#red-team-capstone-challenge

1 messages Β· Page 2 of 1

normal spire
#

yeah

#

and regenerated

regal basin
#

and joined again? and ips didn't change?

normal spire
#

mhm

#

oh new subnet now

#

had to do it again

#

nice

regal basin
#

there is it

#

this network sucks πŸ˜„

normal spire
#

yeah i had done that

#

gonna see if it works now

#

huh, the routes are all good now automatically...

#

but still nothing

#

oh wait had to redo the routes, all good now??

#

kinda

#

ehh, still broken ish

#

maybe at some point the creator can help me out but for now, really unfortunately can't progress with this network

hidden galleon
#

There are multiple ways in. If one route is not working out for you, we highly recommend you change your approach, enumerate more, and try another one.

quaint knot
sweet patrol
#

i have a question, sorry if its been covered: ive managed to get a foothold on the interior machines and get the first flag, but after getting admin on some of these machines (and some other machines via pivoting), not sure which category this might be for Tier 2 or whatever flags? the e-citizen tool rejects the hostnames

#

i might not have breached far enough

dense pecan
#

is this normal that i had to manually add routes for the file ||corpusername.ovpn|| ?
||(it was routing to 10.2001.21 and 10.2001.22)||

smoky breach
#

10.200.x.21 Is there anyone who can't access RDP?
2 day RDP can't access me

quaint knot
sweet patrol
#

hmmmmmmmmmmmmmmm no. unless im in the wrong network

#

possible

quaint knot
sweet patrol
#

ive already dmed you!

smoky breach
#

maybe i do Leave room again join room

#

bad network

#

why can't access RDP

#

I haven't been able to do anything for two days because of this

fervent sail
quaint knot
# smoky breach why can't access RDP

The network likely isn't bad -- to access that machine you need|| to have two VPNs set up||. Make sure they are both set up, and both are configured properly.

Finally, that's only one of many attacks paths. In a real red team engagement or pentest, if one way doesn't work, you need to go back to enumerating to attack a different path. That's very realistic. πŸ™‚

quaint knot
fossil bobcat
#

anyone know why this is happening? i followed the directions and even set permissions on the file and folder to 777 (this is for VPN machine root flag)

#

network was just reset as well

sage citrus
#

Stop using remmina and go for xfreerdp

quaint knot
#

THE FIRST DOMAIN HAS FALLEN!

I successfully get Domain Admin permissions on the first domain in this video. Details are in the description - as usual, don't watch if you don't want a spoiler!

https://youtu.be/xzxpn6k7OIQ

This is the 6th video working through the "Red Team Capstone Challenge" by TryHackMe.

This is an in-depth network challenge simulating a Red Teaming engagement. The challenge includes several phases structured around the cyber kill chain that will require you to enumerate a perimeter, breach the organisation, perform lateral movement, and fina...

β–Ά Play video
trim beacon
#

You still having this issue?

trim beacon
fossil bobcat
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

sage citrus
#

Any chance the platform can issue Certificates of Completion for this lab (similar to Throwback)?

smoky breach
#

Leave room is same

#

Does anyone else experience the same phenomenon as me?

stuck vine
#

Hi guys, I'm getting the same issue above where the ||corpUsername.ovpn|| VPN file routes me to a public 172.32 network which I don't think is correct 😬 am i doing something wrong?

trim beacon
trim beacon
trim beacon
stuck vine
#

sounds good sir thank you salute

sweet patrol
stuck vine
#

if it's part of the challenge that's cool, i'll smack my head against it a few times

sweet patrol
#

fixed it with ip route add 10.200.116.21 dev tun0

trim beacon
#

Going to say this once more and pin it and start referring challengers to this message. This network has multiple attack paths, we are also making slight modifications to the paths in cases where we see that too many users are relying on a specific path.

For this reason, in most cases, you can't just watch a stream and follow the exact path that they performed on stream. Chances are something will not work exactly right. Also, sometimes things just break. Go watch @quaint knot's last video (Part 6), where his socks proxy just simply died. These are normal challenges you will face during a normal red team engagement.

If this happens to you:

  • Follow a debug approach to try and figure out what exactly changed or is different, and how you can overcome this hurdle
  • Leverage your knowledge that you have gathered during the red team learning pathway to explore other paths
  • At each stage, there are at least 2-5 different ways of doing something. If one path does not work for you, try a different attack approach. See THM staff as the client, during a red team engagement, you can't call the client every 5 minutes to double check something during a red team, you simply provide them with weekly updates.

We will continue to make certain attack paths harder until they are in balance with the other ones. Therefore expect changes where "things that worked yesterday", won't simply work today. See this as Trimento applying patches to make their estate less vulnerable, same as what would happen on a normal engagement.

However, for the following requests, I'll be more than happy to assist:

  • Not being able to redeem flags cause of an issue with the flag system
  • E-citizen giving an issue that does not allow you to authenticate or recreate your mailbox
stuck vine
#

Ah I understand, thanks @trim beacon. I'm not watching streams or anything. Appreciate it!

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

smoky breach
#

ah, i see ok

stuck vine
#

really gotta start seeing this as a real red team engagement, and not a CTF πŸ™‚

trim beacon
stuck vine
#

I can imagine that gets annoying haha, thanks for the info though!

smoky breach
trim beacon
# stuck vine really gotta start seeing this as a real red team engagement, and not a CTF πŸ™‚

That is the aim here, and also why we don't just want to give challengers the full answer for a specific attack path. With multiple routes, it is an acceptable risk for us that a specific attack fails, since that really simulates real life, which then forces users to take another path. Once the challenge has been out there for quite a while and a user is really looking to focus on a specific technique, more than happy to make sure that exact path works for them.

sweet patrol
#

i rust scan my breakfast in the morning

smoky breach
#

What was working 5 seconds ago, it may not work after 5 seconds.

When you find a possible way, the only way is to never go to rest and continue.

You're gonna wake up the next morning and do it? Tomorrow the way will be blocked and see hell.

#

I also want to be a steff and try to stop people from succeeding

I think it would look really funny to see you keep trying because you couldn't do what you were doing yesterday

#

πŸ™‚

#

This is a great tip. Never quit what you're doing

Don't take a shower, don't eat, don't sleep.

After 5 seconds, everything you did will be blocked

slender verge
#

It does seem somewhat unfair that people who didn't start immediately and grind like crazy will now face a harder challenge.

I was going to follow the same path people are now complaining doesn't work for them, but decided to go through the red teaming path as quickly as I can while still retaining the material, so I can be equipped to proceed further, but I am feeling quite discouraged just reading this channel.

By the time I come back to this network, it'll be too difficult for me with the easier exploitation paths patched up to make them unattainable.

We only get the chance to do this for a limited amount of time.

smoky breach
digital plaza
#

Yo @trim beacon how long did it take you and the team to make this?

sweet patrol
#

eh seems the same as yesterday for me as it does today

smoky breach
#

We have to lower the patch to the "BABY VERSION" πŸ™‚

slender verge
#

By all means, you could make it harder for when it moves to business only using whatever data you gather so the write-ups wouldn't be a lifeline, but for now, doesn't seem fair like I said.

trim beacon
# slender verge It does seem somewhat unfair that people who didn't start immediately and grind ...

The modifications that are made are minor. The overall attack will still work, but will require you to apply knowledge to get it working for you. For this first month, no attack path is fully removed or new ones added, just modifications made. At this point 99% of these modifications are aimed at a single breaching path, since there are 5, and it seems that 99% of users just choose the one. We have not yet made any other major modifications to the network.

clear badger
trim beacon
trim beacon
digital plaza
#

I bet lots of it goes over my head but just generally exploring the network I have to appreciate how much work it must've taken

trim beacon
brittle badgeBOT
#

Gave +1 Rep to @digital plaza

slender verge
digital plaza
#

Oh also is the eternal blue Easter egg somewhere deeper in the network or was that just a joke

#

Because I've been looking everywhere for it

trim beacon
trim beacon
digital plaza
#

I'll find it super fast considering how I think don't you worry

trim beacon
clear badger
slender verge
ruby roost
#

For some reason my VPN keeps restarting, is anyone facing the same issue or faced it and then fixed it ?

#

I have regenerated the OVPN file a few times now but that doesn't fix the issue

trim beacon
ruby roost
trim beacon
ruby roost
#

Shall I DM you the IP ?

trim beacon
trim beacon
# ruby roost ?

