#holo-network

1 messages · Page 11 of 1

minor flax
#

That's a great shout too. If you are proxying through burp this will all not work though!

wise quarry
faint iris
#

Does this lab block ips in the event of too much fuzzing from a unique one ?

wind bobcat
#

nope

faint iris
#

Aight so the serv is just down

#

Great

timid moss
#

How do you find the username for task 28? I feel like this is obvious and I'm just overlooking something simple

tepid halo
#

I feel like my network is broken. It just shutdown cuz I forgot to extend and since the restart the linux host is not reachable

$ ping 10.200.107.33
PING 10.200.107.33 (10.200.107.33) 56(84) bytes of data.
From 10.50.103.1 icmp_seq=1 Destination Host Unreachable
timid moss
#

Does the amsi bypass run within the shell code? Or do you run it prior to the revere shell callback to disable Amsi? I'm getting a bit confused

silent gulch
snow nest
#

Hello anyone available to talk about holo ?

#

Especially about privesc part on .35

minor flax
timid sandal
#

Hey...I think I'm stuck on task 37...

I can't seem to authenticate to the fileserver 01 using the syntax given....tried running evil-winrm with proxy chains... didn't work..

Tried RDP.... I'm getting "account restrictions are preventing this user from signing in. For example blank password's......"

Anybody got past this point?

#

Oh snap...I realized my mistake😹

cyan fractal
#

Hi, it's been like one hour that i cant access the holo web server wordpress site, is that normal ?

#

is it because of other people spamming wfuzz ?

cyan fractal
#

😢

#

ill just wait i guess

timid moss
timid moss
#

Can we get a reset on this?

#

Anyone on the network?

#

Uptime is 30minutes and nothing is working

minor flax
timid moss
minor flax
hollow steepleBOT
#

Gave +1 Rep to @minor flax

clever sky
#

Can someone shed some light on: Task 38 Post Exploitation Watson left her locker open

I created a payload ||kavremoverENU.dll|| and copied to the same directory where the ||kavremover application|| is located at; ||C:\Users\watamet\Applications||

I setup a multi handler on Metasploit. However the reverse shell is never caught by the handler.

Unless I misuderstood something the trigger to run ||kavremover|| is a ||scheduled task||. Am I missing something?

timid sandal
timid sandal
#

Quick question on task 47/48....
would adding both socks 4 & 5 be affecting my ntmrelayx session?

wild slate
#

i have 3 days left on holo network. I think in finish in time. but if not, can i do it again ?

cinder notch
#

You will be able to rejoin, they just have the 10 days to they can lighten the load on the networks

wild slate
#

cool thanks @cinder notch

hollow steepleBOT
#

Gave +1 Rep to @cinder notch

minor flax
minor flax
timid sandal
minor flax
timid sandal
minor flax
#

Sshuttle through to get to the .35 box. Then that leaves the ports available for the local pivot for the ntlmrelay

clever sky
hollow steepleBOT
#

Gave +1 Rep to @minor flax

clever sky
#

did someone on the 10.200.95.0/24 network change the password of linux-admin account 10.200.95.33?

#

I cannot use sshuttle anymore with the usual credentials

minor flax
hollow steepleBOT
#

Gave +1 Rep to @minor flax

clever sky
#

Getting the following messages from ntlmrelayx for task 48:

Is there a switch to use a compatible version of kerberos?

minor flax
#

I had that but it worked anyway. The second error looks like the port forward is the issue @clever sky

timid moss
#

why doesn't this command work sc config lanmanserver start= disabled

timid moss
#

Also, how in the hell do you get sshuttle to work. I run the command and get "connected to server". However I can't navigate to any of the devices

@minor flax Any chance you can help with this?

minor flax
timid moss
minor flax
#

You might need to add -x to exclude the host you are connecting too. But from memory that looks right

#

sshuttle -r root@admin.holo.live --ssh-cmd "ssh -i /home/yekki/.ssh/id_rsa" 10.200.142.0/24 -x 10.200.142.33

#

That's the command I had that worked @timid moss

timid moss
#

I can't wait to finish this room. It has been a major pain in my ass

timid moss
#

Nothing after the connection and I can't ping anything

#

@minor flax You ran this command sc config lanmanserver start= disabled on the PC server as admin, correct?

wind bobcat
#

ICMP is its own seperate protocol and doesn't proxy through sshuttle

hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

digital vault
#

Is holo the continuation lab after Throwback?

#

Is it more complex?

minor flax
ionic mesa
#

Hey, I just wanted to know if we have limited days of access to the Holo Network?

minor flax
ionic mesa
hollow steepleBOT
#

Gave +1 Rep to @minor flax

minor flax
frail mason
#

hello. what does the "9 days left" mean?

analog snow
frail mason
#

but I still have more days till the next subscription date, so...

zenith delta
#

You have 10 day(s) until you're removed from the lab.

#

So you have 9 left.

zenith delta
frail mason
#

oooh I get it now. thanks @zenith delta

hollow steepleBOT
#

Gave +1 Rep to @verbal prawn

prime crater
#

I'm returning to holo after a day offline, network uptime is 23m and I can ping L-SRV01 but no other ports are open, is this normal?

spice pendant
timid moss
spice pendant
#

I don't think I can ssh....

#

it's a connection between compromised host to internal target. I can get the internal target id_rsa but the compromised host doesn't have ssh installed.

#

perhaps meterpreter will make it work. (UPDATE; has not worked.)

spice pendant
bitter lava
#

having a hard time finding which application is vulnerable on PC-FILESRV01. Any suggestions?

minor flax
spice pendant
minor flax
bitter lava
#

@minor flax did you ever find a way to locate vulnerable APP on PC-FILE endpoint?

minor flax
bitter lava
#

Yup. I was about 2 seconds from doing that exact same thing. I figured I would give it a chance and find the vuln app. I'll try your way. Thanks!

minor flax
bitter lava
#

You mind if I DM you?

spice pendant
minor flax
minor flax
spice pendant
#

The good thing is that it's working right now 🙂

minor flax
spice pendant
#

Stabilizing sh shell

minor flax
#

Ahhh cool. Odd though!

left geyser
#

Anyone got problem with holo network ?

