#red-team-capstone-challenge

1 messages ยท Page 1 of 1 (latest)

lyric stream
#

Please be mindful not to ask for/provide hints or answers during the competition for this challenge, which ends May 31st, 2023. ๐Ÿ™ Good luck and have fun! ๐Ÿฅณ
Note: To access this challenge requires a subscription AND a 7 day streak.

trim beacon
#

First! ๐Ÿ™‚

hazy widget
#

Yay!

#

Good luck everyone!

brittle ledge
#

GL!

pseudo parrot
#

Yes!

Have fun! โš”๏ธ

clear badger
#

May the odds be ever in your favor! Let the race commence!

frozen plume
#

Donโ€™t have a 7 day streak ๐Ÿ˜ฆ 4 more days until I can start!

hidden galleon
frozen plume
limpid fjord
#

You need a 7 day streak to join this room + a subscription? ... why?

pseudo parrot
#

Most of the networks are streak requirements.

lofty dove
#

Hello, I'm gonna start attacking this network. I will likely need a lot of help, hopefully I will be able to offer someone some help in return. Good luck other peps.

limpid fjord
#

Switching to B2B Exclusive ... sry. why i can not by like throwback ...

torpid ore
#

Gl everyone, have fun - this one is an absolute banger!

#

๐Ÿ˜

limpid fjord
#

here are people with real live and not everyone have every day time ... the concept based on streak are irrational and unworldly

normal ocean
pseudo parrot
#

It's just going to be a single prize.

normal ocean
#

yeah

trim beacon
limpid fjord
pseudo parrot
limpid fjord
#

thats the first one ... and thats really bad

pseudo parrot
#

I'm sure Breaching AD had too.

limpid fjord
#

i'am sure, not ๐Ÿ˜‰ and now ... i made them all ๐Ÿ˜‰

pseudo parrot
slender verge
#

in any case, the initial announcement said to keep our streaks

limpid fjord
#

i'am not a free user ๐Ÿ˜‰

#

subscriber

pseudo parrot
#

still had a streak.

#

However, I'm not discussing that in this channel, instead keeping it for the topic.

limpid fjord
#

sry, thats not true

#

๐Ÿ˜‰

pseudo parrot
grave sable
lofty dove
slender verge
#

there's enough time to do the red teaming pathway

#

and attempt this network

normal ocean
#

but remember, this network is not for the weak ๐Ÿ˜‰

limpid fjord
brittle badgeBOT
#

Gave +1 Rep to @grave sable

lofty dove
brittle badgeBOT
#

Gave +1 Rep to @slender verge

pseudo parrot
limpid fjord
#

Exclusive content only for B2B is not my taste ...

deep hearth
#

I thought achieving a 7 day streak badge or higher would allow a subscriber join the room?

lofty dove
#

FFS I have to do all the red rooms before this blobheart

slender verge
trim beacon
# limpid fjord thats not the point, the most think what is really bad here, the content will be...

This network, like our AWS content, would have been a B2B exclusive from the start, since it is those clients that have asked for this type of content. Running a 14 host network is not something that is cost effective to do on the scale that we have for subscribers. Effectively, we would have to almost double our subscription cost. That's why this is B2B content.

However, we thought it good to at the very least give normal users, those that have helped us build to where we are today, an opportunity to experience this content. Our only ask, which was clearly communicated a month in advance, was to make sure you keep your streak up.

slender verge
lofty dove
#

I'm so bad ๐Ÿ˜ข

limpid fjord
trim beacon
limpid fjord
limpid fjord
slender verge
#

then people would complain there's no support...

limpid fjord
lofty dove
#

If I don't get the chance to take part because I suck a red teaming, I'm gonna be mad. I'm gonna spend more time doing CTF's and get a lot better.

lyric stream
#

Who's got the first flag? ๐Ÿ˜„

grave sable
# limpid fjord ok, make a offer without support, why not ...

THM isn't just tailored to you. Of course, we would like to make everyone happy, but sometimes decisions must be made. This was one of them; as Am03bam4n said, we made it accessible to b2c users for a few days despite this being a b2b offering; why only see things negatively?

limpid fjord
pseudo parrot
limpid fjord
grave sable
limpid fjord
#

ok

brittle ledge
#

really loving how this challenge looks! Gonna be a tough one ^^

random forge
#

Hi

trim beacon
#

Please make sure to answer the questions, which means you read the actual scope of the assessment, and then your network diagram will show you IPs ๐Ÿ™‚ This is normal, read, "sign" the red team contract by answering the questions and you are good to go

sweet shale
#

is this subscriber only?

pseudo parrot
pseudo parrot
lyric stream
#

I've added the join requirements to the pinned message. ๐Ÿ™‚

pseudo parrot
#

The flag system is great too.

#

This room is my favourite, I'm glad we are able to get a chance to have a bash!

heavy dragon
#

bruh how to regist ssh

#

im confused

lusty gazelle
#

3 more days for my 7 day streak! Maybe I can finish the offensive learning path while waiting. I'm 70% complete so far. I've already finished Red Teamer, Jr. Pentester, and so much more. Very excited for this new network!!! Let's go!!!

pseudo parrot
#

the task tells you.

trim beacon
# heavy dragon bruh how to regist ssh

I highly recommend you don't skim the content in the room but really read it. Else you will easily get lost in the room. The steps to register should be clear after reading the entire task 2

trim beacon
lusty gazelle
#

Indeed. Can we work in small groups?

pseudo parrot
trim beacon
quaint knot
#

Hey friends -- I was approved by THM to live stream this challenge. Feel free to join me tonight for the kick off stream ๐Ÿ™‚ -- I'll be working through it all live with no prior knowledge, so we shall stumble through it together!

A few details I want you to be aware of:

  1. My kick-off stream will be tonight at 8pm CST on the Hack Smarter Twitch Channel (https://hacksmarter.live/)
  2. All streams will be posted afterwards on my YouTube Channel (https://www.youtube.com/c/TylerRamsbey)
  3. I will be treating this like a real engagement, spending much of our time performing enumeration and taking good notes.
  4. I am not going to attempt anything with the network until I am live on stream - so it will be my first reaction to everything (we can stumble through together).

https://hacksmarter.live

pseudo parrot
#

NVM

#

Lool.

#

I need to convert it to UK.

hidden galleon
#

2am for UK!

pseudo parrot
#

Ouch, maybe I won't check it out then.

pseudo parrot
#

So, who's working on it now? ๐Ÿ˜„

lofty dove
#

Sucks to suck that's all I can say xD

warped eagle
#

really a 7 day streak ugggg guess I won't be doing this network ๐Ÿ‘Ž

pseudo parrot
trim beacon
torpid ore
trim beacon
warped eagle
cerulean wraith
vital stag
#

Isn't this kinda unfair**, only people from business can get access to this content, so even if we want to pay we can't have access to it

torpid ore
#

Nope?

vital stag
#

unfair**

#

Sorry, typo

torpid ore
#

At the time being subs with a 7+ day streak can access it...

vital stag
#

Yeah, but only until june 5th

cerulean wraith
#

until june the 5th

torpid ore
#

yes

#

It is designed to be for the business side, so we're lucky to even get 24 days!

cerulean wraith
#

task one of this network clearly explains why

vital stag
cerulean wraith
#

does not feel like copying all of task 1:s text out here

cerulean wraith
normal ocean
hazy lodge
#

Anyone would help me just to get started with this challange in pm?๐Ÿ˜•

normal ocean
cerulean wraith
cerulean wraith
#

would mean being able to do the aws path too

warped eagle
lyric stream
hazy lodge
#

Not the engagement, the "registration"

pseudo parrot
warped eagle
vital stag
lyric stream
normal ocean
#

The reason why you might feel it's no fun anymore is because you're getting in this "forced" behavior

hazy lodge
trim beacon
normal ocean
# warped eagle forced?

The thoughts that you have to complete a task, that you have to do the newest room, and have to keep on learning

warped eagle
pseudo parrot
#

Do you have a subnet on your network diagram?

hazy lodge
#

I have, i see the vpn and webmail

pseudo parrot
#

Ok, then replace the xxx with your details.

