#site-support

1 messages · Page 15 of 1

cerulean skiff
#

Having some isses with copying files from TryHackMe machine to MacOS. Currently i am stuck in the Room "Threat Intelligence Tools" Task 5 PhishTool. Here are files in .eml format provided which should be used with webbased PhishTool. Can't export these files out of the machine. Any help on that?

nocturne dirge
cerulean skiff
cerulean skiff
cerulean skiff
#

found the details for attack box. Here it's about the other machine that you fire up for this task. this one has only a private IP address and is not intended to be connected to. but there are the .eml files residing that should be used to be uploaded online in PhishTool.

plush bay
tribal mason
plush bay
tribal mason
#

Okay so You need to have access first, you got it?

#

If it's a webserver you need to find URL and download from there, If it's not you need to get access from ssh or netcat

#

And Then you can mount files from the target machine to your machine

cerulean skiff
#

can't get access to this machine. can ping it but there are no shared credentials like with the attackbox

tribal mason
#

Then it should be in your task to find, Which room are you in?

bronze vale
#

Please do not tell people to download anything from the rooms, especially the malware rooms.

cerulean skiff
#

did i get the instructions wrong for this room / task?

plush bay
#

sorry jabba

bronze vale
#

Hey all,

Please do not tell people to download any material from the rooms on the site.
We specifically use machines that are in an isolated environment to avoid damage to your systems.

It is imperative that you use the labs provided:)
Thanks animewave

cerulean skiff
#

the files are in the machine that have no internet access. attackbox would have been easy, because there i have internet access.

bronze vale
#

Well, the person in question is looking for help copying files from the room machine, not the AttackBox.

But regardless of where, we are really trying to avoid anyone from damaging their system, especially as downloading malware onto your home network might not end well:)

tribal mason
cerulean skiff
#

i do not need necessarily on macos, would be happy to have them in attackbox, but there are stored in the other vm

tribal mason
#

So, finally i understood you want to access a file from target machine to your Attackbox right?

cerulean skiff
#

yes

tribal mason
#

So, you need an application have you downloaded it?

plush bay
#

you sure the target machine does not have a local instance of phishtool on it already???

bronze vale
tribal mason
#

It should be somewhere in your machine

plush bay
#

also the listed questions looks like ones you can answer by simply using a text reader on the eml file or opening it in thunderbird on the target machine

tribal mason
#

It's machine implemented task so everything you need (especially files that is needed for answers) should be in your machine

cerulean skiff
#

Yeah i got it now. room was all about PhishTool and setting up an account, but yeah i see just opening the mails with thunderbird is fine. sorry for confusing everybody. thanks for your great help.

plush bay
#

no problem... also sorry again jabba

cerulean skiff
#

imho instructions could have been written better, at least i was confused.

tribal mason
#

yeah, i was also irritated while writing that. (Sorry again)

signal condor
#

sorry I have never published a repository on github and I got a doubt when I saw the licenses section, the program I intend to publish is a client that uses an api to connect to a site, there shouldn't be any problems if I put an apache license even if I'm using an api that is not mine? (sorry for stupid question)

plush bay
scenic torrentBOT
#

Gave +1 Rep to @plush bay

plush bay
#

no problem... just trying to help you get an answer as this might be drowned out otherwise

ocean maple
#

I am having some trouble. I can't connect to the network. I have a subscription but when I went to the Access tab it says not connected. I thought that I could use the web based machines when I bought the subscription. I am trying to work on Advent of Cyber.

sour prairie
#

hey i am doing the breaching ad room

#

and when i try to set up a dns on a web attack box running this command systemd-resolve --interface breachad --set-dns $THMDCIP --set-domain za.tryhackme.com

#

i get a systemd-resolve command not found...

twilit patio
#

Just got an email saying sorry to see you go, subscription is expired, but neither have I cancelled , and I've had enough funds why did I get automatically booted off platform.

zealous yoke
sterile linden
#

Hi everyone,

I experienced problems copying files and watching videos from the target machine.
In agent Sudo, can’t copy pictures
Advent of security 2022, can’t download the logs.
Year of the rabbit, can’t watch or copy the video.

I use OpenVPN to connect my VM Kali. Windows 10 is a host, and everything is up to date.
My Kali doesn't have an AV, firewall, etc.
Turning off the host machine security measures didn’t solve the issue.
Using the THM attack box didn’t have issues, however, this temporary solution is not compatible anymore.

I tried:
+) Using the scp -l tag to limit bandwidth
+) Using rsync
+) ethtool -K tun0 tso off gso off gro off
+) I can’t create an ssh tunnel since I don’t have permissions

The get command with FTP ends up as “stalled.”
The get command with SMB ends up with “NT_STATUS_IO_TIMEOUT listing”
Please advise.

Best day yo 🙂

boreal tapir
#

Anyone knows why Complete Beginner(Path) shows up for some people, and some don't? In my class we need to do the hole room for a challenge, but some people (premium users and free) just don't have it.

austere cobalt
#

I need help logging back into TryHackMe please.

mystic snow
#

Hello all,
Did any of you already cloned a room with a lab like https://tryhackme.com/room/breachingad ?
When I am cloning it I am not able to access to the network, is that normal ?
I sent an email to hello@thm.com few days ago regarding this problem, but I did not get any answer yet :/

glacial hound
glacial hound
austere cobalt
#

Sent

velvet wasp
#

which latest openvpn client versions are supported by tryhackme?

naive dust
#

Beginner question "Do you guys recommend a bare bones Ubuntu docker image to learn and build tools from scratch or kali headless?" Im on a intel mac book pro 2015 I have a kali VM but dont use it a lot because of ram issues.

vague hull
#

i'm a beginner too. i think its nice to have a gui for tools like burp suite for example, so i would make it dual boot bare metal or create a bootable usb with kali on it

#

8 gig ram should be enough for a host and one vm though

broken bear
#

that's cutting it kind of close; I wouldn't want to trust a windows host to manage 8GB smart enough to not starve even a 2GB guest

naive dust
#

@broken bearYeah this is why I was thinking of using docker

stark frigate
#

Can anyone else not access the openVPN config file?

broken bear
pale sandal
#

How can I use the student discount and also see if I'm eligible to use it

weary spindle
pale sandal
mystic snow
naive dust
#

I'm getting "sorry this token is already used by someone" when attempting to verify my Discord...

inner pulsar
#

I did many commands to the bot but didn't got any response
Like notifyme, rank etc..

#

Yes im verified

warped knot
inner pulsar
#

No

quaint birch
#

Has anyone else had an issue with downloading a VPN config file for Networks? I've gotten the config file for machines to work (just switching servers), but can't seem to fix this issue. I just get a 404 and no downloaded config. Thanks!

obtuse moss
#

Ethiopia, East Africa

unique nebula
#

heyo, trying to download the VPN config file for Wreath (I've regenerated them), except I keep catching 404's

naive dust
#
└─# ftp 10.10.245.177 21
Connected to 10.10.245.177.
220 (vsFTPd 3.0.3)
Name (10.10.245.177:kali): anonymous
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||43078|)
ls
ls
s

sdfsdfsfsfs```
#

what is Entering Extended Passive Mode

#

this happens every time i use ftp

#

how to disable it

full prawn
#

I'm having the same issue as @unique nebula. Can't download the VPN pack for Wreath, just keep getting a 404.

glad orbit
#

how can I connect to tryhackme through openvpn using tcp connection instead of udp?

weary spindle
full prawn
scenic torrentBOT
#

Gave +1 Rep to @weary spindle

weary spindle
#

Happy Hacking

clear bough
crystal marlin
# naive dust Anyone?

That would mean you have already verified your THM account with a different discord account

#

What happened to the other discord account ?

naive dust
#

I'm not aware of another discord account

spring wren
#

why is nmap so slow on Telnet Network services? Seems really slow on that nmap request today.

wise sluice
#

Hi there, just got an e-mail with the vouchers offer. If I buy it, can I offer it to someone else? It asks for an e-mail, is it supposed to use my e-mail (associated with THM) or use the email from the person who will receive the gift/voucher ? (which also has a THM account)

dawn olive
#

Hello, what is the mail address for sales/customer support? I need my personnal data on the invoice (full name, and postal address)

sharp bisonBOT
hasty cargo
#

hello there. please, let me know when to put my token so to get verified ?

#

*where

broken bear
#

!docs verify

sharp bisonBOT
hasty cargo
#

thank you @broken bear

scenic torrentBOT
#

Gave +1 Rep to @broken bear

sterile steppe
#

I have done AoC every day for all 20 days of December. Yesterday, my streak was at 19 and I just completed day 20. After doing so, my streak has been reset to 0. How can I resolve this?

keen pumice
steel dome
#

hi tech support. no t sure where this question fits (if its not in this channel) so please lmk, but here's my issue
when I'm in a room and finish a task (or whatever its called the content is below the long grey bar) and move on to the next task, the problem I have is when I click the down arrow on the grey bar to expand the content, the page sends me to the middle or lower end of that next content section. I then have to scroll all the way up to the beginning of that content section. Is there a way to get the (web)page to navigate to the beginning of the content when the bar is clicked on?

