#site-support
1 messages · Page 3 of 1
lollll i put the same ques there but tot i'd be better to put here tho okkk im gonna go there
right im stuck on getting the vpn diagnostic tool to work
i git cloned the repo then went cd Downloads/openvpn-troubleshooting chmod +x on thm-troubleshoot and now when i run sudo thm-troubleshoot im getting command not found
any ideas
Again you are a hero kind sir
Heyyy figured it out I had another instance of openvpn running. thanks for the help I appreicaite it
Gave +1 Rep to @gray loom
Using the attack box and getting this error with Agent T, probably due to iOS. Is it not compatible with Firefox iOS? Loads up fine and works, just the script error doesn’t go away
Seems to be the case, loads up fine on safari.
Hey all, I'm trying to do the password spray attack task in the Password Attacks room, and when I use hydra it gives me this error:
[ERROR] could not connect to ssh://10.10.40.209:22 - kex error : no match for method server host key algo: server [ssh-rsa,rsa-sha2-512,rsa-sha2-256,ecdsa-sha2-nistp256,ssh-ed25519], client [ssh-dss]
However ssh-ing to that IP works fine outside of hydra. Any idea what I'm doing wrong here?
(I'm using a Kali VM not the attack box)
I tried to modify this info for ssh-dss instead of ssh-ed25519 as described, but unfortunately it did not solve the problem. I am guessing it's something to do with the Kali VM setup as it works fine on the AttackBox
that's possible
but u should try to google for more solution
I did, and there are only solutions for ssh itself, rather than the ssh mode for hydra. I have no issues using ssh from my VM, it's just hydra that is having issues connecting through ssh
My experience is that it's far more than a week. I've been waiting months after multiple requests via multiple methods. The response in Discord is very good and sometimes amazing. But support has been a weakness for an otherwise stellar operation.
then reinstall hydra might fix the problem rather than reinstall your whole kali
thanks, I'll give this a go
Hi there, any issues with OpenVPN as I can't connect to any servers and I generally use EU-Regular-3
!vpnscript
This is not the issue. OpenVPN is not creating an IP for EU-Regular-3 on the TryHackMe website. It was working yesterday and now it's not.
how about other region?
None are working
is there any specific group created for Follina discussions
The access page is not reliable to verify if you are connected.
Use curl 10.10.10.10/whoami in your terminal, if it replies with your tun0 IP you are successfully connected
#recent-threats-module would be a channel that would fit for the Follina room
When I go to OpenVPN Access Details it is showing:
VPN Server Name EU-Regular-3
Connected X
Internal Virtual IP Address 0.0.0.0
I am refreshing constantly, tried other servers. It has nothing to do with my side.
I have been using THM for quite sometime.
I am doing the Windows Privilege Escalation via TCM Security.
First time I am experiencing this with THM as it has worked fine everytime.
Yes and I already told you that the access page is not reliable, sometimes it's not showing that you are connected ?
could someone help me on this
i did something with a command of 600 chmod rsapriv
and this happened
i dont know how to change it
You did not stabilized the shell, did you ?
how do i stabilize it ?
I'm assuming you got initial foothold as one the users via netcat (like www-data).
If yes, then if you know you're going to use text editors, then you should stabilize the shell. It ensures that you do not kill the shell accidentally by pressing Ctrl+C.
This room covers all these things https://tryhackme.com/room/introtoshells
i just want to exit here
i did this by accident and i got no idea how to exit
im not doing a room or anything
What are you experiencing?
However testing it in my Kali Machine it doesn't work
Or should I test another VIP VPN?
^
xD
Oh I got I got it
@gray loom @weary spindle Thanks! And sorry to bother with that question
Gave +1 Rep to @gray loom
😅
Oh, should I give thanks to @weary spindle to give a +1 too?
@weary spindle Thanks!
You're not a bother, everyone is at different points in their learning, and don't worry about it (the rep) 

Gave +1 Rep to @weary spindle
How do brute force
Hello. I am wondering how do I invite people to a workspace. No matter what I click inside my workspace I get redirected to https://tryhackme.com/business
Need a mod to change my token THM link on my discord account please, my school just made me create a new acc :/
Do you just want the token removed from your current discord account?
Exact please ! To put my new one !
stupid bot
Thank you so much for your help sir !
!tokenremove 217382513608228865
Done, no more entry with UID "217382513608228865".
Thank you very much ! Have a good day / night ! 😄
Gave +1 Rep to @broken bear
Good luck
Apologies if this is in the wrong channel as I wasn't too sure where to ask this....
Is it possible to somehow have my username changed on THM so that it can match other platforms?
Hey, how long does it usually take to get a data export?
Yes, there is,
Just E-mail support from your account E-mail politely and it will be changed. (Unless of course you choose a username that is taken.
Any else THM web down? Its showing 500 internal error on my phone
All fine for me.
For Task 5 in TheHive room the url is https, it doesn't work and should be http
try hackme did an auto subscription with my friend credit card
how can i cancel it an return ...
ow okey thank you
Gave +1 Rep to @weary spindle
on the linux server forensics room i can only ssh from attackbox I have tried regenerating the ovpn file and changing from udp to tcp i can access the web server but not ssh
Please do not send the same message multiple times, ask once and please wait patiently. Everyone here is a volunteer.
I unsent it from room help and sent it here since its more of a techsuport question
Hey guys, can anyone help me?
I've one doubt. I wanna write writeups on a tryhackme room. But if I do copy paste the whole things and in between solve those questions in my article, will that be okay?
P.S. I don't want any copyright issue in my article which would be published on Hashnode.
It would be better if any Staff could clear this issue
#site-support hi good folks im working on enumerating nfs anf after i mount the share there are no filles in the directory.. pls help... thank you
thank you i think i figured it 🙂
Happened same glitch to me
Restart the lab
Hi Is It possible to reset all the rooms I have completed while keeping my level?
u can reset progress in each room
hello, If I use hackmachine(web version) then does not work ctrl + v / ctrl + c between my machine and hack machine. How to fix it?
Full screen the machine, or there is a little grey/white arrow on the left hand side of the attackbox.
then right click to paste
thank you so much
i wanted to know what is a open vpn machine
ik what OpenVPN is, I've used it but i don't understand what is Access via OpenVPN
and is it 1h only?
ah ok, like i use an app like virtualbox to have the machine in my pc and then connect to tryhackme network
ol right, why didnt i do that
real quick how much space do you need for a linux machine
oof i was thinking in the range of 5/10 bcs i dont have much space
but i guess il have to delete some stuff
hello! are y'all still giving roles for certain cyber certs? I've made some more progress :)
Hey I'm completing a task and it has a site attached to it for practice, but whenever I open it it shows a white screen and says "static-labs.tryhackme.cloud took too long to respond". Does anyone have any ideas on how to fix it? Thanks.
Same thing is happening to me rn for Intro to Defensive Security task 3. Think its a sitewide issue.
Same issue on me as well, this happened in my case on DNS in detail
I think this happens on all mock webpages, I proceeded to the next room and still got the same issue
Hay.
You'll need to wait for site staff.
now work
If i run this command;
└──╼ $sudo python3 setup.py install
Is there some command i can then run to uninstall everything the previous command installed ?
How so.........
@naive dust I installed profil3r.py
It seems like it's not incredibly useful so i was thinking i would remove it including any other files that may have been installed elsewhere in the system.
