#modules

1 messages Β· Page 526 of 1

languid dawn
#

these are not beginner chat and general is the brain damage channel.

glass reef
#

also i know a guy who's a HTB "GOD" or something.. is that any good? how good is he?

languid dawn
#

I mean, just do CTFs and try out bug bounties

#

also if you want to understand the level needed to do HTB just try it out yourself! it's free

#

and it is real hacking shit lel

glass reef
glass reef
languid dawn
#

hacking is hacking my man, I'm not sure what makes it not real.

#

your rank is just time spent on the platform, but if you can get bloods on box or challenges release you're already one of the better hackers

glass reef
languid dawn
#

if you're talking about levels like on THM that would be omniscient I guess

#

it just means you complete 100% of the challenges and boxes

glass reef
#

whats THM

glass reef
languid dawn
#

everything is possible, but mostly no, noone will hack your pc

#

unless you download weird files from weird places

glass reef
#

im running ssh on my pc 24/7 with no keys

#

only password

#

can he hack me

#

as HTB GOD

glass reef
#

ok i just found out THM means tryhackme and yea he is GOD in tryhackme and says its top 1%
and also he is "pro hacker" in HTB @languid dawn
so is prohacker in HTB any good?

languid dawn
#

rank is just the time spent on the platform

#

you will find people with a noob rank that have multiple CVE to their names

limpid wharf
#

Still stuck there. How do I move the key.pub to the root and how do I chmod it ? They keep asking for user2 password

stable sparrow
#

yup! I eventually figured it out whoops

crimson atlas
#

Hey need a little help on broken auth skill assessment, feel like I'm close to finish got all the s*. users, I get how cookie were encrypted, but I still can't get it :/

ebon pine
#

Ok need a bit of help; I have created the file for LinEnum.sh. Proof above, I did chmod +x to make it executable but whenever I run it this is all that happens? any tips on what I am doing wrong?

polar widget
# ebon pine

Upgrade your shell to execute the command AND receive its output successfully

ebon pine
#

by running? python3 -c 'import pty;pty.spawn("/bin/bash")' I am getting started so thats the only upgrade i have encountered so far

polar widget
#

Yes that's great

#

You can switch between python and python3

#

I've encountered python3 not working once,
That's on some old box

ebon pine
#

yup i did that earlier in the process, is there a reason its no longer upgraded?

polar widget
#

Remember
If you upgraded it, the shell will function as its upgraded
At ant point if you're just limited to $ , you better upgrade it

#

export TERM=xterm

ebon pine
#

is it cool if I DM you? @polar widget

polar widget
#

Yes sure

ebon pine
#

thank you

crimson atlas
#

that a nice source for shell upgrade

#

dont forget to switch to bash if your term is in zsh

#

before running listener

polar widget
crimson atlas
#

^^ best one imo

onyx dust
#

can you install crapmapexec on pwnbox ?

#

i can't get it to run w/o errors

#

i'll use vpn and my own computer to get it out of the way but considering unlimited pwnbox access costs money it'd be nice if it worked in concert with the modules

#

when trying with the 1st instruction in the module. not to receive errors out of the box

#

installed with pipx (like instructed in the github) it's just errors

#

how frustrating to get anything done with the materials provided and make any progress in the absence of adequate quality control.

#

why this costs money?

#

?? @here

#

if this doesn't work out of the box what am i paying for?

#

can't even use the suggested software on the box provided i have to do it myself. sad.

#

finally i can retire knowing what it means to find bliss in saying, "it works on my computer"

#

rolls eyes

rustic sage
#

i thought pwnbox was ffree after you purchase your fist module...

polar widget
#

CME
Responder and several other tools and sometimes individual dependencies will require that much of effort

rustic sage
#

can anyone help with "Information Gathering - Web Edition : harvester" im getting this error :[!] An error occurred while saving the JSON file: a bytes-like object is required, not 'str'

#

the command im running is : cat sources.txt | while read source; do theHarvester -d "${TARGET}" -b $source -f "${source}_${TARGET}";done

vital bough
#

Hey all I'm stuck on command injection module, Bypassing other black-listed characters, been at it awhile anyone able to help?

onyx dust
#

meanwhile, it works on my computer no thanks to pwnbox

#

fix yo shit. this is training not a "real world" experience.

#

it's supposed to be guided. thanks.

onyx dust
#

how many platinum customers u have @here ?

#

so far i believe it's a waste of my money. i've done all the content on thm and it's cheaper + the same quality.

#

to be met with that rhtetoric that it's real world experience is asinine when it's your business to create a guided experience.

polar widget
#

@surreal rain might wanna look into it :/

surreal rain
#

Hey what's up?

rustic sage
#

so here we can get some help or hints

#

im stuck on using the metasploit framework module in sessions and jobs section

#

the question is ( the target system has an old version of sudo running , find the relevant exploit and get root access

#

so im on the target but low user and i cant get to root

#

how i can find the exploit that help me to get to root

#

how u guys even know what to search about

#

im stuck here for 2 days 😦

west canopy
#

@rustic sage DM me πŸ™‚

rustic sage
#

big thanks to @west canopy and @placid quest

#

probably i need more courses

sweet heron
#

Module Pivoting... section RDP and Socks: I can't load the plugin.dll using regsvr32.exe. I get this error message instead of a success:

west canopy
#

I think we might have to turn off windows defender

sweet heron
jagged zenith
#

Any hint session security skill ass

west canopy
#

@jagged zenith try using the technique shown in Cross Site Scripting module "Session Hijacking" section

west canopy
#

Also you can use the api endpoint|| to make the admin user visit any page|| πŸ™‚

sweet heron
#

I can't seem to connect to the last target in pivoting module, RDP and socks section.

outer ledge
#

Hacking Wordpress: I clicked every clickable thing but no page is using wordpress.. Am I missing something?

sweet heron
#

yes: check for a blog. ^^

outer ledge
#

Nvrmnd got it! Thank you

acoustic owl
sweet heron
#

I'm on US2

sweet heron
acoustic owl
acoustic owl
sweet heron
#

almost done, but stuck at enumerating the network on the pivot machine.

woeful oxide
#

Hey fellow hackers, quick question regarding the web proxies module, how do i create the rule that changes the behaviour of the ping button using burpsuite

distant stream
vital bough
#

Guys, I'm stuck on command injection module, Bypassing other black-listed characters, been at it awhile anyone able to give a nudge

median canyon
#

Any luck on this one? I'm stuck here as well

vital bough
sweet heron
acoustic owl
acoustic owl
blissful verge
#

hey all, you may have noticed extra cubes on your account today. we moved a few tier III modules down to tier II so the entire Junior Penetration Tester path is accessible with the student sub or silver sub. Since some had already paid more for the modules that were tier III we decided to auto credit back cubes to everyone who paid for the higher price. This would effect the Windows and Linux Privilege Escalation modules

acoustic owl
jagged zenith
coral heath
#

Does anyone know if it's ok to share my module notes ( probably with flags) but with the skills assessment flag as a password to view the content? on my personal blog or else where

#

same as what we do for live machines

blissful verge
blissful verge
coral heath
#

Thanks

polar widget
shut bronze
#

Anyone can help m

#

w Metasploit module

#

I'm stucked at this question

#

i've already tried

devout cliff
#

uh its looking for the terminal command to start it i think

#

@shut bronze

shut bronze
#

Thanks it worked!

muted comet
#

keep getting this error when trying to download redis-tools

#

why cant i put pictures in here?

#

anyway

#

─$ sudo apt install redis-tools
[sudo] password for kali:
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
E: Unable to locate package redis-tools

#

the unable to locate package error

devout cliff
#

this might point you in a good direction

#

also you might not be properly verified on the discord which is why you cannot post pictures (this is a guess). check the welcome page at #welcome for info

muted comet
#

ive tried this

#

doesnt work

devout cliff
#

you have tried all of those options?

muted comet
devout cliff
#

ok, that article talks about more installation options beyond apt or apt-get

#

there looks to be a wget option to download a tar.gz file

#

and another for git

muted comet
#

i dont understand tbh

devout cliff
#

are you new to linux?

muted comet
#

yeah

devout cliff
#

what type of linux are you running?

muted comet
#

kali

devout cliff
#

what distro

#

ok

#

i think he wants just the cli and not the entire redis installation

muted comet
#

i keep getting unable to locate pakage

#

do i have to install something?

