#cyber-security-101-path

1 messages ยท Page 2 of 1

hasty scroll
#

I love the raccoon!!!

brazen blade
#

give me 5 minutes to start it up and get to where you are

hasty scroll
#

ok

brazen blade
hasty scroll
#

task 4, question 2 is the one I am on right now

brazen blade
#

did you export the file?

hasty scroll
#

this is what I get when I do

brazen blade
#

yes

#

you can enter a name

#

and then hit save at the bottom right

hasty scroll
#

should append it with a jpeg?

brazen blade
#

not needed

hasty scroll
#

picture

#

sorry,

brazen blade
#

alright. Now open a terminal and use the command to get a md5 hash with the name of the file you just saved

hasty scroll
#

took me back to wireshark

#

ok

brazen blade
#

keep in mind that you need to be in the same folder as the image

hasty scroll
#

how do I do the hash command again?'

#

I just did hash and the file

brazen blade
#

what kind of hash are we looking for?

#

what variant

hasty scroll
#

md5

brazen blade
#

what is the exact command to get an md5 hash?

hasty scroll
#

let me look it up

brazen blade
#

basically we're looking up an md5 checksum

hasty scroll
#

hashfile is n't working

brazen blade
#

what are you entering exactly?

hasty scroll
#

I have tried several. hash picture MD5

#

hashfile

brazen blade
#

no no wait

#

take a step back

hasty scroll
#

with and without the dash in front of it

brazen blade
#

we're looking for the command that prints the md5 hash of a file

#

its a single command thats 6 characters long

hasty scroll
#

certutil -hashfile

brazen blade
#

I'm not sure if cryptography already came up or was before

#

but what you're looking for is hidden in here:

brazen blade
#

if you need more direct help, let me know and I'll just spoil the answer lmao

hasty scroll
#

now I am getting this

brazen blade
#

nono

#

drop certutil

#

ignore it

#

you're looking for a md5 checksum (the bold marked might be a command if combined together) + filename

#

Now I either gave you the hint you needed or completely threw you off the topic lmao

#

let me know which one it is so I can actually give you the command

hasty scroll
#

this is what I get

brazen blade
#

drop -hashfile as well

#

6 letter command

#

ok so its

#

||md5sum|| + filename

#

obv not the + but a space

#

try that

hasty scroll
#

That finally worked!!! I have never seen it done that way before. I am still new to this cybersecurity thing. I would have been at it for hours if not days and weeks. LOL

brazen blade
#

dw it will get explained in Cryptography in more detail

#

which should come after networking I believe

hasty scroll
#

I have definitel been redoing rooms with this new path. Doesn't hurt me to redo them

#

I take copious notes though, LOL

brazen blade
#

thats the way

#

I think I burned through 20 pages on notes for the network fundamentals alone

hasty scroll
#

Lol, that's good

#

They have crptography after this section

#

They should have crptography before networking, lol

brazen blade
#

yea. I mean I think its the only time you need anything cryptography related

#

but that knowledge may have not hurt beforehand

hasty scroll
#

definitely wouldn't have but I still can't find question 1

brazen blade
#

help me out please, which one is that?

hasty scroll
#

the question before that one you helped me with

#

same room

brazen blade
#

if you look for the string r4w, you get thrown onto package 33790

#

inside the html is the artist name

#

it should already be highlighted in blue if you searched the string

#

and as mentioned, its a bit more to the right inside <h3>

hasty scroll
#

I don't see anything

brazen blade
#

you can drag the window to the right

#

move that slider to the right a bit

#

or press on the > arrow at the right side

hasty scroll
brazen blade
#

well thats too far

#

your answer is hidden somewhere inbetween

hasty scroll
#

all I see is a bunch of code and websites

brazen blade
#

if you press find again

#

it will take you to the exact line

#

on that, just go a bit to the right

hasty scroll
#

I was looking for a name not a friggen code word, lol

brazen blade
#

xd

hasty scroll
#

Not sure what to think of this question, lol

#

They could have worded it differently

brazen blade
#

I guess I should then prepare you and let you know that the second task wants you to find another artists name? ๐Ÿ˜„

hasty scroll
#

First you have to find the .txt file, lol

#

Not sure I am liking Wireshark, lol

brazen blade
#

it takes some getting used to

hasty scroll
#

when I hit the find button it goes between two different packet numbers

brazen blade
#

then what you were looking for is in multiple packets

#

depending on what you're looking for obviously

brazen blade
hasty scroll
#

I am ok with Metasploit, SO FAR, LOL

#

but I am not finding the txt file but I am looking in the html/text

#

section

#

I think I am done for awhile. I am not seeing the .txt file in either packet. I'll either get back on later or tomorrow for sure

#

Thanks for all your help!!!

brazen blade
#

Take a break! It's fine. The Wireshark room as a lot of input

#

I'm sure you'll get it tomorrow easily. If not, I might be here

#

otherwise someone else is

nocturne crest
#

I'm on the struggle bus. I working on Windows Command Line in cyber security 101. Task 4 What are the fileโ€™s contents in C:\Treasure\Hunt?

Could someone help? I just keep getting a access denied error.

woeful jungle
#

You first need to go to C:\Treasure\Hunt directory || cd C:\Treasure\Hunt ||

#

Than use the || dir || command in it to list files

#

You can than read the file contents with || more || or || type || command

nocturne crest
#

Thank you you let me try.

#

I'm sorry idk what I'm doing wrong. If I type more I getting syntax of command line is incorrect

#

same thing with type

woeful jungle
nocturne crest
#

user@WINSRV2022-CORE C:\Treasure\Hunt>cc

#

sorry not the cc

#

user@WINSRV2022-CORE C:\Treasure\Hunt>

woeful jungle
nocturne crest
#

I'm sorry I got it

#

I'm a dumb ass. I was looking at the wrong thing. Completely user error. THANK YOU so much for your help.

woeful jungle
hasty scroll
#

I am not sure what packet to be looking in. Wireshark: The Basics task 4

#

I have looked in the r4w packets, both of them and didn't see a thing

woeful jungle
#

Press save to save it on your machine

hasty scroll
#

Which packet number?

woeful jungle
#

You can sometimes export files from unencrypted pcap which were transmitted during communication

hasty scroll
#

it give me a bunch of objects but no text files really. I see wireshark.desktop

woeful jungle
hasty scroll
#

I don't see any text files

#

ads%3fclient=ca-pub-2309191948673629&random=1084443430285&lmt=1082467020&format=468x60_as&output=html&url=http%3A%2F%2Fwww.ethereal.com%2Fdownload

#

I see text/html. And then when I save it, it saves different things when I click on different lines.

woeful jungle
hasty scroll
#

Thank you, that was more confusing than it should have been

#

now where do i find the expert info section?

