#hacktricks

816 messages · Page 1 of 1 (latest)

charred zodiac
abstract vector
#

Hi every one

#

i am new joiner in this server

pseudo yew
rigid crown
#

I found a very small error

placid fjord
#

Exfiltration of data via CSV injection over DNS without warning prompt and without requiring user to click a link, seems to only be referenced in off-hand remark in this albinowax talk, nowhere else on the internet at all, https://www.youtube.com/watch?v=skbKjO8ahCI&t=1284s

Abstract :

Do you ever wonder about the vulnerabilities you've missed? Why didn't they show themselves - and will they be discovered by somebody else later?

Certain vulnerabilities have a knack for evading auditors. As we enter the age of continuous security, knowing how to unearth these is becoming an essential skill. This is...

▶ Play video
#

I played with it, it works still

pearl horizon
fluid thunder
pearl horizon
pastel glen
shrewd harbor
#

Hi guys, can I use legion tool in OSCP exam?

clear scarab
fluid thunder
shrewd harbor
clear scarab
#

xd

#

although it's an automatic tool and the main point of the OSCP it's the manual exploitation

shrewd harbor
clear scarab
#

Xd

#

Feel free to ask men xd

placid fjord
pastel glen
shrewd harbor
placid fjord
#

i assume whoever is talking about legion here means this

shrewd harbor
#

thanks friend

gilded vale
#

@fluid thunder Sorry to ping you, I didn’t find a better way to reach you…
I published yesterday a tool for post exploitation during pentest
it automates computers and users extraction from ldap and credentials extraction through smbclient on all computers for all users and then decryption of all blobs with the domain controller private key 😉
the tool is named Hekatomb and the GitHub repo is here : https://github.com/Processus-Thief/HEKATOMB
A friend suggested me to contact you to add the tool in DPAPI section of hacktricks (https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords)
The tool uses the impacket syntax to works and is able to automatically extract domain controller private key by himself
You can pm me for more infos if you want 😉

GitHub

Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain ba...

#

Instead of other tool like DonPAPI, it is based on ldap computers and it resolves ip address and didn’t just take ip range in parameter
In that way you can reach all subnets even if you didn’t know them because it resolves it

fluid thunder
gilded vale
marble linden
#

yo

#

does anyone know how to bypass payhip paymenyt

alpine swan
#

I'm trying to wrap my head around linux capabilities. Would this mean that I should just be able to chown files?

teal plank
#

Does anyone know a good free service where I can use a VM with a GUI with Windows 11 or a Linux distro. I’m also looking for a way I could make a VM locally on an iPad 9th gen (A13 bionic version) not rooted with latest IOS. I have iSH AOK installed .

#

Basically looking for a free method to utilize a VM with an OS of my choice on an iPad.

fluid thunder
fluid thunder
severe brook
#

hey, is there any wordpress version in which there was auth bypass on login page?

little marlin
#

Is there a "physical release" of the book?

fluid thunder
little marlin
#

Thanks anyway for all the amazing effort you put into it. It's amazing and helps me everyday!

sage forge
winter pivot
burnt niche
#

Hi Calros and thanks for such a nice book. Do you have any update for advanced IPS/IDS evasion techniques?

fluid thunder
burnt niche
#

Ok

glossy zodiac
#

مرحبا😀

manic sand
#

WTB Service (bypass pc limit )

zinc vine
#

The http request smuggling page specifies rfc 2161, instead of rfc 2616 ^^

fallow coral
#

hi, I'm do some exercise on htb. Now I discovery a smb server on linux, and I already have username and password. what should i do can get shell?

stoic citrus
#

how do i byapps payment

#

bypass

#

i dont underestand

fluid thunder
#

First cloud hacking twitch session scheduled next Wednesday (7th) at 6.30pm(CET)!

I will be explaining hacking techniques in twitch Wednesdays at 5.30pm(UTC), 6.30pm(CET), 12.30(EST), 11pm(IST).
If you want to learn about hacking cloud, kubernetes, web and resolve interesting CTFs feel free to follow!

Twitch: https://lnkd.in/d2bYdUNS
Youtube: https://lnkd.in/damJC2JX
Twitter: https://lnkd.in/dbZ9s8t4

woeful yoke
#

hey, guy, i want arp spoof someone victim, and intercept all http traffic in my windows and specific network adapter,
Who can give me some suggestions and how to achieve it

versed cosmos
#

Hi there! If you're interested in learning about reverse engineering and assembly, you should definitely check out my blog.
https://yrncollo.github.io/posts/Reverse_elf/
I cover a variety of topics related to these fields, including disassembly techniques, debugging, and more. Whether you're a beginner or an experienced engineer, you'll find something of value on my blog. So if you're looking to expand your knowledge and skills in reverse engineering and assembly, be sure to give my blog a visit! Finally if you have a question or any clarification you can leave a comment on the blog.

Thanks 😉

fluid thunder
worn lotus
fluid thunder
rose lion
#

How to download PDF version for offline viewing

fluid thunder
#

Hey guys, participate to get some free tickets to rootedcon and hacktricks track in rootedcon!
https://twitter.com/carlospolopm/status/1617854356782747652

Tickets are for sale for #RootedCON2023 (Madrid, 9-11th March)!
The awesome @criptored and #HackTricks tracks are giving away a pack of 2 tickets to attend it.
Retweet and/or comment to participate!
(Do both for double opportunity ;)

Winner will be announced next Tuesday

fluid thunder
#

Hey guys! We are looking for companies to sponsor HackTricks track at RootedCon Madrid. Among other things sponsors will get tickets for the Con and the option to give a talk. Contact me if you know companies taht could be interested!

tawny parcel
# rose lion How to download PDF version for offline viewing

https://github.com/sponsors/carlospolop -> Where can I find the Hacktricks PDF?
In this page there is a Tier for 18$ that will give you access to the repo with the HackTricks PDF. I try to update the PDF once a month and the sponsorship will be charged every month.
However, if you only want to buy it one time, you can pay that tier, download it, and cancel the subscription.

worn lotus
#

when the user is deleted isn there a way to remove their posts too? lots of spam

fluid thunder
worn lotus
#

ouch

#

@fluid thunder when you ban then you can chose to delete all their posts mate:

but has to be done at the time of banning.

#

"delete message history"

keen flower
#

got some cc's in this week

#

want to make a -3000 $

#

but couldn't do that bcs of this fucking 2fa shit

#

if someone helps i'll gave him a 800$ cash or paypal etc

thorn saffron
#

Hey wanna learn from the beginning hack tricks, is anyone who can help me

weak spindle
#

🤣

buoyant pasture
#

New to discord and hacks. Want to know how to copy a webpage to fake real one.

wild narwhal
#

There's a few wifi hacks that do that, too

#

I think Wifi Pumpkin had that feature. Probably a few more

buoyant pasture
#

I did so much research on Blackeye until I realized it was not a thing anymore. Now I’m going down the httrack rabbit hole. I’m scared to put anything on my computer. Don’t know what I’m doing yet, but want to learn, and so trying. I’m scared to execute anything in fear of doing anything wrong.

wild narwhal
#

be afraid... be very afraid lol

bleak vale
#

Hello, is it possible to contact an admin of hacktricks ? I have a question to ask

manic ember
#

Hi, why don't you ask here ?

still anchor
still anchor
lyric ginkgo
#

@fluid thunder I am a native Chinese speaker and I would like to add a CN branch to the repo of hacktricks.
I have submitted a pull request, but I am not sure if I have performed the correct operation

buoyant pasture
still anchor
wild narwhal
#

As well as port blocks.

fluid thunder
reef jackal
#

@fluid thunder Hello, I found a small error on the page

#

Is this sentence correct? If you are on an old version of Werkzeug, try changing the hashing algorithm to md5 instead of md5.

fluid thunder
#

Thanks, I'll change it!

brazen lodge
#

@fluid thunder can you please update the pdf in the github private repo? I sponsored but the pdf is from 7 months ago, I presume it is not up to date 🙂

golden sparrow
#

@brazen lodge

fluid thunder
brazen lodge
#

Thank you!

fluid thunder
# brazen lodge Thank you!

