm for the file upload attacks skill assessment?

shut bronze
#

guy i need help on windows file transfer

west canopy
#

@gray cypress are you checking the box for "remember me" when logging in? You want to decode the HTBPERSISTENT cookie

#

@rough pelican Try running the powershell command to view sticky notes

balmy creek
#

Send screen shot

shadow verge
#

anyone got a hint for finding CT059 credentials in AD Enumeration and Attacks Skills assessment Part 2 ?

west canopy
#

@shadow verge Were you able to finish assessment Part 1?

shadow verge
#

Yes

west canopy
#

Any chance I can shoot you a DM?

shadow verge
#

Yep

#

DM me

icy pelican
#

Can you guys help me with the ssh practice on the academy? Im hard stuck there hehe

small panther
#

Anyone mind helping me out with the SQLMap Essentials Skills Assesment?

small panther
# sweet heron Where are you stuck?

@CryptoAnar84 Skills assessment flag. I have a hypothesis a POST request needs to be exploited, but can't figure out the parameter. I have been using burp to help gather information.

stiff tiger
#

I did that section a while ago, but my notes are not great - if you are desperate, send me a DM and I will try to help

sweet heron
small panther
sweet heron
slow venture
#

for the XSS - Phishing module, did anyone else have issues with using port 80 like it says? I've tried other ports but not working

sweet heron
slow venture
#

i think something may be using port 80 for listening but i looked at ss -ntlp and theres no service to shut down

spice olive
#

Hello guys, can someone help me with a in issue? Im stuck at the "Information Gathering - Web Edition" - Active Subdomain Enumeration, and each time i try to use the nslook tool to scan the domain "inlanefreight.htb", it returns me this message "** server can't find inlanefreight.htb: NXDOMAIN **"

I've allready add the vhost to the /etc/hosts file, and nothing seems to work

plucky bobcat
#

Hello, need help for the Q3 - Skills Assessment - Information Gathering, i tried a lot of thing but idk impossible the submit the right NS

devout cliff
#

for the skill assessment in command injections im trying to figure out which part of the webpage is my injection point, can i get a hint?

vernal bough
#

I am working on Tier 1 - Responder and I can not get the web page to open. I have a pi running pi-hole with a recursive dns server. I am assuming that is the reason. Anyone else run into this?

sweet heron
vernal bough
shut bronze
#

why i cannot write on other chanels. how do i know if i get banned?

final salmon
#

Looking for some friendly guidance on Web Services and API attacks module assessment. If anybody is available?

sharp violet
sharp violet
devout cliff
#

yeah im hardstuck now on this skills assessment for command injections someone please help

sweet heron
#

In the session hijacking section in the XSS module, the target's registration page doesn't work: nothing happen when I click on "register"

spice olive
rotund gust
devout cliff
#

i figured it out with some assistance

#

i figured out the injection point but was stuck on not really receiving additional feedback from using commands

#

but got it figured out

rotund gust
#

ah i see, nice!

#

i'm still stuck on the file upload attacks skill assessment 😅 but doing another module for now

devout cliff
#

thats the next module ill be doing also

#

probably starting it tmrw

crystal quail
#

anyone else having connectivity issues? or is it just me?

sweet heron
#

Did they changed the answer of command injection module, identifying filters? The character that fits the answer is blacklisted for me. Another one is not blacklisted...

#

Ok, I see its url encoded version is working, but the & still works (but not its encoded version). So there are two good answers, right?

crystal quail
#

Finally - I've completed the "Starting Point' content, and now I'm starting the 'Beginner Track". Does this still use the 'Starting Point' VPN, or do I need to disconnect and download another ovpn file?

west canopy
#

@spice olive DM me 🙂

#

@plucky bobcat Feel free to DM me as well !

raven cairn
#

Information Gathering Web-Edition: Subdomain enumeration. I have been stuck on this section for a while. Help would be appreciated.

summer lake
#

hi guys, is xss able to search for files ? like cat flag.txt

#

ty

distant stream
#

Xss can lead to rce -e.g. CVE-2021-37794- From XSS to RCE -or htb retired machine CrossFit-. The retired book machine has an example XSS Fileread

jagged zenith
#

My account was suspended because I wanted to change my name, I sent a message to support and to whom there is no response now i have 3 days I emailed technical support, what do I do?

primal sundial
#

It's been the weekend

#

You'll probably get a reply tomorrow because it's bank holiday today

novel matrix
#

It's Holiday for AU as well today. @jagged zenith waht do you mean email?

