#bandit-network-challenge

1 messages Β· Page 1 of 1 (latest)

cerulean cobalt
#

Please note: For free users, this Network requires a 7-day streak. πŸ₯³

wary mantle
#

πŸ΄β€β˜ οΈ

wraith mesa
mighty gulch
#

:O

#

New network room is sick

wraith mesa
#

Good luck to all

mighty gulch
#

too bad my streak is over :(

blissful forum
#

meep meep go go go

final wyvern
#

cannot ping the machine with machine vpn

jagged garnet
final wyvern
#

VPN profile keeps restarting itself

wary mantle
jagged garnet
wary mantle
#

The VPN file should be ok.

final wyvern
#

All the machines are busy at the moment, please retry later

wary mantle
final wyvern
wary mantle
final wyvern
#

my vpn works now with regen

wary mantle
#

Happy hacking.

cerulean cobalt
#

Need one volunteer: anyone who is not in the 10.200.64.x subnet? πŸ˜„

#

@scenic pasture Which subnet are you in?

final wyvern
#

i'm in 10.50.61.17

#

i can reach 10.200.64.10

scenic pasture
#

oh sorry misread I actually am 64 πŸ˜΅β€πŸ’« , need to sleep more

acoustic orbit
#

All the machines are busy at the moment xD

final wyvern
#
$ ssh register@10.200.64.250
register@10.200.64.250's password:

Welcome to the Bandit challenge!
Please make a selection:
[1] Register
[2] Exit
Selection:1

Your VPN IP will start with 10.50.61.X. Please provide us with X, the last octet of your VPN IP:
17
All the machines are busy at the moment, please retry later
Connection to 10.200.64.250 closed.

#

so we need to register to get into 10.200.64.x subnet?

cerulean cobalt
final wyvern
acoustic orbit
#

same

cerulean cobalt
#

Let me check. (still checking)

wary mantle
#

I'm in 64.

#

If you still need someone.

dawn ermine
cerulean cobalt
#

I need someone who is not in 10.200.64.x πŸ˜„

wary mantle
#

:d

#

I'll try my best.

#

Ok

#

I'm in 114.

#

No wait, I'm not πŸ˜‚

swift comet
#

I'm in 61.24

dawn ermine
cerulean cobalt
acoustic orbit
#

I seem to be in 10.200.114.x now, though the ip under the linux machine is still showing 64.x but the windows one 114.x

velvet linden
#

Yeah same issue here

acoustic orbit
#

the registration seemed to have worked though

wary mantle
#

I think they're all the same.

cerulean cobalt
wary mantle
#

Server reset work?

jagged garnet
#

should we do register again here?

calm gazelle
#

im also getting the same error "all machines are busy"

jagged garnet
#

now me too

calm gazelle
#

today has been a rough day for ctfs for me. lots of tech issues

#

not just here at thm

cerulean cobalt
#

Please note: In case you get the following output when registering:
All the machines are busy at the moment, please retry later

Leave the room (Gear icon βš™οΈ > Leave), wait 2 minutes, and rejoin. The Windows IP 10.200.x subnet should have changed, where x should no longer be 64. πŸ™

A successful registration should look similar to this:

Please add the challenge IP to your /etc/hosts resolving with the hostname bandit.escape 
Good luck

Thank you for using challenge registration, goodbye!
Connection to 10.200.zzz.250 closed.```
calm gazelle
#

how do i leave a room? sorry noob question

#

i see, its in the gear wheel

jagged garnet
#

hahahhahaha why " 14" is work πŸ™‚

cerulean cobalt
calm gazelle
#

Thank you πŸ™‚

final wyvern
#

Network state: Resetting

cerulean cobalt
#

All should be fine now, please let me know if registering is not working. 😎

tiny thistle
cerulean cobalt
tiny thistle
#

Oooh, sorry

cerulean cobalt
#

Some bandit had stolen all the subnets, we've recovered them now. πŸ΄β€β˜ οΈ πŸ˜‚

alpine bear
#

"3 days of access left" Does that mean we have to finish in 3 days?

cerulean cobalt
gleaming adder
#

Man, this first webpage is already a wall

wraith mesa
wraith mesa
gleaming adder
#

Thanks thanks :> nothing so far though

wraith mesa
#

Little crumbs here and there together make a whole cake

gleaming adder
#

Only found one thing so far using ffuf

#

I hate not being able to use gobuster ;-;

wraith mesa
#

And just for your general reminder:
Please be mindful as a general guideline to not ask for/provide hints in the first 72 hours after a challenge is released. πŸ™

gleaming adder
#

yep yep, we're trying harder

cerulean cobalt
#

Everyone having fun? πŸ˜„

scenic pasture
#

yap πŸ˜„

final wyvern
#

very very fun

scenic pasture
#

mmh seems like my target hung up, time for a break πŸ˜„

gleaming adder
#

pretty goofy

#

but the true hacking experience

cerulean cobalt
gleaming adder
#

Correct and then some, or I'm overlooking something completely

wraith mesa
#

Blood is still up for grabs 🩸 it’s still anyone’s game

final wyvern
#

exploited 2 vulns, but not yet get a flag

#

πŸ₯Ή

#

i am not sure if my instance is broken. can i ping a mod for a checkpoint?

