#holo-network

1 messages Β· Page 9 of 1

zenith delta
#

what's CME?

solid timber
#

If in doubt turn to google

#

That and/or do more enumeration

prime verge
#

Task 37:
I got the hash and the username but after running crackmapexec on the subnet I see the S-SRV01 is the only one I can authenticate however the task says we can authenticate to the fire server as well. What am I missing?

zenith delta
solid timber
#

I'll help you out in a bit. Not home rn and I don't remember how I found what it was.

empty ridge
#

Why is holo so unstable?

#

I can't access right now

zenith delta
#

Hello All, What does the 7 days of access left mean? What happens if I do not finish it in 7 days. Do I start all over?
Thanks,

solid timber
#

No. I forget the reason for giving a time limit, but you will not have to start over. (Even if you did, you should be taking notes so it would be easy to get back to where you're up to)

#

Speaking of holo, I gotta finish this sucker

wind bobcat
#

reason being more networks means less aws instances available for the rest of thm

solid timber
#

Ah yes. That was it lol.

zenith delta
#

Thanks for the information.

foggy spire
#

uhh little stupid thingy but i think colabcat and hashcat is not able to crack the hash

#

of task 22

#

it is giving error token value exceeded or the separator unmatched

solid timber
#

Yea, I didn't use colabcat. Couldn't make it work. I just used hashcat. Do make sure to crack it on your gpu tho. It'll take forever if you dont

lone spruce
foggy spire
#

yeah that what i want to know i am doing wrong

#

do i have to take the string till :::

#

or just stop at first /

zenith delta
#

I ran the gobuster command for the first question but got nothing positive

#

All I got was status code 400 size:442

#

somebody help me

solid timber
#

I couldn't get gobuster or wfuzz to work for that and I still don't know why. I was able to guess what the vhosts are tho

zenith delta
#

Or just anyone who solved it

solid timber
#

Honestly I just tried a bunch if common directories, that would make sense to be a vhost. Idk how to explain my thoughts process more.

#

Like, you should know what some common directories are to find on a website. Which if them would make sense to be vhosts?

#

Altho, if someone could explain how to do the vhost fuzzing that would be nice. Cuz I kinda wanna know what I did wrong

zenith delta
#

Subdomains top 1million...

solid timber
#

I didn't use a wordlist lol. Again, I couldn't get it to work with gobuster or wfuzz. So I litterwly just guessed

torpid pelican
#

Hey guys, I have some technical questions about what I am seeing. Can someone help me out?

torpid pelican
#

actually, that's exactly my issue as well

prime verge
frail axle
#

PC-FILESRV01 on 10.200.131.35 rejects valid credentials with error message that its TRUST fails (needs to rejoin domain). Please fix it if possible. Thanks.

frail axle
solid timber
#

Yea I tried that. I didn't wanna work lol

#

It*

lone spruce
#

So?

#

The script was there

#

and now its not?

#

AWS makes me cry

solid timber
#

if anyone could explain what im doing wrong would be dope

regal mason
#

Or replace it with url i guess

#

@solid timber

solid timber
night widget
solid timber
#

Yea. But if you do it dosent change the www, it just tacks everything from the wordlist onto the front of it. (So you end up with www.www.holo.live and all things like that)

night widget
#

I believe you can try it with https instead of http

#

But not sure though

#

Also just to be sure, have you added the ip address etc/hosts?

lone spruce
#

why is it pointing at a home address

solid timber
#

I don't know

#

Lmao

#

I genuinely have no idea

solid timber
#

I can access the sites just fine. Like I said, I guess what the vhosts are. I just don't understand why gobuster won't work

lone spruce
#

I can tell you exactly why gobuster isnt working

#

its pointing towards a home address

solid timber
#

Yes I know thag

#

But how do I fix it?

#

Lol

night widget
#

you can change that in the hosts file

#

and first making sure you"re connected to the vpn

solid timber
#

I am

lone spruce
#

You havent given us any information to help you fix it other than it doesnt work

#

what does your host file look like?

night widget
#

can you give a screenshot of you /etc/hosts file? and your subnet your on?

solid timber
#

Yea gimme a sec

night widget
#

you don't have the holo.live

lone spruce
#

you dont have anything for the domain

#

youre trying to point to something that to your machine doesnt exist

solid timber
#

Ah

lone spruce
#

so its providing its best guess i.e. 192.168.1.1

solid timber
#

Right. Ok. That makes sense

night widget
#

because the network doesn't resolves dns requests

#

from the outside

solid timber
#

Yep. Got it.

#

Damn

#

Can't believe I overlooked thay

#

Thag

#

That*

night widget
#

ooh haha it happens to the best of us

#

sometimes i overlook the most basic thing or i mispell a word/ command with 1 letter, but i'd be bashing my head into my dry wall kekw

solid timber
#

Lmao. I did that last week. I was trying to crack a password with John and I left out = between --wordlist and the path to the list I was using

#

Spent a solid half hour trying to figure out what I was doing wrong

night widget
#

haha, had that also happen to me a few times by now xD, does the gobuster now work for you?

solid timber
#

Yea. Thanks

night widget
#

np, how are you feeling so far about the network? i personally really enjoyed it, but boy windows AV will be a b-** :p

solid timber
#

Haha. I'm in the middle of doing the AV evasion. I started holo a few weeks ago then stopped halfway through to go do wreath cuz I was just absolutley lost with this one.

#

The AV evasion is rough but I think I almost have it

#

I'm absolutley loving the challenge tho. I haven't had this much fun in a while

night widget
#

Yeah because you get to experience the whole kill chain of a pentest, but wreath indeed is a well written guide for learning pivoting, which you've obviously also gotta do in holo xd

solid timber
#

Yea. Wreath pretty much filled in the gaps I was missing.

#

I still can't get covenant to work tho. Pretty much given up on it at this point

#

Might come back to it and play around after I finish the rest of the network

night widget
#

tbh, i did the network without covenant, but i'll link some yt vids if i can find them that aren't "tutorials" but they showcase covenant

solid timber
#

Yea, I'm prolly gonna do the same thing. And yea, that'd be dope

solid timber
hollow steepleBOT
#

Gave +1 Rep to @night widget

night widget
livid shoal
#

are the feedbacks already sent or in the process.. ?

frail axle
#

I still cannot get to PC-FILESRV01 on 10.200.131.35 due to the following issue: STATUS_TRUSTED_RELATIONSHIP_FAILURE. The domain user cannot get authorized against domain when logging into PC-FILESRV01. Can somebody help with that?

torpid pelican
#

I am facing the same problem as well

obtuse quiver
#

There’s been a lot of ppl saying that, so is someone gonna fix it ? Or its intended and we are just complaining for no reason ?

wind bobcat
#

you're complaining for no reason lol.
cry pushed the fix and is waiting on Skidy to clone and push the change

hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

solid timber
#

Anyone know how to fix this? trying to get covenant to work. Getting this error when trying to execute the launcher

#

Cant figure out how to fix it

solid timber
#

Ok, so i pulled it up in visual studio to tyr to figure it out and now its giving me this error. Again, im not sure how to fix it. Any help would be dope, im not fantastic at C# which is prolly why i dont understand

solid timber
#

I've come to the conclusion I spent wayyyy too long trying ti get covenant to work

#

AV bypass took litteraly 15 minutes with a simple rev shell

night widget
#

Did you get covenant to work?

solid timber
#

Nope

#

Gave up

#

I don't understand enough c# to make the code work

night widget
#

yeah

#

there's this one article

#

but even after you rebuild it defender still detects the grunts for some reason

solid timber
#

Weird. Can you send me the article? I'm curious to see it

night widget
#

sure

solid timber
#

Thanks!

solid timber
#

Oh that's the one that it links to in the AV part. I understand that part of it. I know enough to understand the obfuscation. I can't get the grunt binary to run tho and idk why.

night widget
#

yeah i've also wasted a lot of time trying to get that to work but didn't unfortunately

solid timber
#

Yea. Altho, now that I think about it I probably could have gotten the powershell launcher to run but this way worked just fine lol

#

Question, is PC-FILESRV01 broken?