#

in the kali browser of tryhackme i got this

3: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 100
    link/none 
    inet 10.50.108.120/24 brd 10.50.108.255 scope global tun0
       valid_lft forever preferred_lft forever
    inet6 fe80::9105:2bc7:a0f0:98b6/64 scope link stable-privacy 
       valid_lft forever preferred_lft forever
root@kali:~# ping 10.200.111.33 
PING 10.200.111.33 (10.200.111.33) 56(84) bytes of data.
From 10.50.108.1 icmp_seq=1 Destination Host Unreachable
From 10.50.108.1 icmp_seq=2 Destination Host Unreachable
From 10.50.108.1 icmp_seq=3 Destination Host Unreachable
From 10.50.108.1 icmp_seq=4 Destination Host Unreachable
From 10.50.108.1 icmp_seq=5 Destination Host Unreachable
From 10.50.108.1 icmp_seq=6 Destination Host Unreachable
From 10.50.108.1 icmp_seq=7 Destination Host Unreachable
From 10.50.108.1 icmp_seq=8 Destination Host Unreachable
From 10.50.108.1 icmp_seq=9 Destination Host Unreachable
From 10.50.108.1 icmp_seq=10 Destination Host Unreachable
From 10.50.108.1 icmp_seq=11 Destination Host Unreachable
From 10.50.108.1 icmp_seq=12 Destination Host Unreachable
#

it was working super yesterday

spice pendant
#

Have this happened to any of you?

#

I was getting mimikatz for the S-SRV01

quiet raft
#

It says dangerous programs

#

Mimikatz is a hacking tool

spice pendant
# quiet raft It says dangerous programs

I find quite funny how people report the github repository, and tag it as a malware. Just because its a hacking tool doesn't mean its going to be used in ilegal or malicious ways. Lol

amber matrix
#

is holo-network bugged or is it just me? I tried a couple of things but I might just be tired lol

knotty gulch
#

hey I'm not able to get the DC to connect to ntlmrelayx, i have admin access to it and set up the port forward on meterpreter ... no errors but for some reason, it won't send the hash

summer flame
#

I am having trouble with initial recon

#

I guess I am supposed to do the following but

#

Pulling out the IP is not working for me. I have network set as 10.200.119.0/24

#

Is the address 10.200.119.30 supposed to be ping-able?

summer flame
#

Is there any admin on this channel?

left geyser
#

.NET 3.2 for Covenant ,
.NET 4.7.2 for ThreatCheck/DefenderCheck
.NET 6.0 default microsoft page

#

once this network finishes i shall become a .NET developer

knotty gulch
summer flame
summer flame
knotty gulch
#

@summer flame can you check your ip routing table (cmd: ip route) and see if there is a route to 10.200 .119.0/24

#

if you can then just reset the room it should be working after that

left geyser
left geyser
knotty gulch
#

i used rdp to login to the fileserv

#

used it with socks

left geyser
#

sshuttle , and chisel

#

i will check socat i guess

#

by the way L-SRV01 is vulnerable to Pwnkit

knotty gulch
#

Chisel or sshuttle should be more than enough

#

Make sure in your rdp client u specify socks proxy

knotty gulch
left geyser
#

it's fixed , thanks

sonic vale
#

so no matter what i do I can't get holo to kick back a shell. I know i'm doing it right because i've had shell before but it won't give me one now. not sure what to do I've tried

  1. attack box - no luck
    2.Openvpn - No luck
    3.resetting server - No luck
    4.resetting room - no luck
#

nvm solved it

iron galleon
sonic vale
#

lol yeah it was me just being dumb. I was using the attackbox listed IP and when i checked ifconfig i found it was running the other ip i had and it worked. so i'm betting the reset of the room is what did it because it fixed the ip addreses that were listing with the internal ip on the main netowkr infographic. (hope that helps)

fluid sorrel
deft iris
#

Am I missing something or is it nowhere stated that the third octet ("x") is meant to be the third octet of the L-SRV01 and DC-SRV01 machines?

left geyser
dim prism
#

curl: (7) Failed to connect to 192.168.100.1 port 8080: Connection refused

#

anyone can help on this...

dim prism
#

nvm got it

hard temple
#

one thing, S-SRV01 with proxy-chains through chisel is very slow, any way to make it faster?

timber girder
#

hi

subtle nacelle
#

Hi, HOLO guides say: nmap -sV -sC -p- -v 10.200.x.0/24
My network is: Internal Virtual IP Address 10.50.112.163
Not sure what should I scan... ? What should I type instead of 'x'?

#

VPN Server Name Hololive
Server Status
Connected
Internal Virtual IP Address 10.50.112.163

cinder notch
#

One of the tasks should tell you what your scope is. The VPN subnet is different from the target network.

cinder notch
#

Idk I’m on mobile right now

#

Are you in the room?

subtle nacelle
#

yes

cinder notch
#

Read through the first few tasks carefully. Also it should show you an IP address on the network topology screen-area-thing

subtle nacelle
#

yes, on the screenshot I can see but I was not sure if it is just static screenshot 🙂 I'll try

#

I don't think it is correct. I have one server found ..

subtle nacelle
#

I am trying my subnet now but oh god, it is 15 minutes and still scanning..

quiet raft
#

It's a big scan that you're doing. -p- -sC -sV is a lot.

minor flax
proven falcon
#

Anyone else having issues logging into the dashboard on the admin instance?

#

I get the login prompt but after submitting the username/password, it just hangs

wind bobcat
#

clear cache + retry!

proven falcon
#

thanks @wind bobcat! I should be ashamed...

hollow steepleBOT
#

Gave +1 Rep to @wind bobcat

agile crescent
#

Hey, so i've got through to rdp on PC-FILESRV01 and i'm trying to do the dll hijack, but even if i copy the executable to an executable permission directory, and the dll in the same folder, I find that my msfvenom dll doesnt connect back to my host, and there doesnt appear to be a scheduled task or service that references it so i don't understand why its not triggering for an admin user or for the low priv user

paper ember
#

im in the container machine ,am i supposed to be able to connect to the sql data base in 100.1 or not ?

summer radish
paper ember
#

yes i already answered the questions so they should be correct

#

i try to connect with this commands but no respond " mysql -u **** -p -h 192.....1

#

is it right ?

summer radish
#

Yeah, it looks correct

paper ember
#

can i avoid this step or no way around ?

#

i think i need to wait until next reset

summer radish
paper ember
#

no respond at all

#

im using meterpreter

summer radish
#

And is the port open?

#

3306/tcp

paper ember
#

i should specified the port ?

summer radish
#

Oh, perhaps because of your shell.
Try to get a stabilized reverse shell

paper ember
#

okay i will try

#

thank you ❤️

summer radish
paper ember
#

it works now

#

thank bro ❤️

crude jewel
#

hello guys! i am stuck at obfuscating the payload. can anyone help me with this ? thank in advance.

wet sphinx
#

Is this network down? I'm unable to ping or reach anything here?

crude jewel
#

no bro. the network is up

wet sphinx
#

Weird, I'm connected with holo vpn but unable to reach anythin. I tried from attack box as well, same thing there.

crude jewel
#

you need to start the network bro

#

click on the start button

wet sphinx
#

Well it's already started with 50 mins left on the clock?

#

Network state: Running

paper ember
crude jewel
#

i'm now attacking and the network is fine

proven falcon
#

Hey guys, got a question around shell stabalisation. I did ask this in #general but no reply and as I'm on having this issue on holo network I thought I'd try my luck here too...

Whenever I try to get a stable shell I can never seem to get the special characters working. My user and root both have /usr/bin/zsh set as their shell in /etc/passwd so I tried chsh to /bin/bash for both but that didn't help. Tried running /bin/bash before starting the whole process but that didn't help. Commands I'm using seem to be standard i.e.

python3 -c 'import pty; pty.spawn("/bin/bash")'
CTRL+Z
stty raw -echo; fg; export SHELL=/bin/bash; export TERM=xterm-256color; stty rows 29 columns 116; reset

So I get a shell back and its aligned OK but TAB completion and cursor keys for history etc don't work. Can't seem to find the answer on google so hoping someone can point me in the right direction

paper ember
proven falcon
#

yeah, I'm having issues on and off too

#

I think people are ignoring the warning about thread counts

paper ember
#

the problem is ,other rooms are fine ,only this network im not able to connect to it

proven falcon
#

You are connected OK. Like I say, under task 10 people are warned that the machine will go unresponsive if they don't reduce the thread count on gobuster when fuzzing. Too many people fuzzing without reducing the thread count must be killing the machine

#

maybe not, I get a ping reply

paper ember
#

ahh ,but even after reset immediately i tried to ping ,samething

#

ip is the same or changed ,for the machine 192.168.100.100 ?

proven falcon
#

I can ping it and hit the admin.holo.live login page but can't log in. It just hangs

#

10.200.109.33

#

You must be ahead of me

paper ember
#

i meant docker machine " L-SRV02 "

proven falcon
#

looking at the map, the connection goes via L-SRV01 which is fecked at the moment so I'm not surprised you can't access 02

paper ember
#

:S

proven falcon
#

maybe an admin can see who is hitting the box hardest and have a quiet word with them but otherwise I guess we do another room for now

paper ember
#

im waiting for admin to check and help ,but been waiting for 2 days

#

is there anyone to DM ?

proven falcon
#

Sorry, I don't know :/

#

I've been stuck on my little issue for a few daaaaaays and what you're experiencing has been a recurring issue for me

proven falcon
wind bobcat
#

I've never done that before, always
pythons -c 'import pty;pty.spawn("/bin/bash")'
ctrl+z
stty raw -echo;fg
export TERM=xterm

proven falcon
#

Sorry but it seems like we're doing the same thing, aren't we?

#

interestingly I just had to reconnect and first time I couldn't TAB or get history. Connected again without the space between "pty; pty" and its now working

#

don't think I changed anything else

#

Nah its got nothing to do with the space

#

this time I was able to get everything just with:

python3 -c 'import pty; pty.spawn("/bin/bash")'
ctrl+Z
stty raw -echo; fg
stty rows 29 columns 116

I didn't even need to set the environment variables

#

so I dunno what is going on

wind bobcat
#

difference being the stty raw -echo;fg;stty rows 29 columns 116

#

vs
stty raw -echo;fg
<enter>
export term=...
<enter>
.....
<enter>

crude jewel
proven falcon
proven falcon
#

either seems to work fine now

#

I have made it fail by using python instead of python3 or by not running nc with sudo but in the cases the result is that it just hangs completely. I can't seem to make it behave the way it was before i.e. no tab completion and history now which is odd because that was the result before no matter what I tried

#

scratch that, its not hanging when I don't run nc with sudo

#

no env vars are needing to be set at all

#

on the victim I mean

#

actually new lines work better with the TERM var set

#

People reading this are probably thinking "why does he keep going on about this?!" blobfingerguns

#

its simply that I was getting the same result for daaaaaays and now its just working as it should and I'm not doing anything different so I'm just curious to know what it could have been

#

anyway, I'm moving on! I'll shut up about it now

cosmic bobcat
#

ssh -R 10.200.101.200:16001:127.0.0.1:4444 -i id_rsa root@10.200.101.200
[root@prod-serv ~]# netstat -tlpn
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 0.0.0.0:10000 0.0.0.0:* LISTEN 1827/perl
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 853/sshd
tcp 0 0 *127.0.0.1:16001 ** 0.0.0.0: LISTEN 2121/sshd: root@pts

Anyone know how to make the one in bold** 0.0.0.0**

proven falcon
cosmic bobcat
#

Yes it is. I am trying to use 16001 as a port to listen to reverse connection and forward to 4444, it is a wreath machine I am asking in general how do we do this for SSH

proven falcon
#

Sorry bud, not sure myself. If its not in a config file, I guess its the command you're using that limits it to localhost

quiet raft
proven falcon
#

completed wreath so I guess I must have done it at some point but I can't remember :/

crude jewel
#

guys , i am facing the problems on dll hijacking. Can anyone help me with this? I can't even run proc monitor.

fading wing
#

Hey all, curious if things are working properly with the network at the moment? Seems to be broken but please correct me if I'm wrong.

