#enumerating-ad

1 messages Β· Page 2 of 1

ebon adder
#

!docs verify

runic hornetBOT
late maple
#

ohh okay let me verify , i though i was already verified

ebon adder
late maple
#

okay doing it rightaway

#

I am getting this

#

when trying to connect to VPN and on access tab old VPN IP is shown already connected

ebon adder
late maple
#

nope

ebon adder
ebon adder
# late maple nope

Quickly send me a screenshot of your network diagram in the room so I can confirm subnets there?

late maple
#

okay just a sec

calm lotus
#

That's looking like the openvpn 2.6 issue

ebon adder
ebon adder
late maple
late maple
#

which shows already connected

ebon adder
late maple
#

strange had no issue untill the update && upgrade 8-12 hr before

#

okay will try to search what solution i get

#

thank you

ebon adder
late maple
#

okay will try that thank you

calm lotus
late maple
#

thats helpfull , thanks

late maple
unreal graniteBOT
#

Gave +1 Rep to @calm lotus

calm lotus
#
  • @ebon adder Some recognition for you too πŸ˜„
unreal graniteBOT
#

Gave +1 Rep to @ebon adder

shy wren
#

@shrewd roost You know if this is something they can change on THM's end?

ebon adder
shy wren
#

I mean you'd hope it'll use the strongest mutually supported cipher right?

shrewd roost
#

Good morning

shrewd roost
#

So

shy wren
#

Neat

#

Always fun...

shrewd roost
#

We either break 2.5.x to fix 2.6

#

Or keep 2.6 broken so that a lot of 2.5’s and 2.4’s can work

shy wren
#

Drop the ciphers line entirely and let it negotiate?

shrewd roost
#

possibly Β―_(ツ)_/Β―

#

We’re looking at updating the ciphers on the servers

shy wren
#

Neat, glad you're all aware, thanks @shrewd roost

unreal graniteBOT
#

Gave +1 Rep to @shrewd roost

shrewd roost
#

Indeed (:

#

It just sucks that 2.6 is in the release for kali apt KEKW

#

Cause it isn’t anywhere else

fickle glade
#

Hi, anyone knows what to put in the name server switch (-ns) for bloodhound-python?
Example:
bloodhound-python -c ALL,LoggedOn -u 't-skid' -p 'tj072889*' -d vulnnet-rst.local -ns <name server>

ebon adder
fickle glade
flint hare
#

Hello, I've tried to download the Vpn but get a 404 error and a darth vader head, please could you help

flint hare
#

hey @gusty inlet tried that already yesterday

gusty inlet
#

Can you try it again now?

flint hare
#

@gusty inlet yeah all good now, thank you

unreal graniteBOT
#

Gave +1 Rep to @gusty inlet

gusty inlet
#

You're welcome

flint hare
#

@gusty inlet πŸ‘

flint hare
#

Okay might be failing at first hurdle and doing something stupid but can't get DNS to resolve

#

can ping the DC and have entered the DNS into my kali box

shy wren
#

Can you query against it manually?

gusty inlet
flint hare
#

yeah

gusty inlet
#

Can you ping the ip?

flint hare
#

yes can ping the ip

gusty inlet
#

Where did you write the dns settings?

flint hare
#

Additional DNS servers and the method set to Automatic DHCP for IP

#

Advance network configuration, don't have network manager

gusty inlet
#

try edit /etc/systemd/resolved.conf instead

flint hare
#

yeah tried that first didn't work and restarted

gusty inlet
#

can you verify and send some screenshots of what you have

#

!docs verify

runic hornetBOT
flint hare
#

trying but keep getting can't msg

#

Your message could not be delivered. This is usually because you don't share a server with the recipient or the recipient is only accepting direct messages from friends. You can see the full list of reasons here

ebon adder
gusty inlet
#

make sure this one is green

flint hare
#

@ebon adder yeah i can see the name server on the second line above it is a local name server, want me to hash that out for now

ebon adder
flint hare
#

@gusty inlet sorry not really up on discord, hardly use.

