NITE Team 4

NITE Team 4

评价数不足
Network Intrusion
由 LeikRad 制作
This is a walkthrough for the Academy Training "Network Intrusion"
   
奖励
收藏
已收藏
取消收藏
CODENAME : NETWORK INTRUSION
In Network Intrusion agent Conway will teach you about several tools that are used to gather Intel on a certain network and exploit it. You will learn more about the following tools: "Social Engineering Toolkit" (or SET for short), "WMI Scanner", "Active Directory", "Man In The Middle" (or MITM for short), "Aircrack" and you will also need to use the skills you learn in a final test to prove yourself.

This section contains 6 training missions, each with multiple parts.

This guide is meant to be used as a resource and will contain hints in order to help you solve the missions, but it will not contain the actual answers.

If at any time you feel like you need more help please go to either the discussion board or the Discord channel[discord.gg] and there will be fellow agents happy to help you.

The missions are the following:
  1. SET Toolkit ( NITE.02 )
  2. Network Scanning ( NITE.03 )
  3. Active Directory ( NITE.04 )
  4. Man In The Middle ( NITE.05 )
  5. Aircrack ( NITE.06 )
  6. Newstream Live ( NITE.07 )
Network Intrusion Overview
https://steamuserimages-a.akamaihd.net/ugc/954101770864037255/8E486D808A2B265FF340146A0E66D4C262954C53/?imw=256&&ima=fit&impolicy=Letterbox&imcolor=%23000000&letterbox=false
SET TOOLKIT ( NITE.02 )
This training mission will teach you about the "Social Engineering Toolkit" module which exploits human flaws to give you access to a network.

SET TOOLKIT ( NITE.02 ) : Phase 1
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2Read what the game wants you to do.

  • Hint 3The game wants you to use the Social Engineering Toolkit with the specifications from the objectives.
SET TOOLKIT ( NITE.02 ) : Phase 2
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2Read what the game wants you to do.

  • Hint 3The game wants you to use the Social Engineering Toolkit with the specifications from the objectives.

    SET TOOLKIT ( NITE.02 ) : Phase 3
    Difficulty: Training
    • Hint 1It's as easy as following instructions.

    • Hint 2Read what the game wants you to do.

    • Hint 3The game wants you to use the Social Engineering Toolkit with the specifications from the objectives.

    • Hint 4 -- You know the company's name, now what could use to build an email database by crawling LinkedIn?

    • Hint 5 -- The rest of the options (File Format, Payload, Template) are told to you in the objectives.
NETWORK SCANNING ( NITE.03 )
This training mission will teach about the "WMI Scanner" module, this is one of the tools that is used to do reconnaissance when inside of a private network. We will continue where you left off from the "SET Toolkit" certification (Leon's Computer).

Network Scanning ( NITE.03 ) : Phase 1
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2 -- The tutorial wants you to use the WMI Scanner in the network you got from the SET certification.

Network Scanning ( NITE.03 ) : Phase 2
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2 -- The tutorial wants you to use the WMI Scanner in the network you got from the SET certification.

  • Hint 3 -- You can use the "help" command to understand more about the "dig" command.

  • Hint 4 -- You can use the "dig" command to find out what path from netscan has the "IBM Watson" technology.

Network Scanning ( NITE.03 ) : Phase 3
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2You are looking for a mail server, what tool could you use to gather that information?

  • Hint 3 -- The game gave you a domain for Sunshade Corp. Now just remember the previous certifications and how you are supposed to find subdomains.

  • Hint 4 -- Maybe sfuzzer will be able to find it.

  • Hint 5 -- Remember the first part of this certification.

  • Hint 6 -- You may find a username for a Sunshade Corp IT employee if you use WMI.

  • Hint 7 -- You already have a target subdomain and a username to perform a password attack on a user's mail account.
ACTIVE DIRECTORY ( NITE.04 )
This training mission will allow you to familiarize yourself with the "Active Directory" module, which is used to look at certain information contained in the computer network, more specifically Windows domain networks.

