#public-training

1 messages · Page 1 of 1 (latest)

modest elbow
reef orbit
#

@modest elbow Is there dedicate channel for people who registered?

coarse ocean
coarse ocean
#

@modest elbow Access Key/Secret Access Key not showing up in the IAM labs section as shown in the Labs presentation. Where do we get the creds to access the labs if they're not showing near the lab exercises below the video?

rare onyx
coarse ocean
rare onyx
#

there's a training support channel

#

also if you add your discord handle (check as some start with a period) from here into your profile on the training website it will give you access to the #arte-general channel as well

coarse ocean
#

@reef orbit See above ^

modest elbow
#

How to contact support or ask technical questions in a training.
If you have an active course, you can can go to your user profile in https://training.hacktricks.xyz/profile and add your Discord handle. This will add you to a new role in this server where you will be able to find new channels to open support tickets or ask questions.

cosmic coyote
#

Asking here since I guess this is a common question for the whole training platform: Is there any way to get a full invoice for the voucher payment? After I bought mine, I got the quick receipt via email, but I see nothing else. Maybe I missed something?

modest elbow
magic shore
#

need quick help, if you know there is attached policy for specific user and want to check what exactly that policy looks like via CLI how should we check this?

Also how do we know user has iam:SetDefaultPolicyVersion permissions...

#

am able to see the policy name, using versions you can check version as well, but whats inside that policy? how do we check

spare cloud
#

There's no need, ever, to cross-post a question

magic shore
#

i thought it be wrong group 😉 hence posted twice

spare cloud
#

So you delete it from the channel where it's irrelevant, and keep it in the one where it is

magic shore
#

done .

modest elbow
orchid berry
#

Hey, just making sure, if I signed up now, I'd get access to labs immediately right?

#

I still see the first 100 haven't signed up but want to make sure that if I paid, I wouldn't get put on a wiatlist

#

@modest elbow

#

I'd like to begin right away!

modest elbow
orchid berry
#

oh perfect!!!

#

Pays immediately.

#

❤️

#

I have to mention, HackTricks has been an amazing educational resource for me, I think what you're doing is fantastic

#

Also, do you have some time for a quick DM?

#

I have a couple questions regarding something that I would prefer to keep off the public channel

#

Not about HackTricks

modest elbow
#

thanks mate, sure. About the dm sure, send it

empty topaz
#

Hi @modest elbow ! I am considering to purchase the course and looking to clear a couple of doubts I have.

  1. Do I get lifetime access to the course materials or the contents will it be limited to a certain time?
  2. If lifetime access is provided, will any future updates be included in the purchase as well?
  3. (Eventhough this is kinda answered in previous post) If I get the course now, can I start my lab after new year? I won't be able to start the labs now as I am focussing on a different cert atm.

Please let me know. Thanks in advance!

glacial kelp
# empty topaz Hi <@642394020064264242> ! I am considering to purchase the course and looking t...

Hi @empty topaz

  1. Access to the videos and slider is lifetime. Access to labs is not, purchasing the course grants access for 45 days. It is possible to purchase extra lab time (15, 30 or 90 days)
  2. Updates to correct things that change in the future will be included. However, there will be no new material added (like other services)
  3. You can purchase the course now with the early bird discount and activate it in the next 365 days. Once the course is activated the lab does start automatically. So only activate the course when you are ready to start the lab
    Let us know if you have any other questions
empty topaz
glacial kelp
orchid berry
#

Hey guys, so far I'm loving the course! Quick question, for the EC2 labs, are the instances up when the lab is running?

glacial kelp
orchid berry
glacial kelp
dry garden
#

Hi @modest elbow @glacial kelp I bought the ARTE training course and started it yesterday, I also added my discord handle to my profile, but I wasn't added to the ARTE channels just yet. Could you please check if there are any issue? Thank you

glacial kelp
limber sand
#

Hello,
I purchased ARTE training and added my discord handle to my profile, however, I am not added to the channel. Could you please help me with that?
Thank you

glacial kelp
limber sand
orchid berry
#

Afternoon everybody! Quick question regarding the extra credit for the ARTE class. Does the pull request have to be specifically about AWS, or can it be about other cloud environments like Azure or even Digital Ocean?

modest elbow
orchid berry
#

I understand, thank you! Is there a timeline on when those other courses are released?

modest elbow
tawdry canopy
#

Hi @carlospolop @glacial kelp I bought the ARTE training course and started it yesterday, I also added my discord handle to my profile, but I wasn't added to the ARTE channels just yet. Could you please check if there are any issue? Thank you

glacial kelp
lone summit
balmy sparrow
#

Hey all! Curious how the ARTE course has been for those taking it. I’m currently doing the AWS CloudBreach course

tropic cove
#

Hey all, I just finished the HackTricks ARTE exam.
This was a great course and exam, OSCP style (despite a small reset issue at the beginning, quickly addressed by congon4tor).
Really great course, good instructional up-to-date content in the videos, written documentation via Cloud HackTricks, linked resources to original research, great exercises with cool flag system.
I've done a ton of remote trainings (OSCP, OSCE, CRTO, SANS courses etc; I'm holding 17 certs) - including the ones from Altered Security for offensive stuff in on-prem AD and Azure as well as as CloudBreach's AWS and Azure courses. CloudBreach pales in comparison. ARTE was hands down one of my best training experiences. Already am recommending this to my colleagues. 10/10

orchid berry
#

That one you have to like set the labs up yourself with their terraform files right?

tropic cove
orchid berry
#

So like, now with that expanded knowledge, I feel like I am more prepared to tackle more elaborate AWS environments, and better yet, even environments of which there aren't labs in ARTE for because of how well documented https://cloud.hacktricks.xyz/ is.

#

I know I can just go there and research how to enumerate the service, I can also go to AWS's website do some research there, and find out what I can achieve through it.

cyan mango
#

or replace the instance profile of the compromised instance (ec2:ReplaceIamInstanceProfileAssociation). *