#

yeah

devout cliff
#

im assuming that will not work, so next option you can try is this

#

see if that works

#

Optionally, you can put the compiled executable in your load path for convenience:

$ ln -s src/redis-cli /usr/local/bin/redis-cli

#

both of what i copied here is in that article i linked above

muted comet
#

i did all of that

devout cliff
#

if you cannot get either of those to work or only partially work i would look for some articles and get some general knowledge base of how to install things in linux. fundamentals are very important for a consistent good user experience with any linux distro

muted comet
#

and this came up

devout cliff
#

does redis-tools work?

muted comet
#

no

devout cliff
#

oh wait

#

try yum

#

Please install the EPEL repository, and update the YUM to confirm your change: type sudo yum install epel-release ll the EPEL repository, and update YUM to confirm your change: sudo yum install epel-release sudo yum update.
Redis can be installed with sudo yum install.
redis is launched by running systemctl: rstall redis. Optional: It is then possible for you to manually launch it with ng suctl start redis.

#

i need to go but good luck

muted comet
#

i got it

#

using this

#

cd

polar widget
urban valley
#

If anyone is stuck on the Window Priv Esc module- DNSAdmins section, I found that you have to restart Windows in order to read the flag.txt. Its not as simple as simply closing your RDP and then reopening. But its as simple as googling the restart Windows command. Hope this helps someone

blissful verge
urban valley
#

start menu didnt have the shut down or restart option :/

polar widget
urban valley
urban valley
polar widget
#

I meant the same
I had injected DLL for reverse shell as jared once said it worked for him, but apparently didn't worked for me

polar widget
#

Restarting and killing the connection are different

coral heath
#

Does anyone know which tool you use for url encoding?

#

for Server side attack module, I see this but when I use "hURL" it's not encluding some special characters as HTB module does..

polar widget
#

Indeed, like minded people and security experts at HTB team are doing a phenomenal job at delivering the contents.
Wish there was academy while I was getting started.

#

But now it is so I'm happy

#

I'm gonna blog on my HTB academy experience once I complete all the modules

polar widget
#

I tried decoding with build it decoder from burp suite, didn't quite worked..so I had to switch to cyberchef (online tool)

#

With 2-3 iterations on most common encoding mechanisms you'll get there

iron plaza
#

anyone else completed the OpenVAS skills assessment? I keep getting this error message on the pwnbox

radiant dagger
#

HTB academy server is down?

iron plaza
radiant dagger
shadow verge
#

I think I have more cubes than i'm supposed to, someone else having the same?

iron plaza
shadow verge
#

Actually there is no gift option on cubes

acoustic owl
shadow verge
polar widget
pure birch
#

Is here anyone experienced with airodump ?

polar widget
steep oxide
#

hi guys, need some help cracking this hash in module hashcat 'Crack the following hash: 7106812752615cdfe427e01b98cd4083', ive hashid the hash and tried all modes but cant find it still
my command as follow ; sudo hashcat -a 0 -m 900 ntlm_example '/home/htb-ac496803/Desktop/Useful Repos/SecLists/Passwords/Leaked-Databases/rockyou.txt'

polar widget
#

I was waiting for reverse shell in one instance.
The other time I thought its better to leave it to the modules example, via adding the user itself, so resetted the target and once again tried it all

steep oxide
#

any help guys?

steep oxide
#

u mean ive have to do rules to test for all modes?

#

one by one?

vital adder
steep oxide
vital adder
steep oxide
polar widget
vital adder
steep oxide
#

ill try first, thanks for the heads up

rotund oxide
#

Hi, has anyone done "Active Driectory LDAP"? im stuck at this question "What is the password history size of the domain? (How many passwords remembered.)?". Just need to be pointed to the right direction

polar widget
rotund oxide
#

DM me @polar widget

tender dawn
#

hackthebox vs tryhackme

languid dawn
#

Both have their use, just do what you find fun πŸ˜„

zenith schooner
#

anybody working on port forwading and pivoting module. I need some help. I am working Dynamic Port but the lab machine doesn't show me the rdp port as in the lesson explanation. So, there is something wrong or I am doing something wrong.

#

thank you

zenith schooner
#

meaning?

zenith schooner
#

anybody to ask a question about portforwarding module?

#

DM please

vital adder
zenith schooner
zenith schooner
vital adder
zenith schooner
# vital adder yes

But the issue is I followed the steps with dynamic port and the open ports reported are 22 and 80 instead of windows ports (specially 3306 RDP port). So, this is why I post here.

zenith schooner
vital adder
#

you can only access the windows machine if you are on the target

#

try list all of the network interface on the target and use (nmap binary) use scan /24

zenith schooner
#

I did a ifconfig on the target and I found 172.16.5.129. ok

#

I configure my proxychains to work on SOCKS4 port 9050

#

I did a ssh -D 9050 ubuntu@<victim IP>

#

and finally I made a proxychains nmap -n -v -sT 172.16.5.129 to check open ports.

#

only 22 and 80.

#

I tried also proxychains xfreerdp as it shows on module with no results

vital adder
zenith schooner
#

I guess it could be something wrong on the lab machine.

#

I also tested from pwnbox to discard something wrong on my box

vital adder
zenith schooner
vital adder
#

@zenith schooner did you find the windows machine ip?

zenith schooner
vital adder
jagged zenith
polar widget
lethal atlas
jagged zenith
drifting glacier
#

Working on the hashcat - hybrid attack using wordlists with masks section in the hashcat module. Tried running both sha1 modes on the hash in the exercise, but hashcat just keeps exhausting and not finding the password. Any sort of nudge on this section? I've got what i tried so far ready to view

lethal atlas
#

@drifting glacier DM me

drifting glacier
#

Solved, for anyone else that might come across this issue. order of the flags actually matters here

polar widget
#

I've already done that module,

atomic river
#

Could I ask some hints to someone for the question "Work on webapp at URL /question2/ and try to bypass the login form using one of the method showed. What is the flag?" in the Broken Authentication module?

#

I just solved it! Indeed I was stuck in a rabbit-hole!

steep oxide
#

hi guys, hashcat module "Extract the hash from the attached 7-Zip file, crack the hash, and submit the value of the flag.txt file contained inside the archive." the hint says"Use 7z2john.py in /opt on the Pwnbox extract the hash.", my command is ./7z2john.py 'home/htb-ac496803/Downloads/Misc_hashes.zip' but couldnt get the hash and having invalid syntax error, any help guys?

polar widget
#

I was having some issues with this one, troubleshooted it don't remember exactly how but yeah

steep oxide
#

ill try python3 and see if it works..thanks

#

still didnt work, anyone else can help?

polar widget
#

Try this

#

Read this article too

#

It helped me
Or I've tried stuffs it said

steep oxide
#

aight, thanks

rustic sage
#

Can someone assist me on the question about CMS in information Gathering module - Active Infrastructure Identification. I am using whatweb on the Server IP provided at the bottom which got me the answers to the 1st and 3rd question (Apache version and OS respectively)but whatweb is not showing me any information regarding a CMS ?

steep oxide
#

about hashcat module "Perform MIC cracking using the attached .cap file." ; hint "Leverage the cap2hccapx.bin tool!" Ive converted the .cap file to hccapx file, then ; sudo hashcat -a 0 -m 22000 mic_to_crack.hccapx '/home/htb-ac496803/Desktop/Useful Repos/SecLists/Passwords/Leaked-Databases/rockyou.txt' but cant crack the hash, can anyone help me?

acoustic owl
sweet heron
#

With some help, yes. Ping me if you get stuck!

acoustic owl
velvet geyser
#

heyy

#

can somebody tell what are the best modules to learn on hackthebox since im just a starter and i only know some stuff

kind path
#

anyone having issue with HTB Academy academy.ovpn

velvet geyser
#

@acoustic owl Thank you so much!