@blissful gull try sed -i 's/cipher AES-256-CBC/data-ciphers AES-256-CBC/' *.ovp
that might fix it, not sure
if not then I'm not sure so someone else will have to help
do you mean run this command then sudo openvpn file.ovpn
just run that in commandline and then connect to the vpn as you did before
i get this error sed: can't read *.ovp: No such file or directory
could you run this first: openvpn --version
to tell us what version of openvpn you are using
do what shadow said first sorry
doubt it is a version error and actually something else along the way that is the problem
I just remember being sent that at some point for helping fix vpn issues and that was all I could think of trying
aside from that idk
@opaque lagoon @plush bay the output of openvpn --version is ```OpenVPN 2.5.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Jul 5 2022
library versions: OpenSSL 3.0.3 3 May 2022, LZO 2.10
Originally developed by James Yonan
Copyright (C) 2002-2022 OpenVPN Inc sales@openvpn.net
Compile time defines: enable_async_push=no enable_comp_stub=no enable_crypto_ofb_cfb=yes enable_debug=yes enable_def_auth=yes enable_dependency_tracking=no enable_dlopen=unknown enable_dlopen_self=unknown enable_dlopen_self_static=unknown enable_fast_install=needless enable_fragment=yes enable_iproute2=no enable_libtool_lock=yes enable_lz4=yes enable_lzo=yes enable_maintainer_mode=no enable_management=yes enable_multihome=yes enable_option_checking=no enable_pam_dlopen=no enable_pedantic=no enable_pf=yes enable_pkcs11=yes enable_plugin_auth_pam=yes enable_plugin_down_root=yes enable_plugins=yes enable_port_share=yes enable_selinux=no enable_shared=yes enable_shared_with_static_runtimes=no enable_silent_rules=no enable_small=no enable_static=yes enable_strict=no enable_strict_options=no enable_systemd=yes enable_werror=no enable_win32_dll=yes enable_x509_alt_username=yes with_aix_soname=aix with_crypto_library=openssl with_gnu_ld=yes with_mem_check=no with_openssl_engine=auto with_sysroot=no
okay then it is not a version issue
so what is the issue?
dunno as shadow has not seen the full error but could be a decent bit of things
!vpnscript
could help by running this script
i will try it but now i run the last command that @opaque lagoon say sed -i 's/cipher AES-256-CBC/data-ciphers AES-256-CBC/' *.ovpn and i get different errror
2022-08-14 17:30:15 --cipher is not set. Previous OpenVPN version defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2022-08-14 17:30:15 OpenVPN 2.5.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Jul 5 2022
2022-08-14 17:30:15 library versions: OpenSSL 3.0.3 3 May 2022, LZO 2.10
2022-08-14 17:30:15 Cipher BF-CBC not supported
2022-08-14 17:30:15 Exiting due to fatal error```
shadow was saying it's not a version problem, redownload the original vpn config and then go through the troubleshooting list
do you know anything about it?
ok, i will try
delete the current config and re-download it before going through that list in the URL shadow sent
gg you just fixed an unexisting error meaning you would need to reverse the above command you used
sed -i 's/data-ciphers AES-256-CBC/cipher AES-256-CBC/' *.ovpn
should reverse the sed command you ran last if you don't feel like redownloading the vpn file
also you are not located in egypt are you menna???
yes
because egypt blocks openvpn connections on a state/country level
i get it , but how can i access the network
if you are in egypt your only option is to use the attackbox
okay thanks
Gave +1 Rep to @plush bay
they could block that but the amount of outrage if the tls port gets blocked would be interesting and problematic
depends how they block the traffic
might find that it looks at the packet and if it isn't https traffic on port 443 then it blocks it anyway
It depends on how VPNs communicate, assuming it's TLS and has nothing that makes it identifiable as a VPN it'd probably be fine
also is it even legal to try and bypass the vpn block in egypt???
just so we are not instigating someone to commit a crime???
Just a new member and I was trying HackPark and I can no longer get a proper response from the web server. I had no issues and now I am getting a "Error response" Error code 405 Method not allowed. I am assuming the webserver broke. Do I just terminate the VM and start all over?
????
no
yeah restarting the target machine vm should be the easiest fix
Thanks shadow. I would know if I had a weberver running on my machine
gcc -fPIC -o openssl.o -c openssl.c
gcc -shared -o openssl.so -lcrypto openssl.o
i have problems with the 2nd command
I understand........though that's not what i'm trying to figure out.
@opaque lagoon Sometimes you may need to remove the tun interfaces
Connection was reset you can just try pressing that "-" button to close out the side window, then launch AttackBox again and it should reconnect to the same session. If not press the power button on the side panel there and restart the AttackBox
also iirc a lot of Linux fundamentals 2 is just based on ssh, if you're confident enough, you can use the THM VPN and ssh into the machine
didnt work
Hey guys im having problems connecting to VPN.
2022-08-15 11:15:26 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such device (errno=19)
it worked a week ago
OpenVPN?
yes
i tried to change the server too
Not connecting to the virtual machine
Im on a physical machine
Artix -> Fork of arch linux
It works now.
Thx
Hi, I got a problem with box in https://tryhackme.com/room/commonlinuxprivesc . It does not respond to any commands like : cat /etc/passwd
It basically does nothing except for letting ssh into it
It seems to be a problem only with etc folder
Task 4
use linenum. That task is explaining the use of linenum
Make sure to read the information carefully as it'll help you with the tasks
I did but LinEnum starts and then hangs at
user3@polobox:~$ chmod +x LinEnum.sh
user3@polobox:~$ ./LinEnum.sh
#########################################################
Local Linux Enumeration & Privilege Escalation Script
#########################################################
www.rebootuser.com
version 0.982
[-] Debug Info
[+] Thorough tests = Disabled
Scan started at:
Mon Aug 15 11:31:18 EDT 2022
SYSTEM
[-] Kernel information:
already for 5 minutes
on my local kali machine it executes perfectly
you need to run it on the machine that you're enumerating
not the kali machine
https://www.youtube.com/watch?v=CNodxp9Jy4A&ab_channel=Veritasium this is proper interesting (there was stuff that I expected but there were a few other vulnerabilities that I didn't know about)
Or almost any garage - it's particularly good with fixed code gates and garages. Samy proposes other weaknesses with rolling codes.
This video was sponsored by LastPass: http://bit.ly/2oscAe9
I don't condone malicious hacking of gates, garages or other property. The point of this video was to discuss how it could be done using fairly basic tech...
I constantly keep getting disconnected on the virtual machines. I thought this was down to using a VPN but I disabled that whilst on THM and still experiencing the issue. I raised this a few days ago and had no response. Anyone have any ideas?
Not using the OpenVPN
Just the attackbox
In the Attackbox, just constantly disconnecting me and has been for a while now
It's impossible for me to work on anything within the attack boxes
No, I am just going through the tasks on Phishing Emails at present and this keeps happening
I'm having issues connecting to thm on my laptop, I accidently connected using Tor's proxy chain and ever since I haven't been able to connect (even after it's disabled)
my main computer is able to connect but not so much on my laptop
im trying to do the web enumeration and during the wpscan i get "Scan Aborted: The url supplied 'http://cmnatics.playground/' seems to be down (Couldn't resolve host name)"
and http://cmnatics.playground/wp-content/themes/twentytwentyone is not working as the answer which is where the theme is
thank you i figured it dang silly me
Gave +1 Rep to @gray loom
https://tryhackme.com/room/bpnetworking why I cannot access this room as a free user ??