Updated, sorry for the delay! Apart from updating both hacktricks I have been very busy configuring everything to have automatic translation to other languages to make hacktricks more accessible

brazen lodge
#

Awesome, thanks for the amazing work

frail bolt
frail bolt
lyric ginkgo
#

@fluid thunderI recently came across the new course that you've announced, titled "AWS Red Team Expert," and I am profoundly interested. With some time spent working in the cyber security environment, I am constantly searching for ways to enhance my skills specifically in red teaming.

Additionally, I am curious if there are any discounted prices for participants who engage at the early stage of course introduction. If such is the case, I would certainly appreciate more information on this aspect.

fluid thunder
lyric ginkgo
harsh nimbus
#

hi @fluid thunder, recently I made what I think a very helpful merge request for HackTricks regarding MSSQL.
When you can, please take a look 🙂

golden sparrow
#

hello

alpine swan
#

Anyone know of a good way to automatically strings multiple binaries looking for sensitive info?

alpine swan
#

Yeah. I'm looking to see if there's an automated way to do stringsing basically

whole escarp
#

hi @fluid thunder, just wanted to download the Hacktricks PDF after starting the sponsorship via GitHub. However, it says that the LFS bandwidth quota is over. Could you verify if you can get LFS data pack and preferably update the PDF file? 🙂

fluid thunder
whole escarp
#

thanks for your fast response 🙂 it works now

sudden patio
#

Is there any message for the arte course ?

fluid thunder
scenic swan
#

@fluid thunder hey I was wondering when I buy the voucher, will the lab launch directly or will I have access to the courses first and then I can activate the lab whenever I want?

#

I'd like to take the voucher but I'm not available right now to start certification.

#

I think I got my answer.

fluid thunder
young coral
#

Bam! Been waiting for this one to drop! Just got it.

#

No specific channel for the course though?

fluid thunder
young coral
scenic swan
#

@fluid thunder is this intended ?

fluid thunder
arctic gorge
#

Hii Guys! If you can upload any files to Minio, any chances we can get web shell on that? any feedback would be appreciated.

covert spindle
rose mesa
#

@fluid thunder

fluid thunder
rose mesa
rose mesa
#

@fluid thunder

reef rivet
#

Came here to ask that I see many providing AWS Pentesting training but not much or none for Azure. Why is it so, In Azure default settings are more secure and less chance of misconfiguration or is there any other reason?

fluid thunder
fluid thunder
#

Hi @everyone ! Just to let you know the early bird discount of HackTricks Training ARTE (AWS Red Team Expert) will be ending the 9th of Feb!
If you are interested in doing the certification and learn AWS hacking from 0 to hero, I would suggest you to buy the voucher before that day as you will be able to redeem it within a year!
More info about the course in https://training.hacktricks.xyz/

thorny gate
#

You just launched but it is written it is "recognized by thousands of security professionals" ??!!

#

Did they have beta access to it? Do you have some names?

fluid thunder
thorny gate
#

But it is written "our certifications, ..., are recognized..." Not that hacktricks is used by them.

#

For the moment your certification (just one so not certificationS) is unknown by thousands of security professionnals, and hacktricks cloud is very new and not a reference iirc

fluid thunder
#

Just HackTricks Cloud is used by thousands of people every day (and personally I don't know a better reference for cloud hacking), and it was created by the same team as HackTricks, used by tens of thousands of people every day.
We do give other courses and certifications in person, feel free to join us in the next one at RootedCON Madrid (https://www.rootedcon.com/rooted2024-en/#trainings) and we will soon release more in training.hacktricks.xyz!
In any case I don't feel like this conversation will help people on this channel as you just criticised the brand. So feel free to continue this conversation in private to not fill this channel with this.

chrome mantle
chrome mantle
#

and those who don't, will use soon

#

because I'd say 90% of the offensive security space has used or uses HackTricks on a daily basis

thorny gate
chrome mantle
#

It's pretty not cool to just call it a "CTF" tool. A lot of work has been put into making the website and I use it for reference daily on my job. Been in the industry for 8 years.

#

I have most things memorized by now sure, but the website gets updated so often with new content that it's always great to check out and use, for live engagements, as well as CTFs

fluid thunder
#

Thanks for your kind words @chrome mantle !
In any case I would ike to ask you guys to stop here this conversacion as the goal of this channel should be to sahre hacking tricks!

thorny gate
# chrome mantle It's pretty not cool to just call it a "CTF" tool. A lot of work has been put in...

Nobody called it a CTF took lmao people like to make shortcut. I use it too in my job but we all know it took others' people articles and put it in one place, which is great (when it is sourced). But come on ARTE cert isnt recognized by thousands of professionnals... Hacktricks is known by thousands OK but their cert isnt period. And im not against them, i did the same when tcm made his marketing lies etc etc

#

I like how we pass from the cert is recognized by thousands of people for marketing to hacktricks is used by thousands of pro xD

thorny gate
#

Lol you are the one who continued it xD

#

And when proved to be wrong you listen it lmao

chrome mantle
#

Is AWS Gamelift used by many orgs? I mean, it's a gamedev platform afaik, so it's likely already a small marketplace for usage, but I saw the hacktricks page on it, so it makes me wonder if anyone has actually seen it before in a real engagement.

chrome mantle
#

Probably just some research someone has done on the service or something.

#

Still cool though.

#

I feel like people are not very likely to use AWS of all things for game development lol.

woeful ferry
#

Hello everyone is anyone an AD pentester?

chrome mantle
#

Me @woeful ferry

#

your name should be @extrasids

fluid thunder
#

This channel is dedicated to the in-depth exploration and discussion of the latest hacking news, as well as the exploration of cutting-edge hacking techniques. For other hacktricks-related topics, please review https://book.hacktricks.xyz/welcome/hacktricks-values-and-faq and contact an administrator for approval.

vale python
#

Hi Team

#

I am interested in purchasing the ART exam voucher, I would like to know if I can start the course next month because in the message they show they say that it is activated next year, I understand that it should be activated in the year 2025. So I need to buy the course having but to take it in 2024.

outer forge
fleet vessel
#

Question for ARTE lab secretsmanager:PutResourcePolicy:

aws  --profile secretmanager-lab1 secretsmanager put-resource-policy --secret-id flag_secretsmanager_lab_1-omPxUO --resource-policy file://exploit_policy.json
An error occurred (AccessDeniedException) when calling the PutResourcePolicy operation: User: arn:aws:iam::X:user/secretsmanager-lab-1-start-point is not authorized to perform: secretsmanager:PutResourcePolicy on resource: flag_secretsmanager_lab_1-omPxUO because no identity-based policy allows the secretsmanager:PutResourcePolicy action

Anyone can help please ? 🙂

fleet vessel
#

Solved! Thanks @digital cliff for the backup, flag_secretsmanager_lab_1 instead of flag_secretsmanager_lab_1-omPxUO.

sterile latch
#

Put in my PR 🙂

silk canyon
#

Hi, I need some help with kms:PutKeyPolicy lab🙏

outer forge
wanton thunder
#

Questions for codebuild lab2.

#

When I build the image. It always return the error message: {
"statusCode": "SINGLE_BUILD_CONTAINER_DEAD",
"message": "Build container found dead before completing the build. Build container died because it was out of memory, or the Docker image is not supported"
}

wanton thunder
#

@fluid thunder

outer forge
ebon salmon
#

can someone help with disabling 2fa on compromised account, or with the reset password process (lost 2fa)

autumn ledge
#

hello on what channel should i ask questions?

civic berry
#

Friends, good evening! Who can help and sort out 2.2 STS - Security Token Service: Github Actions?

fluid thunder
#

Questions about the certifications in #arte-general please
If you dont have access to the channel make sure to put your discord handle in your user settings in the training platform

hexed lotus
#

I need some help, which is that cloudflare security

strong steppe
fluid thunder
strong steppe
chrome mantle
#

Hey guys! Anyone interested in joining a CTF team? Looking for web, pwn and crypto guys.

eternal gazelle
#

Hello. Can you explain me how to steal an account on Roblox

#

Because I was scammed

strong steppe
# eternal gazelle Because I was scammed

just because someone scammed you doesn't mean you can legally take action against them. If you got scammed out of your money reach out to your bank, if your account was compromised reach out to customer service

burnt berry
#

lol

hexed lotus
#

Yoo

tender thistle
#

Hello -
1521 oracle listener hacktricks page has a dead link.

