#breaching-ad

1 messages Β· Page 1 of 1 (latest)

frank stratus
#

configuring DNS in this room is annoying

#

is there anything wrong or is it just me?

#

can someone help?

wooden minnow
#

Can you verify your account and show us

#

!docs verify

outer timberBOT
frank stratus
# wooden minnow Can you verify your account and show us

I think I spoke to you in the tech chat. You told me to try and reset it by pressing the red button which I have and it did not make a difference. There seems to be other people facing this issue as well. Is there not a standard step by step solution for this issue?

#

I watched your video. Did you run into the same issue? I was not sure how you managed to get it to work in the video because your saved button was greyed out

karmic prawn
frank stratus
karmic prawn
#

Kali I take it?

Which subnet are you on in the breaching ad room?

frank stratus
#

Yep Kali 10.200.55.101

karmic prawn
#

Okay, can you ping the DC directly via IP? Just ping <dc ip address>

frank stratus
#

Yep

#

but it is nslookup that does not work

karmic prawn
#

Okay so are you setting your IP with network configuration, then going to console as root and doing systemctl restart networkmanager --- AFTER connecting to the VPN?

karmic prawn
#

I'm not sure if it makes a difference but try as root or sudo -- if you run pimpmykali.sh (google it) you can re-enable root login in Kali

sacred acorn
#

are you editing the systemd file or the etc file

#

and are you putting it at the top

karmic prawn
#

Each time I did it, I just added DNS to the advance network configuration GUI and then restarted network manager. I have completed every room and that worked for me

#

With my own Kali VM for context

sacred acorn
#

no

#

as root

#

cd /etc

#

then nano /resolv.vonf

#

then put it at the top

#

if you restar network manager as well it removes

#

it

frank stratus
sacred acorn
#

ctrl x and the hit y

frank stratus
#

systemctl restart resolv.conf?

sacred acorn
#

no

karmic prawn
#

no what panda said above

sacred acorn
#

thats only for systemd

#

which never works

frank stratus
#

So once I save it then it needs a reboot?

#

to apply changes?

sacred acorn
#

no

karmic prawn
#

I never actually did those steps on mine though -- i literally just updated my advanced network configuration with the DNS, saved it, then restarted network manager -- I never had an issue -- I didn't edit the resolv.conf file but that should work too

sacred acorn
#

because its automatically taking it as a DNS setting

#

sometimes that DOES work but ive always edited the conf

karmic prawn
#

yeah that seems a more sure way to do it

sacred acorn
#

make sure you put it at the top

#

so it p1's that IP

frank stratus
#

Then beneath that something like 8.8.8.8 to make sure I have internet access as well right?

sacred acorn
#

okay so

#

one sec

#

this is what it should look like

#

dont worry about the commented out or the ip i have

frank stratus
#

oh so just one nameserver

#

nothing beneath it correct?

sacred acorn
#

IF you have anything beneath it just leave it

#

but the ip nameserver NEEDS to be at the top

frank stratus
sacred acorn
#

no

#

do not restart kali

#

because it will rmeove it

#

duno wy

frank stratus
#

oh does it always do that? and is there a way to not make it remove it? I am guessing not?

sacred acorn
#

but everytime i restart my machine or Network Man it removes it

#

im not sure

#

id just remove it after the box is done so remove clutter

#

liek i said once it is in, restart the vpn connection and NSlookup

karmic prawn
#

@frank stratus -- let us know if it works. If it doesn't, I might be able to jump on a screenshare with you and do some more troubleshooting. Wrapping up a work meeting at the moment

frank stratus
sacred acorn
#

i believe so if you reboot it

abstract shadow
#

Guys :-; Im currently trying to setup the openldap server, Since I'm on arch I cannot use dpkg-reconfigure so I'm following the arch wiki. :-;
after making the config file I'm facing the following issue while adding the config file . https://wiki.archlinux.org/title/OpenLDAP . I don't know much about ldap. can anyone help? tried googling up but couldn't come up with anything helpful

#

I tried deleting all the contents of /etc/openldap/snapd.d and tried the command again. Then I received the following error.

small pulsar
#

Hello. I finished the room. However, I have not privilege escalated on the domain controller. This task seems to be out of scope but I want to just do it as a challenge. Was the DC meant to be pwned or is it actually maintained and trying to own it might not be a feasible task for a beginner like me? Thank you in at advance whoever answers.

dense cedar
spice tree
#

From where I can get the DNS host address of the DC?

DNS=<THMDC IP>
spice tree
#

Also it is not working in the THM hosted attackbox or kali machines. I tried both

#

plz lmk what I am missing here

dense cedar
spice tree
#

I see thanks for this, more clarity you can mention this in the note of the room as well

spice tree
wooden minnow
#

so it matches 10.200.27.101

dense cedar
# spice tree I tried adding the IP as described in the task 1, not working in my case

If you read the task, you will see that there is a specific section for doing DNS on Kali. I would really recommend reading the task in full before trying the very first thing. In these networks, there are a lot of Notes (in bold) that tell you about exceptions and edge cases. If you don't read these, you will get stuck for quite a while.

Since Kali does DNS through network manager, the systemd-resolve method will not work for you. You can either follow the process described in the task to add the DNS server to network manager, or you can directly modify your /etc/resolv.conf file that network manager uses.

You can also use nslookup za.tryhackme.com 10.200.27.101 to verify that DNS is working in the network. If this works, but nslookup za.tryhackme.com does not, then it means there is still something wrong with your configuration of DNS. However if the first command fails, chances are there is something wrong with the network (might not be started perhaps) and then you should ask for support.

DNS solving is vital for AD hacking (due to Kerberos authentication), so I would really suggest you take the time to work through this and get it sorted.

pure glade
#

any pros

shy kettle
#

Please reset the network as no response is coming from the dns

warm snow
#

Task 5, using the attack box now because I couldn't get any hashes from responder on my vpn host. Same issue with AttackBox, have left it running and not catching anything. I reset hosts which didnt seem to help.

spice tree
#

I just got the hash from the server

spice tree
warm snow
warm snow
gaunt shell
#

!docs verify

outer timberBOT
warm snow
slate swanBOT
#

Gave +1 Rep to @gaunt shell

spice tree
# warm snow

You need to kill the services with "Error starting **" message

#

Checkout the process occupying the port number using sudo lsof -i :[PORTNO]

proud rain
#

noob question
may I know what is the meaning of this on AD networks?

#

3 days of access left

young vale
#

the room kicks you out after ten days but you can simply click the 'join' button to get back :)

proud rain
#

thanks @young vale for the info

slate swanBOT
#

Gave +1 Rep to @young vale

spice tree
#

Yes,

#

I also didnt get this prompt and it worked in my case

stable junco
#

@drifting rain

#

Check the message he deleted when you can

wooden minnow
#

It doesn't have to be just Hydra.

stable junco
#

Yeah i know pinged him because i saw his status as online and i usually ping him anyways πŸ˜„

abstract monolith
#

This solved my issue as well. Was unaware that spacing between lines would cause an issue. Thanks!

slate swanBOT
#

Gave +1 Rep to @dense cedar

glacial willow
#

Hi guys, any suggestion to dump AD hashes? am practicing and I have checked smb, rdp and AD including kerberos, but no luck

prisma escarp
#

Hi
In Task 4 LDAP Bind Credentials

First I set Hosting a Rogue LDAP Server, and then I tried ldapsearch ~supportedSASLMechanisms.
But ladapsearch output was only "dn:".

Could you tell me to fix it.

glacial willow
bright sundial
#

In Task 4 (LDAP Bind Credentials), when I run ldapsearch -H ldap:// -x -LLL -s base -b "" supportedSASLMechanisms, I don't get any output other than dn: (I should be seeing "supportedSASLMechanisms: PLAIN" and "supportedSASLMechanisms: LOGIN" after dn:), which leads me to believe that my olcSaslSecProps.ldif file is not configured correctly. I also get an error after clicking on "Test Settings" that says the " LDAP Connection failed: The LDAP server is unavailable.".

#

The contents of my olcSaslSecProps.ldif file:

dn: cn=config
replace: olcSaslSecProps
olcSaslSecProps: noanonymous,minssf=0,passcred
bright sundial
#

Still nothing and I've reconfigured slapd 3 times now

#

Don't know if thiis has anything to do with this issue but when I'm configuring slapd, I don't get asked the question about which LDAP database to use.

#

voted for a network reset because I keep getting the error "LDAP Connection failed: The LDAP server is unavailable." when clicking on "Test Settings"

true kestrel
#

I guys, can anyone explain me why johntheripper and hashcat down't work in this task?

#

I've downloaded password list from site, and i saw write up in internet, so the password is in the list.. I really don't understand

dense cedar
bright sundial
#

Yes, I looked at most of the messages regarding this issue and tried starting nc. I received no connections to where I was listening (port 389)

dense cedar
true kestrel
#

i'm pretty sure..

dense cedar
dense cedar
bright sundial
dense cedar
bright sundial
#

Right, didn't even realize that. Thanks again!

coral bay
sick hull
#

i know this is beyond the scope of the lab, but has anyone tried doing task 4 ldap bind with Responder (for fun and practice)? the ldap server apparently supports simple bind, so it should work. but i'm not having much luck with figuring out how to enable it. i can get the ssp hash but not cleartext

dense cedar
sick hull
dense cedar
sick hull
# dense cedar Let's me know if you get something working there, would be really interesting πŸ™‚

major challenge is that its all based on hex codes and i cant find a reference for them anywhere. example https://github.com/lgandx/Responder/blob/master/servers/LDAP.py#L170

GitHub

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat...

dense cedar
coral bay
#

Hey , in task 6 , whenever i try to open http://pxeboot.za.tryhackme.com , browser showing SERVER NOT FOUND

-- i connected with breachingad with openvpn
-- change DNS=10.200.54.101 in /etc/systemd/resolved.conf
-- also added DNS in Advance network manager ..
My ping is working with 10.200.54.101

#

Also restarted both services of systemd & NetworkManager

gaunt shell
#

@celest fable Please don't post random job offers, there would be a proper channel for that #jobs-board.

dense cedar
coral bay
still yarrow
#

Hello everyone.