#

So if you're in 10.10.10.10

You simply just replace the xxx.xxx.xxx.250 with 10.10.10.250

hollow ember
#

Can premium members bypass the streak, and can individual users purchase access after the 5th of June?

pseudo parrot
#

Only business customers will have access to the network after that time is up.

hollow ember
#

Damn, thats really unfortunate

hazy lodge
pseudo parrot
hollow ember
#

Missed the streak due to moving house :p

empty dome
#

7 day streak for premium users too??

pseudo parrot
#

Yes.

cerulean wraith
#

yuup

#

not a problem for most people probably

high ice
#

I guess it's so you're all beta testing it for business users which is a positive sign for it working well at launch. Has anyone started it yet? Is it as broken/buggy as Holo & Throwback?

cerulean wraith
#

shadow was left out because they focused on school work

#

so seems like it is working as intended

pseudo parrot
#

Yes, Shadow is correct.

I've had a 2 week head start(alongside Bella and jayy), (so right now I'm not doing it as I know how to get some of the flags)

However anything that didn't work was fixed.

tardy wharf
#

It has also been tested internally prior to that ๐Ÿ™‚

pseudo parrot
#

Yup

tardy wharf
#

That isn't to discount the fact that there's potentially going to be some strange things happening of course ๐Ÿ˜„ Networks always have their own surprises when you have multiple people trying different things at the same time

pseudo parrot
#

Just blame it on DNS

sturdy kestrel
#

7 day streak makes sense just sucks having to wait after getting the email and looking forward to it since I haven't been so active the past month. I have a 365 day streak and took a mini break after that.

trim beacon
trim beacon
high ice
tardy wharf
trim beacon
sturdy kestrel
cerulean wraith
slender verge
#

I am probably blind or something, but I have no IP such as x.x.x.250...

pseudo parrot
#

Did you read task 2?

#

Specifically that part.

slender verge
#

I had read it... and it didn't click until now ๐Ÿ˜…

trim beacon
pseudo parrot
#

If not jail, a heft fine.

lyric stream
#

Tib3rius is now live-streaming our new Red Team Capstone Challenge Network ๐Ÿ”ฅ

Watch live: https://www.twitch.tv/0xTib3rius

Twitch

Professional pentester since 2012, specializing in web app security since 2014. Developer of AutoRecon. Creator of Linux & Windows Privilege Escalation courses on Udemy & Hacker's Academy. Streaming mostly HTB/ THM boxes, plus Web Academy challenges.

โ–ถ Play video
pseudo parrot
high ice
#

That's a VOD from last month

trim beacon
#

He said "soonish", think he is just getting final setup ready ๐Ÿ™‚ Give him a minute or two or three ๐Ÿ˜‚

vale pewter
#

will the streams be recorded and published on YT later. Asking just in case we miss out on completing the room.

pseudo parrot
#

Doesn't twitch have VoD?

cerulean wraith
pseudo parrot
#

Unless you can change it by video/video basis.

cerulean wraith
#

think he also uploads it to youtube anyways

cerulean wraith
trim beacon
solemn lava
#

Hi, I read an announcement saying that there is gonna be a "limited time" event.
This network will stay though right?

pseudo parrot
#

No.

pseudo parrot
#

which is current;y 24 days 18 hours, 10 min(s)

solemn lava
#

So after that it wont be free or it wont be available at all?

pseudo parrot
#

Only to business customers.

cerulean wraith
#

the videos and writeups will still exist though

solemn lava
#

Okay, thanks.

cerulean wraith
#

i.e you got until june the 5th to do it

trim beacon
#

Stream has started ๐Ÿ™‚

cerulean wraith
#

neat time to chill with this stream instead of the usual game stream

pseudo parrot
#

Anyone got a flag yet?

gusty stag
#

Can it be played with premium If I don't have streak?

pseudo parrot
#

No,.you need a streak.

cerulean wraith
#

lol typo squatting

tacit scaffold
#

Is the competition till 31 May or 5th June?

#

Also does it count to our monthly/overall score?

pseudo parrot
#

31st of May.

#

I think so, as it has blood points I'm sure.

tacit scaffold
#

So the writeup competition is between 31st May and 5th June?

pseudo parrot
#

Unsure.

hidden galleon
#

Starting now, submissions end 31st, we announce winners June 5th

#

How fast you submit does not matter, as long as you submit before May 31st

#

Quality report writing will get you the win

tacit scaffold
#

Oh so the submission is for some portal you offer, not in pubilc

hidden galleon
#

We're using the normal writeup feature, best 3 reports will get published on official blog.

tacit scaffold
#

Hmmmm
I don't understand
If there is a competition going on
Shouldn't any type of write ups be restricted?

#

Like in ctfs

lyric stream
grave sable
brittle badgeBOT
#

Gave +1 Rep to @grave sable

tacit scaffold
hidden galleon
#

You get points for the room flags, the competition itself does not give you points - we do have cool prizes though, like subscription vouchers and special custom swag!

vale pewter
trim beacon
trim beacon
pseudo parrot
cerulean wraith
#

same

#

it is decently fun

lofty dove
pseudo parrot
#

You do it for the experience.

lofty dove
#

And points ๐Ÿ˜„

cerulean wraith
#

what about badges????

lofty dove
#

Sheeeeeeiiiiiit you're right. I gotta get the badge!

#

Imagine if I got a discord badge too if I get it.

#

โค๏ธ

#

If I cancel an nmap scan half way through do I get the results still? I forgot.

pseudo parrot
#

No?

lofty dove
#

Dang. Scrubz I told you have done 0 red team things since I started THM :3

pseudo parrot
#

Maybe, now is a good time to start before you try this ๐Ÿ˜„

lofty dove
#

It's going to take me longer than 24 day pepehands

trim beacon
#

It is sitting there quite pretty...

cerulean wraith
#

think this is one of the few badges that will get unobtainable eventually

cerulean wraith
trim beacon
warped eagle
trim beacon
warped eagle
#

well I have 32/40 bages and at least 2 of the badges I have completed all the requirments but did not receive the badge for it bummer

cerulean wraith
cerulean wraith
#

or well that was the case around 6 months ago

#

dunno if it changed

hidden galleon
#

I'd be interested to hear details, dm please?

hidden galleon
pure parrot
#

Hey I just wanted to say to the creator of the network, I'm really enjoying all the work you put into this! I'm still struggling to get initial access, but I'm learning a lot in the process. (:

trim beacon
brittle badgeBOT
#

Gave +1 Rep to @pure parrot

pure parrot
cerulean wraith
#

or do the shadow and wait until the competition is mostly over and use other peoples writeups to get all the info you need....... probably not the best course of action but ey shadow is at least learning something from it

pure parrot
#

I'd like to get as far as I can without it haha.

#

But totally fair (:

pseudo parrot
#

You'll definitely learn something new.

pure parrot
#

I mean, that's the whole point of this platform right?

cerulean wraith
#

at minimum shadow will learn what more true to life reports of red teaming or pentesting would look like

#

but shadow is more leaning on this being a huge list of new information for them

pure parrot
#

Do you always refer to yourself in third person?

cerulean wraith
pure parrot
#

Fair enough, I respect that

lyric stream
clear badger
pure parrot
brittle badgeBOT
#

Gave +1 Rep to @clear badger

frail spade
#

This has probably already been covered; but if some hero could save me from endless scrolling.
This requires 7 day streak... BUT also says 'subscribers only'. All good.. Im a paid subscriber, but dont have a 7 day streak (life and such).
So even as a paid sub, i ALSO need to have a 7 day streak? - not like other rooms where its one or the other.