#

I saw some people saying they were having issues with it earlier

#

im having the same issue now

wind bobcat
#

current update

#

skidy couldn't clone the vm

#

cry is looking into it

solid timber
#

ah ok

#

thanks

#

well, guess im done for now then

frail axle
hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

lone spruce
solid timber
#

Oh that's fun

wind bobcat
frail axle
severe vale
#

having trouble getting the RCE to show...i know what the vulnerable page is and the parameter, but getting a 302 redirect, any help?

severe vale
#

the lab said i had 1 day left for access....now it doesn't anymore....

wind bobcat
severe vale
#

so i can renew it?

wind bobcat
#

you just leave and rejoin the room

severe vale
#

ahh....cool!

#

thanks!

sonic arch
#

Hi there πŸ™‚
I have a general question: Do you guys have a dedicated machine you use for Holo (9 days time) you leave running during the night, or are you securing the access with persistent backdoors?

quiet raft
#

For Wreath and Throwback, I used a dedicated instance of Kali.
If you document your steps well enough, it should be fast to regain access

sonic arch
quiet raft
#

Virtual machine, that I shut down as appropriate

#

No point keeping it on as the network will sleep and reset

sonic arch
hollow steepleBOT
#

Gave +1 Rep to @quiet raft

boreal oak
#

Is PC-fileSRV01 still down? I am not able to move forward from task 37

solid timber
severe vale
#

is anyone able to get to holo.live? i can ping the address, but no web page comes up and connection is refused on port 80

solid timber
#

Did you add it to you /etc/hosts file?

severe vale
#

the graphic didn't update when i refreshed everything, so its back to the other IP, but still shows the old IP

solid timber
#

The ip won't change. Even after a reset

#

Can you send a screenshot of what you get when you try to access the website?

severe vale
#

discord won't let me paste any pictures in the chat

solid timber
#

!docs verify

final patioBOT
solid timber
#

Read that

#

Follow the steps

#

Then send your screenshots

severe vale
#

now that i've changed the IP, i can access the website...but i wouldn't have known about the change in the IP if I hadn't tried it before

#

the proof was in the route that was given to me when I refreshed my VPN

hollow steepleBOT
#

Gave +1 Rep to @solid timber

lone spruce
#

@severe vale probably just a caching issue

solid timber
#

Any update on PCFILESERV?

forest forge
#

i have a problem in scalation with docket suid. I manually set ubuntu image because is the one that have the machine locally and we i run the gtfobins command, it show an error that not find that image.

#

www-data@ip-10-200-109-33:~$ docker run -v /:/mnt --rm -it ubuntu chroot /mnt sh
<docker run -v /:/mnt --rm -it alpine chroot /mnt sh
Unable to find image 'ubuntu:latest' locally

lone spruce
#

You cant just copy and paste the gtfobins command

forest forge
#

yes, i modified i little bit. i undertand that that mount a new container "ubuntu" and in that root process spawn a shell.

#

I've gotten a little lost. Any help?

solid timber
#

Your still not putting the correct information into the command

lone spruce
forest forge
#

mb

#

thanks

severe vale
#

having trouble with the privesc on the first server...i think i know the what, i just don't know the how

solid timber
solid timber
#

Any update on the broken machine?