#

I hope I'm explaining this right. I wish I could show what I mean.

chilly pike
#

Hey @steel dome I think I know what you mean. Whch browser are you using?

#

actually the browser is probably irrelevant. This kind of scroll behaviour is quite normal on pages with accordions. Its because when one accordion is open, it will automatically get closed ( only 1 can be open at the same time ) and thus you 'lose' the height of that container and your scrolled position gets a little funky

#

I dont think you can really prevent this but to make it maybe slightly less annoying, you can consider to scroll up to the bar of the current open container, close that first and then open the next one. You'll still need to scroll to close the current oe, but at least when you open the next one, you'll be at the top of that 🙂

steel dome
#

@chilly pike -- thanks for the feedback. I predominantly use firefox, but its the same experience on any browser.
I'll try your suggestion as it does seem a little less annoying. Thanks.

scenic torrentBOT
#

Gave +1 Rep to @chilly pike

cosmic haven
#

new coupon

chilly pike
cosmic haven
#

is there any valid voucher or coupon that still working please

tidal ether
#

hey can someone pls help me with the openVPN service? i am trying to access a machine with an ssh tryhackme@machine-ip and using the tryhackme password but keep geting permission denied.

supple lion
#

Hi, i have a problem with my subscription, how can I contact with TryHackMe Support.

tidal ether
scenic torrentBOT
#

Gave +1 Rep to @tidal ether

glacial hound
tidal ether
#

im on the OWASP Top 10 in task 29

#

nvm

#

found my problem

bronze vale
inland ether
#

Good day, I am trying to use VPN pack for wreath network, but when I download it, it is empty and I get the following error:
2022-12-21 07:38:43 Cipher negotiation is disabled since neither P2MP client nor server mode is enabled
Options error: You must define TUN/TAP device (--dev)
Use --help for more information.

sterile steppe
#

Is there an official support method for incorrect streaks? I went from 19 to 0 after completing AoC day 20 in the middle of the afternoon.

A few other friends and I do it every day and they also reset. We have refreshed the page and logged in/out.

vagrant loom
#

Hi all, I am having issues with the DNS in the lab 'Enumerate Active Directory'. I'm connected to the the network, I can ping the THMDC IP, I have set up the DNS server to the THMDC IP, I restarted NetworkManager but I still can't resolve thmdc.za.tryhackme.com

weary spindle
#

?*

vagrant loom
#

What is the lab vpn pack ?

#

I connect with the enumad opvn file

weary spindle
#

That should be the right one.

Can you

cat \etc\resolv.conf

#

Or is it / ...

vagrant loom
#

Generated by NetworkManager

search home
nameserver 192.168.1.1
nameserver 10.200.49.101
nameserver 1.1.1.1

#

10.200.49.101 is the THMDC IP in the diagram

weary spindle
#

Is the server started, yes?

#

Top right corner of the image in the room.

vagrant loom
#

──╼ $ping 10.200.49.101
PING 10.200.49.101 (10.200.49.101) 56(84) bytes of data.
64 bytes from 10.200.49.101: icmp_seq=1 ttl=127 time=34.2 ms
64 bytes from 10.200.49.101: icmp_seq=2 ttl=127 time=34.4 ms
64 bytes from 10.200.49.101: icmp_seq=3 ttl=127 time=35.1 ms

#

yes, running

#

I have the issue since yesterday, I guess it has restarted since but nothing changed

sour prairie
#

i am doing explotiing ad room and on attack box when i want to connect to the ad i get this

#
Unknown interface exploitad: No such device
vagrant loom
vagrant loom
#

Somehow worked once, same command few seconds later failed

weary spindle
#

nslookup can be buggy.

#

When I helped test the room, nslookup wouldn't work for me, but I was connected.

gleaming lynx
#

whenever i try to download my openvpn configuration file for wreath, the page give me: Uh-oh, this page has been lost in the matrix. Is there something special about downloading a network config file i need to know`?

vagrant loom
#

Can't resolve

#

So can't do the lab

weary spindle
gleaming lynx
scenic torrentBOT
#

Gave +1 Rep to @weary spindle

gleaming lynx
#

wow, now i can download the config file but nothing is in it

naive dust
#

Hey folks, can anyone check if Spring room is working as it's supposed to be? The machine shows only port 22 as open. I've restarted it a few times.

pulsar jetty
#

Can someone help me with openvpn ? I can not connect over udp

bronze vale
radiant matrix
#

Hi- I'm using the in-browser windows machine in Chrome on Mac. How to I cut/paste into the Windows machine from the other side of my browser? Do not see the slide-out clipboard like on attackbox.

muted harness
#

Can anyone access the attack box or Kali box for Day 21 advent of cyber?

#

Nothing seems to load for me

#

I tried terminating and accessing the box again, but no luck.

chilly osprey
#

I'm a bit behind and working on Day #6 Advent task. A question - Why is it evident from the result(screen) that we are dealing with a PowerShell script, and it is using base64 Encoded string to hide the actual code?

glacial hound
pine spoke
#

Hi, is there any legitimate way to obtain csrf token outside of rooms? I am making QoL extension for THM, but recent update removed csrf token from HTML code, hence I should make request in room to just obtain token, which would increase traffic and would be suboptimal solution in general ||https://gitlab.com/privat33r/THM-Extender||

#

It's in early stages of development, so I apologize in advance for code quality, lack of refactoring and general bad practices, such as posting directly to "master" branch (at the moment it doesn't have really "stable" version, so I decided that a few commits later I will move development to "dev" brach)

glacial hound
scenic torrentBOT
#

Gave +1 Rep to @pine spoke

uncut oxide
#

Is there a means of only requesting a singular apt-get install to pull the one package specified in a parameter?

I'm needing to update the kali box vm's Wine32 install to attempt the Brainpan 1 lab, but it's attempting to pull MANY other packages as well that dont seem to be relevant, resulting in a 1.2gb pull before I can even begin

Adds a bit of overhead if I need to pause or restart the lab..

eager fulcrum
radiant dagger
#

;slkdjf;lksjdf

#

what he said

eager fulcrum
#

Wine being 1.2GB isn't that much.

#

It's a whole windows interoperability layer.

uncut oxide
#

Normally i'd be fine with a oneoff dependancy install, just annoying if it's a requrement every time i need to spin up the browser vm..

Guess I'll look into setting up a local vm instead, might help save time

arctic prawn
#

It’s impossible for me to change my occupation in public profile. It’s driving me crazy. Any solutions?

karmic canyon
#

I have a question, & maybe this isn’t the correct chat, or even group, but I have an old laptop with an i3, & 8 ram with 500gb for hard drive. It’s currently running windows, is there a possibility to root the laptop & use a Linux OS?

radiant dagger
karmic canyon
#

I am fairly new to Linux, still getting used to the command line, what version of Linux would be good for a beginner? Ubuntu, X-Ubuntu, Kali, Parrot or other?

radiant dagger
#

well if you're doing tryhackme stuff, Kali.

karmic canyon
#

I am, also going back to college for cybersecurity… biggest change of my life. Thank you @radiant dagger

scenic torrentBOT
#

Gave +1 Rep to @radiant dagger

wind cosmos
#

how do i ssh into a vm?

#

whats is the password?

wintry aurora
#

Hi I'm developing a room and I'm trying to upload a windows server 2008 R2 image. I keep getting Problem converting vm.

Does Windows need to be activated with some type of volume license?

velvet wasp
vocal fog
#

The Exploiting AD network may have gotten stuck—no pingback from the hosts.

plush bay
vocal fog
plush bay
#

well posting in #exploiting-ad and stating which subnet might get others attention to help with reseting the network

unique crane
#

hello , does someone knows how to fix "exit code 1" on replit?

plush bay
#

yes.... the attackbox does not really have a lot of services that could be hacked if that is what you are worrying about.... also it would be against tos to attack someone elses target machine or attackbox meaning said person has a high chance of getting banned from the platform permanently... also when you shut down the attackbox that ip gets poofed unitl another random chance makes it used again

serene terrace
#

I am doing the intro to offensive security course, and the first part has you "hacking" fakebank.com. However, after successfully doing it, I try to enter the account balance, and it says incorrect, even after refreshing the page and completely relaunching firefox. Id attach a screenshot, but it wont let me. Any ideas?

plush bay
serene terrace
#

ohhhh, I am sorry. Thank you, I apologize for my stupidity lol

plush bay
glad oyster
#

Could you verify for me and then post a screenshot? @viral robin

#

!docs verify

sharp bisonBOT
viral robin
glad oyster
viral robin
#

ok

glad oyster
viral robin
#

ok

#

let me try again

#

@glad oyster

#

i am fairly certain that is the IP address I am supposed to ssh to

#

at least according to the follow along video

#

nvm, its the ip address at the top of the screen, not in the lesson

#

must just be an example

#

For example: ssh tryhackme@MACHINE_IP . Replacing the IP address with the IP address for your Linux target machine. Once executed, we will then be asked to trust the host and then provide a password for the "tryhackme" account, which is also "tryhackme".