#

..never mind i think i managed to find the answer above; you need BOTH a sub AND a streak yeah?

frail spade
#

Better get moving then blobfingerguns see you all in a week

cerulean wraith
#

good luck and have fun

cerulean wraith
frail spade
#

Thanks @cerulean wraith appreciate the tip. Probably all good with the skillset, but plenty of rooms on THM to keep have me sorted ๐Ÿ™‚

brittle badgeBOT
#

Gave +1 Rep to @cerulean wraith

lyric stream
brittle badgeBOT
#

Gave +1 Rep to @lyric stream

lyric stream
#

Tyler Ramsbey is now live-streaming our new Red Team Capstone Challenge Network ๐Ÿ”ฅ

Watch live: https://hacksmarter.live

You can also watch on replay here: https://www.youtube.com/c/TylerRamsbey

Twitch

Welcome to the Hack Smarter Twitch stream! This stream is managed by Tyler, Nate, Josh, and KaliMax. We will be streaming hands-on hacking through TryHackMe, HackTheBox, VulnHub, and various other platforms. Enjoy!

โ–ถ Play video
quaint knot
#

Hey friends -- I am LIVE on Twitch to start the challenge. Grab a black hoodie, boot up Kali Linux, and let's take down the bank!!!!!!!!

slender verge
#

no one has the first flag?

trim beacon
slender verge
#

oh for sure, and it's waaay beyond me, just somewhat surprised

trim beacon
slender verge
#

probably not ready, I'm not all done with the red teaming path, but I'm trying anyway, it's a lot of fun

warped eagle
#

I was bummed out anticipating the release and when it finally comes out aww sorry you not allowed to access the network

lyric stream
warped eagle
lyric stream
slender verge
clear badger
slender verge
#

if it can be done by stubbornness alone ๐Ÿ˜

clear badger
slender verge
quaint knot
#

The full recording of the stream for those who missed it live:
https://youtu.be/xrh3g5VjY6Y

This is the first video working through the "Red Team Capstone Challenge" by TryHackMe. This is an in-depth network challenge simulating a Red Teaming engagement. The challenge includes several phases structured around the cyber kill chain that will require you to enumerate a perimeter, breach the organisation, perform lateral movement, and fina...

โ–ถ Play video
digital plaza
quaint knot
brittle badgeBOT
#

Gave +1 Rep to @digital plaza

hidden galleon
austere oriole
#

I have a problem verifying my first flag

#

even though I did what it asks :|

#

Can i get some help tyvm

trim beacon
#

I can see your active submission ID, so now you just need to follow the instructions, but DM me and I'll help

#

We have our first breach flag submission! ๐ŸŽ‰ ๐ŸŽ‰ ๐ŸŽ‰

pseudo parrot
#

Woooo!

normal ocean
#

Woop Woop!!

pseudo parrot
#

Was it Hmmmm?

austere oriole
#

yes

normal ocean
#

Niiiice, good job

pseudo parrot
#

Good going!

#

I'm curious how you done it, we can catch up after the event ends ๐Ÿ˜„

normal ocean
#

then it's good that there's a writeup competition too, meaning we can read peoples writeups!

#

so remember to keep notes people, you might need them later ๐Ÿ˜‰

pseudo parrot
serene crystal
#

I can't reach any of the systems at the moment, is there a known problem at the moment ?

hidden galleon
#

Shouldn't be, what are you seeing on the network diagram?

serene crystal
#

I see the servers in the DMZ but I can't see the web page on 13 or 11. I was able to access both of them earlier and now I can't access any of the services

hidden galleon
#

Can you refresh the room page and see it the network is still up?

pseudo parrot
#

^ That was a pain for me, I had to set a timer in the end.

serene crystal
#

It still shows as up, and 36 mins left

pseudo parrot
#

If MartaS doesn't kind, can you send me a pic of the webpage you're trying to view? (dm)

#

This is something I could possibly help with.

serene crystal
#

I'll try again later

fossil harbor
#

Hello everyone!
I have question about red team capstone challange.
I don't have learn read team path, to learn that it will take 1 month for me. I afraid it said limitied time. But how many tme can I access to that challenge?

tepid sapphire
#

competition we are running until the 31st of May 2023!

fossil harbor
serene sedge
austere oriole
#

been months since i worked on anything related to red teaming

hidden galleon
austere oriole
#

I'm just looking on my notes and going "Yes, i forgot all that"

pseudo parrot
hidden galleon
#

^ After June 5th

pseudo parrot
#

Oops!

Thanks.

fossil harbor
pseudo parrot
uneven relic
#

I'm having trouble registering for the Capstone challenge on the e-Citizen system - it is asking for my THM username which is dave.taylor however when I enter this it is saying it's not allowed as my username shouldn't contain any symbols. What should I do?

#

ie the . in my THM username seems to be an issue...

pseudo parrot
#

You don't need your exact username.

uneven relic
#

Ah ok - so I'll just register with similar without the dot then ๐Ÿ™‚

pseudo parrot
#

Yeah. ๐Ÿ™‚

uneven relic
#

Thanks! ๐Ÿ‘ Wasn't sure if this would be significant so thought I'd ask ๐Ÿ™‚

pseudo parrot
#

How many flags now!?

austere oriole
#

laggy af tho

pseudo parrot
#

When i done it wasn't.

I hope it stays

trim beacon
# austere oriole laggy af tho

That delay is intentional... Specifically forcing y'all to read and not just skip through instructions ๐Ÿ™‚ Although I know it can become annoying

broken marsh
#

im very bummed out you need 7 day streak. I wanna get started ๐Ÿ˜…

pseudo parrot
broken marsh
#

Been a while since I was on THM, but this new room got me back

#

So just starting it today

pseudo parrot
#

6 days to go!

Do the red team path whilst you wait. ๐Ÿ’ช

trim beacon
austere oriole
#

why do we keep over thinking stuff

normal spire
#

yikes i gotta do this before it goes away

#

but need to get a streak

pseudo parrot
#

Yup!

austere oriole
#

the machine reset and i can't connect to anything anymore

#

any fixes? @_@

lyric stream
austere oriole
#

10.200.89.0/24

lyric stream
#

Let me check.

lyric stream
# austere oriole 10.200.89.0/24

Can you DM me a screenshot of the Network Diagram, which shows the Network state and the three buttons below the diagram in the room?

austere oriole
#

sure

lyric stream
#

We're cautious with this as we don't want to spoil the challenge. We're looking into it. ๐Ÿ™

heavy crag
#

Ok I can delete or "Spoiler"- should I come back to this later when it's fixed? Please advise.

lyric stream
heavy crag
#

Thanks I will delete my post too -thank you@

broken nest
#

Im just curious why would you set up a 7 day hacking streak a must to access that challenge, why being sub is not enough?

slender verge
broken nest
#

Are 7 days of streak add any income to them? Its the subscription

#

Its hard to keep that streak going once you landed 1%+

pseudo parrot
#

It's not though

#

It's really easy.

slender verge
#

You can just reset a room

broken nest
#

Im not ok just login to site and clicking the single answer or reset the room for the sake of keeping that streak

pseudo parrot
#

There are plenty of rooms you can do, anyway, this is not the channel for that discussion.

It's up to you if you want to build the streak and join the room.

broken nest
#

I can agree on that, but after 200+ rooms and all completed paths a lot of people just occasionally come by for new releases. And im one of those. I will build that streak anyway for the sake of the lab , i just dont feel that it was such a necessity if you have a subscription.

lyric stream
serene sedge
lyric stream
serene sedge
#

All right, thanks for the fast response! I hope it will get resolved ๐Ÿ™

lyric stream
serene sedge
#

Network is restarting rn

lyric stream
lyric stream
serene sedge
viral yew
#

is anyone having issues loading the challenge page?

#

ok, its something on my side

clear badger
#

If you find that a certain path is not working for you, rest assured that this network has been carefully designed so that if one path has been cut off, there are multiple paths that are also available. That doesn't mean we are not looking into why a particular path isn't working, but having more than one way to achieve something will benefit you greatly in this network.
We appreciate your patience ๐Ÿ™‚

viral yew
#

I feel like I am already doing something and missing the initial flags

cerulean wraith
#

flag 20 is the goal

viral yew
#

@trim beacon is it possible to do a sane check?

cerulean wraith
#

or is one of the goals

#

the other goal is a good written report on how you exploits it

viral yew
#

well, I am taking notes so

#

:p

#

So I am having trouble accessing the network resources.