#

I am trying to do breaching active directory and i am struggling with dns configuration i tried to use GUI and /etc/resolv.conf both is not working can someone help me?

#

I use vmware

dense cedar
still yarrow
#

It give me connection timeout.

#

Right now away from my laptop

dense cedar
still yarrow
still yarrow
#

Hello guys i am trying to configure DNS but keep getting "** server can't find thmdc.za.tryhackme.com: NXDOMAIN" although i modified /etc/resolv.conf any idea? i am using kali 2020 as VM

dense cedar
still yarrow
#

Already solved thanks

grizzled lagoon
#

Hi !

I'm stuck at the LDAP passback... Does anyone know why I can't see nothing when checking enabled auth mechanisms ?

#

Running this version of kali with freshly installed & reconfigured LDAP as shown in the instructions :

dense cedar
grizzled lagoon
#

Ok thanks !

grizzled lagoon
#

@dense cedar Sry for asking for your help again but I'm ending up with this message from the printer settings page : LDAP Connection failed: The distinguished name contains invalid syntax.

dense cedar
grizzled lagoon
#

oh ||sh*t||

dense cedar
#

So that means it is working, are you getting anything on your TCPDump? if not, did you get something from NC?

grizzled lagoon
#

I got from NC

#

nothing from TCPDump

dense cedar
#

Then TCP dump should also work, have you tried spamming the test settings button a couple times? Sometimes TCPdump lags. Else, just again verify with NC and then move back to TCPdump

grizzled lagoon
dense cedar
#

Looks fine, just confirm that tun1 is the correct adapter. It might be tun0. If you want me to check, run ifconfig and route -n and send output

#

And then just spam the Test Settings button on the webapp a couple times

grizzled lagoon
#

i did ip a and it was tun1 with the same IP than my OVPN connection

dense cedar
#

So everything else based on the output should be fine, so then if NC is working but not TCPdump, I'm a tad bit lost unless it is an incorrect interface, since at that point you are getting the connection back

grizzled lagoon
#

I'll work a bit on it and I'll tell you πŸ™‚ thannks πŸ‘

dense cedar
#

πŸ‘ Good luck there, I'm calling it for the night. Sure you will get it

grizzled lagoon
#

I had a network issue where my VPN restarted every 5 seconds… reboot and it was ok

#

Thanks for your time πŸ‘ŒπŸ»πŸ”₯

sleek grotto
#

hello, I've ran responder for almost one hour and I still don't have captured hash

#

I did the previous task without problems, nslookup is working for the DC and ping too

prisma thorn
#

Stupid question, but should I configure the DNS in a real world attack like in this room?

#

Like is there going to be a machine like THMDC

sleek grotto
#

I was on a kali VM so I switched to the attack box and did responder for several hours and it's not working either, I've done all the others task except that one... even my attacking box has given up and terminated without giving me an hash πŸ˜†

wet barn
#

Is the Attacking AD module going to be archived and put into a room at a later date? I saw that there was only 2 days left for this particular room and was curious if there was going to be a way to access these rooms in the future.

wet barn
rain spear
#

Hello, I can't connect to breaching-ad. I connected VPN and started the network. Thanks

grizzled lagoon
#

Did u follow the procedure for Kali ?

#

@rain spear

rain spear
dense cedar
dense cedar
dense cedar
wet barn
stable junco
#

@somber ledge

somber ledge
#

-ban 951185780175437854 -ddays 1 scam

slate swanBOT
#

πŸ”¨ Banned Bille.san#6392 indefinitely

sleek grotto
slate swanBOT
#

Gave +1 Rep to @dense cedar

sleek grotto
#

I remember I had similar problem with the throwback network but it was eventually sorted out

dense cedar
primal saffron
#

hi i am stuck on dns configuration its not working for me

#

I have tried Kali method but nslookup is saying (;; connection timed out; no servers could be reached
)

prisma thorn
#

Hello all, I am trying out LDAP pass back attack. I am using in browser attackbox. So the server address in the LDAP settings (Printer Settings) is given as Attackbox IP. I have turned the nc listening to 389. when i save and test settings i am not getting any response in netcat.

#

Anybody could help me on this?

grizzled lagoon
#

Can u provide screenshots of ur setup ?

#

IP adresses, Settings page + nc terminal

prisma thorn
#

Why am I not allowed to paste the screenshot?

#

How could I paste the screenshot?

grizzled lagoon
#

You are not verified

#

Check With THM bot

prisma thorn
#

yes done, Thank you

#

I have stopped the slapd service also

grizzled lagoon
#

Restart the slapd service

#

Did you reconfigured it ?

#

With sudo dpkg-reconfigure slapd

#

And added the weak configuration in it ?

prisma thorn
#

Depackaging steps comes after receiving the connection back in the netcat from printersettings, right?

#

I am not receiving the nc listening if I have changed the printer settings. I have provided my Attackbox IP in the Server field of Printer settings. But still my nc is not receiving any connection.

grizzled lagoon
#

Everything seems correct on your side…

#

Did u asked for Network reset ?

prisma thorn
#

Does this have anything to do with Network reset?

grizzled lagoon
#

Depending on what others have done to the Network, some things may be broken

prisma thorn
#

Ok, will try to reset the network

dense cedar
dense cedar
#

See here:

primal saffron
prisma thorn
#

Thank you @dense cedar

slate swanBOT
#

Gave +1 Rep to @dense cedar

fierce juniper
#

Hello, I have been solving Breaching AD room and at Authentication Relay part it says that NTLM challenges are encrypted with user's hash. As far as I know that is not true at all. Challenge value is never encrypted. I have also checked RFC but could not find any information on challenge being encrypted with user's hash. And also when we capture with Responder, we are capturing responses not challenges. In my opinion, the word challenge has been confused with response through the module. I would appreciate for the clarification. Thanks.

spice tree
# fierce juniper Hello, I have been solving Breaching AD room and at Authentication Relay part it...

Challenge value is never encrypted
That is true challenge from the server is not encrypted. It is rather a random string generated. The client is then supposed to encrypt that with its NTLM hash and then send back to the server. The server then passthrough this information (both challenge and response) to the authentication server (in case of AD, it is DC) and then the DC tries to decrypt the challenge (because it has hash of all the users) and return the response back to the server.

This will give you an abstract understanding about the concept https://medium.com/@petergombos/lm-ntlm-net-ntlmv2-oh-my-a9b235c58ed4

fierce juniper
# spice tree > Challenge value is never encrypted That is true challenge from the server is n...

This part and also Once we have a couple, we can start to perform some offline cracking of the challenges in the hopes of recovering their associated NTLM passwords part must change. And also in the blog post you have sent, there are some misunderstanding also. There is no such a thing as client challenge. There is a blob which includes client nonce. You can check out the RFC for a better explanation. https://curl.se/rfc/ntlm.html#ntlmv2Response

dense cedar
# fierce juniper This part and also `Once we have a couple, we can start to perform some offline ...

The protocol itself is described as a challenge/response protocol: https://docs.microsoft.com/en-us/windows/win32/secauthn/microsoft-ntlm

You are correct that the blob part is call a nonce, but that doesn't really explain the process to users quite well. Using words like challenge and response makes things simpler. Please also see the following directly from Microsoft's documentation that explains the challenge encryption part (step 4):

The following steps present an outline of NTLM noninteractive authentication. The first step provides the user's NTLM credentials and occurs only as part of the interactive authentication (logon) process.

  1. (Interactive authentication only) A user accesses a client computer and provides a domain name, user name, and password. The client computes a cryptographic hash of the password and discards the actual password.

  2. The client sends the user name to the server (in plaintext).

  3. The server generates a 8-byte random number, called a challenge or nonce, and sends it to the client.

4. The client encrypts this challenge with the hash of the user's password and returns the result to the server. This is called the response.

  1. The server sends the following three items to the domain controller:
  • User name
  • Challenge sent to the client
  • Response received from the client
  1. The domain controller uses the user name to retrieve the hash of the user's password from the Security Account Manager database. It uses this password hash to encrypt the challenge.

  2. The domain controller compares the encrypted challenge it computed (in step 6) to the response computed by the client (in step 4). If they are identical, authentication is successful.

#

What I think is perhaps mis-interpreted in the diagram, which makes sense, is that it is the "server" that encrypts the "user" challenge. That is definitely not the case. It is the "user" that encrypts the challenge to generate the response for the "server". So I'll tweak the diagram a bit to make that clearer

fierce juniper
# dense cedar What I think is perhaps mis-interpreted in the diagram, which makes sense, is th...

Exactly. That was the part confused me. DC uses the user's hash to encrypt the challenge so it can compare the result with the cilent's response. But we are capturing the client's response with Responder not challenge. When I red the guide in the room, I understood it like we were capturing the challenge and trying to crack it. Don't get me wrong. I just saw a possible misleading information and wanted to correct it to contribute ❀️

dense cedar
# fierce juniper Exactly. That was the part confused me. DC uses the user's hash to encrypt the c...

All good! Thanks for reporting, we need to make sure that the information that is provided is accurate, and I can see how the diagram can be misleading so I'll fix that.

There is also common terminology that is used in the CyberSec space. So you are 100% correct that we are actually cracking the client responses, not the server challenges. However, it is fairly common out there to loosely refer to the part that is going to get cracked as the "NTLM Challenge". This is to distinguish the cracking of these vs NTLM hashes, which refers to actual NTLM MD4 hashes. Similar to cracking "Kerberos Challenges", which isn't actual Kerberos challenges. But I agree to ensure the information we provide is sound, hence we should call them client responses in the text.