aws ec2 replace-iam-instance-profile-association --iam-instance-profile <value> --association-id <value>
``` There is a error. The right query is :--iam-instance-profile Name=<value>
#

@modest elbow @glacial kelp

glacial kelp
tawdry canopy
#

Anyone had trouble connecting to their RDS instance after launching it in rds-lab-2?

tawdry canopy
#

I figured it might be a security group issue but I can't ping

glacial kelp
#

It is highly likely a SG issue

tawdry canopy
#

got the flag 😎

modest elbow
#

@everyone Friendly reminder that today is the last day of the early bird discount for the HackTricks AWS Red Team Expert cert! You can get a voucher today and redeem it within a year! More info in training.hacktricks.xyz

tawdry canopy
#

Did anyone else get a 502 bad gateway after uploading their app on the Elastic Beanstalk lab?

glacial kelp
tawdry canopy
candid turret
#

hi, I just entered the ARTE training. Is there a private channel for that? Sorry, I never used Discord before.

modest elbow
tawdry canopy
glacial kelp
candid turret
glacial kelp
candid turret
#

Will there be an Azure training similar to ARTE in the future?

modest elbow
silent rune
#

Hello I have sent an email to support about the AWS Red Team Expert labs, one of them seems to be broken.

Also, is there any consideration to give us a 60-day lab time? This would give us a chance to a complete 1 lab a day instead of 2 labs a day which is very demanding for people who are employed.

This would also leave people time to research the video contents. Please deeply consider this.

glacial kelp
#

Regarding extending the lab duration we are not able to cover the cost of the labs for 60 days without raising the price. For this reason we think it makes more sense to keep the certification cheaper with 45 days and in case people need it they can extend 15, 30 or 90 days.
I wouldn't think of x labs a day as a goal since there are labs that can be done in 10 minutes and others that will take multiple hours to figure out.

But we appreciate the feedback. We give a feedback form at the end of the certification so looking forward to seeing you opinions

silent rune
silent rune
#

@glacial kelp I added my handle to the profile section. I may need to open another ticket

silent rune
# glacial kelp Regarding extending the lab duration we are not able to cover the cost of the la...

I've been thinking about the issue you raised about lab costs. What if you start with the cheaper labs (like IAM, S3, Security Groups) and save the pricier EC2, RDS, DynamoDB labs for a separate provisioning cycle (like a part 2 of the course), making them on-demand..?

This way, we keep initial costs down and only use resources when needed, potentially extending lab access without a big price hike. It could balance cost management with a solid learning curve, offering flexibility for those needing more time. Thoughts?

glacial kelp
coarse ocean
#

Why change the whole course for one person? I and many others think it's just fine the way it is. Having access to all the labs from day one is actually better for learning due to a process called interleaving and spaced repetition. So, if you limit it and break it into two courses that would be shitty overall experience simply because you don't want to spend some time on the weekends, and at night doing the labs. Not to mention you literally just started, so you don't even know how long it will take you @silent rune . Why not try it first before you complain and ask for changes?

silent rune
# coarse ocean Why change the whole course for one person? I and many others think it's just fi...

I respectfully would like to respond to this:

"Why change the whole course for one person?"

  • While I agree, you shouldn't change the whole course for 1 individual. I'm the only person that "you" saw raise this problem. To write off my entire suggest as I'm the only person is not a fair judgement.

"I and many others think it's just fine the way it is."

  • You've not backed this claim with any data, it's an opinion you have. A more proper response would be to have a poll.

"break it into two courses that would be shitty overall experience simply because you don't want to spend some time on the weekends"

  • This is very narrow minded. You can simply provision the second part at the start, it would just have a stricter timebound like 30-45 days or something, where as the other labs could be provisioned longer because they are simply cheaper to keep provisioned from a cost point a view. The couse would not degrade in quality. I think you misunderstood my suggestion.

"Not to mention you literally just started"

  • 20/50 flags captured so far. I'm about half way through. But again, this doesn't discredit my suggestion as not being beneficial or breaking the course in anyway.

"Why not try it first before you complain and ask for changes"

  • Your comment is highly offensive and doesn't take into my perspective. I'd like to share that I am "trying it" and I do enjoy the content. Furthermore, it's difficult to juggle full-time security work and still complete all the labs. I work 40 hours a week for a security firm, I usually need to devote my free time on the weekends to cover the labs I missed during the week.
balmy sparrow
#

While I’ve purchased but not started the course yet, it sounds like @glacial kelp point was the lab would be too expensive to keep running for >45 days without raising the price. One way to reduce the infra cost is only spin up the infrastructure needed for the lab. Example, when lab one starts, it provisions lab one infra. When the flag is found it’s deprovisoned. In theory this could allow the course to remain the same price but extend the duration. Or the course authors could just keep the extra money 🤷🏻‍♂️

modest elbow
#

Guys, we are optimizing the labs so no worries about this. Labs will always be available from day 1 and the quality won't be affected

silent rune
silent rune
glacial kelp
#

Also once the exam is passed we share a feedback form to collect opinions and ensure we keep improving as much as possible

tawdry canopy
#

totally stuck on blackbox-lab-1. ||When I simulate the group permissions I get nothing back. After adding my user to the group I get back the same permissions I had before when re-simulating.||

modest elbow
#

Blaclbox1

coarse ocean
#

I respectfully would like to respond to

lofty imp
#

@modest elbow @glacial kelp hi ! do you know when the course on gcp will be available?

glacial kelp
granite silo
#

I modified the database, the status is "active" but postgress seems not accessible

#

From ec2 instance on lab2 psql is not installed but with nc i am able to get a reply. How do you managed to get the access? seems like sg is denying trafic from public but not from vpc

#

nvm, got it ||ec2 has internet access, just download psql binary and there we go||

lofty imp
#

Hey guys with @hardy canyon we wrote a review of the certification for those who are interested ⬇️
https://www.hackcyom.com/2024/02/arte-review/

glacial kelp
halcyon ocean
#

what is this channel?

glacial kelp
#

For people that have purchased the certification they can access some other channels

glacial kelp
#

Our hacktricks training AWS Red Team Expert

next olive
#

Hi all im unable to solve the sts lab 2. I am specifically stuck at running the github workflow where im getting errors unrelated to the lab.
Do we require aws as well?- tried referencing it including my aws arn
Any support would be appreciated

glacial kelp
#

You only require a github account, check github docs on how to connect to aws from github actions using oidc

next olive
#

Thanks!

tired wyvern
#

I am a noob, doing a challenge and have a png file; trying to learn from output of zsteg -all xyz.png am stuck, anyone who can help?

ionic violet
#

hey friends, someone can help me with some doubts with iam lab?

mental tartan
glacial kelp
orchid berry
#

I can't wait to do the Azure and GCP trainings

modest elbow
#

GCP + Workspace before summer and Azure+EntraID before the end of the year hopefully!

torpid sandal
#

Friends, good evening! Who can help and sort out 2.2 STS - Security Token Service: Github Actions?

orchid berry
#

Watch it

#

?

wanton latch
#

does ARTE have a written component in tandem with the videos?

wanton latch
#

cool, are they comprehensive to stand on their own?

prisma raven
#

I recomend it

wanton latch
#

i absorb information better reading. not that i won't watch the videos, i just like having reference text. thanks!

#

probably going to give it a whirl

prisma raven
modest elbow
wanton latch
#

gotcha

#

thx

icy jewel
#

Hello, I added my discord handler to my hacktricks profile but I still don't have access to the training channel, can someone help?

glacial kelp
icy jewel
visual sedge
#

hey @modest elbow I'm looking to do the ARTE when I have some time - do you have a timescale for the Azure version (I belive there was mention of Azure and GCP versions potentially)

modest elbow
prisma raven
#

Interesting 😎

#

A lot of checks are going to be automated with nuclei now I guess

#

Powerfull integration

glacial kelp
#

Interesting nuclei took the time to do this. I thought they were more bug bounty related than for whitebox pentests. They don't have too many checks right now compared to prowler or steampipe but they will add more probably

prisma raven
orchid berry
#

I hope they add cognito templates

#

It's also my favorite exploit

#

I found an 0day in a hack cracking platform by coalfire.

#

Based on Carlos's teachings!

#

Super exciting to have found that

prisma raven
#

🔥

prisma raven
#

Interesting

#

😂😂😂

lone summit
tame knoll
#

I can't deploy "github actions" in STS module, though other sub modules are successfully deployed.

#

<@&937047799441268746> Please help check it

novel stone
#

@tame knoll I will notify it thanks

tame knoll
#

Thx

glacial kelp
#

Hey @tame knoll can you open a support ticket? You will need to add your discord handle to your profile in the website

tame knoll
#

Sure, will do

little belfry
#

I have a question about sql injection wargame, can anyone take a question?

modest elbow
visual sedge
modest elbow
#

@everyone
The best hacking course & cert in GCP and Workspace is coming to HackTricks Training!

Learn from the basics (organization hierarchy, permissions...) to expert level (how to escalate privileges, remain undetected, pivot between GCP and Workspace...) in the htGRTE course and certification (GCP Red Team Expert).

Soon we will be releasing the presale with an amazing early bird discount!

orchid berry
#

ohhhhhhhhhhhhhhhhhhhhhhhhh snap

visual sedge
#

nice

orchid berry
#

I'm so glad I've been here from the beginning to see how things are progressing, you're killing it @modest elbow and @glacial kelp !

strong osprey
#

Take my moneyyyyyyyyy

latent trail
#

I AM EXCITED!!

cosmic coyote
#

Preparing myself to first blood the GRTE cert exam! 🔥

orchid berry
#

Are there any cool attacks you can do if you only have a Google project ID? I keep finding these in mobile penetration tests that I do as a result of firebase db installations from the app. Being able to leverage that into an attack would be slick

