you're a life and time saver, you earn a sub. BTW I'm new to cybersecurity.
@passingrass14253 күн бұрын
Thank you for these!
@toouniquetobe4 күн бұрын
Thanks! The HTB Note 1: Don't forget to add "admin.academy.htb" to "/etc/hosts". is willingly misleading.
@ferreira8206 күн бұрын
I was stumped! I appreciate you posting this :)
@serjinskiy14 күн бұрын
Great!
@serjinskiy15 күн бұрын
helped thanks!
@Onyx8Y8Ай бұрын
This was the first one I did all by my self. Every time I get so close before giving up and coming here. This time it was because I changed the flags country I couldn't get the flag. Thank you man please keep posting these!
@camy3493Ай бұрын
Cheers I had a pretty good idea this was how I should solve it but the search bar on my website would not let me interact with it strange dunno if anyone else ran into this issue
@KenzytronАй бұрын
how to kill multiple programs with command prompt?
@ForgeStudiosWRZАй бұрын
For anyone getting the "Invalid JSON" error, you need to format the data after -d like this: ^"^{^\^"search^\^":^\^"flag^\^"^}^" ^ So for example: curl -X POST -d ^"^{^\^"search^\^":^\^"flag^\^"^}^" ^ -b [sessionid] -H "Content-Type:application/json" [url]
@atlasbredalen887Ай бұрын
I have to say so far HTB is very unprofessional and aggravating. It feels like it was made by very technologically illiterate people who don't know about computers. The fact this lesson had a target machine you basically never interact with then it just says stuff like "oh do this to this page" it is so broad and unspecific that it quite literally is unusable they need to annotate and explain things better. Also the adding to etc hosts via echo is also very very annoying as there is not even one single scenario that that would be necessary all you need to do is use the tool how it was intended who tf would make a tool that doesn't even work unless you add every site into etc/hosts no that's not how it works. HTB is very poor setup and TERRIBLE at teaching ppl cause it is literally explaining things like an uncategorized caveman. Also it never once explains to completely disregard the target ip, in this case they need to remove the target ip if it isn't being used for the exercise. VERY VERY infuriating and pointless I am so upset and discouraged to keep using this platform it is so unprofessional. And it also never explains to disregard the entire target EXCEPT for just magically the port! lol what the actual FUCK!? SO we are attacking htb has NOTHING to do with the IP but somehow does have to do with the port? what the actual fuck is this thing trying to teach us? It is quite literally teaching us nothing and teaching us incorrect info FUCK HTB!
@Shrek_fannnАй бұрын
I keep receiving “A Valid Cookie is required” I don’t understand what I’m doing wrong as I provide the cookie I get
@WizzardHackerАй бұрын
I get the same response. going to go over it again
@WizzardHackerАй бұрын
make sure you capitalize everything he capitalizes
@Shrek_fannnАй бұрын
@@WizzardHacker I have tried that
@CheesecakeDaddy23 күн бұрын
I had to refresh the browser page, do the shift=ctrl=E and look in storage under cookies to get the PHPSESSID value and amend my command. Hope that helps
@ausefulparadox2 ай бұрын
Thanks for this bud, all of this stuff was totally standard, but for some reason HTB kept rejecting my answer for MAC address. Even though I was 99% sure it was the answer it kept rejecting it and I was going insane. Which lead me to your video, turns it I had to put in MAC-address. You saved me a lot of pain
@anton40462 ай бұрын
thanks man
@JFCConley2 ай бұрын
My nose was right on it. the file path flag is what I overlooked.
@culturalheritages2 ай бұрын
thanks so much, really helpful
@culturalheritages2 ай бұрын
great video
@culturalheritages2 ай бұрын
thanks so much ❤
@Macdoesnothing2 ай бұрын
doesnt work at all there isnt a dowload file anymore 2024 nov
@thenextbigthing89982 ай бұрын
fucking clickbait bullshit video
@dinudaya9902 ай бұрын
Really helpfull ❤
@ahmedbousaleh10183 ай бұрын
i was just about to try this but i give up and seached on google
@JohnV-e6g3 ай бұрын
<3
@alvin47k3 ай бұрын
Awesome. Been stuck on this lab for a while till I came across your video. Thank you.
@Thais-s5b3 ай бұрын
Hello, if I search through curl I get the flag from the terminal, but when I want to see the search.php in the developer tools in the requests it does not load
@aezonyx3 ай бұрын
thanks
@ritchyyT3 ай бұрын
Thank you for providing a step by step process and clear explanation!
@S1eepy_ic3 ай бұрын
You can also use "sudo --version" in the session.
@marcmorris70793 ай бұрын
How do I vpn into the HTB academy servers from my linux environment.
@GamingWithHasty3 ай бұрын
Hey, great content you have been watching some of your videos and explanations when i'm stuck on one of these modules. Do you have or would you consider creating a discord community? That would be great to get to talk with people more knowledgable than I am in IT and cybersec and learn from one another
@italia-tech3 ай бұрын
Yeah that's actually a great idea! I think in the future that'll definitely happen.
@hasibulhossainemon3 ай бұрын
thank u
@WolfSaintVII4 ай бұрын
incredible thank you, was so stuck
@bartdomingos4 ай бұрын
My jpeg files dont show when i filter the capture to http
@Mamduh_alsaied4 ай бұрын
using what you learned in this section, try to deobfuscate 'secret.js' in order to get the content of the flag. what is the flag? :::::::::::::::::::::::::::::::::::::::: Can you answer this question? I searched a lot and did not find a correct answer. I did everything that was correct, but it did not work. Is the laboratory wrong or old? I hope for an answer and thank you very much❤❤
@franpan894 ай бұрын
they updated this module.. hoping this technique still applies
@ahmedfaisal19854 ай бұрын
it is not taking me to there as it sasys coming More documentation is coming, in the meantime consult source files
@NeonWidow4 ай бұрын
Like a bossssssssssssss!
@banana-99594 ай бұрын
lmao, I left out the version number and for that reason there were lots of exploits and I just randomly used one which didn't work obviously. thanks for the help
@nelsoncruz-os7nz4 ай бұрын
Huge help man. Thanks!
@Eyevan16984 ай бұрын
Great Videos, I was lost on either using the pcap or spawning the machine
@Eyevan16984 ай бұрын
So nice! Thanks
@nelsoncruz-os7nz4 ай бұрын
Awesome content. Keep going!
@italia-tech4 ай бұрын
@@nelsoncruz-os7nz Thanks!
@fontanot4 ай бұрын
for me it doesnt show that have saved any file even if i set FILEPATH to /flag.txt
@juanprograma1816Ай бұрын
yeah i follow the steps and it only shows Scanned 1 of 1 hosts (100% complete) [*] Auxiliary module execution completed
@ablackball36754 ай бұрын
Grazie !
@Joshua2025xoxo4 ай бұрын
Do you offer 1on1 zoom sessions at all? I'm just starting out in this industry and could use the help when stuck. I'm in Australia so the time difference may be an issue? Get back to me when you can. Cheers.
@caml17204 ай бұрын
never clicked for me that i needed to add in front of the numerical IP. thank you!
@Joshua2025xoxo4 ай бұрын
Thankyou legend
@ramirez_drl4 ай бұрын
when i do de request in the search bar i dont see nothing in the devtools but yes when i reload the page, could someone help me??
@yeahyeahmuke5 ай бұрын
Thanks for posting this, I too, got stumped at the same place!
@СеменЛюбас5 ай бұрын
А можно так же описать прохождение Privilege Escalation следующей главы, потом что понять логику товарища который написал руководство к этому очень сложно.