kind path
#

**error log **

2022-06-30 12:10:36 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2022-06-30 12:10:36 DEPRECATED OPTION: --cipher set to 'AES-128-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305). OpenVPN ignores --cipher for cipher negotiations. 
2022-06-30 12:10:36 Cannot find ovpn_dco netlink component: Object not found
2022-06-30 12:10:36 Note: Kernel support for ovpn-dco missing, disabling data channel offload.
2022-06-30 12:10:36 OpenVPN 2.6_git x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO] built on May 30 2022
steep oxide
acoustic owl
kind path
steep oxide
#

no problemπŸ˜€

rustic sage
acoustic owl
#

and make sure that the two domains are entered in the hosts file,

rustic sage
#

I dont understand how I am supposed to incorporate or reach those inlanefreights domains with prefixes. I can only reach the IP given by the server which is the default vhost it says. I have run whatweb on the server IP but what do I do with the domains?

rustic sage
acoustic owl
rustic sage
muted comet
#

need a little advice on which file to use for bruteforcing a web directory I am using seclists and see it has a lot of options

#

which .txt document should i use within seclist if you guys have any advice

random kettle
#

quick question, subbing as a Silver, will get me into the jr penetration tester path?

acoustic owl
muted comet
#

yo so SQL Injection is basically cross site scripting yeah? using code in order to gain access yo the data base?

acoustic owl
muted comet
#

i found one thanks

#

im confused now on the lesson apoointment how it goes from using bruteforce attacks to analyzing the PHP file

#

it didnt even teach me how to tell if this is PHP just kinda goes owe this is PHP you can enter code in username and boom cracked

acoustic owl
acoustic owl
muted comet
#

Apointment section 1

#

starting point

#

i solved the flag just confused on how it goes from using gobuster to ohh just type Admin'# and boom SQL injection

#

like how do i even see the PHP code and also how can I tell this is vulnerable to SQL injection

acoustic owl
muted comet
#

im gonna get to academy after i finish starting point

#

but thanks for advice

vital bough
#

Hey team, can anybody give me a nudge for Command Injection - Skills assessment?
I'm just banging my head at this point

light yacht
#

Hi ! I have a question with this module I am not able to turn the on break its at off break could you help me about it ?

zenith schooner
vital adder
coral heath
#

Can someone please help me with Server-Side Attacks - Skills Assessment ? I've been trying to solve this for 3 days but seems none of the parameter is vulnerable to SSTI..

paper gust
#

the modes for it are still around but I believe 22000 no longer accepts them directly

#

I don't know if/when that module will be updated but I believe that's a known issue with it and has been for a bit

slow ruin
#

Need a nudge/hint on Password Attacks:Credential Hunting in Linux. Working on finding the credentials to ssh onto the target. Was able to get on a smb share but it has no permissions

coral heath
lethal atlas
#

yes

coral heath
#

Okay, Thanks @lethal atlas for helping. Though how this SSRF skill assessment is related to SSTI & SSRF? I don't get it

severe copper
#

Are the answers really correct? I am doing the introductory module to the analysis of network traffic and both at the beginning of the module and now it does not mark any correct answer. I even marked a wrong answer until I capitalized the first letter while the other answers I write completely in lowercase and I have no problem.

severe copper
#

sorry for de mayus

lethal atlas
#

but which section in the module?

#

nm TCPdump fundamentals

#

question2

#

DM me

knotty falcon
#

Stuck on File Uploads Skills Assessment and could use a nudge. Please DM if you can lend a hand.

uneven lake
#

hello guys..

#

glad to be on here

lethal atlas
#

welcome @uneven lake

steep oxide
light yacht
#

Hello ! Is there any one has already complete session Using Web Proxies ?

radiant dagger
#
1..254 | % {"172.16.5.$($_): $(Test-Connection -count 1 -comp 172.15.5.$($_) -quiet)"}PowerShell one-liner used to ping addresses 1 - 254 in the specified network segment.
#

PS ping sweep one liner not working

#

Try this 1..254 | % {echo "172.16.6.$_"; ping -n 1 -w 100 172.16.6.$_} | Select-String ttl

paper gust
#

if you want to run hccapx files, then use mode 2500 but realize its a deprecated mode

#

or hcxpcapngtool

steep oxide
#

thanks! managed to solve it now

radiant dagger
#

VPN key not working anymore?

#
❯ openvpn Downloads/academy.ovpn
2022-07-01 16:01:57 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2022-07-01 16:01:57 DEPRECATED OPTION: --cipher set to 'AES-128-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305). OpenVPN ignores --cipher for cipher negotiations. 
2022-07-01 16:01:57 Cannot find ovpn_dco netlink component: Object not found
2022-07-01 16:01:57 Note: Kernel support for ovpn-dco missing, disabling data channel offload.
2022-07-01 16:01:57 OpenVPN 2.6_git x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO] built on May 30 2022
2022-07-01 16:01:57 library versions: OpenSSL 3.0.3 3 May 2022, LZO 2.10
2022-07-01 16:01:57 OpenSSL: error:0A00018E:SSL routines::ca md too weak
2022-07-01 16:01:57 Cannot load inline certificate file
2022-07-01 16:01:57 Exiting due to fatal error
steep oxide
radiant dagger
polar widget
#

Like before getting started in Cybersecurity?

#

Oh its about Go

#

But they say, Go has excellent backwards compatibility

#

Installation should be convenient

plain coral
#

I got it working and wrote notes this time,
nano ~/.bashrc
export GOPATH=/home/$USER/go
export GOROOT=/usr/local/src/go
export PATH=${PATH}:$GOROOT/bin:/home/$USER/go/bin
source ~/.bashrc
Moved to the directory to $GOROOT that I specified in ~/.bashrc.
sudo mv go $GOROOT
With that last line, I could now run it from the shell.

steep oxide
#

hi guys, need help on this question in hashcat module

"After cracking the NTLM password hashes contained in the NTDS.dit file, perform an analysis of the results and find out the MOST common password in the INLANEFREIGHT.LOCAL domain." ;

hint 'Specify --username when outputting the results from hashcat or each hash will be returned one time only. To perform your post-cracking analysis, try out a domain password analysis tool such as NtdsAudit or DPAT. Alternatively, use command line utilities such as grep.'

my command is sudo hashcat -a 0 -m 1000 --username hash4 '/home/htb-ac496803/Desktop/Useful Repos/SecLists/Passwords/Leaked-Databases/rockyou.txt'

vital adder
steep oxide
#

hashcat result turns out exhausted

vital adder
steep oxide
#

do you cut the hash to just include the password portion?

#

or you include the username portion as well

#

if just the password portion i managed to crack it but not sure how to filter out the most common password

#

if include the username portion i cant crack it not sure for what reason

steep oxide
#

the hash

vital adder
steep oxide
#

yeah

vital adder
steep oxide
#

do you change the original hash file?

vital adder
#

and the most common hash can be cracked on crackstation

steep oxide
#

what is crackstation?

vital adder
vital adder
#

wait crackstation isn't in the hashcat module?

steep oxide
#

nope

vital adder
#

wait i'm dumb of course not

#

@steep oxide so i can't remember how but you just need to filter for the most re-use hash and crack it on crackstation

steep oxide
#

oh ya, and what command you use to filter out most reuse hash

#

grep what?

vital adder
steep oxide
#

i still dont get it but thanks anyways

vital adder
# steep oxide i still dont get it but thanks anyways

i just found this on a super secret hacking tool call ||google|| https://www.techgrapple.com/online-tools/find-duplicate-words-the-duplicate-word-finder/ just remove the empty part in all of the hash and paste every thing into here it should be the top result

How to find Duplicate Words easily in any article, sentence, or paragraph. Here is a simple duplicate words finder tool

languid dawn
#

aad3b435b51404eeaad3b435b51404ee is a null hash

#

don't try to crack it...

vital adder
steep oxide
#

with the --username i get this error, without --username i managed to crack it but cant find the most used because hashcat doesnt shows duplicate without --username, any help?πŸ˜…

steep oxide
#

i pasted the results in the website u given, theres no duplicates

vital adder
rustic sage
#

guys i dont wanna ask the question and someone help cuz this will fk me in the long run