#

We have a bubble chat support

jagged zenith
novel matrix
jagged zenith
#

In order to solve this problem

#

But it has not been resolved

novel matrix
#

Create a support ticket rather email.

jagged zenith
jagged zenith
rare jackal
#

could I please get some help with Broken authentication module weak bruteforce protections second question?

dim yarrow
#

Can someone help me with the Web Attacks module in the Blind Data Exfiltration section. The tool XXEinjector doesn't get anything out and when I work with Burp and the PHP script I don't get a response from the server.

sly grotto
#

can someone help me please in File Upload Attacks Skills Assessment - File Upload Attacks?

sly grotto
gray cypress
lethal atlas
#

gm academy

little talon
#

Afternoon all, I'm on Nmap Enum. What is the best way to enum FTP, SMB, SMTP and Shares?
Are the nmap scripts the best only way?
i.e. nmap -p 445 --script smb-enum-shares <IP>

raven cairn
little talon
#

Hi yaoi74, are you able to help with my question above? I'm on the Nmap Enum Module

raven cairn
tight mesa
#

hello everyone

#

who can give me a hint with this AD question:
What AD object handles all authentication requests for a domain?

sharp violet
tight mesa
#

I tried some with no success

lethal atlas
tight mesa
#

or I really don't know read or .........

lethal atlas
#

has anyone done the windows buffer overflow module? Im on the skills assessment but the program I download just comes up a black screen.

pseudo kiln
#

Same here. I can't find the member of Remote Management Users group. Did you succed in the end ?

lethal atlas
#

VM

tight mesa
# lethal atlas

the 2nd option is what I though from the beginning but LoL "s" made me crazy

lethal atlas
#

I run a Kali VM. I did install most of the tools myself except for powershell which I have not really needed much.

#

looks like powershell is installed in kali by default

#

I dont lose internet

#

My vpn is connected all the time and I still have full access

#

no

#

I also dont use virtual box

#

My VM runs on a hyperv server

#

one network interface, NAT enabled

blissful verge
#

@lethal atlas come over to the dark side and use Parrot 😉

lethal atlas
#

I have considered it but the time it would take to move all my tools and notes....ugh

blissful verge
#

ya transferring everything is a pain

lethal atlas
#

hey @blissful verge can you tell me if the win32bof.exe file from windows buffer overflow is supposed to only open a black screen?

blissful verge
#

is that the skills assessment?

lethal atlas
#

yes

blissful verge
#

yes its intended to just print errors

lethal atlas
#

ok I was just making sure there wasnt something wrong on my end. Thank you.

blissful verge
#

no problem!

kindred scroll
#

Am I the only one who finds windows stuff too overwhelming? I am doing AD (Tier 0 one) now and I can't fit so much terminology and stuff in my head anymore. I hope I can get better one day FeelsBadMan

lethal atlas
#

TBH, I despise windows.

#

And I work in an AD environment

kindred scroll
#

How am I wrong?

knotty blade
#

hello group, sort of stuck or puzzled. on intro to bash, comparison, I successfully wrote the script down to the end and used tail -c 20 to print the last characters and get 15 lines, which I have no idea where the answer the module is looking for is within these lines?? please any guidance would be appreciated. thanks

lethal atlas
kindred scroll
#

Ahh I am so dumb

#

it said messages in the question so I don't have to repeat it in the answer

plucky plover
#

Hey i just started learning htb after i was told to try and learn using it after doing some picoCTFs and having fun doing them. Is there some other stuff i should learn before getting into this, im on the getting started module after finishing the tutorial one, and i feel dumb and dont understand alot of what its talking about

#

i dont know what any of this means, is there somewhere else im suppose to learn first before getting into htb?