#

the tryhackme password is not working

gusty steppe
#

Hi, I cannot submit any answers for any of my open AoC 2022 tasks, days 20-22. So far, I have never had problems with that. No idea what happened.

plush bay
viral robin
#

@plush bay am I missing something on the exercise? I am ssh to the device listed at the top of the page in green. Once connected I am prompted to enter than password "tryhackme" but it's being denied

plush bay
#

also do you get any errors in the tarminal

#

if so post a screenshot of those here please

viral robin
#

@plush bay

gusty steppe
scenic torrentBOT
#

Gave +1 Rep to @plush bay

plush bay
#

the ip shown in the images is an example ip

#

you need to start your own target machine and use that ip instead

viral robin
#

ok, I was confused, I thought that was for my machine

plush bay
#

green start machine button == target machines
blue start attackbox button == your in browser attacking virtual machine to use to attack the target machines

#

sorry if you are colour blind as then this might be harder to react to

viral robin
#

im not color blind just not reading apparently

#

as I tell engineers, reading is hard, I should know

#

wohoo, im in, thank you

#

@plush bay how do I give you rep points?

plush bay
scenic torrentBOT
#

Gave +1 Rep to @plush bay

glad oyster
#

Glad shadow could help!

#

Sorry for not responding, was busy

atomic flax
#

Hello would anyone be able to help me ?

chilly pike
#

best to ask your question @atomic flax 🙂

atomic flax
#

Ok, So I started to use my own VM. Yesterday morning it was working fine but i noticed that it stopped working mid-day. I read some forms and reddit and i am not able to get anywhere. its like the first part of my IP address does not match up with the machine i am trying to access. How can I fix that ?

#

for example my VM is 10.2.xx.xx while the machine i want to access is 10.10.xx.xx . Am i able to control this to an extent ?

#

I keep trying to change servers and regenerating the openvpn. Idk what else to do.

weary spindle
#

If you use the cli command and see connection successful or something it will work

atomic flax
#

Oh ! Ok then 🙂

#

Thank you

violet vale
#

I’m using a VM to connect to the THM network to complete various series. I’m noticing that while running <NMAP> <GOBUSTER> or just browsing to the webpage for a series the connection seems to timeout briefly. I’ve checked my local network and not seeing any issues. Any thoughts on why this is happening?

violet vale
#

I don’t recall seeing one but will take another look in case I missed it.

heady summit
#

i'm on the task authentication bypass -> username emuration and started my attackbox. There should be running a website http://IP_AD-RE_SS/customers/signup but only getting error 405.

Error response

Error code: 405

Message: Method Not Allowed.

Error code explanation: 405 - Specified method is invalid for this resource.

weary spindle
heady summit
weary spindle
#

Which room are you doing?

There might be another green start machine button on task 1.

broken bear
long ingot
#

Hello! I am doing the Yara room in the Blue Team track... I'm connected via Ovpn, can see the machine with port 22 open, but when I attempt to connect it simply times out without providing a way for me to enter my password.

#

I just moved onto doing it in the browser, but is really odd.

atomic flax
#

Via the terminal

long ingot
#

Yeah... sorry I should say when I attempt to SSH via the terminal it times out and says 'connection closed by remote host"... doing it in split screen but its still really odd

crystal marlin
long ingot
crystal marlin
long ingot
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

long ingot
crystal marlin
crystal marlin
#

!docs verify

sharp bisonBOT
broken bear
#

Your other discord account was banned?

#

So you are evading a ban? Did you get in contact with the discord administrator to appeal?

chilly pike
#

-undelete -a

radiant matrix
#

I'm trying to rdp into a tryhackme windows machine from my kali linux (not attackbox). I've tried rdesktop to the IP but receive error. How do I do this?

radiant dagger
#

is the target listening on 3389? what command are you using, and what syntax

unique nebula
uncut vortex
#

Hello, is there an admin to DM me please ?

pine spoke
#

@glacial hound hi. Excuse me, any update on my issue?

glacial hound
urban flare
#

Good people tell me that after refreshing/restarting browser I should have an option to split the window and reopen my attack/kali box. Where I should find it? Can't see it anywhere

#

Tried other browser too, literally can't see it anywhere :/

lime geyser
#

Hi All, I had this write up in the advent of cyber room and they told me to use the attack box. I'm locked out of the attack box even though I wasn't able to use it today. I hope someone can reset my access.

Hi, All first time here. I'm looking for a little advice. I'm a semi new TryHackMe user so I lurk to learn and the subscribe button actually never works for me when I contemplate it.

Anyway so today I had one of those glitches with the site where my attack box wouldn't load and just sat their on the post loading screen. I closed the box after ten minutes and surprise the box's free hour is used up. okay not terrible I'll just use the Kali box.

Subject: advent of cyber Day 21 - MQTT

So on Kali I actually had to manually install Mosquitto. okay cool did that. I got a touch stuck setting up the subscription so I went to the video tape. I preformed the nmap cmds got ip:port and mqtt... so now I get to my actual issue/ question.

I enter the following and receive:
mosquitto_sub -h 10.10.169.14 -t device/init
Error: No route to host (edited)

pine spoke
pearl chasm
#

Hey Everyone, new here, I have been working through Advent of cyber Day 11, but I am stuck

#

it says : volatility error file does not exist

naive dust
#

Hi,
Does anyone know how to get support for subscription related issue. I am new here. I have raised issue on email support but thats 3 days now.

#

I am getting frustrated now.

eager fulcrum
pearl chasm
#

thats the extension it shows in the directory

#

and in the instructions and walkthrough vid

#

ahhhh, you are absolutely correct.

#

vmem. not vnem. wwo

#

Thank you for your response James, ill be sure to triple check my characters when typing out. I cannot believe I missed that.

desert kayak
#

static-labs.tryhackme.cloud’s server IP address could not be found. shows up while using view site

fathom schooner
#

Is VPN down for everyone? I can't even download my ovpn...

#

Looks like it's just the US-East server

#

West is working

tribal mason
#

It shouldn't have access to your real machine due to security, AttackBox already has everything you need in a room

#

For example, you wouldn't want someone to download a virus file from an attack box in the malware analysis rooms right?

tall flame
#

Hello. How can I change my tryhackme username?

plush bay
tribal mason
plush bay
#

!email

sharp bisonBOT
tribal mason
#

Shadow is fast.

plush bay
#

is the email address

#

yuup shadow is fast typer

tall flame
#

thanks : )

keen pumice
#

SSH via VPN isn't working. nmap scan showed SSH is open, http and ftp all worked.

#

ssh tryhackme@X.X.X.X just hangs

#

Found some posts online that suggested changing MTU; I tried doing that for tun0 and eth0 ( sudo ip li set mtu 1200 tun0) and no dice

#

Tried closing/re-opening the OpenVPN connection. Nothing

#

It works from a different computer so possibly something wrong with the one I'm right now.

pine spoke
keen pumice
pine spoke
#

Maybe it rejects fingerprints? Try to clean fingerprints cache

keen pumice
#

mv ~/.ssh/known_hosts ~/.ssh/known_hosts.old still not working

#

No indication from nmap that telnet is open on the target machine

#

Also on Kali, so probably no putty

pine spoke
#

I mean:
telnet Target 22

keen pumice
#

Well on Kali in WSL2 in Windows 11, but rather keep vpn contained there. Other working computer is Kali in WSL2 in Windows 10 so I wonder if there's a firewall difference.

pine spoke
#

Also you can try ssh -vvv flag to check more data

keen pumice
#

Interesting I got a "Connection established"

#

Stops with "expecting SSH2_MSG_KEX_ECDH_REPLY"

pine spoke
#

if mtu manipulations didn't help, you can try again with turned off firewall, if it works, then consider changing firewall settings. Also reboot sometimes might be a solution, especially for VM and after altering network settings.

keen pumice
naive dust
#

!email

sharp bisonBOT
keen pumice
#

Random online comment mentioned upgrading some packages on their system fixed it for them.. Just noticed I 224 upgradeable packages. I have no idea why that would work but bombs away (and after 5 minutes it's only 10% through >.<)

subtle bay
#

Seem to have a repeating issue with NaN erros when importing json files into Bloodhound (Post-Exploitation Basics room)

#

...also I had to use the Attackbox rather than my Kali VM as ssh into Kali is a security risk. Should I build a new Kali VM for more risky activities and open ssh?

finite oxide
#

It seems that I can't use a hyphen in my full name on my profile? :(
A-B reverts to AB

tribal mason
bronze vale
tepid sleet
#

Hello everyone! I wanted to know, How much time does it take for the writeup to get published in a ctf's page ?

weary spindle
tepid sleet
#

Oook Thanks !

hoary comet
#

help

#

my bluetooth isn't showing up on windows 11

#

although i have bluetooth capabilities on my Intel Dual Band AC Wireless 7265

tribal mason
#

Have you updated drivers?

#

(Also Reminder This channel is only for TryHackMe related tech support)

hoary comet
#

ive updated drivers

pine spoke
#

@hoary comet

  1. Check that the device transmits bluetooth
  2. Check that bluetooth capabilities are on (search "bluetooth" in start menu)
  3. Try restart
  4. Reinstall drivers
  5. Try from Live OS
  6. At this stage it might be hardware problem, if aforementioned + google didn't help, consider using external bluetooth adapter/replacing current one
proven fulcrum
#

Please fix the first four badge its not working thank you. Merry Christmas ❤️

feral delta
#

Hi,
i can't deploy machines and when i try to do it, it says that "you already have a machine running in this room terminate it first" but i don't have any machines running

feral delta
#

does anyone know, about this?

tribal mason
feral delta
#

and what to do?

tribal burrow
#

if ther is running target machine, try refresh browse. sometime it not showing IP and indicate that machine is running

feral delta
#

The rooms are terminated when finished, but still showing error

tribal mason
#

do CTRL + F5

feral delta
feral delta
tribal mason
#

Can you try clearing your browser cache

tribal burrow
#

do you have split screan option

#

or try CTRL + SHIFT + F5

tribal mason
#

If you still get that error look into rooms that you've been recently If a machine is still open

pine spoke
#

It adds button with which you can manage your machines

ruby flax
#

uhm does anyone know why i can't view the hints in the advent of cyber room?

pine spoke
balmy birch
#

Hi Team... How can share my badge on social media ?

tribal burrow
scenic torrentBOT
#

Gave +1 Rep to @tribal burrow

molten zenith
#

I am running kali-linux on Mac M1 using UTM VM. Used the current .iso full offline installation file. Updated Kali, installed spice-vdagent and spice-webdavd and still can't share or cut and paste between host and guest. I can access the share folder at the very top of the UTM window, but not in Kali file system. Don't know what else to do. Can someone tell me if there is something else I need to do or if I forgot something? need help, so I can share files.

neat vapor
#

is it impossible to change Nickname on Certificate? can thm support help me?

weary spindle
cobalt crown
#

Hey guys. I want to import a VPN connection(THM connection) to the GNOME network settings:

#

But it displays an error msg when i try to do it

#

Can anyone help me with this

tribal burrow
#

what error ?

#

are you select import from file or openVPN

cobalt crown
#

then it worked

little crater
#

hello guys !

I want to report a bug in a room, can i dm an admin ?

tribal mason
bronze vale
little crater
bronze vale
tribal mason
#

It counts as a bug.

little crater
#

ok thanks guys

molten zenith
tribal burrow
#

vpn is vpn. how you start it is ypu personal thing

molten zenith
#

That's what I thought. Thank youblobfingerguns

novel estuary
#

Hi, it seems https://tryhackme.com/room/exploitingad network got an issue. I am connected to the network via OpenVPN but cannot connect to anything from the network. All seem to be unreachable.

Seems to be having an issue from attackbox as well.

eager fulcrum
#

Networks are different

tribal mason
long ingot
#

Hello! I am doing the MISP room currently, and it acting very strangely... Whenever I click on (seemingly) anything, It either locks out or asks for credentials again. When I provide those credentials it is giving me an error message that I have tripped the cross-site request forgery protection of MISP. Any help would be appreciated!

misty moss
#

is this the place for subscription related questions ?

long ingot
viral robin
#

Hi all

Having an issue in walking an application task 3

I have what appears to be the right flag but it’s not working

The question is

What is the framework flag?

#

@torn citrus

torn citrus
torn citrus
#

Javascript includes on the homepage possibly

#

The framework meaning (what it was built upon)

viral robin
torn citrus
#

I would assume, I’m on mobile and guessing but from the question it seems that’ll solve your problem.

viral robin
scenic torrentBOT
#

Gave +1 Rep to @torn citrus

torn citrus
#

Going to be something easy like that

viral robin
#

It’s all new to me, so finding these things is exciting

torn citrus
viral robin
summer matrix
#

Stuck on 0.00% , uplaoding an .ova file

olive gorge
#

Hey I just noticed that I paid for a yearly subscription however in my account it says my subscription will expire in February of 2023. I think I might need to contact, the billing people or something but I thought I would ask here first.

rocky galleon
#

Having issues with VPN. Downloaded VPN file for wreath and shows connected in the green back but cant access the network. already tried to reboot vm and regenerate vpn file. still no luck.

cobalt crown
#

Its just easier to use

sharp bisonBOT
summer matrix
olive gorge
rocky galleon
#

having issues with wreath. shows connected but not able to ping or perform nmap scans. had similar issues with AD labs. the only ones that work fine are the standalone machines. have the correct certificate, rebooted vm, also regenerated certificate for wreath.

summer matrix
#

a 350 mb file

#

taking forever

tribal mason
#

just cancel and do CTRL + F5 and then upload your file again

summer matrix
#

done that many times

#

it stays on 0.00% for more thn half an hour

tribal mason
#

weird, have you tried clearing browser cache?

summer matrix
#

im working inside a ubuntu vm btw

#

and yess

#

clear cache , reboot , etc

tribal mason
#

Well, I don't know sorry

summer matrix
#

thankss

summer matrix
timid rose
#

can anyone help me

#

averytime i start up my kali even when i shut it down

#

i get this terminal i just cant close or something

#

i probs hit the wrong keybind accidently

bronze vale
unique nebula
#

how does one remove friends?

#

nvm there's a UI bug

#

what's this about a maximum amount of friends though?

#

I have 13

pliant bough
#

Hi I'd like to change my username, who do I need to contact

tribal mason
sharp bisonBOT
pliant bough
#

Thanks @tribal mason

scenic torrentBOT
#

Gave +1 Rep to @tribal mason

versed skiff
#

I lost my steaks i don't know why it happens with me many times

plush bay
versed skiff
#

Yes

plush bay
#

hmmm

#

what is the country flag you get on your profile???

versed skiff
#

I already answered yesterday and when i come today i found 0

#

Morocco

plush bay
#

because then daily reset is at the time of 00:00 for morocco

versed skiff
#

But it's not even 00:00 now

plush bay
#

so if you miss to answer a question inside that time frame you could probably see the problem

#

¯_(ツ)_/¯

versed skiff
#

It's 11:50

plush bay
#

best email support explaining the issue

#

!email

sharp bisonBOT
weary spindle
#

I've seen people say they refreshed and it restored it

#

Try Ctrl and F5.

versed skiff
scenic torrentBOT
#

Gave +1 Rep to @plush bay

plush bay
versed skiff
somber pike
#

The VM's are slow and not even responding 😦

bronze vale
somber pike
#

Attackbox
I was doing warzone room

quartz mirage
#

Trying to complete the Metasploit: Exploitation room but my elf file keeps throwing a Segmentation Fault

root@ip-10-10-10.10:/tmp# strace ./rev.elf 
execve("./rev.elf", ["./rev.elf"], 0x7ffc021f9ab0 /* 21 vars */) = 0
strace: [ Process PID=1548 runs in 32 bit mode. ]
socket(AF_INET, SOCK_STREAM, IPPROTO_IP) = 3
connect(3, {sa_family=AF_INET, sin_port=htons(4444), sin_addr=inet_addr("10.x.x.x")}, 102) = 0
mprotect(0xffe43000, 4096, PROT_READ|PROT_WRITE|PROT_EXEC) = 0
read(3, "echo VDVZOtq48wWk\n", 106)     = 18
--- SIGSEGV {si_signo=SIGSEGV, si_code=SI_KERNEL, si_addr=NULL} ---
+++ killed by SIGSEGV (core dumped) +++
Segmentation fault (core dumped)
#

Is the fault with the machine?

msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=tun0 LPORT=4444 -f elf > rev.elf
#

nvm, gave up on it and just got the hash from shadow..

atomic flax
#

i am having trouble connecting to a room via openvpn with a vm would anyone be able to help me ?

weary spindle
pine spoke
pine spoke
#

Thank you 🙂 @glacial hound

scenic torrentBOT
#

Gave +1 Rep to @glacial hound

blissful minnow
#

How to get 5% on my swag... because i have more than 45 days streak?

weary spindle
#

You need to contact support.