Is it locked or private?
Hi everyone, I recently completed the Pentest room and was given an expired voucher. It was stated before enrolling the room that a voucher would be given.
says this is issue contact us
Any idea if this will be updated?
Is that the CompTia+?
The Comptia Pentest+
What is the code? DM me.
I need help connecting to the TryHackMe VPN. I'm in egypt where both PPTP and L2TP are disabled, what should I do? [using Kali]
GG
you are stuck using the attackbox.... as the tryhackme vpn is also blocked
what the hell?
cant somehow use a different port?
nope
even if tryhackme changed port and other vpn providers did the same the new port would just also get blocked
well thanks for nothing
Rude.
-mute @ripe grove That attitude won't be accepted here. You're asking us to help you break your region's laws, which should be a ban in itself.
🔇 Muted gebz#7155 for 1 day
Ok, thank you
Gave +1 Rep to @gray loom
-warn @ripe grove Please adjust your attitude here, everyone is a volunteer here. Don't send unsolicited friend requests. Don't ask for help breaking the law. Anything further will be a ban, so please read the rules.
⚠ Warned gebz#7155
In your case, the option is to use the AttackBox. When you subscribe you get unlimited access to the AttackBox. 🙂
Discord spam/phishing
USER ID: 920299758122319913
@naive dust
-ban 920299758122319913 -ddays 1 pretending to be discord to scam/spam something
🔨 Banned PARTNER DlSCORD#7332 indefinitely
muchas gracias @static quail
np 
Hi. For the HackPark i created a reverse_tcp payload with the Message.exe title and set up the handler. But when i tried to invoke it from my shell i get the following error: Invoke-WebRequest : The process cannot access the file 'C:\Program Files
(x86)\SystemScheduler\Message.exe' because it is being used by another process.
any ideas?
Rename current Message.exe to Message.exe.bak, then try again
same
Hello I am on the Linux Fundamentals room #3 and it is saying I have the incorrect password when trying to SSH into the machine, could anyone help? Thank you
Yes, it is different. Im using the one they gave and the standard tryhackme password 😦
Disregard I had the IP and username swapped
I'm stuck. I've tried over a dozen possible answers but nothing works.
What is the flag that you obtained by following along? Intro to defensive security. task 3.
any tips?
Didn't you complete the static site?
Hello,
I'm your monthly subscriber. I've made a payment for my subscription. but it's not reflected in my tryhackme account and asks me to pay for the subscription again. also, not able to access premium rooms. Please be helpful as soon as possible.
I already spent 3 days and am not able to access subscription rooms. what should I do? I've contacted you on each and every option but still have not received any response from your side.
Thanks,
Archin Modi
hello 🙂 I was wondering, is Parallels on a Mac good for working in Kali via the VPN connection?
is there some reason not to use Parallels?
Hi
My openvpn is too slow when I connect and I'm using ubuntu.
Even when I switched servers multiple times and regenerated configuration files multiple times it remains slow. It's not just my internet connection, cuz if I open youtube it's totally fine, but when I open up webpages hosted on thm machines the response is too slow. Maybe there's like a configuration where the bandwidth is limited? can I modify that configuration?
what is your mtu setting on your tun0 device???
ip a
you could try setting it to 1200 with sudo ifconfig tun0 mtu 1200
and it might speed it up
hmmmm
there is a chance this speeds it up and fixes your slow connection problem
yuups
i don't know what I can't comprehend this but ok
it is easy to set it back to the default if it does not help
didn't work either
btw how does that work?
decreasing it
Isn't increasing the mtu supposed to improve the connection? (unless the internet connection is slow)
there's also a very big packet loss
80% packet loss
yeah decreasing it helps with unreliable connections and somehow speeds it up a lot for some users
mhm
you could use discords search feature and look into other cases where mtu changes have been recommended
saw other cases like mine
I think there's something wrong with openvpn since like 1 month (or less)
cuz I've been using it
and it's was completely fine
but since like late july it started to slow down
unless I'm on a fiber connection
ty anyways
no problem
Hello... My school removed my email account and now I dont have access to my tryhackme account
yeah but that'll end by default
gl I hope you can get ur account back if possible
or at least some access to thm
Thank you!
you can login using your username and password. Once you login you can change your email(:
heya! I was building my streak for the last 50days or so and it just dropped to now whereas i worked everyday Oo any idea why?
Is there a way to change your username on TryHackMe?
Thanks!
Gave +1 Rep to @gray loom
timezone95 — Today at 11:51 AM
Hi all need some help with Splunk BP room.
Problem:
-> No data found in 'Investigation workshop'
Anyone else experiencing the same problem?
timezone95
Hi all need some help with Splunk BP room. Problem: -> No data found in 'Investigation workshop' Anyone else experiencing the same problem?
timezone95 — Today at 11:51 AM
https://tryhackme.com/room/bpsplunk
Probably shouldn't spam across channels #room-help would be the best place to ask, someone will probably help you at some point in there
hey my apologise. Thanks man
nw
Hello is there any way I can get my streak frozen/not lost, I have no wifi currently and won’t be able to have it for almost 2 weeks and I also do not want to lose my 178 streak. I also cannot email support as I’m not logged into any of my emails on my phone
This is for someone from the THM team:
When doing the PrintNightmare room in the Recent Threats module, I was trying to start up the smb server using the attack box (after following all the in room instructions) and I was getting this error:
"Exception: Version mismatch: this is the 'cffi' package version 1.14.2, located in '/usr/local/lib/python3.6/dist-packages/cffi/api.py'. When we import the top-level '_cffi_backend' extension module, we get version 1.11.5, located in '/usr/lib/python3/dist-packages/_cffi_backend.cpython-36m-x86_64-linux-gnu.so'. The two versions should be equal; check your installation."
I was able to complete the room with no issues using my own Kali VM so I thought this might be something for THM Tech Support to solve on their end, as there is some kind of mismatch between the cffi versions. I did try some google related troubleshooting myself but I couldn't solve it so I just used my own VM instead. If anyone else has a workaround for this kinda thing please let me know in case I run into it again in the future. Cheers!
Hi all, I have a question about the VPN connection. I can create a VPN connection and when I enter a room I can ping the target host and do a nmap scan. For example port 22 and 80 are open, but I cannot SSH to the target or open the webpage in a browser. I see in the VPN log 2022-08-18 01:58:24 read UDP [ENETUNREACH]: Network is unreachable (code=101). But when I do a traceroute to the target, it reaches the target. Anyone an idea?
does your VM have firewall?
that's bad but only the staffs can solve this kinda problem via email
i still have some hotspot currently so im gonna email them rn
i thought my phone's hotspot wasn't working it just would only let me connect by plugging it in to my laptop
but mail usually takes few day to get respond
yea ill just let them know that i wont be able to see the response and just hope they respond ig
@acoustic sand I'm working on Kali with no firewall / iptables
@acoustic sand I'm working on Kali with no firewall / iptables
I don't know if support will help, as it will be > 7 days.
is there any way to change the name on the certificate
Unfortunately there is not, but if you add your full name to your profile it will be on further certs you receive.