#

Network state is running

#

but cant reach the machines

#

Can someone help?

#

trying to recreate the mailbox I get "No route to host"

clear badger
#

@viral yew feel free to DM me

lyric stream
trim beacon
viral yew
#

hey @trim beacon , it was ๐Ÿ™‚

#

but can I DM you for a sane check?

#

not asking for hints

trim beacon
#

Jip, happy to listen ๐Ÿ™‚

thin void
#

where is the capstone located at? lol I have a 40 day streak but don't see the red teaming capstone

thin void
#

dont see it on the dashboard

lyric stream
#

Have to be a subscriber.

thin void
#

found the challenge through a blog.

#

so we only get 6 days worth?

serene sedge
#

No, u have access til june 5

serene sedge
thin void
#

yea I thought it meant that

#

sorry

#

sleep deprived lol. Newborn + overworked

viral yew
#

3 flags so far, I am having a blast!

clear badger
lyric stream
brittle badgeBOT
#

Gave +1 Rep to @clear badger

trim beacon
#

Hey all super happy to see that some of you have gotten some flags!

Just two things from my side, when you compromise a host, go and authenticate to e-citizen to submit proof of compromise. That will get you your respective flag.

Secondly. Use good old command prompt to create your flag (or even notepad). Powershell echo is different (| instead of >) which can add a null byte, which will make e-citizen not verify the proof

trim beacon
# serene sedge I'm sorry for all the troubles, but i'm still experiencing issues ๐Ÿ˜ฆ

Was this issue resolved? If not, just DM me your VPN internet IP and a bit later today I'll take a look.

When the network resets it goes back to its base state. From there, config scripts execute to have it saturate the values of the network's specific subnet. Some of this saturation, like changes routes, DNS, or connections, takes a bit longer (5-15 minutes) and if users already start using them during this saturation period, it can make them unstable or not saturate config at all. But nothing a quick manual force can't fix

viral yew
#

yeah, I got some issues when the network resets sometimes

#

the major issue is that the routes are not applied correctly

#

for example, the network was resetted now, and I cant reach the machines

trim beacon
#

I would also recommend fewer resets, reset only when you are sure there is an issue. Reseting won't make the challenge easier sadly ๐Ÿ˜…

viral yew
#

I didnt reset it

#

the time was over

trim beacon
trim beacon
# viral yew the time was over

That will just required a restart. But make sure to read the note in bold. If you don't refresh the page before clicking start after the network stopped. It will be locked for the time on the timer

viral yew
#

I always do a refresh

trim beacon
# viral yew I always do a refresh

As discussed on DMs, also just give it 2 minutes. If AWS is still stopping the network while you give the Start signal, it can cause a clash

#

If your network stops, it is nature's way of telling you to take a leg stretch break ๐Ÿ™‚ Red teams are marathons, not sprints

brittle wagon
#

Can't seem to access the machines due to routing issues. Can anyone help?

frosty bluff
#

@trim beacon I'm having issues with my corp connection, being reset in a loop. The Capstone connection is stable, any ideas?
Thanks,

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

viral yew
brittle wagon
#

This normal? Will I have to repeat this process from time to time?

viral yew
#

it is not normal. Apparently, when the network stops, we should give it a couple of minutes before refreshing the page and starting it again, and then a couple of more minutes for the network to stabilize

#

failing to do so might lock the network in a state where the machines are offline

#

im runing out of ideas, might as well go to bed

#

๐Ÿ˜ฉ

quaint knot
#

Hey friends!

I am LIVE again on Twitch working through the Red Team Capstone Challenge by TryHackMe. I am by no means an expert, but am focused on going slow and learning through the process. If you'd like to hack alongside me, come join & let's learn together.

TIME TO HACK THE BANK!

https://hacksmarter.live

trim beacon
quaint knot
#

Full recording of the second stream. We also explain the intentional instability @trim beacon is referring to above in the video. If you watch it right when I post it, quality might be bad because YouTube is still processing the HD version ๐Ÿ™‚
https://youtu.be/TUyYUSr0O_Y

This is the second video working through the "Red Team Capstone Challenge" by TryHackMe. This is an in-depth network challenge simulating a Red Teaming engagement. The challenge includes several phases structured around the cyber kill chain that will require you to enumerate a perimeter, breach the organisation, perform lateral movement, and fin...

โ–ถ Play video
serene sedge
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

austere oriole
#

the subnet 10.200.89.0/24 works fine please dont reset

#

๐Ÿ˜ข

torpid ore
#

@smoky breach What IP? .11, .12 or .13 ?

smoky breach
#

13

torpid ore
smoky breach
trim beacon
#

We went through two months of QA testing without a single reset. This network is really stable. The biggest issue we had was once a DNS issue krept in after the DC ran for a straight 10 hours. But even then just letting the network sleep and then start again solved the issue. We are seeing a high number of resets. I do mean this in the nicest way possible, resets are not going to make this challenge easier

pseudo parrot
#

Yeah, that was our issue also.

Network was fine unless it was reset.

ornate turtle
#

I am not a subscriber but I am considering to subscribe just for trying this. Please let me know how this network has been so far. If you guys were able to learn something new or cool. Would love to hear some feedbacks on it. Thanks!

wild pier
#

Hello, I just got back back from 1 week vacation and wanted to do this nice red team capstone challenge. Now it is blocked by a 7 day streak what is really frustrating. I'm a paying customer for years and in global top 100 what shows my commitment so I would really appriciate the possibility to start with this room. Is there anybody here from THM that can activate this?

pseudo parrot
trim beacon
#

Just email support

trim beacon
#

Thought I'd share the leaderboard thus far. For anonymity, only publishing the first letter of your username. You know who you are ๐Ÿ˜‰

  • First Place: M - 8 flags ๐ŸŽ‰
  • Second Place: Joint S and a - 4 flags
  • Third Place: J - 3 flags

Even if you start late, still have a chance in the competition!

clear badger
#

Ohhh ๐Ÿ˜ฎ letโ€™s go!!

normal spire
#

i think i'll just participate to play it since it seems really interesting but not compete

trim beacon
normal spire
#

question, once your like 6 days of access runs out do you need a new streak to rejoin

hidden galleon
serene crystal
#

I must say I'm enjoying the challenge. The problems with the networks where come hosts go down then others go down is brilliant. Thanks @trim beacon

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

viral yew
#

that is the same leaderboard?

trim beacon
viral yew
#

ok ok ๐Ÿ™‚

trim beacon
viral yew
#

gonna work for a couple of more later this night ^^

trim beacon
viral yew
#

Tnks

#

I am having a blast so far

south mirage
#

I think I made the mistake of starting the network back up too fast after it stopped and now none of the hosts is responding :/
Will this fix itself after the timer ran out again?

serene sedge
trim beacon
south mirage
frosty bluff
#

question, just got back at it and I noticed that my Corp VPN is giving me the 172.x.x.x IPs for the routes. So, what should I do, as I did not start the network, it was already running for less than 30 mins. I know @trim beacon, said this is the stabilization issue.

quaint knot
trim beacon
# frosty bluff question, just got back at it and I noticed that my Corp VPN is giving me the 17...

Sorted in DMs. For others, since it seems that this is the path most taken, I'm balancing the "breach meta" and saying that users need to figure this out. If the VPN is pushing down the wrong routes, what is stopping you from pushing down different routes yourself? Since this is the most taken path of breach, going to now request users to fix this themselves to push more users to the other attack paths

quaint knot
#

Full recording from today's stream. I was able to compromise the first 3 flags so please do not watch if you don't want a spoiler/massive hint ๐Ÿ™‚
https://youtu.be/svdhIyifHC8

This is the third video working through the "Red Team Capstone Challenge" by TryHackMe.