Open the ovpn file and send me the IP you have in there for remote

sweet patrol
#

one dc down, boom. nice network @trim beacon reminds me a lot of OSEP

austere oriole
trim beacon
# austere oriole tempted to try the room again

If you do, just choose an entirely different attack path and you will have lots of fun! If you went for VPN, go for CMS this time. If you went for WRK1, go for WRK2. If you do that, you will find a lot more in this network

digital plaza
#

Hey @quaint knot, could I drop you a DM real quick?

hexed whale
#

I was just wondering if that was an option, not that experienced in web app attacking so didn’t know

graceful bolt
#

I went to verify my first flag, after making sure it's there, and got an ssh public key access denied error. Is this a bug or do I need to 'git gud', as the saying goes?

#

I can provide more details tomorrow if this gets traction, off to bed for now πŸ’€

hidden galleon
tidal junco
#

@hidden galleon I can reach e-citizen but not mail web and vpn. I had to download a new openvpn file because the old one was just resetting over and over again

weary flicker
#

Hi guys, I have a problem, I'm connected to the internal VPN but I can not reach any internal hosts, I don't get pings or anything from WRK1 and WRK2

#

which I already breached yesterday

tidal junco
#

same

weary flicker
#

both VPNs seems fine (external and internal)

weary flicker
#

Looking at the internal vpn screenshot now I notice for some reason I'm being directed to 172.32.5.21 instead of 10.200.103.21, now I wonder if something changed overnight in the challenge

weary flicker
fiery frost
#

the lab is just reset but my internal vpn connection is stuck on a restart loop

2023-05-19 09:55:55 Initialization Sequence Completed
2023-05-19 09:55:55 Data Channel: cipher 'AES-256-CBC', auth 'SHA512', peer-id: 0
2023-05-19 09:55:55 Timers: ping 5, ping-restart 120
2023-05-19 09:55:57 Connection reset, restarting [0]
2023-05-19 09:55:57 SIGUSR1[soft,connection-reset] received, process restarting
2023-05-19 09:55:57 Restart pause, 1 second(s)
14: capstone: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
    link/none 
    inet 10.50.114.44/24 scope global capstone
       valid_lft forever preferred_lft forever
    inet6 fe80::623:1092:adf:c83f/64 scope link stable-privacy 
       valid_lft forever preferred_lft forever
17: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
    link/none 
    inet 12.100.1.8/24 scope global tun0
       valid_lft forever preferred_lft forever
    inet6 fe80::c4c:7fc3:d65c:5cff/64 scope link stable-privacy 
       valid_lft forever preferred_lft forever
weary flicker
#

@fiery frostdm me

hidden galleon
weary flicker
#

Yesterday I just downloaded the vpn file (although in a slightly different way which I dont want to spoil) and it worked out of the box

trim beacon
sage citrus
torpid ore
#

😁

open heath
#

Can someone help me confirm if there's something wrong with my subnet I know where the ovpn file is, changed the Xs but I have only been able to reach 2 servers once and it crashed after 10 minutes and didn't work again...Now when I use the ovpn file the IP are showing external IPs rather than internal to the nextwork.

hidden galleon
#

Can you ping the .12 machine on your subnet?

open heath
#

yes

hidden galleon
#

Then your subnet is ok, and the issues you're experiencing are because that particular path is unstable (by design).

#

Try looking for another way in!

#

You can also run through a debug/troubleshooting process with this path if you'd like, but that is part of the challenge.

open heath
#

whats the debug process?

hidden galleon
#

I'll suggest you try researching the term on your own at this point!

graceful bolt
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

granite valve
#

@sweet patrol yo man ; can i dm you ?

wild pier
#

I got problem with second vpn where new addresses start with 172 for the .21 and .22. I read that this is a stabilization issue. After retry the vpn now continues to reset. The network is still up so nu clue what the problem is here. Any suggestions?

hidden galleon
broken nest
#

Fellow hackers , might someone help me to transfer some money to my offshore account? Quite dont understand the transaction chain.

#

I will do share

granite valve
forest dune
#

Hello there, found a way to get the first flag, but the validation is not working because (I guess) somebody messed up with the ssh keys. Except reset the network, nothing else to do ?

viral yew
forest dune
#

OK thx for the advice !

obtuse mantle
#

So ive managed to make it to the .22/.21 stations. But im stumped on how to access the webserver on the external network. Ive only received errors trying to access. And I remember when authenticating it said there was additional info. So if someone can point me in the write direction or a room on how to access a mail server.

obtuse mantle
#

Mail server

#

Not the web or vpn on the external

pseudo parrot
obtuse mantle
#

Yes. When doing tge authentication for the first time you are given an email and it mentions further information will be in it

pseudo parrot
obtuse mantle
#

Yes or at least scanned it and dirbusted it

pseudo parrot
#

So you found the IIS page?

obtuse mantle
#

I didnt find anything of use last night. Im not currently attempting anything. Was going to on my lunch break so figured id ask ahead of that

pseudo parrot
#

But just to confirm, the IIS page was the only one you found?

obtuse mantle
#

I dont think i found an iis page unless i missed it

pseudo parrot
#

You didn't visit 10.200.xxx.11 ?

obtuse mantle
#

Ill give it another look in 30 mins. Yes i got a windows page

pseudo parrot
#

Ok, now you know from your network diagram there is something there, what do you think is at work here?

fossil bobcat
pseudo parrot
obtuse mantle
#

Ill put some more time on the mail server. I know when i tried each port to connect to it i just got firefox has closed connections. But ill do a more indepth scan during lunch

normal spire
#

breached the perimeter πŸŽ‰

pseudo parrot
cerulean wraith
#

waiting for the first writeups to get released because shadow feels stuck on this

pseudo parrot
cerulean wraith
#

not figured out how to even download the vpn file....(technically shadow knows just they are busy with other stuff and get distracted so have not done it yet)

granite valve
cerulean wraith
#

probably just waiting to the first of june when the competition period is over and then having fun reading the writeups and learning all the stuffs

granite valve
cerulean wraith
#

or shadow could go scope out the vods from the streams

cerulean wraith
granite valve
cerulean wraith
#

oooh yeah the vpn is not busy... shadow is busy

hidden galleon
cerulean wraith
#

it is a very big difference

cerulean wraith
granite valve
cerulean wraith
#

the math meaning of ! not the programming meaning

hidden galleon
hidden galleon
cerulean wraith
#

yuup fair

#

lets just say there is a 1/8192 chance shadow can tackle this room on their own.... or about the chance to get a shiny pokemon in the gen 3 games

hidden galleon
#

I believe in you!

normal spire
#

omg, freerdp supports PTH?

#

that makes persistence much easier

#

wait nvm this only works on old windows :(

#

or restricted admin ig

#

although once you have the hash you can enable it with winrm so it would work out

quaint knot
broken nest
#

We're on the same boat , came back to see the network is reset NotLikeThis

quaint knot
broken nest
#

Btw , sorry tyler didnt mean to put you off the rdp session from first domain controller

quaint knot
pseudo parrot
quaint knot
#

That's probably my only frustration but there isn't really a fix on the THM side. I take the time each time to establish real persistence by making my own accounts, access, etc. but I have to re-do it every single day so... it's not really persistent since users keep resetting my subnets!

broken nest
#

I just could not resist poking you there

quaint knot
#

Can you imagine if TryHackMe did NOT have a streak requirement? How often these networks would be reset?

stuck vine
#

it seems like 5 votes to reset is a little low, maybe they should make it 10 votes or something

#

if they can

pseudo parrot
#

I think the votes are related to people in your subnet.

#

more people = more votes.

stuck vine
#

ohhh i see, it's not always 5?

#

gotcha

broken nest
#

I had a solid 8 hours today without a reset, feeling lucky. My only suggestion would be the network reset should be initialized by moderator if there is a request submitted on unresponsive host , or make it single time overnight.

#

Cause at present moment a single user can initiate restart every 5 hours just out of frustration.

#

Daily restart is fine for me , since a lot can break in the shared lab environment. Coming back to where you left is quite easy once you minimize the set of actions needed.

quaint knot
#

TeneBrae93 is Domain Admin again, now please don't reset networks πŸ˜‚

cerulean wraith
#

is that a play on of the old latin word for darkness???

quaint knot
#

WOW YOU ACTUALLY RECOGNIZE IT!!!

