eto
eto4w ago

REMNUX authentication error as the super user

Im getting this error when I try to insert the guest additions CD
No description
163 Replies
eto
etoOP4w ago
@Stebe
Stebe
Stebe4w ago
ummmm what was the command you ran that popped this open?
eto
etoOP4w ago
the only codes that video showed the media stuff and the mounnt but the mount one was an error and nothing else I also have the option to upgrade the guest additions
Stebe
Stebe4w ago
try the password malware i mightve been wrong about that
eto
etoOP4w ago
yes its malware lol
Stebe
Stebe4w ago
my bad i thought it was remnux/remnux lol
eto
etoOP4w ago
tysm
Stebe
Stebe4w ago
we can keep this open while youre going through setup in case you have any other issues feel free to ping me in here and ofc! excited for you and your journey!!
eto
etoOP4w ago
alright my remnux and windows are both work like 20 fps is that normal but the same doesnt happen on kali linux its smooth
Stebe
Stebe4w ago
do you use the same hypervisor for kali as youre using for remnux and flare?
eto
etoOP4w ago
I deleted windows 10 gotta do everything back I tried most of the stuff and didnt really work I also didnt give 60gb so I coujldnt download flarevm gotta start most of the stuff from the beginning :skull_sob: probably, since I'm installing windows 10 again Im going to check everything neatly
Stebe
Stebe4w ago
so you have your kali vm in virtualbox as well? (where i’m assuming your flare and remnux vms are?)
eto
etoOP4w ago
yep
Stebe
Stebe4w ago
are you using the same graphics controller for it? should be under settings>expert>display
eto
etoOP4w ago
I'll check it in a moment lemme take care of the windows 10 then I'll check it out
Stebe
Stebe4w ago
okay sounds good, and having the VBoxGuestAdditions installed might be part of it but not sure if you were alr able to do that with the other ones
eto
etoOP4w ago
my system crashes while downloading flarevm after a while tried restarting it with saving but worked only once then didnt work and it keeps doing that when I click to the vm tab, my mouse gets kicked out of it and it becomes a loop each time I try it
Stebe
Stebe4w ago
did you disable defender/edr?
eto
etoOP4w ago
I didnt . . .
Stebe
Stebe4w ago
that'll do it lol there should be a link to a post about disabling it
eto
etoOP4w ago
in github?
Stebe
Stebe4w ago
i think it might be in the flare github repo i think
Stebe
Stebe4w ago
Ensure the requirements above are satisfied, including: Disable Windows Updates (at least until installation is finished) https://www.windowscentral.com/how-stop-updates-installing-automatically-windows-10 Disable Tamper Protection and any Anti-Malware solution (e.g., Windows Defender), preferably via Group Policy. GPO: https://stackoverflow.com/questions/62174426/how-to-permanently-disable-windows-defender-real-time-protection-with-gpo Non-GPO - Manual: https://www.maketecheasier.com/permanently-disable-windows-defender-windows-10/ Non-GPO - Automated: https://github.com/ionuttbara/windows-defender-remover Non-GPO - Semi-Automated (User needs to toggle off Tamper Protection): [https://github.com/AveYo/LeanAndMean/blob/main/ToggleDefender.ps1] (https://github.com/AveYo/LeanAndMean/blob/main/ToggleDefender.ps1)
Windows Central
How to stop automatic updates on Windows 10
Yes, it's possible to disable automatic updates on Windows 10, and in this guide, we'll show you how.
Crystal Crowder
Make Tech Easier
How to Permanently Disable Microsoft Defender - Make Tech Easier
Don't want to be bothered by Microsoft Defender, aka Windows Defender? Learn how to permanently disable it.
GitHub
GitHub - ionuttbara/windows-defender-remover: A tool which is uses ...