"in order to user MSF oracle modules you need to install some dependencies: Installation"

#

that link goes to a dead github page

sinful briar
restive tree
#

Hi everyone

#

Has anyone been successful in disabling SSL Pinning and capturing traffic with burpsuite for an app that has the latest flutter framework?

I've tried frida/objection and reflutter but no luck with either

restive tree
#

Also tried SSL killswitch V3 with no luck

chrome mantle
#

flutter can be a pain, if that doesn't work, I suggest just hooking all functions and writing your own fridascript

restive tree
chrome mantle
#

no problem man

#

yeah if that fails, use the classdump and obj-c hooks to find out where the SSL pinning is occurring, and then write your own frida script.

#

writing frida hooks is pretty easy even if you don't know JS (which I don't)

#

just take someone else's template and change the function names and return values.

restive tree
#

My problem is that objection seems to hook and be all good until you try to do something. If I disable ssl pinning it says all good but functionally it doesn't work and if I try to run any other objection functions it just throws errors. In some ways it makes me feel like I need to be running it in a conda or venv environment

#

But I wouldn't know which version

chrome mantle
#

I'm pretty lucky in the fact that I use Corellium, which is basically running up-to-date always, so I need not worry about dependency bs and versioning issues.

dull lichen
#

I have problem on EC2 Labs, i configure aws:

aws iam list-users
{
"Users": [
{
"Path": "/",
"UserName": "ec2-......
[SNIP]
......

everything is good, but when i do:

aws ec2 describe-instances

Could not connect to the endpoint URL: "https://ec2.us-east1.amazonaws.com/"

What I'm missing? :/

outer forge
frigid slate
#

Hello, my name is Jonathan and I'm a research engineer working at Apart Research (apartresearch.com). We are doing research on cybersecurity evaluations, especially interested in whether language models can pass qualifications related to pentesting. We are doing this because it seems important to keep a close eye on cybersecurity capabilities, and if a LM could pass the hacktricks course, it would be very interesting. Is there anyone that I can ask about researcher access to the course?

void skiff
#

How do i access to the ARTE channel? May required some assistance =/

fluid thunder
void skiff
void skiff
#

It seems to be resolved thanks 🙂

sleek lily
#

Hi everyone, when purchasing ARTE course, do they typically provide an invoice? I need one for company reimbursement. Thanks!

outer forge
outer forge
chrome mantle
glossy jetty
#

Hi guys

chrome mantle
#

hola!

outer forge
chrome mantle
#

Thoughts?

#

I was thinking of giving them a try after I finish GRTE

outer forge
#

They are good but pretty basic... Probabaly there are some limitations to keep things easy to set up. Hopefully in the future we make a cicd course as it is one of my passions

chrome mantle
#

I would love to learn it as I see it as a possible attack vector during red team operations I perform quite regularly but my familiarity with the attacks is not strong enough to feel comfortable making changes to a development pipeline without risking damaging business operations.

#

I know the older stuff like the Jenkins and TeamCity attacks, but not the more like generic attacks against CI/CD platforms themselves.

lucid bronze
#

Does anyone know if an iframe adds cookies to the request? I tried it, and it didn't seem like it did. However, I've seen people using clickjacking techniques, which presumably requires the user to be logged in within the iframe. Can someone explain this?

finite compass
#

Hi all, I’d like to try the GRTE course, but I’m not finding enough info in the wild. For the ones who are currently doing it: without spoiler anything, could you please give some feedback? Dm me if you prefer, thanks in advance.

Btw thanks for all the effort to the Hacktricks team❤️

chrome mantle
#

Carlos goes into such depth, starting with the fundamentals of GCP architecture so that before you start actually attacking stuff, you have a firm grasp as to the organizational structure of a GCP environment, contrary to many other platforms or trainings, which either expect you to already know such content, or just skip over it completely.

#

Then, the labs, designed to show you how to attack the environment are well written, realistic and applicable in the real world. One problem I have with other cloud content providers is that they just show you what I call “tricks”.

#

They’re cool, but impractical or just completely useless.

#

As I’m sure you know, HackTricks is a staple of the cyber community and is persistently one of my open tabs at work as a reference all the time due to its sheer detail, and the course follows the same suit.

finite compass
chrome mantle
#

If you have any more specific questions, I can answer them too, but if you want to learn GCP hacking, it’s like literally the only option in my opinion 😂

finite compass
#

Thanksa lot for the detailed feedback, I’ll buy the voucher and take the course later this year.

finite compass
chrome mantle
#

SANS cloud course costs 8k and is terrible lmao, this costs less than the OSCP and will prep you for a real world GCP pentesting job

#

Yeah I type a lot haha

#

Feel free to DM if you have any specific questions!

chrome mantle
#

I could show you one of the labs or something so you know what you’re getting into

finite compass
finite compass
chrome mantle
#

Yeah, I think I could get permission. There are over 50 individual labs, so me showing you one probably wouldn’t be a huge deal haha

#

Anyways, I’m sure some other guys here would say pretty much same as me, I know @umbral kayak would agree with what I’m saying

finite compass
chrome mantle
umbral kayak
#

You won’t be finding this quality of course anywhere else

umbral kayak
#

and if you like it course ARTE one completed

#

you get a discount voucher so it´s not a big difference

finite compass
#

Thanks for the suggestion, but GCP covers most of the market within my customer base :/

finite compass
chrome mantle
#

I’m just saying my federal clients are primarily in GCP or AWS GovCloud, so I get it

finite compass
chrome mantle
#

It’s a relatively equal split from what I hear.

#

I think it depends on which branch of govt and what country

simple thunder
#

Gov worker here - we use AWS. Thankfully.

chrome mantle
simple thunder
heavy dust
#

Hi, I am enrolled in ARTE course and want to add to its discord channel but my handle is not getting accepted in my profile...

chrome mantle
#

Message @outer forge

outer forge
indigo thicket
#

Hyyy

#

Instagram I'd hack

#

Plz give me hack

burnt berry
#

Go away

sharp hinge
#

How to start? That is the question. I already threw the GPS in the trash! Second step, what do I have to do with the battery and the controller? In order to be able to use it?

dry grove
#

Guys I need help pls any one can help me, my friend have Al lots of bad reviews in his business page he got attacked from some one now for 6months and his looking to remove them

chrome mantle
#

Not the right place to ask my man…

dry grove
#

Sorry

void yarrow
#

Hi, I am enrolled in ARTE course and want to add to its discord channel.

void yarrow
#

tried addding handle and discord id in hacktricks training website but there is an error

#

Error adding user to discord role. Ensure you are using the correct handle

fluid thunder
umbral kayak
#

He is already in

fluid thunder
#

Thanks!

umbral kayak
#

🔥

graceful cliff
#

Same issue as koolacac, how do I gain access to the ARTE channel

umbral kayak
#

And configure your discord ID

graceful cliff
verbal sorrel
#

hello

simple rover
#

hi

verbal sorrel
#

whatsup

crude wadi
#

Do you still see it??

umbral kayak
umbral kayak
#

So check the rest of the channels

crude wadi
#

On my way

#

Thanks!!

umbral kayak
#

🙌🙌🔥🤣

#

Pinned last 3

#

im still able to se some don´t know why

#

but if you deleted them I guess they will disappear

crude wadi
#

Really?? I removed every single one🤔

umbral kayak
#

maybe DC is crazy rn

#

now I only see the general channel one

crude wadi
#

Done

#

Thanks again :)))

umbral kayak
#

I think when banning a user you have an option for deleting all his messages.