cerulean cobalt
final wyvern
#

it is supposed to be 1 minute interval right

#

sometime it is missing

blissful forum
#

looks through the documentation for this well this is definitely not easy

cerulean cobalt
blissful forum
#

or possibly reseting

wraith mesa
#

Keep it going!

blissful forum
#

good job jaxa

wraith mesa
blissful forum
#

have a feeling this might not get the top 10 users completed until tuesday next week

scenic pasture
wintry mist
#

Nice room ! Still working on it . I hope finishing tomorrow 🀣

lunar plaza
#

Huge thanks to anyone involved, was an awesome room!

wraith mesa
#

Congrats @lunar plaza πŸ₯‡

wraith field
#

Those components are not connected. Are you sure about it? Can you perhaps reach me privately?

tall phoenix
#

we have a second foothold: congrats @final wyvern !

blissful forum
#

go go go go people prove shadow wrong in how long it will take to reach 10 completions

wraith mesa
#

+rep @wraith field

fierce mantleBOT
#

Gave +1 Rep to @wraith field

velvet linden
#

That room was a bit wild! I really liked it. That last part was funky to say the least 🀣

#

+rep @final wyvern

fierce mantleBOT
#

Gave +1 Rep to @final wyvern

wintry mist
#

Shadow is not wrong ! I’m clueless

#

403

scenic pasture
#

is there an issue with subnet .64? I am able to register, but no machine I get is reachable

cerulean cobalt
scenic pasture
fierce mantleBOT
#

Gave +1 Rep to @cerulean cobalt

wraith mesa
#

Top 10 is still up for grabs

scenic pasture
#

yeah stuck on the edge of the foothold, got some privileges on the site :D. Hope that's allowed to share here πŸ˜…

wraith mesa
lusty glacier
#

uhhh i think i broke it - a page is just endlessly redirecting...

hot falcon
#

yeah mine too...

cerulean cobalt
compact tangle
#

EYYY New network!

lusty glacier
cerulean cobalt
compact tangle
#

Gotta give it a try, need a streak for that, so streak it is!

jagged garnet
#

i cannot access ssh now its filtered

velvet linden
jagged garnet
#

bandit.escape

velvet linden
#

Did your network reset, and did you register?

jagged garnet
#

twice

velvet linden
#

Did you regenerate your VPN?

#

I had to do that 3 times, before I realized I was doing something stupid.

jagged garnet
#

yes

#

oo

#

thanks! i have survive

velvet linden
#

haha no problem, SSH should definitely not be filtered on the IP that the register bot gives you.

jagged garnet
#

for sure πŸ™‚

scenic pasture
cerulean cobalt
scenic pasture
#

The last part is killing me. I feel like I am in a prison, a really, really tiny prison. bashzoom

acoustic orbit
#

Yeah stuck with the second part too xD

jagged garnet
#

Done!

wraith mesa
#

πŸ‘πŸ½ πŸ‘πŸ½ spot number 4 is taken

#

+rep @jagged garnet

fierce mantleBOT
#

Gave +1 Rep to @jagged garnet

wraith mesa
#

There we go, silly Robocop

wraith mesa
#

I believe in you @scenic pasture and @acoustic orbit

Planning on doing a writeup @scenic pasture after?

wraith mesa
#

Nice, I'll look forward to it

jagged garnet
#

@wraith mesa are u here can u pm me please?

topaz edge
#

Just a sanity check for myself. I'm getting close to 4-5 attempts of 2-3 hours at this now.
I have some clues here and there, but nothing to really progress.

The network is indeed hard, seeing the room has over 300 users, with only 5 roots and 2 users flags.

wary mantle
#

Oh wow!

wraith field
#

Feel free to ping me for sanity checks!

topaz edge
#

w00p w00p!! User took too long, but learnt something new and that is the end goal.

velvet linden
#

^ rocket

scenic pasture
#

Many thanks to the creator, @wraith field, and all involved in this challenge. In the last few days, I have spent more time than on any other challenge so far (except the red team capstone challenge), and the best thing is that I could learn a lot again. My favorite part was the entire foothold and the fact that the ||sources|| were also ||locatable in the wild||. The last part really had me on the edge of my seat, and that was a good thing. Many thanks!

fierce mantleBOT
#

Gave +1 Rep to @wraith field

wraith mesa
#

But seriously the initial part of the foothold though 😎 wild

hearty whale
#

Thanks for this awesome room, I'm pretty new here on THM, and I really liked it.