oblique flint
#
``` I'm getting this error on task 18, any tips?
oblique flint
#

Oops thats my bad ignore this

#

can anyone dm me and help me with the privesc?

solid timber
#

Dm me what you need help with

oblique flint
#

Im kinda stuck on the docker suid bit

#

its isn't pulling alpine what soever

solid timber
#

You can't just blindly copy commands from GTFO bins

#

You need to understand what it's doing to make it work

oblique flint
#

I tried changing tons of stuff in it

solid timber
#

Such as?

oblique flint
#

mainly like dir and the alpine and the shell type

solid timber
#

What did you change alpine to?

oblique flint
#

debian,ubuntu

#

alpine:latest

#

debian:latest

#

and same for ubuntu

solid timber
#

Those won't work

#

In order to use the exploit you need to supply to name of an image that already exists on the machine

#

Maybe you want to look into how to check docker images

oblique flint
#

oops

#

my bad lol I avoid docker as much as I can lol

solid timber
#

Np

#

Docker is a very useful tool. Would recommend trying to learn a bit about it

oblique flint
#

Yeah Im gonna do the docker room after holo

kind valve
#

anyone stuck with threat checker part?

#

it keeps giving me a System.ArgumentException error

kind valve
solid timber
#

Nope. I didn't have that error. Just double checking, the exe, dll, and the 3rd file (can't remember what kind of file it is), are all in the same folder?

kind valve
#

yep

solid timber
#

Hm. I got nothing then.

kind valve
#

this is what I execute

solid timber
#

Idk. I had a lot of issues with the grunt files. Ended up not using covenant

sonic arch
#

Hi there πŸ™‚
I'm a bit stuck at task 28. I can scan S-SRV01, but I can't access the website.. What am I missing??

solid timber
#

Have you set up your pivot properly?

sonic arch
#

yeah, I guess. With chisel... From my attacker to the L-SRV01.

solid timber
#

You have to route your browser through the proxy then

sonic arch
#

facepalm

solid timber
#

Looool

#

I did that the first time I used chisel

#

Don't worry

#

Everyone makes that mistake

sonic arch
#

Man this holo thingy is just awesome, I learn soo much πŸ™‚

solid timber
#

Ikr. I need to finish it. Assuming the broken server is fixed

sonic arch
#

I pray it is, when I get to that point hahaha

solid timber
#

Fingers crossed

lone spruce
#

This is how I feel debugging the network

solid timber
#

🀣

kind valve
#

Hello, is it normal that I can't access with evilwin-rm or/and rdp PC-FILESRV01 with the credentials discovered in the previous task or am I doing something wrong?

prime verge
kind valve
hollow steepleBOT
#

Gave +1 Rep to @prime verge

prime verge
#

also better to hide the username so it doesnt get spoiled for others

kind valve
#

thanks

kind valve
#

this is what I get when rdesktop the machine, for anyone who has the same problem on .35

sonic arch
wind bobcat
#

@lone spruce dork stork server bork

#

fix

#

fix

#

fix

lone spruce
livid shoal
#

any updates about reports πŸ‘€

lone spruce
#

We’re done analyzing just writing feedback for each

lone spruce
#

Changes should be made. Reset your networks and it should be pushed. If the patch did not work let me know

solid timber
#

Will take a look when I get home

solid timber
#

Oh right. Need to reset it. Lol. Guess I gotta wait another 4 hours

kind valve
#

still can't access the fileserver using ||watamet|| credentials

lone spruce
kind valve
#

yep

kind valve
#

also dont know if it is useful info, but the AV is killing all the covenant binary now

#

it give me the session once I execute the php file, but after few second the .exe gets removed and the session killed

#

before it did not happen blobhuh

lone spruce
#

Yes because I fixed the AV

kind valve
#

πŸ‘€ I thought that I did the obfuscation right, since threat check gave me a clean result

#

Oh... I think it kills the session once I execute mimikatz inside covenant

lone spruce
#

Okay

#

I fixed one problem

#

now theres another one

#

blame @wind bobcat

pure escarp
#

I can no longer ping the network

pure escarp
#

I get a 10.200.114 IP however I cannot connect to any machine, it works from Attack Box however

old holly
#

Hello. I'm having issues with L-SRV01. /robots.txt is retrieved immediately, but nothing else is on the server loads. I missed something or is a issue with the machine?

frail axle
#

Is PC-FILESRV01 still broken? I keep getting the same error regarding "trust" that I got over 2 weeks ago.

lone spruce
naive lotus
#

@harsh pier

frail axle
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

fluid ravine
pure escarp
fluid ravine
#

I have the attackers IP but I don't know my local IP I should use for reverse shells

#

Ah I think I have a different problem then

lone spruce
fluid ravine
#

I think I found it in the access tab

#

When doing other machines the ip stands here

#

But I found my ip in OpenVPN Access Details

lone spruce
#

just use an ip a

#

Or ifconfig

fluid ravine
#

Ah nice I see its under tun0

#

Thanks for the tip

#

Never knew that

cobalt slate
#

I can't upload the mimikatz to the server. I have the nt authority/system, but I'm getting a message of denied...

#

using the covenant upload task

fallow hill
#

NT_STATUS_TRUSTED_RELATIONSHIP_FAILURE .. i cant connect on PC-FILESRV01 becouse of this error.

frail axle
dusk kelp
#

anyone else having issues connecting to Holo?

sonic arch
dusk kelp
#

Yeah, I can't connect to anything using my holo VPN (DC or Linux server). Just going to wait for the network to get reset and see if that helps

cobalt slate
# livid shoal av envasion

I already did the av evasion step, my grunt was uploaded and activated. The problem is access denied writing to a folder.

sonic arch
#

What happens, if I would not be able to complete holo in 9 days? Is it possible to attempt it again?

earnest hornet
#

You will be kicked off the network, just rejoin when you're ready.

sonic arch
hollow steepleBOT
#

Gave +1 Rep to @earnest hornet

frail axle
sonic arch
#

And another question: Is it better to use a 32 or 64 bit machine to compile the exploits with Visual Studio?

frail axle
#

It depends on the architecture of the victim

sonic arch
frail axle
solid timber
sonic arch
frail axle
hollow steepleBOT
#

Gave +1 Rep to @solid timber

sonic arch
frail axle
# sonic arch Do you mean target 32 and msf 64 bit, or the other way around?

The mistmatch between multi/handler payload and the rev shell e.g. windows/x64/meterpreter/reverse_tcp and 32 bit rev shell generated with msfvenom. That's why the best way is just to try it. If it fails than I would go with the same architecture on both end and also I would not use the staged payload. You need to try.

fallow hill
#

PC-fileSRV01 still not working ... NT_STATUS_TRUSTED_RELATIONSHIP_FAILURE

wind bobcat
#

@lone spruce dork stork server bork

pale steeple
#

Is it normal to have issues with understanding the AV evasion part?

#

I have a lot of programming experience but this feels like rocket science

solid timber
#

AV evasion is an art. If you haven't done wreath yet I'd go do that first. It goes much more in depth on it

pale steeple
#

Oooh okay.

#

I was stuck at the empire part in wreath, so you might be getting at something

solid timber
#

If you need any help understanding lmk

cobalt slate
#

any news about pc-filesrv01?

wind bobcat
#

@lone spruce

#

dork stork

#

server bork

hard mica
#

how long does it take to crack the password in task 22

dusty forge
solid timber
hard mica
#

yup got it crack with john in 31mins hahaha dont know how to set threads or to make my hashcat do it faster

solid timber
#

Rip

hard mica
#

is it only me or you guys cant see picture also

zenith delta
#

could someone reset in 10.200.109/24

#

it just get down

hard mica
#

does anyone have a hard time connecting with evil win rm for task 37

solid timber
#

Unless cry fixed it and didn't tell anyone, PCFILESERV is dead

hard mica