#

maybe is usefull next time

#

😎

frosty prairie
#

hi

#

who is 2FA cracker

#

please

burnt berry
#

Do these people have any idea what kinda servers they're on before asking stupid questions?

crude wadi
#

Thanks!!

stone rapids
#

i am relatively new to CTF and cyber security.
I just played KOTH in THM and people seem to root the machine pretty quickly. while i am struggling to get a foothold.

is it just pure skill and practice or are there any tools/scripts? 🤔

proper epoch
# stone rapids i am relatively new to CTF and cyber security. I just played KOTH in THM and pe...

Hi Wizard, i'm not and expert but I can suggest an answer to your question.

It is normal that you have difficulties in the foothold phase. It is the phase where you don't have any knowledge of the machine, the black box phase, as I like to call it.

Imagine how difficult it is to get into a black box where you don't see any entrance, no lock that can be opened. You can try to hit it with a hammer, kick it, but you will not get any result.

This is the same, there are 200 million tools that you can use in the foothold phase, but if you apply them without knowledge it will be useless. As it is well known “Enumeration is the key”. You have to try to enumerate everything: technology that is being implemented, vulnerable versions of that technology, everything you can think of, until a moment will come when you will discover a possible backdoor to get inside the box.

It is normal that at the beginning you will be more lost, as always experience is wise and the more challenges you face the more you will be able to find vulnerabilities that can be exploited.

stone rapids
#

thank you @proper epoch for the clarification.
I was really puzzled how fast some players captured the king. 😄
now i know. thanks again. 🙂

proper epoch
stone rapids
#

haha...can't remember the last day I went to the gym, but keep paying the subscription. 😄 😄

thin crater
#

@fluid thunder yooo, are you the main person who manages the book?

#
quick wave
#

hello, has anyone managed to compile winpeas from the solution? The executable generated raises an error on execution about missing regexes.yml, I've downloaded the regexes file, but I think I'm missing an extra step to pack it with the executable

fluid thunder
zealous gyro
#

Carlos are you familiar with the current AD apple exploit? I'm searching for a cyber security professional that can assist me in regaining control of my devices both Mac os and iOS as they are all under control of a network domain admin. There are just at first glance thousands of apple users that have been hijacked through the open directory or directly services fork of the Mac OS. It's very serious and while I'm not a researcher I'm well versed in IT and without doubt is the worst malware/hijacking I've ever seen or could conceive truly. With limited Microsoft windows experience I've been told that all the attackers need is a apple users phone number and a reply from a text message and all devices contained in the apple id are under control of the AD admin. Please excuse me if parts of my terminology aren't adequate but in closing I should mention that all my devices are hijacked and after using NSA level bitraser erasure my hard drives still contain a hidden HFS+ partition and in the recovery environment one of the first sequences is contacting the AD node and before Mac OS is even reinstalled the attack has begun. As I mentioned going out in a bit of a limb I'm suspecting this could be happening to a an enormous amount of users and I have also been told apple is aware of this which is discouraging to say the least but in reaching out to you to get your take and see if your interested in having a look. I'd be happy to compensate you for your time. Your thoughts, Jeff

fast sonnet
#

Hello. First I want to thank to @fluid thunder for allowing me to promo this here.

I'm glad to announce my collaboration on CWP (Certified WifiChallenge Professional) certification, where I've personally contributed to the content. If you're interested in learning how to conduct a professional WiFi assessment at an affordable price, this is for you:

Course in English 🎯
https://academy.wifichallenge.com/courses/certified-wifichallenge-professional-cwp?ref=c02137

Course in Spanish 🎯
https://academy.wifichallenge.com/courses/certified-wifichallenge-professional-cwp-esp?ref=c02137

Sorry for the late notification as the Black Friday offer ends today (25% off), but you still can take advantage of it using these links.

This certification is very competitively priced compared to other options and includes a lab where you can put the knowledge you acquire into practice. The content is highly up-to-date, and once you purchase the course, you’ll have lifetime access to it.

I, as the main author of airgeddon tool have taken and passed the exam. After experiencing its potential and quality first-hand, I decided to collaborate with the certification, contributing to its content by expanding and improving certain aspects.

I truly believe this could be a noteworthy alternative in the current landscape of Wi-Fi certifications, as others are either much more expensive, outdated, or both. This certification is practice-focused and includes everything you need to know (and then some) to perform professional Wi-Fi audits.

Throughout the 100% online certification course, students will be guided step by step on how to complete each lab exercise. That said, the exam should pose no difficulty for anyone who has successfully completed the course challenges.

Let’s hope it can carve out a place in the market. Cheers!

uneven berry
#

do you hacktricks has a pdf book ?

umbral kayak
#

using the website is the beset way to check for anything, having payloads on books is kind of XD, is more focused on daily ussage

inner plinth
#

Hi everyone! I tried to sign up my own account and filled all information required. However, it just wouldn't allow me to submit it anyways. How should I solve this?

outer forge
#

I'll dm you

coarse moth
#

How are you

#

Please tell me

dense valley
#

is that me or hacktricks isn't showing up in google anymore ?

#

only the github but not the book itself

fluid thunder
# dense valley is that me or hacktricks isn't showing up in google anymore ?

Yep, we have no idea why HackTricks has just disappeared from Google.
Now if you want that the results from Google to also contain links from HackTricks you need to specify "hacktricks" in your search.

While we try to figure out what happened we have created the site http://www.hacktricks.xyz/ to search with bing or google content in HackTricks and you can also use the search feature inside "book.hacktricks.xyz" and "cloud.hacktricks.xyz"

dense valley
#

yea basically i am using google dork to find , thanks for the confirmation

coarse beacon
#

Can still see it on DuckDuckGo but yeah not on google anymore.

fluid thunder
arctic sail
#

even with google dork

fluid thunder
#

Happy New Year, @everyone! Wishing you all a 2025 filled with (ethically reported) vulnerabilities! 🎉

After Google’s recent algorithm update, HackTricks' English version was almost deindexed. SEO experts concluded this happened because HackTricks is available in many languages, but the platform we used didn’t allow us to control SEO settings that could allow to indicate what was the main site and what the translations. This likely led Google to misinterpret our translations as an attempt to boost rankings, rather than genuinely offering multilingual content.

To fix this, we’re moving HackTricks and HackTricks Cloud to a new domain (hacktricks.wiki) where we can fully manage SEO. Redirects from the old site will ensure a seamless experience.

Therefore, if you experience any issues these days, please be patient as we’re working to make the migration as smooth as possible.

hasty flax
fluid thunder
arctic sail
fluid thunder
arctic sail
sweet turtle
#

Hi @fluid thunder I have issues deploying labs in the ARTE course "Error provisioning lesson labs", could you please support ? thanks

fluid thunder
sweet turtle
fluid thunder
sweet turtle
fluid thunder
atomic meadow
#

I bought the ARTE course in Nov, but I couldn’t find my voucher in email, can please resend ?

outer forge
chrome mantle
#

Lucky me I just go straight to the source 😉

#

Got the website in my mental bookmarks lmao

atomic meadow
pallid dew
#

Hey everyone! I just saw the LinkedIn post where hacktricks talked about getting de-indexed from Google because having the site available in multiple languages. And they switched to a new domain.

I'm curious if they are still using GitBooks for their content or using something else now. 🤔🤔

#

Also, now I see they have a few sponsor ads running on the side. Which was not possible if they use Gitrbooks I guess? 🤔

fluid thunder
fluid thunder
#

@everyone
Introducing NaxusAI – Your Source Code Security Companion!
www.naxusai.com is now live!

🔍 What is NaxusAI?

  • Generate a call graph of your code repository to analyze vulnerabilities & backdoors using LLMs with maximum context and minimal code submission.
  • Monitor commits and PRs in real-time, ensuring your code is secure before it hits production.

💡 Why NaxusAI?

  • Optimize code audits with cutting-edge AI.
  • Seamless integration with your existing workflow.
  • Free to try with your API keys!