Used way too much time on this box - I was supposed to do work for a client, but somehow forgot that.

(It's done now, but did not expect to use my night working.)

I'm on the free tier for now, but this has really pushed me closer to becoming a full member πŸ‘ well done.

wintry mist
#

Well .. I didn’t have much luck with this room , one day port 80, and 8002 open and next day filtered , I try several s networks like 64,133,135 etc .. then try to register and all the time was lost connection, lost connection . First day was awesome. So Don’t let for tomorrow what you can do today!

wraith field
wintry mist
#

Thank you for asking, yes several times. Also I try on diferentes computers that has installed kali , because maybe I have some corrupted file or something. But it’s the same thing.

#

Maybe πŸ€” it is because now there is more people on the network?

brittle canopy
#

I'm getting "lost connection" during registration too, regenerated the vpn configuration but the issue persist

pulsar fractal
#

this network still working? can't seem to register, just times out and the machines are not reachable (all from attackbox)

pulsar fractal
#

managed to finish it - the issue is inconsistent, but after a reset i was able to connect again and go through.

velvet linden
#

I've tried multiple VPN's and leaving / rejoining with new networks. @wraith field @cerulean cobalt

wraith mesa
velvet linden
#

I was trying to show a friend the challenge, that would definitely cause the issue.

#

Sorry for false alarm

wraith mesa
velvet linden
#

114 and 111

wraith mesa
#

Thank you πŸ™‚

velvet linden
#

No problem

pulsar fractal
cerulean cobalt
velvet linden
velvet linden
#

I'm pretty sure it's the opposite and @cerulean cobalt occupies all spaces.

young yew
#

I'm on the Bandit room and although I can use the AttackBox to SSH into the registration portal, and successfully edit the hosts file for adding bandit.escape, trying to access the web page in FireFox always times out and never connects. I can even verify the address is correct b/c nmap bandit.escape can sniff out the ports, which includes a filtered port 80 for http. What can I do to proceed with the room?

young yew
#

Is the room just broken? It wouldn't be the first time I've had issues with THM rooms being broken.

blissful forum
#

hit the reset button or play subnet roulette and see if another one works... network rooms are finicky

young yew
#

Well the Reset button is at 0/3, so even if I did press it, nothing would happen without others actively doing the room and pressing it as well. And subnet roulette? I thought the whole premise of doing the registration was to open a specific IP access point.

blissful forum
#

and you can send 1 vote every hour too

#

there is also the vpnscript

#

!vpnscript

haughty flowerBOT
young yew
#

Oh, my typical daily activity on THM is clearing one room per day.

blissful forum
young yew
#

It's worked so far during my 278 day streak.

#

Alright, trying again now with a new subnet. nmap result says the same with port 80 filtered for http, which never responds when trying to visit in FireFox on the AttackBox.

blissful forum
#

hmmm

#

oh wait... what vpn are you using @young yew

#

as the network rooms use their own dedicated vpn files

young yew
#

Ah, I finally found the issue. I had to look deeper into the bandit room VPN that's default on my OpenVPN page on the THM website interface, nothing to do with the AttackBox interface as I'm used to dealing with. Got the right octet value now so the nmap states all 4 ports are open.

#

And bandit.escape navigates properly now.

#

Thank you for telling me about the OpenVPN troubleshooter, @blissful forum. Without that directive, I wouldn't have known to search for my OpenVPN info on the webpage, even though I didn't use the troubleshooter directly.

blissful forum
#

nice that you could solve it

fierce mantleBOT
#

Gave +1 Rep to @blissful forum

blissful forum
#

you're welcome

young yew
#

YATTA

Thank you for the right nudge into starting the room once again, @blissful forum. I finally completed the room.

fierce mantleBOT
#

Gave +1 Rep to @blissful forum

blissful forum
#

nice good job

lavish lion
#

Hey everyone!

I'm currently working on the Bandit network challenge. I am trying to exploit the XSS vulnerability to steal the user's PHPSESSID cookie. So I first tried to steal my own cookie by using the following payload:
/"><script>alert(document.cookie);</script>
But it does not work. It gives me an empty alert like the one in the screenshot.

#

Any advise please?