#

Had a team go through it and find that there were some issues across everyones experience. From Applocker disabling to NTLM.

wind bobcat
#

the only thing I'm aware of being broken at the moment is DLL hijacking

crude jewel
wind bobcat
#

TL:Dr print nightmare

#

running karemover yourself will result in a session from your current user

crude jewel
#

hello i can't even remote desktop on .30 machine. I restart it for ntlmrelayx and it failed and then now it does not work

terse palm
#

@crude jewel may be depend on your connection ... can u ping this machine?

rapid saddle
#

I already have a session as an administrator on SRV02, but in THM's pivot graph, I can't see it as compromised machine.

crude jewel
#

can anyone help me resetting the network plz?

#

i need votes

quiet raft
wind bobcat
#

previously, it was not possible to compromise s-srv02, due to a recent update, that was patched. You can now compromise it.
The flag submission to update the network map was not likely updated

paper ember
#

its been a week ,and im still not able to ping the L-SRV02 yet through the attack box or either my pc ,i sent an email to support email ,but unfortunately it passed the 3 WD with no respond

cursive marlin
#

any problems with the network? i lost connection from one moment to the other to L-SRV01

cursive marlin
#

L-SRV01 seems to be down, can anybody from the Staff please have a look at it?

#

Instance is the 10.200.107

#

we are already only one reset vote away

cursive marlin
#

Reset is done, thx to whoever 👍

subtle sleet
#

i cant escape my privileges for some reason, when i start the docker container it fails

#

nvm i got it

random elm
#

allo all. does the final ntlm relay thing still work?

#

all i get is this

#

thats using meterpreter to port forward off a nt authority/system session, and impacket 9.22

wind bobcat
#

if you run socks, do you see
Protocol Target Username AdminStatus Port

SMB 10.200.x.30 HOLOLIVE/SRV-ADM TRUE 445

random elm
#

er, let me try. just closed it briefly

random elm
#

nope (sorry for the delay, had to reboot all the things)

random elm
#

could it be that the attack box needs to be able to reach 10.200.107.30?

#

yes thats in the solutions. hmm

random elm
#

ended up using proxychains ntlmrelayx.py over a ssh socks proxy through to the pc file serv machine, in order to allow it to attack 10.200.x.30

shadow quest
#

hey

#

need some help with a certain shell upload for S-SRV01

midnight condor
#

started the network 20 minutes ago, still cannot reach 10.200.111.33 - is there anything I could do except for waiting for others to vote for reset?

shadow quest
#

@midnight condor wanna vc?

midnight condor
midnight condor
paper ember
#

try to ping LSrv01

#

i mean LSrv02

#

the docker machine

midnight condor
#

the docker machine cannot be pinged as ICMP is being answered on L-SRV01

paper ember
#

not Lsrv01

#

you are able to ping Lsrv02 - docker machine

#

if the network works with u

midnight condor
#

its NATed..

#

holo-vpn is up though (and the network is running)

-> the network bridge cannot connect to the holo-network after a fresh reset

fast sparrow
#

Is there anything I can do about L-SRV01 crashing?

#

I cant access it anymore for some reason

#

I can't access admin.holo.live idk if that has anything to do with it

#

but I can access dev.holo.live and www.holo.live

zenith delta
hollow steepleBOT
#

Gave +1 Rep to @proven falcon

zenith delta
#

Hi All, is there any Network Security expert?

mental lichen
#

I started doing Holo. During the first enumeration, the machine has only port 22 open and no web server running.

wind bobcat
#

reset the network

quiet raft
zenith delta
#

Is there any way to download Holo Network image? The network is unstable

quiet raft
mental lichen
raven pike
#

I was getting the same issue.

#

in that the network is being unstable. However - my issue was with the dashboard whereby clearing browser cache seemed to resolve the issue. Perhaps this knowledge may help you @mental lichen

shadow quest
#

keep getting this error:

#
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.15

Evil-WinRM shell v3.3

Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine

Data: For more information, check Evil-WinRM Github: https://github.com/Hackplayers/evil-winrm#Remote-path-completion

Info: Establishing connection to remote endpoint

[proxychains] Strict chain  ...  127.0.0.1:1080  ...  10.200.109.30:5985  ...  OK
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  10.200.109.30:5985  ...  OK
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  10.200.109.30:5985  ...  OK
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  10.200.109.30:5985  ...  OK
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  10.200.109.30:5985  ...  OK
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  10.200.109.30:5985  ...  OK
[proxychains] Strict chain  ...  127.0.0.1:1080  ...  10.200.109.30:5985  ...  OK


Error: An error of type WinRM::WinRMAuthorizationError happened, message is WinRM::WinRMAuthorizationError

Error: Exiting with code 1
#

i swear this is supposed to work... and yes im using the right password/user combo

fast sparrow
#

Is there anyway i can crack the hashes for the l-srv01 without the using collab

#

Or for someone to just tell me the password

#

In dms

fast sparrow
#

Nvm got it

#

💀

viscid oak
#

Hey guys webserver port 80 is not opened at all

limber oasis
#

Yeah, It's bugged for me as well

#

maybe it needs a restart or sum

quiet raft
#

If you're asking for a reset, please specify the subnet that you're on

viscid oak
#

I'm on the 100.200.110.0/24 Subnet

#

Hey actually no need already port 80 is opened

#

Somehow

limber oasis
#

My PowerShell grunt dies almost immediately after getting a connection, any tips on how I can make it not die instantly?

shadow quest
#

having trouble with the hijacking ...can someone help?

wind bobcat
shadow quest
#

can someone help me please...trying to set up a meterpreter shell at PC-FILESRV01 but not getting a call back

#

can someone go in vc for a chat about it?

#

been googling for hours

shadow quest
#

right...need help with the NTLM relay attack

#

im 95% of the way there...help me root this damn network plz

#

i'll be on 2pm UTC

shadow quest
#

is the NTLM relay even working right now?

#

can someone run through this with me?

fast sparrow
#

can anyone give me any tips for obfuscating a grunt to bypass windows defender

#

I alr have the amsi bypass but can't get the grunt past defender

fast sparrow
#

@shadow quest if ur free could u help me since ur alr past the stage im on?