gusty inlet
#

no worries, right click the server icon and press privacy settings

flint hare
#

@ebon adder perfect, thank you

unreal graniteBOT
#

Gave +1 Rep to @ebon adder

ebon adder
flint hare
#

@gusty inlet I'll sort verify now

#

Yes i have that on laready when just checked

#

I'm up and running if what i need to do room, is there support for this somewhere so not taking up the channel with this

gusty inlet
flint hare
#

@gusty inlet Thanks as always

severe wave
#

Hi all. In the Bloodhound task, I'm having the Bad JSON file error when importing the generated zip file using my own machine and Attackbox. I'm thinking this is a compatibility issue as I've encountered this before when I used a wrong version of SharpHound.ps1, but it should have worked this time with the SharpHound.exe on the jump host, right?

ebon adder
severe wave
#

oh i got it now. i just ran it with "-ep bypass"

ebon adder
jagged swift
#

Are we supposed to find the plain text password for t1_henry.miller user? I have escalate my privileges on thmjmp1 and tried to dump the password as explained here (https://bloodhound.readthedocs.io/en/latest/data-analysis/edges.html#id4), but i am only seeing the NTLM hash for t1_henry.miller user and not the plain text password? Tried with PTH of t1_henry.miller but didn't work.

ebon adder
jagged swift
#

ok, thank you!

rugged nebula
#

Hello..Why not nothing found on diagram ??? I started machine & still nothing found( sorry for my english).. Please someone help me ... thanks you ...

silk zinc
#

Hey ! Network with DC 10.200.67.101 is acting weird , it was really slow 30 mins ago. I had issue with my VPN so I regenerated a new .ovpn file and now I can't even nslookup the DC anymore, can someone tell me if the network died or anything ? blobheart

rugged nebula
#

still black screen.

ebon adder
ebon adder
silk zinc
#

And I still have the same configuration than yesterday when it was working fine

ebon adder
ebon adder
# silk zinc

It might be the network brick that was discussed in #lateral-movement-and-pivoting .

Can you inspect element to re-enable the Start button and press it? We have a frontend issue where if the network sleeps and you press extend it extends the timer without actually starting the network. Give it 10 minutes and then see if the network comes back alive?

silk zinc
unreal graniteBOT
#

Gave +1 Rep to @ebon adder

silk zinc
#

@ebon adder Ok it works fine now, not sure if that was the issue or not, because it looked like I had 2 VPN connections to the network at the same time (dunno why). I reboot my kali and now I can ping the DC. Anyway, thanks for your help !

unreal graniteBOT
#

Gave +1 Rep to @ebon adder

silk zinc
#

Great rooms btw !

light leaf
#

in Remmina what is the difference between server and domain? I keep getting server not found but the network is running

#

trying to RDP in

#

it says in the task "Remember to specify the domain of za.tryhackme.com when connecting" so I got that but nothing is working for Server

#

oh hang on now ssh isn't working, maybe I have same issue as above πŸ€¦β€β™‚οΈ

#

omg it's always the simple things, I'm fine now haha

charred ledge
#

Hello,
I'm doing this room ( https://tryhackme.com/room/postexploit ) and having some issues here.

From the cmd i run powershell -ep bypass as instructed and then i try to run PowerView.ps1 which ends instantly without any error. To my understanding, this should enable me with a serie of additional commands for enumeration but these are not working so i assume PowerView did not run correclty. But I'm not doing anything outside the normal. Any ideas?

violet panther
#

. .\PowerView.ps1

violet panther
charred ledge
violet panther
#

first dot is probably meaning to import it into here the second dot is for the path of the file

#

not sure exactly though

charred ledge
#

hmm never heard of that usage. But anyway, thanks !

ebon adder
# charred ledge hmm never heard of that usage. But anyway, thanks !

If you just run .\PowerView.ps1 it executes the PowerView script which does nothing. Since there is nothing in main and everything is written as functions.

You need to run Import-Module .\PowerView.ps1 which would import all the functions in the ps1 script for you to use, including Get-NetUser. . .\PowerView.ps1 is the shorthand for Import-Module.