modest elbow
grim meadow
#

Any timeline for Azure (MARTE!!!??? :D) ?

modest elbow
smoky rune
#

@everyone for those in Barcelona and interested there's a CTF game based on a 0day and serverless cloud environments within aws this Saturday 1.
It's free and there will be prices for the winners!

More info:
https://www.meetup.com/es-ES/hackingcybersecurity/events/300898931/?notificationId=1369556153578446848
https://www.meetup.com/es-ES/serverless-barcelona/events/300898832/

Meetup

This CTF is a contest oriented to cloud and serverless services, where contestants have to work together to solve security and cloud/security challanges to win!

Teams will

Meetup

What is a CTF? Is a kind of information security competition that challenges contestants to solve a variety of tasks.
A Serverless CTF is oriented to cloud and serverless s

steady sentinel
#

👋 hi…what are the charges for lab extension if needed

#

I am in a full time job with limited time each day…do you think typically 60 days is more than sufficient or is that a chase to finish the course and labs

#

Additionally, if I take the course which is for life and at any point I just want to do the labs, is that possible without repurchasing the course but only the labs…also any new updates to the labs will be automatically also available to everyone that bought previously …is that right?

#

This is for ARTE and do we get a certification badge that can be verified by the employers

#

Last question 😅…are we taught any stealth and bypass in the course as well

orchid berry
orchid berry
orchid berry
steady sentinel
#

Ok..thanks a ton

#

Looking forward to get started…planning to start end of June

steady sentinel
glacial kelp
steady sentinel
#

Thnx

#

And can I buy the course today but go through the document and videos first and start the lab 2 weeks later…I think it’s not possible but just trying my luck

steady sentinel
glacial kelp
glacial kelp
modest elbow
#

Hi @everyone ! The presale of HT GCP Red Team Expert (GRTE) is finally here!
Become a GCP and Google Workspace security expert by getting access to this certification with the early bird discount!

More information at https://training.hacktricks.xyz/courses/grte

(The certification is expected to be released with all the content and labs on July 22nd)

visual sedge
#

Nice

strong osprey
#

activate it at any point in the next year
this is nice

visual sedge
#

@modest elbow how long is the early bird offer valid for

modest elbow
strong osprey
#

When will the presale start?

glacial kelp
orchid berry
#

oh wattt

#

This is what it says when you try to purchase now

strong osprey
turbid rune
glacial kelp
# orchid berry

Deploying a fix now it was set so only admins could purchase (for our testing) and I forgot to undo that

orchid berry
#

July 22nd here we come baby 🏎️

glacial kelp
orchid berry
#

damn I've having that stupid issue with international purchases again 😐

sage sparrow
#

Moreover, do you have some plans for people who would like to buy ARTE + GRTE? @modest elbow

orchid berry
#

Are there discounts for students?

Yes there are! Create an account using your universities email address, then send us an email from that email address to training-support@hacktricks.xyz asking for the discount and indicating a link to your linkedin and we will send you a 20% discount.

sage sparrow
modest elbow
modest elbow
# sage sparrow Is it possible to get student discount in early access voucher?

It's not possible to use several discounts at once, either early bird or other discounts.
And we have special discounts if several vouchers are bought in bulk (usually by companies). We might considder adding special packs in the future, but the early bird discount is the biggest discount we give, so atm it doesn0t make sense to create more discounts for GRTE

steady sentinel
#

Any plans of issuing badges via badger or Credly?

glacial kelp
orchid berry
#

Accredible or Credly seem to be the move for most businesses atm.

glacial kelp
#

Both are above the pricepoint that makes sense for us at our scale. I'm adding a button in the certificates table that simplifies adding the cert to linkedin profiles

#

Hopefully that is good enough for the time being

glacial kelp
#

@steady sentinel If you go to https://training.hacktricks.xyz/certificates you should see a new linkedin button which will take you to a prefilled form to add the certificate to your linkedin profile. You can add the PDF as Media and it should look pretty nice

turbid rune
#

Hi @glacial kelp @modest elbow, if I buy the ARTE voucher now, when should I activate it at the latest?

glacial kelp
shy spindle
#

Hey there @glacial kelp ! Super interested in the ARTE training. Is it possible to do a payment plan or installments for the voucher?

glacial kelp
tacit stump
#

Hi all, I have trouble with provisioning the lab for AWS-Lambda, I have tried to rest the lab with no luck . Anyone can can help please.

glacial kelp
tacit stump
#

I'll try the entire lab now - Thanks

balmy edge
#

I have problem on EC2 Labs, i configure aws:

aws iam list-users
{
"Users": [
{
"Path": "/",
"UserName": "ec2-......
[SNIP]
......

everything is good, but when i do:

aws ec2 describe-instances

Could not connect to the endpoint URL: "https://ec2.us-east1.amazonaws.com/"

What I'm missing? :/

orchid berry
#

look at what your policy allows

#
aws iam list-attached-user-policies --user-name <username> #this flag might be wrong?
aws iam get-policy-version v1 --policy-name <policy-arn>```
#

you may only be able to describe some instances

languid carbon
#

hi mates, just bought voucher for GRTE, am i right that it will be available after release on 22nd of July?

modest elbow
analog scarab
#

Hi everyone, GRTE finally starts tomorrow, we are looking forward to it 🎉 Are you guys planning to do Azure RTE in the near future?

glacial kelp
analog scarab
#

ok, thx)

glacial kelp
#

But we are really happy with how it is turning out I think it is going to be great

orchid berry
#

And hopefully teach me what I can do with all these keys for google projects I keep finding on pentests 😂

turbid rune
#

Hi, you give me an invoice when I purchase the training, right?

modest elbow
turbid rune
#

Hey @modest elbow @glacial kelp, today, I bought ARTE but ran into a small problem. I have contacted training-support@hacktricks.xyz via email. I would be grateful for any assistance you can provide

south wave
#

Hello @modest elbow I am buying the voucher soon for expert aws cert, I have a couple questions kindly, 1. how long does each lab take per day, 2. is the exam guided (meaning that despite being black box, are there directions to what to exploit or to find?) 3. can i buy the voucher now and begin in few months?
Thank you

south wave
#

@glacial kelp eagerly waiting for your response :^)

glacial kelp
# south wave Hello <@642394020064264242> I am buying the voucher soon for expert aws cert, I...

Hey 👋,

  1. Lab completion time depends a lot on your experience and also what labs. There are some that I expect most people will solve within 15 minutes and others I expect even experienced people to take a few hours. There are 50 of them and they are very varied in difficulty.
  2. The exam has very minimal directions. You get a url and work from there to get 3 different flags. It is designed so that if you have worked through the labs you should be able to pass. We have 3 blackbox labs specifically to prepare you for the style of the exam.
  3. The voucher is valid for 1 year from the day of purchase. And they once you activate it you have another year to schedule your exam
south wave
#

Beautiful, thank you ❤️

south wave
#

@glacial kelp purchased, added discord id, will discord access be given shortly or only once the voucher has been activated?

glacial kelp
modest elbow
#

@everyone
ARTE (https://training.hacktricks.xyz/courses/arte) cert was just updated with new techniques in the Black Box (Red Team) and CloudTrail sections and a new Black Box lab was released!
Get it with a 20% discount using the "SUMMERTRAINING" code before the 1st of August.

If you already bought it, you have lifetime access to these updates. Go to those sections and check the updated slides and videos!

lethal quail
south wave
#

@glacial kelp please note I DM'd you about voucher questions further, about to activate it. kindly when you have a moment to get to it

orchid berry
#

T-15 DAYS UNTIL GRTE LAUNCH

lethal ore
#

🔐 Calling All Cyber Enthusiasts! 🔐

Are you passionate about cybersecurity? Eager to stay ahead of the digital curve? Look no further! Join our exclusive WhatsApp group where we share top-notch resources, insightful content, and cutting-edge techniques to keep your skills razor-sharp. 🚀

Whether you’re a seasoned pro or just starting your cybersecurity journey, this community is for you. Let’s learn, collaborate and elevate our skills together! 💻🔍🔒

join this invite link https://chat.whatsapp.com/J8HVeSEPDUR2gaE5NB4OoM Let’s fortify our knowledge and build a stronger, more secure digital wor

gaunt slate
#

When I purchase the ARTE training, does the course start immediately or do I get to choose a start date? Thx

near prairie
balmy hollow
#

Wanna know if GRTE is worth to take it???

#

I'm definitely going to take ARTE, but I don't know how big the market size is for Google Cloud

orchid berry
#

Well

#

AWS, Azure and GCP take up like 90% (made up number, probably accurate) of the market share, so by preparing yourself for all three environments, you are then ready to handle assessments that many people just don't know how to do.

balmy hollow
#

Good way to put it.

modest elbow
# balmy hollow Wanna know if GRTE is worth to take it???

The GRTE cert is no only about GCP but also about Google Workspace which is one of the most used identity providers. And the companies that use Google Workspace tends to use GCP sooner or later just because it's easier. So even though it's just the hird biggest cloud provider, I find it being used pretty frequently (specially combined with AWS)

orchid berry
#

Combined market share is 67% in total, and GCP makes up 10%, so it's like half of Azure and 1/3rd of AWS.

#

So yeah it's pretty common, especially if you think about how often you see AWS and Azure nowadays.

#

And the multi-cloud / hybrid environments are increasingly more common as well

balmy hollow
#

Thank you very much for the information. Im tend to be very new to the cloud but I found cloud hacking very interesting. Definitely going to get both bro.

#

💯

orchid berry
#

Yeah plus it's fun to learn new stuff 😄

balmy hollow
#

To join the arte traning private group, do I have to purchase the course first

balmy hollow
#

thank you very much

orchid berry
#

T-Minus Monday GRTE

orchid berry
#

T-M 24 HRs!!!

glacial kelp
languid carbon
#

Hi,
There is a CORS error that prevents watching videos in the GRTE course.

glacial kelp
#

I'll fix it in a bit sorry

modest elbow
#

Lets go @everyone !! GRTE - GCP Red Team Expert- certification is finally live!
Get it with the early bird discount while it last!
And good luck to everybody that is trying to get first bloods of the labs and exam!