#

i see thats why i cant connect does it help if the machine gets reset ?

dull island
#

Can anyone help me with task 23? I followed the steps for the chisel server/client but not really sure what the point of it is

hard mica
#

theres also a same task in wreath network for port forward and pivots

dull island
#

I get that but how can i see what internal ports LSRV01 can see?

#

like in task 28 it says ' have identified a new target, S-SRV01. We know that S-SRV01 has an open web server '

#

how would i know that?

#

sorry if its easy just been confused for a while sure theres one little thing i'm missing

hard mica
#

look at the /usr/bin i think

#

theres something you can use there

#

if you dont like that just upload network enum tools then run it or just use linux commands

dull island
#

ok thank you

zenith delta
hard mica
solid timber
#

Cry is working on it

zenith delta
#

nice

olive jolt
#

Which extensions am I supposed to look for in task 10?

#

I think I am doing something wrong because I am getting multiple hours as estimated time

solid timber
#

What did you use to look for directories?

olive jolt
#

feroxbuster

olive jolt
solid timber
#

Let me see the command u used

olive jolt
solid timber
#

Is that the only one you used?

olive jolt
#

feroxbuster -u http://www.holo.live -w /usr/share/wordlists/SecLists/Discovery/Web-Content/big.txt -x php,txt,js,html,cgi -o fuzz_www.holo.live.log

#

I did the same for dev.holo.live and admin.holo.live

solid timber
#

Then you should have found what you need

#

You can dm the results you found if you want and I can take a look real quick if you want

olive jolt
olive jolt
solid timber
#

That's what you were supposed to do lol

olive jolt
solid timber
#

Cuz you can find the answers with brutefircing too

olive jolt
#

what I did not find is img.php

solid timber
#

Huh. You should have I believe.

olive jolt
solid timber
#

Ah

#

Well thats why

#

It's. Php

#

You won't wind it unless your scanning for the php extention

olive jolt
solid timber
#

Ah lol

#

That's what I did for vhosts originally cuz I couldn't get it to work

zenith delta
#

its holo fixed now?

solid timber
#

Haven't heard any updates so I'll assume no

wind bobcat
#

from dev chat -
Cry is testing, you can try resetting

lone spruce
#

Cry is bogged down with school work for the next hour and hasnt had a chance to test

#

the patch is pushed if you want to see if it worked

#

If it doesnt work I will just go crawl into a hole

solid timber
#

Lmao. If you can reset the .112 subnet I can test it now. If not then you'll have to wait 3 hours

wind bobcat
#

creators can't issue/force resets

#

a network is a fancy room

solid timber
#

Yea I figured as much lol

kind valve
#

dunno if I'm missing something, but I've reset the network and now everything doesnt work

#

the hosts alive are only .250 and .33 alive

lone spruce
#

As it should be

kind valve
#

this is what I got with nmap

#

vent so sorry, Cry

lone spruce
#

youre seeing exactly what you should be?

#

what about it?

#

you dont have access to the rest of the network yet as you should

kind valve
#

port 80 should be open to access admin.holo.live

lone spruce
#

We didn’t touch that machine. I’ll check but nothing changed there

kind valve
#

maybe Im just doing something wrong, gonna check it later

solid timber
#

Still waiting to reset my subnet lol. Forgot about it for a bit.

tranquil fulcrum
#

has anyone can connect to Holo room through VPN, i can't Download a configuration file , how can i download ?

#

404 not found

earnest hornet
tranquil fulcrum
#

no, can't

#

404 not found

earnest hornet
#

@outer junco Holo 404^

#

What’s your site username?

tranquil fulcrum
earnest hornet
#

You said Holo?

tranquil fulcrum
earnest hornet
#

I’m so confused

#

Have you selected the Holo network VPN from the networks drop down list?

tranquil fulcrum
#

VPN server US-West-VIP-1
Network VPN server Hololive

tranquil fulcrum
#

when i downloading configuration file, 404 not found

#

Uh-oh, this page has been lost in the matrix.

#

404 - an error occured , uh oh something has gone wrong

outer junco
tranquil fulcrum
#

IP L-SRV01

outer junco
hard mica
#

is file serv work now ?

lone spruce
#

theoretically

#

its on my honey do list to test this morning

solid timber
#

ill test it right now, hold on

#

just realized i showed the hash in that pic lol

#

there. looks to be all good now

zenith delta
#

delete it 😭

tranquil fulcrum
#

no i don't

#

Wreath is ok

#

hololive it doesn't work

#

can't download file

#

has anyone fixed it ?

#

I have downloaded it successfully . Thank you

solid timber
#

Im supposed to be able to use evil-winrm to connect to fileserv right?

#

or did i miss a step

kind valve
#

is anyone on .115 subnet and cant access the web server .33?

solid timber
kind valve
solid timber
#

ah ok, lemme try. forgot that was an option

#

nope

lone spruce
#

thats not the same issue though

solid timber
#

yea ik

#

im just trying to figure out what my issue is now

#

this is the error i get with winrm

#

but i know i have the right hash cuz i can winrm to .31 with it

lone spruce
#

win rm is wack

solid timber
#

lol so what should i use to connect?

lone spruce
solid timber
#

yea, everything is working fine, but i cant connect to fileserv and i dont know why

lone spruce
#

Im working on it

#

please be patient

solid timber
#

ah

#

my bad

#

didnt realize you were looking into

#

sorry

#

take your time

solid timber
#

πŸ˜†

hard mica
#

hmm do i have the chance to see yagoo somewhere in the network blobhuh

lone spruce
#

what?

solid timber
hard mica
#

cover corp CEO yagoooooo haha

lone spruce
#

okay

#

literally

#

where do these files go

#

it doesnt make sense

#

how do they just

#

...

solid timber
#

lmfao

lone spruce
#

Okay

#

Ive fixed it, give it a second to clone over and push the patch

zenith delta
#

hey people. when I nmap the webserver I only get port 22. is it broken or smthn?

zenith delta
#

10.200.112.33

kind valve
#

got the same problem on 10.200.115.33 NotLikeThis

solid timber
#

I'll take a look an a second. I happen to be on the same sibnet

#

Yea, seeing the same thing here

lone spruce
#

I can’t give any advice other than reset the network. I just went on today on a public network and the machine was running fine. Nmap can be really wacky, validate by navigating to the page itself

solid timber
#

I tried. Page wouldn't load

solid timber
zenith delta
#

voted

kind valve
#

I already reset it two times mine

#

not working tho

solid timber
zenith delta
solid timber
#

Well I can't help you there lol

kind valve
#

it's working now for me

solid timber
#

Im still getting the same error with evil-winrm when trying to connect to PC-FILESERV

kind valve
solid timber
#

rippppppppp

#

at least its not just me

kind valve
solid timber
#

yep same here

#

sadge

kind valve
#

feel u NotLikeThis

solid timber
#

guess ill go back to doing malware analysis until its fixed lol

zenith delta
#

still same after reset, right?

solid timber
#

yea.

zenith delta
#

can we file a bug or smthn?

wind bobcat
#

Cry and Skidy are aware

#

tl:dr the people that have access to things are busy.

solid timber
lone spruce
#

its fixed.

#

servers have a mind of their own

#

so

#

its not fixed

wind bobcat
#

shut up nerd, no one asked

upper frost
#

What's up guys... been trying to log in to admin dashboard but for whatever reason its not working... My guess is that someone changed the hash on the DB for the admin user

wind bobcat
#

try clearing browser cache

hard mica
#

can i dm someone not sure why i cant still connect for task 37 i tried using rdp and evilwinrm to connect

zenith delta
#

I still can't access the webserver...

solid timber
cobalt slate
#

I'm using sshuttle, and the crackmapexec on pc-filesrv01 is returning this: NT_STATUS_TRUSTED_RELATIONSHIP_FAILURE any idea about what would this be?