#

Nvm, I found it

hasty scroll
#

Only three are displayed

#

Wireshark: the basics task 5

woeful jungle
hasty scroll
#

I changed it slightly now I am not seeing anything

woeful jungle
hasty scroll
#

I will do it again like that then I'll send what it gives me

#

Cause I did it that way but I couldn't find how many packets. The number at the bottom of the screen was wrong

woeful jungle
hasty scroll
#

I don't see the number of packets

#

56820 was wrong

woeful jungle
hasty scroll
#

58620

woeful jungle
#

and see how many packets are displayed

#

The number you're looking is the total number of packets in the pcap file

hasty scroll
#

and where do I find the pcap file, lol

woeful jungle
hasty scroll
#

well the answer is not 58620

#

1089

woeful jungle
hasty scroll
#

nope

#

yep, I had it in the wrong spot, lol

#

I am beginning to really not like Wireshark, lol

woeful jungle
hasty scroll
#

I am almost done with the room

#

I have looked at this file before and now they want us to find how many artists there are and the names? Lol

#

I am not seeing anything but the first artist's name.

woeful jungle
hasty scroll
#

won't do it

#

neither works

woeful jungle
#

for packet 33790

hasty scroll
#

Thank you for your help tonight

#

I really do appreciate it. I may repeat this room this weekend.

noble sun
crimson silo
#

How would you retrieve the items in the current directory with size greater than 100? [for the sake of this question, avoid the use of quotes (" or ') in your answer]
Get-ChildItem | Where-Object Length -gt 100

woeful jungle
#

It is its ? ๐Ÿ™‚

crimson silo
#

property

woeful jungle
#

๐Ÿ™‚

#

Just add it to your command

crimson silo
#

thank you @woeful jungle @quaint plover ๐Ÿ˜ƒ

olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #102 - 74)

dark narwhal
#

Are the laptop tickets and THM vouchers over already?

I am keep completing rooms and only getting CYBER Crusader and Streak freeze tickets ๐Ÿ˜„

scarlet vine
gentle shoal
#

How many prizes left?

civic tartan
gentle shoal
civic tartan
gentle shoal
#

Also I got only 2 rooms left (not subscribed). Just gonna do it for fun now.

woeful jungle
magic arch
green tree
#

I'm doing the web application basic, but i don't get the flag for the POST command, it just says "user 2 is successfully updated", is there a problem?

civic tartan
#

i havent done it, but hint says to watch for case sensitivity, maybe not Country but country?

green tree
#

I did that (in the screenshot)

civic tartan
green tree
#

what do you mean, i changed if after looking at the hint

civic tartan
green tree
#

nope

civic tartan
# green tree nope

I just got the flag that way. In your screenshot the country:US is not saved yet.

stark jay
#

thank you for help. The issue was with my eyes. I just used password as a username... I should probably wear glasses.

olive fogBOT
#

Gave +1 Rep to @lavish trellis (current: #29 - 295)

green tree
#

Yes, i saved it but nothing change

civic tartan
green tree
#

Still no flag

civic tartan
#

then refresh the room maybe. I can click Go 100x and the flags will show every time..

green tree
#

I try that...

#

nothing x)

#

Got it, it was supposed to be lower-case...

brazen blade
#

I believe API requests should always be lowercase, Might be something to keep in mind

green tree
#

i forgot to say thank you @civic tartan !

olive fogBOT
#

Gave +1 Rep to @civic tartan (current: #32 - 254)

merry tide
#

Hey guys... I am stuck here...

#

What is the IP address of the host that sent packets larger than 15000 bytes?

#

Can anyone tell me

#

this is the filter I am using

#

tcpdump -r traffic.pcap 'ip[2:2] > 15000'

sharp ferry
#

Let me know if that solves it for you.

merry tide
olive fogBOT
#

Gave +1 Rep to @sharp ferry (current: #2326 - 1)

merry tide
#

really helpful

sharp ferry
#

Helpful if it works :-), I am on the journey too!

merry tide
#

me too

#

all the best for your journey

sharp ferry
#

๐Ÿ‘ Thanks, if I can help, let me know.

merry tide
#

sure thing

#

i will..

hasty scroll
#

Tcp: The basics. I am not getting anything back when I put a command in and was wondering why

#

or does it take a long time to get results

green tree
#

show the command please?

#

ah sorry

#

which task is it?

hasty scroll
#

The command is in the screenshot

#

It's not a specific task. I'm just trying to get a response like the examples show.

zealous lake
#

Traffic needs to be generated for tcpdump to capture it

inner falcon
#

^ there is a pcap file saved in the machine named traffic.pcap
This is useful for answering some of the questions in the tasks.

green tree
lavish trellis
gentle shoal
#

In the Blue room, how do I confirm if the exploit has run correctly?

green tree
#

@gentle shoal for the Recon part?

gentle shoal
#

I keep getting the Failed message.

#

I tried restarting the target machine too.

green tree
#

You should see the result in metasploit

#

if you don't have a reverse shell, it's a failure

gentle shoal
#

What could be the issue?
I got the "exploit completed but no session was created" message

civic tartan
gentle shoal
oak lark
#

finally jus one remain

woeful jungle
oak lark
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #76 - 95)

olive fogBOT
#

Gave +1 Rep to @lavish trellis (current: #29 - 296)

little spire
#

In the Hydra room, it's showing 16 correct passwords for molly. This can't be right. Has anyone else encountered this?

hasty scroll
#

Tcpdump: The Basics, task 3. Why is it not filtering out the ICMP traffic?

lavish trellis
hasty scroll
#

Lol, good question! How would I know or how do I do that?

#

I am new to this cybersecurity thing

lavish trellis
hasty scroll
#

How long would I ping for?

lavish trellis
# hasty scroll How long would I ping for?

you could do ping <IP of target> -c 5 to generate 5 ping, i. e. 10 ICMP messages if you prefer that instead of starting by default an infinite ping that you stop with Ctrl-C

lavish trellis
little spire
olive fogBOT
#

Gave +1 Rep to @lavish trellis (current: #29 - 297)

lavish trellis
hasty scroll
#

When I ping it, it still won't give me anything in the target box

#

it just resets the terminal

#

I have tried starting the tcpdump before I ping it and it still doesn't give me anything

lavish trellis
# hasty scroll

before you showed this screenshot for your tcpdump command, which was different from what you just post here:

hasty scroll
#

basically it just goes back to the prompt and the tcpdump command doesn't show

#

when I try to run the command again, it just listens

#

should I be putting the name of the file in there/

#

in the command

lavish trellis
hasty scroll
#

did I just post that? or is that an old one? Because that is not the IP address of either box

#

I see it now. I don't know where that came from. That is on the target box

#

Should I close it out and open another target box?

#

I figured it out. It was the wrong command that I was using

dense hatch
#

I am trying to complete task 4 of the tcpdump basics room. I tried tcpdump -r traffic.pcap greater 15000. The results look correct to a newbie like me, but the site does not like the IP address 192.168.124.137. Any tips would be helpful. Thanks!

lavish trellis
dense hatch
#

ok... can I get a bit more info? this question has thrown me thru a loop.

#

I got it.

#

Thank you

lavish trellis
# dense hatch ok... can I get a bit more info? this question has thrown me thru a loop.

your screenshot shows traffic between 2 devices:

  • one that sent traffic
  • one that received traffic
    the direction of the traffic is noted by tcpdump with the > character
    this means that the device before the > character is the source of the traffic and the device after the > character is the destination of the traffic
    back to the wording of the question: What is the IP address of the host that sent packets larger than 15000 bytes? From these words, you should understand that THM are after the device that originated the traffic, i. e. the source
    Final thought: consider using the -n option with your tcpdump command, so that IP addresses are not resolved into names; without the -n option you will not see the IP addresses properly
olive fogBOT
#

Gave +1 Rep to @lavish trellis (current: #29 - 299)

pearl sky
#

help me

woeful jungle
pearl sky
#

nvm my command was also right i was just writing the wrong output

#

this was it

gentle shoal
rapid jacinth
cursive dew
#

23%6โ€„=โ€„5 because 25 divided by 6 is 3, with a remainder of 5, i.e., 23โ€„=โ€„3โ€…ร—โ€…6โ€…+โ€…5

#

25 should be 23

cursive dew
#

Meant to say mod not divided by

brazen blade
#

ah nvm

#

I see the typo u mean

cursive dew
#

The line was copied from the room and it should be 23%6 = 5 because 23 mod 6 is 3

gentle shoal
reef compass
#

Finally done with the path. I would say around 75% of the course-load I had little experience with prior. It is a really beefy path with a lot of good information. I really enjoyed the tools and appreciated that there were hands-on exercises.

random egret
#

Anyone giving their premium vouchers?

green tree
#

Guys, i would have a question about CAPA task-4, i don't understand this question

left lion
#

Doesn't nmap by default run a tcp scan? I assume -sT flag is just for more clear specification or do I have my understanding mixed up

tepid lance
left lion
tepid lance
#

it gives you more granular control over the behavior, and a variety of other things that you might want to adjust when it comes to running scripts with nmap, and what not

left lion
tepid lance
#

but if you specify a syn scan with -sS it will simply fail

left lion
#

oh ok so if your not under elevated perms it will default to a tcp scan?

left lion
#

very interesting. I was like I swear I heard tcp being default, but didnt realize how the permissions affect it.

tepid lance
#

just nmap 8.8.8.8 or something with an unprivileged account and see if you are setting up full tcp connections or just responding with rst when the server rplies synack

left lion
left lion
tepid lance
#

that was just me running nmap 8.8.8.8 as an admin account, no -sS specifier

tepid lance
#

right

left lion
#

makes sense

tepid lance
#

if I was not an admin, it'd complete the handshake

#

and if you write a scanner to do a syn scan and forget to send rst, then you've made a slowloris tool lol

left lion
#

yea so a normal tcp scan rather than a syn scan. I suppose that is another way to determine if you are on a account that has elevated privilages or not but obviously there are more straight forward ways

tepid lance
tepid lance
#

so you could just use that to check as well, on a code-level

left lion
#

makes sense

tepid lance
fallen marsh
#

active directory is really annoying

oak lark
#

finally finished all ๐Ÿ™‚

woeful jungle
hasty scroll
#

Hashing Basics task 2. Why is it not giving me the file like the example shows?

wicked otter
dire violet
#

Good morning, i get 7 days streak, but i've some doubts about how it works. Let me explane better... when it is activated, will it have to be 7 days in a row or can it be 7 days in different periods? for example one day today, and the next day if it happens next week etc etc until reaching the threshold of 7? I hope I explained myself well

hasty scroll
#

Hashing the basics. I use the answer I found online and it says it's wrong, I don't get it

wicked otter
noble sinew
#

Hi guys, Im currently on pre security after having completed intro to cyber security. I was going to do complete beginner before moving to jr penetration tester however now I see a new cyber security 101 path.

#

Where would this fit in?

woeful jungle
#

Go with Cyber 101

noble sinew
woeful jungle
lavish trellis
cursive dew
#

how do i stop getting streak freeze and discord role tickets

olive fogBOT
#

Gave +1 Rep to @lavish trellis (current: #29 - 300)

young heath
cursive dew
#

:(

#

have they confirmed that all the prizes were won already?

young heath
cursive dew
#

guess i'll finish the path to inflate my rank

#

i'll probably hit top 5k when i'm done lol

young heath
cursive dew
gloomy sundial
#

โœ‹๐Ÿผall room two tickets, havenโ€™t got the final one for any except 1st row. Finished all the rooms

stone pelican
#

Did anyone get a prize besides streak freezes? I have 2 of every single one of them, yet I keep getting streak freezes. I also uploaded a video, and nothing. I feel ๐Ÿ˜ช

green tree
#

Same same

magic arch
#

๐Ÿฅฒ

cursive dew
#

has anyone posted their prizes yet?

hasty scroll
#

Metasploit: Exploitation room task 3. Why is it asking me to run as non root user when the example shows it as root user?

vague zealot
#

Just use sudo

oak lark
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #69 - 114)

rugged minnow
#

Hello guys, im stuck on a easy room on Hashing at this question

rugged minnow
#

I crack it alone on my kali but still not working

woeful jungle
rugged minnow
#

why the hell i find another password with John the ripper ๐Ÿ˜ซ

woeful jungle
dusk valley
#

https://tryhackme.com/r/room/socfundamentals
What is the way i should format the answer on task 3, 1uestion 1: Alert triage and reporting is the responsibility of?

Soc analyst level * is not accepted but i cant imagine one of the other roles.

woeful jungle
#

Replace * with the actual level

dusk valley
#

Did that but it does not accept my answer...

woeful jungle
dusk valley
#

Had to use the ( ) ... sill me

woeful jungle
#

Maybe your answer is right but formatting is incorrect

dusk valley
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #64 - 122)

woeful jungle
latent birch
#

Do we have to clear all to get gifts ?

woeful jungle
latent birch
#

Thank you

woeful jungle
latent birch
#

Yeah but i have not enough time to clear ๐Ÿ˜ฆ

oak lark
coarse jasper
#

how can i connect ti rdp ?

woeful jungle
coarse jasper
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #62 - 128)

woeful jungle
rugged minnow
#

IM STUCK STEPBRO

#

i don't know why maybe the syntax ?

woeful jungle
#

Use using different font for " double-quotes

tawdry gull
rugged minnow
#

it works

#

but..

woeful jungle
hasty scroll
#

anybody on to help?

lavish trellis
hasty scroll
# lavish trellis let's just start ๐Ÿ™ƒ

Lol, I just finished the room and can't remember what I needed help with now but I was able to figure it out. Thank you though, I just saw this. Not sure why my notifcations are quiet on me.

olive fogBOT
#

Gave +1 Rep to @lavish trellis (current: #29 - 305)

hasty scroll
#

In the Blue room, everytime a click on something this pop up keeps coming up

violet orchid
#

do not allow anything nor click any of the links

lavish trellis
violet orchid
#

@hasty scroll

hasty scroll
olive fogBOT
#

Gave +1 Rep to @violet orchid (current: #640 - 7)

hasty scroll
lavish trellis
hasty scroll
lavish trellis
lavish trellis
hasty scroll
#

ok thank you

merry tide
#

laptop stock over?

#

๐Ÿ˜ฆ

#

??????

tawdry gull
#

wow so crazy how I completed 100% of the cyber sec 101 path and have gotten all of the tickets x2 from the start and like last 20 rooms all I got was streak freezes...

#

I was hoping to get a tshirt but oh well ๐Ÿ™ƒ

woeful jungle
tawdry gull
#

right

#

and they didn't review my video that I uploaded to yt and submitted on like day 2 yet

spiral trail
tawdry gull
compact solar
#

I have completed some rooms, if I buy premium now will I get tickets for those completed rooms also??

woeful jungle
compact solar
#

No I'm asking, for premium users we get 2 tickets n for free users only 1 right for every room, so my question if I buy now will I get that extra ticket for completed rooms

woeful jungle
hot cedar
#

Finally finished whole path it was fun! coolguy

woeful jungle
brazen kestrel
civic tartan
brazen blade
#

of 10$ help ya out?

#

its pound actually, so a 10pound voucher of any use to you?

indigo garden
#

Does anyone know if this pathway will stay free after the event? I will definitely not have enough time to complete before the ticket event closes but would like to

indigo garden
#

Thank you:)

calm solstice
woeful jungle
tawdry gull
errant sparrow
#

Networking Core Protocols, I don't think this is supposed to be hard but the instructions said use telnet to get the flag.html file but it keeps telling me bad request

#

like ?

lavish trellis
errant sparrow
#

yeah in that room you use GET, press enter, and then use host, but it just immediately returns bad request for me here and closes the connection before I can specify host

tulip linden
#

Because it's not GET /flag.html

errant sparrow
#

okay yeah apparently because it's case sensitive lol thanks๐Ÿ˜“ ๐Ÿ˜ฉ

rapid jacinth
#

is there any one who did gobuster?

woeful jungle
void prairie
#

In Intro to SQL I'd be interested to know if there's a recommended one liner to extract the answer on the last question of the penultimate task, since the two items have nothing in common to group and concatenate by. The only solution I could see was to create a new boolean column for items with an amount not ending in 0, and then group by that, but I feel I might have misunderstood something.

rapid jacinth
void prairie
olive fogBOT
#

Gave +1 Rep to @lavish trellis (current: #29 - 306)

hollow olive
#

Some help Cyber Security Advanced Roadmap

#

Give Recourses

noble sinew
#

when are the tickets over and done witg

tulip linden
tepid lance
#

in the webhacking room, if you find the flag by accessing the /admin page with SSRF, is there a place to redeem that flag anywhere? Or is it just yours to hang on your wall in your room?

tepid lance
errant sparrow
#

Monikerlink room, it says if I have an authentication error to check i've entered the IPs of the target and attacker right, but I can't tell what's wrong about it

tepid lance
#

and then sender email you set as an IP, but it's not supposed to be

#

that's supposed to be an email address

errant sparrow
#

no, it said to put the attackbox IP there, and the server was MAILSERVER before I changed it which it said to do

noble sinew
woeful jungle
shy rose
#

after completing multiple rooms, i'm getting repeated tickets of 1D, 7D streak freeze or cyber badge

red pilot
#

Coming from JS Essentials.
So when I find obfuscated JS code in a browser it doesn't immediately mean that's it's from a bad actor?

woeful jungle
red pilot
#

But your 2nd sentence, isn't this a kind of invalid point. This would just be security by obscurity.

woeful jungle
red pilot
#

Thanks for explaining.
At least I now know that minification and obfuscation is kind of the same thing and when I see obfuscated code, it doesn't necessarily mean that's it's a bad actor.

twin egret
#

Network concepts task 7 what flag did you get

woeful jungle
twin egret
broken furnace
#

i got a swag shop voucher. how i do redeem it?

woeful jungle
broken furnace
#

alright, thanks. I'll wait a moment then

warm glacier
#

Can I gift a month Premium Membership to a friend?

#

I won from Cyber Security 101 Pathway.

civic tartan
warm glacier
olive fogBOT
#

Gave +1 Rep to @civic tartan (current: #32 - 264)

civic tartan
warm glacier
#

I received a LInk. Not a voucher.

civic tartan
warm glacier
#

Yes I have got it.

#

Thanks

#

Did you participate? @civic tartan

civic tartan
#

๐Ÿคทโ€โ™‚๏ธ

warm glacier
#

They did not mention expiry date does it mean that It never expire. @civic tartan

warm glacier
#

Is it laptop or DEFCON33 Ticket? @civic tartan

civic tartan
warm glacier
warm glacier
warm glacier
warm glacier
warm glacier
warm glacier
# civic tartan

I am nearly finish so I will send you once I achieve CERT.

ionic swan
#

Is the result been announced?

oak lark
#

hey guys, how can i get voucher prize?

woeful jungle
woeful jungle
brazen blade
oak lark
oak lark
brazen blade
#

wdym?

#

You said you got a voucher prize

#

and im asking you when you got the last ticket for it

oak lark
short radish
#

i might be dumb but how do i use rdp for the ad task in the winad room?

woeful jungle
short radish
#

thanks <3

eager reef
#

hello

woeful jungle
eager reef
#

How can I get verified?

eager reef
#

I searched for settings on the tryhackme site in my profile but couldn't find it

olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #35 - 232)

eager reef
#

@woeful jungle bro thanks

woeful jungle
eager reef
#

Sorry for disturbing your time๐Ÿ˜”

woeful jungle
plain oxide
#

hi

twilit lodge
quartz igloo
#

Hi

woeful jungle
quartz igloo
#

Thank you! I'm trying to figure out how to get the subscriber role. Kindly point me in the right direction

woeful jungle
quartz igloo
#

I am a sub ๐Ÿ˜„

#

Ah. I got it. Came across an article named "Discord: How do I verify my TryHackMe account?"

#

I got it from here!

quartz igloo
#

Thanks! โค๏ธ

woeful jungle
quartz igloo
#

๐Ÿ˜ Orange 4 eva!

#

lmao. even my account color is orange

north tiger
#

I completed some room cyber security 101 but I cannt clamin the ticket. How to get the ticket?

woeful jungle
#

It ended on November 4th

north tiger
#

oh sorry, I updated late. thanks so much

woeful jungle
north tiger
mortal temple
lofty pond
#

Hi, don't know if anyone knows this. I am on last task of sqlmap room. I can see data in all fields of the db, but the password data is all \n\n\n\n....it's not even a hash that I could try to crack. How do I get this password? Please and thanks for your help

lofty pond
#

Sqlmap -u 'the-url-i-got-from-headers' -D ai -T user --dump --level=5

#

I can see data from all other columns of this table except the password

woeful jungle
lofty pond
#

Tried dump all as well....it's still \n\n

#

KGB vi sprashivute Ruskin?

#

I learnt a bit of Russian back in the day

#

Loved it

#

I am also happy that I can type the whole sqlmap command on my phone....I already shutdown my laptop and thought let's ask around on discord...I m new to all this

woeful jungle
lofty pond
#

I think url is not the issue as I can see the rest of table data..

woeful jungle
lofty pond
#

I forgot the exact url as I shutdown my laptop and I m just on my phone

woeful jungle
lofty pond
#

Oh yeah....ok I will try again and report back if any issues...thanks a lot Chief

woeful jungle
unborn estuary
#

Hello guys, what happened with those users who won a DEF CON tickets ? from CyberSecurity10`

hollow inlet
#

Anyone want to swap codes for a swag ยฃ20 baseball cap and a thm t shirt with thm premium coupon?

oak lark
#

guys i ddint get code of 20 euro swag? how can i get it?

woeful jungle
oak lark
#

what should i do?

woeful jungle
oak lark
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #24 - 365)

nova isle
#

More like Cybersecurity 1-0-DONE! ๐Ÿ˜„ ๐Ÿ‘ Really enjoyed this one.

woeful jungle
lofty pond
#

Hello, i am learning the REMnux VM to analyse the malicious files. When simulating a fake network, the task uses attack-box to open a fake page. But all other commands/actions are done inside the REMnux VM. So why are we using attack-box to open the fake site? thank you

woeful jungle
lofty pond
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #21 - 422)

zenith herald
#

Ok so I'm on the Metasploit: Exploitation room
I've tried using eternal blue but it keeps telling me The target is not vulnerable.

zenith herald
civic tartan
zenith herald
zenith herald
civic tartan
sour goblet
#

Also it must run on vulnerable OS version, and to see if it's vulnerable do nmap -p445 --script smb-vuln-ms17-010 <target_ip>

sour goblet
#

It may have already recieved MS17-010 patch so it renders it immune but it should be vulnerable

#

If unpatched

zenith herald
civic tartan
zenith herald
#

ok

#

Terminated it and started a new target machine

civic tartan
sour goblet
zenith herald
#

I'm in

zenith herald
#

So I found the Hash for user Pirate
But it won't accept my answer

tulip linden
#

Did you get correct hash?

zenith herald
#

I'm I supposed to include pirate: in the answer?

zenith herald
tulip linden
zenith herald
tulip linden
#

Ok, you're giving toooo much info.

#

One of them, is the NTLM hash, I'll allow you to research it ๐Ÿ˜‰

prime socket
#

is it normal to have this long of a machine time?

#

it's from the wireshark room

woeful jungle
prime socket
#

the machine isn't working properly and lagging here and there

#

and giving outrageously long times like this

woeful jungle
prime socket
#

same thing

woeful jungle
prime socket
prime socket
#

can you try running the machine and see if it works on for you

#

maybe something is wrong on their end

woeful jungle
prime socket
woeful jungle
prime socket
#

i tried a different browser and the tryhackme website isn't even loading

#

although it opens on chrome

woeful jungle
woeful jungle
#

Does it work buddy ๐Ÿ™‚ ?

prime socket
#

its loading

woeful jungle
prime socket
#

yeah this one is working a lot faster than mine

#

thanks buddy

#

i'll use this one to complete this room then report the issue to support

woeful jungle
zenith herald
#

I'm on the Active Directory Basics room
It's telling me to remote desktop into the windows machine
How do I do that?

pulsar bloom
#

phew done with wireshark room

#

next tcpdump

woeful jungle
stray stream
#

Out of curiosity, are there any certs people plan to take after finishing this path? Like ceh or any CompTIA ones?

woeful jungle
#
TryHackMe

CompTIA PenTest+ is for cybersecurity professionals tasked with penetration testing and vulnerability management. Use this pathway as supporting content and pre-preparation for the CompTIA certification exam. Upon completing this pathway get 10% off the exam.

stray stream
#

I was planning on taking all the paths (or at least as much as I can during this holiday break), trying to make a break into the security field, I have a lot of IT experiences, just not specifically security

#

And it seems like I need to get pass the hr recruiters

woeful jungle
stray stream
#

Thanks ๐Ÿ™‚

golden mantle
torpid yoke
#

||Hey, I'm struggling with answering the OS version of the Windows VM. Using systteminfo cmd spits out; OS Version: 10.0.20348 N/A Build 20348. It doesn't accept my answer. Tips?||

woeful jungle
torpid yoke
#

Task 2

woeful jungle
torpid yoke
woeful jungle
sacred orchid
#

I haven't done the pre-security path, is it bad if I do the Cyber Security 101 path before ?

#

because i don't feel like I need to do it

#

Idk if the pre-security path contain knowledge that I should not miss

woeful jungle
sacred orchid
#

ok thanks

verbal wolf
#

Hi

woeful jungle
tropic sorrel
#

Hi, can someone help me with this question ? "What flag did you get when you viewed the page?" Networking Concepts module "task 7" Telnet.

torpid yoke
tropic sorrel
torpid yoke
#

Gotchu, glad you got it sorted. Good luck moving forward ๐Ÿ˜„

woeful jungle
olive fogBOT
#

Gave +1 Rep to @wooden rock (current: #2486 - 1)

tropic sorrel
torpid yoke
#

GET / HTTP/.1.1 made a lot more sense to me personally a bit further down the line, as I understood what the "/" after GET actually did in practice. You should be just around the corner if you keep going ๐Ÿ‘

woeful jungle
tropic sorrel
torpid yoke
torpid yoke
woeful jungle
torpid yoke
torpid yoke
#

Like this?

woeful jungle
torpid yoke
woeful jungle
torpid yoke
woeful jungle
# torpid yoke The task is; One of the packets contains login credentials. What password did th...

You can follow streams instead of inspecting packet by packet , but there will probably be multiple streams so you will still need to invest some time ๐Ÿ˜„ . You can also perform wildcard searches for common patterns that you're looking for ( For example : frame contains "username" which will check if the string username is present in any of the frames - of course traffic needs to be decrypted beforehand ) ๐Ÿ˜„

woeful jungle
torpid yoke
#

So how come there is nothing in the result list?

woeful jungle
#

Delete all present filters before that and exit packet stream search

torpid yoke
#

Same, nothing.

#

I also tried frame contains

woeful jungle
#

or http contains ".*pass.*"

torpid yoke
#

||Thanks. Worked with http2 contains "pass"||

torpid yoke
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #7 - 1247)

torpid yoke
#

good evening fellas, I'm new to Cyber Security 101 and want to warn you, that I 'll have a huge amount of question in spe kekw donยดt be too hard to me ๐Ÿ˜‰

woeful jungle
torpid yoke
#

how can I enable the modules that I solved before to answer the questions in the end of each module again ?

woeful jungle
#

You want to restart the room ๐Ÿ™‚ ?

torpid yoke
woeful jungle
torpid yoke
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #6 - 1354)

woeful jungle
inland crow
woeful jungle
#

It's already initialized ๐Ÿ™‚

inland crow
#

Oh yeah, you're right. Thanks

torpid yoke
#

||Am I not correct saying the name and detected version is lighttpd 1.4.74?||

tulip linden
torpid yoke
torpid yoke
tulip linden
#

lighttpd 1.4.74

#

Try that one, copy/paste it

torpid yoke
#

Eh.. I did a refresh of the page, works now ๐Ÿฅฒ

tulip linden
torpid yoke
#

I got it on Stream if you want it as a bug, if not I'll just move on

inland crow
#

Is there a way I could've found this instead of taking the hint? Nmap -sV [target-ip] doesn't really show exact service versions

inland crow
inland crow
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #5 - 1404)

tulip linden
#

Metasploit also checks.

torpid yoke
sacred orchid
#

On average, how long does it take a person to complete this path ?

woeful jungle
sacred orchid
#

ok

torpid yoke
#

What should I be able to after finishing introduction and cyber-security-101 paths ? Is that the point considering certifications or would it be to earlier at that moment ? Thanks in advance

woeful jungle
torpid yoke
woeful jungle
torpid yoke
woeful jungle
#

Time depends from person to person

coarse loom
#

Hi, in Windows and AD Fundamentals-> Active directory basics: task 4 , How do i connect to Phillip account with RDP ?

woeful jungle
coarse loom
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #5 - 1467)

coarse loom
woeful jungle
coarse loom
woeful jungle
coarse loom
inland crow
#

Anyone else do way longer over the metasploit rooms than any other previous ones? even though the blue room was pretty simple

woeful jungle
umbral socket
steady relic
#

Bought annual subscription to finish this path, along with participating AoC. Did learnt a lot more than I expected, guess I'm still a beginner...

woeful jungle
coarse loom
#

Hi, does anyone know if try hack me attackbox in some rooms have kali Linux automatically on it when we open the attackbox ?

woeful jungle
solemn wyvern
#

Loving the THM platform. Keeping me out of trouble these days.

quasi bridge
#

Same, been grinding this path for 6 hours and took mad notes

woeful jungle
#

@solemn wyvern @quasi bridge Great job guys , keep up the good work ๐Ÿ™‚

solemn wyvern
woeful jungle
smoky timber
#

Is it possible to get a job if someone finish cyber security 101 ?

woeful jungle
inland crow
#

Guys I've tried editing the payload value username from admin to guest and then pasting this JWT string into the POST request for /flag. Everything feels like im doing the right thing but I get the message saying it's not right.

woeful jungle
inland crow
#

So they explain a JWT cookie has a header.payload.signature format, i've only edited the header, tried numerous sites, also made sure to keep it HS256.

#

Also tried setting alg to none and user to admin like they do in the explaination.

woeful jungle
inland crow
#

Like an empty signature?

woeful jungle
inland crow
#

Thanks

quasi bridge
#

This grind is insane, I spend 6 hours only to get 2 modules done๐Ÿ˜

umbral socket
#

Welcome to the club!!

woeful jungle
errant fossil
#

Is there any role in cybersecurity that has a mix of red and blue team activities? I kind of love both offensive and defensive ๐Ÿ™‚

coarse loom
#

On tryhackme the Metasploit rooms it is said to be easy and to last like 30 minutes. But it can take few hours to do and understand... Does that mean that other rooms who are labeled as "hard" will be extremely complicated and long to do or just that it require background knowledge that would make it hard for a beginner with no background knowledge ?

woeful jungle
coarse loom
woeful jungle
coarse loom
#

yes i know, what is the path you did ? And i see there is too much information to remember. I'm forced to find a way to search easily and quickly for any information because it is impossible to remember everything there is too much. Just to command line sometime in metasploit it is too long and complicated to remember. In hacking there is just too much information to grasp it can be soo hard.

woeful jungle
rain elbow
cloud fossil
#

I'm having some trouble with the Gobuster room. I followed the instructions to edit and save resolved.conf, used the systemctl restart command, and confirmed that the changes to resolved.conf saved. However, every time I attempt to run gobuster I get the following error: "Error: error on running gobuster: unable to connect to http://www.offensivetools.thm/: Get "http://www.offensivetools.thm/": dial tcp: lookup www.offensivetools.thm on 127.0.0.53:53: no such host"

Is anyone else experiencing this? I am doing this room as a refresher and am starting to question my sanity.

feral rivet
cloud fossil
#

Thanks you kind sir/madame

cloud fossil
olive fogBOT
#

Gave +1 Rep to @feral rivet (current: #2555 - 1)

coarse loom
#

Hi, in the room "sql fundamentals" , i needed to instal mysql because the machine did not recognise the command mysql, but now that i installed it, i do the command mysql and when i enter the password it says: ERROR 2002 (HY000): Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (2)

#

what does that mean and how does i fix that ?

#

ok i think i found, it's because i was on the attackbox but now i tried on the target machine and it work fine

feral rivet
#

Hey! So, I'm in the REMnux: Getting Started room and this is more of a question to understand what's actually happening using iNetSim

In Task 4, we configured to set the DNS as our attackbox's ip

then we tried to download files to the attackbox from that ip to emulate the malware behavior right?

Where are these files stored in the first place that it's retrieving from?

feral rivet
feral rivet
olive fogBOT
#

Gave +1 Rep to @tulip linden (current: #1 - 3204)

torpid yoke
#

hey guys, your the same problem ?

woeful jungle
torpid yoke
#

okay

#

I can't fix it

woeful jungle
torpid yoke
woeful jungle
torpid yoke
#

I went to modify the domain in /etc/systemd/resolver.conf

woeful jungle
torpid yoke
#

ok

steady roost
#

Which section should i do next, exploitation basics, cryptography or web hacking

#

im thinking itd probably be better to learn more about cryptography before the other sections

woeful jungle
tough scaffold
#

Hello

woeful jungle
quasi bridge
#

Finally finished the path

woeful jungle
jovial dirge
# quasi bridge Finally finished the path

I am determined to finish this path and continue onto the Pentester path. I am finishing up the Active Directory section. It's hard to stay motivated sometimes when I dont have a buddy to work with, like a workout partner to keep you accountable, but I guess thats what the discords for ๐Ÿคทโ€โ™‚๏ธ

woeful jungle
jovial dirge
#

that's fair, motivation can only get you so far

woeful jungle
jovial dirge
#

I will keep updated here to keep myself accountable! Hopefully I can finish the track by the end of the month, a great start to the year

woeful jungle
quasi bridge
jovial dirge
quasi bridge
jovial dirge
jovial dirge
#

finished up the AD module ๐Ÿ™Œ

#

command line should be fun

woeful jungle
sick crystal
forest quest
#

Hi, anyone else having Issiues in the Gobuster room? Where the Target domain isnt reachable even if the DNS is configured Properly? Or am I doing sth wrong?

woeful jungle
forest quest
#

ok, will do ๐Ÿ˜„

forest quest
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #4 - 1986)

umbral obsidian
#

I have a question about Wireshark Basics room, specifically task number 4, how can I extract .txt file from the image ?

woeful jungle
umbral obsidian
umbral obsidian
woeful jungle
# umbral obsidian Yes, task number 4

Click on File > Export object > HTTP > note.txt , that's the file you're insterested in ๐Ÿ™‚ . Even the task says .txt file ๐Ÿ™‚ . This from your screenshot is an image ๐Ÿ™‚ .

umbral obsidian
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #4 - 1994)

coarse loom
#

Hi, i do the basic pentesting lab and when i try gobuster it always says Error: unknown shorthand flag: 'u' in -u . I wrote this command: gobuster -w /Desktop/Tools/wordlists/dirbuster/directory-list-2.3-medium.txt -u http://10.10.237.188/ , why it doesn't work with me ? I looked at many video on youtube but couldn't find the problem.

feral rivet
coarse loom
#

ok but it's the Basic pentesting lab CTF in the challenge rooms. And finally i just used the same command as shown in the course and it seem to work.