https://training.hacktricks.xyz/courses/grte

dusk vessel
modest elbow
cosmic coyote
modest nexus
#

Anyone else having trouble deploying the lambda lab in ARTE?

glacial kelp
#

If you get errors deployong labs try resetting your entire environment from the dashboard

orchid berry
#

Resetting the lab is triggering errors.

#

This occurred after the second deployment of the labs failed.

#

I was getting unable to deploy project/topic labs or somehting like that, reset my whole lab and it then failed.

orchid berry
#

second lab reset today and the deployment once again failed just now 😐

glacial kelp
#

Fixed it for you but still investigating the root cause if anyone else has any issues please open a ticket

glacial kelp
#

Found the root cause the lab destruction deletes that resource when it should not

glacial kelp
#

Shold be fixed now. Please reopen a ticket if you find any issues

sudden merlin
glacial kelp
pastel totem
#

Hi

GRTE labs - iam section, got multiple issue while trying start up the lab, after couple of lab restart it start working, now do not have possibility to extend lab time due to error, could You check it:

glacial kelp
glacial kelp
#

Do you mind moving this message to the #grte-general channel please

orchid berry
#

done

mental tartan
#

<@&1128840997581889586> <@&937047799441268746>

novel stone
#

thx

toxic trellis
#

i have a problem with one challenge on EC2
is there someone to help?

glacial kelp
modest elbow
#

Hi guys!
@SoteriaSecurity is looking for a Senior Offensive Security Consultant (Cloud Pentester) valuing the HackTricks Training ARTE (AWS Red Team Expert) certification as a plus to access the role!

More info about the role in https://ats.rippling.com/en-GB/soteria/jobs/e6251998-dea0-41ab-a13e-e718e1591136

If your company is looking for Cloud Security engineers contact us and we will help you find them!

fringe violet
orchid berry
#

@modest elbow when are we getting ARTE/GRTE energy drinks?? 😂

modest elbow
#

Hahahaha that would be great

orchid berry
#

And why are you only arta-certified 😂😂😂

orchid berry
modest elbow
orchid berry
modest elbow
toxic trellis
#

I got AWS Red Team Apprentice certificate 🤞
thanks for your support @modest elbow @jimmy
I just posted on LinkedIn and recommended amazing courses and labs to others
https://www.linkedin.com/posts/mohammadhosseinnamadi_aws-pentesting-hacktricks-activity-7228309612368658433-eGTJ?utm_source=share&utm_medium=member_desktop

I’m happy to share that I’ve obtained a new certification: HackTicks AWS Red Team Apprentice from HackTricks!
It was truly an incredible journey toward AWS…

orchid berry
#

Just got an offer from Coalfire's AWS team! Couldn't have done it without @modest elbow, @glacial kelp and the HackTricks team!

#

ARTE definitely leveled me up to where I needed to be in order to crush their interviews!

modest elbow
#

Thanks for your words mate! Happy to have helped!!

frank adder
#

A fun killchain that isn't talked about anywhere on Hacktricks is attack AppSync GQL. Lots of devs are lazy and directly inject the temporary API keys into javascript (AWS gives them a maximum life of a couple weeks to prevent this, but people do it anyway). The API key is always fully privileged, so all data is readable.

Less fruitful but just as fun is using Cognito credentials to reach into GQL. Fine grained access control for Cognito+AppSync GQL is really hard, and if they don't use AWS WAF to prevent introspection queries, you can read the entire schema and query whatever you want.

orchid berry
# frank adder Hahaha, I founded that team. Congratz!

That's awesome!! I don't know if you're still there! But I actually wasn't able to take that offer due it being kind of a low offer and also due to legal's extremely restrictive contract language but it's always cool to know that know that I got the chops now! ❤️

orchid berry
normal python
normal python
#

this is correct email to ask about student discount: training-support@hacktricks.xyz?

normal python
#

Thanks really appreciate this course. There’s is not much training like this out there and new fedramp guidelines require a red team but most people are not teaching cloud red team skills.

modest elbow
normal python
#

what is the cost for lab extension?

orchid berry
#

Yeah I actually just breached an AWS environment and significantly escalated as a result of my training here!

modest elbow
normal python
#

Anyone aware of any configuration mapping tools similar to bloodhound/azurehound but for aws and gcp?

prisma raven
#

First GRTE Certified!. 🎉

#

Awesome GRTE journey, I recommend it to anyone interested on GCLOUD, you are not going to find nothing similar to the Hacktricks training course out there!.

glacial kelp
#

Congratulations 👏👏

modest elbow
#

Congrats!!!

modest elbow
#

In GCP it's possible to find your permissions with the testIamPermissions API even if you don't have any permission!
Moreover, it doesn't generate any logs!
Find a PoC in https://github.com/carlospolop/Bruteforce-GCP-Permissions and learn this and many more GCP & Workspace hacking tricks in the GRTE certification: https://training.hacktricks.xyz/courses/grte

GitHub

Use the GCP testIamPermissions functionality to bruteforce and discover your permissions - carlospolop/Bruteforce-GCP-Permissions

modest elbow
#

Next Friday Sept 13th is the last day of the GRTE (GCP Red Team Expert) early bird discount! Don't miss it!

icy tide
#

Hey, If my labs are expiring and I extend the lab after it expires.Does it carry on the progress I made or it will reset?

prisma raven
icy tide
#

great, thank you for the response @prisma raven

prisma raven
tame mantle
#

dear sir
I have already purchased the GCP course, but can I study the course first and then start the experimental environment?

#

@prisma raven

modest elbow
prisma raven
#

60 days is more than enough

#

I was still having 25 days after passing the exam

#

So don’t worry

tame mantle
#

ok

tame mantle
#

thank

prisma raven
cobalt swift
#

Is there a channel for ARTE?

prisma raven
#

And you will be granted access

cobalt swift
#

Got it I'm yet to take the course

#

Wanted some feedback on how deep do the modules go

#

I've got lot of mixed reviews online saying most of that content is out on youtube or that it is to basic :/

prisma raven
#

Im pretty sure you won’t be finding nothing like ARTE anywhere else

#

Tell me what you want to know , I will answer your doubts

#

You can also check my post where I explained how it works

#
cobalt swift
#

Can I dm you?

prisma raven
#

Sure

modest elbow
#

2 new lessons about (ab)using GCP Cloud Scheduler and Workflows were released in GRTE certification (https://training.hacktricks.xyz/courses/grte)
If you already got access to it you can check them, if not, you can get access to the certification and will have access to all the updates in the future!

You can also take a glance to these GCP service from a offensive security perspective in:

prisma raven
glacial kelp
prisma raven
#

like NASA, PDF letters

#

probably...

glacial kelp
prisma raven
#

Let´s see

orchid berry
#

oof

#

that's a big nono

prisma raven
orchid berry
#

well

#

they have like thousands of services

prisma raven
#

yeah...

#

don´t know XD

orchid berry
#

it's pretty tough to catch EVERY thing

#

it's easy to say from our perspective 😄

prisma raven
#

after discovering this you always asks your self if someone has discovered before XD

glacial kelp
#

You would think a service this critical would have been tested a lot more... I feel like any pentester would try this the first thing they would do when assessing this service

orchid berry
#

Yeah true I would

orchid berry
#

"I wonder if I can connect to random on-prem environments!"

modest elbow
#

Did you know that setting arbitrary environment variables can get RCE in most scripting languages?

Some cloud services allow to modify env variables and you can:

  • Escalate privileges to roles or service accounts without typical permissions to access them (e.g. https://shorturl.at/ziMvo)
  • Execute code in unexpected places, such as GCP Composer’s DAG processor, triggerer, workers, and webserver (already fixed)

Learn and practice these and other hacking techniques at http://training.hacktricks.xyz and http://cloud.hacktricks.xyz.

orchid berry
#

When are we gonna get HackTricks Prod Energy Drinks?

#

"Fuel Your Code. Break the Rules. HackTricks Prod—Power for the Bold."

#

🔥

modest elbow
orchid berry
#

Do you have a patreon btw?

prisma raven
#

Interesting tool for fast checking in azure/microsoft stuff

modest elbow
modest elbow
orchid berry
normal python
#

Is anyone familiar with any vulnerabilities related to dce-rpc in azure ?

near prairie
near prairie
#

🚨 New Course Alert! 🚨

Excited to introduce HACKTRICKS GRTA: GCP Red Team Apprentice, the perfect starting point for mastering security in GCP and Google Workspace (https://training.hacktricks.xyz/courses/grta).

👉 Learn about the GCP key services.
👉 Discover how to spot and exploit common misconfigurations.
👉 Increase your skills in hardening GCP environments.

To celebrate it we have reduced the prices of both ARTA and GRTA the following month!!

wraith canyon
#

Hi there, how are you? If I want a sanity check on an ARTA flag, can I consult through this channel?

near prairie
#

If you dont have it, in the profile section of hacktricks training you can provide your discord username and you will be added!!

wraith canyon
#

Thank you!

near prairie
drifting stump
#

hello all
I'm just curious
if i want to conduct a pentest on Azure and the client will create a user account for me to test with
which role should that iser account get assigned with?
maybe global reader? or is it something else?

orchid berry
#

I typically ask for multiple roles. Not just a single one.

orchid berry
#

Additionally, make sure that the client assigns you an O365 license and all that. It will increase the depth of the analysis you will get to perform.

#

I recently did a red team op where we could've done a whole bunch of cool stuff and demonstrated a lot of impact had we been assigned a 365 license to our assumed breach account likke everyone else had been

prisma raven
#

🔥

drifting stump
#

hello
how can i know how many days i have left for the lab

#

i got busy in the past week and didn't get the chance to study

near prairie
#

Let me know if you find it!!

drifting stump
orchid berry
wraith canyon
normal python
#

passed CRTP, CRTO, PNPT, and OSCP in the last 2 months it's finally time for this baby

halcyon linden
#

Hello, will the azure red team expert be available soon?

near prairie
halcyon linden
near prairie
#

🚨 GRTE Update & Discounts Alert! 🚨

We celebrate it with new discounts for GRTE. Go to our LinkedIn (https://www.linkedin.com/posts/hacktricks_grte-update-discounts-alert-we-activity-7254065963841576962-Lhio?utm_source=share&utm_medium=member_desktop) or Twitter (https://x.com/hacktricks_live/status/1848302265641173155) and learn how to get the discount!!

Our new lesson on how to abuse Google Workspace Sync is up now. Furthermore we have updated our Cloud Functions laboratories, learn how to escalate Cloud functions via storage monitoring here https://training.hacktricks.xyz/courses/grte.