#

for some reason everytime I try to change code of one of the grunt templates covenant just stops working.

shadow quest
#

@fast sparrow sure

#

still need help?

limber oasis
fast sparrow
#

Thanks a lot

fast sparrow
fast sparrow
limber oasis
#

You're fine without

#

and dw about the ping, it's fine

limber oasis
shadow quest
#

got it working...but damnnnn its so hard to 😦

shadow quest
#

JUST got DC

#

@limber oasis

limber oasis
#

@shadow quest Ayye congrats my dude

shadow quest
#

still need help

#

?

limber oasis
#

Yeah, still didn't manage to get it working

shadow quest
#

right...wanna vc?

limber oasis
#

Sure

shadow quest
#

small study room?

limber oasis
#

+rep @shadow quest ty dude

hollow steepleBOT
#

Gave +1 Rep to @shadow quest

shadow quest
#

np 🙂

fast sparrow
#

Ayo can u also tell me how to do it for when I get to that part

#

pls

#

lmao idk have to get stuck on it

#

i only got 5 days left for my vip sub so gotta hurry to finish this yk

limber oasis
#

@shadow quest got DC PES4_HappyAwesome

shadow quest
#

niceeee

limber oasis
#

Shits weird

shadow quest
#

the way i told you?

#

@limber oasis

limber oasis
#

I kinda forgot midway but I think I figured out what you did

#

I'm still kinda confused

#

But it worked

#

So I'm happy

fast sparrow
#

im still stuck on makin a damn script to actually get me a foothold

#

i prob sound like a script kiddie rn but can I see the php payload u used

#

actually nvm

#

I think Ik a way

limber oasis
#

Good luck

#

If you're getting close to the end of your sub you can ping me and I'll send u the payload I used

#

But I believe in u

#

U got this!

fast sparrow
#

thanks!

#

so far I have my powershell script that gives me a connections and bypasses av

#

now I just need to see if it works

#

on the network (it works les go)

next kite
#

.109 network - someone has filled up all space on the first box somehow which means the sql file write totally fails kek

fast sparrow
#

I havent even touched the domain controller

#

but apparently I just rooted it

#

I would send a ss but cant

fast sparrow
#

Im on the NTLM relay section, specifically task 46 where you have to run responder, but it isn't working because port 53 is already taken.

#

I've tried killing the process running it but it doesn't change anything.

#

I don't want to mess up my VM in case it happens to be important, so if anyone could help me that'd be n o i c e

#

nvm I'll just go on without it

fast sparrow
#

How long does it take to get a connection from smb for the ntlm relay section?

#

nvm

mystic latch
#

Am i too dumb? I connected to the holo-vpn but the webserver isn´t reachable in my subnet (10.200.111.0/24). The only system is the 10.200.111.250

#

vpn connection is up and running.

fervent plaza
#

Have the same problem on 10.200.111.0/24, I hope a reset will fix it.

mystic latch
#

unfortunately they´re only 2/5 resets :/

fervent plaza
#

Yeah, we can add one each every hour 😄
I can again at around 22h

mystic latch
#

didn´t know that 🙂 only 1 vote left 🙂

fervent plaza
#

Does it work again? 🙂

mystic latch
#

I´m working on Wreath at the moment (Task 28) will give it a try later.

midnight condor
cinder pawn
#

Hi, i am doing Holo live, i have to the admin password (from supersecretdir), but its not working to admin portal... can you please help to fix it...

wide pagoda
#

hello guys

cinder pawn
lofty gulch
#

Is this an error in my syntax, or is the machine borked?

#

elliamy@pop-os:~/Downloads$ gobuster vhost -u holo.live -w subdomains-top1million-110000.txt
2022/04/21 20:40:44 [!] 2 errors occurred:
* WordList (-w): Must be specified (use -w - for stdin)
* Url/Domain (-u): Must be specified

#

also tried with the http:// infront of the url

quiet raft
#

Did you install it with apt?

lofty gulch
#

yup

quiet raft
#

That is a syntax error, it can't be an error with the remote machine

quiet raft
lofty gulch
#

Ah, will do

quiet raft
#

Or use Kali for up to date security tools

lofty gulch
#

Cheers, didn't realise the apt version was so out of date

quiet raft
#

The problem is with those repos, not apt itself

#

Packages are different between Kali, Debian, Ubuntu, PopOS, even though they all use apt

lofty gulch
#

Yeah, been trying to keep on top of it, but clearly messed it up there. I have Pop as I'm doing a physics degree and it works well for that, and win11. Maybe I need to learn how to Tri-boot for Kali

quiet raft
#

Make a VM

lofty gulch
#

True true!

#

What proportion of ram and cpu threads do you reckon I should allocate?

quiet raft
#

¯_(ツ)_/¯

#

I usually run kali with 4g and 2-4 threads

lofty gulch
#

Thanks!

tribal vigil
#

Hi,
I think Holo network is down (and as no one is using it so no one try to reset it ?)
I cannot ping while being connected to the VPN or on attack box (none of the (visible) machines reply).
Is it possible to reset it without waiting 5 hours ? (1 vote per hour if I'm the only one here)
Thanks !

#

(PS : does not ping even after > 15 minutes and not really urgent since I probably won't have the time to continue tonight, just saying in case someone wants to do it)

quiet raft
#

The VPNs will conflict as your account only has one IP

tribal vigil
#

Well yeah but I tried at first with the VPN and it did not work, then I tried with the attack box

#

I'm going to try with the attack box only, might be a issue from my vpn

#

Just tried with only the attack box (no vpn), does not ping neither

quiet raft
#

In fact, you know one machine is running a webserver. I'd suggest trying to interact with that

tribal vigil
#

Well I initially tried to ping because the web server did not respond, but now it seems to work so... my bad 😦

#

Sorry

#

guess I'm dumb 🙂

visual mortar
#

Hello I have a similar problem, I am in the initial recon phase, I know the ip of the web server but it doesn't respond to anything, I have tried ping, nmap, browser, curl, nmap with -Pn and still nothing

#

I am connected to vpn also

#

I am stuck at this problem since yesterday

#

If anyone could help I would really appreciate it

spare beacon
#

Which room?