#

but how the hell you know what exploit gonna work or what exploit to use

steep oxide
steep oxide
polar widget
#

I haven't read all of the above messages but quickly lemme describe my strategy

#

I've chopped off that NT part of hash, crackable easily

steep oxide
#

error came out only when --username is used

polar widget
#

Then code in python or any language
Which takes a list of those NT hashes and tells you which is the most appearing one
Take that NT hash and crack it

rustic sage
#

ok im gonna go to corner and cry

polar widget
rustic sage
#

so if i have 9 ports open should i check em all ?

vital adder
#

@steep oxide can i dm you a screenshot of what i paste on that web

polar widget
#

Suppose you found a service called potato 2.3

You google about - potato 2.3 exploit and something shows up from packetstorm or exploitdb.com

There you download the exploit and run it

polar widget
vital adder
rustic sage
#

ok thanks guys

#

wish me luck

vital adder
tepid jolt
#

I need some help with File Upload Attacks- Skills Assessment. I know the source code of .php file. I have found the Uploading directory. I need some help with under standing how files are being named.

vital adder
tepid jolt
rotund oxide
#

Hi, has anyone done "Active Directory LDAP" stuck at the last question in the skill assessment, and one question in the last section. Have been stuck for a few days

polar widget
#

Mine last section, theory+exercises is remaining and Skills assessment

#

There's so much possibilities, I am interested in how you approached the questions and your LDAP filters

dire eagle
#

I'm on Getting Started Service Scanning. Is the password to user: bob not the one suggested that we use in the text? I've tried bob:Welcome1, bob Welcome1, Welcome1 nothing gets me in to the user shares. The question is List the SMB shares available on the target host. Connect to the available share as the bob user. Once connected, access the folder called 'flag' and submit the contents of the flag.txt file.

#

^ "Let us try again using credentials for the user bob (bob:Welcome1)."

uncut mirage
#

Hi, I'm stuck at Active Subdomain Enumeration in the Information Gathering module. I can't find the answer to "What is the FQDN of the IP address 10.10.34.136?". Please DM me, many thanks!

acoustic owl
vital adder
steep oxide
acoustic owl
steep oxide
#

ill try first.. thanks

#

@acoustic owl i tried sqlmap -u URL --schema to find the table name but i cant find any table relevent with passwords and the database as well

silent knoll
#

Authenticate to 104.248.172.48 with user "guest" and password "guest", what does this mean?

#

With which protocol should i authenticate?

polar widget
#

Try http first

silent knoll
#

how

polar widget
#

Then ftp
Then ssh
Then smb

polar widget
silent knoll
#

Its the skills assessment of command injections

polar widget
#

Don't know

silent knoll
#

got it, thx

steep oxide
#

anyone can help me with sqlmap flag 7 ?
Hint is"Try to count the number of columns in the page output, and specify them for sqlmap."
but how am i supposed to know number of columns?

#

which page output

raven lagoon
#

Hi guys did someone complete this question in Password Cracking module? I generated the worldlist with "sam" and the custom.rule file in the zip. But no one of these seems valid whenever i do scan with hydra
https://prnt.sc/FhIvyhRXRcke

blissful verge
#

Hi all, Happy Friday. Just a quick update for y’all. The File Transfers module has undergone a substantial re-write and I recommend going through it again if you’ve already done it. Also the AD Enumeration and Attacks module has a new section that explains the Kerberos β€œdouble hop” problem and workarounds in depth if you’ve been curious about it or confused by it. Keep hacking, and try to learn something new every day!

paper gust
#

use --show in your command to get the results

prisma coral
#

I need some help with the File Inclusion Module. Trying to answer the question on the RFI section but the container won't load for me. Is there anyone I can ping to look into this?

prisma coral
#

Go for it

dire eagle
#

Anyone know why the password bob:Welcome1 for Getting Started Service Scanning doesn’t work?

vital adder
steep oxide
dire eagle
#

askes for bob's password. I put in bob:Welcome1 like the text says and fail.

rustic sage
#

so I threw

rich mulch
#

Hi guys.
I am confused about the wordlist when fuzzing. Sometimes, use wordlist in dirbuster can find a result, sometime use wordlist in Seclist. So which one you guys often use?

acoustic owl
rustic sage
#

Hi all,
Anyone able to help with the Type Filters section of File upload attacks, i am getting "File successfully uploaded" but when i navigate to the file i get a "cannot be displayed because it contains errors"

polar widget
#

yo I have been switching to all different regions but VPN ain't working

#

Options error: Unrecognized option or missing or extra parameter(s) in academy.ovpn:12: data-ciphers-fallback (2.4.7)

modest moth
#

anyone done the pivoting, tunneling and port forwarding module? i need a bit of help understanding one part on the Remote/Reverse Port Forwarding with SSH chapter. DM me if you can help. Thanks πŸ™‚

twin gulch
#

Hey everyone

#

I need help please, at skill assessments of Linux privilege escalation. Flag 3 - I’ve got the GET request I need to search to find flag3.txt but stuck on trying to send it.

#

Is anyone online for some help?

modest moth
twin gulch
#

I’m trying to look for it by trying lol, just hyped to success this flag.. went to the end and got stuck there.

strong spruce
#

I am trying to do this question from Using the Metasploit Framework Module in the 'Modules' section but I am not able to establish a connection. Any suggestions on how I can overcome this issue ?

fluid valley
#

so, im working on the Intro to Python module atm. Does the HTB viewer have its own python client I can use?

shut owl
#

Has anyone finished the Linux Privilege Escalation Assessment? I could use a nudge on flag4.

twin gulch
shut owl
#

DM me

twin gulch
#

Got the Hidden GET massage but don’t know how to move forward

#

Thanks bro

shut owl
sweet heron
#

Attacking Enterprise Networks, external info gathering: What is the FQDN....? What am I missing? Did not red the question thoroughly.

wheat garden
placid quest
#

If anyone has done network enumeration with nmap i would like to get you help on medium lab and hard lab

twin gulch
#

I need help at flag5 of Linux privilege escalation!! Please

vital adder
pastel veldt
#

πŸ€”

#

🀣🀣

#

What’s dlscold nilro?

vital adder
lethal atlas
polar widget
#

Use just cyberchef at this point
Take it slow through steps
Prepare a strategy for decoding, and it shouldn't be more than 2-3
Like base64-> url decoding -> ...

#

There's a magic button which cyberchef gives us, while decoding stuffs
Use that as well,

ebon pine
#

has anyone here completed the knowledge check on the getting started module?

raven cairn
#

Can I have help on the command injections skill assesment??

vital adder
raven cairn
vital adder
vital adder
radiant dagger
#

Does anyone face the same for 'AD Enumeration & Attacks - Skills Assessment Part I'

#

proxychain evil-winrm always failing to upload on MS01

steep oxide
#

Anyone can help me in Sql map skill assessment, i cant find the URL to do sqlmap

radiant dagger
#

also constantly lost the connection. have to start again Error: An error of type Errno::ECONNREFUSED happened, message is Connection refused - Connection refused - connect(2) for

dire eagle
#

I'll give it another go once the instance refreshes. Maybe it'll work today. I've had xfreerdp not work one day and then work another

dire eagle
#

will try

#

thanks everyone

steep oxide
#

Can someone help me with sqlmap essentials module

Q: What's the contents of table final_flag?

Hint: First, navigate the website to find potential attack vectors. Then, try to use various security bypassing techniques you learned to get SQL injection working.

My problem: not sure whether the URL i found if is correct & couldnt find the correct security bypassing technique

Anyone can help me?

polar widget
steep oxide
#

why do we have to load the web request in a file btw?

polar widget
steep oxide
polar widget
steep oxide
#

this i understand, but what am i suppose to manipulate in the request, it does not seem to be in the sqlmap essential module

#

can you guide me a little bit

polar widget
#

A full fledged web request or rather just a web request would contain several components, that's detailed in web requests module + intro to web application I guess,

It'll have several headers, parameters, user agent, and all those stuffs

polar widget
#

Basically we are looking for anything that carries a parameter and its value to the web server

steep oxide
#

ive completed the web request module

polar widget
#

We're gonna manipulate that

polar widget
steep oxide
#

i know we can manipulate it but manipulate into what?

polar widget
polar widget
steep oxide
polar widget
#

The first paragraph says -

#

The Host request header specifies the host and port number of the server to which the request is being sent.

polar widget
# steep oxide

Now see what's the Host header contains in this web request
Is it really something we're pentesting?