This is an in-depth network challenge simulating a Red Teaming engagement. The challenge includes several phases structured around the cyber kill chain that will require you to enumerate a perimeter, breach the organisation, perform lateral movement, and fi...

โ–ถ Play video
smoky breach
#

I found new ovpn

sudo openvpn new.ovpn (i run code)

"Initialization Sequence Completed" Done.

But why again again ~~ "Restart pause, 1 second(s)"
is bug?

#

plz help me

austere oriole
#

Spoilers

smoky breach
tall imp
#

Very disappointed to find out that I still need a 7-day streak to join this room even though I pay for a premium membership.

pseudo parrot
tardy thicket
#

internal VPN is pushing public ip routes after network restart?

tardy thicket
#

Yeah got it! Tnx

smoky breach
#

2023-05-14 10:49:01 Initialization Sequence Completed
2023-05-14 10:49:10 Connection reset, restarting [0]
2023-05-14 10:49:10 SIGUSR1[soft,connection-reset] received, process restarting
2023-05-14 10:49:10 Restart pause, 1 second(s)

how can i fix it? Do you know anyone??

  • two ip is 172.x.x.x not 10.x.x.x
smoky breach
pseudo parrot
#

Did you change the x?

smoky breach
#

yes, change it
1.)sudo gedit corpUsername.ovpn

2.) and change that -> remote 10.200.x.x 1194 -> remote 10.200.116.12 1194
3.) save and, run command -> sudo openvpn corpUsername.ovpn

4.)
2023-05-14 10:49:01 Initialization Sequence Completed
2023-05-14 10:49:10 Connection reset, restarting [0]
2023-05-14 10:49:10 SIGUSR1[soft,connection-reset] received, process restarting
2023-05-14 10:49:10 Restart pause, 1 second(s)

5.) two ip is 172.x.x.x not 10.x.x.x

#

4.) <----- just again again again show me

#

I haven't done anything for two days because of this.
I want to solve this problem, please.

viral yew
#

You need to add the routes manually

#

That is what I do

#

Delete the routes of 172.x.x.x

#

Add the routes of 10.200.x.21/22 manually

#

And you are good to go

#

The connection reset is not an issue

smoky breach
#

How can I do that? If I knew that, I wouldn't have asked

#

And, I copied Tyler's YouTube video exactly the same. By the way, he works fine without any problems and why should I change something?

smoky breach
torpid ore
#

You need to research

smoky breach
smoky breach
#

172.x.x.x Even if I delete it, it's still the same.

#

4.) again show me
and 172.x.x.x

small talon
#

We are just the beta testers for the business customers ๐Ÿ˜•

smoky breach
#

ahhhh

smoky breach
smoky breach
narrow charm
smoky breach
torpid ore
#

It's not lucky, you just need to figure out how to fix the VPN file

#

Remember that this is a challenge room

clear badger
smoky breach
#

i see youtube Tyler was connects right away without any settings

#

why can't i...

#

sooooo sad

#

I've been stuck on this for three days

red yarrow
cerulean wraith
#

do not blame or praise shadow for testing this though as shadow was focusing on their national tests in swedish 3 during the testing phase so have not done any of this

quaint knot
smoky breach
brittle badgeBOT
#

Gave +1 Rep to @quaint knot

small talon
pseudo parrot
#

With the price structure, I doubt it.

red yarrow
# small talon There has to be a way to make it available after the 30 days to non-business cus...

This network is 10x bigger than Throwback, it would be incredibly expensive to run publicly, we have ran the numbers and it wouldn't be sustainable. Furthermore, business users have a different support pipeline that is able to handle supporting this network.

We do love our community, and we will never forget where we came from, we are looking into what we can do for our non-business members. And there are plenty more updates down the road that everyone can benefit from ๐Ÿ˜‰ ๐Ÿ˜

trim beacon
#

Leaderboard for Day 3:

+----------+-----------------------+
| username | Flag Submission Count |
+----------+-----------------------+
| M        |                     8 |
| a        |                     7 |
| S        |                     6 |
| J        |                     5 |
| j        |                     4 |
| m        |                     3 |
| u        |                     3 |
| T        |                     3 |
| s        |                     3 |
| S        |                     3 |
| p        |                     3 |
| m        |                     3 |
| K        |                     3 |
| H        |                     3 |
| d        |                     3 |
| d        |                     3 |
| d        |                     3 |
| B        |                     3 |
| a        |                     3 |
| K        |                     2 |
| N        |                     1 |
| n        |                     1 |
| h        |                     1 |
| S        |                     1 |
+----------+-----------------------+
solemn knot
pseudo parrot
#

I've been doing the network, but I haven't entered any flags.

#

I'll enter em in at the end.

trim beacon
#

Cause you can submit up to flag 8 without ruining first bloods for the competition participants

pseudo parrot
trim beacon
#

Might just be other users kicking you out, so might have to take an approach different than just RDP, which is single user use

pseudo parrot
#

It was.

stone spire
trim beacon
pseudo parrot
#

I like to use CrackMapExec just to confirm I have a login.

stone spire
viral yew
stone spire
#

quick Q. is it allowed to delete services that windows running ?

digital plaza
#

@quaint knot I know you are taking a very methodical red team approach through the capstone, is there any chance you might also write a mock report at the end? I think that would be extremely cool and insightful

lusty gazelle
#

is the network down for anyone else?

quaint knot
lusty gazelle
#

having an issue. Anyone else get this error when verifying your newly created email account?

quaint knot
trim beacon
lusty gazelle
trim beacon
quaint knot
#

Day 4 recording... I don't want to share too much, so as not to spoil the network. But I demonstrate some reverse shells... privilege escalation... and port forwarding. Enjoy ๐Ÿ™‚
https://youtu.be/qr8eGM1zhV8

This is the fourth video working through the "Red Team Capstone Challenge" by TryHackMe.

This is an in-depth network challenge simulating a Red Teaming engagement. The challenge includes several phases structured around the cyber kill chain that will require you to enumerate a perimeter, breach the organisation, perform lateral movement, and f...

โ–ถ Play video
trim beacon
#

The bank has fallen!

Congrats to @south mirage who is our SWIFTest hacker after four days on intensive hacking! Fully compromising TheReserve and transferring 1 million dollars!

Who will take the coveted second and third place?

Also, don't forget that speed isn't everything! Even if you don't make the first three places, we have another competition for the three best writeups of the challenge and some runner ups! Let it rain shells and dollars! Best of luck to everyone

south mirage
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

torpid ore
#

Woahh 4 days! That's impressive!

vast pebble
#

helo

#

can someone help me`? i can't join the room, it says i need 7 day streak, which i had (i am able to access all other rooms that require 7 days streak), is this a known issue?

pseudo parrot
#

What is your current streak?

vast pebble
#

0?

#

so its current streak.. why??

pseudo parrot
#

When was the last time you had a streak?

vast pebble
#

i don't know, let me check

pseudo parrot
#

AFAIK.

You need a streak of 7 or more at time of release.

#

Any streaks before the room release won't be counted.

vast pebble
#

oh...

#

so i've got 20 days to get a 7 days streak and jojnthe room,

pseudo parrot
#

Yup ๐Ÿ™‚

#

Someone already has all 20 flags, but AFAIK, 2nd and 3rd are still possible.

vast pebble
#

i don't care about prizes

pseudo parrot
#

๐Ÿ˜„

#

Then you'll have plenty of time.

vast pebble
#

i just can't get my head ove rthe fact that they're switching to business only content...

pseudo parrot
#

It's due to how this network is designed, it's not cost effect to run it on the normal sub plan.

vast pebble
#

well, what about having it available for purchase just like other rooms?

pseudo parrot
#

Because the cost would be too great, I think.

Also, the business account has support that is more structured to this type of network,

#

This network is 10x bigger than Throwback, it would be incredibly expensive to run publicly, we have ran the numbers and it wouldn't be sustainable. Furthermore, business users have a different support pipeline that is able to handle supporting this network.