#

yes

#

You're like the first person ever to recognize where my username comes from πŸ˜„

cerulean wraith
#

haha more darkness and abyss and void lovers

acoustic bough
#

I got access to swift application as my first flag and haven't breached the perimeter yet. Am I doing something wrong or is it that non-linear?

cerulean wraith
#

but what does shadow know that they have not touched at all yet

broken nest
quaint knot
#

Forget Swatting, THM users do resetting

broken nest
#

Its a late time for me , so best of luck Tyler with the network and on upcoming stream if you will do it!

quaint knot
#

I finished my pentest report for a client, so I think I have some time this afternoon. Should hopefully be on stream shortly πŸ™‚

stuck vine
#

lol me too tyler! itching to get back to the THM network

quaint knot
obtuse mantle
#

resetting was rough was doing medium dirbuster had to restart is sad life

normal spire
#

(Pass-The-Hash)

hidden galleon
#

Oh wow, I get to watch live!

dawn zinc
#

so I just got started and the timer for extend was already running, I didn't (have) to press start because the timer was already running but from what I understood searching this chat the network ist stuck now I had waited before for the timer to run out just so it was extended again automatically. I'll be honest I don't understand it at all. and I also don't understand why the staff didn't add screenshot instructions on what (not) to do instead of the sentence that will have noobs jump off a cliff πŸ˜„ no offense though. Also I have no clue when to use reset. It's currently 4/5 but I don't want to ruin it for others because I know it's super frustrating when that happens and it seems to happen a lot πŸ˜„

hidden galleon
#

Does the network diagram say the network is running? Are you connected to the redteamcapstone VPN?

dawn zinc
#

the network says uptime 1h 3m and extend(1h26m)

hidden galleon
#

Top right corner - does it say Running in green?

dawn zinc
#

yeah

hidden galleon
#

Ok, have you successfully connected to the network VPN?

dawn zinc
#

i was kind of able to register

#

it did say something went wrong but then created the acc

hidden galleon
#

Ok, so you can ssh to e-citizen? Can you ping the .12 machine?

dawn zinc
#

nothing happening so I guess that's a no

hidden galleon
#

There should at least be an error message of the network is stuck/locked.

dawn zinc
#

can I share a screenshot of the IP I'm pingig?

hidden galleon
#

You can use spoilers to hide it.

dawn zinc
#

So I pinged the ||10.200.1*.12||

#

1sec

#

yeah I just thought it was because I wasn't auhtenicated but I am again and still no response at all for that ip

#

I can screenshot it if you like

granite valve
#

U goota leave the room for couple of minutes ; and join again ; regenerate the vpn and connect

#

U would be joined in different subnet

hidden galleon
dawn zinc
#

so I just got the message that it is now resetting should I still leave and join again?

hidden galleon
#

Reset should fix it too! Just remember to give it ~15 minutes for all the config scripts to stabilize.

dawn zinc
#

I'll try again in 15 minutes then

#

thanks!

dense pecan
#

if we use phishing, should we wait a certain amount of time ? or the mail have to contain some specifics details to trigger the opening ?

normal spire
#

are you supposed to be able to send email from the email they give you?

#

getting connection refused when trying to send email

#

getting Mail server configuration error. Too many recursive forwards..

hidden galleon
dense pecan
hidden galleon
dense pecan
brittle badgeBOT
#

Gave +1 Rep to @hidden galleon

normal spire
dense pecan
hidden galleon
#

I was about to say - you're on your own with details, that's all the nudges I'm giving, research if you need to!

normal spire
#

thank you!

#

i think i'm just not sending it to the right email

#

NOO i triggered windows antivirus which deleted the whole way of doing privesc catNO

quaint knot
lyric stream
quaint knot
#

OKAY I think I am taking the weekend off friends! Streaming every single night is getting much -- and I think I've been on stream for 3 hours today!

quaint knot
#

ROOTDC has fallen at least πŸ™‚
https://youtu.be/Td_Krk1S3yg

This is the 7th video working through the "Red Team Capstone Challenge" by TryHackMe.

This is an in-depth network challenge simulating a Red Teaming engagement. The challenge includes several phases structured around the cyber kill chain that will require you to enumerate a perimeter, breach the organisation, perform lateral movement, and fina...

β–Ά Play video
cerulean wraith
#

oooh was just about to ask about vods

sweet patrol
#

hey just a sanity check please; if i can't query the rootdc with commands like get-aduser etc, it always failing saying active directory services are not running, is that intended or an issue?

#

this is from the corpdc. trying to get its sid

#

nvm, i think it might have just been a perculiarity of my shell. adding a user to the dc and remoting in over mstsc seems to have fixed these commands

sweet patrol
#

four flags to go!!!

viral yew
#

you got this!

normal spire
#

almost got privesc on both wrk1 and 2 but taking the weekend off

sweet patrol
#

hiya again. email from @trim beacon (nicely done by the way) advises that once i find the swift website, more details will be provided to me? is this automatic or is there something i need to do to trigger it - have the website open

trim beacon
sweet patrol
#

i literally just realised i probably need to use the e-citizen tool πŸ˜„

#

thanks

trim beacon
#

Good luck with the final goal execution!

sweet patrol
#

just a note, there seems to be an issue with the e-citizen authorized_keys on the .116 subnet. didn't affect getting the first flag, but looks a bit boned (prints maybe a dozen of these):

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the ECDSA key sent by the remote host is
SHA256:HaDm9ACgV3jW0WzWgixDjckkkgx/29ax6jq4RuA0gFI.
Please contact your system administrator.
Add correct host key in /home/e-citizen/.ssh/known_hosts to get rid of this message.
Offending ECDSA key in /home/e-citizen/.ssh/known_hosts:2
  remove with:
  ssh-keygen -f "/home/e-citizen/.ssh/known_hosts" -R "10.200.116.201"
Password authentication is disabled to avoid man-in-the-middle attacks.
Keyboard-interactive authentication is disabled to avoid man-in-the-middle attacks.
trim beacon
broken nest
#

I did also encounter same behaviour in e-citized as aquinas did. But i was able to submit it. Also if it possible to DM you to report possible misdeployement? @trim beacon

sweet patrol
#

sure. misdeployment of what tho

broken nest
#

That might give away some hosts on the network, i would love to clarify first.

sweet patrol
#

great lab @trim beacon - would be good practice for people going for OSEP i reckon

trim beacon
trim beacon
valid orchid
#

has someone good resources about bloodhound-python, or encountered any dns-tcp problems with it and was able to resolve them? I m always getting ||TCP port 53 answered The DNS operation timed out.|| thrown and don't now if it's proxychains or an bloodhound-python issue

trim beacon
valid orchid
#

yes i am proxychaining and i added --dns-tcp I have the issue on my machine and tried it on the attack box, i think i m mising something πŸ˜„

broken nest
#

Feeling accomplished and grateful after completing the Red Team Capstone Challenge! Massive thanks to @trim beacon and the entire team for putting together such an amazing lab. The e-citizen and your own working mail implementation added a whole new level of realism, and were hands down one of the most unique and innovative features. Kudos to everyone involved! ❀️

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

trim beacon
brittle badgeBOT
#

Gave +1 Rep to @broken nest

trim beacon
stiff pawn
# valid orchid has someone good resources about bloodhound-python, or encountered any dns-tcp p...

I've had similar issues in the past. As a workaround for smaller lab scenarios where ip-addresses and hostnames are known you can trick bloddhound and use DNS Chef (https://github.com/iphelix/dnschef). You can simply use a a config file where you plug in all the addresses and hostnames and basically fake DNS responses from the DC / NS. But as mentioned, this is not really applicable for larger or unknown environments, but should work in this lab.

valid orchid
#

Ok, thank you, i ll try both πŸ™‚

granite valve
#

yo hackers ; Is red teaming more about making things / tools work rather than exploits ? ; cause i am having hard time debuging and changing tools to work than doing exploits .

#

Is this also the case in real engagments or ?

tame island
#

hi to you all, might be dumb, BUTTT. should WORK1 and WORK2 be reachable from BANKDC? also in the .116 network

broken nest
tame island
brittle badgeBOT
#

Gave +1 Rep to @broken nest

broken nest
#

You have an rdp connection on bankdc and cant ping them?

tame island
#

Exactly, it does indeed timeout, the DNS resolution is correct due to the ping command shows correctly the IP of the machines

broken nest
#

You can DM me so we wont spoil anything to other users.

valid orchid
# stiff pawn I've had similar issues in the past. As a workaround for smaller lab scenarios w...

if someone has similar issues i ll recommend watching ||https://www.youtube.com/watch?v=4ydjpSSKQ8g|| resolved it. Thank you @trim beacon @stiff pawn

Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005:


An educational look at cyber security, this time on Hak5:
Souce: https://github.com/fox-it/bloodhound.py

Usage:

  • PIP: pip3 install bloodhound
  • Docker
  • docker build -t bloodhound .
  • docker run -v ${PWD}:/bloodhound-data ...
β–Ά Play video
brittle badgeBOT
#

Gave +1 Rep to @stiff pawn

trim beacon
deep hearth
#

All the way to the swift part and people vote to reset the network when it's working fine. Lost connection 😭

dull kestrel
austere oriole
#

if someone voted to reset the network they should provide a reason to. when 5 votes are reached a staffer should do it manually after reading the reasons and confirming a network issue

#

but that might be too much for staff

#

idk

pseudo parrot
#

But then you'd need to wait until a staff member reviewed it, staff aren't on 24/7.