📚 Check the docs here: https://docs.naxusai.com/
Ready to level up your code security? Start now at www.naxusai.com! 🚀

If you have questions or want to report a bug or ask for a feature you can also do it in the new NaxusAI discord server: https://discord.gg/6ghgw7Cw

What is NaxusAI and a step-by-step instructions on how to set up an account, log in, and utilize the naxusAI vulnerability code monitoring service.

nocturne dragon
#

I was trying to purchase the PDF Hacktrick book and see that PayPal is no longer accepted. How can I purchase that PDF?

fluid thunder
nocturne dragon
#

OK, thanks. I am going to step out for a minute to kick my own ass. I do see that in there and missed that. LOL

nocturne dragon
#

@fluid thunder Just curious if you are working on a HackTricks AI model?

fluid thunder
nocturne dragon
#

ohh, I need to check that out. Thats why I wanted to get a PDF of Hacktricks. I am feeding my AI model to pull from it.

nocturne dragon
nimble tartan
#

Oh for a local one mb didn’t see that 😂

#

What model u running can I dm you ?

nocturne dragon
#

Ya. All private and local

#

Sure

fluid thunder
pastel cave
#

There is a mock exam from secops group

#

its just one question

#

login as admin and get the flag

#

anybody can help?

#

The only thing is given is a JWT and an api endpoint, tried all jwt attacks

nocturne dragon
north otter
nocturne dragon
#

Ollama right now

rotund nacelle
#

Why does hacktricks have its macosx readteaming removed

#

?

fluid thunder
rotund nacelle
#

Check privilege escalation section

fluid thunder
dim narwhal
#

also...man I feel like a dummy, ever since the update to the new domain, my left sidebar on hacktricks disappeared, and it turns out uBlock Origin was blocking the sidebar from loading 😭 I was finding it so hard to navigate the hacktricks site just by using the search function constantly haha

fluid thunder
fluid thunder
old elk
#

Hi. I have purchased ARTE exam voucher. Not redeemed it yet. But before redeeming, I have few queries to ask. I came to know that there is a separate channel for that. Will I be able to get the access of that channel so that I can put my queries forward over there?

I have added my discord handle link too in the profile section but haven't received an invite yet since one week.

Thanks in advance.

fluid thunder
atomic meadow
#

I have activated voucher for ARTE, I haven’t received invite link yet

fluid thunder
atomic meadow
#

I have set. Which channel needs this setting ?

crude wadi
hardy tusk
#

Here’s a supply-chain attack just waiting to happen. A group of researchers searched for, and then registered, abandoned Amazon S3 buckets for about $400. These buckets contained software libraries that are still used. Presumably the projects don’t realize that they have been abandoned, and still ping them for patches, updates, and etc. The TL;D...

fluid thunder
#

Very interesting!

hardy tusk
vague schooner
#

AzRTE!!! When is the last day to get the Pre-Release discount?? 🙁 ❓

south jackal
#

I already hacked a tiktok account but the password is difficult for me I need to put URL link but I don't know how to do that

fluid thunder
vague schooner
honest lintel
#

Sorry one question , does the new azure certification cover pentest of hosted services as well ?

fluid thunder
outer forge
#

We will probably leave the discount for a couple of weeks

coarse beacon
#

how much to pay hacktricks team for private sesiso

#

*session

fluid thunder
tacit osprey
#

Does anybody have experience with OCI (Oracle Cloud)?
I'm looking for a way to leak somehow the OCI tenancy/user ID, given the storage namespace name (if that's possible ofc)

safe spire
#

Can anyone in here help me with the training registration? I'm not getting any activation emails.

fluid thunder
safe spire
#

@fluid thunder sent a dm

young pivot
#

Hey carlos your wiki page of web hacking is just basics and intermediate or it's whole enterprise level knowledge source? I had visited but get confused , that this things helps me to do better in bug bounty field?

#

Or this whole pages are just for starting out any carrier in cyber security field?

spare cloak
#

anyone here who is using arch as distro?

outer forge
spare cloak
#

i suppose you learn a lot with it?

outer forge
spare cloak
#

I feel from a hacker and security point of view, arch/blackarch should be very valuable since it will really force you to learn linux (and computers in general) deeply ?

#

I'm still a Linux noobie but considering with just getting arch dual boot anyway

glossy vale
#

Hi

regal trail
#

Hi guys

iron vapor
#

Hey guys
Just started the labs in Azure red team in hacktricks
I’m trying to figure how to
enumerate few things in azure

#

Specifically in the application add secret lab

umbral kayak
iron vapor
#

Great ! How do I join the group?

umbral kayak
#

Link your discord account in the hacktricks training website

#

On your profile you should see the option to do it

iron vapor
#

Ok thanks will check

fluid thunder
sterile yacht
#

Hello. In ARTA KMS Lab any ideas?
An error occurred (InvalidCiphertextException) when calling the Decrypt operation:
aws kms decrypt --ciphertext-blob ms_lab_1_user2_credentials_encrypted.txt --key-id 32778d35-462d-4bf6-b62d-f2c6eb043bbe --profile audit01 --region us-east-1 --output text --query Plaintext | base64 --decode
i removed whitespaces in the base64 encrypted key file already
i used file://enc.txt and fileb://enc.txt
nothing working
file should work as its textmode

sterile yacht
#

ok solved both

young pivot
#

Carlos bro make an online android app of hacktricks

craggy basin
#

@fluid thunder I would like to request a quotation for the ARTE certification course to submit to my management for approval

fluid thunder
fluid thunder
young pivot
fluid thunder
young pivot
#

Ok but i have a another request

#

Can you please make a seperate section of bug bounty in your wiki?

umbral kayak
fluid thunder
# young pivot .

HackTricks is always open for suggestions of improvements and new hacking techniques in the Github repository via PRs.
Feel free to open a PR explaining in detail how that would be helpful and what to expect

glossy vale
#

Hello

sour mountain
#

The hint was not enough to solve the first lab. I need another hint. I did the following: az ad app credential reset --id <appId> --append
& az login --service-principal --username APP_ID --password CLIENT_SECRET --tenant TENANT_ID. Don't know how to retrieve the flag from the key vault.

#

I need the solutions for the Azure Red Team Expert labs.

loud lake
crude wadi
arctic cape
#

Hi, everyone!!

#

am i the only one that gets this error
i've tried differet browsers

fluid thunder
#

Do you have any errors in the console?

arctic cape
#

the site works for few sec then it hangs

fluid thunder
arctic cape
#

i've reloaded multiple times
the site jus works for few sec when it'sloading an then after loading it hangs

fluid thunder
arctic cape
normal tundra
#

Aviator signal bot

#

I want

spice hare
#

Hi everybody, how are things going?
I've noticed some slow behavior on hacktricks website in the last week, someone else has experienced that?

fluid thunder
spice hare
#

I really appreciate

fluid thunder
spice hare
#

Congrats for all of your job

fluid thunder
#

Thanks!

fluid thunder
#

Hi @everyone !
You can now use the search button of book.hacktricks.wiki to search in both book.hacktricks.wiki and cloud.hacktricks.wiki. This should allow to find information in hacktricks easily, but can be confusing if you were just expecting to search info only in book.hacktricks.wiki.
What do you thikn about this? Should cloud.hacktricks.wiki also show results from book.hacktricks.wiki?

glossy vale
#

Okay

snow grail
fluid thunder
crystal gyro
#

Hi ! I'm coursing the ARTE certification and I saw in the profile section there's a Discord handle to enter to access course content discord channels. It's giving me an error that says "Error adding user to discord role. Ensure you are using the correct handle". I found my handle in the way that official Discord page explained !

glossy vale
#

Hi

harsh kestrel
#

I wanted to thank Carlos, Ignacio, and Jaime for helping us explore the exploitable AWS and Azure in 2-Days 2-Clouds

fluid thunder
hearty obsidian
#

Hello - new to the community. Registered on the website with my discord handle, slayer recommended I join here with questions about cloudpeas. Any channel I should look for those conversations?

(Not yet in a course but will likely sign up for one in late June)

crude wadi
umbral kayak
#

🎉 Excited to announce that I have successfully completed the Azure Red Team Expert (AZRTE) certification from HackTricks!