west canopy
#

@plucky plover Honestly most of that stuff isn't too relevant imo, just an overview of the different file types for Virtual Machines

normal marsh
#

ISO is what we used to burn to physical media like CDs or DVDs. You can still mount them virtually, and click all the installation options as if you were installing it on bare metal.
OVAs are pre-built virtual machines that you just double click and go, change your password, check for updates, and you're set. Definitely the easier way to get started, unless of course your goal is replacing one operating system within an entirely different one. But unless this is a secondary computer, I highly recommend against using a security focused distribution as your main OS.

plucky plover
normal marsh
#

Exactly, a pre-built virtual machine that has all the defaults and whatnot configured for you out of the box. Definitely the way to go, as snapshotting and rolling back the machine is a whole lot easier than having to do a wipe and load of your entire computer.

#

The V is for virtual, and the A is for appliance. I am drawing a blank on what the O is for.

plucky plover
#

Operating maybe?

#

idk

#

oh open

normal marsh
#

But you can also build your own virtual machines from scratch. One of the retired HTB machines actually required something to be done in Windows, and I remember in the IppSec video he did it in a brand new windows virtual machine. Microsoft will actually let you download Windows virtual machines with a 30-day license for free. Great for temporary projects.

#

Yeah, open, I should have guessed that.

plucky plover
normal marsh
#

Think of an ISO as more like a really big zip file. In fact, if you have 7zip installed on your machine, you can literally open up an ISO with it and see what is contained within.

#

Software like brasero, or command utilities like dd can be used to write out the contents of an ISO to an optical media. However, VMware and virtual box can also be pointed to an ISO file on your hard drive, and mount it as a virtual drive.

#

For instance, if you ever wish to play with a RaspberryPi computer, the instructions on how to get the operating system onto the micro SD card will involve using an ISO file as well. Of course in that instance, you will be using dd to extract it to an SD card, instead of a CD or DVD.

plucky plover
#

So an ISO is a file while an OSA is an application? Sorry im really confused

kindred scroll
#

By the way, when learning hacking/anything IT related, if you don't understand something you should google it first. Will save you a lot of time

kindred scroll
onyx briar
#

im too dumb to solve the first interactive section of the academy 😦

sharp violet
onyx briar
sharp violet
onyx briar
onyx briar
sharp violet
onyx briar
#

this is gonna be fun. english isnt even my mother language 🥶

west canopy
#

Anyone able to give me a hint on Active Directory Attacks Skill Assessment II ? "Submit the contents of flag.txt on the Administrator Desktop on the SQL01 host". I was able to connect using mssqlclient.py , and can enable xp_cmdshell, but I still don't have permissions to access the flag.

Edit: Solved!

weary forum
#

Stupid question on this "Introduction to Web Applications" module. The question is: What is the CSS "property: value" used to make an HTML element's text aligned to the left?

#

As a programmer, I am tempted to use p{text-align:left;} (since p is a HTML element), but the module marks this as wrong.

#

Or if you want to define the entire HTML document, you would use <html><style>p{text-align:left;}</html></style>

final salmon
west canopy
#

@final salmon now we just gotta take the exam!

final salmon
#

@west canopy yeah lol terrified!

west canopy
#

me too

lethal atlas
#

makes 3 of us

unique valve
#

@west canopy @final salmon @lethal atlas you 3 got this. Study up and jump in to the exam!

lethal atlas
#

@unique valve IM beefing up my skills. Just participated in Nahamcon and our team is looking forward to Cyber Apoc..

#

we came in 237 out of over 4000 so not bad.

devout cliff
#

can anyone assist with a reverse shell?

lethal atlas
devout cliff
#

for some reason cant get pentestmonkey's reverse shell working and i think im messing up something obvious

#

is nc supposed to be on 0.0.0.0?

lethal atlas
#

listening? yeah thats ok

devout cliff
#

ok and i altered the file already

#

and im connect to academy via openvpn

#

so im using that in the file

lethal atlas
#

what module and are you working on

devout cliff
#

file upload attacks first section

#

2nd section*

#

its just doing a simple reverse shell via a file upload site

lethal atlas
#

bypassing filters?

devout cliff
#

doesnt have any

#

its like the very first reverse shell they show to understand the concept

lethal atlas
#

ok so Try to exploit the upload feature to upload a web shell and get the content of /flag.txt

#

?

devout cliff
#

actually i guess they are asking for a web shell and not a reverse shell

#

yeah

lethal atlas
#

yes you just got it

devout cliff
#

ok so if i use seclists obfuscated php web shell that should work then?