solid timber
#

Reset your network

#

That's specific issue was fixed yesterday

hard mica
solid timber
#

No

#

There's another issue with fileserv now

#

But the trusted relationship failure was fixed

#

Now it's NO_LOGON_SERVERS

hard mica
#

i see gonna do other rooms for now i guess

solid timber
#

I'm gonna try again later cuz to quote cry "it's fixed but the servers have a mind of their own, so it's not fixed"

upper frost
upper frost
upper frost
#

#update So... host .33 port 80 still not working, it's closed

cobalt slate
hollow steepleBOT
#

Gave +1 Rep to @solid timber

upper frost
#

I'm worried because the network had been restarted... still port 80 is closed on host .33

solid timber
#

The people in charge of maintaining the networks are working on it however they also have other things they need to do. I'm sure they will help when they get a chance

upper frost
hollow steepleBOT
#

Gave +1 Rep to @solid timber

zenith delta
#

just reseted seems to work

zenith delta
lone spruce
#

I just tested it today. The machine is working as intended now

upper frost
#

Thank you!! will continue tomorrow then πŸ™‚

kind valve
#

It's working vent

solid timber
#

Dope. I'll finally finish it up then πŸ˜‚

queen panther
#

Having the same issue with the webserver or 33, just not working sadly

#

I'm on the 122 subnet.

solid timber
#

Reset the network

#

Everything is working fine now

zenith delta
upper frost
#

Not only that... when it was opened (2 days ago), the creds for the admin.holo.live dashboard didnt work at all... again, my guess is that someone changed the hash in the DB haha

kind valve
upper frost
#

Same here, just tried right now

#

segment 115

zenith delta
#

Hi, box DC-SRV01 is dead. segment 115

#

Can't evens start doing anything from the network

wind bobcat
#

the DC isn't directly accessible from outside of the 10.200.x.0/24 address ranges

lone spruce
#

The DC is not your initial access to the network

zenith delta
#

I know, the initial access is L-Srv01, which doesn't have the port 80 open, so i can't redo my steps, and earlier when trying to go ping the dc was dead.

lone spruce
#

It’s not dead you don’t have access. I’m aware of the Linux issues I’m working to resolve

solid timber
zenith delta
#

could someone reset in .122 segment

#

i crashed a machine 😒

solid timber
#

How'd you manage that?

zenith delta
#

Hello, when connecting to PC-Filesrv01 i get

#

Is this intented? because i know you have to logoff the user from the domain and then put him again to work with it.

lone spruce
#

reset your network

kind valve
#

is there a way to do the dll hijacking with msfvenom?

#

I'm stuck on the AV part

solid timber
#

I haven't gotten around to finishing it yet, but you'll likely need to do some AV evasion to get it to work

#

There are some interesting articles you can find via Google about how to evade AV with msfvenom

kind valve
#

hmm all that I found was about .exe file, not for dll

solid timber
#

You'd best be going back and done some more research then. I can link you a few things in dm if you want

kind valve
#

sure, thanks

zenith delta
#

Task 43 literally tells you what to Google to do the DLL Hijacking

#

By the way, the box 33 is unreachable so I can't continue.

lone spruce
#

No way

#

Is your network running?

zenith delta
#

@lone spruce the network is running was 1 hour left, now 37m, uptime 52m. Tried regenerating the VPN and using the attackbox

#

I was waiting for the network to run off time to start it again.

lone spruce
#

My only advice can be to reset the network. I just verified everything last day

zenith delta
#

Yeah 1/5 to reset it. I'll wait the time and start it again.

cobalt slate
#

I did reset on the network today and the problems I had were solved! thank you for the hints, guys!

lone spruce
#

ah

lone spruce
#

seems to be on your end

zenith delta
#

will check now

zenith delta
#

@lone spruce this is opening the AttackBox directly, no ping and i am in the Holo VPN, tried regenerating my VPN again and nothing.

#
PING 10.200.123.33 (10.200.123.33) 56(84) bytes of data.
^C
--- 10.200.123.33 ping statistics ---
61 packets transmitted, 0 received, 100% packet loss, time 61442ms
#

Will leave it for now, i'll check again tomorrow.

lone spruce
sonic arch
bright blaze
#

I just started this network a couple of days ago and have not been able to successfully find any host that is up even though I know which should be by looking at the map. I guess I should reset the network?
Apparently I can discover it on the attack box but not when using VPN, is there something I'm missing?

solid timber
#

are you connected to the correct vpn?

#

Networks have their own vpn file you need to download and use

bright blaze
#

oh damn, didn't notice, I skipped that part thought it was just the usual connect via vpn

bright blaze
hollow steepleBOT
#

Gave +1 Rep to @solid timber

solid timber
#

Is someone avalible to help me with the NTLM relay part? Ive tried everything and I cant get it to work

solid timber
#

Bruhhh, im sooo close

bright blaze
#

Can I access this network again if the timer expires?

lone spruce
#

yes, leave and rejoin the room

bright blaze
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

sonic arch
#

A question regarding testing the amsi bypass:
Should it be enough to exclude the working folder from Windows Defender and just try to run a malicious file outside this very folder,
or is it better to test it on a seperate machine?

lone spruce
#

Its always better to test on a separate machine and I don't actually know how Defender would react to an exception

solid timber
cobalt slate
#

Running kavremover.exe even without administrator privilege and this raising an alert is able to activate de hijacked dll? Because I tried both methods (msf && covenant) and no one worked...

solid timber
#

I'm not sure I understand what you're asking

cobalt slate
#

I did the dll hijacking task and I'm not getting the reverse-shell/grunt, I tried ev evasion as well and didn't work

solid timber
#

Are you sure you have the correct dll?

cobalt slate
#

yes, that with ENU in the name

#

by the blog post searching on google

solid timber
#

Where did you put it?

cobalt slate
#

in the same place as the executable file

solid timber
#

That's not the right place

#

There is a different dll that goes in the same folder as the executable

#

The one you have goes in a different location iirc

cobalt slate
#

And I tried put in a place that isn't being affected by the group policy AppLocker

solid timber
#

You have 2 option, 1, download the exe and do some testing on your own, or 2, do some more research on the exe.

cobalt slate
#

Sure, thank you πŸ™‚

solid timber
#

There's a specific blog post you're looking for. I don't remember exactly what it's called, but you'll find it

solid timber
#

Is someone available to help me troubleshoot the NTLM relay part? Im not enitrely sure what im doing wrong.

solid timber
# solid timber

I posted some images earlier of what im doing. If you need any other info tell me what and i will provide it

sage drift
#

Hello, last time I got stuck on the PCFILESRV machine (no WinRM protocol). Does anyone know if that issue is fixed?

solid timber
wind bobcat
#

@lone spruce did you ever pick a winner for osep

lone spruce
wind bobcat
#

I have your DMs muted

orchid carbon
#

there's no scheduled task in PCFILESERV for administrator

wind bobcat
#

you're not meant to see/know it's a scheduled task

#

it's "simulated user interaction"

orchid carbon
wind bobcat
#

Being able to spot applications that aren't natively installed on Windows is huge for priv esc

orchid carbon
solid timber
#

Then you did it wrong

hard mica
#

is pcfileserve working ?

#

i still cant connect trough evilwinrm or with rdp

hard mica
solid timber
#

See, you kinda cut all the relevant information out of the pictures, so it's a little bit hard to help you figure out what you're doing wrong