Hope that helps πŸ™‚

#

Also the second . means the current folder.

If you do ls -al on linux, you would see a directory called . and one called ... . refers to the current working directory and .. refers to the parent directory. That's why cd .. takes you up a directory. Same with windows, . means current directory so .\PowerView.ps1 mean in the current directory, look for the script

#

So many dots πŸ˜‚

violet panther
unreal graniteBOT
#

Gave +1 Rep to @ebon adder

charred ledge
#

after i break i come to this and having new issue that im stuck already..

I've been running the bloodhound command:
Invoke-Bloodhound -CollectionMethod All -Domain CONTROLLER.local -ZipFileName loot.zip

That seems to work but at the end when it 'completes' and says Happy Graphing.. it stays like doing something and never ending the process. Earlier i stopped it and dropped the zip in bloodhound but it fails. 'BAD JSON' among other errors

ebon adder
#

CONTROLLER.LOCAL is not the correct domain to use. Also, if you have import errors, chances are it is your version of Bloodhound that needs to be updated.

unreal graniteBOT
#

Gave +1 Rep to @ebon adder

charred ledge
charred ledge
#

But anyway it was good the controller.local i believe

ebon adder
#

It does not seem like you are doing the Enumerating AD room. Since that is not our DC. For more general support, I recommend #site-support

coral quartz
#

Hey @ebon adder just got done with this room and it was very informative thanks! Noticed a quick typo in the MMC instructions, it says to right click but I think you mean left click? Right-click on Active Directory Users and Computers in the left-hand pane Click on View -> Advanced Features

unreal graniteBOT
#

Gave +1 Rep to @ebon adder

ebon adder
#

Second way which is left click πŸ™‚

#

Both ways work πŸ™‚

coral quartz
# ebon adder Both ways work πŸ™‚

Oh woops. I didn't notice that hah. Sorry! In the powershell enumeration you specify the domain. Is this just good habit in case you're in multiple? As the command was working without.

ebon adder
# coral quartz Oh woops. I didn't notice that hah. Sorry! In the powershell enumeration you spe...

No worries! So to specify the domain serves two purposes:

  • If you do an actual assessment against an organisation, almost all of them will have multiple domains. You might have creds for za.tryhackme.loc, but you want to enumerate uk.tryhackme.loc, since there is domain trust between those two, you can actually do this. By specifying the domain, you are deliberate in what domain you are enumerating, meaning you don't confuse yourself.
  • Often on an assessment your "testing windows system" will not actually be domain joined. For example, they gave you AD creds and a VPN file. In these cases, you need to deliberately specify the domain so the powershell cmdlet knows you are talking to the client's domain, and not your local WORKGROUP domain.

Hope that explains its use cases! Even if for this room you could skip it πŸ™‚

coral quartz
unreal graniteBOT
#

Gave +1 Rep to @ebon adder

ebon adder
shut gulch
#

Hi! I finished the room more or less, but with sharphound, it always returns me no users, any idea why ?

crystal dragon
#

hey @shut gulch , if you are using Kali, try to sudo apt remove bloodhound and install fresh realease from Github

shut gulch
#

@crystal dragon I used the kali box vm, I installed bloodhound from apt, bad idea ? πŸ˜„

shut gulch
#

Damn ok, I redid the box with the attackbox to save me hassle, and it did work. I couldn't print the path from my user to T1 Tier Admins though, I don't know if I was supposed to, but I found that pretty unfortunate

crystal dragon
#

AttackBox is parrot, not Kali right? I've faced exactly same issue and found discussion in Bloodhound Github issues where devs saying they are not maintaining releases /repo for Kali πŸ™‚ and maybe for Parrot is different situation, so installing fresh from github seems like a good idea anyway πŸ™‚

marble haven
pseudo cape
#

EnumAD it's a nice room, enjoyed doing it.

somber elk
#

I got disconnected from the thmjmp1 machine and now I can't connect at all back with ssh, neither reach the distributor.za.tryhackme.com/creds and nslookup fails what's wrong