visual mortar
#

Holo, that's why I sent it here

spare beacon
#

Sorry, I clicked in the channel and didn't notice.

visual mortar
#

it's ok

visual mortar
#

does anyone know why isn't it working?

analog snow
slow cosmos
#

Hi all, hoping someone can help as I've been stuck on this for hours. On my attacking machine I have no issue with chisel, however on the remote machine I keep on receiving the following error:

./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by ./chisel)

I'm up to Task 23 and cannot proceed any further, any help is appreciated.

timid current
slow cosmos
slow cosmos
hollow steepleBOT
#

Gave +1 Rep to @timid current

wide pagoda
#

hello guys

#

someone in the network? I need a reset

#

the login page stop working

quiet raft
wide pagoda
#

it's working now, just my host wasn't up

#

mb

hybrid wedge
#

Anything wrong with the network got booted off from my shell. Dropped and reconnected the VPN still unable to see any hosts.

quiet raft
#

Remember there's several instances

grand pelican
#

There is something wrong with this network. Every time I go to this room shows that the network is up even though I didn’t start it. And now I am not able to connect to the host 10.200.111.33

blazing cedar
#

I'm going to struggle explaining this, so please be patient. Once I escape the docker container and get www-data on L-SRV01, there is a bash error bash: cannot set terminal process group (2041): Inappropriate ioctl for device bash: no job control in this shell which i believe is whats causing the privEsc to root to fail. I'm following the tips and guide in TryHackMe so I'm attempting to abuse the privEsc it suggests. The session I have in the docker container is stabilized like the guide suggests, with bash. I'm having a hard time even wrapping my head around the connection from the Remote host w/container and how its able to connect back to me if they aren't on the same subnet. I see that the shell relies on command injection with curl.

blazing cedar
#

I solved my problem

#

this error is basically not important

cinder notch
#

There's a lot of stuff like that in the room since stuff was moved around a lot in the editing from my understanding. Tasks 1-8 are initial setup tasks, everything onward is in order.

hollow steepleBOT
#

Gave +1 Rep to @cinder notch

blazing cedar
#

Is anyone else having pivot issues in the 112 instance? I think it might need reset

#

the remote webservers don't finish loading

crude inlet
#

same here dude

#

once i login on the admin panel . the server hangs on the redirection phase

modern moat
#

Hi guys

#

when i solve the holo i get access to 10.200.110.35
but After resting the same credentials didn't work so i can't access the machine

#

any one faced this problem

blazing cedar
thorn shoal
#

@blazing cedar Great advice

wide pagoda
#

hello guys

#

can't communicate with hosts

static cosmos
#

Hey Guys, does the L-SRV01 respond to ICMP by any chance

#

L-SRV01 - crashed, need one more vote to reset the machine

quiet raft
#

There's several instances of holo, each with totally separate networks

cinder notch
#

Someone correct me if I'm wrong, but the AV evasion on this network will get easier the older this network gets since Defender can't pull new signatures/updates from the internet.

#

iirc the DumpStack.log trick that mr.d0x tweeted a while back worked to get past an initial static scan in this network months later

thorn shoal
#

@unreal hemlock man me too hahaha thanks for recommending a room for it, legendary for that

hollow steepleBOT
#

Gave +1 Rep to @unreal hemlock

nimble pendant
#

Can a mod or whomever restart the 10.200.19 instance. The network stopped, i started it up again but its been 24min and the .33 machine never came back online

polar verge
#

same happen to me right now

rough jasper
#

Anyone having issues spawning a tty shell ... I run the python one liner & it does nothing no responce/change? I have never encountered this issue before?

rough jasper
#

I'm on hololive task 14 ..... I'm not sure with this machine what's going on It won't give me a reading when I tried to fuzz it, it also didn't want to give anything on dir busting. I just got in through some trial & error. So for what ever reason it's not doing things it should.... Now I'm at the part of getting the tty ...I did get a net cat shell and I could load up linpeas to do a scan but it won't take the python one liner. I also tried the socat & that have way works... Showing that the port is being used but won't give me a shell

#

So I got a dimb shell with nc but It doesn't want to respond to the python script for me to continue getting a stable shell

final patioBOT
rough jasper
#

I have a screenshot for you, but I have never posted one on this platform before. Just getting that figured out

#

┌──(root㉿kali)-[/home/kali]
└─# nc -lvnp 6666
listening on [any] 6666 ...
connect to [10.50.152.26] from (UNKNOWN) [10.200.155.33] 60172
whoami
www-data
pwd
/var/www/admin
python -c 'import pty; pty.spawn("/bin/bash")'

pwd
/var/www/admin
whoami
www-data

rough jasper
#

python's in the /usr/bin I just tried running it from the bin dir & nothing ...looking for bash ... there is a bashbug in bin ....I'm guessing it would be in root

#

bash is in the other bin

rough jasper
rough jasper
#

Thanks for the help either way

ashen sage
#

hi guys i have been tryng for days to root into Linux Server but with no sucess. could anyone help me out a bit i would be very grateful

rough jasper
#

I seen the python3 I just typed python my mistake should have been better at relaying back the info.... I'll try and see if it will take a python3 instead of just python...... Learned something new python3 -c 'import pty; pty.spawn("/bin/bash")'
www-data@6338e635a442:/var/www/admin$ I haven't encountered that before Thanks

cobalt solar
#

can we get a reset on 10.200.112.0/24? the S-SRV01 machine is completely borked (at least for me it is) : (

cobalt solar
#

it does? hmm.. i'll check it again. perhaps it's a problem with sshuttle

#

i'll try autoroute + socks server instead, thank you! : )

#

sshuttle -r user@$ip x.x.x.x/24 -D

although now that i think about i, i think i may have used the wrong ip for the pivot since i export ip’s with bash so it could’ve been pointed to the container LOL i’ll double check that just to make sure

cobalt solar
#

solved! it was a thing with sshuttle, i don't typically use it so i went back to the msf way of pivoting and everything's working normally. thank you for the help tho! : )

cobalt solar
#

same! 😈

zenith delta
#

It looks like getting an RCE in task 15 doesn't work. Signin with credentials or other access to the dxxxxbxxxx.php file gets redirected.