#

This reflects that you just went through the web requests module and didn't processed the information

steep oxide
polar widget
steep oxide
#

when i press on the product or search stuff in the box no requests occurs

polar widget
steep oxide
#

i still dont get it

polar widget
#

I'll suggest you take a break and contemplate upon what I said above

#

Also, remember
Every functionality is a piece of code

steep oxide
#

theres only 2 function thats possible for pentesting, the review function and the checkout function

polar widget
#

Earlier I used to take things lightly,
Just like you couldn't see that apparently

steep oxide
#

the checkout function ive tried no request being sent upon filling out the details

polar widget
#

Any action done to the website would be a valid transaction of web requests from our client to the server

#

I'll suggest using web proxies, which can intercept requests on our behalf

#

Lke Zap or Burp suite

steep oxide
#

im using burpsuite

polar widget
#

Clear the HTTP history
Re-do those checkout steps

steep oxide
#

no request being sent when place an order being pressed after filling out the details

polar widget
#

Turn intercept off
Make sure your traffic goes through burp, which is likely configured properly

steep oxide
#

if i turn intercept off, traffic dont goes through burp anymore

dire eagle
dire eagle
#

lol on to the next one and the internet won't load in the pown. good times

slate osprey
#

Hey folks, excited to be part of the community πŸ‘πŸ½

polar widget
polar widget
jagged zenith
steep oxide
rugged stag
#

In the Footprinting Easy Lab, there don't seem to be any files on the ftp server (2121). Is it supposed to be this way, or am I doing something wrong? πŸ€”

fathom bay
#

Anyone available to help with the file upload attacks -> type filters?

vital adder
#

hi, could you give me a hint on this, the hint on that section suggest to use Kira cred to login via ssh on somewhere but when i scan the box internal network it give me new ip (almost every time) i'm i supposed to do that? is that other people box ip

vital adder
fathom bay
vital adder
tender dawn
#

any zsh autosuggestions user here? why is it not working over ssh

rustic sage
#

ok im back to ask other question cuz it appears im trash

#

so they asked me to find exploit and get a shell on target - took me 3 days but i did it

#

and then they told me to get NTLM password hash

#

i used run hashdump but didt worked

twin gulch
#

Guys. I’m at flag5 of Linux privilege escalation and upgraded my shell. But how can I locate flag5?

rustic sage
#

use find

#

so i used other exploit and get the hash but it says its wrong when i try to post it

#

any ideas ?

twin gulch
vital adder
#

@rustic sage what module are you on?

rustic sage
#

using the metasploit framework

vital adder
rustic sage
#

find / -name flag.txt

#

something like that

#

meterpeter

vital adder
rustic sage
#

yup

#

use mimikatz

#

and i got 4 hashes for admin and htb-student

#

i post the hash they say wrong

vital adder
twin gulch
#

And no flag5

rustic sage
#

arf

#

idk i didnt do this module

#

maybe the flag will apear if you use "the intended" way to privesc

#

yea and it give me a error

#

and tell me to use the hash_d8mp exploit

#

all the 4 hashes i found litterly the same

#

and since they asked for NTLM then it means the last hash after :

vital adder
rustic sage
#

wait what privesc

#

i didt do that xD

vital adder
rustic sage
#

nope

vital adder
rustic sage
#

but im already on root

#

yup yup in NT / AUTHORITY

#

witch is root for windows i think

vital adder
vital adder
rustic sage
#

how the hell this module easy

vital adder
rustic sage
#

ok

twin gulch
#

Man I cannot locate that flag5

#

Did anyone have done this? Can give a hint? I just upgraded the shell

#

On Linux privilege escalation skill assessment 5

twin gulch
#

I’ve doneeeee

#

Finally

polar widget
rustic sage
#

Guys

#

I am stuck at enumeration with nmap

#

Medium and hard lab

pastel python
#

subdomain enum?

rustic sage
#

Nah like it's a module

pastel python
#

oh my bad

rustic sage
#

I have student subscription

#

So got it with that

#

Need help

lethal atlas
#

@rustic sage are you using pwnbox?

rustic sage
#

I have dual booted

lethal atlas
#

I will try and help you. I know on the hard lab my method doesnt work on pwnbox but does on kali

#

dm me

lethal atlas
#

use nc to connect

brisk geode
west canopy
#

@brisk geode you might have to ||spoof your source port while connecting with netcat||

lethal atlas
#

I also had tcpdump running and ran the nc command a couple of times

brisk geode
#

Removed my text someone was trying to solve the lab using my result...

white mulch
#

hey guys can anyone give me a nudge in SQLinjection skills assesment ?

novel anchor
#

Hey guys every install i do in my kali they tel me « E:Invalid operation ….Β Β» i change the sources.list and i do update and ubgrade but it’s still the same problem, what i should be do? Heeeelp

lethal atlas
#

post a screen shot of the error and the command

lethal atlas
rustic sage
#

why is this port filtered

unkempt elm
#

not sure if this is supposed to be here or not since i know nothing about this, but what do you do with your starting point file?

unkempt elm
#

lemme verify

lethal atlas
novel anchor
#

@lethal atlas bro i send u in private

lethal atlas
novel anchor
#

Ok

idle cliff
#

Can anybody give me a nudge in the Using Web Proxies skills assement? The cookie decoding challenged has me stumped. I've tried every method of encoding and nothing I've tried seems to bring it down to the 31 character cookie.

shut owl
#

Has anyone finished the web proxies skills assessment? I've done all of the questions except for the first one, which clearly has something I'm overlooking. It would help if someone could spot check me.

twin gulch
#

Done πŸ™‚

boreal vine
#

someone for Windows Privilege Escalation Skills Assessment - Part I ? I have questions

mystic perch
#

Has anyone finished module the "network enumeration with nmap"

acoustic owl
knotty falcon
#

I could use a hand with the Web Attacks Module:Bypassing Security Filters -

It seems like the ||HEAD|| verb may be the right one(?), but when I forward the tampered request I just get a blank a webpage, or "Malicious Request Denied" or I'm redirected to the HTTP AUTH portal.

I've tried tampering the requests for /admin.reset and /index.php as others here have suggested, but no luck so far.

novel anchor
#

Who works with FatRat?

round magnet
#

can i get some assistance with AD enum & exploit module: questions regarding skill asessment 2, please

#

i dumped the hashes for a user however that hash does not work to pivot to the next step

sweet heron
#

Is somebody available to help me get he double pivot working to MGMT01 on Attacking Enterprise Networks module (post exploit section). The handler on my host doesn't catch DC01 payload even tough everything is set up ok. DMZ01 even confirms it's listening on port 1234

unique valve
round magnet
#

the hashes i received i cannot use to psexec to ms01

sweet heron
radiant dagger
#

Also I think the instances are broken right now.

#

restart won't help. I already contact the support team

worthy yoke
#

hi everyone , i am trying to find out the FQDN of ip address 10.10.34.136 , i just understand it is something like PTR record , i tried dig -x 10.10.34.136 @dnsserver_ip but found nothing , can anyone suggest?

worthy yoke
#

I'm stuck at the lesson Active Subdomain Enumeration at HTB academy

polar widget
#

Under which module this section comes from?

worthy yoke
#

Information Gathering Web Edition - Active Subdomain Enumeration

polar widget
#

Haven't tried yet

worthy yoke
#

everything was so easy until this question 😦

polar widget
#

Hey @blissful verge
I wanna talk to you about something, can I DM you?

vital adder
worthy yoke
vital adder
worthy yoke
vital adder
worthy yoke
tender dawn
#

thought they were supposed to be the same?

languid dawn
#

To help you learn about security and to challenge you

vital adder
tender dawn
#

HTB vs THM

#

both are for learning security, I agree

polar widget
#

Its more like HTB and THM hugthebox

tender dawn
#

but I'm confused on which one I should start with

polar widget
#

At least on the learners side

polar widget
languid dawn
#

Just try them both, you'll see they are quite different, and only you can say which you like best