If you’ve already purchased the cert, these lessons are waiting for you now!

You can also learn some Cloud Functions cool hacking tricks in https://cloud.hacktricks.xyz/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-cloudfunctions-privesc and learn about Google workspace Sync in https://cloud.hacktricks.xyz/pentesting-cloud/workspace-security/gws-workspace-sync-attacks-gcpw-gcds-gps-directory-sync-with-ad-and-entraid

true nest
#

Hiya, Python security researcher here. Can someone reach out to me regarding an inquiry in the course content for GRTE when you have the opportunity? (Not a generic question, probably more line of business/abuse of platform related.)

true nest
modest elbow
true nest
#

Might be stuck in your DM requests.

#

Hopefully it didn't go to Spam lol.

near prairie
#

🎉 New HackTricks Bundles! 🎉

These bundles give you a 20% discount compared to getting each course on its own, so you get more for less!

1️⃣ Expert Bundle: Includes GRTE (GCP Red Team Expert) + ARTE (AWS Red Team Expert): Ideal for those ready to master advanced cloud security techniques in both AWS and GCP. (https://training.hacktricks.xyz/bundles#expert)

2️⃣ Apprentice Bundle: Includes GRTA (GCP Red Team Apprentice) + ARTA (AWS Red Team Apprentice): Perfect for beginners looking to build a strong foundation in cloud security. (https://training.hacktricks.xyz/bundles#apprentice)

Take advantage of this opportunity to boost your skills with a HackTricks bundle (https://training.hacktricks.xyz) !

short lantern
#

Hello!
Does anyone else experience with training site issues?

near prairie
#

Should be working just accessed it without any problem!!

#

Try reloading it

short lantern
#

Ah, it works now 🙂

limber cairn
#

How can I join the ARTE channel?
I am a student and got stuck

near prairie
#

You will be added automatically

limber cairn
#

Thanks, I did, but..I don't see the private channels

near prairie
#

Weird should be right below this one

#

@glacial kelp Should it be already there right??

glacial kelp
near prairie
#

🔥 Black Friday Deals Are Here! 🔥

Until November 30th, take advantage of 30% OFF our Cloud Security Bundles and 20% OFF on individual courses with our Black Friday discount codes. Master advanced security tactics in AWS and GCP with our ARTE and GRTE certifications!

⏳ Don't miss out on these limited-time deals and start your journey with HackTricks today!

The discounts are applied automatically in the web http://training.hacktricks.xyz

modest elbow
potent gull
#

Thanks for the discount offers. When can we expect to see the release of the Azure material?

modest elbow
glad karma
#

Hey how do I buy the course ?

#

Nvm my bad no coffee full piss head mode

raven onyx
#

Hi team, just quick question.
How long does hacktricks takes to respond on my emails regarding student discount as i need to buy the ARTE asap

near prairie
#

Not much, why?

sour ginkgo
#

Hi all. I need a copy of my invoice for ARTE course. Can I request that through email (If so, which email address)? Thanks

near prairie
sour ginkgo
#

Great! Thanks

sour ginkgo
near prairie
sour ginkgo
near prairie
devout hinge
#

Are the labs in browser or do you create your own lab environment?

prisma raven
glacial kelp
halcyon linden
#

Hello, sorry to bother you.
It seems that the azure training is scheduled for early 2025.
Will be there some early bird discount?

near prairie
halcyon linden
near prairie
#

⏳ Black Friday Deals Ending Soon!

This is your LAST chance to grab Black Friday deals on HackTricks Training. Until November 30th, take advantage of 30% OFF our Cloud Security Bundles and 20% OFF on individual courses with our Black Friday discounts. Master advanced security tactics in AWS and GCP with our ARTE and GRTE certifications!

🔥HURRY!!🔥

The discounts are applied automatically in the web http://training.hacktricks.xyz.

glad orbit
#

My GRTE lab hasn't been provisioned yet, can someone have a look into it. Its been 5 hours since I activated my voucher.

modest elbow
near prairie
#

The labs start in the part 2!

glad orbit
#

I get an empty page when I try to access part 2

near prairie
glad orbit
#

ok, let me try chrome

glad orbit
near prairie
#

@glacial kelp @modest elbow Can you take a look to this?

near prairie
glacial kelp
#

Hey @glad orbit I think you should be good to go now. GCP made a change yesterday and yours was 1 of the 2 deployments that failed because of this. I missed that it happened twice and only retried for the other student. Sorry about the delay

glad orbit
glacial kelp
manic solar
#

Hi there! I keep getting this error message, I'd like to purchase this before the deal ends

near prairie
glad orbit
orchid berry
#

Any updates on when the AzRTE is coming out?

#

Also, @glacial kelp I never got my GRTE badge

glacial kelp
#

It is a shame you have to choose between what can to show in discord

orchid berry
#

Ik 😭

#

But thanks!

modest elbow
manic solar
near prairie
manic solar
#

However, I assume I can use this option to get a new activation link at any time

modest elbow
glad orbit
near prairie
glad orbit
near prairie
glad orbit
#

Thanks, I see it now

near prairie
#

Great

hybrid forge
#

Howdy @modest elbow or anyone that can help.
I am doing the ARTE and am stuck on 2.13 ECR - Elastic Container Registry 2nd Lab - Push Docker Image.
I downloaded the walkthrough but still cannot get it to work.
When I run the lambda invoke command I get the following error in the out.txt file:
{"errorType":"Runtime.InvalidEntrypoint","errorMessage":"RequestId: 0f86b30a-b562-4235-bac1-61ce7e19ad0c Error: fork/exec /lambda-entrypoint.sh: exec format error"}

hybrid forge
#

Howdy @carlospolop or anyone that can

near prairie
hybrid forge
near prairie
hybrid forge
#

I dont have access

near prairie
#

Did you added your discord id to your profile in hacktricks training?

hybrid forge
#

I'll do that now

tiny perch
#

Hey there, I am thinking to get 15 days lab extension for ARTA course. But if I am able to finish all the labs in the allocated time that I have left and if I did not redeem the voucher for lab extension (I am guessing everything on this platform is based vouchers), can I then issue an refund for this unused voucher?

near prairie
#

If its being more than a month, and of course it has not being used yes.

near prairie
orchid berry
modest elbow
south wave
#

creds are fine, anyone has same output for kms:PutKeyPolicy (I reset lab, same thing)

#

other labs ok

#

I ran --debug also, but doesnt seem to be issue on my end - could someone help please

south wave
#

ok

cedar marsh
#

Hi all 🙂 Is this the right channel to ask for hints about ARTE labs? I think my instance of "API Gateway Sign Request" may be faulty

near prairie
#

You have to add your discrod name to the hacktricks-training profile

cedar marsh
#

Awesome thanks - just added 🙂

near prairie
stray kraken
#

Is there any way to invoke Lambda function without the Invoke permissions?

#

I noticed the lambda:UpdateFunctionConfiguration privilege escalation via env variables but is it enough just to set them or do I need to invoke the function anyway?

near prairie
#

Im not aware of any other way of doing it

stray kraken
#

But there can be some triggers, right? like uploading something to S3 bucket ?

near prairie
modest elbow
iron agate
modest elbow
#

Hi @everyone !
We are releasing the HackTricks assistant chatbot https://www.hacktricks.ai/ for free!

This chatbot has access to HackTricks & HackTricks Cloud knowledge base so you can ask it questions about topics discussed in HackTricks or cybersecurity in general and it'll be able to help you using HackTricks knowledge.

Moreover, it also allows to generate interesting facts and questions about the selected HackTricks topic or even about a specific certification. This allows you to practice hacking (from a theoretical way) from anywhere and prepare for the top certs!

marble heart
modest elbow
# marble heart

Might have been a temporary vercel breakdown, its working now

marble heart
#

I still can't access it.

modest elbow
#

? I can access it without any problems

#

And a couple of guys I asked also can.
You get that error always?

marble heart
#

My friends also cannot access the webpage.

#

I can access the webpage now.

marble heart
#

I was able to access the website using a VPN. After disconnecting the VPN, I can still access it. However, browsers that have never accessed the site using a VPN cannot reach it.

#

By the way, I am currently in Taiwan.

modest elbow
modest elbow
modest elbow
marble heart
modest elbow
# marble heart

shit, ok, I'll take a look these days but for the moment I guess you need to keep using the VPN

west wharf
#

guys i got an announcement of a pentest AI assistant bot

#

how to access it ?

#

think it was from this server, if i remember correctly

modest elbow
west wharf
#

been using chatgtp some time and its quite alright for brainstorming

#

how would this compare?

modest elbow
# west wharf how would this compare?

This is like chatgpt with further access to hacktricks data with an interface prepared to learn about hacktricks content and prepare for other certs with questions related to them

west wharf
#

This is great

#

Probably less chance to hallucinations then since hacktricks data is awesome

pastel totem
#

Even in polish it has good flow when I am testing it :d

modest elbow
glad karma
#

Works great !

south wave
mossy pumice
#

Hey thanks for sharing. @south wave

neon storm
#

Hi! I don't know if it's proper channel to ask, but: has anyone run into issues with the ARTA SQS lab? Could you walk me through the correct way to retrieve the output after injecting commands into the vulnerable Lambda function? I’ve tried several approaches and still can’t figure it out. Thanks in advance! 😉

neon storm
near prairie
#

Did you put your discors id into the hacktricks trainning account?

neon storm
#

no, I'll do it in a minute - thank You!

south wave
molten vortex
#

Hi everyone, would someone from support be so kind and add me to the gcp channel ? Thank you in advance ps. yes i added my discord id on my profile

molten vortex
#

hi @near prairie , thanks for reaching out. no unfortunately not.

near prairie
#

You should have it now @molten vortex

molten vortex
#

Thank you @near prairie

modest elbow
odd thunder
#

Not available in English too?

sterile oracle
#

Azure course has been released?

modest elbow
modest elbow
stiff wharf
modest elbow
wispy cradle
#

Hi, I'm thinking about buying a voucher for the courses, but before doing so, want to check one thing. Is there any expiration for the certifications, or are they valid indefinetly?

near prairie
wispy cradle
iron agate
#

I passed Google's Cloud Security Professional Engineer Exam last night and I attribute most of my success to actually taking the GRTE Hacktricks Course: https://hackidle.com/Course+%26+Certification+Reviews/Google+Cloud+Certified+Professional+Cloud+Security+Engineer

hackIDLE

#cloud-security #google-cloud Google Cloud Certified Professional Cloud Security Engineer Google Cloud Certified Professional Cloud Security Engineer-20250211201817480.webp TLDR: Weird Remote Exam S…