zenith delta
#

back to index.php
Now when scanning the box, it only has port 22 open..

zenith delta
#

10.200.107.0/24

#

Np. Thanks though

hollow steepleBOT
#

Gave +1 Rep to @unreal hemlock

cobalt solar
#

no!! XD not at all haha i'm very careful to not barrage packets especially when proxychains are in use since they can be pretty brittle. I've noticed it as well, I think it's just people who are scanning the host or a lot of people accessing a specific resource at once : )

cobalt solar
#

dont worry! you'll get there! ik i said i was gonna root this today as well but i havent even opened a terminal yet. but we'll see what happens : -}

hoary crest
#

HOW I send the android app file format .apk to anyone from my VirtualBox kalilinux.

quiet raft
#

@hoary crest This channel is for the holo network in tryhackme.

hoary crest
#

what is this holo network

cursive carbon
#

Hi Guys, can anyone help me with AV evasion section. I am able to bypass AMSI but I am facing issues with AV.

cursive carbon
#

Yes. I was following rasta mouse blog. I generated a binary from covenant and with the help of threat checker, i was iteratively removing all the bad bytes but at later point, the output of threat checker was very vague and I couldn't figure out whats going on. It was 3 am in the morning so I shut down everything because I was frustrated. At the moment I am going through BCSecurity 's webinar on evasion. I hope it has something to offer. I was thinking instead of using a C2 agent, I will obfuscate a powershell reverse shell combined with amsi bypass. What do you think? Any suggestions?

#

Yeah Even I am doing everything on win 11 dev machine. I was also thinking of using some other c2 like empire which I learned in throwback network. So what you are saying is, if I am able to bypass Amsi, then there is no need to obfuscate my powershell reverse shell, but will defender not catch it?

#

I think it makes sense, as long as I am running everything on memory, AV won't catch it. And when I get admin privileges I will immediately turn off real time monitoring as it is a headache lol

#

Yeah sorry. Makes sense. I won't do it.

#

Anyways thanks for the heads up man. Really appreciate it.

zenith delta
#

Yo, what to do if someone changed to way for the RCE?

quiet raft
zenith delta
#

seems im alone 😛

quiet raft
zenith delta
#

cool, thanks

cursive carbon
#

Can anyone help me with the ntlm relay section? My ntlmrelayx.py is not receiving any smb connections. I have tried to replicate the steps numerous times but no luck. I even downgraded impacket to 0.9.19 using pimpmykali, but still no luck. Any help would be greatly appreciated.

cursive carbon
zenith delta
#

Hey everyone

#

Idk why my proxychain not working

#

Its showing connected but whenever i try to run nmap or check if machine is accessible or not it shows host seems down

zenith delta
#

Yeah that i know but simple nmap scan also not working

zenith delta
#

Its probably dumb question to ask but

#

Why we bypass amsi rather then just connecting it with rdp and turning off the windows defender

#

Nope

#

O got it

#

So in oscp we need to bypass that too?

quiet raft
#

IIRC OSCP AV Evasion is very simple in comparison

zenith delta
#

Is it necessary to learn c2 framework for oscp ad

cobalt solar
zenith delta
cobalt solar
#

i'd say, that in my case, the ad in holo asks more of you than the ad in the oscp. i found the oscp ad part easier but that's just me and it's different for everyone

zenith delta
cobalt solar
#

aaaand rooted! fun network, i definitely learned a lot from this room

odd warren
#

any idea how to bypass the amsi and do a reverse shell to windows with ip address x.x.x.31? I'm following the steps of tryhackme but it doesn't work

rose delta
#

Is the HTTP server on L-SRV01 down?

rose delta
#

Can someone please hit the reset? Been waiting for quite a while...

quiet raft
frail axle
#

Anybody faced the port forwarding issue in task 47? I have set up everything as expected (turned off services on PC-FILESRV01, checked that 445 was closed, started ntlmrelay.py-0.9.22 prior executing portfwd, netstat shows that port 445 is owned by my payload on PC-FILESRV01, on kali port 445 is owned by ntmlrelayx.py and I use shuttle) and I cannot get SMB traffic redirected to ntlmrelayx. PC-FILESRV01 receives connections from S-SRV02 (confirmed by wireshark) but they are not routed to port 445 opened on kali by ntlmrelayx.py. I even managed to reset the network but it did not help. Anybody faced such issue? It seems to be related to MSF.

slow ocean
#

Can anyone help , I got SYStem on PC-FILESERVER01 but i made a huge mistake while doing the task 47 , I sent the shutdown /r command in meterpreter instead of reboot . I cant wait for 4 hrs to reset network every once in an hour . My network is 10.200.95.33 [DC-SRV01]

frail axle
slow ocean
slow ocean
sage brook
#

Anyone not able to reach the Holo boxes?

sage brook
#

Yeah, realised this soon after asking lol

#

Been working on Holo throughout the day and I didn't notice the timer run out, since starting it back up again, I've not been able to do anything, can't load a page, ping...nothing

zenith delta
frosty kiln
#

hey, what knowledge do i need to have in order to start with holo?
or is there any recommended rooms that i should complete before?

quiet raft
#

I'd do wreath first at the very least

winged kelp
#

Is 10.200.x.0/24 where x is typo or intended

quiet raft
winged kelp
#

Will it be same as dc in the picture above (room)

nimble rune
#

Hello everyone, I am having trouble reaching the network, it shows that it's started but I launched the nmap scan and I got nothing

winged kelp
#

Anyone doing holo here

#

Pls let me know if you are able to login as it seems broken now

#

Can anyone please help me to reset only one vote required.