We do love our community, and we will never forget where we came from, we are looking into what we can do for our non-business members. And there are plenty more updates down the road that everyone can benefit from

#

From Jabba.

lusty gazelle
#

Is there tech support I can DM in here in regards to email authentication for the capstone?

pseudo parrot
#

You having issues?

lusty gazelle
#

yes. Having issues authenticating to my inbox

pseudo parrot
#

Has the network been reset lately?

I'm not sure Amo3 is here just now.

lusty gazelle
#

I think it has been, yes

pseudo parrot
#

What error do you get when you and authenticate?

viral yew
#

so hard to get access on a DC and someone just reset the network ๐Ÿ˜ฉ

austere oriole
#

Subnet 10.200.89.x please stop reseting the network

#

Its the 3rd time now

hidden galleon
#

So ssh to e-citizen -> authenticate -> recreate mailbox

vast pebble
#

no

real lark
#

I was about to yell ๐Ÿ˜‚

#

I may not have scrolled up far enough.

vast pebble
#

but the fact that they're building content business only marks a change in how they'll operate

pseudo parrot
#

Not at all.

#

There's still over 200 waiting for be QA verified so they can be released.

#

That's not including in house content.

real lark
#

Nah lol I get what you mean but it'd be a dumb business move with a lot of people willing to learn or at least give it a try.

#

I started with no experience about 9 ish months ago properly. THM has helped a ton in that time. Didn't even know how to work a Linux terminal lol.

austere oriole
#

why are people resetting the network

lyric stream
#

Deleted your third image, as it is not quite appropriate @austere oriole Do you think the reset count (number of votes needed) should be increased?

austere oriole
#

I think it should

#

people will face minor inconvenience and reset the whole network for it :|

viral yew
#

idd

normal spire
#

3 more days then i have 7 days of streak!

viral yew
#

Ready to show impact

viral yew
#

any mod for an explanation?

lyric stream
viral yew
#

Can I DM?

lyric stream
#

Yeah go ahead. ๐Ÿ™‚

viral yew
#

Can I post my network here?

#

Completed

normal spire
#

congrats!!

quaint knot
viral yew
#

I still feel that dopamine rush

#

I should go to sleep since I'm gonna work tomorrow morning, but I can't ๐Ÿ˜‚

#

btw my current network is up and running for 10 hours straight

#

which is awesome, since I got like 2 resets in the morning

clear badger
#

Congrats! ๐Ÿพ๐ŸŽˆ๐ŸŽ‰๐ŸŽŠ

normal spire
#

ahhh 3 more days i am really looking forward to this but i'm worried i'll get stuck

rigid talon
#

having probs with setting up of email account (using evolution in linux terminal) - have entered all the creds as supplied in initial briefing but keeps giving error message ... frustration as have made progress into internal network but when i goto validate the e-citizen portal says will send email with flag detail - am unable to receive them

#

could an admin pls check my creds at thier side ...

#

and BIG THANK YOU to am03bam4n for such an EPIC adventure !!!!

#

this is my fav thing i've ever done with THM !!!

viral yew
#

that was, by far, my favorite room/lab on tryhackme.

deep hearth
#

Verifying the flag fails for me and I get the following: "Issue with reading the file provided: 'utf-8' codec can't decode byte 0xff in position 0: invalid start byte" Any suggestions?

viral yew
#

Use cmd

#

Instead of powershell

#

Or make a text file by hand

deep hearth
brittle badgeBOT
#

Gave +1 Rep to @viral yew

hidden galleon
#

You need to ssh to e-citizen -> authenticate -> recreate mailbox using option 3

rigid talon
brittle badgeBOT
#

Gave +1 Rep to @hidden galleon

rigid talon
brittle badgeBOT
#

Gave +1 Rep to @hidden galleon

trim beacon
#

The results have been confirmed in e-citizen! @viral yew is our second SWIFTest red teamer! Congrats! ๐ŸŽ‰

Who will take the third place?

Remember even if you don't make the first three places, we have another competition for the three best writeups of the challenge and some runner ups! Let it rain shells and dollars! Best of luck to everyone!

viral yew
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

trim beacon
normal ocean
#

it's a nice network!

stiff oracle
#

Congratulations on completing the challenge Azkrath can I ask how long you bin doing this sort of work thanks

viral yew
#

I've been working in security for almost 4 years now, but have been in IT for the past 18

pseudo parrot
viral yew
# pseudo parrot What did you think of the flag system?

enjoyed a lot. Way better than typical text files as you need to "prove" the ownership. The next step is to find a way of randomize the flag based on the user providing the proof (for example, if the user was the same between the e-citizen and the THM, you could use the username to generate a unique flag and then validate the flag on the platform against the username that is inserting it).

#

that way it could mitigate the release of flags in public or writeups

#

but there is not an easy way to tackle this "problem" tho

pseudo parrot
#

I can't say too much about what I know, other than that.

viral yew
#

but yeah, definitely it is a good improvement to the typical system

#

enjoyed a lot

pseudo parrot
#

I hope it comes in to place for many future rooms.

normal ocean
#

same

viral yew
#

yeah, that would be excellent

lusty gazelle
#

Is there anyone available to help remedy this issue? I can not connect to webmail server. I've tried verifying email address and I get this error below.

trim beacon
rigid talon
#

any admins able to help please? have made couple attempts to verify this flag but keep getting error mess saying there's an issue with reading the file -

#

(it's not letting me paste screengrab - am happy to DM)

trim beacon
rigid talon
#

ah, okay - cools thanks - an using PS

#

cheers !!!

trim beacon
rigid talon
#

๐Ÿ™‚

trim beacon
#

In powershell I think the command would be echo UIDFlag | C:\Windows\Temp\username.txt but typing from memory so might be missing something

rigid talon
#

thanks so much am03bam4n - worked a treat in cmd - much appreciated (and thanks for such an AMAZING network !!!!)

trim beacon
rigid talon
#

thanks - will bear that in mind - much appreciated, cheers!!

tardy sage
#

Hi guys, I have a problem with 10.200.X.21 VPN domain. I can ping and access any (Web, WebMail) address, but the VPN website is no longer working. Yesterday it was still working. I have also successfully connected to the Capstone network.
Can anyone help me with this problem?

tardy sage
#

Because I think I got banned

stone spire
#

might just be the case that vpn server is bonked. did you try to ping it ?

tardy sage
#

Yes I do

#

I accidentally scanned the wrong IP address. Do you know how to get unbanned

stone spire
#

not sure for that. might try vote to reset network

tardy sage
#

I have had the VPN file generated several times and it does not work on the Attack Box either. But yes I could vote for it

trim beacon
fossil bobcat
#

can i get a sanity check ||trying to rdp into .21 but it's not up. i have employees vpn on as well. also was able to run nmap scans against it last night but now i'm unable to connect. openvpn connection log also shows a different network ip 172.32.5.21 from the first time i connected but that also doesn't work||

hardy hull
#

Subs to THM but still needs a streak to join room???????????????????????????????????????

cerulean wraith
hardy hull
#

...

#

completed that like months ago

#

like when it was first released

slender verge
#

The initial announcement said people should keep up their streak

torpid ore
#

๐Ÿ‘ You still have time to do it!

quaint knot
#

For those following my nightly live stream through the "Red Team Capstone" network by TryHackMe -- I will be taking tonight off. Unfortunately my son is sick, which means I got about 3 hours of sleep last night. I will not be speaking coherently if I stay up as late as I usually do and then go live for everyone to watch ๐Ÿ˜‚

I'm planning on going to bed early tonight, and then the stream will be back tomorrow at 9pm CST.

slender verge
stone spire
fossil bobcat
torpid ore
#

@quaint knot Hope your son feels better soon, just a heads up - your invite link seems to be invalid in the description

pseudo parrot
trim beacon
valid orchid
#

The hosts .13 WEB, .12 VPN and .11 WebMail aren't reachable anymore. Tried it with the Attackbox and on my machine via ovpn. Is this part of the challenge ๐Ÿ˜… ?

trim beacon
trim beacon
valid orchid
#

yes, it just extended automatically several minutes ago

trim beacon
valid orchid
#

i had the issue before running both on my machine, and to test it i ran the attackbox, which might have created a conflict now

trim beacon
#

If ping says no route to host, it is this problem

trim beacon
valid orchid
#

ok, i ll try that. Thank you very much for your fast response ๐Ÿ™‚ ๐Ÿ‘

valid orchid
#

icmp_seq=1 Destination Host Unreachable it still persist, i ll go to work, maybe it resolves by itself in the next 8 hours ๐Ÿ˜„

trim beacon
#

Congrats to @austere oriole , our third SWIFTest hacker to successfully complete the challenge and take all the monies! ๐ŸŽ‰

Now the competition for the Red Teamer of the Month starts! Make sure to get those writeups submitted before the 31st of May! Best of luck to all you red teamers!

austere oriole
sage citrus
#

To whoever put effort into creating this network, you rock.