#

I really just had to fill in a few personal gaps in key management

glacial kelp
modest elbow
#

@everyone we are super excited to share with you that AzRTE (Azure Red Team Expert) is now in pre-release with the early bird discount applied! Don't lose the opportunity to get it at the best price.
Get ready to improve your Azure & EntraID hacking skills!
More info in https://training.hacktricks.xyz/courses/azrte

unique spruce
#

Signing up now! [or well, one of my guys are] ... great to see this coming out, we have been waiting with bated breath 😄
Will it be possible to gain access to the course material prior to the 29 March ?

near prairie
unique spruce
candid pike
#

Pls I have html script am looking for the php who can help out

chrome fox
#

I honestly read AzERTY (which is like the qwerty of french keyboard layouts) when I said the message out loud

cursive zealot
#

when is the kubernetes course coming out? @modest elbow

modest elbow
cursive zealot
#

why the domain is not indexed?

#

is it just me?

cursive zealot
#

Another question, is microsoft grapth api mention in any of this chapters from the new azrte?

pastel totem
#

I assuming that tokens & API could covered it

near prairie
near prairie
modest elbow
glacial kelp
vapid lagoon
#

Would ARTE help with Security Engineering?

glacial kelp
#

If what you do relates to aws I would say yes. Although it is more tailored towards attacking aws more than defending

rotund drift
#

Does the GRTE course have any training on "Apigee X" ?

near prairie
#

Please use the #arte-general channel for these questions, or the ticket system

pine compass
#

I struggled a while with the signup form to create an account for the new azrte training.
It says 8 to 32 chars. But it's actually **24chars **max, it won't accept passwords of 25chars or longer

My advice would be either allow up to 32 chars or change the error msg. It's a bit outdated though, why not accept 40 chars passwords e.g.?

glacial kelp
pine compass
glacial kelp
#

Yes sorry, I'll check in a bit

glacial kelp
prisma raven
#

Let´s get ready to rumbleeeee 😎

modest elbow
#

Yeaaahhh

mental compass
#

Hi guys, not sure if it's the proper channel...
I'm a little blocked in the EC2 lab from ARTA...
I did the SSRF, i got two roles, the one listing the secrets is not allowed to read them...
So, after trying this and that, and re-readig the materials a couple of times I'm lost...
I also tried to privesc based in the roles I found but I couldn't move forward from that...

#

lab 1

#

@modest elbow

jovial hamlet
modest elbow
mental compass
#

thanks!

mental compass
#

Hi folks, general question:
It's not yet clear for me whether Cloud attacks are post-exploitation/pivot or we can target the cloud gathering the organization ID or even with no credentials ??

near prairie
mental compass
#

thanks Jim, i see... then it's clear to me now that it's possible to perform unauth tests against the cloud... but the "how-to" is not yet fully 100% clear... should I gather target information, as a "must-have" element, or I as the pentester might have my own cloud user/org to perform the test?
coz in my mind there're 2 possible scenarios: my-creds (kind of "cross env" testing), or no-creds.
So, both scenarios test for publicly available resources, but i wonder if behind the scenes, the cli/cloud requires some such of creds being loaded, or the tests on the publicly available services won't fail when there's someone testing without creds... ??

#

the "technical" part is not yet fully clear...

near prairie
mental compass
near prairie
mental compass
lone summit
pastel totem
prisma raven
#

we are all ready

#

Glory for everyone, we fight the same battle

#

🫡

mental compass
#

Hi all! Happy Friday! Hope you enjoy your weekend!

cursive zealot
pastel totem
#

Yep

#

You got 12 months to activate it

near prairie
cursive zealot
#

Got it

glacial kelp
#

Of march *

near prairie
#

Yes March😅

iron agate
prisma raven
#

This is interesting

#

Didn’t know about it

#

Have you ever found it applied in real assessments? @modest elbow @glacial kelp

#

Im curious now

glacial kelp
#

Never seen this

wispy cradle
#

Hi there! Is there a timeline on when the AzRTA course will be available?

near prairie
wispy cradle
prisma raven
wispy cradle
modest elbow
#

Hi @everyone ! To celebrate the Azure Red Team Expert certification is released in a week we are going to launch the first Cloud PEASS!
Welcome Azure PEASS (https://github.com/carlospolop/cloudpeass), a script that can get a management and/or a graph token and find ALL your permissions inside Azure resources and Entra ID. Moreover, it'll use Cloud Hacktricks (https://cloud.hacktricks.wiki/en/index.html) and HackTricksAI (https://www.hacktricks.ai/) to color the sensitive permissions you have and even tell you how to (ab)use them!

This is just the first of the 3 initial Cloud PEASS to be released with HackTricksAI support for red teams!

halcyon linden
#

Hello, who is/are the authors of the AZRTE course please?

modest elbow
halcyon linden
#

After AZRTE purchase, can I enable it whenever it fits my schedule?

modest elbow
halcyon linden
modest elbow
halcyon linden
#

Does the course cover hybrid scenarios?

modest elbow
halcyon linden
#

ok, I understand

modest elbow
#

@everyone the new AzRTE (Azure Red Team Expert) certification is up and running!
If you have a voucher you can redeem it from today!
If you don't, get one while the early bird discount lasts (only a couple weeks more left!)

lunar crown
#

Hey carlos make a complete web hacking frow intermediate to enterprise level in video form

#

If you can't then help me about your wiki pages

#

I am confused

#

Does those content about web is enough for bug bounty and entry level jobs?

pastel totem
#

for entry jobs despite of "know" vulnerabilities you have to have some basic of app developing, networking, scripting and so one. Most of companies form my experience looking for people which could learn fast, have analytic mindset got basic knowledge which will be valuable during problem resolution. No one looking for guy who could from memory describe all owasp top 10 vulnerabilities

lunar crown
#

This is just describing me

pastel totem
#

so if you got a match not be worried to try 😄 job interviews are not hard like most people thinking

lunar crown
#

Main thing is my english language is weak and and am still learning computer language 🥲, communication skill is literally 0

silk bolt
#

Is there anyone looking for developer?
Now I am actively looking for a new job opportunity or task, and here, I'd like to connect with you. Thank you.

bronze remnant
#

Hello, I don't know it this is the right channel but I'm stucked on SSRF lab, on ARTA.

bronze remnant
#

Appear as No Access.

near prairie
#

Add your discrod handle to your account in hactricks training

near prairie
prisma raven
#

hellooo, I have been researching recently about device flow authentication, and discovered in a yt video that is supported by Az Cli, what didn´t expect as Az Cli can´t be configured with access tokens, I might take a look on how it´s managing the connection, cause maybe something can be done in order to make it work with Access/refresh tokens

#

At the end of the day that´s what you get when device login, a FOCI refresh/access token

modest elbow
#

Hi @everyone !

AzRTE (Azure Red Team Expert) early bird discount will be gone on April 25th. Learn Azure and Entra ID hacking with tens of hands-on labs to practice at the best price while it lasts at https://training.hacktricks.xyz/courses/azrte

Moreover, if you prefer to learn on a live training check out the 2 days 2 clouds course we offer at HackSpaceCon in https://www.hackspacecon.com/HackSpaceCon#/awsazurehacking and learn AWS and Azure hacking in 2 days!

Hack Space Con is an innovative and dynamic conference bringing together cybersecurity professionals, ethical hackers, and space technology

pine compass
#

Pfeww i'm getting the payment on the 24th. Right on time!

prisma raven
#

☁️ I'm releasing a new tool: Cloud Detective

🌐 Lately, I’ve been getting more involved with cloud stuff, and one thing that quickly stood out is that whether it’s an external audit or a red team engagement, we almost always end up with a pretty big list of subdomains after the OSINT/Recon phase.

The next logical step? Scanning for ...

#

Thanks everyone for the support, don´t know why but the tool is getting too much love ❤️

leaden patio
#

Hello. In ARTA KMS Lab any ideas?

#

An error occurred (InvalidCiphertextException) when calling the Decrypt operation:

#

aws kms decrypt --ciphertext-blob ms_lab_1_user2_credentials_encrypted.txt --key-id 32778d35-462d-4bf6-b62d-f2c6eb043bbe --profile audit01 --region us-east-1 --output text --query Plaintext | base64 --decode

#

i removed whitespaces in the base64 encrypted key file already

#

i used file://enc.txt and fileb://enc.txt

#

nothing working

#

file should work as its textmode

modest elbow
#

Hi @leaden patio, please, in the training web go to your settings and set your discord hadle. Then, you will be invited to other training private channels were you will be able to get support and also open tickets!

leaden patio
#

hmm i have done this but never got an invite

#

😦

modest elbow
leaden patio
#

ok solved both problems

trail veldt
#

is the hacktricks training dashboard not loading for anyone else?

#

i’m not able to access my courses

near prairie
golden hatch
near prairie
#

Try removing te cache

trail veldt
#

tried that, tried switching browsers, tried on my phone

#

just getting a blank screen

#

maybe something’s wrong with my account

near prairie
#

You should not have any issues, in any case @glacial kelp can you take a look to this?

glacial kelp
#

I'll DM you to troubleshoot the issue

stiff wharf
tame mantle
near prairie
icy tide
#

few days back there some discounted offer for gcp course right? is it still valid?

#

@modest elbow

modest elbow
icy tide
#

let me ask my boss il get back!

turbid rune
#

Hey, I bought ARTE last June. But I didn't activate the voucher. I'm going through a busy period. Is there a deadline to enable it? Or can I enable it whenever I want?

glacial kelp
cloud grove
plucky tundra
#

Hey everyone,
I have a couple of questions about the ARTE certification.
In the FAQ section, it says:
"The voucher will grant you 60 days to complete the laboratories. However, you will be able to purchase laboratory extensions if you need them."

  • How much does it cost to extend the lab time, say for an additional 30 days?
  • Is an extension typically necessary, or are the 60 days usually enough to properly prepare for the exam?
    Also, after passing the exam, is the certificate provided only as a PDF, or do you also receive a digital badge for LinkedIn or other social media platforms?
    Thanks in advance!
pastel totem
#

60 days in my opinion is more then enough i finish all in 30 days

near prairie
tidal spoke
#

I just started the ARTA training. I deployed my first lab and was able to configure the CLI. When I deploy my lab again, will it generate new keys that I need to update my CLI profile with?