Hi, my username on THM is botmancol and I created a room "a first project" and emailed support as they are out of RAM so mysql is not working .. . the support answered me that if I had put it in public the tester would add RAM on my machine if necessary, only, timtaylor (the tester) did not accept my room because "the writeup does not work "but it works perfectly, I think the problem comes from mysql is it possible to enter to contact with timtaylor for more informations?
cc @tawdry orbit
Your writeup page results in a 404 page not found. You likely have made it private.
Hi there! First time using Discord, so sorry if wrong thread or smth. I have issue with Linux Fundamentals rooms. When I deploy machine in attackbox, I use ssh tryhackme@my_machine_address to connect and it says password is wrong, even though it used to work a day before... Could someone possibly help me please? Thanks!
Are you in a VM or Attackbox?
Can you also give the machine ip?
Thanks for respond, however it have just worked this time. Idk why... What I'm seeing now, there is different IP in room "Active Machine Information" and inside Attackbox's Terminal.
Gave +1 Rep to @weary spindle
Room IP: 10.10.179.253 and attackbox: 10.10.113.245
They're two seperate ip's.
Your attackbox IP is what you use to catch rev shells etc.
Room IP is what you use to attack, enumerate etc.
Ohh, so they are independent and I have to run those separately. Thanks A LOT!
Your attackbox IP won't change for as long as you have it booted, however each machine you spawn with the green "Start" button will give you a new ip.
Also some rooms take slightly longer to boot up their services, (longer if you're not subscribed).
Thank You very much! have a nice day 😉
You too 
Okay, I'm trying to use OpenVPN, but unable to connect ..
Can you give a screenshot?
Okay, seems to be a configuration file issue. I regenerated the config file, and tried to connect again to take a screenshot, it worked! 😅
ho, no, I'm sorry for the inconvenience, i have fix the problem by change the url and resubmit my room 🙂
All good now. 🙂
Hello i just started the free guide on try hackme . i want to do (https://tryhackme.com/room/ccpentesting) but it is saying that is a private room. How can i access it. can anyone help me please
ok, so 🤞 🙂
hello i'm trying to use the ssh to connect to the simple ctf room machine but i'm getting a blank line after typing the ssh command and "tryhack@machineip"
Did u write ssh before tryhackme@....... ?
"ssh tryhackme@machineip"
I think like that been a while
you are not meant to ssh into it until after you find some stuffs
if said challenge box has ssh open that is
I have a problem in attackbox
That the msfvenom command not found
And I don't what should I do for this problem
!docs verify
verify first the u can send screenshot
Hi the dataset for https://tryhackme.com/room/bpsplunk Splunk room is not loading up anymore. Anyone facing the same issue?
anyone helpme with installing drivers for tplink t3u plus(Realtek RTL8812BU chipset) in kali linux. i tried with some methods in internet but all methods are giving me same error that linux headers 5.14 missing. in linux repository we only have 5.18 version
This channel is for THM, best to use #general
ok
In hte Upload Vulnerabilities room, the machine is returning http 500 when uploading a PNG image - somehow it feels that should not be happening - Task 8 - Bypassing Server-Side Filtering: File Extensions
Try and make sure that you can upload a proper image, and if that woesn't work, terminate the machine and restart it
Thanks, already tried a few valid images - will terminate and have another go
Hello, this room has been retired. I recommend to search for the newer splunk rooms on the platform. 🙂
hey guys i cant get 1920 x 1080 resolution on virtual bx
Is it somehow possible to change your username?
Be sure to install the guest extensions.
"VirtualBox 6.1.36 Oracle VM VirtualBox Extension Pack" from https://www.virtualbox.org/wiki/Downloads
Close all your VMs and VBox itself down, the double click the pack once you've DLed it.
why am i getting this message while i'm trying to list folders on brainstorm machine?
thanks!
Gave +1 Rep to @gray loom
is there a way to list all the rooms with active machines?
Hey! Thanks for the update, understand!
Am i supposed to let someone know if i find spelling mistakes on the website ?
You can post them in #room-bugs
@candid yacht Oh I see, I guess i figured they should be fixed is all. Thanks.
Gave +1 Rep to @candid yacht
Hello, why I don't have internet connection in AttackBox? I started yesterday and now I'm on Content Discovery task
Oh so when in the task i'm told "On the AttackBox, open firefox and enter the url https://static-labs.tryhackme.cloud/sites/favicon/ here you'll see..." That's mean i can't do that cuz i'm not a subscriber? 😄
yes, and i'm told to use curl
i'm supposed to run my own kali then? Like in vmware?
ohh 😄
Will there be any tasks where i must be solving using openvpn or attackbox then?
and if so, can you please help me, is it possible to connect through openvpn if i already have one connection? Like is it possible to use several vpn configurations
Oki, thanks lassi very much
Could someone give me a clue for the Dirty Pipe: CVE-2022-0847 room plz ?
Oh......... I mean.
@gray loom After i salt the file i need to format it correctly right ?
I mean......... THM:$6$THM$MeGI7eYSh.ex3l79m8sMQ2dq9Ux77JfC7XlCgZbneUFAvnHj4gphJKnnveuf2AndcoLn2mmhJVhcxvAIgA8RJ.:0:0::/root:/bin/bash
I know it's incorrect at this point.......
So how do i know where the / / / goes....... ?
Or....... i don't know i'm not sure how this one works.
I'm currently on the Jr Penetration Tester path. When launching a linux machine in the split-screen view in the browser, I'm getting a red error message that says: "thmVNC encountered an error: SecurityError: Permission denied to access property "dispatchEvent" on cross-origin object" and then some more details about the error relating to moz-extension and onKeyDownMouseDownToushStart. I can't dismiss the error window. Any idea what's going on here and how to fix it?
Hello , I`m from Russia and I wanna ask how buy premium THM if I from Russia
Are there any solutions ?
I thought a lot and realized that the only solution would be to ask someone to buy a voucher
And someone has to buy from America, and then I get a voucher, am I right or not ?
Yes , they are rejected
Yes , I understand , thanks anyway for the information
I even bought a USA card with $ 10 , but even it was rejected for payment
So I wasn 't going to buy a voucher for the stolen money . I would have sent the money myself , I would have been bought and that 's it . Or is it already impossible ?
If your card is rejected, there’s nothing we can do. Contact your bank, if you still can’t, you’ll be unable to subscribe.
Purchasing non-official THM vouchers will result in your account being banned
And how are these unofficial vouchers ?
I will find an intermediary who lives in the USA . I will send him the money to his account , he will pay the voucher with my money , and then send me the voucher . Can 't you do that ?
It looks like you may be right. I'm still with the same browser (for now), but I disabled all of my extensions and the box is no longer there. Thank you.
Gave +1 Rep to @gray loom
Hi , so i am trying to launch gatekeeper.exe in my immunity debugger windows 7 x64 :
but immunity crashes here is the error :
Problem signature:
Problem Event Name: APPCRASH
Application Name: ImmunityDebugger.exe
Application Version: 1.0.10.0
Application Timestamp: 4f3bc27a
Fault Module Name: ntdll.dll
Fault Module Version: 6.1.7601.24384
Fault Module Timestamp: 5c6e2180
Exception Code: c0000005
Exception Offset: 0007be36
OS Version: 6.1.7601.2.1.0.256.1
Locale ID: 1033
Additional Information 1: 0a9e
Additional Information 2: 0a9e372d3b4ad19135b953a78882e789
Additional Information 3: 0a9e
Additional Information 4: 0a9e372d3b4ad19135b953a78882e789
Read our privacy statement online:
http://go.microsoft.com/fwlink/?linkid=104288&clcid=0x0409
If the online privacy statement is not available, please read our privacy statement offline:
C:\Windows\system32\en-US\erofflps.txt
to note , other BOF rooms works fine for me (oscp.exe , chatserver.exe , vulnserver.exe ..)
i also tried this solution : https://answers.microsoft.com/en-us/windows/forum/windows_10-update/vcruntime140dll/fc4c0470-4db0-4e7b-9537-58ea62f8ac05
but didn't work
Can someone explain to me what am I doing wrong here? I just wrote the username, wrote the text, but when I try to send it,but it gives me such an error.
wait there is chat functionality on tryhackme???
Yeah, about a couple of weeks ago
I tried, but this feature doesn't finished. Doesn't always show nicknames
guys i need your help with room introtoshells
i clicked all answers but some of them not finished
some of them have answer fields you need to fill with an answer before clicking the button to answer
is this tech support if there is a technical issue in the room, i.e. a host was up and now I there isnt any response from it, i mean 5 minutes after I did a nmap scan. Pretty sure it is supposed to be up. I check to see and I am on the VPN and the network shows it is up and running.
im trying to run vm but is just says starting
@tribal wyvern where is it hanging, it just says it is starting? No other messages
ill show
nvm got it
To post screenshits, you'll need to verify with the bot.
!docs verify
oh, and the room I am in is Holo
And, this channel is usually for technical questions Re: VPN. If you are having problems with a room, #room-hints and #room-help are probably going to be more productive.
@naive dust thanks
Gave +1 Rep to @boreal pine
Are you using NoScript ?
Tip for those who may use an M1 mac with Kali arm64 VM. when you need to run x86 code you can use qemu-user-static binfmt-support. I didn't want to give up my Macbook but needed to run amd64 exploits. Lifesave.
Hi Support Team,
I want to change my username on THM, please let me know the ways.
Not sure what the right channel for this one is. Is there a simple way to get files from a task with downloadable files into the browser-based VM?
Keeping in mind you will not be signed into the website on the VM as it gets purged on shutdown.
Well you can sign in yourself on the site, go to that task and download the files into the attackbox
Having to do that is a pain every time the attack box is restarted, hence my question
That's why I put it in the question explicitly
well the attackbox is not permanent unfortunately and does not carry over every session so yeah, this is the easiest way unfortunately 🙂
Didn't know if there was some trick to copying files over the browser VNC session
If it's possible to somehow grab the link and bring it in, that would also work
You would have to sign in anyways i guess
But you can use your own VM and bypass all of this would be much simpler, the files would remain there etc
Yeah I've been just grabbing my own laptop for these types of tasks generally
but it seems like something that could be improved
Being able to copy the link to the task files would sort it immediately
Yeah idk the exact mechanism behind the attackbox but i'm sure they thought of these things before but who know
And it's not like you encounter a task with files in it all the time so i don't find it that hard to just sign in on the attackbox, get the files, finish the task and move on...
Maybe an odd question, but I’ve recently started using a Security key and so far feel really good about it just had a hard ended question. Is it best turn to disable other 2FA methods for those services? It seems from what I can tell when I sign in I still get the old 2FA options like OTP app or SMS
Ah, understood
└──╼ $sudo nmap -sV -sC --script=default,vuln -p- 10.10.225.215 -T4 -oN Lazy_admin
Does the --script==default,vuln flag cause Nmap to typically take longer completing a scan ?
it's the -p- here i think
cuz u are scanning 65535 ports
How can I link my THM profile with discord?
!docs verify
Thanks!
keep having this problem in the avengers room. I've switched vpn servers and regenerated my .ovpn a few times already. Any help would be great.
have you tried changing the tun0 mtu???
not sure how to do that.
Is your attacking machine a VM ?
no, have kali installed on bare metal
Can I have the target machine IP to try to access it myself ?
Not able to access it either, let's wait a bit longer, maybe the machine takes some time to fully boot
when I first booted it, it was working fine, after I ran gobuster and went to open the /portal/ extension was when it started timing out.
should I try to terminate it again and reboot it?
I started the target machine myself, took about 5 - 10 mins for it to be fully up.
So ye, restart your target machine and wait 5 - 10 mins before trying to connect or to scan it
ok, will update you.
working now. thanks for the help!
I've added a sentence just saying it may take 5-10 minutes to load
Oh, perfect 🙂
If there are any others like that let myself and/or Tim know, and we can either add a comment about expected boot time, or have a look at giving it a resource bump 🙂 I figured given the age of the room, a comment will do in this case.
Will do, much appreciated for your swift update on that 🙂
Room: Network Services 2
Task: 8 - Question 3 "What communication model does MySQL use?" - It doesn't accept the right answer, which is client-server model. I tried without the"-", still doesn't accept it
Brother, i just figured it out, without model, lol, ty tho ❤️

Sorry i would like to know if i can publish a writeup into the "Anonymous playground" room, because i saw that there are not any published into the site.
it's either the creator don't accept write up or no one submit any
but u can ask the owner of the room
@somber spindle thank you
Gave +1 Rep to @somber spindle
can someone help me setup my new tryhackme account to this same discord account
@sand olive
can you help?
I am having issues getting the Velociraptor server to run in the THMs VM
for the velociraptor room
Google chrome will not load the velociraptor server
How do I shut down machines? I'm getting a message that I can only run three machines simultaneously.
thx
Is this a public room?
i need help with a vbs file error
To answer your question, yes, it is a public room. Why do you ask
correction, it is a subscribers only room.
Is it possible to change the registered username? Thanks!
Yes, you need to E-mail support.
thx
Ad block in this case 🙂
Hey all - I'm having an issue accessing the Hololive network. I downloaded the OpenVPN config file, but it's 0KB. I tried regenerating the file several times, and always just ends up being an empty 0KB file.
I'll have someone look into it.
Thanks! For what it's worth, I downloaded the OpenVPN config file for Wreath and it works just fine
Gave +1 Rep to @deep spire
I've just managed to download one, could you leave the network and re-join?
and if you verify, can you give me a screenshot of if there's anything in the file at all (you'll need to verify first)
!docs verify
Ok, I verified - should I just paste the screenshot here?
Yes please, or DM me if you'd prefer. Also, what holo subnet are you in?
I'm just trying to download the config file from here
This is what the file looks like
hey guys in my wifi card I can change mode to "monitor mode" but I cannot change monitor mode to "managed mode"
It's possible your card doesn't support that then.
Which subnet are you in in Holo?
but it was working when I first connected
I can't get into the ROM (Zero Logon) to solve it and this wastes my time a lot. Please reply
How do I find that out
go to https://tryhackme.com/room/hololive and look at the network diagram at the top. it should show you a network starting in 10.200.x.x
when i plug in my wifi card first time it was managed mode
10.200.69.x
Brill, I'll see what we can do
Thanks! I appreciate it
Gave +1 Rep to @deep spire
I'd suggest asking this in #room-help , with details as to what task you're stuck on, and what you've done to try and solve it.
I turned off and on again
guess what it worked
Thanks @deep spire xd
Gave +1 Rep to @deep spire
Classic fix 😄
yeah idk why it works everytime 😄
Just checking, have you tried leaving the Holo room and re-joining?
I have not
I'll do that now
Same thing unfortunately
Very strange, I can dl the 'machines' openvpn config file and the wreath network config file just fine
hmm, gotcha
Find anything out?
The person who can fix it is still in a meeting unfortunately, there's been some other comments, but nothing we haven't already tried. I'd recommend leaving the network for now, I'm not sure if it's down to RNG-esus which subnet you get put into or if it sticks with the same one for a while. I'll update you when i know more
Haha, sounds good. In the meantime I'll just go through some other modules
Would a moderator/admin be able to assist me in linking my thm profile to a different discord account?
@sand olive are you lurking? ID is 600060687758131201 if you need it
new discord account is YoakeSec#6719. Also is it possible to get around the phone verification as I have only one number and linked to this account. No rush. Thanks @sand olive
Gave +1 Rep to @sand olive
I know some server can do a manual approval.
I asked Jabba a few weeks ago and they gave a hint there will be,
It's also not a bug, Tim said they fixed it recently.
I think the old bar looked more buggy.
@wheat plinth @gray loom @weary spindle hate to burst the bubble, but it's a bug 😛 there's a fix that's waiting to go live
Oh come on.
Well done I was freaking hyped 😭
If it helps, we've talked about how to deal with the "huh, but I'm max level now" thing... dunno what'll be done to sort it though
I have a question regarding Levels.
I might have an answer
Already got it solved ?
If you have enough points to go lvl 15, will you just auto skip 14?
Or will the level points reset back to 30k?
I would assume you'd skip 14
Ah, sorry
I thought that would be obvious, but thought I'd ask anyway, thanks 😄
Gave +1 Rep to @deep spire
0day probably has an api trick for that already 😂
Finally unlocks a room link, which just redirects to an rickroll 😄
Not yet.
Send me a DM pls and we can go for it
Sorted the unlink
All switched over. Thanks @crystal marlin
Gave +1 Rep to @crystal marlin
Hi guys, I am using open vpn to connect to vulnversity. However, the pages are not loading regardless of what I try. I have already restarted my kali machine and everything
Any suggestions!
?*
I can also ping the vulnversity ip
The pages just refuse to load in the browser
Yes… the vulnversity pages are not loading
step one... check the port the web server is running on
step two.... connect to the web server on that port
step three ????
step four profit
I already did
I started last night and came back to finish today
But nothing is loading now
wonders the probability of you using the same ip you got yesterday trying to connect today hence not working as your target machine ip has changed
or forgetting the most important part of the url
I’ve actually restarted. And using the new ip now
Of my nmap results ?
Yes
Have you done any directory enumeration with gobuster yet?
Thats weird because the home page didnt load for me
When I was at home, yes. Now, I can’t get go buster to run. I’m getting errors. I’m at work now
But I was able to access other pages
Is Work blocking the VPN?
the ip and website works for shadow too
I got the homepage to load with /index.html
I actually wondered this, but it used to work here before
Maybe it is now
👀👀 nope
I’m on break so I’m just trying to level up
Hello! Does anyone have any idea why "my-machine" processes are running slow?
i try to run nmap nmap 10.10.212.143 and i find this error Starting Nmap 7.92 ( https://nmap.org ) at 2022-08-23 14:29 EDT Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn Nmap done: 1 IP address (0 hosts up) scanned in 3.12 seconds , i check the access page and i find that i access the network successfully
Did you read the note?
in what context?
which note?
The note in the text you posted
I mean I have used it for a while now and lately I've seen a remarkable slowdown of the processes generally speaking
i read it and i try to ping the ip but i get no respone
read it again, what's it telling you to do?
Thats right, that's what the note is saying "but blocking our ping probes"
when you're talking about "my-machine" are you talking about your personal pc, or something else?
and?
I'm using the subscription attackers' machine
the attackbox? ok, do you know if it's network lag, or have you been running some other benchmark or something?
I'm not saying you're wrong, just that it's hard to do anything with "it's slower"
Yes. Not exactly. I really mean when I say it's gotten remarkably slow. If for example 1 week ago took me 5-10 seconds to enter a command, now it takes more than 1 minute. Ever since I started with the subscription, all was good until two days ago I guess
Can you ping the attackbox public IP and try rule out latency/packet drops?
Also, if you try fullscreening it you can try changing what proxy it goes through
I.e. https://vnc.tryhackme.tech/index.html?host=proxy-2.tryhackme.tech&password=db24061c71cb6246&proxyIP=10.10.174.247&resize=remote if they change the host-proxy-2 to host-proxy-3 and see if they have the same issues?
@deep spire This is what I get from pinging "4 packets transmitted, 4 received, 0% packet loss, time 3077ms
rtt min/avg/max/mdev = 0.294/0.338/0.362/0.026 ms".
I also try switching the proxy but I get the same response.
Hmmm, is that with the VPN up? seems very fast unless those times aren't ms?
I'm not using VPN. I'm not even downloading anything on my pc that could cause the internet slow down
wait... did you ping the attackbox from itself, or from another machine?
From itself
try pinging the Public IP from the machine that you are currently on
I already did that. I get more or less the same results: "4 packets transmitted, 4 received, 0% packet loss, time 3053ms
rtt min/avg/max/mdev = 0.272/0.288/0.324/0.021 ms"
I mean from the computer you are physically sat at, to the attackbox. you cannot have a <1ms ping from your computer to a machine in the cloud. I'm trying to figure out if it's a latency issue rather than an attackbox issue.
To demonstrate
I got it. It comes back with a request time out message
That would suggest there may be some latency issues on your network/internet. You can leave it running to see what it averages out at, but ultimately that's something you'll need to speak to your ISP about, as it'll be likely other sites will be slow to load too.
Although i will check you weren't pinging a 10.10.x.x address for that?
I see. Honestly, the main reason why I made the subscription in the first place was using the attack boxes. I had issues connecting via OpenVPN on my home network and I realized that the issue was on the ISP side because I could connect to it(OpenVPN) on another network. Apparently, I'm gonna have to break up with them.
Thanks for your support though @deep spire
Gave +1 Rep to @deep spire
No worries, and hope you can find a better ISP 🙂 I know the pain of that slow typing into the console on slow mobile connections, so I understand what you're up against
I was 🤏 close to driving nuts. Take care bud
i don't get any result
just nmap -Pn 10.10.212.143 Starting Nmap 7.92 ( https://nmap.org ) at 2022-08-23 16:38 EDT
try adding -vv so that it tells you more. I'd also suggest trying to curl 10.10.10.10/whoami to check you're connected properly too
Hi, i have a problem with my account, some learning path are missing and i have a different layout compared to one of my friend's account (sorry for my english)
That's my screenshot https://ibb.co/0V9KhMH
That's my friend's screenshot https://ibb.co/ys7v2NZ
It's just the complete beginner path, which got announced to be replaced by Junior Pentester path quite a while ago.
Regarding the layout, it seems to be A/B testing
You talking about what exactly?
The content/rooms?
sorry, didn't know
tryhackme.com rooms == most of them are free
the tools to hack said rooms == most of those are free too
Excuse where is that?
So what does happen in this server then
#start-here might help
this server is to chat and help each other do content for that website
ok sure thx
Gave +1 Rep to @plush bay
and as fontaene said... the #start-here channel is great to explain a bit about this discord server
Hey! I am on the last leg of my cybersecurity degree and finally have a lesser courseload so I can do things on THM again- but I went to resubscribe and it keeps saying my bank is declining payment, but I called my bank and they said they aren't even showing an attempt on their end. Could I get someone to help out with this? No rush of course, but it is a bit odd
I tried toggling my dns adblock, thinking maybe somehow that was the issue, but it still isn't quite working right
You would have to reach out to support via email for that
Thanks! I'll do that - edit: all solved :)
Hello, this is kind of a dumb reason to reach out but my Streak was reset today and I definitely performed some tasks today, can I get me streak back? The only reason I care is I was at like 422 days
or is it better to reach out to support?
Yup, you'll need to email support, they can reset it for you 🙂 best to email them fromt he account you use for THM
Hey, are you still in the network/able to rejoin Holo to try it out?
Yo. I've been working some other modules, but let me try to rejoin the room and see what happens
Boom
Got the ol' 9kb file
I think since I'm on a new subnet now, that may have been what fixed it?
Everyone beware if you're on 10.200.69.x network for the Holo room 🤭
Nice
I'll keep an eye out for it.
Thank you!
Gave +1 Rep to @deep spire
For some reason I’m the attacktive directory module I’m not able to download bloodhound
Where are you downloading it from?
In the Empire room the screenshots for the following tasks are missing/don't render:
"Task 5 Listeners", "Task 6 Stagers", and "Task 8 Modules".
no help needed but just interesting... anyone else?
Refresh and it fixes itself 🙂 it just gets a little confused sometimes
it sure did fix it... I sometimes just hesitate to refresh because it might fail to reconnect and well, there went the work I did for the past hour
thanks @deep spire
Gave +1 Rep to @deep spire
Hello, my wifi keeps reconnecting on my phone
I am in range and there's definitely no overloading
Oh my bad
Hi. Recently, my OpenVPN Client recently went kaput... Is there a solution to standard THM Config for the 3.3.6.2752_signed Winx64 version?
The data-ciphers mentioned by cmnatic on the Forum is not working for some reason... https://tryhackme.com/forum/thread/62bc5fb1fcafa700618f25f0
Post a screenshot of the error you get pls.
You will have to verify first to do so
!docs verify
I'm unable to access externally when connected to the VPN
I can try
I can access the box, but that it
You mean to access the internet when being connected to the VPN ?
Yeah
What OS you on ?
Are you using the network manager to connect to the VPN or the command line ?
And once you disconnect from the VPN you can access the general internet as usual ?
Yup
Mh
I switched vpn servers and rebooted my vm too
What's the error you get when browsing to a website ?
Could you post a screenshot of the output from ip a s
As well as of ip r s
While being connected to the VPN
And the ip a s ?
I'm a bit confused about the 10.1.0.0/16
As I said, I'm a bit confused about the 10.1.0.0/16 one, you might try to list your routes with route -n
Also, have you tried to ping a machine via it's IP, like a google machine or something to see if it's just a DNS issue?
also known as pinging 8.8.8.8 for google main dns
or 1.1.1.1 for cloudflare dns
Hi! I've completed Metasploit and Burp Suite room with 100% but they are not checked... Do you know why?
Oh uh
So the badge is stuck
:/
apt install bloodhound neo4j this is the command i was using
I would try their github if you still haven't resolved it
Can someone tell me what's wrong with this python script?
python -c 'open("/etc/passwd","w+").write("root:$1$IzBMiwm1$nG8PvxzsMa8NxgSwU0jqc0:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
systemd-network:x:100:102:systemd Network Management,,,:/run/systemd/netif:/usr/sbin/nologin
systemd-resolve:x:101:103:systemd Resolver,,,:/run/systemd/resolve:/usr/sbin/nologin
syslog:x:102:106::/home/syslog:/usr/sbin/nologin
messagebus:x:103:107::/nonexistent:/usr/sbin/nologin
_apt:x:104:65534::/nonexistent:/usr/sbin/nologin
lxd:x:105:65534::/var/lib/lxd/:/bin/false
uuidd:x:106:110::/run/uuidd:/usr/sbin/nologin
dnsmasq:x:107:65534:dnsmasq,,,:/var/lib/misc:/usr/sbin/nologin
landscape:x:108:112::/var/lib/landscape:/usr/sbin/nologin
pollinate:x:109:1::/var/cache/pollinate:/bin/false
rootme:x:1000:1000:RootMe:/home/rootme:/bin/bash
sshd:x:110:65534::/run/sshd:/usr/sbin/nologin
test:x:1001:1001:,,,:/home/test:/bin/bash
")'```
I got this error "EOL while scanning string literal"
I'm guessing that the line breaks are causing the error but I don't know how to fix that
u ever try with just one user?
I just thought of that actually
if I use this python line to write to the file, will it just write to the end of the file ?
where did you find this?
google lol
extremely cool of you
a is append
sorry I got butthurt
I was frustrated with the box
thanks for the tip
I ended up using this ```open("/etc/passwd","a+").write('\nnewroot:$1$or1G1DVk$dZYhQeyhI6VMsFjJAiYwk1:0:0:root:/root:/bin/bash')
and it worked 😮
I was able to switch to root after spawning a pty
now I want to know how to create an ssh key since I have root and ssh is open
I don't understand why I can't ssh into this use I've created
the password works fine when using 'su' to switch users in the spawned shell, but when I try to SSH the password fails?
Heyy there, is there any option to buy 90 days(3 months) vip voucher? Or I have to buy 1 month x3 voucher????
If yes is there any discount on 3 or 6 months voucher??? :))
are u trying to switch user locally?
ssh-keygen will generate priv and public key for ssh if u don't want to use password
when using a command like r < <(cyclic 50) in gdb on someone elses machine how do i get it to not create a redirect error from the arrows?
I can't find the password here
@naive dustCrocc Crew
//IP/disk or \\\\IP\\disk
@somber spindle Can you write the code directly as in the picture?
smbclient \\10.x.x.x\Home
thanks
Have you tried to google that exact question?
Also, this channel is more for THM, it's best to use general for this type of Q.
I'm from Egypt which is blocking OpenVPN via UDP, THM docs says until TCP is supported, the alternative is deploy the attackbox
Are there any tweaks to OpenVPN until THM support TCP?
You can use the attackbox.
I was subscribed for the last 2 months but had to cancel because we're at the end of the month and I'm running short with money haha
Will re-sub when I earn my salary next month haha
Other than that, there nothing anyone can do.
😄
This isn’t really tech related but how does the levelling system work on THM
Tryhackme works on a level system. This is also echoed over into the Discord server, if you're a member of that.
This is fixed now. 🙂
I'm in the content discovery room and it appears the site that we are supposed to run curl on in order to download a favicon is down? I have tried using my own machine connected via VPN and the attackbox. for reference it is the Content Discovery room, Task 3, url is https://static-labs.tryhackme.cloud/sites/favicon/images/favicon.io
looks like the attackbox is also having trouble just getting out to google, so it may be a general THM outage
Seems to work fine for me?