A tool which is uses to remove Windows Defender in Windows 8.x, Windows 10 (every version) and Windows 11. - ionuttbara/windows-defender-remover
eto
etoOP4w ago
so, what to do now should I just close the vm fully then restart it and close the antivirus then continue
Stebe
Stebe4w ago
uhhh if you took a snapshot before attempting to install flare i would revert back to that
eto
etoOP4w ago
alright it was progressing for an hour now :skull_sob:
Stebe
Stebe4w ago
yeah the flare install takes a hot minute
eto
etoOP4w ago
so, do I just disable everything in windows defnder :AngryCry:
Stebe
Stebe4w ago
yeah if you follow the steps in those articles it should take care of everything that would cause the flare install to bug out
eto
etoOP4w ago
tysm!
Stebe
Stebe4w ago
ofc!
eto
etoOP4w ago
is it ok for it to be like this
No description
Stebe
Stebe4w ago
uhhhhhh i think? iirc it doesnt need to be in any particular directory as long as you can run it
eto
etoOP4w ago
its been an hour and 10 minutes. I don't even know how long this is gonna take :blue_screen:
Stebe
Stebe4w ago
mine took a few hours ngl
eto
etoOP4w ago
its literally 1 am and I have an exam today :AngryCry:
Stebe
Stebe4w ago
i’m sorry!! gl on the exam tho 😅
eto
etoOP3w ago
So, I waited overnight and I think not everything went right. My internet connection was gone and my pc was in sleep mode..
Stebe
Stebe3w ago
were you able to check in on the vm? there should be a log.txt or something similar either at the same path that the install.ps1 script was ran from or in a folder on the desktop called Flare
eto
etoOP3w ago
Yes but I closed it I hope its saved
Stebe
Stebe3w ago
you should be good, when you get a chance to check on it lmk, hoping the best for your sake lol
eto
etoOP3w ago
so, I am continuing on the video and Im making a shield to my physical host and letting the other 2 vm interract with each other. But the ips are reverse for me. They are the custom ip that isn't my main ip. But they are reversed. Like one of them is 11.6.5.3 and the other must be 11.6.5.4 but instead the one I set 11.6.5.3 is the other one. Could that get my main host in trouble?
Stebe
Stebe3w ago
youre talking about setting up the Host-only adapter right? and the two IP addresses are for your Flare and Remnux vms?
eto
etoOP3w ago
yes the video is 6 hours and the first hour is just creating an experimental lab for ourselves :Bruh:
Stebe
Stebe3w ago
this is the setup i have for my adapter, and then i believe the two local ip addresses for my vms are 10.0.0.3 and 10.0.0.4. you can always apply that adapter and then try to ping outside of that network to your local or host machine and it should give you a network unreachable message
No description
No description
Stebe
Stebe3w ago
safety is rule number 1 when playing with malware lol last thing you want is it going where you didnt want it to
eto
etoOP3w ago
yeah it does give an error
Stebe
Stebe3w ago
okay you should be good as long as your local network isnt reachable from either two machines, i would just say to make sure to watch and follow those safety guidelines very carefully also make sure shared clipboard and drag and drop are turned off in your virtualbox settings
eto
etoOP3w ago
alright, but I cant reach to internet on my flarevm rn, what to do?
Stebe
Stebe3w ago
he should go over it in the video, iirc you just make sure youre on a snapshot that hasn't had any detonations on it and temporarily switch it over to the regular network adapter, get the tools or whatever you need downloaded and then switch it back over to the host only adapter but in general unless youre downloading a new tool or something youll want to keep the flare and remnux machines offline or if youre using inetsim or something similar then you can put them on the host-only adapter network
eto
etoOP3w ago
I have already done that I suppose
Stebe
Stebe3w ago
good work! the fun stuff comes soon lol
eto
etoOP3w ago
uh it says this
No description
eto
etoOP3w ago
could this be the cause
Stebe
Stebe3w ago
what are you trying to use OpenVPN for?
eto
etoOP3w ago
no idea it downloaded anyway I think it was a bad idea to mark everything 💀 also now I can ping 8.8.8.8 so I think I reversed something from flarevm. . .