#

is there anything i need to change in that file normally?

final salmon
devout cliff
#

weird, phpbash worked but seclists obfuscated bash did not

devout cliff
#

ok i understand why the obfuscated php shell didnt work, theres a password you need to incorporate with it as well, i just dont know the syntax to input it into the url and what it wants

flint helm
#

Hey I'm stuck at the file inclusion skills assessment, I've reached the admin panel but whenever I try to change my agent it ends up blank like this: '408 0 "-" "'

lethal atlas
#

Sorry I left you hanging. We had a pretty good storm blow thru.

west canopy
#

@lament crag DM me 🙂

flint helm
lethal atlas
#

the little things get me all the time

summer lake
#

can anyone assist me with the server-side module? Im having trouble setting up the nginx

lethal atlas
#

what section

west canopy
#

@summer lake DM me 🙂

summer lake
summer lake
lethal atlas
#

you can pretty much follow that section step by step

west canopy
#

I felt like the directions weren't super granular. It took me quite a while before i got the config file working

summer lake
#

and if you get an error, its pretty much hard to troubleshoot

west canopy
#

@radiant dagger try googling "inlanefreight DNS records" and check the website cutestat.com

radiant dagger
#

Although, I'm confusing why other tools can't get it

#

viewdns domaintools are unless on that

#

I should just try dig TXT inlanefreight.com 🥲

fleet anvil
#

Can anyone explain to me what I'm doing wrong? I'm doing to file transfer module and I'm stuck at the windows upload bit

summer lake
#

hi to anyone who has done Web Attacks

#

When I curl -X OPTIONS , I am still unable to view the allowed http methods.

#

It shows me something like Allow: /, anyone knows why ?

lethal atlas
#

what options are you trying?

#

@summer lake Allow: / means all if im not mistaken. Feel free to dm me

lethal atlas
# fleet anvil

You need to find a directory that you have permission to write to.

lethal atlas
#

Dig and nslookup will both get the flag.

#

It's all how you format the commnd

frail marsh
#

Hi

rustic sage
#

hi

frail marsh
#

Anyone know well knowledge about CTF

rustic sage
#

#general this channel is for help basically

frail marsh
#

Yes I want to doubt in ctf

lethal atlas
#

This channel is for academy related stuff

#

Dm me and I'll help you thru it

sharp crest
#

hello

#

i have a question

#

if I want to have access to the courses on htb academy do I have to make a different subscription than the one on the ctf hack the box platform?

#

or if i have silver packet on the htb academy i have access to labs /

#

?

#

with ctf

west canopy
#

The Academy platform is separate from the main HTB website

#

So you would have a separate account and subscription for each 🙂

sharp crest
#

now i understand

#

thx

broken warren
weary forum
#

Hello, everyone. I am having trouble with the Introduction to Web Applications module

#

The question is: What is the CSS "property: value" used to make an HTML element's text aligned to the left?

#

I assumed that the answer if {text-align:left;}, but HTB said that that isn't correct

west canopy
#

@weary forum here is an example of aligning to center

weary forum
#

Yup, you could use any HTML element such as p, h1, br to left align the text

west canopy
#

your answer is right just needs to be formatted

#

try dropping your curly brackets and add a space between align: left

weary forum
#

Ok, I will try that. Not sure why HTB doesn't like my answer

devout cliff
#

can i get some assistance on file upload attacks module, the blacklist filters section? i already fuzzed all extensions via ZAP that should work but none of them are giving me the feedback im expecting.

manic ermine
#

Anyone have hints for the Password Attack Easy Lab?