It seems the network is broken.

quiet raft
#

You can add a vote to reset every hour

winged kelp
#

I'm in 109

#

Thanks someone voted

winged kelp
#

Again facing same issue and I lost my shell

#

Is someone messing with the machine 😫

winged kelp
#

Any admins here

#

@help

nimble rune
#

The network crashed again for me, I need 4 more people to vote on the reset

iron galleon
nimble rune
hollow steepleBOT
#

Gave +1 Rep to @iron galleon

winged kelp
#

Same here my network crashed , mistakenly closed the reverse shell terminal😩

#

anyone in 111 need 2 more votes

winged kelp
#

I don't know why but why she'll is continuously freezing

#

@anyhelp

runic matrix
iron galleon
slow ocean
#

a quick question , Im on dll hijacking task , and ive done everything accordingly , but scheduled tasks are not showing the particular application which we are looking to hijack. Been running the listner for 5 mins now but no connection yet , Any suggestions ? I looked over the internet but I wanna know what wrong Im doin since i followed the path from THM only

nimble rune
#

Hello, at the moment, I can ping the linux web server but I can't access the admin.holo.live dashboard. This happens to me multiple times, and I always have to wait for the network to stop (due to inactivity)

#

This is really annoying, I have been stuck at the same step for two days now for this exact reason

fiery gate
#

I had gained initial foothold and now the port is closed -,-

frail axle
slow ocean
fiery gate
#

Is someone bruteforcing the webserver? If so could you decrease the threads?

#

10.200.95.33

#

Landing page is working fine, but authenticated resources like /dashboard.php is not working

frail axle
bronze crag
fiery gate
#

I lost access to public IP 10.200.95.33, how can I execute shell again and try lateral movement and breakout?

#
nmap -sn 10.200.0.0/16 --min-rate 2000
Nmap done: 65536 IP addresses (0 hosts up) scanned in 139.66 seconds
#

Regened ovpn config -,-

#

nvm fixed for now

fossil star
#

Hi can't login in the dashboard anymore, anyone else with the same problem?

copper dust
#

hello fellow hackers

#

anyone has trouble pivoting through the network

#

I mainly use sshuttle for pivoting

#

tried different commands with different parameters but still can't reach the internal network

copper dust
#

Ok chisel doesn't do either

paper ember
#

yes its working with me

#

use chisel to portforward a specific port

paper ember
paper ember
#

really great room ,i have learnt a lot of new things
really grateful guys ❤️

lavish latch
#

Network broken?

#

10.200.109.30

night widget
#

can we still submit our reports for it ?

stiff vessel
#

how do i install chisel on the target machine?

dusty forge
stiff vessel
#

Ok thanks

woven quiver
#

My pings and nmap scans are getting rejected when I try to recon the network

#

OVPN is connected

iron galleon
#

!vpnscript

final patioBOT
iron galleon
#

just to be sure it is not the vpn being the problem

spare beacon
#

Holo is a sub only room ( unless it's changed) and has it's own VPN script to download.

woven quiver
#

Im a sub. Trying to connect from my OSX, i’ll try the script on my kali machine later

oblique garnet
woven quiver
#

How did you fix?

#

Haven’t looked into it yet

oblique garnet
finite lion
#

Is anyone here to help HOLO NTML Relay?
I disabled netlogon on 10.200.XXX.35 and restart.
but now I cannot login or RDP to this machine.
Any idea on this step please?

regal hazel
#

I have the same issue as @woven quiver , machines seem to be down, (I moved to another room, so its not the vpn)

regal hazel
#

Thanks for your answer.... you are absolutely right ! Sorry for the inconvenience

hollow steepleBOT
#

Gave +1 Rep to @unreal hemlock

woven quiver
#

It worked yesterday so I’d guess the machines were down for when I tried

rigid elm
#

I can't access HOLO machine

#

Can anyone vote for reset

rigid elm
zenith delta
#

I have a Q about holo. Is there a dns server i should be pointing at so I can resolve www.holo.live?

quiet raft
#

Your hosts file

zenith delta
#

ok cool thats what i was thinking, just wanted to confirm I was supposed to use some other dns. thanks!

night widget
bitter lava
#

Unable to root the DC or even attempt to due to some sort of issue with how the environment is setup. I believe it's a DNS issue. Was the DC purposely configured to prevent exploits such as Sam the admin or ADCS?

#

If the purpose of this room was for pivoting then someone should have a closer look at how ntlm relay attack is working. Disabling lan man services on PC FileSVR breaks any means of getting a call back if you don't lay some sort of startup persistent to call back once you reboot.

#

Even using KrbRelayUp with valid low priv user account doesn't work. Literally nothing works when trying to root or even gain a shell on the DC.

woven quiver
#

Is it me or why can't I fuzz for different vhosts when I try to fuzz holo.live?

#

tried both gobuster and wfuzz

#

I tried guessing admin and dev and they were both correct

#

why didnt the fuzzers find them?

night widget
#

anyone else having problems accessing the webserver on the .107 subnet?

analog snow
#

In the final tasks, is the ntlm relay working, (10.200.107.30) I think I've got the setup right but can't receive anything with ntlmrelayx

analog snow
#

Yeh, they say to use shuttle as its more stable or something and I've used it but still nothing

#

I think, I've read in here that the ntlm relay was broken but wanted to confirm if others could get it to work

iron galleon
#

oh noes not broken network stuffs.... as shadow wants to do this eventually

analog snow
#

Well, it's hellish to setup correctly then if it's working

agile wind
#

is there anyway the L-SRV01 machine can be rebooted ? ... the admin panel isn't working for me ... it's stuck here with no response

analog snow
#

if you specify the domain ip, people could vote for resets :)

agile wind
#

10.200.155.33 ... already 4/5 requesting reset ... we only need one lol

#

it is time to shine chosen one

outer tangle
#

I was signed into it earlier and now when I login it just spins

#

10.200.110.30

outer tangle
#

I’ve even rebooted my machine just to make sure. Admin page loads but won’t let you login

outer tangle
#

2 more resets needed unless an admin or someone can go ahead and reboot L-SRV01

iron galleon
outer tangle
#

I think it’s ever hour. I’ve done 2 of the 3….

iron galleon
#

i.e if shadow recalls correctly you your self can reset the network given enough time

#

ah okay

outer tangle
#

Wish there was a better way of catching these machines freezing

#

Sucks having to wait

outer tangle
#

1 more!!!

outer tangle
#

I do have a question about task 13. I saw the rce in the source code first but when testing with wfuzz it won’t find it and i think it’s because to get to dashboard.php you need to be signed into the admin panel.

zenith delta
#

Did anyone get the NTLM Task?

#

I think that network is broken

steady hamlet
#

Can you guys help me reset 10.200.110.x!

#

Smash that reset button 😄