I'll go make the updates later this week!

slate swanBOT
#

Gave +1 Rep to @fierce juniper

dense cedar
slate swanBOT
#

Gave +1 Rep to @fierce juniper

fierce juniper
fossil finch
#

Evening guys. Im stuck on the BreachingAD room

#

Configuring the dns settings

trim mica
# fossil finch

this needs to be your main dns... so you should change from automatic dhcp to dhcp ip address only

fossil finch
#

Okay it works

#

Thank you sm

slate swanBOT
#

Gave +1 Rep to @trim mica

trim mica
#

also anyone on the 10.200.25 subnet??? seem that the pxeboot site gives 0 response

#

started the reset process to see if that fix it

trim mica
# fossil finch Thanks *

also as they state in the tutorial part of how to configure dns... add another dns server like googles 8.8.8.8 after the vpn dns to still access the internet

fossil finch
#

would 1.1.1.1 also work?

#

Or is it 8.8.8.8

#

And do I add this to the "Additional search domains" or by the "Additional Static Adressess"?

trim mica
fossil finch
#

oh right

trim mica
#

you add it after the 10.200 ip seperated by a comma

fossil finch
#

Okay it works now. thank you sm

trim mica
#

no problem

#

having used linux and network manager a lot shadow is used to its quirks

fossil finch
#

Yet again it's probably me being stupid but when trying to run the spaying script I get this error?

trim mica
#

hmmm

trim mica
#

think that means they don't have some module they need installed via pip on that kali machine

#

could be wrong though

fossil finch
#

Got it working

#

yeah

#

Had to install requests-ntlm with pip

trim mica
#

YAY

deep torrent
#

How to get this working?

boreal token
#

hello guys how hack a wifi pc or mobile?

wooden minnow
quartz pewter
#

Ah, nevermind

#

-ban 993126830007664752 joined to ask how to hack a wifi

slate swanBOT
#

πŸ”¨ Banned daivis#8704 indefinitely

unique mist
deep torrent
#

I was having same problem using my own machine so tried using attack box, but same error

unique mist
#

Not sure off the top of my head then, you might be able to update resolv.conf instead? but it may get over-written in the attackbox

deep torrent
#

If anyone is able to solve this error then please help

deep torrent
#

What this means? I cannot access it more than 2 days or what?

wooden minnow
deep torrent
#

Why is that?πŸ€”

wooden minnow
trim mica
#

i.e if shadow rejoins the answers are still answered???

wooden minnow
deep torrent
#

DNS setting up part of this room is real pain. I am still having problems

wooden minnow
deep torrent
deep torrent
wooden minnow
trim mica
#

shadow is lost with manoobs problems so dunno how to trouble shoot and help

wooden minnow
#

Also can you

cat /etc/systemd/resolved.conf

@deep torrent

deep torrent
#

wait, i am sending

#

seems to be working now, idk how lol

wooden minnow
#

Sometimes the nslookup decides it isn't working.

#

And gives you a false reply.

deep torrent
#

thanks blobfingerguns

ocean plinth
#

Hey, apologies if this has been asked already, but I'm stuck on configuring slapd in Section 4 - LDAP Bind Credentials.
We are supposed to downgrade the authentication protocols used by slapd by creating a ldif file and using ldapmodify to update the config. I've followed the instructions exactly but ldapsearch does not return any results and it seems like these authentication mechanisms aren't supported by slapd? are there additional dependencies that need to be installed for SASL auth to work with slapd?

#
$ sudo ldapmodify -Y EXTERNAL -H ldapi:// -f ./olcSaslSecProps.ldif && sudo service slapd restart
SASL/EXTERNAL authentication started
ldap_sasl_interactive_bind: Authentication method not supported (7)
        additional info: SASL(-4): no mechanism available: security flags do not match required
#
$ ldapsearch -H ldap:// -x -LLL -s base -b "" supportedSASLMechanisms
dn:
#

This is in my Kali VM, not attackbox.

#

Oh, just saw this is a known issue on Kali and that the attack should still work

ocean plinth
#

It works happyPanda

sturdy nest
#

how did you solve it @ocean plinth

dense cedar
sweet reef
#

if that's what ur using

sweet reef
#

the Breaching AD net's been stuck on reset for days. Can't interact/ join. Does anyone know what's happening?

unique mist
sweet reef
unique mist
sweet reef
#

network state has been on reset for like 4 days, at least on my end

unique mist
#

screenshot time

sweet reef
#

yup

#

can't start it either

unique mist
unique mist
sweet reef
#

you mean reset progress? i believe I've tried that.

#

what's going on man? πŸ˜„

#

it's not cached or anything.

unique mist
sweet reef
#

oh my ...

sweet reef
slate swanBOT
#

Gave +1 Rep to @unique mist

unique mist
sweet reef
#

about to find out

#

openvpn's giving me a hard time

#

think something's wrong with network manager. it was doing this to me the last time and I just switched over to network d

#

and I don't understand it. it works for other people

#

I think I'll just switch

sweet reef
#

πŸ‘

unique mist
sweet reef
#

just got internet back up after switching to networkd. I'm set up DNS and see what happens.

as far as the Breaching -AD it's up and running

sweet reef
#

So, quick question.

#

I was playing with the password spraying script just messing around and now I can't seem to connect.

is there intrusion prevention or something? heh

#

like did I get blocked?

#

it says failed to establish connection. no route to host

unique mist
sweet reef
#

what have i done lol...

#

restart again

trim mica
#

wait the domain controller responds to pings???

sweet reef
#

no. so i borked it or something

trim mica
#

normally windows machines don't tend to repsond to pings

sweet reef
#

that's true

#

no ICMP

unique mist
sweet reef
#

Good, now I'll have to wait for someone else to vote

unique mist
sweet reef
#

10.200.54.101

#

for the DC

unique mist
sweet reef
#

?

#

what in the world...

unique mist
#

I can vote for reset if you like, but i think you just need to press the lil blue start button

#

Caching issues ftw

sweet reef
#

it was started earlier. it responded

#

what in the

unique mist
sweet reef
unique mist
sweet reef
#

i seem to not be capturing the full message from za.tryhackme's printer service (LDAP) or something got messed up

It captures up to the point of "invalid DN". I'm almost positive I've set this up correctly with Slap.

I'm not sure what's happening.

#

wait...

#

yeah, I'm authenticated

#

reset

#

this is captured with tcpdump. it keeps saying invalid DN

#

ahh, but during configuration i do not get the option to choose my db-type. I'll check to see...

#

nope... it's still mdb

#

that wouldn't give an invalid dn error anyway

...

#

hold on...

#

no wonder

#

dc=nodomainza.tryhackme.com... no idea how that happened

silent steppe
#

please tell me something I can't understand.
what could be wrong then.?)

#

NAT addapter
Parrot
Oracle VM VirtualBox

#

I did
systemctl restart systemd-resolved
sudo systemctl restart NetworkManager

unique mist
midnight swift
#

Hello I'm using attackbox and can ping the dc, but cant nslookup even after adding dc ip to the /etc/systemd/resolved.conf and restarting systemd-resolved

#

if manually set the server in nslookup, i can resolve dc fqdn but otherwise i cant

#

Unfortunately I don't have permission to upload images here I guess

silent steppe
#

Yes, indeed, I somehow missed this moment.
thank you very much, RobertABT.
now everything is ok

unique mist
#

!docs verify

outer timberBOT
silent steppe
#

By the way, anyone who uses Parrot may encounter the fact that the external Internet will stop working after the settings.
As an option, have a NAT and a Bridge in the settings.
By configuring the adapters in this way.

#

And you will be happy.

unique mist
silent steppe
#

yes, you rarely have to climb there. that's for sure.

unique mist
jovial hearth
#

$ sudo ldapmodify -Y EXTERNAL -H ldapi:// -f ./olcSaslSecProps.ldif && sudo service slapd restart
SASL/EXTERNAL authentication started
SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth
SASL SSF: 0
modifying entry "cn=config"

$ ldapsearch -H ldap:// -x -LLL -s base -b "" supportedSASLMechanisms
dn:

#

Anybody had this issue here? Not getting what is expected with the ldapsearch.

#

nvm.. I see it posted once I scrolled up..

prisma thorn
#

Hello All,

#

When I try to use responder I get Error starting on TCP server on port 389, check permissions orother servers running

#

I tried to look into the PID by lsof -i:389, but nothing runs on 389. How to resolve this?

idle blaze
sweet reef
#

I've been trying for a couple days to figure out what's going on with ldap.
Everything looks right. I receive Invalid.DN. There is nothing wrong with how I've set this up. Maybe there's a small detail I missed but I've followed step-by-step.

Here's a couple configs:

β”Œβ”€β”€(rootγ‰ΏHP-DeskJet-3755)-[/etc/ldap/slapd.d]
└─# cat 'cn=config.ldif'     
    
# AUTO-GENERATED FILE - DO NOT EDIT!! Use ldapmodify.
# CRC32 c163bca2
dn: cn=config
objectClass: olcGlobal
cn: config
olcArgsFile: /var/run/slapd/slapd.args
olcLogLevel: none
olcPidFile: /var/run/slapd/slapd.pid
olcToolThreads: 1
structuralObjectClass: olcGlobal
entryUUID: aad289b4-c5b5-103c-80be-27d0a6001545
creatorsName: cn=config
createTimestamp: 20220911003732Z
olcSaslSecProps: noanonymous,minssf=0,passcred
entryCSN: 20220911003911.601380Z#000000#000#000000
modifiersName: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth
modifyTimestamp: 20220911003911Z

β”Œβ”€β”€(rootγ‰ΏHP-DeskJet-3755)-[/etc/ldap/slapd.d/cn=config]
└─# cat 'olcDatabase={1}mdb.ldif' 

# AUTO-GENERATED FILE - DO NOT EDIT!! Use ldapmodify.
# CRC32 e2741582
dn: olcDatabase={1}mdb
objectClass: olcDatabaseConfig
objectClass: olcMdbConfig
olcDatabase: {1}mdb
olcDbDirectory: /var/lib/ldap
olcSuffix: dc=za,dc=tryhackme,dc=com
olcAccess: {0}to attrs=userPassword by self write by anonymous auth by * none
olcAccess: {1}to attrs=shadowLastChange by self write by * read
olcAccess: {2}to * by * read
olcLastMod: TRUE
olcRootDN: cn=admin,dc=za,dc=tryhackme,dc=com
olcRootPW:: e1NTSEF9VysrNEJEM09aLzhRR0J1VFB4SGwvSHhxZ3JHK0tKZng=
olcDbCheckpoint: 512 30
olcDbIndex: objectClass eq
olcDbIndex: cn,uid eq
olcDbIndex: uidNumber,gidNumber eq
olcDbIndex: member,memberUid eq
olcDbMaxSize: 1073741824
structuralObjectClass: olcMdbConfig
entryUUID: aad3a858-c5b5-103c-80c7-27d0a6001545
creatorsName: cn=admin,cn=config
createTimestamp: 20220911003732Z
entryCSN: 20220911003732.338968Z#000000#000#000000
modifiersName: cn=admin,cn=config
modifyTimestamp: 20220911003732Z

#

It looks fine to me.