☁️ This advanced certification has been a challenging and rewarding journey into Azure cloud red teaming.
As always, the HackTricks Training team delivered a top-notch learning experience covering:

• Enumeration a...

#

🫶

teal hinge
#

how can I reach support? I have some problem with environment

crude wadi
shut python
#

Do we have an idea on the Azure Apprentice release date?

fluid thunder
shut python
lean garnet
#

I am looking for help with invoice which I paid for the course, made a mistake with location

fluid thunder
#

Hi @everyone ! I would like to introduce you #hacktricks-feed , a new channel were the hacktricks bot will find new technical posts about vulnerabilities and hacking techniques and post them with a PDF which would be the summary of the post. The goal is to only get technical hacking posts and get the explained techniques sumarized to learn those faster.
I hope you like it!

atomic parcel
#

hello, i can't run hacktricks locally. i mean, i run docker command and all stuff but webserver not works after 5m

young pivot
#

Hey everyone 👋
I’ve just started my public Web & API Security journey on Twitter — focusing on deep learning + real-world bug bounty hunting.
Here’s my full roadmap & routine:
Plan: https://x.com/kalki_x0/status/1937079941050380331
Daily Routine: https://x.com/kalki_x0/status/1937102330802880944
🙌 Would really appreciate feedback from experienced hackers:
Any suggestions or areas to improve?
Also, if anyone wants to join, I’ll share my Notion template and free learning resources. Just DM me!

Thanks 🙏

red portal
#

Anyone here from Apple who can give a referral for a strong candidate with matching profile?

abstract vector
#

Dear all I am beginner in this field and I have some query. please help me

abstract vector
#

hello

crude wadi
livid fossil
#

Hello!

I just started the Azure Red Team Apprentice course and noticed that the "Methodologies" section is empty. Is this expected?

fluid thunder
crude wadi
livid fossil
#

Beauty ! Thanks !

abstract vector
#

Good morning all

abstract vector
silk lynx
#

or tryhackme beginners path depending what basic cyber security means.

abstract vector
silk lynx
prime flint
fallen pebble
#

I've added my discord id to Hacktrick profile. I am taking ARTE. Could someone grant me access to the channels?

fluid thunder
fallen pebble
fluid thunder
fallen pebble
#

yes I can see it now. Thank you!

#

and thank you for the speedy response

#

We are going to do a red team exercise in our company's aws environment soon. Hopefully I can use some tricks from ARTE.

fluid thunder
#

good luck!

spare vault
#

Hey all, for thoses interested in GCP I built GCP Delegate tool to abuse Domain Wide Delegation, and posted a blog post about it back in 2023 if you are new to GCP and interested I tried my best to make it digestible and accessible 😉 https://medium.com/@lutzenfried/gcp-domain-wide-delegation-abuses-b82b8dd8cf15

Medium

In today’s dynamic technological landscape, the shift to cloud environments has become a cornerstone of business innovation. As companies…

#

And BTW; Hi to everyone here ✌️

paper hedge
#

I'm coursing the ARTE certification and I saw in the profile section there's a Discord handle to enter to access course content discord channels. It's giving me an error that says "Error adding user to discord role. Ensure you are using the correct handle".

fluid thunder
lean folio
#

i set my username to evil.com and able to send a mail to another user and when the another user opens the mail evil.com is clickale amd open real evil.com site
is this a bug guysss?
like i am able to set any domain name as my username and i mail it is clickable

nimble radish
#

hello everyone, i am trying to get remote access via XXE in a lab, tried many methods, none of them worked.
works fine: <!ENTITY xxe SYSTEM "expect://id;ls">
doesn't work: <!ENTITY xxe SYSTEM "expect://id; ls">
${IFS}, %20, %09, \t, \
any help plz?

ornate moat
#

Hey,
Quick question: what’s the cost of a retake if one fails the AzRTE exam?

coral crow
#

Hey @fluid thunder when is the next discount?

fluid thunder
clever wolf
pine pollen
#

or it's a link to the image on the top of the website?

fluid thunder
thorny cedar
#

Howdy. Looks like Google is aggressively trying to block Hacktricks again.

crystal solstice
fluid thunder
scenic pivot
#

How can I add myself in ARTE channel? Can anyone pls let me know?

crystal solstice
coral crow
#

Hey @crude wadi unrelated to the GCP course so I thought I should ask it here: Are you a cloud security analyst ? I'm wondering how well the courses from HackTricks helped you with real world assessments

crude wadi
coral crow
scarlet zenith
#

Is there any content related to AWS Managed Workflows for Apache Airflow (mwaa)?

Any tucked in the airflow section or anything, I can't find any...

fluid thunder
scarlet zenith
#

Got some stuff headed your way cat_jam

crude wadi
scarlet zenith
coral crow
coral crow
astral ivy
#

Hey, regarding last BB challenge(AWS), I'll try not to spoil anything - but in the reverse shell with the start role, while trying to change dirs and such (into Internal), the shell starts breaking apart. I tried destroying and re-starting multiple times but I just gave up. Anyone had this issue? (also, backspace began writing the equiv value of ^? and stty erase doesn't work on it).

crude wadi
pine pollen
#

Users/roles can have different types of policies applied:

  • inline
  • attached
  • PermissionsBoundary

In this case, the most restrictive policy, and the one referenced by AWS, will be PermissionsBoundary. For example, if the inline/attached policies contain conditional s3:GetObject or s3:ListObject, but PermissionsBoundary does not, the user will not be able to perform any operations on the s3 bucket.

However, inline and attached policies should not be neglected, as they may contain the following permissions:

  • iam:PutUserPolicy for oneself
  • iam:PutRolePolicy for a certain role
  • iam CreatePolicy + iam:AttachUserPolicy
  • iam:CreateAccessKey for yourself
  • sts:AssumeRole for a role that either does not have PermissionsBoundary or has it but has more rights
  • lambda:UpdateFunctionCode + lambda:InvokeFunction
  • iam:UpdateAssumeRolePolicy

because having the above rights allows you to somehow upgrade or for lateral movement.

short ginkgo
#

hacktricks cloud loading weird/broken for anyone else? mostly in the sidepanel. The search icon is missing too but still clickable.

#

looked fine yesterday I think. on chrome/firefox on both my mac/windows boxes

fluid thunder
short ginkgo
#

cheers! Thanks for all the work on a great resource!

rocky plank
#

How do I reload changes in my local copy of HackTricks? I tried removing a section in the HackTricks folder but the changes didn't reload

fluid thunder
next python
#

Hi, with whom can i talk about my training voucher?

crude wadi
urban jetty
#

@next python

twin quarry
#

Hi, is there anyone I can talk to about some technical issues during the Exam?

crude wadi
outer forge
#

@twin quarry granted you the necessary discord role to open a ticket. You should see #training-support

full flax
fluid thunder
fluid thunder
#

@everyone Happy 2026! 🎉
Hope 2025 treated you as well as it could, and that 2026 brings more wins, learning, certs and good energy.
Thanks for being part of the HackTricks community — let’s level up this year! 🚀

clever wolf
#

Thanks Carlos! Your content has been amazing and I'm looking forward to the future with the community. Shout out to @crude wadi. That guy is great

icy sky
#

any discount?

tawdry lynx
fluid thunder
paper condor
#

Why won't it let me register?

fluid thunder
fluid thunder
paper condor
fluid thunder
#

@everyone the limit was increased and now you can create your account in https://tools.hacktricks.wiki/

(If you find any other issue let me know please)

worldly grotto
#

Hey Carlos, I'm getting a 502 error for some queries on ai.hacktricks.wiki, and when clicking the ? for AWS security, I get this error:

An error occurred: Unexpected token 'I', "Internal S"... is not valid JSON

fluid thunder
fluid thunder
#

Hi @everyone !
There have been several fixes applied in past couple of days to https://tools.hacktricks.wiki/ as we discovered new rate limits and new edge cases while going into production.
I think most of these issues have been solved already. If you are using the AI chat please, refresh the page to use the latest version.