Stebe
Stebe3w ago
check your network adapter and make sure its the one that you created that should look like this one
eto
etoOP3w ago
it looks like that rn I have done stuff back let's see if it sgonna work now then Im going to check if I can pig 8.8.8.8 again if I can ping it I think I have missed something theres no internet rn unidentified network for me
Stebe
Stebe3w ago
youre able to ping 8.8.8.8 from your flare VM?
eto
etoOP3w ago
I was able to, now I have done the steps again but now, I just dont have internet connection in flare vm so I cant basically open inetsim on flarevm or download google chrome
Stebe
Stebe3w ago
do you have the right adapter selected here?
No description
eto
etoOP3w ago
yes
eto
etoOP3w ago
yalnızca : only host : anamakine bağdaştırıcı : adapter
No description
eto
etoOP3w ago
and I have only checked adapter 1
Stebe
Stebe3w ago
okay so you have it set to use your host only adapter right now correct?
eto
etoOP3w ago
yes
Stebe
Stebe3w ago
youll have to switch it to NAT or bridged to be able to access the internet iirc
eto
etoOP3w ago
wouldnt that let it access to my pc too?
Stebe
Stebe3w ago
yeah thats why i said this only switch it to that temporarily if you need to download a tool or something otherwise keep it offline
eto
etoOP3w ago
I need to inetsim rn oh
Stebe
Stebe3w ago
as long as you havent detonated anything on it you should be fine
eto
etoOP3w ago
you also have to do the same too? Or is it just a problem that is caused by my mistake somewhere
Stebe
Stebe3w ago
switching adapters?
eto
etoOP3w ago
yep
Stebe
Stebe3w ago
yeah thats just how it works, im not an expert in vm networking by any means but the whole purpose for that host only adapter with the separate local IP space is to prevent it from talking to anything else (your local network which you need to get to the internet) its never a bad idea if youre about to detonate something to double check by pinging your local network and out to the internet just to be sure
eto
etoOP3w ago
tysm bro, you have saved me. I would've been confused for hours 💀
Stebe
Stebe3w ago
no problem lol it can be confusing
eto
etoOP3w ago
alright, I will make sure to check it! I can't make my connection to make it only access to the ip address of my remnux I have tried it but it doesnt work what do I do
Stebe
Stebe3w ago
you switched back to the default adapter and set the adapter type to NAT or bridged right? i got timed out trying to explain im trying to figure out why then i will try again lol
eto
etoOP3w ago
yup
Stebe
Stebe3w ago
did you change any settings in "View network connections" > "<adapter_name" > "Properties"?
eto
etoOP3w ago
yes made it the same as inetsim 10.0.0.4
Stebe
Stebe3w ago
if you changed your DNS server there or turned off "Internet Protocol Version 4 (TCP/IPv4) it may be the cause
eto
etoOP3w ago
(for me)
Stebe
Stebe3w ago
yeahhhhh you gotta change that back otherwise its looking on the wrong network for a DNS server
eto
etoOP3w ago
so the video is wrong?
Stebe
Stebe3w ago
but then when you go to use inetsim youll need to change your DNS server back to 10.0.0.4 not necessarily, just when you want to connect to your local network or the internet, youll need to change that back (set DNS server to default/obtain automatically)
eto
etoOP3w ago
@˚₊‧꒰ა tenshi♡ ୭ৎ you know we see the people that only chat here? :wideskull:
Stebe
Stebe3w ago
they tried to hide we saw you 🤣
eto
etoOP3w ago
I changed it to 10.0.0.4 but now but it doesnt work. It just tells me to check my internet connection and doesnt direct me into 10.0.04 and I think in the video he means we will need it somewhere
Stebe
Stebe3w ago
yes so if you want to connect to the internet, youll have to change your adapter and adapter type and that setting to obtain automatically or whatever DNS server you prefer, but when you go to use INetSim, youll want to change back to your host-only adapter and change your DNS server to 10.0.0.4
eto
etoOP3w ago
ok I understand that but when I go to use INetSim, I change it to host-only adapter and change my dns server to 10.0.0.4, it doesnt work like in the video
Stebe
Stebe3w ago
how so?