#

Invalid.DN is what i'm getting back.

idle blaze
#

I dunno what any of that is, I was able to moreorless just follow the steps. I've not had to look at anything like that.

sweet reef
#

It's the configs, trying to check what isnt' right. I also followed the steps word for word

idle blaze
#

both files look the same as mine other than uuid and times.

#

I'm not on a deskjet printer, though. just a default kali 2022.03 VM.

sweet reef
#

yeah, i don't understand it either

#

no clue what it's whining about

#

i've been looking around for days for some kind of hint

idle blaze
#

what commands ends up throwing the Invalid.DN error?

sweet reef
#

Just running the pass-back attack. I'll listen with tcpdump and it goes through it's process, then at the end throws it... Invalid.DN and leaves.

#

No password.

#

It get's only so far and claims that I have a bad DN name

idle blaze
#

You sure the password isn't given maybe a packet before that one?

#

or two

sweet reef
#

Well, i've looked through it a few times and it's not giving it to me.

#

Ill take a SS

idle blaze
#

I do also see Invalid.DN in my capture several times, but I also have a few with the password. I admit, when I first hit the button, nothing came in, so I probably hit it like 4 more times and a bunch then came in.

#

the word "pass" will be part of it.

sweet reef
slate swanBOT
#

Gave +1 Rep to @idle blaze

idle blaze
sweet reef
#

I bullied that printer

#

give me ur lunch money

shy dune
#

Hi All,
I'm doing task right now,
i start the responder but didn't capture any username with the challenge

#

i wait about 40 mins btw

#

i also use Printer Settings "Test Setting" to test my responder, i do captured the username

idle blaze
#

I also have not gotten an auth attempt either on my own system or the attackbox.

dense cedar
# shy dune

If you send me your VPN file I can see what is happening with the service. However a reset of the network should fix any weird issue as well

dense cedar
gleaming crest
#

I can't seem to resolve THMDC again ,i haven't changed anything,
Checked ip it's the same nothing's changed , restarted systemd-resolved ,
vpn is connected i even regenerated it still nothing
Network state shows running

wintry dragon
#

Hello again...hopefully for the last time today haha. I am currently working on Breaching AD. I am this portion:
Before using the rogue LDAP server, we need to make it vulnerable by downgrading the supported authentication mechanisms. We want to ensure that our LDAP server only supports PLAIN and LOGIN authentication methods. To do this, we need to create a new ldif file, called with the following content:

My question is WHERE do we create that file on our kali machine? Thank you!

trim mica
#

yes you create that file on your own kali machine or on the attackbox if you are using that

wintry dragon
#

what should the path to the file be?

trim mica
#

does not matter much as long as when you run the ldap thingy you specify the correct path to said config file

wintry dragon
slate swanBOT
#

Gave +1 Rep to @trim mica

dense cedar
gleaming crest
dense cedar
# gleaming crest Network is active but I can't ping the ip So nslookup doesn't work, I use parrot...

Confirm that the error you are getting when you try to ping is a no route to host error from the VPN IP?

If so, then the network is not active. Contrary to what the UI says. There is a UI issue where if the network times out and a user selects extend instead of start, the UI believes the network is active where it is not.

You can try to trick the UI by inspecting element, re-enabling the start button and pressing it. However, if it is being stubborn and won't accept that, you will have to wait until the network time expires.

gleaming crest
slate swanBOT
#

Gave +1 Rep to @dense cedar

runic wind
#

ugh, can't ping the DC.

#

or resolve dns or any of that

trim mica
runic wind
#

yep i started it

dense cedar
runic wind
runic wind
dreamy niche
#

Hello, I just started configuring DNS on my machine, followed the instructions yet I'm having ** server can't find thmdc.za.tryhackme.com: NXDOMAIN ( I can ping the DC tho..) :/

hardy depot
#

I can't even ping the DC.

#

Up to a few minutes ago, I was thinking that I was just doing it wrong. Now I"m nmap scanning everything in sight, in case the IP displayed might have been wrong. Can't find a thing, though.

runic wind
#

@dense cedar (sorry for ping)
someone updated mcafee-sitelist-pwd-decryption for python3 and i confirm it works
https://github.com/funoverip/mcafee-sitelist-pwd-decryption/blob/c0e20ac0ac1588e0937d06dbced734202fd6d33f/mcafee_sitelist_pwd_decrypt.py

GitHub

Password decryption tool for the McAfee SiteList.xml file - mcafee-sitelist-pwd-decryption/mcafee_sitelist_pwd_decrypt.py at c0e20ac0ac1588e0937d06dbced734202fd6d33f Β· funoverip/mcafee-sitelist-pwd...

#

maybe consider using that instead?

dense cedar
amber trellis
#

Hi guys
I'm not able to connect with AD domain

#

Please help me

#

After changing the resolved.xonf file

#

I restarted the services also

#

But it's showing "server can't find thmdc.za.tryhackme.xom"

#

Anybody here @short drift

idle blaze
# amber trellis Anybody here <@984390515694899241>

I never had to change anything in resolved on my own kali 2022.3 instance. I did have to connect to the network, edit my DNS entries in connections (10.200.x.101,my_local_dns), and then restart NetworkManager.

#

After doing that, a ping to the DC, getting credentials from the distributor site, and an ssh into the first host (using the hostname, not the IP address) usually proved everything was fine.

trail jasper
unique mist
true quartz
#

This is a silly question, but can someone explain why I have to configure my DNS to be able to connect to a Active Directory network? Can't I just connect to a domain-joined computer via RDP or SSH, just like any other machine?

unique mist
true quartz
slate swanBOT
#

Gave +1 Rep to @unique mist

mighty phoenix
#

hi guys, would love some help in task 1, i have done all the steps but nslookup doesnt work for me, any advice?
the input:
nslookup thmdc.za.tryhackme.com
the output:
Server: 213.57.2.5
Address: 213.57.2.5#53
** server can't find thmdc.za.tryhackme.com: NXDOMAIN

also when i ping the DC i get a response
but when i attempt to browse to http://ntlmauth.za.tryhackme.com in task 3 i get site not found.

dense cedar
queen stratus
dense cedar
agile hound
#

Good evening everyone, please, i will be most grateful if someone could help me out.

#

I have done everything I can and still, the network IP does not connect or reflect on the page while the "Network state" is running. Please, I will appreciate a lot for any assistance or help rendered.

Thank you house.
πŸ™‡ πŸ™

trim mica
obsidian girder
#

is it normal I cannot connect to breachad network ?

#

vpn breachad connects correctly, but then its impossible to ping or nslookup THMDC server

#

I did dns confugurations accordingly

#

Ok solved I just reset the Network (wait for 5 asking resets) and worked

agile hound
sacred trail
#

my network is stuck on resetting for part 30 mins, any help on how can I fix it.

#

I have reloaded the page several times and also have reconnected to the vpn a few times now

trim mica
#

!vpnscritp

#

!vpnscript

outer timberBOT
torn dome
#

Can I ask if it is normal that my route to the breachingad network is via docker?

#

Thanks in advance!

trim mica
# sacred trail didn't work

oh that comment was not for you.... have you tried leaving and rejoining the room??? that sometimes fixes that type of error

sacred trail
surreal nexus
#

Hi everyone, I'm trying to do the 'Breaching Active Directory' Room, but I too have the problem that the room is stuck at 'Resetting'. I tried first yesterday and today, the state persists. Other Network Rooms can be started or stopped, but in 'Breaching Active Directory' the buttons are disabled. Any lead or idea?

dense cedar
surreal nexus
dense cedar
slate swanBOT
#

Gave +1 Rep to @surreal nexus

surreal nexus
#

Ah, I see. Thank you very much for your time

dense cedar
#

Sent through, will let you know if I get any feedback

surreal nexus
surreal nexus
slate swanBOT
#

Gave +1 Rep to @dense cedar

prisma thorn
neon swan
#

Hello, what does "2 days of access left " on the top left of the room mean? Do I have to finish this room in 2 days and after it will be gone forever for me?

dense cedar
neon swan
slate swanBOT
#

Gave +1 Rep to @dense cedar

worthy escarp
#

Anyone having issues getting the printer to sent LDAP requests out to either the DC or our rogue LDAP service?

neon swan
#

worked for me without problems two days ago.

next dragon
#

Hi, I'm getting 404's for all the files on the pxeboot.za.tryhackme.com webserver. anyone else getting this or had this issue?

#

Nvm. Just realized I only need the name of the file at this point.

#

I think something is wrong, actually. I run the command to tftp the file from ssh on THMJMP1, and i get a connection error. However, I can ping the THMMDT server.

#

Looks like the files were regenerating. I was successful with a new filename.

stable elbow
#

Hey team, having trouble connecting to THMDC (10.200.89.101) and IIS (10.200.89.201) - successfully connected to THM via OpenVPN on my mac and can ping 10.10.10.10, however, can't seem to access the IPs given above.