#

!email

sharp bisonBOT
blissful minnow
scenic torrentBOT
#

Gave +1 Rep to @weary spindle

atomic flax
#

i am trying to ping a room, i can with an attackbox but i cant with my vm

tribal mason
atomic flax
#

let me try

#

that is not working :/

tribal mason
#

that means you're not connected to vpn correctly, Can you show me openvpn command output?

atomic flax
#

qml@ubuntudesktop:~$ sudo openvpn Qlacus.ovpn
2022-12-26 11:04:47 DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-256-CBC' to --data-ciphers or change --cipher 'AES-256-CBC' to --data-ciphers-fallback 'AES-256-CBC' to silence this warning.
2022-12-26 11:04:47 OpenVPN 2.5.5 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Jul 14 2022
2022-12-26 11:04:47 library versions: OpenSSL 3.0.2 15 Mar 2022, LZO 2.10
2022-12-26 11:04:47 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2022-12-26 11:04:47 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2022-12-26 11:04:47 TCP/UDP: Preserving recently used remote address: [AF_INET]54.193.147.96:1194
2022-12-26 11:04:47 Socket Buffers: R=[212992->212992] S=[212992->212992]
2022-12-26 11:04:47 UDP link local: (not bound)
2022-12-26 11:04:47 UDP link remote: [AF_INET]54.193.147.96:1194
2022-12-26 11:04:47 TLS: Initial packet from [AF_INET]54.193.147.96:1194, sid=aebd30ad 25f6c03d
2022-12-26 11:04:47 VERIFY OK: depth=1, CN=ChangeMe
2022-12-26 11:04:47 VERIFY KU OK
2022-12-26 11:04:47 Validating certificate extended key usage
2022-12-26 11:04:47 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2022-12-26 11:04:47 VERIFY EKU OK
2022-12-26 11:04:47 VERIFY OK: depth=0, CN=server
2022-12-26 11:04:47 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bit RSA, signature: RSA-SHA256
2022-12-26 11:04:47 [server] Peer Connection Initiated with [AF_INET]54.193.147.96:1194
2022-12-26 11:04:48 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)

#

2022-12-26 11:04:48 PUSH: Received control message: 'PUSH_REPLY,route 10.10.0.0 255.255.0.0,route 10.1.0.0 255.255.0.0,route-metric 1000,route-gateway 10.13.0.1,topology subnet,ping 5,ping-restart 120,ifconfig 10.13.11.218 255.255.128.0,peer-id 79'
2022-12-26 11:04:48 OPTIONS IMPORT: timers and/or timeouts modified
2022-12-26 11:04:48 OPTIONS IMPORT: --ifconfig/up options modified
2022-12-26 11:04:48 OPTIONS IMPORT: route options modified
2022-12-26 11:04:48 OPTIONS IMPORT: route-related options modified
2022-12-26 11:04:48 OPTIONS IMPORT: peer-id set
2022-12-26 11:04:48 OPTIONS IMPORT: adjusting link_mtu to 1624
2022-12-26 11:04:48 Using peer cipher 'AES-256-CBC'
2022-12-26 11:04:48 Outgoing Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
2022-12-26 11:04:48 Outgoing Data Channel: Using 512 bit message hash 'SHA512' for HMAC authentication
2022-12-26 11:04:48 Incoming Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
2022-12-26 11:04:48 Incoming Data Channel: Using 512 bit message hash 'SHA512' for HMAC authentication
2022-12-26 11:04:48 net_route_v4_best_gw query: dst 0.0.0.0
2022-12-26 11:04:48 net_route_v4_best_gw result: via 192.168.254.254 dev enp0s3
2022-12-26 11:04:48 ROUTE_GATEWAY 192.168.254.254/255.255.255.0 IFACE=enp0s3 HWADDR=08:00:27:d0:71:70
2022-12-26 11:04:48 TUN/TAP device tun0 opened
2022-12-26 11:04:48 net_iface_mtu_set: mtu 1500 for tun0
2022-12-26 11:04:48 net_iface_up: set tun0 up
2022-12-26 11:04:48 net_addr_v4_add: 10.13.11.218/17 dev tun0
2022-12-26 11:04:48 net_route_v4_add: 10.10.0.0/16 via 10.13.0.1 dev [NULL] table 0 metric 1000
2022-12-26 11:04:48 net_route_v4_add: 10.1.0.0/16 via 10.13.0.1 dev [NULL] table 0 metric 1000
2022-12-26 11:04:48 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
2022-12-26 11:04:48 Initialization Sequence Completed

tribal mason
#

Can you regenerate your VPN file and try again?

atomic flax
#

eys

#

eys

#

yes

broken bear
#

This looks like a completed connection. From another terminal, can you ping 10.10.10.10 or curl http://10.10.10.10/whoami?

atomic flax
#

i tried pinging 10.10.10.10 but still nothing

broken bear
#

Can you post a screenshot? You'll need to verify your THM account first

#

!docs verify

sharp bisonBOT
atomic flax
#

!docs verify

sharp bisonBOT
atomic flax
#

thx @broken bear

scenic torrentBOT
#

Gave +1 Rep to @broken bear

atomic flax
#

!docs

sharp bisonBOT
#
TryHackMe
Here are all of the possible topics!
!docs url

Visit the help site

!docs verify

Learn how to sync your THM profile to Discord

!docs student

Learn about our student discount programme

!docs levels

View all the TryHackMe levels & point requirements

!docs room-notes

Get started with making TryHackMe room

!docs room-review

Learn about the TryHackMe room review process

!docs api

Read about the TryHackMe API

!docs koth

How to play TryHackMe's King of the Hill (KoTH)

!docs free-path

What rooms should you do? A free guide for beginners

!docs bug-bounty

Learn about TryHackMe's Bug Bounty Programme!

atomic flax
#

this is the openvpn outout

#

*output

tribal mason
#

can you show the output of curl http://10.10.10.10/whoami as juun said

atomic flax
#

this is the output from my host machine

tribal mason
#

have you tried regenerating though?

atomic flax
#

yes i did

broken bear
#

in the second terminal, can you show ip a

#

so you are running the vpn in the host or in the guest vm?

atomic flax
#

i am running it in the guest machine

broken bear
#

so you will not be able to access 10.10.10.10 from the host with the vpn in the guest

#

that's not how network segmentation works in this case

#

from the guest, open a new terminal and try the ip a ping and curl commands again

atomic flax
#

ok

#

this is from the guest

tribal mason
#

Open a new tab, while VPN sequence is on (It needs to be in same machine)

atomic flax
#

ok

broken bear
#

Hold up, we need to clear a couple of misconceptions up

#

If you hit CTRL-C What signal does it send to the open window?

tribal mason
#

are you using macos terminal or a virtual machine?

broken bear
#

@tribal mason Stop for a minute. You are trying to troubleshoot without having enough info.

atomic flax
#

after i press ctrl c this iswhat pops up

broken bear
#

Thatt's not what I asked.

#

When you press CTRL-C what signal does *nix send to the terminal or running program?

#

I'm asking this because I am not convinced you understand some of the basics that you need to understand to troubleshoot this in the future.

atomic flax
#

i do not understand, how can i see the *nix ?

#

ill open the vm with a gui

broken bear
#

*nix is the type of operating system. In this case, it looks like your terminal is Ubuntu, right?

atomic flax
#

yes

#

it is ubuntu

broken bear
#

What does CTRL-C do in Ubuntu?

atomic flax
#

it stops the program

broken bear
#

Right. Specifically, it sends the SIGTERM or SIGINT, which is a signal to terminate or interrupt the program.

#

So if openvpn is connected, and you send SIGTERM, it stops the openvpn program.

#

To check for your VPN connectivity, you need to either run the openvpn in a background process, or open another terminal after you connect.

molten zenith
scenic torrentBOT
#

Gave +1 Rep to @cobalt crown

broken bear
tribal mason
#

Thanks, Juun, for reminding me; I'll be cautious in the future about that.

atomic flax
#

it works

broken bear
broken bear
atomic flax
#

kinda, i think i closed the openvpn and was trying to access the network but it was closed. So i couldnt access the network

broken bear
#

Yep

atomic flax
#

dope !! thanks !!

broken bear
#

A good check is to run the ip addr show command, it will show you all the interfaces that have an IP address

#

For openvpn, you are looking for the tun0 interface

#

You can also check if THM thinks you are conneced in the THM web page

atomic flax
#

ok :)))

solemn tree
#

I'm having an issue where i'm unable to copy and paste from the left side into the attack box. I have tried using that, and the kali attack box version. ive also tried using external keyboard too. For example, right now im in the John The Ripper room and I cant copy a hash into the terminal. I have made sure to also be pressing ctrl+shift+C. The issue persists across rooms too

tribal mason
#

Rooms? like can you copy paste in your main PC?

solemn tree
#

Yes, I can copy and paste in my main PC.

tribal mason
#

It's perhaps you didn't allow clipboard permissions for tryhackme in your browser then, check for that

solemn tree
#

Just checked, that's not it

#

I ran into this issue last night. Tried terminating the room and bringing back up again and again this morning, same issue.

tribal mason
#

Can you paste things from the clipboard part of attackbox? (If you click the arrow on the left hand side of the attackbox, it should give you box you can use to interact with the AttackBox clipboard)

solemn tree
#

Didn't even know that existed. Yes I can

tribal mason
#

Keep up hacking then mate 🙂

solemn tree
#

So that's the official way to copy and paste? It wont do it straight into terminal from side window with the lesons?

tribal mason
#

It requires clipboard permission but apparently There's something with it in your browser settings

solemn tree
#

I'll figure that part out on my own. It's good to hear that there is something I can use otherwise. Thanks a lot for the help!

tribal mason
#

No problem!

plain bough
#

Hey, Im connecting to THM through openVPN on a Ubuntu VM. It gives me an IP that I can see in the top right corner of the browser when I'm in the room, but all of the URLs (http://MACHINE_IP/) do not get regenerated with my machine IP. Clicking the links gives me a 404 error, manually entering the machine IP I get into the URL throws 404. nmap scan on the IP I get shows all ports are closed.

tribal mason
plain bough
#

yes. It shows my IP is 10.2.19.174

tribal mason
#

Do you know where you should go for in a room?

plain bough
#

sorry I don't understand the question. I'm trying to do Task 4 of contentdiscovery (machine_ip/sitemap.xml)

tribal mason
#

Yeah, have you seen this button before?

plain bough
#

ohhhh.... I thought you only had to do that if using attackbox in browser

tribal mason
#

This machine is used for gaining access to room resources

plain bough
#

gotcha ok.

#

thank you

tribal mason
#

and this is the IP of your connection in the VPN

#

(You will use it to communicate with room machines)

#

For example, reverse shells

plain bough
#

Ok I got it now thank you... always something way simpler than you think.

#

u da man dr heap

tribal mason
#

😁

plain bough
#

sorry one more question... am I still limited to 1 hour per day if im accessing through openvpn?

tribal mason
polar pagoda
#

I'm working on the Holo network, and am up to the point where I have to open a reverse shell to escalate privs. I've done this 10000 times on the tryhackme attack box, but for whatever reason, I can't seem to get a reverse shell working via tun0/openvpn. on my machine. This isn't a new problem; just the first time I got annoyed enough to post.

tun0: flags=4305<UP,POINTOPOINT,RUNNING,NOARP,MULTICAST> mtu 1500
inet 10.50.104.xxx

My eth0 is a local 10.0.whatever, which I set up using instructions from Network Chuck's site for virtualbox.

My setup is a bit nonstandard, so that could be the issue. I'm using virtual box with a kali image. I've got internet connection via wireless adapters (NAT and Bridged), and tun0 shows up within the Holo domain. At times I swap back and forth if I'm attaching machines to VBox, as opposed to using something like try hack me. Everything else seems to work (ping, curl, nmap, etc).

Is there something obvious that I can check to get this working? Also, I'm assuming I can't connect to these networks from the attack boxes?

bold jetty
#

can someone help me out, or nudge me in the direction i need to go...
i installed openvpn. its connected. i can open 10[.]10[.]10[.]10 just fine and i can see the flag and the ip of my connection.

but i can't open the ip address for my active machine for the tasks (currently catching up on the AoC2022 stuff.

tribal mason
bold jetty
tribal mason
#

Can you re-deploy it and wait 5 minutes at least?

bold jetty
#

i've been like, trying to access through openvpn for the past hour. i can access 10101010 just fine and i can see the vpn/thm ip just fine. but when i try to go on the module. i get err_connection_refused

bold jetty
tribal mason
#

so you can't access 8080 port?

bold jetty
#

oh. is that all that i needed to do... it works now if i specify the port

tribal mason
#

Yeah It's specified in the task

bold jetty
#

ohhh. ok. ty. i usually fire up the machine and work through it as i read from top down.

#

thank you so much!

tribal mason
#

No problem mate

#

Hope you can catch it before it ends

bold jetty
#

hope so. i was late to the party working on an intro securities course through school. instructor told us about this just as we were wrapping up a final exam and term project as day 9 was released

golden inlet
#

Hello, how do I become verified on this discord channel? I would love to include my videos to the THM site and #thm-community-media channel. Thanks!

#

Got it, thanks!

tribal burrow
#

!docs verify

sharp bisonBOT
tame whale
#

Any discount codes available? Really want to get the Yeti t-shirt but its a little pricey to Canada. Thanks!

loud marsh
tame whale
#

I dropped off Twitter a while ago. Oh well. Guess I will have to think about this a little more.

red monolith
#

hey can anyone help me with msfconsole

spare laurel
#

I'm missing the tun0 in my system config

#

how can i help with that?

chilly pike
#

@spare laurel look through the pinned messages of this thread, there's a few on vpn issues. Perhaps there is something there that can help you

#

I didnt really read the chat of what you already tried but .. yeah have a look in pinned 🙂

spare laurel
#

it says device tun0 not found

tribal mason
#

Wait, can you send me the output of systemctl status openvpn?

weary spindle
weary spindle
spare laurel
tribal mason
#

can you try re-installing openvpn?

weary spindle
spare laurel
spare laurel
#

[+] Stable internet connection
[+] OpenVPN is installed
[-] tun0 interface does not exist
Would you like the script to attempt a connection automatically (Y/n)? y
[+] Connecting....
[Warning!] Connection process is taking longer than expected to complete

tribal mason
#

sudo apt-get --purge remove openvpn

weary spindle
tribal mason
spare laurel
weary spindle
spare laurel
weary spindle
#

Or if there is any errors.

tribal mason
#

Hey Mr_Code, have you installed the openvpn or it exists by default?

spare laurel
spare laurel
spare laurel
weary spindle
spare laurel
weary spindle
#

Or is your host network being a problem?

spare laurel
weary spindle
tribal mason
#

so you can't connect it right now?

#

can you show the output of sudo openvpn YourVPNFile.ovpn

spare laurel
#

Lmao what the

#

it worked by itself

tribal mason
#

It should work normally...

weary spindle
#

It was restarting...

spare laurel
tribal mason
#

I'm being impatient again, I'll just blame my sleepness

weary spindle
#

So it won't work normally of it's constantly restarting.

tribal mason
#

Sorry*

weary spindle
#

If*

spare laurel
scenic torrentBOT
#

Gave +1 Rep to @tribal mason

surreal oyster
tribal mason
#

You can ping 8.8.8.8 in your main os while you're doing rooms so you can determine if it's your network or tryhackme's VPN

weary spindle
#

But if it cuts off even for a second, the vpn will start restart.

tribal mason
#

For directory bruteforcing?

weary spindle
#

Yes you can.

Should you? Probably not a good idea.

tribal burrow
#

rockyou is more password list than folder/directories

tribal mason
#

You will need to use dirbuster wordlists which is in /usr/share/wordlists/dirbuster

weary spindle
#

You don't need to use them.

#

SecLists is a good alternative.

tribal mason
#

Yeah, or seclists located in /usr/share/seclists

spare laurel
tribal mason
#

It's not in debian by default i think

spare laurel
surreal oyster
#

GitHub

tribal burrow
#

get kali u potato 🙂

spare laurel
#

oh ok

spare laurel
tribal mason
spare laurel
#

i think i thought it was debian but it's kali

tribal burrow
#

get vm version and is faster

scenic torrentBOT
#

Gave +1 Rep to @tribal mason

tribal burrow
#

w8. you running kali not debian

spare laurel
#

xD

bronze vale
spare laurel
tribal burrow
#

we thinked is not kali at first indeed

bronze fox
#

hey! I have a question to Fowsniff CTF (https://tryhackme.com/room/ctf): i did all tasks (100% complete), but it seems that I only get 30+30 points for the two questions where I had to enter something. however - according to the scoreboard, all other users got 450 points (instead of just 60): see also: https://paste.pics/11c490bc030f49c6e4460007a4156496
has the room changed previously or am I doing something wrong?

tribal mason
#

It's giving extra points to first 10 users and the room is 992 days old

peak lake
#

Is there a reason my machines "run out" despite having ample time left (over and hour or just under) and even when I hit extend it still closes?

tribal mason
vital sonnet
#

!docs studen

sharp bisonBOT
#
TryHackMe
That topic does not exist!

Use !docs to list all of the available topics.

vital sonnet
#

!docs student

sharp bisonBOT
cold nebula
#

Anyone know why my new-ish TP link router isn't getting a WAN ip assigned by the modem? I went back to the older asus router and it works fine. I've even set up the static wan ip on the TP link and it still won't connect.

crystal marlin
cold nebula
#

Woops sorry. Read it wrong. Apologies

crystal marlin
#

Not an issue 🙂

strange thunder
#

Anyone else ever experience losing their daily streak despite doing it everyday? I have made sure to do a little everyday but I seem to have lost it today despite doing it yesterday?

weary spindle
#

!email

sharp bisonBOT
scenic torrentBOT
#

Gave +1 Rep to @weary spindle

woeful jetty
#

Hey!
can anyone help me out why it still shows in my rooms, even tho i;ve completed the room ? it still shows as uncompleted ?

#

like a few days back, it was showing normally and suddenly now even the old machines which I completed about a month a ago were coming up on "My rooms" tab and when I click "Hide completed machines", it still shows the completed ones

normal vale
#

what happens if you contrl f5 refresh your "my rooms" page

#

sometimes, it will glitch out and you just untick and retick the box for "Hide completed machines"

woeful jetty
#

I think im a script kiddie enough to refresh the site 😂 , thats my first troubleshooting step in anything

normal vale
#

that's why I suggested it 😛

woeful jetty
#

but it still shows that, it didn't until yesterday, and now I just checked it and BOOM

#

maybe it will fix itself in a day or 2

normal vale
#

just try unchecking "hide completed machines" and retick it as well, just to make sure

woeful jetty
#

done that as well!

normal vale
#

Because I know on search it glitches out there

#

D:

woeful jetty
#

no luck! all the machines which I completed are all showing up

normal vale
#

actually

#

it might just be the whole site for that page

#

I just checked mine as well, and same thing as you

woeful jetty
#

aaaah

#

yeah I think they will fix it soon

#

I just paniked I was like hold up! 😂

loud marsh
nocturne dirge
#

Does anyone can help me know what is the time period considered for counting streak. Like EST, MST, etc. This is 2nd time I lost my streak even after completing events today but it is showing zero events in Yearly activity.

weary spindle
nocturne dirge
upbeat turtle
#

I need to stop automatically subscription renewal

weary spindle
upbeat turtle
#

Yeah but I have a valid subscription I still need it
I want to cancel the automatic renewal without lose this month subscription

weary spindle
#

You won't lose the sub, it will just turn off the auto renew.

royal widget
#

Hi i don't get redeem code

#

Hello anyone here to help

#

?

#

Hello i paid the subs but all i saw is 404 page what happend ?

tribal mason
#

better contact support with e-mail

#

!email

sharp bisonBOT
tacit silo
#

My bagde is being automatically resets to 0 for the past 2 days?
Anyone facing the same issue?

zealous linden
#

@royal widget
Facing the same issue, twice

tribal mason
# sharp bison

I think e-mailing support will be faster way to tell staff

zealous linden
#

Already sent an email to support, autoreply said 1-3 days to get a reply

tribal mason
#

When did you send?

zealous linden
#

About 1 minutes ago

#

10

tribal mason
#

Jabba will reply today ig (Not sure)

zealous linden
#

Ok

royal widget
#

@zealous linden Im facing that 4 time lmao

zealous linden
#

I thought that first time I fell victim for phishing although I know I did everything right, so I bought the vouchers again but same issue 😂

royal widget
#

I hope they fix it fast i still keep proof anyway xD

zealous linden
#

Payment processed on both, so I should get a refund or double vouchers cri

royal widget
#

Yes via email or should get a refund

weary spindle
#

I'd not expect a reply today from Support.

#

The event ending they will be swamped with "Did I win" and "When is the announcement" E-mails.

tribal mason
#

@bronze vale Sorry for pinging but this was kinda important

bronze vale
#

Huh?

weary spindle
sleek grail
#

Not sure this is the right place for this, but I just tried buying a voucher on TryHackMe and the payment went through but I got taken to a "Uh-oh, this page has been lost in the matrix." page and can't see the voucher code. I tried again (didn't realize the payment had worked the first time) and the same thing happened. Can someone help me access the two voucher codes (don't need a refund for the 2nd one, I'll give it away).

plush bay
#

!email

sharp bisonBOT
sleek grail
#

ty

serene mica
#

hello

#

@heavy ginkgo support

bronze vale
novel timber
buoyant pendant
#

Hopefully in the right place. Doing ssh in the attackbox and im getting "Authenticity of host "MACHINE_IP" cant be established then wafflw about permanently adding IP into list of know host. It then comes up with the password section to type into and it wont let me type in there at all, only key that works is Enter and that comes up with password error as it would. I am connected to the openVPN and using the machines inside the rooms. Any help would be great beacuase Im having to skip all SSH missions at the moment.

crystal marlin
buoyant pendant
#

i swear if ive been that dumb lol

#

thanks ill try now

scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

ashen ocean
#

I have the same problem - the wordpress login page is not working... I even tried it with the attack box. Have you found a solution?

tame quest
#

how long does the support email take to get back to you

obtuse cove
#

hello, anyone know how to change username?

weary spindle
#

!email

sharp bisonBOT
glad oyster
naive dust
#

Hi there.
Bought a voucher,transaction went through but error 404 received and no voucher neither in dashboard or email.
Where I can report this?

bronze vale
tribal mason
naive dust
#

Thank you all guys.
All solved very fast.
Kudos skidy

naive dust
#

SOC-LEVEL-1 task 5 of Threat Intelligence Tools cannot access internet over browser. Any solutions?

tribal mason
naive dust
#

i even tried accessing google, it is not taking me to any website, every time same issue

tawdry orbit
tribal mason
#

Oh yup, It's a target machine... mb

naive dust
tribal mason
naive dust
tribal mason
scenic torrentBOT
#

Gave +1 Rep to @tribal mason

nocturne dirge
glad oyster
#

activity != answering questions

#

You need to answer a question for the streak to keep up

nocturne dirge
#

Yes I answered questions every single day

fiery dust
#

On every box I'm loading. Connected via OpenVPN and confirmed through THM site. Just randomly started. Just me?

fiery dust
#

Yep

#

Retried a box that just worked about 15 minutes ago and also the same issue.

#

Working again now

#

Weird, thanks for your help though.

loud marsh
# glad oyster How? Do you have anything to back this claim up? cc <@1052010780171718757> Strea...

Because it kept breaking for me, I'd keep the streak while the yearly with green boxes said I had none that day and lose it when the year tracker did count it. I was doing a q or 2 after local midnight before bed, and then 1 before midnight and 1 after the next night, but I kept losing streak. I asked around this discord and support, and the only answers were that it happened sometimes. Aka "known bug".

final plank
#

Can someone help me resolve tryhackme vpn issue? I'm trying to use vpn inside kali linux VM and it seems to be working fine for around 3 or so minutes and then it is suddenly looses connection. I tried to run https://github.com/tryhackme/openvpn-troubleshooting script to detect any issue but it was not able to find any issue. Moreover, tryhackme vpn seems to be working fine with my host OS.

tribal mason
#

Can you show the output of openvpn?

#

(You need to verify to send media)

#

!docs verify

sharp bisonBOT
robust quarry
#

Hi all. I have successfully installed Openvpn on my mac as described on https://www.tryhackme.com/room/openvpn
Also downloaded and imported configuration file from access pagee and connected successfully to Openvpn server. However, I am still unable to open the webpage on the room's target machine.
I would welcome any suggestions. Thanks in anticipation.

final plank
scenic torrentBOT
#

Gave +1 Rep to @tribal mason

robust quarry
bronze vale
tribal mason
#

is this normal?

bronze vale
#

Connection is being dropped

#

There’s a few reasons but it’s usually the client

final plank
robust quarry
bronze vale
bronze vale
#

brew install openvpn if you haven’t installed it

#

And if you don’t have brew, you’ll either have to download brew or check the OpenVPN website for steps on how to install

final plank
scenic torrentBOT
#

Gave +1 Rep to @bronze vale

robust quarry
robust quarry
scenic torrentBOT
#

Gave +1 Rep to @bronze vale

final plank
scenic torrentBOT
#

Gave +1 Rep to @bronze vale

obsidian sand
#

Hello! Tried to buy a voucher yesterday, money is "blocked" on my card and I'm waiting for the code/voucher. Help pls.

sharp bisonBOT
obsidian sand
#

tkx

tame whale
#

When looking at "My Rooms" is there a way to Hide Completed? I select the option and search but still see rooms I've done.

tawdry orbit
gusty cedar
#

Not an issue, but just something I noticed recently: after starting a room, closing the browser and picking up where I left off the next day, my dashboard bookmark would return that path and room. Recently, it started showing a previous learning path. Again, no big deal, as I can browse back to the room I was working on.

proven fulcrum
#

Please fix this badge or remove it ❤️

fathom warren
#

Hey how do

feral zephyr
#

can someone help? i am stuck in Opencti room. everytime i try to access opencti " unable to connect"

fathom warren
#

How do Iget openvpn to work in WSL?

tribal mason
tribal mason
stoic mortar
#

hi all. Machine "Cyborg" is loosing connection every 2 minutes for about 3-5 minutes. i switched vpn endpoints on my side etc. makes no fun at all this way

glacial hound
tribal mason
bronze vale
tribal mason
scenic torrentBOT
#

Gave +1 Rep to @bronze vale

bronze vale
glad oyster
bronze vale
#

Badge isn't obtainable

glad oyster
#

or I presume just existing users

bronze vale
#

Both

glacial hound
bronze vale
#

Streaming/ Recording TryHackMe content

Hey!

We love when people stream the content on our website! :)

But we do have a couple of rules:

- Please do not use any images in the rooms in your banners or thumbnails
This includes but is not limited to THM logos or exclusive TryHackMe content images (e.g. official TryHackMe artwork, such as the "Blue" room)

- If a room explicitly states not to stream or record it, please respect that.
All content belongs to the room creator (whether that is us or a community member), violating the creator's request may result in a ban from the room and the removal of your content due to copyright. If a room does not say "Do not stream this room" or "You can stream this room after x amount of time" then it's perfectly fine and can be streamed:)

Other than that, I don't really think there's anything else.

Please note: videos will not be accepted as writeups by the room creators if they contain flags, cracked hashes, or passwords.

It is up to you if you want to remove them from your YouTube videos^
If you have any other questions or queries, do not be afraid to ask:)

bronze vale
#

It will be clearly stated in the room, for example in Overpass 3 it says:

hoary swallow
#

team, is it intentional that THM's completion certifications cannot be used for CPE credits (eg: ISC2, ISACA, Comptia, etc). I asking this because, I engaged with the ISACA and realize that the CPE hours should be mentioned in the Completion certificates.

bronze vale
#

If it doesn't say you can't then you can:)

mossy kestrel
#

Hey is there a way to get my name changed on one of my completed certificates? My first path I completed only has my last initial (before I changed my profile) and I would prefer to have them all say the same name lol

plush bay
mossy kestrel
#

Darn, oh well. Thank you for the swift response.

plush bay
#

no problem

jovial carbon
#

Good evening, I am currently having issues with attack box disconnecting randomly.
I have AdGuard as my DNS server however it is not showing any blocked services, filter responses or indications in the logs.
Has any one else had a similar issue where attack-box is randomly disconnecting and is it related to AdGuard?

naive dust
#

i can reset my tryhackme discord token?

plush bay
#

well that would be up to the moderators to do

naive dust
broken bear
#

What's going on with your token?

plush bay
#

^ juun is a moderator

naive dust
tribal mason
#

You can recover it with your email

broken bear
naive dust
#

honestly my passwords were stolen due to stealer they took my discord token and my account is like deleted

#

lol 💀

broken bear
#

Please DM me your THM token

naive dust
#

ok

tribal mason
broken bear
# naive dust ok

Thanks, I'll let you know when we are able to unlink your account.

scenic torrentBOT
#

Gave +1 Rep to @quiet star

naive dust
tribal mason
naive dust
scenic torrentBOT
#

Gave +1 Rep to @tribal mason

jovial carbon
tribal mason
jovial carbon
#

I have no seen the issue on other networks. just changing settings to confirm

#

just bypassed my dns with VPN and still having same issue

#

it disconnects every 10 - 30 seconds

#

got to frustrating I will come back tomorrow. If you have any solutions can you DM me and ill try tomorrow.

fathom warren
# fathom warren How do Iget openvpn to work in WSL?

Hey folks, I posted this at 3am and then finally fell asleep. Is it possible to get OpenVPN to work with a WSL2 Kali setup? I can machines/sites in a browser with openvpn on the host and I've also tried installing it on Kali WSL2. NMAP and metasploit seem to be very hit or miss. I'm also not sure if the VPN is staying open when I ctrl-z out of openVPN on Kali either. Thoughts?

#

Am I just wasting time with WSL2?

plush bay
fathom warren
#

Darn. Seamless mode seems so cool

plush bay
#

windows mixed with linux networking in wsl is a pain

fathom warren
#

I'm getting that vibe

#

A warning on the openvpn guide might be useful to others, I saw that this question has popped up a few times recently although I was having trouble finding the conclusion to the last thread about it

bronze vale
fathom warren
#

Looks like I'll be starting the new year with a fresh OS install lol

#

Feel like I wipe my HD as often as my countertop haha

glad oyster
bronze vale
languid fable
#

Hmm why am I not banned yet

#

Bruh

#

What the fuck

bronze vale
#

Ban speed running?

#

@eager fulcrum Can you right click ban? I’m on my way home can’t restart the bot

#

-ban

scenic torrentBOT
#
Ban <User:Mention/ID> <Duration:Duration> <Reason:Text>
Ban <User:Mention/ID> <Reason:Text> <Duration:Duration>
Ban <User:Mention/ID> <Duration:Duration>
Ban <User:Mention/ID> <Reason:Text>
Ban <User:Mention/ID>

[-ddays ddays:Whole number - Number of days of messages to delete]

Invalid arguments provided: No matching combo found
bronze vale
#

-ban @languid fable Slurs

scenic torrentBOT
#

🔨 Banned 0860#5349 indefinitely

bronze vale
#

Never mind, yag is still enabled

silk galleon
#

Hide Completed filter in https://tryhackme.com/rooms does not work for me .

wind lava
#

My attackbox keeps disconnecting and I am looking for someone to go to for assistance in figuring out what the issue is. Can anyone point me in the right direction?

tribal mason
marsh herald
tribal mason
lament sandal
#

Hi guys, in the Yara room the generated rules are different because a newer version is being used and then the answers don't match...

#

it generates 5 simple rules instead of 1

prime raft
#

Hi
Please can I be contacted directly. #
I just a mail about my payment method expiring .. and I paid for a year. What’s happening?

weary spindle
#

!email

sharp bisonBOT
median roost
#

I need some help

bronze vale
#

Please elaborate :)

raw girder
#

How do i connect to this room Breaching Active Directory
with Attack box

#

Need help

burnt barn
#

Hi, I am using the attackbox for enumeratingAD and the network stopped. I started it again and it claims it is running however I cannot ping thmdc. I restarted the attackbox but I still cannot ping thmdc. The network, after restart, has been running for almost 20 minutes.

#

Email sent

weary spindle
#

cat /etc/resolv.conf

burnt barn
#

a traceroute shows it falls over before getting to the target. The ping fails. What specifically do you want to know from resolve.conf

violet galleon
#

I don't know if this is the right spot for this. How do I change my cc info for my sub?

scenic torrentBOT
#

Gave +1 Rep to @weary spindle

dry ledge
#

Hey I have a problem, I am running Kali Linux with Virtualbox on my machine and am connected to Tryhackme via Openvpn. Both Tryhackme and ifconfig assure me that I am connected and the vpn is working. However, whenever I start a machine and type the ip into the address bar of my browser the page fails to load (I am at the Burp Suite: Repeater room). Strangely, when I ping the ip in a shell I receive a response. Furthermore, I tried the tutorial rooms and that worked. What can I do?

weary spindle
bronze vale
#

It's important that you gather more information before asking them to execute commands

plush bay
#

maybe the vpn troubleshoot script would help too but yeah can be a lot of other stuff that is causing said problems

tribal mason
#

But You are right, It can be messed up if there was a way that scrubz said

#

Sorry.. (The room is about burpsuite so i had to think about it)

dry ledge
#

it is properly configured

tribal mason
# dry ledge yes

Well you need to turn it off in order to view page before it goes to the burp suite

dry ledge
#

it also does not work with the proxy disabled

tribal mason
dry ledge
#

no

#

the tutorial room worked

tribal mason
#

can you access the page http://10.10.10.10/?

dry ledge
#

yes

#

i can see it

tribal mason
#

can you try this command:
sudo ip link set dev tun0 mtu 1200

tribal mason
#

And It's up to intercept settings

dry ledge
#

tysm

tribal mason
#

no problem

#

This command simply turns down the maximum amount of data that can be sent across the VPN tunnel. The default value is 1500 and we are turning it down to 1200.

shell sparrow
#

In My Rooms section of thm, when i check Hide Completed, Nothing happens.

#

I have 400 rooms. How do i find the incomplete ones now 🥲.

twilit yarrow
#

Hello, i can not connection to my openvpn. Anyone can help me?

tribal mason
tribal mason
#

!docs verify

sharp bisonBOT
tribal mason
#

(To send images, you need to verify)

sterile steppe
#

Is there an API endpoint for fetching a user's global rank and points? Something like the bot here does. I see one for fetching a user but it doesn't return points or rank.

bronze vale
peak lake
#

How do I Copy and Paste Into Windows machines, anything I can find on this just points to using the attackbox menu (that is not there as I am not using AB here?)