eto
etoOP3w ago
no idea :skull_sob:
Stebe
Stebe3w ago
INetSim should just return a default response/IP address for all requests, it doesnt actually let you access the internet so if when youre on the host-only adapter network, both the remnux and flare machines, and perhaps you do ping google.com it should return a response from 10.0.0.4
eto
etoOP3w ago
yes it does
Stebe
Stebe3w ago
and youre running that from the flarevm?
eto
etoOP3w ago
yes
Stebe
Stebe3w ago
okay was there anything else that wasnt working? iirc there is a setting that you have to change in inetsim config file but i think the video goes over that
eto
etoOP3w ago
nope, everything works fine except the redirection to 10.0.0.4
Stebe
Stebe3w ago
what do you mean sorry?
eto
etoOP3w ago
so, do I just go on? when I go to a random website like asdasdasd.com it redirects me into 10.0.0.4 at least thats wha the ssaid in the video but for me, that doesnt work and tells me "this site can't be reached"
Stebe
Stebe3w ago
1 sec let me start mine up okay i think i found the issue, i completely forgot having it when i was getting mine set up. run 2 commands for me: ifconfig and ip link show theres probably one interface similar to enp0s17 that will show up in the ip link show output that you wont see in ifconfig whatever the name of that other interface is, you'll want to do sudo dhclient <interface_name> and then start inetsim again
eto
etoOP3w ago
its enp0s3
Stebe
Stebe3w ago
okay so youll want to do sudo dhclient enp0s3 and then restart INetSim
eto
etoOP3w ago
its done site cant be reached you can check your cinternet connection or check the proxy and firewall it says that do I need an internet connection just to reach to that ip?
Stebe
Stebe3w ago
no you should be on the same network as long as both adapters are on hold up doing some more testing on my end
eto
etoOP3w ago
Im already on the same network and its the #2 one both are only host adapter stuff
Stebe
Stebe3w ago
when you run inetsim are you getting this in the output? Couldn't create UDP socket: Address already in use at /usr/share/perl5/INetSim/DNS.pm line 36 ? any update? just fixed it on my end but thats the issue i was having
eto
etoOP3w ago
Nope, is that really important for me to not continue and fix it? Ima sleep... I will make sure to update after school! Thank you so much for your helps, have a nice day:OwO:
Stebe
Stebe3w ago
no problem, sorry it can be a pain to get set up but hope we can get it working for you!
eto
etoOP3w ago
You've tried your best, I'm thankful for your helps, I hope we find a way to achieve that
tenshi♡
tenshi♡3w ago
bros are still trying to get remnux to work just use flare atp :Meow_blub:
Stebe
Stebe3w ago
trying to use flare + remnux to run internet simulation to capture outbound calls inetsim can kinda be a pain in the ass, i dont use it much day to day but the coursework uses it went to go start it again and mine was broke too lmao had to fix but seems like theyre having another issue insert "its always DNS" joke here
eto
etoOP3w ago
Im using a vpn on my physical computer, could that be the cause? My country banned discord btw:AngryCry:
Stebe
Stebe3w ago
dang that’s rough, i don’t think so though it shouldn’t affect your local network just public are you able to wget http://10.0.0.4 from your flare vm? it should give you the HTML of the default INetSim page
eto
etoOP3w ago
Ima check it when Im home Gotta take a while I think I'll skip my class today, this looks way better If I fix that, I'll finally have a place to cook and start the main course
Stebe
Stebe3w ago
i have a feeling its a dns issue, if you were able to ping the remnux machine directly then that would be my first guess
eto
etoOP3w ago
No description
eto
etoOP3w ago
I can't wget it
eto
etoOP3w ago
could it be something
No description
eto
etoOP3w ago
from remnux
Stebe
Stebe3w ago
you can ping the ip of remnux from flare though right?