Which means it could take longer for the reset to happen.

austere oriole
#

for me personally, i'd rather wait 24 hours than redo everything :|

#

i know redoing everything won't take 15 minutes

#

but its annoying doing it 6 times in a single room

#

but das just me

#

because people will reset the room for an issue not even related to the network

tame island
#

could anyone drop a hint for the approvers account? been struggling for a while now, can DM for not spoiling

dull kestrel
#

I just started network an hour ago and someone already voting to reset πŸ˜“

quaint knot
tame island
#

so... what happens if the network reseted while having e-citizen waiting for my "Y" for flag 19? because now it says to me that i already have a verification attempt (the transaction obviously does not exist due to the reset) and none of the options work, the "Z" throws a Python exception

azure tangle
#

I Have the same issue with flag 18 on network 118. They reset the network as I was submitting now it is stuck in this loop...
@trim beacon any way we can fix this?

tame island
#

The transaction for flag 20 will be broken too (I suppose)

trim beacon
fading jolt
#

@trim beacon Please give private subnet to @quaint knot for streaming, as his stream is very educational. Hate him to get frustrated while juggling broken subnets. Thanks! feldmanslv

azure tangle
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

tame island
#

The bank has fallen, thanks @trim beacon for the great and fun network, awesome job!

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

trim beacon
brittle badgeBOT
#

Gave +1 Rep to @tame island

fading jolt
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

serene crystal
#

I spend hours on getting my domain account and reproing all my step, and another reset 😒

rotund magnet
#

someone placed password on vpn server account?

graceful bolt
#

I think were in the same network. Someone disabled ssh password access to the .250 server

quaint knot
main crown
#

Hey guys! I'm having issues connecting to the network here. I can ssh to e-citizen but when I verify my email access it's saying no route to host. Also, not able to access any of the public facing services... is this on my end?

viral yew
#

sometimes I needed to add the routes manually

#

otherwise might be an issue with the network, I would leave the challenge, wait a min, join in and get a different subnet

granite valve
#

yo hackers ; I need help on submiting the flags LOL ; like which host --> which flag no !

#

i am EA ; had only submited 1st flag

#

Each host should had flags which we needed to submit like in ctf's ; haha

#

the challenge was fun --> submiting flags aint

main crown
viral yew
#

on the room, right corner on the gear icon, leave room. Wait a min, refresh the page, join room

#

download the connection of the lab again and you should be good to go

granite valve
main crown
brittle badgeBOT
#

Gave +1 Rep to @viral yew

quaint knot
#

VICTORY!!! Final video will be out soon. Then I'll have a FULL walkthrough from perimeter to goal execution on my YouTube page πŸ™‚

viral yew
#

congrats!

trim beacon
quaint knot
#

8th and final video in my Red Team Capstone series where we successfully submit a fraudulent transaction and complete the network!
https://youtu.be/K_rybcJkxyo

This is the 8th video working through the "Red Team Capstone Challenge" by TryHackMe.

This is an in-depth network challenge simulating a Red Teaming engagement. The challenge includes several phases structured around the cyber kill chain that will require you to enumerate a perimeter, breach the organisation, perform lateral movement, and fina...

β–Ά Play video
dull kestrel
#

My persistence has been reset again 😭

fiery frost
dull kestrel
#

103

#

10.200.103

granite valve
#

isnt the swift bank web page and dc accessible after connectin' internal vpn ??

#

it was there yesterday days back ; lol ;now i cant reach even using proxies .

long prawn
#

I am experiencing a problem while connecting to the corporate VPN. It assigns me a 172.x.x.x IP address, which prevents me from successfully pinging the internal resources, wrk1 and wrk2. Can someone please assist me with this issue?

dull kestrel
#

Bruh, I just set up persistence 5 mins ago and someone already comes and breaks it

dull kestrel
serene crystal
#

Can people PLEASE start being considerate in a shared network. EG, if you need to add yourself to the file for a user don't remove others.

dull kestrel
hexed whale
viral yew
#

any mod available to help?

torpid ore
#

With?

#

Just ask

smoky breach
viral yew
viral yew
# torpid ore Just ask

sorry for bothering Jay, I've resetted my swift progress in order to take some screens for my writeup

#

when I access the e-citizen platform, I get the following warning

#

Although it is possible to confirm Flag 17, I am not able to complete the transaction for the 18 Flag

#

But after a reset I've been able to so I was just confirming the situation

torpid ore
#

The keys shouldn't be changing

fiery frost
#

@trim beacon i mean my verification of SWIFT Approver Access is broken, the lab have reset and i havent validate it and now i have this message:

You already have an active compromise attempt, printing details

You already have an active SWIFT check. If you cannot remember your SWIFT details as required, please use option Z to reset the check

i cant reset it and the transaction is not there anymore

viral yew
#

what happens when you try to reset the swift progress in the e-citizen?

viral yew
smoky breach
fiery frost
viral yew
viral yew
fiery frost
viral yew
#

One thing you could try is to switch networks. Leave the capstone challenge room, wait a minute, join it again and you might get thrown to another subnet. Then repeat the process to check if it is related to the network or your user. Or ping a mod or @trim beacon

trim beacon
trim beacon
smoky breach
fiery frost
trim beacon
trim beacon
viral yew
fiery frost
#

bigger chain i have made yet with ligolo , nice ^^

valid orchid
#

After Selecting 17 under [1] Submit proof of compromise
[17] SWIFT Web Access

I get the following warning looped:

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!

Does the network have to be resetted?
It's the Subnet 10.200.119.X

smoky breach
viral yew
#

From rootdc you should be able to access bankdc

#

RDP to rootdc and then to Bankdc for example

smoky breach
#

So what I'm curious about is how can I connect to BANKDC via RDP?

Can I connect RDP in ROOTDC, through remina, and then from Windows in ROOTDC to BANKDC through use "Remote Desktop Connection"?

smoky breach
smoky breach
trim beacon
fiery frost
#

finaly ^^

viral yew
#

Congrats!

viral yew
muted compass
#

is there an issue with the .116 network? Whenever I try to authenticate to CORPDC it says invalid password even though im using the right credentials

viral yew
#

You can also access it through network path or via psexec

trim beacon
fiery frost
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

trim beacon
muted compass
#

i have re-setup my persistence since evil-winrm works, just logging in with rdp does not

trim beacon
# muted compass 4h 50m

We have seen that sometimes longer than 4 hours CORPDC does not like things, especially given how busy the host is with authentication. Specifically RDP connections. But everything else should still work. Once the network just enters the sleep state, the issue will resolve itself. No reset needed

muted compass
#

alright got it, thank you very much!

weary flicker
#

I'm in the Approver view but I dont see any dummy transaction made

#

Might be a bug? or im doing something wrong?

deep hearth
#

Finally completed the challenge πŸ₯³ Well done am03bam4n for creating an excellent challenge.

viscid frost
#

Does anyone also has problems with the VPN server at 10.200.103.12? I can visit index.php but nothing else works on the website

forest plinth
#

lets go!

trim beacon
trim beacon
weary flicker
#

Need to think of a new route I guess

trim beacon
deep hearth
#

Thanks!

forest plinth
dull kestrel
#

People still be adding themselves and removing others 😭

forest plinth
dull kestrel
#

Did that already today πŸ˜…

trim beacon
dull kestrel
#

Was getting forced disconnected on RDP by someone earlier today, so though I'd give it some time and come back later, I come back to see my persistence removed, all good, Nearly at the end will set it up again and finish soon

trim beacon
trim beacon
dull kestrel
#

SMB is the plan for now

#

It's just that so close to the end πŸ˜‚

trim beacon
cerulean wraith
#

well tyler has produced 8+ hours work of kinda write up that you can follow along to get your teeth into the target

#

which is the closest to a write up we will probably get from multiple sources from the streams until after competition period is over shadow would assume

rotund magnet
#

so can anyone help me, i produced the session with parent domain rootdc and I could access it at first and see its folder form its path, but after sometime I cant access it like its not exsisting anymore , how to fix that, i tried purging my "klist" but nothing

forest plinth
#

ok iknow

smoky breach
#

😭

weary flicker
dawn zinc
#

can someone help me nudge me into an alternative way? I am stuck at the VPN 172. which is supposed to be on purpose.. I tried to do it at different times different days but no success and I I am out of ideas or maybe knowledge

frosty bluff
#

Hello all !! is there anyone facing a problem with the vpn config file in 10.200.103.12 ,

#

I wanted to connect using this vpn but it looks like it goes on infinite loop

tardy thicket
#

Finally done πŸ™‚ @trim beacon dude this was awesome! Thank you.