Also - any tips on setting up DNS entries on Mac? Have done some looking online and tried both changed DNS settings in System Preferences > Network > Advanced > DNS and manually entering the THMDC's IP as well as editing the /private/etc/hosts file however nslookup thmdc.za.tryhackme.com still gives me ** server can't find thmdc.za.tryhackme.com: NXDOMAIN Any help appreciated. Cheers

neon swan
#

Do you use the special breaching-ad VPN co.fig?

#

Also, nslookup does not use the /etc/hosts but does a real DNS query. Try ping instead.

stable elbow
#

Ah yes I think that was the issue - I must have breezed over the line regarding the newly generated breaching-ad config file and was just using my old one. Thanks for the help @neon swan

slate swanBOT
#

Gave +1 Rep to @neon swan

flat osprey
#

Before I was facing issue in setting DNS but atleast connected with breachad network. Now once i execute the thm-troubleshoot script as mentioned in previous issues here now I can't even connect with vpn. I tried generating new vpn file and can not even connect with that.

prisma thorn
#

There is a suggestion for Kali VM to set up alternative DNS with Advanced Network Settings. However this doesn't work for me. Can anyone please confirm if it works for them, since I'd like to know if its VBOX-Kali issue or I'm doing smthn wrong here (tried to set up fallback DNS for both interfaces (vpn and local eth0)), as well as forcing dig to use eth0 assigned IP (vbox NAT network in 10.0.2.0/24 range) with @8.8.8.8 (connection do DC and DC DNS works fine). THNX

oh, and ping -I eth0 8.8.8.8 works fine

marble marlin
#

#breaching-ad Running the Attack box, on task 5 when running either
sudo responder -I tun0
or
sudo responder -I tun1

I get the following error:
[!] Error: tun0: Interface not found
[!] Error: tun1: Interface not found

I have terminated the machine and as of this moment it is on 3/5 for reset

Is anyone aware of any clues, suggestions or advice on how to get responder running?

marble marlin
marble marlin
sage quarry
#

Hi everyone! My instance of the network had some issues during boot, I cannot resolve names so it must be something on the DC, I would like to terminate it and boot it again but I'm alone and it needs 5 votes... (DC ip: 10.200.24.101) My ip is on 10.50.22.X subnet

sage quarry
sage quarry
glossy dagger
#

I'm unable to do anything with this network anymore as well. It was initially working for me for a short period of time, but then it completely stopped. I reset my attackbox, which returned no resolution. I waited for the network time to timeout, then restarted the network, and still am getting nothing.

#

Whenever I try and do an nslookup thmdc.za.tryhackme.com command, I get "connection timed out; no servers could be reached"

hasty osprey
#

Hello everybody. I have a problem in task 6 when I try to download the PXE boot image in tftp. it results always "Connect request failed" . Do you have an issue for that?

serene vault
#

Hello everyone, I have a problem with the DNS on that box - https://tryhackme.com/room/breachingad

  • I use openvpn to connect to the network. The OpenVPN Access Details page tell me all is OK.
  • I check my IP adress with ip a command. I have the same adress on the network than on the OpenVPN Access Details.
  • I change my /etc/resolv.conf like this:
    search za.tryhackme.com
    nameserver 10.200.4.101
    (NB: it was impossible for me to do systemd-resolve --interface breachad --set-dns $THMDCIP --set-domain za.tryhackme.com)
  • For the task 3, it is impossible to reach http://ntlmauth.za.tryhackme.com/ (with firefox or with ping) and I don't understand why because 10.200.4.101 should be the new DNS server and give me the IP of http://ntlmauth.za.tryhackme.com/

Thank you for your help!

proud bridge
# serene vault Hello everyone, I have a problem with the DNS on that box - https://tryhackme.co...

Hey It happened to me yesterday, I close all my VPN connection, than I retrieved a new openVPN conf file for basic THM network, I got connected, I then retrieved a new breachingad openVPN connection and get connected too, I have 2 new interfaces tun0 and breachingad. I have changed the /etc/resolv.conf and put the ip of the DNS server and it works. Do not restart the networking.service unless it will erase you resolv.conf file

serene vault
slate swanBOT
#

Gave +1 Rep to @proud bridge

proud bridge
serene vault
serene vault
proud bridge
#

When you do a nslookup Google.com what dns server answers you ?

serene vault
proud bridge
#

Let’s talk in private message

worthy mountain
#

Hey guys,
I'm trying to run the password spraying script but apparently I'm missing the requests_ntlm module. I tried installing it using pip but it tells me that the module exists already. Any idea how to fix this? Thanks!

worthy mountain
slate swanBOT
#

Gave +1 Rep to @neon swan

neon swan
dense cedar
fast prism
#

Hi

#

How r u fucking uppppp

cosmic kite
#

are you ok?

keen crag
#

Guys can anyone help me in understanding this network ? I got some questions, that need to be answered, anyone interested please dm

signal trail
#

Anyone find a fix for this? Running into same issue ...

signal trail
sacred tinsel
#

HI .. I have started room https://tryhackme.com/room/breachingad Question is : -

What is the username of the third valid credential pair found by the password spraying script?
When I am trying to reach http://ntlmauth.za.tryhackme.com/ through browser , it is not working. I guess DNS is not been configured properly. Tried mentioned way but not working , please help

neon swan
#

Are you using the special breaching-ad VPN? Can you access the dns server and manually resolve the domain?

sacred tinsel
slate swanBOT
#

Gave +1 Rep to @wooden minnow

opaque marsh
plain onyx
opaque marsh
wooden minnow
opaque marsh
# wooden minnow Is `10.200.49.101` their subnet?

no the subnet is another thing πŸ™‚ it tells you the network address. it would most often be (for home networks) 255.255.255.0
10.200.49.101 was the IP address for the DNS server running while I did the room πŸ™‚
Yours would probably be something like 10.200.xx.101
Where xx is some two-dedgit number

wooden minnow
opaque marsh
wooden minnow
wooden minnow
#

Mine is 20.

opaque marsh
wooden minnow
#

So I'm asking you if you know their subnet is 49.

Otherwise it won't work.

#

nslookup thmdc.za.tryhackme.com is the command they would need.

opaque marsh
wooden minnow
#

THM does have multiple instances running.

#

Just like wreath/holo/throwback

opaque marsh
wooden minnow
#

My point it, you're telling someone to look for a subnet they might not even be in.

opaque marsh
wooden minnow
opaque marsh
# wooden minnow But they might not, is all I'm saying.

Ah, I agree! But you are doing a AD enumerating and breaching. So, I'm guessing you knew a bit above average πŸ™‚
But, yea, maybe I should have stated that in the initial message. Anyways, I hope you get it to work! πŸ™‚

wooden minnow
opaque marsh
waxen bison
#

Is anyone else having an issue with task 5 not sending ANYTHING SMB related? Nothing. Been waiting and checking for the past 2 hours

#

I verified that LDAP works just fine through Responder. Just nothing SMB traffic being sent on the network.

opaque marsh
waxen bison
#

I was using my own Kali. No SMB connections established in 3+ hours. Sent the test connection through LDAP for the printer while using Responder just to verify that Responder could receive anything. And it could. I scanned the server it was supposed to be coming from and it had SMB open so I tried enumerating it and it wouldn't let me (not sure if no shares were created or not). Essentially, whatever script they had set up to push an SMB filecopy/transfer or whatever was absolutely not working. At least on the .28 network machine.

opaque marsh
upper wyvern
waxen bison
#

Can you ping the IP?

upper wyvern
#

resolved, 10x

astral yarrow
#

I’m having problems with Task 5the breaching ad ovpn doesn’t give me a tun0 or tun1 interface for responder to use

dense cedar
astral yarrow
slate swanBOT
#

Gave +1 Rep to @dense cedar

spring haven
#

i am with the same problem

normal needle
#

Anybody having trouble with the creds for ntlm auth?

#

Was hoping to test the script a bit more. Is there an actual lockout set up?

wind chasm
torn siren
#

3rd network room ive tried today and all im having is problems

ancient arch
#

my kali machine is not resolving thmdc dns ip

#

even with

#

/etc/resolv.conf

#

or with network manager

#

i'am using automatic dhcp in n-manager gui

#

and after restarting the network manager when i re check the dns in additional dns servers i find it empty

#

weird

#

even with /etc/resolv.conf when excuting [sudo systemctl restart NetworkManager] and [sudo systemctl restart networking.service] the resolv.conf file restore my default configuration and deletes anything new

#

any urgent help

ancient arch
#

😦

#

when in root shell

#

i run this command to get the network manager gui as root

#

nm-connection-editor

#

so i get this output

#

text too long .. can't upload picture

#

FIXED !!

prisma thorn
#

for me the resolve doesnΒ΄t work either

orchid kindle
#

I'm stuck on this as well since the cmd to set the dns server for the breachad interface cant be implemented with systemd-resolve in my personal kali attack box. I tried to get the equivelant resolvectl cmd together but I just get various errors despite the format of my cmd being shaped like the help seems ot suggest...

orchid kindle
#

alright - I got it by adding nameserver $THMDCIP above nameserver 1.1.1.1 in my /etc/resolv.conf file

orchid kindle
#

welp... i take that back it immediately stopped working as it switched nameservers when it couldnt get to the internet thru thm's ip... edit: actually the resolv.conf file was overwritten?

daring copper
#

Hi, I am another person having issues with task 5. Namely, no authentication request comes in. I have tried running responder on both tun0 (which FYI does not show up every time on the Attackbox) and breachad, nothing comes in. I did get what looked like a SQL server connection attempt from a Chinese cloud IP at one point...but no room task request.