Active Directory ( NITE.04 ) : Phase 1
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2Netscan was done with the WMI scanner and the game is asking you to do it while connected.

  • Hint 3Use "help dig" if you are not familiar with the "dig" command.

Active Directory ( NITE.04 ) : Phase 2
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2Using the Active Directory module, you are able to access certain paths from the netscan results.

  • Hint 3The Active Directory module is only compatible with Active Directory technology, normally the paths either have "active_directory" or "AD" to show that they are Active Directories.

Active Directory ( NITE.04 ) : Phase 3
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2Look around for the IT admin in the Active Directory.

  • Hint 3 -- Now that you've got a username you just need to find the IT mainframe that is connected to the network you are currently in.

  • Hint 4 -- Remember what tool could find paths in the internal network, you learned to use it in the previous certification.

  • Hint 5 -- Maybe WMI will be able to find the Mainframe's path.

  • Hint 6 -- Now that you have found a target path (the IT Mainframe) and a user (the IT admin) you can run a password attack.

MAN IN THE MIDDLE ( NITE.05 )
This training mission will teach you about the "Man In the Middle" or "MITM" module for short and how to use it, this tool is powerful when it comes to monitoring a network as it can detect packets that are to and from the network. You will also learn about Password Hashes and how to crack them.

Man In The Middle ( NITE.05 ) : Phase 1
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2The tutorial wants you to use the MITM module that can be found at the bottom of your screen.

  • Hint 3Don't forget that the objective tells you what poison and what IPs you are supposed to use.

Man In The Middle ( NITE.05 ) : Phase 2
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2 -- Go back to the Dialodge Support C2 Card and repeat the steps from the previous part (Opening MITM and using it to get to the URL Snapper).

  • Hint 2 -- There's a weird subdomain on the URL Snapper in the MITM module.

  • Hint 3 -- Maybe it's the intranet subdomain.

  • Hint 4 -- The poison and the IPs the tutorial wants you to use are in the objectives.

Man In The Middle ( NITE.05 ) : Phase 3

  • Hint 1It's as easy as following instructions.

  • Hint 2Remember what module was used to find paths?

  • Hint 3Maybe WMI will help you find the active directory

  • Hint 3You now have an active directory path, there's a module that can use that path.

  • Hint 4You're looking for password policies, think logically.

  • Hint 5Now launch the password attack and use the password hash you found earlier.

  • Hint 6Now you can use the policies to shorten the possibilities.
AIRCRACK ( NITE.06 )
This training mission will test you on how to use the "Aircrack" module, that is used to see the registry of phones connected to a wifi at a certain time and date, and if you have been given permission you are able to access said phone.

.Aircrack ( NITE06 ) : Phase 1
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2Use the Air Crack module in the Information Gathering.

  • Hint 3Don't forget that "help [command]" will help you if you forget how the commands work.

Aircrack ( NITE.06 ) : Phase 2
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2 -- You have the schedule of the target, so you need to cross-reference it with the entities that appear in the Aircrack module.

Aircrack ( NITE.06 ) : Phase 3
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2 -- You can connect to the phone's hotspot in the settings.

  • Hint 3 -- If you have the note in the phone, you will get a url, a username and a password, now you just need to connect to it with filebrowser.
NEWSTREAM LIVE ( NITE.07 )
In this mission you will be put in a simulation of a real life situation, if you manage to prove yourself here, you will finish the certification and be one step closer to a fully skilled Nite Team 4 agent.

Newstream Live ( NITE.07 ) : Phase 1
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2Remember what you learned in the previous academy missions, on how to find a vulnerable subdomain.

  • Hint 3Maybe sfuzzer or osintscan will dig up something.

Newstream Live ( NITE.07 ) : Phase 2
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2Remember the previous certification, where you learn to look for paths connected to a certain network.

  • Hint 3Maybe WMI will find something, don't forget to dig it too.

  • Hint 4Now you need to use XKeyscore to find Intel about where our target's crew car disappeared, remember the target Laura Walker.

  • Hint 5She needs to be accompanied by a cameraman, maybe if you use Laura Walker, the camera man and the organization, you'll find something.