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

trim beacon
cerulean wraith
#

unsubmits the writeup

trim beacon
cerulean wraith
#

after all shadows path of exploitation is watching the creators streams on how to hack it

#

because shadow is slightly lazy and also wanna relax and learn

trim beacon
cerulean wraith
#

rather someone else win

trim beacon
cerulean wraith
trim beacon
cerulean wraith
#

let the competition continue then and lets see if shadow can maybe finish in time... though shadow is not super into doing this kinda competition to win prizes.... rather be on the give away prizes side

dull kestrel
#

Yoo, whoever forced me out of RDP please, I just need 5 mins I'm at the last flag submission πŸ˜…

trim beacon
dull kestrel
#

I hope not I just need to approve the transaction πŸ˜…

viral yew
#

what network?

dull kestrel
#

Let's go, Just finished it πŸ˜„ πŸ”₯

viral yew
#

.118?

trim beacon
viral yew
dull kestrel
#

Thaank Yoou! This was a really fun challenge @trim beacon and everyone else who worked on this. I'm curious about the thought process that went behind making this challenge. 😊

pseudo parrot
#

@trim beacon wanted to torture us before it went to business.

dull kestrel
#

I meant more like how they went about creating it πŸ˜…

#

and I absolutely love the flag submission process

pseudo parrot
dull kestrel
#

Yes

trim beacon
# dull kestrel Thaank Yoou! This was a really fun challenge <@697878147332309156> and everyone ...

I've been creating networks for quite a bit of time. Even before I joined THM. For my day job, I revamped "tabletop exercises", which is an exercise where we play out an incident to the blue team and have them defend. Basically revamped it to make it more real by creating a full organisation and then attacking it during the exercise, meaning the blue team actually had to investigate things and try to find + stop me.

So when I joined THM, always had the idea of creating a large challenge, but realised it would be wasted if THM does not also provide the training required to solve it. So was placed on the back burner to complete the red team learning pathway, where I create the AD network rooms to teach basics of AD security testing.

With the red team learning pathway done, team felt it is time to release a challenge to test that knowledge and I was tasked with creating it. Using previous knowledge of building large scale test networks and with the knowledge I've gained as a security tester over several years, created it. I loved the idea of actually having paths in the challenge that I have personally seen on client engagements. Also without disclosing too much, SWIFT is something that I have dealt with quite closely for several years.

My primary goal was to create a real red team challenge, and what that meant for me it not something like getting DA. Cause if you tell the execs you got DA, they eyes roll. But if you show them the meeting minutes of the CEO's next board discussion, all of the sudden they lose their minds. Sure DA helps you get it, but execs care about impact, no technical deats. So wanted something where you could actually do goal execution, and SWIFT felt like a nice goal due it requiring a couple of steps to achieve.

The other thing I wanted was a network where there wasn't a single path to compromise. Personally, I do not like CTFs. Never have and don't think I ever will. Always get frustrated when I have to do one since if you don't follow the creators exact path, you are screwed. So I wanted something that had multiple attack avenues, again similar to real world where there might be several misconfigurations for you to play around with to reach your goal.

So I first built the full network and made it secure. Had some help from the other team members as well. And then planned out the various different possible attacks at each stage, introducing them and testing them, before finally checking to see if the entire chain worked.

Lastly, since we had multiple attack paths, I realised we could not have flags on the hosts, since you might not compromise the host on your journey, which led me to create e-citizen. I have actually created something very similar for my day job's hackathon competition, so used a based structure and then built it from there.

That was my part in the design, the other massive part where I have to give props is the testing team. Several testers and content engineers help test this behemoth to make sure that things are working. So yeah, quite a massive endeavour!

trim beacon
viral yew
#

and what an adventure it was

trim beacon
viral yew
#

I enjoyed it so much that my wife just gave me free card during the weekend to be around the computer when possible πŸ˜…

viral yew
trim beacon
viral yew
dull kestrel
#

A fascinating read. E-Citizen totally makes sense. This challenge really got me intrigued as to how it was made. Most other CTFs haven't invoked that feeling lol πŸ˜…

trim beacon
# viral yew it might indeed, with different machines to compromise, and different attack ven...

Agree, but could perhaps take it one step further to give an edge to the red team and keep the blue team on their toes but "releasing" misconfigurations as time progresses. Similar to how normal users make mistakes that leads to vulnerabilities. That way even if your blue team fixes all the current things, can keep the exercise going But future plans and dreams, will see what is possible!

trim beacon
brittle badgeBOT
#

Gave +1 Rep to @dull kestrel

torpid ore
cerulean wraith
#

thank you for your vods @quaint knot through the first one now and about to start the second one

brittle badgeBOT
#

Gave +1 Rep to @quaint knot

digital plaza
#

There isn't a good way to address people having done the box a few dozen times but at least this way it would become a speedrun for the flags rather than what it is now

trim beacon
trim beacon
# digital plaza There isn't a good way to address people having done the box a few dozen times b...

My ultimate hope here is to actually randomise "misconfigurations" from a pool of misconfigurations. That way we can always create new misconfigurations and keep things interesting so even on the same boxes, it isn't the same thing. Sure you can still play so often that you get all possible paths, but at the very least it will mean you need to redo enumeration whenever you gain access and can't just copy from memory

serene crystal
#

I as on the swift steps and reset 😒

dawn zinc
forest plinth
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

forest plinth
rotund magnet
#

Any hints on what should I do, I have access to .100 and I made, out of desperation, a user with every privilage possible, can't get that domain RDP access to it, only from local corp/admin. Please some hints

#

Not just RDP, even PsExec if falling on me

granite valve
#

yo @trim beacon ; after the network reset ; do i need to reset the swift process too ??

#

cause i cant login with same email and creds now ;

#

and someone's eavesdropping in the network.

granite valve
#

I know i am a red-teamer and u my client --> but some blackhat hackers doing smthing mischief

#

seems thats the problem for most r.n

trim beacon
trim beacon
trim beacon
dull kestrel
muted compass
#

Does anyone have advice for me on how to add an enterprise admin account on the root dc, i was able to exploit it and submit the flags but user creation errors out in my psexec session.

#

I used || a golden ticket with mimikatz || for the initial compromise, but i need to setup persistence to further attack the bank division

weary flicker
#

For some reason im connected to the VPN but cannot reach any servers, I think the environment didn't really boot up?

serene sedge
serene sedge
#

@tardy wharf spammed it almost everywhere ^

weary flicker
long prawn
#

failed to submit the flag
Issue with reading the file provided: 'utf-8' codec can't decode byte 0xff in position 0: invalid start byte

i try with this command but still not wokring cmd.exe /c echo 3bf54534-7247-47c1-xxxxxxxxbb > filename.txt

warped grail
long prawn
dull kestrel
hidden galleon
dull kestrel
#

echo "---------------------" | Set-Content filename.txt

warped grail
brittle badgeBOT
#

Gave +1 Rep to @dull kestrel

muted compass
#

The corpdc on 116 again responds with invalid credentials upon authentication with rdp. Is there another way to fix this instead of letting the timer run out?

muted compass
warped grail
#

Password has been changed, you have to step back and get that hash again.

muted compass
#

I can login with eviln-winrm so the password is working fine

mental dome
weary flicker
#

It keeps giving me this message when I'm trying to finish task 19

#

and it says I have an active SWIFT check, option Z gives another error:

forest plinth
#

If it really doesn't work, you can choose to reset SWIFT and start again.

weary flicker
brittle badgeBOT
#

Gave +1 Rep to @forest plinth

weary flicker
#

I finally did it!! I didn't do any phishing though so I wonder where that has been needed lol

torpid ore
#

Wonder if anyone has breached through phishing πŸ™ƒ

mental yew
trim beacon
normal ocean
hoary cobalt
#

According to the scope:

Attacking any hosts outside of the provided subnet range. Once you have completed the questions below, your subnet will be displayed in the network diagram. This 10.200.X.0/24 network is the only in-scope network for this challenge.
(dumb question)
However, when I initialized the vpn for the corpUsername.ovpn. I got IPs outside of 10.200.X.0/24 network starting with 172.X.X.21/32 and 172.X.X.22/32 for the net_route_v4_adds. Would this mean running a scan on these is incorrect?

#

Im going to attempt to delete the configuration file for that ovpn and re-downloaded it and edit the file again

tardy thicket
#

@trim beacon we have 13 days or w/e is left to submit the writeup right? No need to rush it?

serene sedge
torpid ore
hoary cobalt
normal spire
#

3 flags down, 17 to go

#

awesome network so far kudos @trim beacon

maiden dagger
#

any clue on getting this

PUSH: Received control message: 'PUSH_REPLY,route 10.2001.21 255.255.255.255,route 10.2001.22 255.255.255.255

#

10.2001.21 ?