#

But if you really want to learn security, do CTFs

#

Absolutely don't neglect ctf, it's really the best way to learn

polar widget
tender dawn
#

I'm going to fully focus on the final choice as I can only work on these occasionally whenever I get time over the years so I'm really confused on which one to pick and worried about the opportunistic cost of picking one over the other

tender dawn
#

or do I have the wrong idea

polar widget
#

They are full of walkthroughs, CTFs, boxes, rooms, dedicated AD labs, and just everything

languid dawn
#

I mean we do have challenges, but it's not the same as a 48h competition

tender dawn
#

where does that happen

distant stream
languid dawn
hollow knot
#

I'd need some hints with the last part of the linux lpe skills assessment I believe I know how I just don't get it to work

rancid holly
#

Unable to poison logs
LFI not able to pass the php shell command it's getting filtered out
can someone help, sure that I am on correct logs as when passed a demo string it's getting reflected

quiet prism
#

anyone available to help me with sqlmap essentials? i'm having a real braindead moment here and can't see what i'm doing wrong

quiet prism
#

sqlmap -u http://IP:PORT/case2.php --data='id=1' --method PUT --dump --batch

#

nvm got it

near bolt
#

Can anyone please help me with Broken Authentication Bruteforcing Cookies - question 1. Look simple enough and ive changed the role to every admin role I can think of but nothing spits out the flag. can anyone be kind enough to help me please?

white mulch
#

In which format am I supposed to write an answer for SQLMap 1st question?

#

Okay copy paste it works

opal vapor
#

I need some help with the Attacking Web Applications with Ffuf module on the section Filtering Resultes. I need to scan for some VHosts on the domain academy.htb, but this domain seems to not exists. I also tried to scan for the target mashine, but there was also nothing. Has anyone any suggestion or ideas what I could try?

mighty pivot
#

Anyone able to help with hashcat? I’m running a kali vm, and when I run hashcat the last line says β€œInitialized device kernels and memory… Illegal instruction”
I’m not sure what the problem is here, is this a memory issue or simply a hardware problem? Any help is appreciated