hard mica
#

i just cant connect to pc file serv

#

using evilinrm or with rdp

hard mica
#

is that the reason why i cant connect ?

solid timber
#

It shouldn't be. Altho, I can't see any of your commands so I can't tell you if you did something wrong or now

#

Not

hard mica
#

can i send you dm

solid timber
#

Sure

zenith delta
#

I'm having an issue where the web server on the .33 IP didn't restart I guess when I reset the network. Anyone had this happen, and do I need to just reset the network again or something else? It's been like an hour since I did the reset.

solid timber
#

Wdym it didn't restart?

zenith delta
#

I mean there is nothing running on port 80 after I reset the network

#

I was getting connection refused errors but I could ping

solid timber
#

Can you send a screenshot?

zenith delta
solid timber
#

Weird. I guess restart the network again.

#

Did you try browsing ti it anyway?

zenith delta
#

Yeah that's where I first noticed it, I only ran this again as my latest step, retracing after I could ping but not get anything from holo.live

solid timber
#

Yea. Thats odd.

zenith delta
#

I'll just reset and see what happens, I was really confused why it stopped working till I checked the scan again

solid timber
#

Yea

austere grove
#

i got a shell out of the docker container, but when running the GTFObins cmd i get an error

austere grove
#

it's task 20 thanks in advance

wind bobcat
austere grove
#

Thank you very much for the response. I am very new to docker. Do I need to provide the image alpine?

solid timber
#

No. Read up on the command your using a bit

#

Don't just copy paste. Understand what you're doing

austere grove
solid timber
#

What does alpine represent in that example command?

austere grove
austere grove
#

Sos. I'm still stuck on this, like i said docker is a weak point. if anyone could suggest any good reading on it? Or please DM if you have a few mins to explain what im doing wrong. Cheers.

lone spruce
#

That image doesn’t exist on the box

#

look for ones that do

austere grove
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

austere grove
#

i just broke back out of the container, any clue to where i can start looking for the image that does exist?

austere grove
#

I got something to happen, am i on the right track with the img name or not so much? thanks in advanced.

solid timber
#

You're on the right track. But that's not the right image.

zenith delta
#

hello

solid timber
#

sup

austere grove
#

great network, trying to wrap my head around AMSI and evading AV.

sonic arch
austere grove
solid timber
#

You'll get one. It just takes a bit of effort

sonic arch
solid timber
#

If you want I can give advice but you'll have to tell me what you're trying ti get passed the AV. I did it a specific way and can only help if you're trying to do the same thing

sonic arch
hollow steepleBOT
#

Gave +1 Rep to @solid timber

solid timber
#

Nah. I pretty much only used the info provided in the tasks. I will say tho, I couldn't get covenant to work no matter what I tried

sonic arch
#

Okay, than I should have everything I need..
Covenant itself, or anti-amsiing the grunts?

viscid willow
#

Can someone explain how DC-SRV01 IP address can just change in the middle of things?

#

Shouldn't we get a bloody warning?

solid timber
solid timber
#

Only way up changes is if you left then rejoined the room

#

It*

viscid willow
#

Ya. I dunno what happened. It definitely changed though. I decided to walk away and come back with a fresh network when things don’t have gremlins in the wire.

solid timber
#

Weird

#

Well, if any if you get the NTLM relay working (the last attack after rooting pc fileserv) lmk. I can't get it to work and don't know what I'm doing wrong

#

And every time I post about it here nobody answers lol

wind bobcat
#

low-key bet when cry made Skidy reclone everything, shit broke

#

in the meantime, just print nightmare the dc

#

ez clap

austere grove
#

i copied the wrapper from task 35, changed the IP adress but when i upload it it never makes a call to my waiting http.server. I've checked for typos but dont see any. anyone have any idea what up? I just turned off javascript to bypass the client side.

solid timber
#

iirc that's the AV

#

Could be wrong but I vaguely remember having that problem

#

That bypass is a nasty one.

lone spruce
# austere grove

are you actually executing the php or are you just uploading it?

#

you can just upload a file and expect it to execute itself

austere grove
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

lone spruce
#

yes

austere grove
# lone spruce yes

okay thank you for the direction. I need to straight up fuzz for the right url?>

lone spruce
#

its not that hard to find

austere grove
solid timber
wind bobcat
#

you've pivoted through the network, right?

solid timber
#

Yea. I've done everything up to the NTLM relay

#

I just can't get that last bit to work

austere grove
#

okay thank you mucho it's hitting my box now atleast XD

austere grove
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

lone spruce
solid timber
#

Idk man. I tried just about everything with the relay and It refuses to work

solid timber
wind bobcat
#

no

solid timber
#

Oh? I guess I have to do more research then

solid timber
# wind bobcat no

Still can't figure out how to do this. Can you point me in the correct direction?

solid timber
#

Decided to try relaying again now now im getting this error when stopping the services. Am i doing something wrong?

livid shoal
#

πŸ™ƒ still waiting for reports review

#

been a long time

lone spruce
#

Blame @wind bobcat

sonic arch
solid timber
#

In general

#

I've tried playing around with the code but I can't get it to work

#

These were the errors. Don't know how to fix them

lone spruce
#

are you trying to build that outside of Covenant? in VSCode? You cant build the agents outside of Covenant

solid timber
#

No. I pulled it up in vs to try to figure out what was up with it

solid timber
# solid timber

This is the error I got originally before opening anything in VS

austere grove
#

can i use the wrapper like this with the .ps1?

solid timber
#

I think that should work. Been a while since I was at that part but I think it looks good

lone spruce
austere grove
#

i put in the x's to hid my ip

austere grove
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

austere grove
#

about escaping the backslash

austere grove
hollow steepleBOT
#

Gave +1 Rep to @lone spruce

cobalt slate
#

I'm still stucked on task 43... Any hints on how to figure out the scheduled task for the vulnerable application? Commands, etc...

lone spruce
cobalt slate
#

Sure, thanks!

zenith delta
#

Anyone could sanity check me on task 43? Been stuck here the past 24 hours and reset the network like 4 times. Payload dll is crafted, with encoding, and on the machine in the right location; metasploit handler up on my box and options match the payload. But I can't get the shell, it's like the task isn't running or something, but I guess it is and I've just messed up on something. It's been about 40 minutes since I dropped the dll last after a fresh network reset...

lone spruce
#

@solid timber this work for you? Ive been messing with that script a bit so.

lone spruce
zenith delta
#

Ok I just went back and checked and yes it does work, I got a shell from my own windows vm changing only the IP in the msfvenom command

#

I'm not above having messed it up a 9-10th time though, so I'll reset again and see. I suppose I could have messed up my listener this last time even though I put the dll in the proper place

placid dove
#

Anyone available for a reset vote on the 10.200.126.0/24 network? L-SRV01 seems to have become completely unresponsive.

austere grove
#

to get a empire agent on the win web server would i need to set up an http_hop on the lin box? I pivoted with chisel, can get a powershell reverse shell but not been able to get empire set up, i dumped sam.bak and system.back, hit with impacket secrets but it only gave me hash for local users didnt seen aything about the domain, figured need mimikatz.