#

is it 10.200.1.21 and 10.200.1.22 ?

cerulean wraith
normal spire
#

or sometimes they might just work without you doing anything

tardy sage
#

I have a little problem, when I try to connect to the vpn (the .ovpn file, that I found in the beginning) worked well, but now it is like a infivite loop, because the connection in off and it is restarting, after it gets a connection

dull kestrel
normal spire
#

try to find anothe way in if vpn doesn't work

#

there are like 4 other ways (||CMS||)

tardy sage
#

Okay, I think think this is the easiest I found

#

but except wait, I can not do anything

slender verge
normal spire
#

yeah, honestly me too though my vpn seems to be stable these days

#

though today i might go back and it might be broken again

#

while it's broken i'm looking at other ways in, still working (apparently you can phish??)

slender verge
#

I did try to do a campaign with GoPhish, but I must have failed to configure something properly

normal spire
#

i havent figured out how to send emails yet haha

#

my smtp settings must be brokenn

slender verge
#

I followed the guide from the path aaand it didn't work 😁

normal spire
#

yikes yeah

#

thersΓ© also probably a way through the ||cms login page|| but no dice yet

#

if you figure anything out feel free to dm me because i havent :/

#

(if the challenge allows)

slender verge
normal spire
#

yeah, i tried the same thing

#

also i feel like the ||todo list|| is exploitable but again no dice

slender verge
#

yeah, must be missing something small but crucial

normal spire
#

there's also ||mssql|| running on one of the machines no? not sure if that's exploitable though

slender verge
normal spire
#

going to get back into it in a bit and if my vpn just dies again will have to look for other ways in

slender verge
#

good luck!

normal spire
#

ty you too

#

will update you if i find something

slender verge
#

thanks

tardy sage
#

thanks

muted compass
#

I just finished it today πŸ₯³. Fantastic network @trim beacon, btw has anyone tried exploiting the || october cms lfi || for initial access?

pseudo parrot
#

I'd be surprised if you can't.

slender verge
#

I finally got my first flag, I could cry of joy πŸ˜‚

normal spire
#

nice!

slender verge
pseudo parrot
slender verge
pseudo parrot
torpid ore
#

Nice man!

slender verge
pseudo parrot
#

Hope you seen that πŸ˜‰

normal spire
#

currently there too

slender verge
brittle badgeBOT
#

Gave +1 Rep to @pseudo parrot

trim beacon
trim beacon
trim beacon
trim beacon
brittle badgeBOT
#

Gave +1 Rep to @muted compass

lyric stream
dreamy comet
#

so is there any prize for submitting a writeup??

lyric stream
dreamy comet
#

ohhh those prizes are for the writeup, gotcha

viscid frost
#

Verifying your email access using your credentials, please stand by....

There was an issue with email access, the most likely cause is a network reset. Please stand by....
Creating email user
ssh: connect to host 10.200.103.11 port 22: No route to host
Something went wrong with user creation

Repopulating mailbox. Please stand by.....
[Errno 113] No route to host
Error: unable to send email

=> Is there anything I can do? I cannot interact with any machine / IP in the network. I also tried from attackbox and I got the error above.

#

3: capstone: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
link/none
inet 10.50.99.xx/24 scope global capstone
valid_lft forever preferred_lft forever
inet6 fe80::3fc9:e213:92e7:9a48/64 scope link stable-privacy
valid_lft forever preferred_lft forever

serene sedge
#

Probably ran out by now

viscid frost
#

57 mins left 😦

#

But ok, thnk you for the hint. Then I probably was just lucky until now and that is the issue described in the intro of the room

white portal
#

haha I wondered why sudo stopped working, someone overwrote the whole passwd file to just one user xD

granite valve
#

@trim beacon The Bank finally got pwned after 3 sleepless nights . Thanks, for this wonderful room man . initial and approver took a long time ; others i pwned like a boss 😎 . I'll be back again to pwn this bad boy with other vector ; . JAI HOSS !! 😈 🦾

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

normal spire
#

let’s goo i don’t need to use this unstable vpn anymore found an alternative way in atada_big atada_big

rotund magnet
#

there is pain pain, and there is reset network before final transaction pain

#

gonna continue tomorrow before someone crashes it again

dawn zinc
serene crystal
#

The SWIFT reset seems to be broken. followed my kill chain 3 times now to get to here. The first time I was reset just before the last 2 flags. Now non of the payment information wok. I get the following when I reset swift

trim beacon
trim beacon
brittle badgeBOT
#

Gave +1 Rep to @granite valve

trim beacon
trim beacon
grand cobalt
#

is it good for me that i started red team capstone when i am not completed offensive pentest path

trim beacon
grand cobalt
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

serene crystal
#

I have run the attack chain so many times to get to the SWIFT with the various resets or disconnects. I finally got it all done this morning. Thanks @trim beacon for the last bit of technical support this morning.

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

trim pecan
#

why after connecting to 2 vpn the config i found on .12 i stopped seeing other network?

trim beacon
brittle badgeBOT
#

Gave +1 Rep to @serene crystal

trim beacon
frosty bluff
#

Thanks for the great experience and for your hard work @trim beacon πŸ™‚

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

hexed whale
#

Despite not doing this (no plan/streak) thank you @trim beacon for creating this! Sat and watched my last few of the series by @quaint knot (thanks to him too).

Loved every minute and cannot wait to see what happens next

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

analog relic
#

Hi, anyone can help, as I was not able to start this room, it always stay the the same, not showing the IP addresses, I rest many times, I am not sure what I am doing wrong here, is not suppose after few minutes show you the IP addresses?>

hidden galleon
dense vessel
dense pecan
analog relic
delicate imp
#

Hi, the proof of compromise verification is broken on 10.200.118.250 for the Red Team Capstone Challenge:

Once you have performed the steps, please enter Y to verify your access.
If you wish to fully exit verification and try again please, please enter X.
If you wish to remove this verification attempt, please enter Z
Ready to verify? [Y/X/Z]: Y
Warning: Permanently added '10.200.118.12' (ECDSA) to the list of known hosts.
ubuntu@10.200.118.12: Permission denied (publickey).

Could not recover the verification file, hence flag could not be verified

#

Can anyone help me with that issue?

#

As far as I can see, the authorized_keys file of the ubuntu user has been overwriten

trim beacon
trim beacon
forest plinth
normal spire
#

sigh... someone deleted the whole /etc/passwd file on .12

#

or made it only have one user in it

#

reset time ugh

#

could some staff reset the 118 subnet? don't feel like waiting 2 more hours... thank you!

clear badger
normal spire
#

yeah... though i would prefer using the technique i have used so far i'll look i guess

trim beacon
normal spire
#

dmed

rotund magnet
#

anyone ever had a problem with blinking rdp black screen

mental yew
#

... blinking how?

granite valve
normal spire
#

CORP-DC has fallen! atada_big

rotund magnet
#

thank @trim beacon the swift reserve bank has fallen!!! One of the best, if not the best AD lab there is, so creative and exciting lab enviroment. I wish I would gain that 1337 level when i completed it xd, but who cares I got the badge and it was an epic path full of network resets and stolen credentials πŸ˜„

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

regal oasis
#

Can someone help me figuring out how to be able to attack the wrk1 and wrk2 after I connect with the ovpn file? There’s something wrong with the routing and can’t figure out how to fix it

normal spire
#

Dm me

#

I’ll give you some hints

trim beacon
brittle badgeBOT
#

Gave +1 Rep to @rotund magnet

regal oasis
weary pecan
#

hey ^^ anyone available for a small tip on .13 ? I've found several small things, but I miss a big thing I guess πŸ˜…

viscid frost
#

Is there any way to get out of the terrible 103 network?

granite valve
viscid frost
#

Nice, that actually worked. Thank you πŸ™‚

normal spire
#

LET'S GOOOO atada_big atada_bigatada_bigatada_big

#

yikes i think i broke my vpn connection now

#

that sucks i wanted to spruce up my writeup before submitting it

#

alr nice it's bacj

forest plinth
#

I submitted the writeup immediately after completing the challenge, and didn't think too much 🀣, Hope I don't lose my prize for a small problem

normal spire
#

submitted writeup πŸ”₯

#

anyone who needs hints on this challenge feel free to dm me btw!

normal spire
#

kudos again to @trim beacon for such an awesome network, def the best thing I’ve done on THM so far

trim beacon
trim beacon
brittle badgeBOT
#

Gave +1 Rep to @normal spire

fallen ether
#

Are the ||routes on the employee entry supposed to point towards 172.32.5.XX||?

trim beacon
fallen ether
normal spire
#

Hey @trim beacon would it be possible to get certificates like throwback?

trim beacon
normal spire
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

slender verge
#

is there any kind of solution to this?

wet wolf
#

||Anyone ever had a problem with the internal VPN connection resetting all the time? I cant seem to establish a proper connection anymore. Getting: Connection reset, restarting [0] & SIGUSR1[soft,connection-reset] received, process restarting all the time||

slender verge
wet wolf
brittle badgeBOT
#

Gave +1 Rep to @slender verge

slender verge
normal spire
dull fable
#

Hello everyone, I have an issue that stops me from getting the first flag, I compromise my first machine, followed the steps, and didn't receive any mail with the flag, there was this message : "Well done! Check your email!" then "Error: unable to send email"

So I verified email access through e-citizen, it detected an issue and created a new user, and now it tells me that I already received the flag and that I should remove it ?