near prairie
tidal spoke
#

Great, thanks!

near prairie
tidal spoke
#

Yes, I wasn't sure since I am doing the ARTA 🙂

modest elbow
#

@everyone
🚨 New HackTricks Training Lab Discounts Now Available!

We’re excited to announce new discounts on HackTricks Training Lab extensions!

When you purchase a new certification, you can now purchase at the same moment a lab extension with great discounts.

🎁 Bonus: This week only, these discounts are automatically applied to users who have already purchased a certification. No action needed!

echo plaza
#

Nice

If we buy them do they immediately activate or can we activate them later?

modest elbow
#

You can activate them whenever you want

echo plaza
#

Awesome, thanks 🙏

carmine flicker
#

Hi guys.I’m thinking of signing up for the arte course — just wondering, is it possible to get an invoice for the payment? I’ll need it for company reimbursement.
Would really appreciate any info!

pastel totem
#

sure it possible

#

during purchesing you need to click on checkmark

modest elbow
carmine flicker
#

I see
thank you all!!

inner galleon
glacial kelp
plucky tundra
#

@modest elbow Hi Carlos! How does it work with ARTE again? Does the lab time automatically start when I buy the course and enroll into the course? Or can I take my time watching the videos and reading the PDF, and then start the lab access after a month or so? Can the lab time be paused?

near prairie
plucky tundra
#

ok, good to know, thank you very much!

near prairie
modest elbow
misty zodiac
#

Hello

prisma raven
#
Tenable®

Tenable Cloud Research discovered a supply chain compromise vulnerability in Google's Gerrit code-collaboration platform which we dubbed GerriScary. GerriScary allowed unauthorized code submission to at least 18 Google projects including ChromiumOS (CVE-2025-1568), Chromium, Dart and Bazel, which are now remediated. Third-party organizations tha...

potent iron
#

Hi all, it seems GRTA is a subset of GRTE. So taking GRTA with intention to the take GRTE is not recommended, right? (Because also there seems to be no discount if you have the apprentice course)
If you have some cybersecurity background but no red team what do you suggest to take?

Thanks to everyone that read until here!

near prairie
# potent iron Hi all, it seems GRTA is a subset of GRTE. So taking GRTA with intention to the ...

Hi! Yes GRTA is subset of GRTE. We recommend to directly take the GRTE course as it has more content and its more complete. Dont worry about having no red team background GRTE starts from the basics and you wont have any issues (There is also the support channel that can help you). And in case you end up getting GRTA, you get a 20% discount after finishing it for the GRTE course.

Let us know if you have any other questions!!

potent iron
near prairie
potent iron
sturdy finch
#

Hi guys 👋, I see you have next meetup in Valencia, Spain

Rooted Valencia, 25–26 de septiembre 2025

Is it possible to register for the event now?

In general, do you have some other resources where people do similar meetings in Spain, especially in Valencia

Thanks🙌

modest elbow
#

@everyone check the HackTricks Training discounts for the Summer!
https://www.linkedin.com/feed/update/urn:li:activity:7346175851421433856/?actorCompanyId=72119507

This summer, learn Cloud Security!
Use the code SUMMER to get 20% off in all certs before August 1st.
Also repost, tag a friend and have him tag you back and you could both win a voucher for the AzRTA cert by July 10th!

#hacktricks #training #cloud #hacking #security #aws #gcp #azure | 41 comments on LinkedIn

golden hatch
near prairie
#

No, just to lab extensions, and individial courses

fallen kraken
#

Hi, has the raffle for the coupons been held?

near prairie
manic spindle
#

Does the ARTE course prepare you for a real world Red Team Simulation? Are stealthy methods and attack paths outlined?

modest elbow
# manic spindle Does the ARTE course prepare you for a real world Red Team Simulation? Are steal...

Yes, Red Teaming and Whitebox review are the main goals of this certification. After learning the basics every lesson contains a section about attack paths per service, and also post exploitation and persistence techniques per service.
Then, in the blackbox lesson you learn more red team like tricks + you have 3 labs simulating red team exercises.
Finally the exam is actually a red team simulation

digital maple
lethal zenith
near prairie
lethal zenith
#

That means I can't buy course separately 😦

near prairie
#

No, you need to buy the full certification, with all the content and lab days included. If you run out of lab time, you can buy extensions for it

lethal zenith
#

I mean like, in bundle, I only see course price, not lab price, so, I was asking about that

near prairie
#

The lab time is included in the course

#

You buy for example an ARTE and a AzRTE you get the course and 60 days of labs for each one of the certs

#

And if the lab time that is included is not enough you can buy extra time

near prairie
lethal zenith
#

okay

hasty sapphire
#

When the course bundles are purchased you will receive vouchers. These vouchers are then redeemed (when you decide) which starts your lab/course time.

The vouchers last for a year, I think? Essentially it lets you set your pace of owning all courses but taking them at your leisure

modest elbow
lethal zenith
modest elbow
#

Hi @everyone
Last 7 days for the SUMMER discount of HackTricks Training!

fallen kraken
near prairie
foggy lodge
#

Hi @near prairie how many flags are required to pass the GRTE exam totally.. I heard there are 3 flags to find. ...? What are the ways to get Certified

near prairie
modest elbow
#

@everyone last day of the summer discount! If you want to get some discounted certs or lab extensions use the SUMMER code today!

rich seal
#

If you could only get one, (and have none yet), which one would you get - and take advantage of the sale?

near prairie
#

(My personal favorite is ARTE)

rich seal
#

Nice! I'm not surprised. I'm a little behind in cloud stuff, but have my eye on these certs!

near prairie
rich seal
#

Thanks for that perspective. I’m definitely kind of a noob when it comes to cloud stuff, but I’ve been around the block with traditional IT stuff.

#

I’ve been putting it off for a while now, but I have come to the realization that I can’t avoid it forever

near prairie
rich seal
#

I really appreciate it.

prisma raven
#

🔍 I've built an improved set of queries for BloodHound Community Edition focused on on-prem -> Entra/Azure.

Quickly match compromised onprem users with Azure/Entra identities for privilege escalation or lateral movement.

Owned objects are always our top priority when querying.

#

Modified queries for bloodhound CE in order to easy query for Owned objects on Onprem-AD -> Entra/Azure, as the default ones doesn't filter owned objects, which are the most interesting ones most of the times.

hardy gorge
#

Hi admin, with mandatory enforcement on MFA on Azure logins, does that affects the existing labs in Azure apprantice/expert courses ?

hardy gorge
modest elbow
idle zenith
#

is the training site down ?
Trying it for few minutes now.

modest elbow
idle zenith
#

yep its working now thanks 🙂

glacial kelp
smoky blaze
#

I noticed the AzRTE course curriculum doesn’t really cover concepts like lateral movement, persistence, or evasion that are usually tied to red teaming. Just curious, is there a reason for that given the cert is called Azure Red Team Expert?

hasty sapphire
modest elbow
# smoky blaze I noticed the AzRTE course curriculum doesn’t really cover concepts like lateral...

The syllabus indicates from a very high level the services that are going to be used in the course.
Inside those services you will learn how they work and then how to (ab)use them (privesc, post exploitation & lateral movement and persistence).
Then we have specific blackbox sections to talk about other common red team attacks (among them AD <--> EntraID pivoting and in the final section we talk about azure defense services and how to try to bypass them
So I think the certification covers all those things

smoky blaze
modest elbow
# smoky blaze Gotcha. Thanks for the clarification.

Np! If you need more info feel free to ask here or check also https://www.youtube.com/watch?v=CBQl7Kvlu-U

Presenting the new HackTricks training Azure Red Team Expert (htAzRTE) certification by HackTricks Training.
The most complete certification to learn about hacking in Azure and Entra ID.

Check more info in https://training.hacktricks.xyz/courses/azrte

▶ Play video
sudden trail
#

Hey . is there any admin for question ?

#

regarding the course ARTE

near prairie
#

Sure

manic solar
#

Is the training site down by any chance?

near prairie
manic solar
near prairie
manic solar
#

Last time I visited the training site was 3 weeks ago, and it was working fine for me

glacial kelp
#

We don't have any geolocation restrictions

#

Is there any kind of content filtering on your side like from a work related proxy or something?

modest elbow
manic solar
modest elbow
#

We dont have any restrictions as mentioned previously

#

Maybe is your ISP restricting the address

hasty sapphire
#

Maybe try adding the IP of the site to your /etc/hosts manually and see if you can visit it

manic solar
#

For some reason, all of a sudden it’s working now

#

Thank you all

manic solar
#

Vouchers expire after a year from the date of purchase, correct?

near prairie
hasty sapphire
#

@near prairie @modest elbow ^ also posted in several other channels

grand vale
#

Who could i speak with regarding purchasing a bundle for a team of 6-8 for GCP/AWS trainings?

modest elbow
trim sparrow
#

Are you guys moving to a new domain for the training website? Stumbled upon this on google, and thought the domain looked different than normal.
https://hacktricks-training.com/

Registered 3 days ago. Just wanna make sure noone is trying to create a phishing site

near prairie
#

We will make an announcement when its ready!

trim sparrow
#

Alright perfect, it's looking good!

lethal zenith
#

Can I buy now and learn later?

#

I saw huge discount and I kinda wanna ... buy it

near prairie
lethal zenith
#

alright thank you, Imma think hard about it

near prairie
modest elbow
#

@everyone Black Friday Month is here! — and so are our biggest HackTricks Training discounts of the year:
• 20% OFF all Courses
• 15% OFF Lab Extensions and Exam Retake Vouchers
• Additional 10% OFF all Bundles
→ That means 25% for 2 courses and 35% for 3 courses.

One discount code per transaction. Offers valid from Nov 1 to Nov 30 .

Discounts already applied at https://training.hacktricks.xyz/

stable yarrow
#

Hey @near prairie is the whitebox for the apprentice course the same as the whitebox for the expert course?

near prairie
hasty sapphire
#

Thank you Hacktricks Team for such an awesome experience, really appreciate all of the help and support for the community and staff. The effort put into the labs is fantastic. A lot of valuable course content and practical examples of how to abuse mis-configurations.