If you are not a subscriber, you have no internet access on the attackbox
ah ok I didn't realize that. maybe user error on my part I'll try again later
Hi....
When I connect t openvpn, it shows that I'm connected on both, the terminal ("initialization sequence completed") and my access page on thm. I can ping 10.10.10.10 succesfully, but when I try to ping any room's machine, I can't. Packet loss is 100%. I'm sure it's not an internet connection problem, cuz I can open YT and watch high quality videos. Btw when I connect to a MUCH faster connection (in public places where there's fiber or 5G), I can ping the room machine successfully, but it's a bit slow. Any recommendations?? I tried switching vpn servers, but nothing worked.
Not all rooms can be pinged.
nmap room?\
the beginners one
it's not only one room
I think it applies to all rooms that I tried
You got one open now?
yes
could I dm you a few screenshots?
No.
You could verify and send them here.
!docs verify
ok 1sec
"Intro to ISAC" room task 8 I get a Windows activation error when I use RDP to the VM
I think you need to post these in #room-bugs
I not find any #room-bugs
ok
I'm referring to the Windows activation.
it's safe to put screenshots here right? even tho they have my machine's IP address
Yeah.
I take it to #room-bugs then 🙂
it shows here that I'm already connected
Here, I can ping 10.10.10.10, but not my room's machine
You can't ping all machines.
I can nmap it?
That machine is a windows one, so it won't respond to pings by default.
Because it's telling you to
I'm special 🙂
Did you add -Pn?
fr tho why didn't it require you to -Pn it/
?
Try it without adding the -sVCS
I tried it wihtout no switches and it asked me to -Pn
I wanna be special then XD
wdym 0xD? 14?
something is making no sense
oops sorry yeah it's 13 XD
And now fixed 👀
Yeah, I noticed today.
Looks strange though
how so?
For example, my points is 34419/20000 Points
Every time I see it, my brain wants to swap it.
Just got to wait for a proper fix
When the new levels take place?
Me no know 🤷♂️
oh wow...
I think it would look better as points total/points total
But that's just my preference.
Obviously after 20K
there is someone ? i have a problem with the Exploiting AD network, i cannot connect to the DC
i have put the correct ip ine resolved.conf and restarted the service but cant resolve with nslookup
i also restarted my attackbox but nothing change
@deep spire still here ? 😭
I'd recommend using the #exploiting-ad channel
Hello, does someone know why using sqlmap in https://tryhackme.com/room/gamezone is so terribly slow? When I run sqlmap on DVWA it finishes in a few seconds, but running it on THM finishes in about 1.5h.
are you running it from the attackbox, or from your own VM? If it's your own VM it may be network latency issues.
Anyone know if there are limitations on versions of Windows Server you can upload when developing a room? I'm under size limit and appropriate format but I get an error when I upload a VM about conversion. The only other thing I can think of is that it's a Server 2022 VM.
@bronze vale can you help here, maybe give them access to #creators-lounge I personally can't remember what windows servers work for thm
GiveRole <User:Mention/ID> <Role:Role> [Duration:Duration]
Invalid arguments provided: Invalid role mention or id
big C and L
-arole 333090403228057600 648695657326182420
➕ Gave the role Creators-Lounge to Xalten#8039
@dry nebula This is most likely due to your privacy settings for this discord server
You have to allow DMs from server members
But you have to allow it for that discord server, switching the privacy settings in your general settings now will only affect servers you join in the future, not the ones you already in
so i need to leave and rejoin the server
No, you can simply set it for that server, on desktop open the drop down menu on the top left corner, that's next to the server name "TryHackMe"
Then go to privacy settings and allow the DMs
thanks 🫡
hey guys, solving ctfs for a while with linux. no problem so far. but i decided to switch to windows. i perfectly got connection tryhackme vpn. but can't run ctfs. does anyone know why?
Hi everyone.....
Would someone help me with the Crack The Hash Level 2 machine plz........... I'm encountering the following error;
└──╼ $./haiti 741ebf5166b9ece4cca88a3868c44871e8370707cf19af3ceaa4a6fba006f224ae03f39153492853
Traceback (most recent call last):
2: from ./haiti:7:in <main>' 1: from /usr/lib/ruby/vendor_ruby/rubygems/core_ext/kernel_require.rb:85:in require'
/usr/lib/ruby/vendor_ruby/rubygems/core_ext/kernel_require.rb:85:in `require': cannot load such file -- haiti (LoadError)
I tried sudo gem upate though it hasn't fixed it.
Has anyone encountered "Error opening configuration file" in their personal Kali Linux machine? I have updated OpenVPN and redownloaded config file. Any suggestions?
sudo openvpn /Downloads/name-of-file.ovpn. My file is in the file explorer.
Thank you! This worked!
Gave +1 Rep to @gray loom
Thanks! I will try this next time.
it is not working at this time, is it problem?
while i was on linux, it was not a problem, do i have to uninstall?
hi
I can't do this part, does anyone know the password?
I think you're doing a room, so you probably want to ask in #room-help. Make sure you say which room it is, what task and question you're stuck on.
netcat is listening, what are you doing to try and get the shell?
so im doing the room OWASP Top 10 i did upload the encoded shell in this cookie but netcat doesnt work idfk
i had same issue before on the pickle something room
on windows i got the via wsl but it seems like if i use the vpn on windows it also works for the wsl right>?
so i gotta use open vpn on wsl and it would work>
i really dont want to do that i will try running it on wsl if it wont work i will just use vm
just checking, is it WSL or WSL2. WSL2 is marginally better than WSL, but you will make your life a lot easier if you set up a VM in Virtualbox or similar
wsl2
ok, WSL v1 is plagued with network issues, WSL2 is borderline usable
i got like 1/2 gb ram left it is so lag its almost unusable
I've just spotted you're a subscriber, you should be able to use the attackbox if you want.
oh yeah i can but still doing it on my computer would be better for me
can vouchers expire?
attack machine keeps disconnecting. I'm pretty sure its not a network issue on my side. Nothing else drops out and when downloading games on steam, I'm getting around 10MB/s down. Only started happening last two days. Any ideas anyone?
its happening every 2 seconds at the moment. very frustrating 😦
Room:Active Directory Basics. Task 4
After changing password for sophie
Can't log in into her account
Seems like a bug. Checked it 2 times yesterday
Came back today, same issue
I will search
Where can I report bugs/typos/cosmetics for rooms?
https://tryhackme.com/room/blog has a bug, cant submit user flag.
/cough
room bugs. thanks
so might be a long shot but is anyone on an M1 macbook attempting to make it work for THM?
I have been having some issues when it comes to Netcat(installed via brew V 0.7.1) whenever I am attempting to listen for a connection (-lvnp) on a port i get no terminal output like "Listening on [any] 1234" im currently using iterm2 and can never seem to netcat to actual connect to anything.
currently im working on the "File Upload Vulns v2.1" room and I have added everything to my /etc/hosts that is required and I have no issues connecting to the sites but I can never seem to get a successful netcat connection.
Sike found out i had an error in the pentest monkey .php -_- Thank you though!
can vouchers expire?
is any mod here?
I need help regarding one thing
I had one month subscription of thm
which was suppose to end on 26th august
But they charged for next session too which I dont want
How can I cancel that And Get refund?
You need to need email