FWIW I am also getting "Error starting TCP server on port 80..." on the Attackbox when using the preinstalled version of responder. Three errors like that for 80/3389/389.

drowsy schooner
#

Hey I am doing Task6 from the "Breaching AD" room. The problem is that when i try to GET the pxeboot .bcd file from the thmmdt machine I receive a "Connect request failed", I am not exactly sure why that could be. Can somebody give me any tips.

wispy tulip
#

what is the role of pxeboot.za.tryhackme.com other than listing BCD files? is there any? if not cant we just do the same thing in THMMDT

wispy tulip
daring copper
#

(both meaning the tunx interface that was present w/ ip a, and also breachad

wispy tulip
#

I just did it again it worked for me

#

Wait ll dm you see and if we could do this right this time

#

If its ok with you

daring copper
#

I'll start up the room again, bbiab, thanks for the offer

drowsy schooner
#

I've tried the command without the quotations too

#

I've connected to the dns and to the domain and I can ping the device

wispy tulip
#

can you paste the nslookup thmmdt.za.tryhackme.com output

drowsy schooner
#
└─$ nslookup thmmdt.za.tryhackme.com
Server:        127.0.0.53
Address:    127.0.0.53#53

Non-authoritative answer:
Name:    thmmdt.za.tryhackme.com
Address: 10.200.27.202

daring copper
daring copper
#

also every single time I run responder from the AttackBox it does this

wispy tulip
daring copper
wispy tulip
#

Can you post the responder and ifconfig output

daring copper
#

I should clarify, on the VM I no longer received the above errors like in the screenshot, but even after pinging the DC, other hosts on the network to verify connectivity, no messages EVER came into responder

#

I appreciate your help but I am done with this room, I've wasted enough time on it.

#

far too much

wispy tulip
#

Just try one last time

#

Dont give up

daring copper
#

Respectfully, no! I have wasted hours on this room that I could have spent learning other things and I'm sure I will have another opportunity to use responder in due time. Thanks for your time tho

wispy tulip
#

Delete and install responder

brittle turtle
#

Anyone have any good resources for learning pentesting AD running on samba?

warm sparrow
#

Hi all. I’m finishing off the configuration files task, specifically transferring the file ma.db to my attack box (in browser). I keep getting the following error. Any ideas?

warm sparrow
# daring copper also every single time I run responder from the AttackBox it does this

My terminal showed the exact same message. As N S mentioned, the ports are in use. No need to use another VM. The job runs every 30 mins. Just need to leave responder running but make sure that you are listening on the breachad interface.

Alternatively, if you have had the attack box running for nearly 3 hours, DNS could have been reset. This is mentioned on the first page (IIRC). Restart the systemd-resolved service.

warm sparrow
#

Finally found the problem (me!). I should be running the SCP transfer command from a terminal on my attacking box and not running the command from the thmjmp1 server. It is a pull not a push!

daring copper
desert spire
#

For Task 4, LDAP Bind Credentials, I'm using the AttackBox. I have the olcSaslSecProps.ldif set as instructed. However, when I execute ldapmodify -Y EXTERNAL -H ldapi:// -f ./olcSaslSecProps.ldif && service slapd restart, I receive an error "ldapmodify: wrong attributeType at line 3, entry "cn=config"

#

any thoughts how to get past this? Nothing turned up in the searching I've been performing thus far in Discord here

dense cedar
thin knoll
#

having issues with the DNS and IP for breaching AD anyone shed some light on how to successfully get the dns to register?

wicked sorrel
#

hello, could you tell me why does this network say "2 days of access left" - does it mean it will be retired after that time? i am subscribed

tough cypress
neon swan
wicked sorrel
#

makes sense, thank you

normal cave
#

Hi, Im on the https://tryhackme.com/room/breachingad room, task 5. First task using responder.
Im using my own kali attack machine.

Are you supposed to only use the AD VPN or are you also supposed to have the "regular" VPN" ON?

I tried ''sudo responder -I tun0'' but I received a "interface not found",.
I tried "sudo responder -I breachad" but no events.
Tried to put on my normal VPN for THM then I got a tun0 when doing "ip a" but when starting responder with this tun0 I had no events either.

wicked sorrel
#

i think the traffic over vpn is simulated and runs once every 30 minutes @normal cave

normal cave
wicked sorrel
#

the breachad i believe

normal cave
wicked sorrel
#

yes, but I was using the attackbox

normal cave
#

Ah

wicked sorrel
#

the thing is the attacks work in local network and wouldn't work over vpn in a real scenario, so it's simulated for the purpose of the exercise

#

so i guess you just need to wait a bit

normal cave
#

Hmm, okey, ill just leave it on, but dunno feels fishy.

wicked sorrel
#

yeah but unfortunately to exploit this you would have to put a jumphost in the LAN of the targeted hosts

#

during pentests the client usually gets a physical box like intel nuc to plug into the starting network

#

so it can be accessed remotely by the team but also has a local interface within the LAN

normal cave
#

Yeah, deffo interesting!

Suddently it worked. I had RDP running on port 3389 interfering with the responder, I killed it and now I got a hash. Dunno if that was the issue or I was just real unlucky with the timing of the server.

Anyways, works now, ty!

wicked sorrel
#

good, no problem

tough cypress
empty crane
#

not sure if youve done that

#

on both attackbox and personal VM

#

I did breaching AD and another one yesterday it was fine for me

tough cypress
tough cypress
#

Don't think i've ever done that for a room before

empty crane
#

I have to leave for the gym in 5 minutes so i cant give you instructions right now but the Room your doing should tell you how to configure them

#

in short for personal VM you have to do it in either the network manager or the file i cant remember correctly

#

for attackbox its relatively simple afaik but i usually use my vm

tough cypress
#

nvm I got it

#

thanks!

ebon cloud
#

In Task 4, everything is working, roque ldap is configured and running. I use tcpdump, start the traffic and then.....
It tells me: 'user no t found'
why? I just left it like it is, what is wrong here?

#

oh, and i don't get any password

ebon cloud
#

oh, nevermind. I restarted all and now it works

patent sapphire
#

i cant figure out for the life of me even following the guide i get lost at Set your DNS IP here to the IP for THMDC in the network diagram above"

patent sapphire
patent sapphire
#

I've never had a room give me more problems than this one. just pure configuration.

gray trench
#

How to stop netcat on a specific port?

brittle turtle
#

Having some trouble just running nslookup thmdc.za.tryhackme.com to see if I'm connected. I'm on a kali box but no luck even after connecting with openvpn to the network

sage epoch
brittle turtle
sage epoch
brittle turtle
quasi cedar
#

There should be instructions on what ip to add to the dns settings

#

When I did it I did ip,1.1.1.1 so I was still able to reach google

brittle turtle
quasi cedar
#

Yes the ip you put is in the instructions on setting it up

#

The ip,1.1.1.1 is what I put in dns and it worked

sage epoch
#

this will be your primary DNS while in this room

brittle turtle
slate swanBOT
#

Gave +1 Rep to @sage epoch

safe magnet
safe magnet
patent sapphire
upbeat heart
#

I'm having a problem with setting up the dns actually

#

The steps are outdated to the current version of kali

prisma thorn
#

Also having problems with Task4 capturing the password, I trashed my ParrotOS trying to get slapd working and ended up setting up an Ubuntu box and re-running the setup, I seem to be able to Add the config however the ldapsearch query returns extra mechanisms and I cant seem to remove them
dn:
supportedSASLMechanisms: GSS-SPNEGO
supportedSASLMechanisms: GSSAPI
supportedSASLMechanisms: GS2-KRB5
supportedSASLMechanisms: GS2-IAKERB
supportedSASLMechanisms: PLAIN
supportedSASLMechanisms: LOGIN

The Capture shows it using the GSS-SPNEGO, so I expect its using top down, I've spent all yesterday and today trying to purge these but it seems that ldap doesnt like being too open.
Can anyone advise on how to purge this list and retain only plain and login

prisma thorn
#

thanks this came in super useful after a long day

#

Thanks, this came in super useful after a long day

slate swanBOT
#

Gave +1 Rep to @near salmon

sage knot
#

Hey, I am doing task 3 where we are supposed to access a site and then password spray it, but the site won't resolve even though I setup the dns and a nslookup works perfectly fine. Anyone know what might be the issue? Here is my resolv.conf file (the top name server being the AD DC)

#

Ah I am dumb, I got it working like this. I swear every time I post a question here I figure it out on my own like 2 seconds later

quasi cedar
quasi cedar
#

With kali network manager

amber grove
amber grove
brittle turtle
#

Go into your Ethernet settings through the GUI and set an additional DNS as the main AD ip

#

It will be under the ipv4 tab

amber grove
brittle turtle
#

Are you first connected through openvpn to the AD network?

amber grove
brittle turtle
#

I think they are just having network issues, was just working on a box, but gave up since I started to get randomly disconnected

pseudo granite
#

I can't seem to setup DNS correctly on my machine with resolvectl.. any help on doing it with resolvectl instead of systemd-resolve?

pseudo granite
#

Alright seems like hosts works fine for that..

ancient laurel
#

Hi, I am struggling with the PXE section "Microsoft Deployment Toolkit" I am attempting to retrieve the PXE image from the server via TFTP with no luck. The command I am running is: "tftp -i 10.200.54.202 GET "\Tmp\x64{9D0F3471-D2FB-475F-B263-2FE41D80E254}.bcd" conf.bcd" Nearly identical to the command shown in the instructions. am I missing something dumb?

#

The response is Connect request failed.

#

NMAP scan shows TFTP is closed, and well TFTP is acting like it isn't even on that host. I am very stuck.

ancient laurel
rotund bluff
steel temple
#

Hellow, I was wondering, is it advisable to use kerbrute to ennumerate active directory users ? (just to ennumerate users, not to bruteforce their passwords)

#

Wouldn't it be detectable easily ?

sage epoch
dense cedar
#

Debugging your initial connection to the network.

As mentioned when the networks released, DNS is a part of AD testing whether you like it or not. This is because one of the two major AD authentication protocols, Keberos, relies on DNS to create tickets. Tickets cannot be associated with IPs, so DNS is a must.