And if anyone find any other bugs, let us know please!

paper condor
tender jetty
#

Guys , i can't register my account in tools.hacktricks. captch stucks

fluid thunder
tender jetty
scarlet zenith
paper condor
scarlet zenith
#

Thanks, it’s been at least good at scaring clients lol

paper condor
round juniper
paper condor
haughty creek
#

How to hack the wifi passwords

shut python
vale python
#

Hello team, how can I open a ticket? My time ran out and I couldn't take the exam. @fluid thunder told me that I can get information through this channel.

crude wadi
fossil birch
#

is books.hacktricks.xyz having some issues?

fluid thunder
celest gorge
#

Hello , i hope you are doing good , i want to learn hacking but i struggling to find powerful resources for beginners , please guys if someone can help me , send me in the private , thanks a lot .

jagged needle
#

Hi

south rune
#

@fluid thunder -> Is hacktricks planing to release any course about AI hacking maybe ?

fluid thunder
scarlet zenith
vague veldt
#

@fluid thunder hey where you the one who made ai.hacktricks ? or is that a third party tool?

vague veldt
#

im going to school for a cyber security degree i havent started the main courses yet, but i love exploring on hacktricks and would love to take a course from hacktricks instead of theose two if i could for more practice

#

another idea would be a freemium chrome/firefox extension for testing websites

#

im gonna try to contribute to the rust docs

vague veldt
# fluid thunder Yes

good i was scared it was a 3rd party for second and my internet blocks it automatically for some reason

vague veldt
ancient mist
#

Hello there! Newbie here, thank you

vague veldt
vague veldt
vague veldt
crystal solstice
vague veldt
#

@crystal solstice so I happen to have xfinity internet I think its gets automatically blocked, I dont know if thats the case for everybodys interent or maybe just for me

crystal solstice
vague veldt
#

i get an alert on my xfinity to allow it, i was just saying that might be concern if its stopping other people from accessing the website

#

So yea idk if this happens for other ppl im in America

paper condor
#

With the updated hacktricks, can I use the online tools for bug bounty? What's new?

restive orbit
#

Is it possible to bypass a soft-2fa email check?

#

with the correct password

patent spear
#

Hi! I just activated my AZRTE voucher. I have added my discord handle to the hacktricks account profile. Could I get access to the training channels please ?

fluid thunder
solar fog
#

What's the difference in the bundles? I see there's an apprentice, and it's much much cheaper, it costs 807e for a 1 ARTA course voucher
1 GRTA course voucher
1 AZRTA course voucher

and the other one costs 2472e.

fluid thunder
# solar fog What's the difference in the bundles? I see there's an apprentice, and it's much...

the apprenitce certs are small subsets of the expert certs.
In the section "Explore the path" in https://hacktricks-training.com/courses/azrta/ and https://hacktricks-training.com/courses/azrte/, if you open each section, you will see that the expert evrsion has a lot more labs and lessons

HackTricks Training

Master Azure with hands-on labs, red team methodology, and expert-led training at HackTricks Training.

simple perch
#

HackTricks Training is celebrating the recent release of the new AWS labs with a limited-time 25% discount on our AWS Red Team Expert and Apprentice courses (ARTE & ARTA)

🕒 Ends April 12th (23:59 CET)
🎟️ Code: AWSUPGRADE
👉 https://hacktricks-training.com/

If you’ve been thinking about improving your cloud security skills, this is the perfect moment to jump in.

HackTricks Training

Learn cloud hacking with practical AWS, GCP, and Azure training. Get certified with HackTricks Training through hands-on labs and red team methodologies.

sand bear
#

Hello, I need help, I had ARTE on my profile, but looks like it's gone. How it's possible? 😩

crude wadi
sand bear
ripe pecan
silent orchid
#

Hey everyone 👋

I’m a trained SOC analyst (fresher). I’ve applied for jobs but haven’t had a chance to showcase my skills yet.

So I’m starting bug bounty. I’ve practiced Broken Access Control (BAC) labs and now moving to real-world testing.

Any tips, guides, or platform suggestions would really help

fluid thunder
#

@everyone check out the HackTricks tools in https://tools.hacktricks.wiki/, among other you now can:

  • Request an automatic update of HackTrick pages
  • Scan public repos for vulnerabilities
  • Talk to HackTricks AI
    And much more!
left agate
#

Will there ever be a course on privilege escalation in Windows?

fluid thunder
short ginkgo
#

Not now, hacktricks. Im trying to privesc

fluid thunder
fluid thunder
short ginkgo
#

Haha yeah it was real. Appreciate you!

lament whale
#

Hi, I started the ARTE cert and I have technical problem activating my voucher. How can I contact the support team?

weary zodiac
#

hey can I use SharpRDP-like tools for RDWEB connectioion with .rdp file?

tranquil cobalt
errant steeple
#

is the book 24/7 updated ?

fluid thunder
#

yep, it's updated everytime I discover a new trick or anyone submits a PR to share some new trick

fluid thunder
fluid thunder
#

Hi Guys! For the people that has bought hacktricks PDF, may I ask you why do you need it offline?

crimson saddle
#

You can buy it?

fluid thunder
#

yes, you can, but it's outdated (JAN 2021), I'm working on being able to update it

plain lake
#

where am i able to buy it just out of interest?

fluid thunder
trim abyss
#

Hello @fluid thunder , can you open a channel to report some issues (alternative to github's issues) to report some broken link and typos?

fluid thunder
trim abyss
spice dirge
fluid thunder
#

thanks guys, I have updated that link

spark plank
spark plank
#

Also, the python code should probably adopt python3 semantics, i.e. print(data) not print data

fluid thunder
#

thanks mate, I now the code calls s.recv() and print is in python3 format, let me know if you have any other troubles with that

spark plank
#

Hi, running the new code example yields an error. I believe recv() requires an argument. This is the part where I don't know what the correct code should look like.

#

Can probably put 1024 in as the argument, but I'm unsure if this will make the program hang indefinitely.

fluid thunder
fluid thunder
lean bear
#

Great site!! Good work!!

rugged folio
#

Hi, I'm currently programming a python script for listing the most common ports (I still forget them), and I would like to integrate your hacktrick page links to the script, would it be OK with you? For example, when I query port 21 it would output something like :

The File Transfer Protocol (FTP) is a standard network protocol used for the transfer of computer files between a client and server on a computer network.
Pentesting tips : https://book.hacktricks.xyz/pentesting/pentesting-ftp

static pebble
#

@rugged folio I dont think there would be any problem, descriptions are basically common knowledge. if the script is only for you its completely fine. but if you want to share it on github etc as a tool and it's actively querying hacktricks to fetch info, it would be nice if you mention hacktricks as part of the tool ;)

#

but @fluid thunder will answer you asap

fluid thunder
thick owl
#

hey

fluid thunder
warm mica
#

I'm experiencing a strange issue where I visit this page https://book.hacktricks.xyz/exploiting/linux-exploiting-basic-esp, the content loads, then is replaced with a little red and blue loading spinner that never disappears. Happens in Chromium and Firefox (on Linux), I've temporarily disabled Ghostery too but it still won't load. I've watched a fresh page load via Firefox's task manager and I see it spike the energy impact value then just disappear (am guessing its crashed). Does anyone else see this?

tawdry otter
#

I do see the loading dots, however it loads for me

warm mica
#

no vpn or firewall, it happens on my virtual machine too. It's weird, must be an issue on my PC though.

#

thanks for checking and replying

tawdry otter
#

Could you try from other device tho?