#

thanks still

coarse loom
#

i just finished the room challenge(Basic pentesting) and there was many problem like few command that didn't worked even when i did the same exact thing as the ones shown in the walkthrough. One time when i used ssh2john , it says "command not found" . many time things where not working like they should. I think Try Hack Me machine are full of problems/bugs... It prevent me from just focusing on doing the job like i should. It's just bad for learning when the right things don't even work.

#

Not all machines but just sometimes i mean.

woeful jungle
coarse loom
#

Ok but, in rooms, challenges, does it happen often bugs or anythings that make command not work or that make things not happen like they should ?

torpid yoke
#

hi!

#

I'm doing channel on reverse shell, and i'm stuck I can't fix

woeful jungle
torpid yoke
woeful jungle
torpid yoke
#

how to do this target it connect on my host ?

woeful jungle
torpid yoke
#

there are 3 urls

woeful jungle
torpid yoke
woeful jungle
# torpid yoke look

Yeah , 2nd URL , enter that into the browser , the one with port 8081 specified ๐Ÿ™‚

torpid yoke
#

yes I did it

#

always nothing pepehands

#

my brain smoke, I think, I need a break

woeful jungle
true wren
#

Is your given URL of the attack machine or the target machine?

#

https://hackertarget.com/gobuster-tutorial/ Here's the resource link that might come in handy for you too

rapid breach
#

why i can't see the start the virtual machine button?

woeful jungle
#

Go to Task 1 and press green Start machine button ๐Ÿ˜„

rapid breach
#

i also thought so but then i checked the other rooms. the button that was normally there seems to be missing in all the rooms i have checked. is this normal?

woeful jungle
rapid breach
#

thanks for fast response

rapid breach
#

i keep getting this notification, is there smt i can do to fix it?

woeful jungle
novel lintel
#

Hi guys, I'm a little stuck in a task, maybe you have an advice for me. I'm currrently working on Metasploit: Exploitation and got a Meterpreter shell and trying to hashdump the shadow file via the meterpreter shell but keep getting a ruby error ( Failed to open file: /etc/security/opasswd: core_channel_open: Operation failed: ). I don't know how to handle that.

woeful jungle
novel lintel
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #3 - 2126)

coarse loom
#

Hi, in Linux Privilege Escalation, why do we need to find any process that we can run as root user, like whatโ€™s the point with that ? I think i did not understood that.

#

When we do a shell/ reverse shell on target machineโ€ฆ

#

Itโ€™s about this thing ยซย SUIDย ยป

woeful jungle
coarse loom
#

Yes but i still donโ€™t see the sense. It seems to be any process like if itโ€™s not important which one. How does running any process make me root ? Or does itโ€™s only to use some process that we need because they do something useful ?

leaden roost
#

quick question, should i also study the defensive modules on this path if i want to get into pentesting?

woeful jungle
leaden roost
#

didnโ€™t thought about that ๐Ÿ˜‚ you are right thanks

tulip linden
oblique kayak
#

Hi! Iโ€™m experiencing an issue with the "Gobuster: The Basics" lab. The mentioned domains, such as example.thm and offensivetools.thm, cannot be scanned. The error I receive is:
Unable to validate base domain: example.thm (lookup example.thm on 127.0.0.53:53: no such host).
I have followed all the instructions from Task 2 on the AttackBox and even restarted lab and I am still stuck with it. What is wrong with it?

woeful jungle
oblique kayak
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #3 - 2182)

woeful jungle
rain elbow
oblique kayak
rain elbow
coarse loom
#

Hi, is there a way to know the total amount of people in this channel ?

coarse loom
#

ok thanks and i mean only in this group "cybersecurity101"

woeful jungle
sick onyx
#

/r/room/blue is not working for me

woeful jungle
sick onyx
#

after running the exploit and trying to convert the shell to a meterpreter shell, it never converts to a meterpreter shell

#

I retried the entire room 2 times

woeful jungle
sick onyx
#

I get this

#

wait now it worked

woeful jungle
steady roost
#

for hashing basics task 6, hashcat is telling me the status is cracked but i dont understand where in this output the cracked hash info would be?

woeful jungle
#

<hash>:<result>

#

Or use hashcat --show

steady roost
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #2 - 2424)

woeful jungle
steady roost
woeful jungle
raw pelican
#

Does anyone in here use a live boot version of kali? it seems most like vms. Is there a readon why?

woeful jungle
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #2 - 2440)

raw pelican
#

Is anyone else using the helpful hackers video walk through?

urban sand
#

Just got two more sections to go ๐Ÿ˜ฎโ€๐Ÿ’จ

#

Think Iโ€™m gonna double back on the path Iโ€™m really starting to see just how important the fundamental skills are vs just learning a ton of tools

woeful jungle
steady roost
#

for john the ripper basics task 5, im trying to crack this nthash but im getting a "no password hashes loaded" error
https://gyazo.com/1af8dfaf872db904eed4090f623b69f6

when i try to check how to fix this its telling me to mess with the /etc/shadow file but that must be wrong because i cant use sudo on the thm machine? i feel like maybe its a syntax error but john isnt giving me any other info other than "no password hashes loaded"
https://gyazo.com/7eba68aaf49d802ae390c1edc65048fa

steady roost
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #2 - 2482)

woeful jungle
sick onyx
#

in r/room/gobusterthebasics it seems like the dns is not working. I set it up according to the tutorial in the room (I changed and uncommented the DNS value in /etc/systemd/resolved.conf and executed sudo systemctl restart systemd-resolved afterwards). When I try to ping offensivetools.thm I get Name or service not known

#

do I need to change the nameserver value in /etc/resolv.conf? they do not tell me to do that in the room

woeful jungle
sick onyx
#

that seems to work, thanks

rapid breach
#

i am here at the same room. i couldn't get what is going wrong

rapid breach
woeful jungle
rapid breach
#

i am still getting the same error :/