Tbh i'm unsure if I configured evolution correctly

clear badger
cursive cypress
normal spire
#

remove the flag

#

then redo it

dull fable
#

Thanks guys 🦾

distant cypress
#

Oh my, I made it! This has probably been the best room I have done so far! Unbelievable what you managed to create here, kudos! @trim beacon And thank you @quaint knot for your guidance along the way!

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

dawn zinc
#

anyone open to helping me? I tried multiple ways to get to the 1st flag but all of them either ended in the 172 or just plain didn't work NotLikeThis

dawn zinc
trim beacon
brittle badgeBOT
#

Gave +1 Rep to @distant cypress

slender verge
normal spire
slender verge
#

it seems to happen every single time I add a user of my own as Administrator on WRK1

normal spire
#

huh

#

worst case you can do net user Administrator <newpasswd>

#

but not sure why that would happen

slender verge
#

might break things for other people

#

I lose access to any /domain commands basically

normal spire
#

wait... why are you trying to add a local admin on wrk1 using /domain

slender verge
#

doesn't the user need to be part of the domain?

normal spire
#

which you probably don't have privileges to do

#

/domain basically adds a user to the whole domain and without it it'll just be on the local machine

regal oasis
#

10.200.118.x network is completely broken only reachable host is the ecitizen can someone look into this or users press reset?

normal spire
#

i pressed it

regal oasis
brittle badgeBOT
#

Gave +1 Rep to @normal spire

dreamy comet
#

so is there a flag to get on the VPN server??

normal spire
#

not really

#

once you get to wrk1/2 you get 3 flags

dreamy comet
#

oh so 3 of the first flag? (sorry for the ping btw πŸ˜…)

#

(i was having a stroke)

vital dirge
#

is anyone around to help me get with rootdc

warped grail
open heath
#

Anyone having issues RDPing into the RootDC? I have psexec access, I changed the admin password but I get the following error when I try to RDP into the host "the connection was denied because the user account is not authorized for remote login" I have tried giving access from the command line but no luck, not sure what's missing

tardy sage
#

I have the problem, that I can't realy generate a golden Ticket. The ticket is gernerated successfuly, but no PAC is generated and signed, I don't see a user id and I don't see groups ID that is generated.

#

I think something with the domain is strange

trim beacon
#

Just thought out of interest to post the latest stats:

  • 1000+ room joins from release
  • 538 profiles registered on E-citizen
  • 166 users has submitted at least one flag
  • 1604 flags have been submitted in total (average of roughly 10 flags per user)
  • 52 users have completed the challenge

Good luck to all for the final push!

heavy crag
#

sanity check? can anyone browse to 10.200.89.13 to confirm it's up? So far, I've even went back to regen the room ovpn, then revalidate email, wait 5 minutes, confirm /etc/hosts file is correct. nmap scan shows port 80 filtered

pseudo parrot
normal spire
#

i am one of 52 sunglas

tardy sage
open heath
#

I am on .89 and nothing has been accessible for about 2 hours

#

except .250

open heath
normal spire
heavy crag
brittle badgeBOT
#

Gave +1 Rep to @open heath

serene sedge
#

Guess it worked

heavy crag
tardy sage
#

Why can I not upload images here, to show my problem?

serene sedge
#

U need to verify your discord wiith ur tryhackme account

#

!doc verify

#

!docs verify

granite emberBOT
serene sedge
#

There xd

heavy crag
# serene sedge Guess it worked

so when u encounter the 172.x.x.x nonsense in the openvpn connection right after a room reset, is it because you need to reverify email access via ssh 1st? I'm doing that now and waiting a few minutes. to clarify this is the internl ovpn file (the one you "find")

serene sedge
heavy crag
#

does it default to 172 when there is too much traffic?

serene sedge
#

Dunno when it does that, but if you look around in this channel u see a bunch of ppl got stuck on this and find some more hints to how to solve it

broken nest
open heath
dawn zinc
#

did anyone have this problem before? why can't I send a picture? my Network diagram is just grey there is nothing there

fervent sail
#

You need to verify to send images

#

!docs verify

granite emberBOT
dawn zinc
brittle badgeBOT
#

Gave +1 Rep to @fervent sail

dawn zinc
fervent sail
#

oh that is weird, I'm sure you have tried to refresh the page already?

dawn zinc
#

okay random I had it yeterday all day and today too now It randomly worked again

#

weird

fervent sail
#

That is odd, glad it working for you now though

sinful mortar
#

hey guys im having this problem while trying to submit a proof of compromise Ready to verify? [Y/X/Z]: Y Warning: Permanently added '10.200.116.102' (ECDSA) to the list of known hosts. Connection reset by 10.200.116.102 port 22 . I'm using meterpreter to pivot and I checked that I am able to reach the domain controller as I can login and follow the instructions to get the flag, but whenever I hit verify, it gives this.

candid yacht
#

Hey everyone. So I just got started with this task and everything seemed fine at first. I ssh’ed in and registered, no problem. Then I tried to verify my email address and I get that β€œssh: connect to host 10.200.103.11 port 22: No route to host” error. Do I have to wait until the network timer runs out and try again?

#

I also can not reach the webserver either..

slate hill
#
Creating email user                                                                                                                                                  ssh: connect to host 10.200.103.11 port 22: No route to host                                                                                                         
Something went wrong with user creation
#

I am getting same error as well

#

can't reach .11 neither web server

#

Could a couple other people vote for the "Reset" please.

clear badger
#

@slate hill @candid yacht
You can wait for a reset, or leave the room, wait a few minutes, and join back in to be placed in a new subnet that is working.
Of course because everyone is doing this, the 103 subnet never gets reset but at least you can personally continue on.

candid yacht
brittle badgeBOT
#

Gave +1 Rep to @clear badger

heavy crag
#

anyone run into filtered ports after setting up proxychains and metasploit trying to move to the .31 -slow going today with all the resets - it's war in here! Retraced my steps 3x, any advice?

long prawn
#

any idia what is the issue?

trim beacon
trim beacon
distant cypress
regal oasis
#

How do I get to the email ????

#

I mean to see the emails

trim beacon
pseudo parrot
#

Enumerate!

long prawn
brittle badgeBOT
#

Gave +1 Rep to @distant cypress

dreamy comet
#

so no flag on both ||31,32|| ??

trim beacon
long prawn
brittle badgeBOT
#

Gave +1 Rep to @distant cypress

distant cypress
#

Alright awesome!

dreamy comet
#

but both hostname doesn't seem to be right for the 4 or 5 flag

dreamy comet
# trim beacon How did you try to get a flag?

no idea what i was doing wrong before but the 5 and 6 flag seem to be working with these hostname but my new issue is i keep getting this error: seem the work with this hostname now Issue with reading the file provided: 'utf-8' codec can't decode byte 0xff in position 0: invalid start byte fixed, thanks @warped grail

open heath
#

If anyone is on the .89 network can you press the reset button, it's inaccessible again after it went to sleep 😦

long prawn
distant cypress
open heath
brittle badgeBOT
#

Gave +1 Rep to @fringe yoke

fringe yoke
brittle badgeBOT
#

Gave +1 Rep to @dreamy comet

open heath
brittle badgeBOT
#

Gave +1 Rep to @dreamy comet

normal spire
#

9 days left! everyone who's still trying, you got this!

open heath
#

Just finished! πŸ₯Ή 😏

normal spire
#

congrats atada_big

long prawn
#

I don't receive the PIN into my email for transaction any help?
and my creds also not working in bank website

open heath
regal oasis
#

Also having issues with finding the final pin for the transfer

#

According to ecitizen it’s sent to email but i haven’t received a any pin

normal spire
#

for anyone who fixed their email access after they redeemed a flag:
go to e citizen, verify past compromises, then delete the flag that you didnt get an email for
then simply re get the flag

stark hemlock
#

For those going for the VPN route, it's still possible but you have to ||rewrite the configuration of the profile||

tardy sage
#

I am stuck on this thing for hours, so my question is, when I have access on 102 and changed the password from the administrator on 100, how can I access 100 with rdp?

heavy crag
# trim beacon Can you run nmap from .12 and see if that gives you a different response?