#

task 36 asks for a domain users creds i didnt not see

#

an empire agent*

solid timber
solid timber
#

Oh and I still haven't been able to finish the network btw. I'm certain that the NTLM Relay is broken and I can't figure out how to print nightmare the DC without being able to log on to it

#

If anyone could point me in the right direction that would be nice

undone rune
wheat marsh
#

In the task 8 ,it asks for the version of the CME, i checked it manually and also did a wpscan , both show 2.4.2 but when i submit it shows wrong answer. Why is it?

austere grove
austere grove
wheat marsh
#

Alright. Thanks.

austere grove
#

and thats good to know about outbound traffic thank you

austere grove
hollow steepleBOT
#

Gave +1 Rep to @undone rune

austere grove
#

i didnt think so, ive been able to get a powershell reverse shell back, but nothing else, glad to know what to work on tho

undone rune
austere grove
undone rune
sonic arch
hollow steepleBOT
#

Gave +1 Rep to @undone rune

austere grove
#

they rec that video in the task, but yes def great

#

i wateched it twice atleast lol

#

this is what pushed me over the edge to win

undone rune
undone rune
austere grove
#

you guys still a step above me, i got a powershell reverse back from s-srv-01, but cant get mimikatz to run no matter what I do. I've tried to obfuscate meterpreter payloads, empire agents with amsi blocks in front, i dumped sam.back and system .back and did secrets but every user but watamet dumped. anyone got a road they can heaed me down. every thing i find online and try is dated 18-20 and no longer works. im system on the box its frustrating i cant get anything to work.

#

cant i just turn off amsi at this point?

#

sam.bak system.bak* lol

undone rune
austere grove
austere grove
undone rune
#

as you have a working shell - disable AMSI. You can do this very easy via powershell

austere grove
#

and you are right i got a shell with the highest rights

#

[Ref].Assembly.GetType ('System.Management.Automation.AmsiUtils').GetField ('amsilnitFailed','NonPublic,Static').SetValue ($null,$true)"

#

?

undone rune
#

Set-MpPreference -DisableRealtimeMonitoring $true

austere grove
undone rune
#

more or less πŸ˜„ but I was to slow with pasting and sending - sorry

austere grove
undone rune
austere grove
#

thank you very much

hollow steepleBOT
#

Gave +1 Rep to @undone rune

undone rune
austere grove
undone rune
austere grove
undone rune
#

yes - xfreerdp work for me like a charm - I also tested rdesktop wit sshuttle which also worked great

austere grove
#

i used chisel to pivot, you think i should trans a pubrsa and sshuttle?

#

i didnt even think to try rdesktop atm

undone rune
undone rune
austere grove
hollow steepleBOT
#

Gave +1 Rep to @undone rune

hollow steepleBOT
#

Gave +1 Rep to @austere grove

solid timber
undone rune
solid timber
#

Yea. Idk

#

Can you dm me how you were trying to do it? Cuz you got farther than me πŸ˜‚ πŸ˜‚

sage drift
solid timber
#

I just did it the other day

#

It most definetly does

#

Can you send some screenshots?

sage drift
#

Yeah, sending you a PM

austere grove
undone rune
wind bobcat
#

@lone spruce it seems like s-srv02 broke kekw

austere grove
hollow steepleBOT
#

Gave +1 Rep to @undone rune

frail axle
#

Have any of you managed to privesc with DLL hijacking on PC-FILESRV01? I cannot find any unique application connected to any scheduled task endpoint that would make sense. I'm on 10.200.128.0/24.

solid timber
hollow steepleBOT
#

Gave +1 Rep to @solid timber

wind bobcat
#

tree /f is super useful btw

austere grove
#

how are yall building AmsiTrigger on linux? I cant really figure it out.

cinder notch
#

You’re not supposed to?

#

It’s a Windows thing

austere grove
#

im guessing you dont know you can run powershell on linux?

#

i cant get it to work on my winVM, it just says that active scanning off

solid timber
#

You have to build AMSI trigger in VS code

#

Or VS studio

austere grove
#

it's def studioj

#

you dont build in code

solid timber
#

Yea

#

That's why I said bith

#

Can never remember which is which

austere grove
#

im so freaking over it really, been trying to get dump creds on a box i have a system shell on

solid timber
#

Wait, what are you stuck on?

#

If you have system shell, just disable av and upload mimikatz

austere grove
#

i cant, or cant figure out how

#

i dont get it

solid timber
#

Ah. I litteralt just close my laptop. Hold on, lemme grab my notes

austere grove
hollow steepleBOT
#

Gave +1 Rep to @solid timber

cinder notch
#

Defender/AMSI have to be on to use the tools mentioned in the tasks, that’s how the checks are made. Unless you know how to get either of those things on Linux, they won’t work

#

Also, afaik, Powershell, like any other shell (e.g. bash, zsh) is simply a means to interact with your operating system. Just because you have Powershell on a Windows machine does not mean you can suddenly make Windows API calls, and just because you have bash on Windows, that doesn't mean something like /etc/passwd just exists on your Windows machine

#

Powershell might be different because it functions differently than the *nix shells, so I very well could be wrong, but I know for certain AMSITrigger and DefenderCheck cannot work on a Linux machine

lone spruce
#

Kekw

#

the funny thing is Defender is on Linux now

#

I don’t know if the AMSI hooks are in place though

solid timber
#

Is it actually? Lmao

pulsar dune
#

Hey! Is 10.200.123.X Up?

cinder notch
#

It's still a lot of effort to try and get all of this on one machine when you can just spin up a Windows machine.

austere grove
#

can anyone help reset 10.200.111.x? only way to get past this on the filesrv right?

austere grove
#

reset worked fine. all is well.

rain mauve
#

hi boys... the lab doesn't work...it don't respond to my ping...can anyone help me?

solid timber
#

Are you on the correct vpn?

rain mauve
solid timber
#

Which machine are you trying to ping?

rain mauve
rain mauve
lone spruce
#

Is the network on?

rain mauve
solid timber
#

You're sure you're using the correct VPN? Networks have their own VPN that is separate from the one you would use to do normal rooms

frail axle
#

It seems to be there are some network problems - ssh: connect to host 10.200.128.33 port 22: No route to host. I've regenerated my vpn config file for hololive but it did not help.

lone spruce
#

Did you reset the network?

rain mauve
#

i've reset the network and i have the corret VPN but all didn't work

frail axle
#

10.200.128.35 PC-FILESRV01 does NOT have an application vulnerable to dll hijacking installed/present. It is just not there. I know what this application should be. Can somebody from THM fix that? Thanks. Also there are still problems with accessing 10.200.128.35. When the network stops running and then starts again all servers stop to be accessible.

solid timber
frail axle
austere grove
#

you have the right answer for task 43 second question?

austere grove
wind bobcat
#

tree /f is your friend.

#

remember, some applications are portable and not always installed on the system.

pliant cosmos
#

Hi guys. So seems I cannot pass the hash nor can I rdp to pc-filesrv01 even though I am sure I have the correct hashes and passwords. I can win-rm to S-SRV01 with admins hash so win-rm is not the issue. I can port scan PC-FILESRV01 so its not a connectvity issue. I think something may up up with it. Iv been playing with this for 2 days now and im bout to give up. Iv tried differnt hashes with differnt users but just get auth errors in winrm and it doesent even show up as online when I hash sweep with crackamap. S-SRV01 shows pwned so I know its not my tools or connection to PC-Filesrv01. Driving me crazy... Anyone able to help or give suggestions? Does the lab need a reset?