opal vapor
#

I also did that

vital adder
opal vapor
#

I also have tried it over the pwnbox, but that also didn't worked

storm dock
storm dock
opal vapor
#

I also tried that out

storm dock
mighty pivot
#

I put the md5 hash I generated where the β€œhash” is

opal vapor
#

````ffuf -w SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://academy.htb -h 'Host: FUZZ.academy.htb'```

#

Or ffuf -w SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://SERVER_IP:PORT -h 'Host: FUZZ.SERVER_IP'

#

And for the host file, I just added the domain with the IP manually

strange aspen
#

can someone help me with the first metasploit question i get "exploit sucessful but no session was created"

strange aspen
#

metasploit framework/modules

vital adder
strange aspen
#

modules

vital adder
#

@strange aspen what metasploit module did you use for the eternal blue vuln?

strange aspen
#

i tried eternal blue and eternal romance

vital adder
strange aspen
#

yes

storm dock
vital adder
plain coral
opal vapor
#

That also didn't worked. I can't even access the domain if I try ping academy.htb I get name or Services not known

plain coral
plain coral
storm dock
opal vapor
#

It seems that I have general problem with the target mashine. I can't even ping the mashine, but I don't get any response. I use the academy-regular.ovpn or EU Academy 1, but I am not able to even ping the target mashine, but I can access the IP over the browser, wich is really confusing.

rustic sage
#

Killing them with 'kill -9 [connection number]' and then reconnecting with the .ovpn file fixed it for me in that case

opal vapor
#

where I can find the connection number?

plain coral
#

Can someone give me a nudge on Information Gathering - Web - Skills Assessment Perform active subdomain enumeration against the target githubapp.com. Which subdomain has the word 'elephants' in the name? yawn

kindred prairie
#

Hello, sorry for this question. I'm a new HTB user and progressing through the academy lab in the getting_started module.
I think I don't quite understand what type of flag should be found in the section of Web ennumeration.
can anyone help me understand this question better ?

rustic sage
sharp citrus
#

hello everyone . can someone please help me with Firewall and IDS/IPS Evasion - Medium Lab ( Network enumeration with nmap )

#

wrtie me in privte

polar widget
#

Anyone who did active directory bloodhound module?

#

I need help with 2 questions

#

From skills assessment

acoustic owl
opal vapor
#

@rustic sage So I killed two of three openvpn process but, one was with sudo and one without the other one was just the ps aux | grep openvpn command. Anyway I killed the two from openvpn and I restarted the connection, but it still dosen't worked. I also looked up for the ps aux | grep openvpn again and the two processes that I killed earlyer was back again and I was again unable to ping the target mashine.

quiet prism
#

can anyone help me with sqlmap essentials. i'm a little confused with specifying a location for an injection mark

quiet prism
hollow knot
#

I'd need some help with the last flag on linux lpe skills assessment

rustic sage
# opal vapor <@456226577798135808> So I killed two of three openvpn process but, one was with...

You will need to run the kill command with sudo regardless afaik, they should be gone permanently once you use kill -9, try to do that and re-run ps aux | grep openvpn to confirm, if theyre gone, reconnect to the vpn and see if the connection is working. Again though, I dont know if this is the problem you are experiencing, it is simply a fix that worked for me when I was struggling with the VPN

opal vapor
#

@rustic sage Ok that didn't worked for me now. I aslo tryied it on my host mashine, I was testing it on a ubuntu VM before, but that also didn't worked. The main situation is that I can access the IP's webserver over a normal webbrowser but I can't ping or make any kind of scan on the IP and the problem is on my ubuntu VM as well as on my windows host mashine. I am not sure how it is on the pwnbox but I can also not test that out, because I already used it today.

slender cedar
#

hi

round magnet
#

AD enum & exploit module: skill assessment 2: Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host. What i have done so far. -Got admin access -dumped lsas with mimikatz -used lazagne.exe -used snaffler.exe
the hashes i received i cannot use to psexec to ms01

reef rampart
#

what happened to the pillaging module that was supposed to come out??

carmine lark
#

FFUF the skills assessment.
Q.Before you run your page fuzzing scan, you should first run an extension fuzzing scan. What are the different extensions accepted by the domains?

so I have found my 3 sub domains and added them to my /etc/hosts
code I'm using :
ffuf -w /opt/useful/SecLists/Discovery/Web-Content/web-extensions.txt:FUZZ -u http://archive.academy.htb:31968/indexFUZZ -v
the result are .php and .phps
However these results are given for every subdomain and not getting the answer.
I have tried to combine two wordlists however takes too long for any results to come back and manually replaced index with other popular pages such as admin, but not getting any solid hits.

can someone explain where I'm going wrong please

rustic sage
#

Im stuck on information gathering - Active Subdomain Enumeration. The main thing I dont understand is ow I determine how many zones there are on the target nameserver? I have completed the first question where you find the name server but from there Im largely at a loss. Anyone able to help?

neon granite
#

Hey
anyone know what is looking for with that the only one I'm missing. From the module Intro to analyze network traffic.

What are the client and server port numbers used in first full TCP three-way handshake? (low number first then high number)πŸ˜ƒ

placid quest
#

I'm stuck on footprinting module. Anyone able to help me

dawn tapir
#

Im stuck at the vpn connection, i cant get any further, ive tried alot of things but it didnt work.. anyone able to help me?

upper vault
#

@dawn tapir using openvpn?

dawn tapir
#

Im using protonvpn

upper vault
#

you're trying to connect to the htb vpn? doing academy or starting point? I haven't used protonvpn, I'm not sure if the packs they give you are compatible with proton

dawn tapir
#

should i dm you?

upper vault
#

Nah, I don't know enough about protonvpn, I'd check the forums, but pretty sure the options are openvpn, or using the pwnbox

acoustic owl
dawn tapir
upper vault
#

You can't 'open' it, its used as an argument for openvpn

#

an example would be 'sudo openvpn academy.ovpn'

dawn tapir
#

Oh okay Thanks!

upper vault
#

np πŸ‘

pliant summit
#

hey guys , I need help with the firewall and IDS/IPS evasion - Easy Lab in the nmap module

#

I'm kind of lost on how to start. My best thought would be to see which ports actually are filtered, however when i run sudo nmap 10.129.2.80 -p-, the filtered ports are just shown as a whole number , i am not given the filtered ports, any help?

acoustic owl
pliant summit
acoustic owl
sweet heron
#

Tadaaa! πŸŽ‰
Path completed! Took me 3-4 months part-time to complete (as a hobby). It wasn't easy, but I now know a hell lot more than I did back then! Special thanks to @distant stream and @west canopy , and all the others without whom it would not have been possible!

reef rampart
#

Gratz!! πŸŽ‰

pliant summit
#

in the firewall and IDS/IPS evasion - Easy Lab in the nmap module , is it really as easy as navigating to the web server to find the OS version?
it kind of seems weird that the entire section is about IPS/IDS and firewall evasion and then there is a challenge that requires you to put the ip into your browser

rustic sage
#

Before I begin to ask a separate question, am I allowed to ask questions or send my thoughts here other than this one?

#

Maintenance is July 6th, at 6:00 - 10:00 UTC HackTheBox

lucid mirage
upper vault
#

@sweet heron Way to go!

brazen hinge
#

Hello!, i'm stuck in 'Attacking common applications' - osTicket, the challange is "Find your way into the osTicket", but in the example is used dehased.py script to get some password leaks but i cant found some version to use, Someone who has done the module and give me some advice to get the credentials?
i already tried creating new user and ticket to get mail, but I have not succeeded

unique valve
pliant summit
#

hey im kind of lost on where to start in the hard lab in the nmap module

steady sandal
#

Hi! I 've just started the linux fundamentals. In the part of linux components I can't understand what exactly is the graphics server component and how it differentiates from the Window Manager (GUI). Could someone recommend me more material to get main idea?

plain coral
vestal thistleBOT
#

Bot Messages Empty?
@vestal thistle makes use of message embeds as output for most commands. Please note that having "Link Preview" disabled will not make these embeds show in your client. Enable User Settings β†’ Text & Images β†’ Link Preview β†’ Show website preview info from links pasted into chat. to fix this.

Help :: Generic Help

Hello @upper vault~!
Click here to read my online documentation!

Need more help? Join my official support server using this invite: https://discord.gg/cYkHGZ96xf

Here's the list of modules that are available for use in this server:

administration, automoderator, bravefrontier, custreact, forms, help, moderation, permissions, revivedwitch, rss, twitter

Use !help (module name) for a list of commands within the specified module.
Use !help (command name) for more details about a command.

Commands Not Working?

Please note that an apparently unresponsive command might be caused by missing, or incorrectly set, module permissions. Refer to the Permissions System documentation page for more info!

In order to understand whether permissions are the root cause of a non-working command, you can enable verbose mode for yourself with !verbose. These messages are always sent via DM, and this mode is configured on a personal basis.

Direct Messages Not Working?

In order to avoid having issues with using the Direct Messages-related commands (most importantly, the Forms Submissions), make sure you have "Allow direct messages from server members" active in this server's "Privacy Settings" and/or in your "User Settings". Refer to the image below for more info.

white mulch
#

can anyone give me a nudge on SQLMap module?

#

Little stuck on case 5 question

sharp citrus
#

Help , with Network enurmation with nmap ( medium lab ?

boreal vine
#

someone for Windows Privilege Escalation Skills Assessment - Part II ?

pliant summit
quiet prism
#

anyone available for a quick sqlmap question? i've got the http request copied into a text document and added the -r flag, but saying it's not a valid http request XD

steep oxide
#

anybody willing to help on this question?

#

intro to network traffic analysis

sturdy robin
steep oxide
#

Module: Intro to Network Traffic Analysis
Section: Packet Inception, Dissecting Network Traffic With Wireshark

#

that is the whole question

#

anybody who knows willing to help?

#

im using pawnbox, so im basically accessiing another machine from pawnbox and using the machine within the machine to capture traffic, which is slow as hell

vital adder
#

the cred for that is in ||one of the link show in that section||

cinder swallow
#

hello

#

i have a problem

#

you must stop your active machine before spawning another one

#

how to fix this error?

white crater
#

Hi, I am working on the question finding cleartext in the assessment 1 of module "AD enum and Attack". I have managed to get both mimikatz (2.1.1, error ERROR kuhl_m_sekurlsa_acquireLSA ; Key import, i did run it as an admin) and lazagne to the target, but just cant find the cleartext. Can someone help give me some directions please?

opal vapor
#

I need some help with the Attacking Web Applications with ffuf module. In the section Filtering Results I need to scan for some VHosts, but if I run this command ffuf -w SecLists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http:// academy.htb:PORT -H 'Host: FUZZ.academy.htb' It seems that every VHost in that list is matching, but if I look up for them in my browser it can't find any of them.

white crater
#

ok, i got it. managed to get the cleartext password with mimikatz (ver 2.2.2)

sly kelp
#

Hello i have a Question. I have signed up as student with my ΓΌniversity email. Can i have access to bug bounty modules with that or i need to buy another subscription for that

Thank You

boreal vine
#

need a nudge on Windows Privilege Escalation Skills Assessment - Part II

white mulch
#

need a nudge on sqlmap,can anyone help?

opal vapor