#

thanks in advance

scenic pasture
#

looks like the session cookie is not set. Try to login with invalid creds first. This should give you a cookie to verify your approach.

plucky garnet
#

Hey need to restart bandit server.. Getting unreachable address after ssh

#

Anyone can vote? I'm on 10.200.130.10

plucky garnet
#

Can anyone help me out, I'm facing an issue, my http req smuggling payload is working fine when I'm using it with search feature of webpage but when I'm using python script to get cookies of another user it is failing ( python made request is working fine when I'm testing on my tun0 address locally)

plucky garnet
#

Finally done it.. anyone who will face struggle with this network, I'm leaving a note: try again and again if you are thinking you are doing everything right and not succeeding, try something different or recheck your payloads and retry, reset machine and again retry. My http smuggling request didn't work also I tried one mentioned is YouTube and took help from internet but nothing gave me positive response but finally got the cookies after trying for consecutively 3 days..
There are some issues in this lab but after resetting the network work fine.

rocky ruin
#

It doesn't seem to work even though the PHPSESSID comes from the target

indigo owl
#

Hello there, maybe I'm just crazy but it seems that I can't download my openvpn file to access Holo Network, when I try to do so, I get a 500, I do have an active subscription so I don't think that's the problem but basically as soon as I head over there: https://tryhackme.com/r/access and try to download hololive configuration file in the networks tab I get this in response:

#

Did anybody tried since January 2024 ? I saw that the last messages are in January 2024, so I don't think it's a problem on my end since I'm receiving a 500 as soon as I tried to get my .ovpn file...

wary mantle
#

Please don't ping random staff members please.

The bot could mute you.

indigo owl
#

Hey I'm sorry, I don't know who to reach out to 😦

#

@wary mantle Am I supposed to fill a ticket for this or how to get this solved ?

eternal orchid
#

You've put this in the Bandit network, if it's the hololive network, should have gone in #site-support or #holo-network

Few things you can try is:
Disable extension
Try incognito
Try refreshing cache
Different browser

indigo owl
#

My bad you right we're in the bandit channel, I got confused

indigo owl
#

Don't want to bother you but just to validate it's entirely on my end is it possible for you to just check ? That way I'll try other ways, but I just want to make sure the problem comes from my end...

cunning herald
#

Issue is it says permission denied

#

And

#

That does not match the

#

Bandit game

wary mantle
#

Can you verify and screenshot?

random graniteBOT
clever plover
#

bandit network not working? I left the room and joined and I cannot seem to ping the linux machine that is supposed to end in .250

#

tried both attack box and downloading bandit vpn on my own machine

#

I have not tried reseting the network so that will be my final solution. Honestly not having a good time with the premium rooms, something is always broken or not working. Also sad to see that this room has only been out for a year and is still having issues. At the time of release it seems to have had issues looking at the earlier chat history

#

I wont be renewing my subscription that is for sure πŸ˜‚

wraith mesa
#

Sorry to hear that you are having an issue @clever plover πŸ™

I just booted up the network, for the first time in over a year, and was able to complete it. Had no issues when connecting either.
Maybe I got lucky, and I am saying this because I don't want to dismiss your claim. Unfortunately, to keep these networks affordable for everyone, they are shared instances. And in shared instances, users tend to mess things up for other users. Sometimes on purpose, and other times, by accident. This happens everywhere, at least to my experience.

I did notice two issues when going through it which can hinder someone's progress. I reported and hopefully someone can look at it.

clever plover
# wraith mesa Sorry to hear that you are having an issue <@717799377137303647> πŸ™ I just boo...

Yeah I mean there will always be people messing around on the network trying to troll. But at least I can reset the network and still continue. Being not connected at all means I cannot do the machine at all. If this is a free room I would not really mind but its a premium room and I expect proper QA checks are done before such rooms are released because this is what THM users are paying for and they should get better experiences in premium rooms than free rooms. I have tried the FAQ advise on THM, which was to leave the room for 30 minutes and then join it again to be connected to another subnet. After 30 minutes I will rejoin and try my luck. But its mind boggling that 0day had to download the VPN file 3 times to get it to work and this was during its release. I am hoping this feedback gets taken on board when making any future network rooms, because overall this is not good.

wraith mesa
# clever plover Yeah I mean there will always be people messing around on the network trying to ...

You are right, certain things shouldn’t happen

But during QA, there wasn’t an issue with the VPN file because you have a small pool of people working on it

Interesting things happen when suddenly over 100 people start making requests. Again not to say that as an excuse, but I am not here to dismiss the QA process either. It is the 1001 test case.

But again, I do understand the frustration so I have passed this on and apologies for the bad experience

wary mantle
clever plover
clever plover
#

"We have millions of users waiting for us to do more, and if we don’t solve their problems better than anyone else, a competitor will." - Ben Spring. Yes he is definitely correct about that πŸ™‚

clever plover
#

any update on this network? when can we expect a fix for this?

flint mortar
rocky maple
#

Hello everyone I still don't understand how to connect. When registering, I specify the last act of my VPN. There is no connection. Is there a clear connection algorithm? Why make it so difficult to connect to this subnet, I don't understand at all?

rocky maple
#

What means:
Your VPN IP will start with .X. Please provide us with X, the last octet of your VPN IP: 2 lost connection lost connection lost connection lost connection
Is this the way it should be, or is it a sign that something went wrong?

rough cedar
#

Heyy