eto
etoOP3w ago
yup just tried it
Stebe
Stebe3w ago
use cmder instead of powershell and try wget http://10.0.0.4
eto
etoOP3w ago
it doesnt see it as a command
Stebe
Stebe3w ago
in cmder?
eto
etoOP3w ago
yes wget isnt a batch file or an internal command
Stebe
Stebe3w ago
does curl work? or iwr in powershell
eto
etoOP3w ago
curl works btw
Stebe
Stebe3w ago
okay so its giving you the content of the default inetsim html page with curl?
eto
etoOP3w ago
yes
Stebe
Stebe3w ago
but when you go into a browser and try looking up any site it tells you site cant be reached
eto
etoOP3w ago
No description
eto
etoOP3w ago
yes
Stebe
Stebe3w ago
nice ok you changed your IPv4 properties in windows back to use 10.0.0.4 as DNS right?
eto
etoOP3w ago
yes
Stebe
Stebe3w ago
can you try nslookup google.com on flare? the nameserver should be 10.0.0.4 but im really thinking something is wrong with DNS on inetsim
eto
etoOP3w ago
No description
eto
etoOP3w ago
it's like that
Stebe
Stebe3w ago
youre using chrome as your browser in flare right?
eto
etoOP3w ago
yes google chrome
Stebe
Stebe3w ago
try going to chrome://settings/security and look for "Secure DNS", "DoH", or "DNS over HTTPS" and make sure its turned off im using firefox so im not sure if thats why but regular dns seems to be working so its prolly a browser issue
eto
etoOP3w ago
I might just use firefox and try it uh I cant use google like even with internet everything becomes cant reached
Stebe
Stebe3w ago
did you change DNS server?
eto
etoOP3w ago
fixed it to auto
Stebe
Stebe3w ago
and changed adapter and adapter type back to main adapter and bridged/NAT?
eto
etoOP3w ago
yes
Stebe
Stebe3w ago
bruh what happens if you try to ping google now
eto
etoOP3w ago
works
Stebe
Stebe3w ago
but browser doesn't?
eto
etoOP3w ago
yes
Stebe
Stebe3w ago
try edge maybe?
eto
etoOP3w ago
firefox doesnt work edge doesnt work either what do I do
Stebe
Stebe3w ago
when youre pinging google youre not getting response from 10.0.0.4 right just want to make sure youre actually connected to internet
eto
etoOP3w ago
yes I am Im truly sorry for the late response harsh day studied at home
Stebe
Stebe3w ago
no problem, do you have a snapshot of your base flare install? might be easier to just revert back to that if you were able to get that connected to the internet and the inetsim network
eto
etoOP3w ago
I don't probably lemme check I actually do flarevm - base I might just revert it
Stebe
Stebe3w ago
yeah thats probably your best bet to be honest, not sure if something got messed up in the interim but if you can just revert back to one you know works i would start there then just whenever youre switching between make sure you change you adapter, adapter settings, IPv4 settings in flare and then double check your inetsim.conf file in flare and make sure its the same as he has in the video
eto
etoOP3w ago
I know I'm asking this way too late but, what will be the advantages of learning malware analysis? Tbh, I might just download flare again Could be something about the downloading Bc I remember I saw smth about inetsim in logs
Stebe
Stebe3w ago
there should be an install log either on the desktop or in tools or flare folder wherever you ran install script from at larger orgs, it could be your sole responsibility to do this, otherwise it can be a really good skill as a blue/purple teamer when you come across it in the wild or for adversary emulation
بابلو اسكوبار
at larger orgs, it could be your sole responsibility to do this, otherwise it can be a really good skill as a blue/purple teamer when you come across it in the wild or for adversary emulation

Did you find this page helpful?