#

To whoever is lucky enough to play this network now or in the future I have one thing to say: "You lucky bastards coolguy "

azure tangle
#

When you register using thm username it fails cause I have a . In my username. Will it work if I just remove the . ?

torpid ore
#

Should do yes

pseudo parrot
azure tangle
#

Thanks

austere oriole
#

Daym

#

What a legend

pseudo parrot
austere oriole
trim beacon
austere oriole
trim beacon
#

Greetings all red teamers!

With the three SWIFTest hacker prizes completed, we are relaxing our "no hints or nudges" policy. Feel free to have discussions about the challenge but please remember to use spoilers tags for these discussions.

Happy hacking!

sage citrus
#

||Hey, I have pwned the domain but still can not get admin access to Tier 2 infrastructure.||

#

What the ... is going on?

vale pewter
#

@trim beacon I just got access to the challenge as I just got done with my 7 days streak. I joined and saw this. Can you let me know what is this about?

#

what does it mean by 6 days of access left?

trim beacon
trim beacon
sage citrus
#

||So i am domain admin to corp. I have dumped everything and captured all the flags up until Flag 8 except the Tier 2 Infrastructure one.||

#

||I have tried accessing with smbclient to write a file (as domain admin), RDP as domain admin and adrian (both are restricted) and using runas which has also failed||

viral yew
#

||how can we take advantage of Domain Trusts?||

trim beacon
#

|| Why not just use your low privileged AD creds to RDP to either WRK1 or WRK2 and submit the flags? Or use your DA permissions to reset the password of a T2 account that will be admin on the workstations? DA's have restrictions on where they can auth since their accounts are part of the protected users group. ||

sage citrus
trim beacon
sage citrus
#

Thanks for the help

trim beacon
sage citrus
trim beacon
# sage citrus || I gave it a try with Adrian who is a local admin (not sure if this account be...

Would usually agree with this: || It is just for completion purposes since gaining DA is what would matter in a real engagement. ||

But in this engagement, your final goal is different. As as mentioned before, you can't really tell the client that you can't get something to work. Luckily those hosts are not required for goal execution in this example, but if they were, you would have to figure out some way to get it to work even if ||the DA account cannot be used directly||

viral yew
lyric stream
#

Hello hello, can we please restrict the usage of spoiler tags to a minimum, as we moderators have to unspoiler all those each time we revisit the channel to "moderate the channel". ๐Ÿ™

#

The last page was reading like a CIA document. ๐Ÿ˜†

sage citrus
#

Sorry but I don't want to give away anything.

#

Perhaps it is easier to ask if we can DM someone for help, after we describe the situation briefly.

lyric stream
#

Long conversations might be more suited in DM if you have to spoiler the whole thing. ๐Ÿ™‚

trim beacon
viral yew
#

you can DM me if needed

#

I have a couple of min during my lunch break ๐Ÿ˜‚

#

and I am watching scans running

lyric stream
#

I've found a way to mitigate the "spoilering" by turning it off (on my side), so please continue. ๐Ÿ˜„

#

Even at my age you learn something new every day. ๐Ÿฅณ

viral yew
#

we are never too old to learn

fossil bobcat
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

fossil bobcat
smoky breach
broken nest
#

Ok , banned.

#

Guys , im reaching out with a question regarding the access to the hosts after the lab reset. After the lab reset i cant access the second group of hosts. Do i need to regenerate the second .ovpn?

trim beacon
trim beacon
broken nest
#

I run into issue that i cant generate the new .ovpn, the site freezes on request

trim beacon
trim beacon
broken nest
#

Might it start responding at some point? Cause it happened right after the lab reset. I went for a break for 15minutes as been suggested before to let the all host go live.

broken nest
#

Im on the vpn server right now, only the site went unresponsive in generating the new vpn's. I have already did a workaround

#

Lastly i cant login to my email

stiff pawn
#

Made it through! What a wonderful challenge ๐Ÿ™‚ Thanks @trim beacon

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

trim beacon
broken nest
trim beacon
broken nest
#

Got it , thanks!

trim beacon
#
+----------+-----------------------+
| username | Flag Submission Count |
+----------+-----------------------+
| K        |                    20 |
| a        |                    20 |
| J        |                    20 |
| M        |                    20 |
| d        |                     8 |
| P        |                     7 |
| S        |                     6 |
| d        |                     5 |
| p        |                     4 |
| l        |                     4 |
| j        |                     4 |
| M        |                     4 |
| g        |                     4 |
| s        |                     4 |
| s        |                     4 |
| z        |                     3 |
| Q        |                     3 |
| N        |                     3 |
| m        |                     3 |
| r        |                     3 |
| S        |                     3 |
| m        |                     3 |
| T        |                     3 |
| u        |                     3 |
| K        |                     3 |
| a        |                     3 |
| B        |                     3 |
| c        |                     3 |
| d        |                     3 |
| d        |                     3 |
| g        |                     3 |
| H        |                     3 |
| I        |                     3 |
| J        |                     3 |
| J        |                     3 |
| h        |                     2 |
| n        |                     1 |
| n        |                     1 |
| P        |                     1 |
| h        |                     1 |
| C        |                     1 |
| c        |                     1 |
| S        |                     1 |
| K        |                     1 |
| A        |                     1 |
| 0        |                     1 |
+----------+-----------------------+

Got some good progress thus far in terms of flags!

pseudo parrot
#

Wow, 4 people with 20 flags.

warped grail
#

I have pwned the DC but found 0 flags. is this a bug?

torpid ore
#

You don't find flags here

#

You prove your access using the ecitizenship program

#

Have you read the task / brief properly?

warped grail
#

yeah I'm not using the e-citizen ssh authentication :D, so flags will spawn after that?

slender verge
trim beacon
# warped grail yeah I'm not using the e-citizen ssh authentication :D, so flags will spawn afte...

It does concern me that you have not read the brief. It really increases your chances of going out of scope, which during a real red team engagement, will have legal implications. Please make sure to read the project brief and to follow the instructions that are provided there. I know it is a lot of information but this is what you would find during a real engagement. This type of guard-rails is what creates the distinction between a red team, and a malicious threat actor.

warped grail
#

Thank you

fossil bobcat
smoky breach
fossil bobcat
normal spire
#

1 more day until i have streak to start this network blob_party

#

doing red team path while waiting

#

i've started to take notes on eveyrthing

scarlet fjord
#

10.200.52.0 has not been working for me for about 4 days now. I've tried regenerating the vpn file multiple times and using the attack box. Occasionally the .11,.12,.13 web servers would be available but not for long. Same for rdp access on .21 and .22. It doesn't seem like it's on my end but is there anything I can do?

cerulean wraith
serene sedge
austere oriole
#

it works fine

sage citrus
#

I need to ping someone for various aspects of my actions in the lab that might affect other users.

Are password changes within scope?

deep hearth
#

Someone turned off ||PubkeyAuthentication yes and changed permissions on auth keys|| on the VPN server. NOT NICE. Luckily I was still on the box and was able to turn it back on.

shell furnace
#

when i try to send an email to applications@corp.thereserve.loc i get this error

#

i tried different email clients

#

or am i going into a completely wrong direction

#

it works when i send it to amoebaman@corp.th3reserve.loc

quaint knot
sweet patrol
#

anyone else on the 10.200.116 network? lost connection and machines are no longer reachable

#

network seeeeems to be running, according to dashboard

#

yeah pretty boned. can connect to .250, and when i verify the mail:

#

seems like the machines are broken

stuck vine
#

Hi @sweet patrol I just posted the same issue in #site-support haha, we're getting the same issue

#

However I'm on the 10.200.113 network...

trim beacon
trim beacon
stuck vine
#

ah, that's my issue too. thanks

stuck vine
#

alright well now i have access to the mailserver but the creds that the e-Citizen server gave me to authenticate didn't work :(

sweet patrol
#

if the server has been reset, you need to login to the e-citizen server again and select verify email

#

its what i was doing in the screenshot above. recreates your mailbox

stuck vine
#

yeah, i did that, it didn't give me different creds

#

i'll try again, np

#

hmm

#

and i get this error

sweet patrol
#

thats not the mail server ๐Ÿ™‚

stuck vine
#

oof you're right omg

#

lol

#

is there just a default install of IIS on the webmail server? sorry just trying to get my bearings and i'll be running with it

trim beacon
#

Check the IPs in your network diagram

stuck vine
#

Am I crazy? haha

trim beacon
trim beacon
stuck vine
#

ah. got it :)

sage citrus
#

I want to ask for some help regarding the SWIFT process. Is anyone available? Preferably in a DM, I do not want to spoil much here.

shell furnace
#

i am getting this error on the vpn server: helloError: Connection to Database could not be made.No such file or directory. what does it mean?

#

when i try random login data

trim beacon
sage citrus
#

Ok, I will give it a try first, I have made some progress.

#

Get some rest. I will ping you if I need help. Thanks for offering!

trim beacon
sage citrus
#

Daytime here as well, but slow day in work, so time to capture the 2 remaining flags.

trim beacon
crystal idol
#

I guess there's something wrong with the VPN server:

PUSH: Received control message: 'PUSH_REPLY,route 10.2001.21 255.255.255.255,route 10.2001.22 255.255.255.255

sturdy kestrel
#

@crystal idol Same everything was working fine until the room reset. I closed the VM and went back in to try and the same issue.

crystal idol
#

I filed a bug report.

sturdy kestrel
#

@crystal idol Yea and I'm not sure what is going on. I enumerated everything again thinking I missed something, but nothing changed.

#

Also, Remmina was being difficult

shell furnace
#

the http server and vpn server are offline on 10.200.121.12 but ssh is on?

quaint knot
#

Hey all -- if you're having issues with the main VPN -- just leave the room fully for 3 - 5 minutes and re-join. This should put you on a different subnet if you don't want to wait for the network to reset or time out. That successfully fixed the issue for me yesterday ๐Ÿ™‚ - That being said, just because a specific attack isn't working, does not mean the network isn't working. Remember, this isn't a CTF. There are multiple pathways for each attack. If one doesn't work, pivot and keep enumerating.

smoky breach
#

RDP can't 10.200.x.21
my vpn running

quaint knot
#

Here's my 5th stream going through the network. Keeping this status vague so as to not spoil the network -- but I was able to get admin on Tier 1 infrastructure and grab the next 2 flags.

Goal is to get Domain Admin tonight on the first domain -- we shall see if it happens!

(Obviously don't watch if you don't wany any spoilers)
https://youtu.be/FRUQMg9IhMA

This is the 5th video working through the "Red Team Capstone Challenge" by TryHackMe.

This is an in-depth network challenge simulating a Red Teaming engagement. The challenge includes several phases structured around the cyber kill chain that will require you to enumerate a perimeter, breach the organisation, perform lateral movement, and fina...

โ–ถ Play video
sage citrus
#

Just completed the lab!

Big thumbs-up to all of TryHackMe stuff for this wonderful network! This is the reason the community loves you.

Anyone who might need nudges, ping me with no mercy! blobfingerguns

hexed whale
brittle badgeBOT
#

Gave +1 Rep to @quaint knot

sage citrus
quaint knot
# hexed whale Thank you so much for these, I canโ€™t do the network myself (not a sub and no str...

Glad to hear you have found it helpful! I'll be live on stream again tonight at 9pm CST. I try to take it slow and explain things as I go, so feel free to ask questions during the stream ๐Ÿ™‚
https://hacksmarter.live

Twitch

Welcome to the Hack Smarter Twitch stream! This stream is managed by Tyler, Nate, Josh, and KaliMax. We will be streaming hands-on hacking through TryHackMe, HackTheBox, VulnHub, and various other platforms. Enjoy!

โ–ถ Play video
sage citrus
#

@quaint knot make sure to explain everything regarding the AD enumeration and exploitation process since this is the keystone in hacking it.

hexed whale
hidden galleon
quaint knot
hexed whale
sage citrus
hexed whale
sage citrus
torpid ore
hexed whale
normal spire
#

it's time!! party_blob

sturdy kestrel
muted compass
#

Do you lose access to the room if you lose your streak after joining?

cerulean wraith
pseudo parrot
#

No, you don't lose access

#

It's just a join requirement.

sage citrus
normal spire
#

hi, when trying to use ||corpUsername.ovpn|| i get this:

2023-05-18 13:18:56 Initialization Sequence Completed
2023-05-18 13:18:56 Connection reset, restarting [0]
#

thanks!

sage citrus
normal spire
normal spire
#

also the routes are ok, it just fails

#

even after deleting the other routes, still fails

normal spire
#

okay, i think it is intended. but i cannot portscan x.22 or x.21

#

okay, added some routes for 21 or 22 but still cannot ping. what am i doing wrong? thank you!

#

wait wtf it just worked nvm so i guess it's completely unstable

gusty oyster
# normal spire

Gotta love that 172 which appeared out of nowhere... it's funny because for me it originally routed the correct IP automatically, and then it all of a sudden routed 172 instead ๐Ÿ‘Œ

stuck trench
#

same

flat folio
#

same

normal spire
#

yeah... though even when switching out those routes it still doesn't work

#

it just started working randomly and now not again

stuck trench
#

Finally find an access point, but no, we have no right to happiness

gusty oyster
#

hmm, wdym? @normal spire

normal spire
#

if i don't find a way to stabilize it it's gonna be such a pain for the whole network

#

i just can't access .21 and .22

#

nmap finds nothing no ping or any response or anything

#

even with -Pn

flat folio
#

Same for me

gusty oyster
normal spire
#

nope

flat folio
#

I had access, the room rebooted and now impossible to access

normal spire
#

i do ||sudo ip route add 10.200.119.22 via 12.100.1.1 dev tun0||

#

(and for .21)

gusty oyster
normal spire
#

i think i tried that

#

lemme check

stuck trench
#

You are a life saver, thanks

normal spire
#

ahh still nope :/

brittle badgeBOT
#

Gave +1 Rep to @gusty oyster

normal spire
#

wait no

#

thank you!

gusty oyster
#

yw

normal spire
#

ehh still unstable

#

only worked for a bit

fossil bobcat
#

having issues verifying a flag, i tried the option to fully exit verification and still wasn't able to verify it. the ssh connection seems to instantly close after i press Y to start the verification

regal basin
normal spire
#

ahh still can't get it to work though

#

it worked like twice

hexed whale
#

Question for VPN Server (Cannot test it so idk if itโ€™ll work):

||Could you not run test && ls -la get the ovpn files on the server and see if theirs a privileged file on there?||

regal basin
normal spire
#

really??

regal basin
#

y

#

it worked

normal spire
#

do i have to re register in e citizen

#

i got the same subnet again Catastrophe_Cat

regal basin
#

no, i did'nt register in ssh

normal spire
#

back on the same subnet though ah

regal basin
#

just sudo the ovpn file of the network, and then sudo the ovpn file you found anyway

normal spire
#

yeah, nothing changed

#

because i'm still in the same subnet

regal basin
#

did you left the room?