Thank you @near prairie especially for always assisting with my bombardment of tickets.

modest elbow
near prairie
dim verge
#

I'd like to ask if the exam requires a passport and webcam like OSCP?

near prairie
dim verge
#

Thanks🫡

near prairie
candid pike
#

Greetings house , please who know how to do redirecting of domain for long lasting

barren viper
#

Hello, if I completed the ARTA course and want to take the ARTE course, will the labs I completed at ARTA count or do I start from scratch?

arctic saddle
#

@barren viper Hi, if you already completed ARTA you will have no problem starting from the beginning. In fact, that would be my advise so you can see if there is any additional information on the topics that u saw in ARTA course. If you ask for the flag progress im not sure maybe just someone else who has your prev situation or a moderator could answer if the ARTA flag progress counts for ARTE

modest elbow
barren viper
cosmic aspen
#

Hi! My voucher for ARTE course is expiring 14.11, but I had a plan to activate it on 17th of November. How can I do it?

near prairie
cosmic aspen
rough idol
#

i have done all of my walkthrough , and got stuck and i want to learn the exact way.. and not to waste time.. can i somehow get more walkthroughs?

near prairie
chrome wadi
#

Stupid question, I've booted my lab up in the ARTA course and have no idea how to access it

near prairie
#

Add the discord handle to the profile area in hacktricks training

near prairie
chrome wadi
near prairie
chrome wadi
high cloud
#

Hi! I am currently preparing for my ARTE exam and thought about getting the other two expert courses too. When reading through the FAQ, I noticed, that the access to the course content after validating the voucher has been limited to just one year? When did this happen? 🙁

near prairie
prisma raven
#

What do you think guys? 🤣

#

A lot of hate on AWS lately

jade ravine
#

well I can definitely agree that you don't need to make MVP complex, but you can still use public cloud like AWS or GCP as simple VPS (also you can get the small boxes for free instead paying the 5€ for VPS somewhere else) - IMO if you have more micro services than paid users you are doing it wrong!

modest elbow
#

Tbh I remember that when I started with AWS I found it pretty complicated to understand. Then I realized that thanks to this AWS is not as vulnerable by default as other clouds (although I agree that several AWS services could be simplified a lot without loosing any features or maing them more vulnerable)

languid wasp
#

AWS is easy to take down if you know where the first data center is….and some tricks from an old hat from the hatter

#

Hopefully they learned their lesson….but I doubt it

#

DNS and cloudflare have been taking some hits lately, they think A.I will do all the work for them when really they should be looking for people who actually know what the hell they are doing

halcyon linden
#

Hello, I would like to start the AWS Red team expert course, I have.some understanding of cloud computing, I.was wondering if I should take an AWS course before starting this course?

hasty sapphire
high fossil
#

yeah, personally I don't love the aws certs (back when I took them in like ~2018). Not very hands on or technical up to the solutions architect/security specialty level. Felt more like sales training than education haha. I'm maybe 75-80% done with the course, and i think you'd get more value from ARTE + experimenting on your own if your goal is any security discipline.

modest elbow
#

@everyone this is the last week of the Black Friday discounts! Check them in training.hacktricks.xyz

hardy gorge
#

@modest elbow Hi there, after I purchase the voucher, when will it be expired, if I do not claim it ?

I am planning to buy bundle but i cannot do all at 1 go. I can only do in sequential when time permits.

near prairie
hardy gorge
#

Oh that is awesome!

#

Appreciate it ! 2 years should be enough.

tiny perch
#

Hi @near prairie 24 I can't extend my lab time for some reason.

near prairie
near prairie
tiny perch
prime shale
#

Hey, does anyone know the code to avail black friday discount?

#

Thanks in advance

olive canopy
prime shale
prime shale
#

Anyway, thank you !

near prairie
odd fractal
#

@near prairie Sir sorry for ping, but just a question. Let's imagine the situation.
I have GCP cloud and have service account credentials, i've listed organizations and projects and in one project i've been found service account over which i have roles/iam.serviceAccountTokenCreator . Then the service account i can impersonate has permissions on the function

  • cloudfunctions.functions.call
  • cloudfunctions.functions.get
  • cloudfunctions.functions.list

I described the function and find where GCP stored the zip archive with function's source code, but i can't list bucket policies using
gcloud storage buckets get-iam-policy gs://bucket_name

is it correct that i have to try list or download the zip archieve with the function's source code (from both account) to understand what the function does and the invoke it if it will be usefull

near prairie
near prairie
odd fractal
#

and is it the good way to find who has it, cause in gcp as i know u have to list everything step by step (and it takes a bit longer than in AWS)
cause i verified it using
gcloud storage objects describe gs://bucketame/function.zip
and if i see the output so i have storage.objects.get permission

near prairie
near prairie
#

@everyone All the videos in the Hacktricks Training courses, now include subtitles in multiple languages. These captions include the languages showed in the screenshot and many more!

Enjoy the content!!

weak gazelle
#

In blackbox lab 1, I reached the point where ||I have the user blackbox-lab-1-user-2, added that user to the group, but bruteforcing the permissions gives the exact same permissions I had before adding to the group. (I bruteforced with both bf-aws-permissions and the simulate scripts). Did I miss the first flag at some point?||

near prairie
weak gazelle
wicked cradle
#

Hi, I need to open a support ticket. I’m having a problem with ARTE Labs. Where can I do that?

echo plaza
modest elbow
echo plaza
#

Ok thank you just needed a sanity check haha

stiff wharf
#

What's the current status of the Kubernetes training.hacktricks.xyz? Did I have a fever-dream or miss something about that, I believe to have read, there would soon be a Kubernetes training available.

stiff wharf
main oak
modest elbow
fallow galleon
#

Is there any role for CRTE?

near prairie
fallow galleon
#

Nickname color is role? red is CRTE?

near prairie
#

Yes, if you click on your own name you can see the crte-certified label

fallow galleon
#

Okay!! I checked !! Thank you!!

placid mason
#

hey guys

celest saffron
#

Hi

#

Hallo

placid mason
#

does anyone help me to build a logger software
literally i m facing so many issues

modest elbow
#

@everyone
Do you want to improve your Cloud, CI/CD & Kubernetes security knowledge?
We are delivering some trainings soon!

🇬🇧 Check the 2 days online training about Cloud, K8s & CI/CD: https://lnkd.in/eib9K72y
🇪🇸 Check our on-site trainings in Spanish at RootedCON:

pastel totem
#

@modest elbow what about k8s ceet from hacktricks ? 😁

modest elbow
hushed zenith
halcyon linden
#

I'm currently studying azure red team expert. The part on apps registration, service principals, managed identities had my head spinning, lol

modest elbow
hardy gorge
#

@modest elbow <@&1128840997581889586> hi there, i am currently doing azure apprantice course and 30 days lab access is expiring on 8 feb. I am half-way through labs. I will be busy from mid-feb till end of march. So, i want to continue Azure apprantice course in April.

In April, then i plan to buy 15 days lab extension & continue the course.

Will it be ok, if i only buy extension in April & continue my apprantice labs ?

near prairie
halcyon linden
#

I have issue understanding tokens in the azure course, It says that refresh tokens are bound to an audience but later when I read the microsft documentation I have " Refresh tokens are bound to a combination of user and client, but aren't tied to a resource or tenant." so I'm genuily confused (I'm not experienced in Azure, it feels really hard)

modest elbow
halcyon linden
#

I'm genuily confused, (I reached the part on FOCI), in the intro module, I thought that we authenticated with az cli, entraID was providing a refresh token, which later could be used to get access token for other APIS (like storage, arm), I feel dumb, I don't really understand Azure

modest elbow
# halcyon linden I'm genuily confused, (I reached the part on FOCI), in the intro module, I thou...

Tokens in Azure are very confusing no worries. My recommendation for you to understand them would be to play with them.

For example in https://cloud.hacktricks.wiki/en/pentesting-cloud/azure-security/az-basic-information/az-tokens-and-public-applications.html#foci-tokens-privilege-escalation you have a guided tutorial on how to login to get refresh token belonging to a FOCI application that allows to generate other tokens for other APP IDs.

Interestingly this tutorial used to use the App ID of the Azure CLI, but just some weeks ago Microsoft removed that App ID from the FOCI apps. So you can follow the tutorial and see how with a FOCI app you can generate tokens for other apps and the repeat it with the app id "04b07795-8ddb-461a-bbee-02f9e1bf7b46" and se hoe the last step doesn't work (It doesn't allow to generate tokens for other client IDs).

Moreover, the refresh tokens are also generated for other "aud"s, however, as you mentioned, the refresh tokens are not bounded to them. Which unfortunately doesn't mean that any refresh token can generate tokens for any "aud"s. Depending on the "app ID" the token will be able to generate tokens fro different "aud"s. And the same happens with scopes (permissions) also!
"Hidden" in the AzureAppsSweep, you can find https://github.com/carlospolop/AzureAppsSweep/tree/main/GraphAppScopes which is the brute-force I did some months ago to find all the possible combinations based on all the APP IDs I found.

GitHub

Contribute to carlospolop/AzureAppsSweep development by creating an account on GitHub.

final bane
#

Hi, I'm currently taking the AWS Red Team Expert exam, but I suddenly can't log in to https://training.hacktricks.xyz/signin. I'm getting a "Sign in failed with unknown error". Could you please help me with this?

small pewter
#

Yep I'm in the same boat, I was just about to submit a flag too ☠️

near prairie
#

Should be fine some time ago

glacial kelp
#

Doing some maintenance now sorry for the inconvenience

mint latch
#

Please let us know here when the maintenance is finished

near prairie
mint latch
neon bane
glacial kelp
#

Working on another fix now so the old website also works

#

Both sites are back and looking healthy

rich gate
#

Hey guys anyone having trouble with the lab deployment on section 2.8 Azure App Services?
I tried deploying the labs multiple times and I get an error "Error provisioning lesson labs".
Do i have email the hacktricks team?

hasty sapphire
rich gate
modest elbow
near prairie
rich gate
rich gate
pastel totem