#

I disconnected reconnected to the VPN, same DNS ips, restarted both services but nothing huh

#

well

golden rover
#

looks like to many users are signed in

#

i was signed out as well

somber elk
#

doesn't work on attackbox either

#

Oh damn ok welp we have to try another time I guess

#

That's frustrating why do we have to be disconnected when we were already connected wth instead of refusing the newer connections

golden rover
#

don't know but thats how it is i guess. not much we can do about it

somber elk
#

I was right in the middle of the room

golden rover
#

same, i was in the powershell section

somber elk
#

yeah same

#

Well at least I'm not a pepiga who messed up something without knowing I guess

golden rover
#

nope. just the pepigas who got kicked off lol

golden rover
#

question. why is mine showing the SID value for the users and not the user names?

ebon adder
ebon adder
# somber elk I got disconnected from the thmjmp1 machine and now I can't connect at all back ...

If the network drops, can you run two things:

  • ping the DC using its IP
  • Run nslookup za.tryhackme.com <DC IP>

If the ping does not work then it is most likely that the network went to sleep. If someone pressed extend instead of Start when the network sleeps, it bricks out. So you have to use inspect element to reenable the Start button and press it (Frontend team is working on a fix)

If both commands work, then the issue if you local DNS configuration.

If the nslookup command fails but the ping works, then there is a network issue that must be inspected. You can then let me know and I'll look into it from the backend

unreal graniteBOT
#

Gave +1 Rep to @ebon adder

somber elk
#

I'm gonna retry again, let me 5 mins to setup

#

It works again

#

(the network was stopped, i just started it, ping and nslookup works now)

ebon adder
inner goblet
#

Can I ask something? What does "domain-joined" mean? Since we are on the same network and can connect via Ssh or RDP, wouldn't we be in the domain?

ebon adder
# inner goblet Can I ask something? What does "domain-joined" mean? Since we are on the same ne...

Hey there, good question!

When you have a Windows host, by default, it is joined to the default WORKGROUP workgroup. Meaning it is not domain joined. Once you change this to the actual domain and enroll the host using credentials that have the permission, this value is changed to the domain.

Since we are on the same network and can connect via Ssh or RDP, wouldn't we be in the domain? - Same network does not really have anything to do with it. But that second part, either SSH or RDP to a domain-joined machine means yes, you are domain joined! πŸ™‚

However, if you perform red team assessments or security testing of networks, a lot of the time your testing VM would not be domain-joined. Simply running the organisation's VPN profile won't make the machine domain-joined and since you don't have an AD account with permissions (usually) to domain-join that machine, you need to be more creative with your enumeration. Hence this is why the room shows how you can perform these techniques from a non-domain-joined Windows machine.

Hope that makes sense πŸ™‚ Let me know if anything is unclear and I'll try to explain it better

inner goblet
unreal graniteBOT
#

Gave +1 Rep to @ebon adder

rough spear
#

added dns server(THMDC) restarted service, but it doesnt work for some reason i nslookup returns error
(server is accessible)
why can it happen?

ebon adder
rough spear
#

i followed the example on my kali host, changed /etc/systemd/resolved.conf, restarted service, but got error from nslookup thmdc.za.tryhackme.com
but it started to work, after i have changed /etc/resolv.conf

ebon adder
unreal graniteBOT
#

Gave +1 Rep to @ebon adder

rough spear
#

i did everything as in example, but looks like its not configured properly

winged crystal
unreal graniteBOT
#

Gave +1 Rep to @winged crystal

rough spear
#

Thank you @ebon adder for this free networks.
will there be released more networks for subscribers, or this are all?

unreal graniteBOT
#

Gave +1 Rep to @ebon adder

leaden cobalt
#

Task6: Hi there, Any idea why I don't get nodes information?....same results with uploaded file on that task or running sharpHound and getting the .zip...

verbal osprey
ebon adder
tidal anchor
#

hello, should task 2 be done or can just skip ?

#

like do i have to do all that it does like inject credentials inside THMJMP1

#

?

tidal anchor
#

i keep getting no data in file

ebon adder