If you are going to test AD networks on security assessment, you will have to equip yourself with the skills required to solve DNS. You therefore have two options:

  • Hardcode entries in your /etc/hosts file - Works great, but on a network of 10000 hosts probably not the way to go
  • Actually fix your DNS to point to the name servers in the network - Harder to do, but in the long run yields good results

Whenever a task is not working for you, your first thought should be: "Is my DNS working?" I've personally wasted countless hours on assessments wondering why my tooling is not working, only to realise my DNS has changed. 99% of the time, it's DNS.

How to connect your DNS to the THM AD network:

  1. Follow the steps provided in the initial task on DNS configuration - If you use a different OS that AttackBox or Kali, you are probably going to have to google your equivalent configuration
  2. Run ping <THM DC IP> - This will verify that the network is actually live. If you get no response, chances are your network is not started or in the "bricked mode" (see below) state
  3. Run nslookup tryhackme.com <THM DC IP> - This will verify that the THM Name server is active. If the PING worked but this does not, time to contact support here since something is wrong. I'd also suggest hitting the network reset button
  4. Run nslookup tryhackme.com - If the first nslookup command worked, but this second one does not, you did something wrong with your DNS configuration and need to go back to step 1.

These AD networks are rated medium, which means if you just joined THM, this is probably not where you should start your learning journey. AD is massive, and you will need to apply the mindset of "figuring stuff out" if you want to make a success of testing it. However, if above all it still fails for you, please be as descriptive on what your are trying and doing to enable support to help you as efficiently as possible.

dense cedar
#

Network Bricked Mode state

If you are unable to ping the DC, but the network on your network diagram shows that the network is started, your network has probably entered the "bricked state"

What has happened?

One of the users in your network subnet clicked on the UI "Extend" button when the network timer reached zero. This causes a bug where the backend thinks that they network is still live, but in fact it is not.

What can you do?

The best thing to do is to wait until the network time expires, then press the "Start" button again. However, you can also attempt a bypass, which does sometimes work:

  1. Refresh your network THM room page
  2. Right click on the Start button and say inspect element
  3. Remove the disabled state from the HTML button
  4. Click the Start button

In certain cases, this can help to resync the backend, so give it 5 minutes to see if that worked for you. Otherwise, we are back to square one about waiting for the network time to expire.

stuck portal
#

I have problems reaching the DC. Able to ping it but can’t perform nslookups… have y’all ran into the same issue?

#

Must I be on the jumphost in order to perform DNS lookup?

stuck portal
knotty tundra
#

I just reset BreachingAD but i can't ping from the attackbox and from the VPN. I tried 4 times at different times but i can't ping THMDC

dense cedar
craggy comet
#

Hi there! The password spraying script is (for me) only working with python 3.9, not 3.10 - why is that? I am using a Kali Linux VM

python3 ntlm_passwordspray.py -u usernames.txt -f za.tryhackme.com -p Changeme123 -a http://ntlmauth.za.tryhackme.com
[*] Starting passwords spray attack using the following password: Changeme123
Traceback (most recent call last):
File "/usr/lib/python3.10/hashlib.py", line 160, in __hash_new
return _hashlib.new(name, data, **kwargs)
ValueError: [digital envelope routines] unsupported

craggy comet
#

In Task5 Authentication Relays when I try to crack the password with hashcat, I get nothing back - I put the whole hash in a file with username, etc. - otherwise hashcat doesn't recognise it as a hash
|| svcFileCopy::ZA:71f1c9c54e6aa27d:E31CCD3F0F070B83149D986555EDBB23:01010000000000008000E2F1CC3AD901C3958C5A348B233A0000000002000800550030004F00350001001E00570049004E002D0037004C0049004300490059004500440033005900530004003400570049004E002D0037004C004900430049005900450044003300590053002E00550030004F0035002E004C004F00430041004C0003001400550030004F0035002E004C004F00430041004C0005001400550030004F0035002E004C004F00430041004C00070008008000E2F1CC3AD901060004000200000008003000300000000000000000000000002000004549C9C6EA4B85F712870CE1BA887CFD5410A6D1A9390E4C7F186AAF0236E6670A0010000000000000000000000000000000000009001E0063006900660073002F00310030002E00350030002E0032002E00320037000000000000000000 ||

command: hashcat.exe -m 5600 hash.txt passwordlist.txt --force

Any ideas what is going wrong?

dense cedar
dense cedar
craggy comet
#

Alright, thank you very much πŸ™‚

lyric cloud
#

Hi,
I am unable to ping/resolve the THMDC DNS Server.
This is my /etc/resolv.conf

search home za.tryhackme.com
nameserver 10.200.54.101
nameserver 192.168.81.2

options timeout:1
options attempts:2
plucky perch
#

Hi I have a question for LLMNR attack
I used responder on breachad network is that correct or I have to connent to tun0
I believe I’ve been waiting more than 30 minutes still nothing been captured

plucky perch
wispy tulip
simple copper
prisma thorn
#

I did get it done, can't recall what I did, sorry.
I might have used the Hackthebox machine

simple copper
prisma thorn
true narwhal
#

Hello

#

I've been trying to connect to the VPN of breachingad with no success, until now, that I discovered how.

#

You have to edit the openVpn file that you download from THM access' page and look for the line that says cipher AES-256-CBC and change it to --data-ciphers AES-256-CBC

#

that way, the VPN stop saying "error negotiating cipher with server"

#

you may pin my comments in this channel so that other users are able to debug it quicker than I had (1.5h... =( )

brazen raptor
#

This is my configuration on /etc/resolv.conf

charred epoch
#
sudo systemctl restart NetworkManager
brazen raptor
charred epoch
brazen raptor
charred epoch
#

it worked for me

brazen raptor
#

It's working now. Thanks @charred epoch

slate swanBOT
#

Gave +1 Rep to @charred epoch

brazen raptor
charred epoch
dense compass
#

sudo ldapmodify -Y EXTERNAL -H ldapi:/// -f ./olcPlainAuthOnly.ldif
SASL/EXTERNAL authentication started
ldap_sasl_interactive_bind: Authentication method not supported (7)
additional info: SASL(-4): no mechanism available: security flags do not match required

#

Can somebody please help me?
Why I am getting this error when I change conf.

faint cypress
#

Hey guys. In breaching-ad page, under "Created by am03bam4n" , it shows 3 days of access left. What does this mean ? I just started subscription yesterday.

frail skiff
slate swanBOT
#

Gave +1 Rep to @frail skiff

carmine laurel
#

Great room, thanks to creators πŸ™‚

brave marsh
#

in the breaching-ad room I got stuck at task 5, when they said there is a server in the domain that performs NTLMv2 authentication every 30 minutes... they let you set up responder with the command: responder -I breachad... but then the NTLMv2 authentication doesnt get captured... Can someone help me please I even tried to follow instructions on other blogs that completed the module but I without any luck...

#

if I do ss -tulpn I can see port 1433 open... that should be the good one for that kind of authentication...

#

@dense cedar

#

Nothing happens if I try to get responder work on attack box... Plus, If I use wireshark I can tell that there are no NTLMv2 protocol going on or LDAP protocols going on, and i tried it for ages...

#

once i set sudo responder -I breachad ... i should be just waiting for the server authentication with NTLMv2 daemon to run right?

brave marsh
#

this is my /etc/resolv.conf:

Generated by NetworkManager

search lan za.tryhackme.com
nameserver 10.200.28.101
nameserver [HERE there is my private gateway IP]

dense cedar
dense cedar
brazen raptor
#

Can't connect with openvpn. I can't ping THMC ip.

#

I regenerated the vpn config, but the result stills the same. It doesn't show "Initialization ... completed" something like that when I tried to connect with openvpn.

#

This is before I pressed CTRL+C

trim mica
#

!vpnscript

outer timberBOT
brazen raptor
#

I am going to take a look at it

brazen raptor
slate swanBOT
#

Gave +1 Rep to @trim mica

trim mica
#

no problem

frail vector
#

Tried checking multiple conversations about this, but haven't been able to find a definitive answer. I'm working on Task 3 and I'm having issues with the Python script, more specifically whenever I try to run it, it throws an error saying some modules being imported are missing.. I don't have experience in Python so I wanted some guidance on what I need to do to fix the script so it works as intended. I also tried running it under Python 2 since people were saying that may have been the issue.

frail vector
plucky perch
shrewd knot
#

Can somebody confirm that the breachad hosts are running? especially the DC? I can not reach the DC/DNS through the attack box or the VPN. Also regenerated the openvpn file

wooden minnow
shrewd knot
#

Yes ..

#

The breachad network was reset some minutes ago .. now the DC is reachable again

wooden minnow
#

So you can do the room now?

shrewd knot
#

Yep πŸ‘

#

But solution was the reset

wooden minnow
#

That can often the problem.

kind leaf
#

Hi all. Can't download my vpn config because of 404 error. I tried to rejoin room, regenerate config, log out

wooden minnow
kind leaf
#

Okay i'll try

kind leaf
slate swanBOT
#

Gave +1 Rep to @wooden minnow

wooden minnow
#

Tun0 is only your main script.

#

Each network has a different interface assigned to it

kind leaf
#

Got it πŸ‘

limber grove
#

Done with Breaching! Off to Enumerating! πŸŽ‰ thanks @dense cedar

uneven pier
#

Today a network state is: resetting. And I can't click on start button. Ping is working and nslookup too bu I can't reach http://http://ntlmauth.za.tryhackme.com/

somber panther
#

Hi, how long does it usually take for the network to reset? The reset vote count is 4/5 and I can't up it to 5, and yet the Network state displays as Resetting since yesterday

lean vine
#

Can anyone access this network? It was working fine yesterday but now not working

uneven pier
#

I can't too

lean vine
#

Mind voting for a reset?

uneven pier
#

I don't know what's happend but from yesterday don't working

lean vine
#

I guess resetting the network will make it work so vote for the reset.

uneven pier
#

mee too πŸ™‚

summer mulch
#

Hey guys on the end of task 6 you will asked to delete the folder which you have created, and also you get the information that you will get an error with access denied, the next information is a script will help me to delete but where is this script?

limber grove
hot acorn
summer mulch
#

@hot acorn @limber grove roger thx

slate swanBOT
#

Gave +1 Rep to @hot acorn

somber panther
#

@uneven pier @lean vine after sending an email to support, I was moved out to a different network segment and had to rejoin the room, but it's no longer Resetting for me and now the buttons work πŸ‘

lean vine
marsh pollen
#

Not sure if this is where I need to post this, but when I try running the ntlm_passwordspray.py script for task 3, I keep getting this error

Exception: Version mismatch: this is the 'cffi' package version 1.14.2, located in '/usr/local/lib/python3.6/dist-packages/cffi/api.py'. When we import the top-level '_cffi_backend' extension module, we get version 1.11.5, located in '/usr/lib/python3/dist-packages/_cffi_backend.cpython-36m-x86_64-linux-gnu.so'. The two versions should be equal; check your installation.