#

Thank you, but I have already the solution.

steep oxide
#

any clue?

rustic sage
#

anyone up for a question about type filters in upload attacks?
I am able to upload stuff but im stuck since when i view them i get the cannot be displayed because it contains errors

golden hornet
#

Hi everyone . I got stuck at skills assessment web attacks . I have admin priv but now I don't know what I have to do . Can someone help me ?

vital adder
golden hornet
#

thank you

#

But what if i don t get XML request to edit ?

vital adder
golden hornet
#

What format should I use to export the content ?

vital adder
golden hornet
#

no , i have only text/html format

#

and others but not xml

vital adder
golden hornet
#

what is add event >

#

?

vital adder
golden hornet
#

Is just an Events tab , but it does nothing

vital adder
golden hornet
#

ok

vital adder
# golden hornet ok

ok i just spin up that box and know what my note is talking about if you still can't find it dm me

sharp citrus
devout cliff
#

if anyone has done the Web Service and API Attacks Module I need a nudge on the information disclosure section, my SQLi keeps getting hung on bypassing the WAF/IPS.

quiet prism
#

i need someone to help me with this sqlmap again. i'm having an absolute nightmare with this module

#

i've got the http request literally straight copied from burpsuite. ive got the json format on my injection point

boreal vine
#

need a nudge on Windows Privilege Escalation Skills Assessment - Part II someone ?

lament beacon
#

Stuck in the IDS/IPS evasion lab - Network Scanning with Nmap module

#

Anyone can help?

honest panther
#

Hi everyone is there anyone help about set up website i'm struggling upload any file on my website

quiet prism
quiet prism
acoustic owl
rich mulch
#

====
Hi guys, I cannot connect to openvpn htb. How to fix this?

west canopy
rich mulch
#

I just downloaded the new one. It got error

acoustic owl
boreal vine
#

need a nudge on Windows Privilege Escalation Skills Assessment - Part II someone ?

west canopy
#

@boreal vine DM me πŸ™‚

devout cliff
#

need some help in the web service and api attacks skill assessment

signal burrow
#

hey im pretty new to this and im stuck on cURL

#

im not sure how im meant to do that and was wondering if anyone could give me a hint

west canopy
#

@signal burrow try running curl against 46.101.47.107:32223/download.php

sharp citrus
#

Guys , can someone please help with this

#

After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer.

#

medium lab - network enumeration with nmap

acoustic owl
sharp citrus
#

can you please tell me how its done

acoustic owl
#

Currently, I am on the Pivoting, Tunneling and Port Forwarding module in the Skills Assesment.
Question 5 is about reading LSASS.

I have generated the dump file, but how do I get it onto my attacker PC?

I am connected to the server via proxychains -> RDP. So I can't just start a SMB server on my attacker PC. On the Foothold PC no Impacket seems to be installed.

Anybody have an idea how I can transfer the file?

woven copper
#

evil-winrm transfer options or if i remember that Windows machine have the ssh service on.

west canopy
#

@acoustic owl I ended up ||transferring mimikatz to PIVOT-SRV01 and running it to extract a password from memory||

rich mulch
#

====
Hello guys,
I am in module "ATTACKING COMMON APPLICATIONS β†’ Attacking Drupal". I gained root by exploiting the Kernel. So other than this, is there any way to gain root? Because I found there are many user account such as "mrb3n, ubuntu, webadmin"
β†’ I think there will be a way to horizontal escalate from www-data to these acount. But I have not figured out yet

rustic sage
#

Hi, people. I have been struggling for days to import new modules from exploit-db to msf console and with no success. Anybody who can help? (I've googled, trust me.)

sand harness
#

hi, can anyone help find out why nmap doesn't work for me? it always says the host is down but even when using -Pn it doesn't work

#

for some reason it says all the ports are in ignored states when they shouldn't be

rich mulch
sand harness
#

I did, still nothing

rich mulch
sand harness
#

surely scanning the first 1000 ports would be enough if checking for common ports like http

#

unless it scans at random

rich mulch
#

and what if your machine is not running at common ports? then you have to scan 65k ports

#

and you yelds that nmap does not work, but you have not counted the case that have weird ports

carmine lark
#

Last question of FFUF skills assessment.
Q. Try fuzzing the parameters you identified for working values. One of them should return a flag. What is the content of the flag?

Got the two parameters and a hit on what the parameter ID is however to get flag i used this post method however still get a access denied.
curl http://faculty.academy.htb:30920/courses/linux-security.php7 -X -POST -d 'username=harry' -H 'Content-Type: application/x-www-form-urlencoded'

Please help

scenic harness
#

I am in the 'using web proxies' module and I'm having trouble finding the flag, my hint is its not in the same location as the last flag. when I check the other 2 directories I am not finding any flags or text files? I don't believe there should be anything overly difficult about finding this flag?

scenic harness
shut owl
scenic harness
shut owl
slow ruin
#

Anyone able to provide a hint for Password Attacks Lab - Easy? I have used the username.list and password.list within the Resources against the ftp and ssh services. Also generated a wordlist using cewl but that also does not seem to work.

mighty pivot
# storm dock what hashcat version are you running?

Sorry I missed this. It’s probably about a year old. Some additional information about the laptop I’m running it on is it’s loaded up and doesn’t have a ton of extra memory, and not a very good processor. I googled the message it showed me, I just didn’t find a definitive reason for others getting the same thing

static bloom
#

hi all, hoping this is the right place to ask this. Trying to use nmap to see what is on the box for the public exploit module. i think im struggling with the nmap portion but i'm fairly sure ive figured out the rest.

#

||i went to the url, saw the plugin. found the vulns in metasploit. looked up the cve as to how to craft it as is also in the forum post. Just not sure what i missed||

barren stone
#

I don't know if this is the right place for this, but if anyone has completed the Windows Fundamentals, I made it threw everything but the assessment and I am lost. I am not an experienced windows user, so this section was a struggle, would anyone have any recommendations for gaining more windows experience?

static bloom
#

such as using a windows vm?

barren stone
# static bloom such as using a windows vm?

Like I have a Windows VM, and I understand some really basic GUI things, but I am lost in how the powershell runs, and basically everything the Windows Fundamental Academy Assessment section is asking for. I am just lost with how windows runs, and the academy kind of went from 0-100 on me. I need maybe something recommended that would give me a good foundation in windows. I don't know, I will keep looking for other courses or something. I'm just lost.

static bloom
#

powershell is similar to python

#

powershell is another shell

static bloom
#

that and what i did with the exploit

normal marsh
# barren stone Like I have a Windows VM, and I understand some really basic GUI things, but I a...

Windows is quite the cluster... So many different rabbit holes you could go down. But since you've mentioned PowerShell, I would recommend searching GitHub, YouTube, and DuckDuckGo for combinations of words such as PowerShell for pen / penetration tests / testing / testers, or PowerShell for admins / administrators. Alternatively, look at the table of content for some windows books and start googling all the section headers. Windows Systems Internals is a very popular book, which as your knowledge skills and abilities grow you'll want to read at some point.

polar widget
#

I did a thing

upper vault
#

@polar widget grats!

polar widget
barren stone
normal marsh
upper vault
#

Does anyone have a usable proxychains that isn't preinstalled on kali?

stiff moon
#

need help on Attacking Domain Trusts - Child -> Parent Trusts - from Linux

i have done all the examples but have no clue what to do to get the ntlm for the domain admin user bross any tips/help?...

west canopy
#

@stiff moon i was able to get the hash by ||using secretsdump.py and authenticating as the adunn user||

wide coral
#

@acoustic owl not sure what your transfering but did you try scp

#

I guess this discord is useless for assitance

sage jackal
#

Hey need some help on the Shells & Payloads module Skills Assessment Last question…I have managed to gain a shell but I can’t read the flag cause of access rights

knotty falcon
#

Could I get a nudge with Web Attacks Skills Assessment please?
I've taken over the administrator account but don't see a path to obtaining the flag from here.

vital adder
knotty falcon
acoustic owl
acoustic owl
wheat anvil
sage jackal
stiff moon
zenith schooner
#

Hi ribit. It is solved. It was my fault. I missunderstood the statement. I was scanning the linux server instead of the entired network to find the windows host. In my opinion, the pictures and and some parts of the lessons aren't clear to understand. But eventually, with some practice I move forward. Thanks.

sage jackal
fair cove
#

So on the Password Attacks Password Reuse / Default Passwords
It asks me to find some credentials for mysql
I cant find it. Any hints?

vital adder
stiff moon
leaden quail
#

Hello guys, can someone help me with this openvpn Error. Not sure how to fix it.

vital adder
leaden quail
#

OpenVPN 2.6_git x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO] built on May 30 2022
library versions: OpenSSL 3.0.3 3 May 2022, LZO 2.10

vital adder
#

@leaden quail this is command they recommend you use to downgrade it on thm
cd /tmp; wget -O openvpn.deb https://kali.download/kali/pool/main/o/openvpn/openvpn_2.5.6-1_amd64.deb; sudo apt install ./openvpn.deb; rm openvpn.deb

leaden quail
#

That works, thank you much

gloomy tangle
#

Hi @everyone. I am stuck at module Attacking Enterprise Networks section Web Enumeration & Exploitation. Can someone help me?

desert stone
#

hey @everyone i am a high schooler exploring options in cs came across cybersecurity. I have offers for the course of cybersecurity and AI from the same university. Can someone help me understand which one will have better scope in future becoz some peeps on net says ai will eat up cybersecurity jobs. Open to suggestions and advices.
Thanks a lot in advance

hollow knot
#

@gloomy tangle dm me

#

Anyone here who can assist with the double pivot in the Attacking Enterprise Networks module? I can't catch the second shell for some reason

rustic sage
#

Hello, is normal, that the academy.ovpn, restarting every 3/4 min ?

novel matrix
rustic sage
#

okap thx

distant stream
polar widget
#

Both are high in demand career options, choice any individual has to make. What suits you better you gotta decide yourself.
I believe if you're good at anything then that works.

#

In both the cases, you need deeper knowledge of lots of things, and it holds true, they are high paying jobs too

#

There are lots of stuffs, like domains within cybersecurity like red teaming vs blue teaming, technical roles vs non technical and so on,

And AI domain I have less idea about, but basically you're gonna hit ML, Data Science, AI and stuffs around that

tribal plinth
opal vapor
#

I have a question with the skill assesment section on the Attacking Web Application with ffuf module. I am right now on the last question where I need to look for some Values for some POST parameters. For that I need a wordlist from the SecLists wordlist, but I have no idea wich one could be right. Do I just need to test all of them or can give me someone a hint?

west canopy
#

@opal vapor try using ||/seclists/Usernames/Names/names.txt||

opal vapor
#

Alright thanks

fair cove
#

Hey guys. Any help on the Password Attacks module?
Examine the target and find out the password of the user Will. Then, submit the password as the answer.

Hint is the following.
Sometimes, we will not have any initial credentials available, and as the last step, we will need to bruteforce the credentials to available services to get access. From other hosts on the network, our colleagues were able to identify the user "Kira", who in most cases had SSH access to other systems with the password "LoveYou1". We have already provided a prepared list of passwords in the "Resources" section for simplicity's purpose.