blissful verge
#

hey all a few changes to Pwnbox just FYSA:

   -you can now sudo without typing a password
   -CrackMapExec installed (need to be root to use)
   -jq installed (needed for some web modules)
   -PortSwigger CA cert added toFirefox for Burp Suite
   -sshuttle and chisel installed```
#

oh and a new module in the Jr Pentester path

exotic ginkgo
#

C R

manic ermine
#

If anyone has hints for the Password Attack Easy Lab, please HMU if you get a chance 🙂

sweet heron
manic zealot
#

i need help in information gathering - web edition module, active subdomain section questions. Tried methods in cheat sheet and nothing works. Any hint?

sweet heron
#

New module added today:
Vulnerability Assessment
Tier 0 - Easy - Offensive - 17 Sections - +10 - 2 hours

west canopy
#

@manic zealot DM me 🙂

#

@devout cliff Feel free to DM as well !

lethal atlas
manic ermine
summer lake
#

Has anyone done the IDOR bypassing Encoded References?

#

Need a little nudge here

sudden sable
#

hello @all...o/...I can't get any further with the third question in the "Using Web Proxies - Skill Assessment" module. could someone pls help me?

twin aspen
#

Türk var mı???

sly grotto
#

guys can anyone help me please in Skills Assessment - File Upload Attacks?

#

i can not find the upload path

broken warren
#

I need assistance on file upload attacks content type filters. I am 100% confused. The way the excersise is written is hard to follow, compared to everything else leading up to It.

carmine lark
#

This following question is linked to Cracking into Hack the Box, the GET method .
My current code to attempt to retrieve the flag is
curl 'http://157.245.42.82:30452/search.php?search=ls' -H 'Authorization: Basic YWRtaW46YWRtaW4='. returned with' Walsall (UK)'

ended up getting it and honestly the answer seems rather simple now. For anyone else struggling with this question as a hint, the search box filters all the names using the parameters you entered in your search, e.g 'search=a' will bring forth all names containing an a.

summer lake
lethal atlas
#

gm

lethal atlas
#

can anyone tell me why this is happening?

#

My ESP value is 00DFFB48
ERC --compare 00DFFB48 C:\Program Files\x64dbg\x32\plugins\ByteArray_1.bin
And I get:
Error: Incorrect parameters provided. Compare must be run as "ERC --compare <start address> <file containing bytes>

blissful verge
#

hey all, another thing. we just made a change to pwnbox to allow whois. this affects at least 1 web module

lethal atlas
#

ok @surreal rain I tried with single and double quotes and still get the exact same error.

#

Resolved!!

hollow knot
#

I need a nudge in ADE&A Skills Assessment I

blissful verge
#

@hollow knot DM me

green skiff
#

Hello everyone, I couldn't solve question 4 and 5 in "Active Subdomain Enumeration" module. Is there anyone who can help? I only have these two questions left to complete the module.

green skiff
turbid hull
#

If someone did the Getting started module, section Publics exploits, i need help on the way to resolve it with searchploit, i already find a way with metasploit but i want to do both

rustic sage
# sudden barn ssh root@host

Do not use ssh. You have to connect with "MySQL client" like it says in the question. Look in the lesson for examples.

final salmon
#

@lethal atlas @west canopy Got the cert(s) gonna give it a go next Thursday.

lethal atlas
#

Wish you the best of luck bro! Dont hesitate to ask for help.

final salmon
sweet heron
#

Sup all!

turbid hull
#

@lament crag Nop but it's a lil bit before

devout cliff
#

if anyone can give me a hint in the file upload attacks module it would be appreciated. been hard stuck for 2 going on 3 days now on the blacklist section question and trying to figure out which extension works.

sour bough
#

These "questions" are not really useful. Maybe develop them to accept variations of the result

devout cliff
#

nvm found the extension 🤦‍♂️ it was an extension zap wasnt enumerating

west canopy
#

@final salmon get it big dawg!

final salmon
#

@west canopy I didn’t know but you get two attempts with it

final salmon
#

Anybody know any easy way to get LinPeas on a system when wget and git clone are permission denied?

#

My awful English