Never mind, it was user error, I've got it run correctly.

slate swanBOT
#

Gave +1 Rep to @somber panther

hot prism
hushed charm
#

im having issues with this

#

it keeps loading

#

and why aint there support here?

hushed charm
#

after loading it gives me this:

limber grove
hushed charm
limber grove
#

No worries πŸ‘πŸΌ

dense cedar
# hushed charm

That IP does not look correct? Is 10.10.10.101 your IP you get on your VPN adapater?

cursive rose
cursive rose
somber ledge
#

@cursive rose Keep it English please

crude furnace
#

Hello, I am unable to connect to the breaching-ad network.

I have performed the following steps:

  1. Connected to the network
  2. Modified DNS settings - in Kali VM
  3. Restarted NetworkManager
#

How can I troubleshoot this issue?

crude furnace
#

Anybody?

wooden minnow
#

And manually add it to /etc/resolv.conf

crude furnace
wooden minnow
crude furnace
wooden minnow
#

Put the 10.200. xxx at the top.

crude furnace
#

Oh wow, that seems to have fixed the issue

#

Able to resolve now

wooden minnow
#

Happy hacking.

steady fiber
#

Hello ! This is impossible to download the vpn config file for breaching-ad network, got a 404 when attempting to download it

wooden minnow
late temple
#

I didn't see any mention of it in the search bar. But there is an updated script for https://tryhackme.com/room/breachingad Task 7 - Configuration files that uses python3 [https://github.com/funoverip/mcafee-sitelist-pwd-decryption/blob/master/mcafee_sitelist_pwd_decrypt.py]. It achieved the result of decrypting the password from the database.

odd storm
#

Hello, does anyone know if the tun0/tun1 interfaces are created automatically upon connecting to the VPN or i have to set them up myself ?

wooden minnow
#

Auto.

#

But they're not called tun0 on networks.

odd storm
wooden minnow
odd storm
#

i do have it, this is in relation to task 5, i have tried setting responder on the breachad interface but it gives a resource or device busy error

knotty tundra
#

i tried with my own kali and now it ping (before only my kali and only the attackbox didn't work)

austere torrent
#

Just wanted to give some feedback to say this room still works 100% from start to finish using AttackBox. Use AttackBox because you won't have to install anything and all necessary files are already on the machine.

knotty tundra
austere torrent
undone thunder
#

cat /etc/resolv.conf

Generated by NetworkManager

nameserver 10.200.55.101
search 1.1.1.1

rare notch
#

Hello guys! I try to start attack box in this room
I can't ping DC because I don't have breachad interface
Instead of it I have only enumad interface for another network

#

What i do wrong?

#

And after rejoin the room i dont have any interface on attack box

mellow shadow
mellow shadow
#

Hello Everyone if someone is facing a dns problem when trying to connect to the network from kali here is a quick and easy solution with resolvectl resolvectl dns breachad 10.200.27.101 1.1.1.1 2 things to note: 1 - you will need to run this every time you connect to the network, 2 - the 1.1.1.1 is a place holder for any public dns server to just have a network connection

rare notch
slate swanBOT
#

Gave +1 Rep to @mellow shadow

formal trellis
#

Hello everyone. I had problem to connect to Breached AD VPN. There is a chiper error. TryHackMe VPN works correctly.

outer timberBOT
limber grove
formal trellis
#

I used the script. Nothing. The script suggest me to contact discord for support

lilac dawn
#

Is there a way to add the network to the attack box? Has the other networks but not this one?

native hamlet
#

Hi @lilac dawn ,
edit the file Desktop/NetworkConfigs/breachad.ovpn

Change
dev breachad
to
dev tun

Then manually start openvpn with command:
openvpn Desktop/NetworkConfigs/breachad.ovpn

and change command in the room:
[thm@thm]$ systemd-resolve --interface breachad --set-dns $THMDCIP --set-domain za.tryhackme.com
to
[thm@thm]$ systemd-resolve --interface tun0 --set-dns $THMDCIP --set-domain za.tryhackme.com

native hamlet
#

Indeed is very frustrating. I established the tunnel, pinged the dc. After some minutes the DC stopped responding to ping and now I can't proceed with the room

native hamlet
#

Ok I was able to complete the room. Beware that sometimes even if page is reporting the network's up, it may be down. A page refresh would reveal it.

lilac dawn
#

Perfect thanks

rare notch
#

Guys, again problem with interface. When I join the room and start AttackBox, there are no interface breachad
I have only lo, ens and docker

slate swanBOT
#

Gave +1 Rep to @native hamlet

dense cedar
# rare notch It works. TY

Issue was found with the VPN server and has now been resolved. VPN server had to be rebooted, so connection might go down. Please regenerate your VPN file again and it will work on the AttackBox

oak estuary
#

hey guys! hope you're having a good time!

i'd like to ask for some help...
i'm trying to start 'breaching ad' room (https://tryhackme.com/room/breachingad) via the attackbox, which i've started from the room's page. so i am on the attackbox atm.

  1. my ping command against the IP of THMDC (from the network diagram) is not working

  2. also i tried the command "systemd-resolve --interface breachad --set-dns $THMDCIP --set-domain za.tryhackme.com", but i get this error: "Unknown interface breachad: No such device"

  3. i've also tried to edit the /etc/systemd/resolved.conf and add "DNS=IP of THMDC", but it doesnt help.

  4. I've noticed the recent advice above, so I've edited Desktop/NetworkConfigs/breachad.ovpn from dev breachad to dev tun, but if I then issue openvpn Desktop/NetworkConfigs/breachad.ovpn, i get this error: Options error: In [CMD-LINE]:1: Error opening configuration file: /root/Desktop/NetworkConfigs/breachad.ovpn

  5. if i run ifconfig, i've got no tun0 interface, i have ens5. if i change from dev breachad to dev ens5 in the breachad.ovpn file, i am not able to run openvpn Desktop/NetworkConfigs/breachad.ovpn -> same error: Options error: In [CMD-LINE]:1: Error opening configuration file: /root/Desktop/NetworkConfigs/breachad.ovpn

could you please give me a piece of advice how to fix this?

candid heron
#

i am still having an issue with breaching AD vpn, it keeps crashing.

wooden minnow
dense cedar
formal trellis
#

The C:\Tools Directory for Sharphound.exe doesn’t exist on the System!!!

whole cedar
#

Hello! I'm having the same issue as drops above. My "breachad" interface is not showing up as a Network interface. I've reset the Network and did the steps to "unbrick" it (inspecting the button and removing disabled), and it still not showing up. I also tried editing the breachingad.ovpn and still nothing. It seems like alot of people are having this same or similar issue. Could this be something on THM's side?

outer timberBOT
tranquil river
wooden minnow
tranquil river
limber grove
#

Regarding any VPN issue:

  1. The original VPN file says cipher AES-256-CBC near the top on line 15. That has to be changed to data-ciphers AES-256-CBC and that will work:
    https://tryhackme.com/forum/thread/62bc5fb1fcafa700618f25f0
  2. I didn't have to edit the dev breachad. However this was done on my personal Kali VM.
    I just tested this and was able to connect to the network πŸ‘
    Hope this helps!
undone knoll
#

I'm quite confused, how did we suddenly obtain SSH credentials to THMJMP1 for task 6, where did that come from?

limber grove
undone knoll
slate swanBOT
#

Gave +1 Rep to @limber grove

undone knoll
whole cedar
#

Working on Breaching AD task 4: After configuring LDAP and all that, when I press "Test Settings" on the webpage, I'm getting this error message. I've tried restarting everything twice and even redoing the LDAP config step 2-3 times. Still can't get past it

wheat jungle
#

so use sudo service slapd start and then configure it with the same command you were using

pulsar saffron
#

Hello, I'm stuck on the question:

"Consider the desk in the photo above. In addition to the smartphone, camera, and SD cards, what would be interesting for digital forensics?"

which comes from "Intro to Digital Forensics"

I tried all the words
6 letters from all over the room and none of them work... can someone help me please?

wheat jungle
#

depending on the type of "thing" that it is, in english it has a different name

hollow dagger
#

can't really access webpage after running system-resolve.. command mentioned in the task 1.

hollow dagger
wooden minnow
hollow dagger
wooden minnow
#

192?

hollow dagger
wooden minnow
#

Show me your breachingVPN output please.

hollow dagger
hollow dagger
wooden minnow
hollow dagger
wooden minnow
#

What's your THMDC?

hollow dagger
wooden minnow
#

Now

sudo nano /etc/resolv.conf

hollow dagger
#

then?

#

do I have to put THMDC IP in nameserver?

wooden minnow
#

Yes.

Put the up at the very top.

hollow dagger
slate swanBOT
#

Gave +1 Rep to @wooden minnow

wooden minnow
hollow dagger
#

no I didnt

trim mica
#

the second line should be nameserver 192.1687.42.129

#

and the third line should be the 127 one

wooden minnow
#

^

hollow dagger
#

Done

hollow dagger
plucky walrus
#

operation for /etc/resolv.conf.

nameserver 10.200.92.101
nameserver 127.0.0.53
options edns0 trust-ad
search za.tryhackme.com
search 1.1.1.1