#

To see if it's an ISP or device issue

warm mica
#

If I try it from my phone it works, that'll do me.

hexed lotus
#

but i can't see anything

warm mica
#

are you on linux as well, with Firefox?

hexed lotus
#

yeaa

#

kali linux, with firefox

warm mica
#

well, there are of us now then

hexed lotus
#

i tried on my other web browsers too but, nothing as well

hexed lotus
#

maybe the location can affect the result, idk

warm mica
#

I'm from the UK, so I doubt we are connected with that

#

who knows though, DNS is a mysterious thing 😂

warm mica
hexed lotus
#

i tested over my windows and

#

it works perfectly

warm mica
#

damn it, it's a linux issue isn't it.

tawdry otter
fluid thunder
#

Yeah, that part is managed by gitbook. If you want put a tweet mentioning me and gitbook

warm mica
#

Are there any special features on that page, as the rest of the site that I've looked at so far works, and other gitbooks sites work so I'm not sure this will be just a gitbook issue, it might be a combination of factors that lead to it.

hexed lotus
thorny gate
#

o/ all

#

is there some people engage in sec699 or CRTO?

nocturne dragon
thorny gate
#

I did it in january 😀 hf it was a fun cert

mental sphinx
#

Hello guy someone can gave me a good advice and good training site to pass OSCP?

fluid thunder
shadow sail
#

Hola Carlos,
I believe there's a typo in https://book.hacktricks.xyz/pentesting/pentesting-smb#hacktricks-automatic-commands

smbclient -h "\\{IP}\" -U {Domain_Name} -W {Username} -l {IP}
smbclient -h "\\{IP}\" -U {Domain_Name} -W {Username} -l {IP} --pw-nt-hash hash

Should be :

smbclient -H \\{IP}\ -U {Username} -W {Domain_Name}
smbclient -H \\{IP}\ -U {Username} -W {Domain_Name} --pw-nt-hash hash

Not sure about the -l, it's suppose to be for log-basename.
Thanks for your awesome work

fluid thunder
shadow sail
#

Cool. BTW, I got my PEAS t-shirt yesterday. A little contribution before your peas's subscription project. I'll try to be the first subscriber.

fluid thunder
upbeat path
#

Hey everyone! I’m a new subscriber on GitHub 👋

fluid thunder
fluid thunder
brave sentinel
#

hi im new to this

potent ether
#

??

fluid thunder
#

Hi guys!
The latest versions of PEASS-ng & HackTricks are now available through https://github.com/sponsors/carlospolop?frequency=one-time
You can find more checks in win/linpeas, more stable versions and several new tricks in HackTricks (new being added everyday!)
The idea is to be able to develop more content for people highly interested on it (subscribers) while updating every X time the community versions to also improve the free content!

safe inlet
#

Hi ,can anybody tell me a good resource to start with os

quiet lichen
# safe inlet Hi ,can anybody tell me a good resource to start with os

If you are looking for an academic course i suggest cs162 by john kubiatowicz. It's known to be the hardest computer science course in b.s in berkeley (not just the hardest operating systems course). AFAIK the videos are on youtube and course material (practical assignments and project) is opensource. In its project you develop a posix-based kernel called PINTOS. You add new features to it like file system, priority scheduling, new system calls, ...
In practical assignments you develop a simple web server, heap allocator, a simple shell, ...
Remember that you should be a very very very motivated person to solve its practical assignments and I guess no one exists that has completed the project without a good and motivated team (in this course you should do it with 3 other guys in a team) and without attending the course.

#

There are some people in reddit that call it as a part time job :))

fluid thunder
#

Hey guys!
I'm happy to announce that HackTricks is NOT going to be private
You can access the latest content in https://book.hacktricks.xyz (as always).
But I'm looking for a few good cybersecurity companies that want to announce their services there (20% discount for the first one!) so if you like HackTricks for free I woul appreciate any help reaching companies!
Also, don't forget to check out new posts about:

woven shore
drifting robin
#

I don't know how often when I search HackTricks or one of the resources show up. It's almost every time I find myself on one of the pages. I should just create a comprehensive crawl and build a favorites menu for chome and use that as my starting point for researching. Excellent job, thanks so much for the work you put into this and sharing with the community.

modern mirage
#

Hi, can I ask technical pentesting questions here ?

fluid thunder
#

sure

storm stratus
#

excellent!

compact void
#

Hi @fluid thunder I'd like to report a mistake on the hacktricks for specific privesc. Can I dm ?

fiery coral
#

Hello, where are you from? @carlospolop I admire you very much 😎🤙

storm stratus
#

hey @fiery coral

#

missouri here

hexed harbor
#

Hi I got a question regarding RSA keys, found some source code with this block in it. Iam pretty new to crypto and those java libraries but is that enough with that keyspec to crack the private key?

upbeat path
#

To me it looks like the RSA private key is hardcored in that code

hexed harbor
#

Yeah it actually was , managed to retrieve det private exponent from it

#

Thanks for reply 🙌

late epoch
#

Hello, I came from the cache-deception page of HackTricks , and I can't find anythings about "In order to perform a cache poisoning attack you need first to identify ukeyed inputs (parameters not needed to appear on the the cached request but that change the returned page)" the ukeyed term, it is a mistake ?

#

My bad it's just unkeyed, sorry for this message ^^

vague cairn
#

I want to access a 200 ok site but it's giving a 307 temporary redirect code by the isp. I want to really access the internet but it's blocked please help me?😢💔🇵🇬☠

split shuttle
vague cairn
#

I can't use tor since the isp blocked the domain so basically internet access is restricted even using a vpn (http injector,hat tunnel pro etc...) it's giving a 307 error code with a 200 ok status so circumventing to use free internet is useless... I hope there is some other ways to bypass this Isp restriction?😢😢😢

civic nest
civic nest
scarlet sleet
#

Anyone?

broken widget
#

who know how to bypass 2FA on gmail?

worthy lodge
#

who knows about computer programs and alphanumeric access keys? paying for some basic info

#

@fluid thunder dm me !

fluid thunder
worthy lodge
#

i have little to no knowledge on software. there is a software i currently use that has an instance limit of open instance per key. i want to be able to open the software more than once though.

#

someone told me that i can manipulate it by turning off the internet connection to the software during the authentication process

worthy lodge
#

no thoughts anyone?

upbeat path
#

This sounds like a reverse engineering problem. Do you have access to the source?

vagrant storm
arctic sail
#

Do you think we can add lsadump::lsa /patch here?

#

this command query the lsass server so the result is a bit different from sekurlsa

fluid thunder
copper ember
#

folks how can I elevate my profile on stackoverflow?

#

You must have 50 reputation to add a comment

#

I feel like all the intelligent questions are already asked

#

how can I get reputation?

stuck python
#

I have a quick question. Why don't The Hacker Recipes merge with the fabulous Hacktricks ?

fluid thunder
stuck python
#

I think it would be a real plus for the community if you contact the creator of this site (https://www.thehacker.recipes/) to make sure the content is fussed over. It contains some fabulous content about Active Directory.

fluid thunder
sudden mauve
#

@fluid thunder On a graphql magento site i used to scrape for months now, they changed their backend in a way the queries are returning

i can still access in browser the /graphql path but the introspection query fails with 500
Could I slide into your dms to show you what i mean & which site? I would happily pay for your help as the work you do and done already is actually amazin, either way keep up the good work 🙏

half egret
#

The buymeacoffe payment wasn't working today

arctic sail
#

theme changed or it's only me?

fluid thunder
fluid thunder
arctic sail
#

it would be better if there's a switch for day/night mode!

#

but still thanks for your efforts!

regal prairie
#

yes hey guys hacktricks is now dark let

fluid thunder
#

Hi guys, some of you have asked me to go back to the white theme of Hacktricks, please, respond to this message or use fire reaction if you prefer white theme or clap reaction for dark theme

worldly turret
#

Isn't there a possibility of a switch to trigger dark/light theme

sonic idol
#

looking for a good CVE download site

fluid thunder
arctic sail
#

is the search bar a bit buggy today or just me

placid steppe
#

Two GitBook projects, one dark theme and one light. 😂

midnight birch
#

Hello fellow hackers,
Didn't know where to drop this so gonna do it here
Just noticed a little mistake in this masterpiece (if I'm not mistaken oc)
https[:]//book[.]hacktricks[.]xyz/pentesting-web/web-tool-wfuzz
In the filtering options, "--hc/sc" doesn't filter by char but by code, it should be "--hh/sh" on the last line

fluid thunder
midnight birch
hexed lotus
#

hi ! who know how to connect Google with cookies ?

turbid apex
fluid thunder