#

Hold up. I think my port forwarding is f*cky.

#

No need to reply to me. Im going to have a nap and come back fresh.

eager cypress
#

@pliant cosmos Figure it out? Having the same issue, Can RM to SV1, portfwd is working as intended, errors from winrm are indicating badcreds yet im certain im using the right ones

pliant cosmos
#

No I havent figured it out. Driving me crazy.

#

I turned the firewall off on srv01 and still cannot get the hash to work

#

I can rdp but the password is invalid

#

Its almost like somethings been changed but I dont want to say that because thats usually not the case

eager cypress
#

I've tried going through SShuttle and through my Sliver implant, so far no dice. I was hoping to finish this before i made dinner but guess thats not happening lol

pliant cosmos
#

yeah I was hoping to finish the entire lab today. I think the lab needs a reset tbh

#

turning off the firewall opened up all ports(obviously) and I can nmap them and see open. Still no working with hashes or rdp login with clear text pass

#

Error: An error of type WinRM::WinRMAuthorizationError happened, message is WinRM::WinRMAuthorizationError

#

crackamap doesent even see filesrv01

solid timber
#

@pliant cosmos @eager cypress the task is misleading. There are some other ways to connect to windows machines. Give them a shot

eager cypress
#

Crackmap sees it for me but still gets the auth issue

pliant cosmos
#

ahhhhhh

#

ok. That task really does basically say to pass the hash...

solid timber
#

Yea. It's very misleading. You have the clear text password of the user so you can connect via other methods

pliant cosmos
#

Cheers mate ❀️

eager cypress
#

What I get for actually reading them for once

solid timber
#

πŸ˜‚ πŸ˜‚

#

That part tripped most people up

lone spruce
#

I promise when I get a second to address more minor issues such as task inaccuracies I will. Currently my bandwidth is being stretched very thin between school and other THM work. Please be patient as with spooks gone I am the sole maintainer of this network

solid timber
#

All good. Take your time. It's a huge network with tons of moving parts

pliant cosmos
#

yeah all good mate. The lab is awesome

hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

austere grove
#

omg advent of cyber 3 shirt so dope, take my $$$

#

but yes this network is dope. I learned so much, and got much cmd chops up alot learning to deal with the "ART" that is dealing with tech.

eager cypress
#

Can I get a sanity check for Task 43 if anyone can spare a minute or two.

eager cypress
#

@solid timber DLLHijack

solid timber
#

Ah yea sure. Dm me

eager cypress
#

@solid timber sent

solid timber
#

Yea, I saw sorry. Was on a call for work

pliant cosmos
#

ok guys, so yesterday after a network reset the creds worked but trying today im getting authentication failed. Is someone changing the users password? Is anyone able to reset the users password on fileserv so I dont have to wait for a network reset and setup percistance all over again?

solid timber
pliant cosmos
#

like zero logon or print nightmare?

#

il play around.

solid timber
#

πŸ€·β€β™‚οΈ I'm sure you'll find it after some testing

#

πŸ˜‰

pliant cosmos
#

aight

forest forge
#

Any problem having access to the network?

#

.ovpn not available

frail axle
#

DLL hijacking does not work in 10.200.128.0 on PC-FILESERV01. I created the expected dll (||kavremoverENU.dll||) with windows/meterpreter/reverse_tcp payload and placed it in the same directory where the app is (||c:\Users\watamet\Applications||). Also I tested the dll (of course with different IP) on my windows PC and kali VM. Then I created a standalone executable (.exe) with windows/meterpreter/reverse_tcp payload and exactly the same IP and port as the malicious dll and it worked (||from C:\Windows\Tasks||). I got the meterpreter session. It proves that DLL hijacking is broken in 10.200.128.0/PC-FILESERV01.

solid timber
#

Number 1 that dosent prove anything cuz you have the dll in the wrong place. Second, if you can't get it to work there's another exploit that you can use to get admin

oak atlas
#

Hi, having some difficulty in Task 23 - Pivoting Networks. I have chisel running on my box (CMD used: sudo ./chisel server -p 8001 --reverse) and the target (CMD used: ./chisel client <my-kali-ip>:8001 R:socks). I appended socks5 127.0.0.1 1080 to the end of /etc/proxychains.conf on my box. Both the Client and Server seem to be connected according to the outputs; though when I try to use the port forwarding on my kali (e.g. sudo proxychains ping 10.200.131.31, the ping fails and gets no result. Any help?

#

The ping command works on the target box, so said IP is up.

solid timber
#

You can't usually ping over pivots and I don't think chisel is an exception

#

Also, just make your life easier and use sshuttle

oak atlas
#

Thanks, sshuttle worked - and it does allow to ping

#

I just tried to use chisel because it seemed to be a more versatile tool

oak atlas
#

But I now have a different problem with sshuttle. When I try to nmap the internal network (nmap 10.200.131.0/24) I get output like the following:

#
 s: warning: closed channel 1866 got cmd=TCP_STOP_SENDING len=0
c : warning: closed channel 1866 got cmd=TCP_EOF len=0
c : warning: closed channel 1867 got cmd=TCP_EOF len=0
 s: warning: closed channel 1867 got cmd=TCP_STOP_SENDING len=0
c : warning: closed channel 1868 got cmd=TCP_EOF len=0
 s: warning: closed channel 1868 got cmd=TCP_STOP_SENDING len=0
 s: warning: closed channel 1869 got cmd=TCP_STOP_SENDING len=0
 s: warning: closed channel 1870 got cmd=TCP_STOP_SENDING len=0
c : warning: closed channel 1869 got cmd=TCP_EOF len=0
c : warning: closed channel 1870 got cmd=TCP_EOF len=0
c : warning: closed channel 1878 got cmd=TCP_EOF len=0
c : warning: closed channel 1879 got cmd=TCP_EOF len=0
 s: warning: closed channel 1878 got cmd=TCP_STOP_SENDING len=0
 s: warning: closed channel 1879 got cmd=TCP_STOP_SENDING len=0
#

This is from the sshuttle

#
Discovered open port 53/tcp on 10.200.131.20
Discovered open port 3389/tcp on 10.200.131.21
Discovered open port 3389/tcp on 10.200.131.22
Discovered open port 53/tcp on 10.200.131.22
Discovered open port 53/tcp on 10.200.131.23
Discovered open port 53/tcp on 10.200.131.24
Discovered open port 3389/tcp on 10.200.131.25
Discovered open port 3389/tcp on 10.200.131.27
Discovered open port 3389/tcp on 10.200.131.28
Discovered open port 3389/tcp on 10.200.131.29
Discovered open port 3389/tcp on 10.200.131.30
#

This is from the nmap

solid timber
#

Ignore what sshutle is saying. You shouldn't have any issues

lone spruce
#

You don’t nmap over sshuttle

#

it’s not traditional proxy

oak atlas
#

So then how am I supposed to scan the internal network?

oak atlas
wind bobcat
#

put a portable nmap binary on the Linux host and scan from there, or use the custom portscan script, but alter it for the internal network :D

#

can't answer the sshuttle thing. The only thing I can think of is nmap sends traffic to the (sshuttle) server (which always gets a valid TCP handshake) and then tries to connect to the remote server you're attempting to scan, then fails, but if doesn't matter because nmap already flagged it as open

#

nmap and proxies generally don't play well together. Even the built in proxy feature nmap has is a huge mystery...

oak atlas
#

So nmap is the only thing thats not supposed to work? The rest should?

wind bobcat
#

pretty much portscanning with nmap is not a good idea, service enumeration should work perfectly fine though

oak atlas
#

πŸ‘ thanks

rain mauve
#

hi boys,i've used sshuttle on L-SRV01 for pivoting into network and it work...i can see the web server on S-SRV01 and also the webserv on DC-SRV01.... when i go to S-SRV01 i see the login page but anything i insert (including the correct credential) i got a blank page and nothing else....anyone can explain me why?

lone spruce
#

TL;DR the correct credential doesnt exist kekw

rain mauve