I can nmap just fine (find open ports) while on .12, just not from my machine using proxychains. I have triple checked my proxychains4.conf, tried dynamic and strict setting (same result). I find it interesting proxychains chooses the proxychains4.conf by default when no proxychains.conf exists (is this OK?). Honestly stumped as I've done this before in other labs with my same kali setup.

trim beacon
#

Also, have you modified the vanilla proxychains file as well? Not just proxychains4?

#

So like /etc/proxychains.conf?

heavy crag
#

I mean I'm already root with a new user added so I guess I could "rough it" and launch my attack by uploading all my tools..... but just trying to go with the flow here.

trim beacon
#

I don't see that your proxychains are showing a chain and you are not running it in silent mode, which tells me the config isn't being respected

#

Give me some feedback on my other questions and let's debug from there

heavy crag
trim beacon
#

Can you add the -sT flag?

heavy crag
#

ok so unless I'm missing something in th confif file- its set to strict, have tried dynamic. proxy dns is set (range 224) and using sock4 127.0.0.1 9050 in Proxy list

trim beacon
heavy crag
trim beacon
#

Usually -Pn alone should work, but have seem some weirdness with nmap requiring the explicit -sT as well

heavy crag
trim beacon
#

Lol

heavy crag
#

so this is a very good sign proxy is working, yes? boy, I'm getting a troubleshooting workout in this one!❀️

trim beacon
#

So the pivot was working perfectly πŸ˜‚

trim beacon
heavy crag
#

even the 70 step metasploit (exaggerating) was working then- it's just darn nmap lying to me

#

I mean I almost expect that kind of behavior from openchat GPT, but nmap??? say it aint so

trim beacon
#

Lol, good luck with the rest there!

heavy crag
#

thanks for the fast help too . -sT going in my notes.....

heavy crag
tardy sage
# normal spire just rdp corpdc->dc

Do you know the command. Because I donβ€˜t really know how to get a rdp session in a remmina session (because I have only access to 100 when I have remmina on 102). I donβ€˜t know how to get further. πŸ˜…

fervent sail
tardy sage
brittle badgeBOT
#

Gave +1 Rep to @fervent sail

fervent sail
normal spire
#

and open it

tardy sage
#

Ah I think ChatGPT say that to me. But it doesn’t react, when I execute it in the 100 shell in the 102 rdp session

tardy sage
brittle badgeBOT
#

Gave +1 Rep to @normal spire

tardy sage
slender verge
#

I've tried to use ||chisel, Metasploit and ssh to proxy my traffic through the VPN server||, but none of it has worked πŸ˜”

#

I even followed Tyler's guide to the letter for Metasploit and still nothing

heavy crag
# trim beacon Lol, good luck with the rest there!

sanity check please? everything alright with my room status ( havent been banned?). Im basically starting from scratch after being locked out of .89, left room, now on [Redacted] subnet - could not even connect there. tried to regenerate ovpn for Redteamcapstone, instead it only onlys me to generate my THM ovpn -- on the brink of no joy

trim beacon
#

When you say can't connect? What's happening?

trim beacon
heavy crag
#

that was so 10 steps ago, hardly remember, I'd like to report a bug on the Access page. system will regenrate your user ovpn, despite clearly populated as Redteamcapstonechallenge - it has been happenening intermittently but now 4x in a row

trim beacon
heavy crag
#

understood, just trying to explain my situation in case you see any pattern to help others

slender verge
trim beacon
trim beacon
slender verge
#

Scanning from the VPN host itself works fine every time.

  1. Chisel is just supposed to be two commands for client and server

./chisel server -p 8080 --reverse on my machine
./ client 10.10.14.3:8080 R:socks on victim machine

It seems like it's working, but when I run for example:
proxychains -q nmap -Pn -p 3389 10.200.116.31 -v , shows up as filtered along with any other port

  1. SSH:

ssh -i id_rsa -D 9050 ubuntu@10.200.116.12

Trying with this command I get this output:

"Password authentication is disabled to avoid man-in-the-middle attacks.
Keyboard-interactive authentication is disabled to avoid man-in-the-middle attacks.
Port forwarding is disabled to avoid man-in-the-middle attacks."

Trying to enable password authentication and port forwarding in the sshd file makes no difference.

  1. Metasploit: screenshots, step-by-step from Tyler's video, added socks4 127.0.0.1 9050 to proxychains.conf, still no dice, ports still filtered.
south mirage
#

Did you try using nmap -sT?
SYN scans over proxychains will not work and always show as filtered, so only connect scans will actually go through

heavy crag
slender verge
brittle badgeBOT
#

Gave +1 Rep to @south mirage

trim beacon
trim beacon
slender verge
heavy crag
trim beacon
trim beacon
#

I even left a .bak file there if you modified it without saving a copy πŸ˜‚ was trying to be nice

heavy crag
#

paying it forward feels good! lets see how long it lasts, just trying to push to the 1st DC - feels like climbing a greasy pole. great troubleshooting practice but feels more like an adversarial game of koth than a Red Team engagement

normal spire
#

or you could just use the other less known way in heh

heavy crag
#

@trim beacon or anyone on .118 can you extend the room? t minus 2minutes.....

trim beacon
heavy crag
#

somehow its still going!! miracle! also notice Defender comes back on after disabling ...after awhile.... kinda like real world eh?

#

no worries zzzzz's are gold!

trim beacon
heavy crag
#

yes of course- such a noob i am- done that before- shows how rusty ive become doing web apps and cloud-lol. ive done that before and its good practice- thank you

#

one might say if you can survive this 14 server war zone, the PNPT with only 3 servers (I think) should be mild by comparison

crude flame
#

When I try to logon to one of the machines in the network it works via the Attackbox but not when I use my own VM and connect via a VPN. Is anyone able to help? I used the exact same credentials both times but can't seem to get it working via my own VM

granite valve
stuck trench
#

Is it normal that when I want to do "nmap -sC" or "nmap -sT", it tells me that .102, .31, .32, .21, .22 are all in "filtered" or "ignored state".
PS: On the tryhackme page, after referencing the first flag, it shows me the CORPDC but not the IPs

fading timber
#

Hi, When I run sudo openvpn corpUsername.vpn I get addresses in 172.32 instead of 10.200

stuck trench
#

Same, but you can use "sudo ip route add 10.200.XXX.21 dev tun0" and that should work

fading timber
fading timber
flat folio
stuck trench
#

xfreerdp /v:IP /u:USERNAME /p:Password

fading timber
flat folio
#

add the route before

fading timber
fading timber
fading timber
fading timber
fading timber
#

Is it better to do the challenge with AttackTheBox than Kali ?

clear badger
heavy crag
# fading timber I have same pb, do you resolve it ?

You need to add routes. Out of respect to everyone inc room builder, that's all I'll share- if you don't know about this it pays to slow down to really learn this part (networking 101) - I had to and I'm glad I did. There's plenty of hints about it in this forum if you care to search- happy hacking!

#

@clear badger network was reset last nite after I had achieved ROOTDC and created "persistence" with add domain admin user account. Has all been wiped? if so, how do you create lasting persistence in real AD pentest when system gets turned off/rebooted? Or is that what you count on- system is rarely turned off?

slender verge
#

It has been wiped, yes

#

Irl systems don't get reset like that, the point here is to go back to a clean state in case someone breaks something

heavy crag
brittle badgeBOT
#

Gave +1 Rep to @slender verge

trim beacon
trim beacon
fading timber
brittle badgeBOT
#

Gave +1 Rep to @heavy crag

fading timber
last bluff
#

Would be nice to remove the streak requirement as it nears being locked. I got excited when I saw the spam in my inbox about it, only to be denied.

clear badger
last bluff
#

Hopefully I can sneak in some time next week.

#

Is it?

fading timber
#

How to leave the room ?

sterile elk
#

so someone reseted the room and now the c*****.ovpn gives me different internal routes, but they aren't working... they were before

#

also the connection keeps resetting itself

serene sedge
fading timber
#

On what video between 3 and 8 ?

heavy crag
dawn zinc
#

did something happen that I was automatically removed from the room and had to join again? changes to the challange or something?

sterile elk
#

I generated a .ovpn file on the vpn portal and it's still resetting all the time

dawn zinc
#

ah yes that took me 4 days to understand

dawn zinc
trim beacon
heavy crag
brittle badgeBOT
#

Gave +1 Rep to @trim beacon

brittle badgeBOT
#

Gave +1 Rep to @trim beacon

trim beacon
heavy crag