  • Hint 6Now that you know she was in a car, you can find her location.

  • Hint 7Since she is in a car, she must have been seen by a traffic CCTV camera.

  • Hint 8Maybe if you try Laura Walker, her organization and an Ottawa service, you'll find her location.

  • Hint 9Now that you have her coordinates and a license plate number, you can track her using the Satellite View.

Newstream Live ( NITE.07 ) : Phase 3
Difficulty: Training
  • Hint 1It's as easy as following instructions.

  • Hint 2You can find the billboards domain from the Satellite view.

  • Hint 3You can find the billboard's company domain from the Satellite view.

  • Hint 4Don't forget to try sfuzzer and osintscan.

  • Hint 5Don't forget to read what the game asks you to do.

  • Hint 6After you have access, return to the Satellite view.

9 条留言
Always Learning 2021 年 12 月 26 日 下午 12:18 
I'm having an issue. Which is "Aircrack Phase 3" I got the username, url and password. When I go into the file browser and enter the information it say. Unable to connect? Anyone else had this issude
bass pro shops enthusiast 2020 年 7 月 7 日 上午 3:41 
nite 05 phase 3 hint 5 doesn't help, i did use the CORRECT hash and the module says it's incorrect that is bs
Mertado 2020 年 6 月 6 日 下午 10:52 
NITE.02, Phase 3, Hint 4 is where I drew the line and refunded this dumpster fire of used diapers. Most of the tutorial is simple hand-holding, but using an offhand remark from your guide as a major bit of IMPORTANT INFORMATION necessary to advancement is pure bu11sh!t. And any time I have to look up an answer for a tutorial means the developers don't deserve my money.

Tutorial has 2 game breaking bugs, this is one of them (though this is more of a stupid design flaw). The other occurs earlier in the training where I'm supposed press a Return to the Globe button that wasn't on the screen. Only after I'd deleted all progress and started again did it show up. I guess the developers didn't account for players exploring parts of the interface that the tutorial didn't ask them to.

This is what happens when pure software engineers attempt to make a game.
They shouldn't.
Ever.

Nice walkthrough though. I like the Invisiclues style (bonus points for knowing where Invisiclues came from).
mikha 2019 年 5 月 10 日 上午 4:47 
Sadly, not helpful at all. Not even a walkthrough - should rename the whole thing to "level hints" instead.
metafish 2019 年 3 月 6 日 下午 3:51 
It's okay, I'm sorry if I came off a little agro as well, and also for being a bit rude when it wasn't really necessary as well. I looked through and it's so much better! Thanks for being reasonable and updating based on the feedback as well :)
LeikRad  [作者] 2019 年 3 月 6 日 下午 2:50 
@metafish Thanks for the feedback, really appreciate it, based on it, I went and did the certification again and added in some new hints. Also, I apologize for sounding condescending, it wasn't my objective.
metafish 2019 年 3 月 4 日 上午 6:29 
Worst review I've ever come across. If someone could do it by just "following the instructions" they wouldn't be coming to a walk-through. More likely they're coming to a walk-through because they couldn't figure out what to do based on the instructions alone. Then the review says "read the instructions, it's simple"

The most condescending, not helpful way to help people. I understand you don't want to spoil the sense of discovery and encourage people's own discernment but come on. At least mention the tools you're supposed to use at each stage, perhaps in a spoiler bubble? Don't black out "read the instructions" how the hell is that a hint? Black out actual spoiler content like the relevant information about how to actually complete the stages.
LeikRad  [作者] 2019 年 3 月 3 日 下午 1:42 
Sorry to hear that. Because it's an Academy mission and the objectives are pretty straightforward, I didn't feel it was needed to add anything more. However, if you are still in need of help, you can always ask in the Steam Discussions or join the Discord server and ask for help there. Also, feel free to add me on Steam if you want so I can help you out.
Gwydion- is the greatest 2019 年 3 月 1 日 下午 4:46 
"Just do what it says" is not a walkthrough. :KOh: