#site-support

1 messages ยท Page 40 of 1

weary spindle
#

Not at all, it will just stop the renewal

scenic torrentBOT
#

Gave +1 Rep to @weary spindle

drowsy elm
ionic zephyr
#

tryhackme has been EXTREMLY slow lately... each box i try would shutdown every 2 minutes and reload for like 1 or 2 minute and does the same thing again, can't do anything.. is this a site problem or something because my wifi is quite fast

weary spindle
ionic zephyr
#

but the same issue has been happening while i've been travelling, and most of the wifi's i've connected too were quite fast so i don't see what could be the issue.

fierce atlas
#

My THM is saying I need to subscribe

#

I subscribed 2 weeks ago

#

Why has it ended early?

weary spindle
#

!email

sharp bisonBOT
#
TryHackMe
Contact us for support, teaching enquires and more!
weary spindle
#

You'll need to contact support via E-mail, replies are about 6-7 days currently.

fierce atlas
#

Ouch okay..

weary spindle
#

(The rare case someone from THM see this and they masy ask you to DM them) [their name is blue]

bronze vale
#

@fierce atlas Did you log into the correct account?

ionic zephyr
#

seems like i'm not the only one but no one found any solutions

#

the box keeps disconnecting and reconnecting every minute, can't do anything, tried different pc, different wifi connection etc.. nothing works

marsh magnet
ionic zephyr
marsh magnet
#

Have you attempted to speak to support?

ionic zephyr
#

Also the first link is only 7 months ago with people replying with the same issue 55 days ago

ionic zephyr
marsh magnet
#

THM doesn't have servers

ionic zephyr
#

Should I speak to support then?

marsh magnet
#

Everything is hosted on Amazon Web Services

#

Same with HTB

ionic zephyr
#

then the issue shouldn't be from THM hmm

marsh magnet
#

Are you running any VPN software?

ionic zephyr
#

only vpn i'm using is the one provided by tryhackme allowing me to connect to the attackbox

marsh magnet
#

Ahhhhhhhhhhh

#

Are you using the attackbox as in the hosted instance on the website?

#

Or do you mean the vulnerable machine?

ionic zephyr
#

Oh sorry, i'm referring to the vulnerable machine

marsh magnet
#

Right

ionic zephyr
#

I call it attack box ๐Ÿ˜… just realized attackbox was the machine provided by THM to attack the vulnerable machine lol

marsh magnet
#

Then the forum posts and everything else you have linked are not relevant to your issue

#

Are you using a VM?

ionic zephyr
marsh magnet
#

Are all your packages up to date?

ionic zephyr
#

Yes, already did that

marsh magnet
#

Have you tried to run the VPN script?

#

Have you tried a different server location?

ionic zephyr
#

the vpn script?

ionic zephyr
sharp bisonBOT
marsh magnet
#

Try that

ionic zephyr
#

I see, i'll give it a try thanks

#

@marsh magnet

[!] Note that a working MTU value might change depending on your network condition
Would you like the script to set the MTU value permanently in your .ovpn file (Y/n)?
``` Yes?
plush bay
#

generally for that??? yes

marsh magnet
#

Yes

ionic zephyr
#

๐Ÿ‘ thanks

plush bay
#

if it messes up again you just rerun the script and it will change it for you again

#

+rep @marsh magnet

scenic torrentBOT
#

Gave +1 Rep to @marsh magnet

ionic zephyr
#

well, i'll try and see if it works

ionic zephyr
#

alright, tried the script, re-loaded my machine, exact same issue keeps happening was working fine the first minute and went ahead and started diconnecting again, so I guess the problem isn't from that vpn

robust bridge
#

hi i have a coupon code for joining with a referral link and when i want to use it it says "invalid coupon code" on the payment popup. So am i doing something wrong ?

rough gyro
#

seem to be having issues connecting suddenly when it was working fine a few mins ago

#

not able to connect to current machine ip or ping or anything

#

the site says im connected fine and ovpn seems fine on my end but the machine ip is just not working rn

#

no typos or anything either as it was just working beforehand

#

also cannot connect to the included site

#

this is the net sec challenge module btw

#

but again it was working up until around when i first posted

#

it was working for a minute and stopped just now

tacit tangle
#

Still need help?

rough gyro
#

looks like its working at the moment, thanks for offering though. im still not sure what the issue was

errant latch
#

anyone know how to solve an issue with openvpn?
this think is not connecting

#

i tried already the steps from the site but nothing

weary spindle
#

What error do you have?

errant latch
#

there is no error. just gets stuck here

weary spindle
#

You need to verify to show screenshots

#

!docs verify

sharp bisonBOT
errant latch
#

2023-08-12 03:33:10 net_addr_v4_add: 10.11.48.168/16 dev tun0
2023-08-12 03:33:10 net_route_v4_add: 10.10.0.0/16 via 10.11.0.1 dev [NULL] table 0 metric 1000
2023-08-12 03:33:10 Initialization Sequence Completed
2023-08-12 03:33:10 Data Channel: cipher 'AES-256-CBC', auth 'SHA512', peer-id: 55, compression: 'lzo'
2023-08-12 03:33:10 Timers: ping 5, ping-restart 120
2023-08-12 03:33:10 Protocol options: explicit-exit-notify 3

weary spindle
#

Oh, that's something that will get fixed.

But you're connected.

errant latch
#

ok

weary spindle
#

5 lines up from the bottom.

errant latch
#

even if after a while gives me a message that is unreachable?

knotty fox
#

Hello Team, While I am starting with the Attacktive Directory room, facing some issues while installing some packages. It is showing Failed to fetch "Source" 404 not found error. Can anyone suggest the Sources that I should add to Sources.list?

#

The sources that I am currently using are: deb https://http.kali.org/kali kali-rolling main contrib non-free
deb https://http.kali.org/kali kali-rolling main non-free contrib
deb https://mirrors.ocf.berkeley.edu/kali/ kali-rolling main non-free contrib
deb-src https://mirrors.ocf.berkeley.edu/kali/ kali-rolling main non-free contrib
deb https://http.kali.org/kali kali-rolling main non-free contrib
deb https://http.kali.org/kali kali-rolling main non-free contrib
deb https://http.kali.org/kali kali-last-snapshot main non-free contrib
deb https://http.kali.org/kali kali-experimental main non-free contrib
deb https://repo.kali.org/kali kali-rolling main non-free contrib

deb-src https://repo.kali.org/kali kali-rolling main non-free contrib
Tried many alternatives but the issue still exists. I would really appreciate your help

chilly kiln
#

hello, where can I get ticket support on discord server?

weary spindle
#

If it's site related, you may need to E-mail support, and await a reply, which I think just now is 6-7 days.

#

!email

sharp bisonBOT
#
TryHackMe
Contact us for support, teaching enquires and more!
chilly kiln
lilac granite
#

Hello! I am new to the site. I have just started going through my first room. I have hit a blocker. I have the machine i am working with open in the browser. The step tells me to now try RDP in as another user. Not sure how i do this as A) I did not RDP in from my own machine. B) When i press the Windows key, there is no option to switch user. If i click logout, it just disconnects the machine. What am i missing?

marsh magnet
robust bridge
#

oh okey thanks

tulip thicket
#

hey how i can share my badges from THM to other sites like linkedin ?

weary spindle
tulip thicket
weary spindle
coral violet
#

So I bought a year long premium subscription back in June, and i recently logged back in after a couple weeks of not using the service and all of my account data is completely wiped. I wrote a detailed email to support about this and got a response from Jabba saying โ€œUnfortunately, it is not currently possible to reset your account progress.โ€ This response ignored all of the concerns I had regarding payment. I emailed back the same day with follow up questions, and it has been two days since with no response. Considering the fact that I paid $100 to use the service I would expect a little bit more than just a generic copy paste response after going 8 days with nothing. Is there any way to restore my account data, and if not what can we do to pursue a refund? Thank you to whoever responds to this, I know itโ€™s long.

plush bay
spare tree
#

I had my streak freeze used a couple weeks ago, after which i stopped receiving messages on my mail as a reminder about learning despite that i still have my streak up. Can i somehow return them? They are really useful for me

sullen oriole
#

Hey, I'm doing Linux Privilege Escalation from my kali linux machine and when I connect via SSH the server response it's really really slow. Any idea?

crystal marlin
lilac idol
toxic cedar
#

I sent a message to support@tryhackme.com approximately 10 days ago, and I have not yet received a response. Is there an estimate for when I can expect a reply?

crystal marlin
toxic cedar
crystal marlin
toxic cedar
#

That's correct

crystal marlin
#

Okay, ye not sure if they are super busy, did you also check your spam folder?

toxic cedar
#

I did, nothing is there

bronze vale
#

Defcon is on atm

#

Weโ€™re attempting to get back to your within a reasonable time frame, thereโ€™s no guarantee on what time we can get back to you at this time ๐Ÿ™‚

toxic cedar
#

Alright, thank you for answer

lunar mulch
#

how do i send photo here

weary spindle
#

You need to verify

#

!docs verify

sharp bisonBOT
weary spindle
#

Follow up the above link.

lunar mulch
#

oke

iron vortex
#

hi, I think my problem in #holo-network is a bug, the PC doesn't start when trying to restart it

lunar mulch
#

i need help why does it gives this error ? no file directory, but I made sure to put everything in the same path

#

im in autentication bypass tutorial

#

i got seclists and i also got the name.txt

#

is this right place to ask for this or there is other support room

stone panther
#

whats the task ur following?

#

and what command are you runnign

lunar mulch
#

username enumeration with ffuf

#

ffuf -w /usr/share/wordlists/SecLists/Usernames/Names/names.txt -X POST -d "username=FUZZ&email=x&password=x&cpassword=x" -H "Content-Type: application/x-www-form-urlencoded" -u http://10.10.128.101/customers/signup -mr "username already exists"

#

i copy paste

stone panther
#

mhh can you share a screenshot of the command youre running

#

from your terminal

#

often time its a simple typo that goes unnoticed

lunar mulch
#

i think i just pasted it

#

as it was

#

im on the home directory

#

~

weary spindle
#

The wordlist isn't there.

stone panther
#

I believe its /usr/share/seclists/Usernames/Names/names.txt @lunar mulch

#

can you run locate /Names/names.txt and see what it points to

lunar mulch
#

i moved them into the wordlist and into the seclist

#

hm i dunno this is not very beginner friendly

stone panther
#

could you try the same command with sudo

#

Im just reaching here

lunar mulch
#

even with sudo "no such file or directory"

#

very strange

weary spindle
#

/usr/.../share

#

Look at the locate command.

#

There is ... between /usr and share

lunar mulch
#

thats cuz it to long but its share

weary spindle
lunar mulch
stone panther
#

could you try ffuf -w /usr/share/seclists/Usernames/Names/names.txt @lunar mulch

#

you didnt remove it from there right? you just copied it over

lunar mulch
#

i copy pasted command as it was

stone panther
#

huh

#

could you run the locate command I posted earlier

#

and screenshot the results

#

locate /Names/names.txt

lunar mulch
#

this is command

#

i try locate now

high stump
#

from the folder where you exec ls

lunar mulch
#

this now tells me /seclists/seclists-master also

stone panther
#

take that path

#

and replace yours

lunar mulch
#

oh

#

do i need to be in the same directory or i can be in every directory when tiping the ffuf ?

#

can i stay in ~

stone panther
#

I think /usr/... is not dependant from where you start

#

but Im unsure, try both

#

its a absolute path* it should work

lunar mulch
#

missing the directory

stone panther
#

"seclists" not "secLists"

lunar mulch
#

uh

#

it gve same 1 error no such directory file

stone panther
#

"SecLists-master"

#

just copy it from the "locate" command

#

ctrl+shift+C

#

and paste it with ctrl+shift+V

#

9 out of 10 times its a typo that goes unnoticed

#

so use copy paste whenever you can ๐Ÿ˜…

lunar mulch
#

its been already some hours i copy paste this seclist my eyes not working anymore

#

i try again now i also need to turn on machine i think cuz it went off

stone panther
lunar mulch
#

its working

stone panther
#

NICE!!

lunar mulch
#

thenks for help

#

you arent even a support or are you

#

but still helped

stone panther
#

no im just bored

lunar mulch
#

haahah

#

๐Ÿ˜ขi was lookin in wrong directory

tiny hatch
#

Hello! I am facing issues with connecting to machines after a successful openvpn connection. I am on a mac (os: sonoma/14) the open vpn client is connecting successfully, but I cannot connect to any machines. I cannot ping any pachine IPs either. I tried connecting through both US-West and US-EAST servers.

#

I must be doing something wrong - but not sure what...

tiny hatch
#

On a mac, the route command is extremely limited - i tried the following :

#
sudo ip link set dev tun0 mtu 1200
#

but macos does not have the ip command

#

also - the hosts are unreachable through ping - so MTU might not be the issue here

mental galleon
#

help

#

pls

lunar mulch
mental galleon
#

emulator is bein dumb

lunar mulch
#

so now it was workin but it took forever to do one line 9000 tries and 9000 errors

#

i left it going for 1 hour and a half

#

i not sure thats how long it should be goin

crystal marlin
crystal marlin
lunar mulch
#

I dont think

crystal marlin
lunar mulch
#

it took 3 second now to do in the right ip

#

left pc on for 1 hour without reason

crystal marlin
stone panther
#

Trying to add 1 hour to a machine never works for me

#

is there a reason why this may be? @crystal marlin

#

does it not let you add time if you were inactive for too long on a machine?

crystal marlin
plush bay
#

and you might need to refresh/reload the page after hitting the add time button for it to show in the target machine ip box

fresh sapphire
#

idk how the conffetti component after a room is finished is implemented but its kidna annoying how it block me from interacting with anything on the site untill the conffeti/component/div dissapears. Is it possible to just change its pointer events or position. Its just a slightly annoying user experience moment ive experienced for the past month.

full warren
#

hey all I have a quick question and I'm pretty sure I'm doing everything right in the module... it's in the linux part 3 section in "pre security"

#

"Locate the process that is running on the deployed instance (10.10.155.131). What flag is given?"

#

I am connected to this ip address using ssh and I've run ps aux but I cannot find this flag anywhere...

#

the reason I'm asking in site support is because I just want to make sure its not a site issue and that I'm definitely doing something wrong

stone panther
#

it should be there, can you double check ๐Ÿ˜… @full warren

#

its on the right side of the screen

full warren
#

I have been looking like a psychopath for the last 20 minutes.

#

lol

stone panther
#

this might be cheating but try ps aux | grep THM

#

it should definetly pop up

full warren
#

ok let me try ๐Ÿ™‚

#

I'll report back

#

i cant share screenshots but its not coming up

stone panther
#

actually ps aux | grep { would make more sense, since you KNOW theres a { in the flag

full warren
#

it just says "THM" in red

stone panther
#

verify your account

#

and share the screenshot

#

its !verify

#

oh you have to DM the bot ๐Ÿ˜…

full warren
#

lmaoo

stone panther
#

this guy here @sharp bison

full warren
#

ahhh thank you

#

I'm back

#

VERIFIED

stone panther
#

NICE!!

#

now run ps aux | grep {

full warren
stone panther
#

and take a screenshot of the results

full warren
#

ok about to run that

stone panther
#

Im assuming youre logged in via SSH IP@tryhackme

#

and your openVPN is running

full warren
#

yea connected to the one requested using ssh

stone panther
#

youre connected through tun0 when you run ifconfig?

#

and you see this in the top right of your VM

full warren
#

it wont let me run ifconfig says I need to download net tools or whatever

stone panther
#

are you on a kali machine?

full warren
#

my actual os?

stone panther
#

I know! but are you connected to that target machine

#

through a Virtual Machine

full warren
#

yes I'm connected to that IP

#

through the vm

#

switched over to that ip, entered the "tryhackme" password. I'm definitely in

stone panther
#

and your definetly connected to your ovpn?

#

Im guessing you wouldnt be able to login if you werent

#

but im unsure

full warren
#

yea I've had zero issues until now

stone panther
#

terminate the machine and open a new one then run ps aux | grep { again

full warren
#

kk

#

just so you see I'm connecting

stone panther
#

thats not a new machine is it?

full warren
#

oh whoops you said for me to terminate the whole thing... sorry. I'll reset everything

stone panther
#

yeah its just 2 clicks

#

terminate -> Start machine

#

wait a minute and do the login again ๐Ÿ˜…

#

could you also run this sudo apt install net-tools

#

on your VM, im guessing its a kali linux machine

#

then you can do ifconfig, screenshot the result of that

full warren
#

we got it baybay

#

thank you

#

not sure what happened but terminating fixed the issue. I see it now. Thank you!

stone panther
#

Nice!!

#

good luck with the rest

full warren
#

thanks!

heavy galleon
#

Hey i'm currently getting this error

stone panther
#

what room, what is the task?

heavy galleon
#

Trying to just complete Web Application Security to fill the path

#

this might be more helpful

stone panther
#

mhh ๐Ÿค” thats not a room I fiddled around with yet

#

I can't access it neither, although I get a different error message

heavy galleon
#

what error are you getting?

stone panther
#

Its not even a machine, its just a static page

heavy galleon
#

even with http it dosent load

stone panther
#

an Admin would know more...someone like @bronze vale maybe ๐Ÿ‘€

#

For now I can recommend you just look at a Walkthrough so you know whats going on @heavy galleon

heavy galleon
#

yeah its not wanting to learn anything

#

more just to fill that completion bar ๐Ÿ’€

stone panther
#

well the video will show you the answer ๐Ÿ˜…

heavy galleon
#

:)

stone panther
#

I usually just look at a writeup

smoky marten
#

Good day people, i'm having issues sshing into a room... i don't know where i'm being dumb or not... but I've tried the password "tryhackme" and it keeps on denying me access...

The VM i am trying to ssh into is "polosmb3" in the "Networking Services" room

#

Sorry if this has been answered before i'm just very new to all of this and am currently stuck.

naive dust
#

Did the static lab's cert expire or something? Danki

chilly pike
#

@cosmic sleet it looks like several people are having similar problems today, please keep an eye on this channel

#

I dont think any staff is online right now but they will be in a few hours

cosmic sleet
#

okay!!
Thank You!!

chilly pike
#

no worries ๐Ÿ™‚

quaint forum
#

oop yea this is what I was gonna ask abt more or less

#

it was just not responding until I connected my vpn to a london server

#

now it says the domain expired or something

#

๐Ÿ˜ญ

valid fractal
#

While opening "View Site" i get error, that "The domain has expired". Tryhackme.cloud

chilly pike
#

yes, please see above ^

valid fractal
#

Ty

chilly pike
#

๐Ÿ™

crystal marlin
distant mantle
#

hello - reporting same issue

#

realize you probably don't need a fifth report but FYI

blissful turret
crystal marlin
#

We are aware of the issue with the static site, please bear with us while we investigate ๐Ÿ™‚

neon jetty
#

Goodmorning,

#

I had an issue with by Google Authenticator app. All of a sudden my links with all my accounts are deleted and i cant get them back. Now i cant log in into my account. Can a support member help me with this? So that i can re-link my google authenticator and log back in to my account?

sharp bisonBOT
#
TryHackMe
Contact us for support, teaching enquires and more!
weary spindle
#

Need to contact support via e_mail for this.0

neon jetty
#

Did that already like a week ago

#

but they didnt reply

weary spindle
#

there is a 6-8 day reply due to how busy they are and Def Con

neon jetty
#

Aaaah

#

damm

#

ok

weary spindle
#

Some cases, it may be slightly longer.

neon jetty
#

then i just have to wait patiently

#

thnx !

full warren
#

task five pentesting fundamentals

weary spindle
full warren
#

ahh

#

bummer

naive dust
#

Task 6 in /room/vulnerabilities101 - Can't view the site

lunar mulch
#

site expired

zealous yoke
#

working on it @naive dust @lunar mulch ๐Ÿ™‚

wanton bone
#

why the website "visit site " are all broke?

weary spindle
neon jetty
#

Guys i managed to log in with a recovery code. Is there a way to re connect my google authenticator once im logged in?

sullen oriole
weary spindle
#

sudo killall openvpn -9

#

Probably not stopped the VPN when rebooting or shutting down

sullen oriole
vague bloom
#

I'm also having issues connecting with the VPN.

#

Downloaded new .OPVN file / Rebooted / and Updated to the latest version in Kali.

weary spindle
#

Screenshots?

They will help.

vague bloom
#

Yup. Just trying another reboot. One moment please ๐Ÿ˜ƒ

stone panther
#

check the comment by Jerome here, this helped me solve it @vague bloom

weary spindle
vague bloom
#

@stone panther Thanks I'll try them now

scenic torrentBOT
#

Gave +1 Rep to @stone panther

gusty belfry
#

im getting issues with the vpn despite having data ciphers present, i even tried --data-ciphers and still to nothing, im using openvpn 2.6.3

vague bloom
#

@gusty belfry I'm using the same version. Haven't tried the steps yet, Got pulled into work. I'll try now and confirm.

gusty belfry
# vague bloom <@956502527560531991> I'm using the same version. Haven't tried the steps yet,...

okay thank you!, sorry for the hassle and just incase to make things easier this is what the openvpn file looks like, this ones a fresh download

dev tun
proto udp
sndbuf 0
rcvbuf 0
remote 18.202.129.195 1194
resolv-retry infinite
nobind
persist-key
persist-tun
remote-cert-tls server
auth SHA512
data-ciphers AES-256-CBC
comp-lzo
pull
key-direction 1
verb 3
reneg-sec 0
data-ciphers AES-256-CBC```
scenic torrentBOT
#

Gave +1 Rep to @vague bloom

vague bloom
#

Looks like that resolved my issue

gusty belfry
#

weird

vague bloom
gusty belfry
#

maybe its because i have data-ciphers? the S?

#

ill try remove it

vague bloom
#

You have a 's' in

#

Yeah. I actually missed that and it looks like it is working

gusty belfry
#

damn lmao

[sudo] password for kali: 
Options error: Unrecognized option or missing or extra parameter(s) in N0rthWinds.ovpn:13: data-cipher (2.6.3)
Use --help for more information.```
#

adding the S back in fixes it

#
2023-08-14 09:29:38 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2023-08-14 09:29:38 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2023-08-14 09:29:38 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2023-08-14 09:29:38 OpenVPN 2.6.3 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2023-08-14 09:29:38 library versions: OpenSSL 3.0.9 30 May 2023, LZO 2.10
2023-08-14 09:29:38 DCO version: N/A
2023-08-14 09:29:38 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.129.195:1194
2023-08-14 09:29:38 Socket Buffers: R=[212992->212992] S=[212992->212992]
2023-08-14 09:29:38 UDPv4 link local: (not bound)
2023-08-14 09:29:38 UDPv4 link remote: [AF_INET]18.202.129.195:1194
2023-08-14 09:29:38 TLS: Initial packet from [AF_INET]18.202.129.195:1194, sid=7869f573 fb01dd2a
2023-08-14 09:29:38 VERIFY OK: depth=1, CN=ChangeMe
2023-08-14 09:29:38 VERIFY KU OK
2023-08-14 09:29:38 Validating certificate extended key usage
2023-08-14 09:29:38 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2023-08-14 09:29:38 VERIFY EKU OK
2023-08-14 09:29:38 VERIFY OK: depth=0, CN=server
2023-08-14 09:29:38 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bit RSA, signature: RSA-SHA256
2023-08-14 09:29:38 [server] Peer Connection Initiated with [AF_INET]18.202.129.195:1194
2023-08-14 09:29:38 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
2023-08-14 09:29:38 TLS: tls_multi_process: initial untrusted session promoted to trusted
2023-08-14 09:29:39 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
2023-08-14 09:29:39 PUSH: Received control message: 'PUSH_REPLY,route 10.10.0.0 255.255.0.0,route-metric 1000,comp-lzo no,route-gateway 10.8.0.1,topology subnet,ping 5,ping-restart 120,ifconfig 10.8.50.7 255.255.0.0,peer-id 8'
2023-08-14 09:29:39 OPTIONS IMPORT: --ifconfig/up options modified
2023-08-14 09:29:39 OPTIONS IMPORT: route options modified
2023-08-14 09:29:39 OPTIONS IMPORT: route-related options modified
2023-08-14 09:29:39 Using peer cipher 'AES-256-CBC'
2023-08-14 09:29:39 net_route_v4_best_gw query: dst 0.0.0.0
2023-08-14 09:29:39 net_route_v4_best_gw result: via 192.168.61.2 dev eth0
2023-08-14 09:29:39 ROUTE_GATEWAY 192.168.61.2/255.255.255.0 IFACE=eth0 HWADDR=00:0c:29:93:7d:1c
2023-08-14 09:29:39 TUN/TAP device tun0 opened
2023-08-14 09:29:39 net_iface_mtu_set: mtu 1500 for tun0
2023-08-14 09:29:39 net_iface_up: set tun0 up
2023-08-14 09:29:39 net_addr_v4_add: 10.8.50.7/16 dev tun0
2023-08-14 09:29:39 net_route_v4_add: 10.10.0.0/16 via 10.8.0.1 dev [NULL] table 0 metric 1000
2023-08-14 09:29:39 Initialization Sequence Completed
2023-08-14 09:29:39 Data Channel: cipher 'AES-256-CBC', auth 'SHA512', peer-id: 8, compression: 'stub'
2023-08-14 09:29:39 Timers: ping 5, ping-restart 120
#

this is the entire response

#

sorry im spilling too much of my spaghett

vague bloom
#

lol makes no sense at this pont but hey, if it works....

gusty belfry
#

i mean, ill try and see if it works on any random machine

#

hopefully it does

#

thanks again i have no clue its super inconsistent with me this vpn, but for now it looks like its working :))

misty nacelle
#

2023-08-14 17:41:40 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2023-08-14 17:41:40 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2023-08-14 17:41:40 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2023-08-14 17:41:40 OpenVPN 2.6.3 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2023-08-14 17:41:40 library versions: OpenSSL 3.0.8 7 Feb 2023, LZO 2.10
2023-08-14 17:41:40 DCO version: N/A
2023-08-14 17:41:40 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.129.195:1194
2023-08-14 17:41:40 Socket Buffers: R=[212992->212992] S=[212992->212992]
2023-08-14 17:41:40 UDPv4 link local: (not bound)
2023-08-14 17:41:40 UDPv4 link remote: [AF_INET]18.202.129.195:1194
2023-08-14 17:41:40 TLS: Initial packet from [AF_INET]18.202.129.195:1194, sid=03504714 a54ec860
2023-08-14 17:42:40 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2023-08-14 17:42:40 TLS Error: TLS handshake failed
2023-08-14 17:42:40 SIGUSR1[soft,tls-error] received, process restarting
2023-08-14 17:42:40 Restart pause, 1 second(s)

#

how can i fix this problem its keeps restarting

weary spindle
#

Which country are you in?

misty nacelle
#

egypt why ?

weary spindle
#

Egypt blocks UDP vpn, you'll need to use the Attackbox

misty nacelle
#

but a couple days ago i was able to connect to the vpn just fine

weary spindle
#

Are you getting THM mixed up with HTB?

Because it's been like that for months, if not year(s)

misty nacelle
#

nope i only tried THM never used HTB

weary spindle
#

I'm not sure why it was working for you then, when it shoudn't have.

misty nacelle
#

ye its kinda weird

weary spindle
#

Still, there is nothing we can do to help, sorry.

#

You're only alternative is use the Attackbox.

misty nacelle
#

alright thanks <3

cloud edge
#

i got the same problem with the vpn

weary spindle
cloud edge
# weary spindle What error are you getting?

2023-08-14 11:37:51 Initialization Sequence Completed 2023-08-14 11:37:51 Data Channel: cipher 'AES-256-CBC', auth 'SHA512', peer-id: 0 2023-08-14 11:37:51 Timers: ping 5, ping-restart 120 2023-08-14 11:37:51 Connection reset, restarting [0] 2023-08-14 11:37:51 SIGUSR1[soft,connection-reset] received, process restarting 2023-08-14 11:37:51 Restart pause, 1 second(s)

weary spindle
cloud edge
#

lateralmovement: only

weary spindle
#

Ah, you're using the lateral VPN.

cloud edge
weary spindle
cloud edge
#

yeah

tawdry yarrow
#

why are rooms, super slow and dropping connections. I am currently working on skynet and had issues with gamezone yday

#

I am using vpn and taking forever to execute command, even ping is dropping packets

weary spindle
tawdry yarrow
tawdry yarrow
#

any other ideas???

#

this is sucking the joy out of these boxes

dense estuary
#

is it ok to not use vpn while attacking a machine in tryhackme room?

weary spindle
dense estuary
#

what is a host vm you mean my own

#

like in my own pc

#

why its needed?

weary spindle
#

You can't talk to the THM machines if you're not on the VPN, it creates a tunnel between you and the machines.

dense estuary
#

ok

#

thanks

honest mauve
#

Hey guys, I am having a really weird issue on a M1 MacBook Pro using UTM Emulator with Kali. When I start the THM tunnel my internet gets really slow even on the host.

#

Has anyone experienced that on a similar setup?

weary spindle
#

The VPN doesn't effect your browsing speed or anything.

honest mauve
#

You say that, but it starts and stops with the tunnel connection.

weary spindle
#

There is no reason for it to.

#

How are you connecting?

zealous yoke
naive dust
#

In /room/metasploitintro, does the ms17_010_eternalblue exploit still work to hack the VM? I tried it multiple times and I believe that my settings are correct

naive dust
weary spindle
#

dont need to change it.

naive dust
#

I guess it just doesnt work anymore

naive dust
#

Works on the AttackBox! (no idea why it doesnt work on my kali)

honest mauve
honest mauve
#

Iโ€˜ve begun thinking about just working on MacOS directly - I just wonder how deep in a hole I am gonna get before realizing I should stick to using a Linux VM.

zealous yoke
naive dust
# naive dust

@zealous yoke Any ideas why this works on the AttackBox, but not on my Kali?

zealous yoke
# honest mauve Yup

Strange. I'm not sure why you'd be having such notable issues while the tunnel is on. If you were to run the VPN on MacOS, do you have a similar experience?

honest mauve
honest mauve
dense estuary
#

how i conect to tryhackme openvpn from kali linux

ivory spruce
weary spindle
#

!vpn

sharp bisonBOT
weary spindle
wanton bone
#

.

dense estuary
#

thanks

neon jetty
#

Is there a way that i can reconnect my google authenticator with my account? I use the recovery codes now.

#

For some reason my connection with google authenticator was removed

crystal marlin
neon jetty
#

Can remove it also using the recovery code?

#

Didn't think of that

#

it worked

#

thanks!

safe yacht
#

I am consistently not able to catch reverse shells with either VPN or AttackBox. Is there some general gotcha that I missed at some point? I can ping the attack box, but it will not catch any shells

weary spindle
#

"ping the attackbox"

Are you targetting the Attackbox, or the target machines (green button machine starts) ?

safe yacht
weary spindle
#

Ah, the telnet.

safe yacht
#

That's the one

weary spindle
#

What command are you using to export the lhost?

safe yacht
#

I'm not exporting the LHOST, but just found it manually in the top right of the attack box interface

weary spindle
#

You need to do

export lhost=**tun0**

#

Then run TCPDUMP in that terminal

#

Then ping from telnet session

safe yacht
#

The pinging works fine without me exporting anyhing. I just entered the IP manually. But this issue it pretty consistent across many rooms for me

naive dust
#

Metasploit on Attackbox is outdated and won't run without running "msfupdate"

crystal marlin
#

!docs verify

sharp bisonBOT
naive dust
#

I tried Setting up a different VM as well, regenerated the VPN file and still i do have same issue

Please someone look into this its been a week since this issue.

naive dust
#

NVM fixed it, i was using my phone as an access point for some time and it was blocking vpn connection.

dense estuary
#

is thet cool if i did nmap scam not on purpos with kali with out the openvpn

weary spindle
#

On a THM IP?

native socket
#

Is anyone from the tryhackme technical@support team available?

zealous yoke
fiery gazelle
#

Is free users vpn servers working..

#

Iam not able to connect to vpn

scenic torrentBOT
#

Gave +1 Rep to @zealous yoke

fiery gazelle
#

Tried different location still issue persist

#

Asked friends also

#

Everyone getting same issue

wind wedge
bronze vale
#

!docs verify

sharp bisonBOT
bronze vale
#

Oh my b, didn't see you there blackout

fiery gazelle
#

@sharp bison

bronze vale
#

Yup, what isn't working?

fiery gazelle
#

Unable ping any machine

bronze vale
#

Open your terminal and type curl 10.10.10.10/whoami, what's the response?

fiery gazelle
#

404 page not found

#

??any solution

dense estuary
#

i think

fiery gazelle
#

After running curl 10.10.10.10/whoami

#

I got response as 404 page not found

#

So wts the issue

weary spindle
#

Are you on the vpn?

fiery gazelle
#

Yup

weary spindle
#

Can you do ip a s

#

And count the tun?

fiery gazelle
#

4

bronze vale
#

Oh yikes

fiery gazelle
#

tun0,1,2,3

bronze vale
#

!multivpn

sharp bisonBOT
#
TryHackMe
Learn how to look for duplicate instance of your OpenVPN connection.
โ€ข Step 1

Make sure you have setup your VPN connection correctly https://tryhackme.com/room/openvpn

โ€ข Step 2

Type ps aux | grep openvpn into your terminal and press enter

โ€ข Step 3

If there's more than one line (that don't start with "grep" or sudo), do the following steps

โ€ข Step 4

Type sudo killall openvpn into your terminal and press enter

โ€ข Step 5

Start the VPN with sudo openvpn <path-to-config>

fiery gazelle
bronze vale
# sharp bison

Make sure not to background or close the OpenVPN terminal.

fiery gazelle
#

Ok

#

What should I do now

#

Should I kill all those ps

bronze vale
#

Yes, follow the instructions above ๐Ÿ™‚

fiery gazelle
#

Ok thanks

rare acorn
#

Hi all, I am new to the site and I am attempting to go through the SOC 1 course but every answer I input tells me it is incorrect. Is there a specific format I need to use when inputting my answers? Seems like nothing is being accepted.

bronze vale
honest mauve
bronze vale
#

I'm not Ben but I use it because it's one of the few Virtualisation Programs that:

  • Supports ARM
  • Is fast
  • Doesn't require me to take out a loan to pay for it
gusty belfry
#

Im trying to do a cutesey little CTF called anthem booted up my vpn and surprisngly i cant ping or do anything nothing seems to reach it, which is strange since when i played KOTH this morning it was fine? everything shows im connected and yet i cant seem to reach it at all

honest mauve
#

Thanks!

jagged ledge
#

Is anyone having trouble with the attack box being extremely laggy? Like almost not functional? The last two days it has been unusable practically. Thanks

fiery gazelle
#

i treid all different ways but iam not able ping the host

#

interface tun0

#

can anyone please help how to fix this issue

weary spindle
#

Which room?

jovial echo
#

you can use your own machine and connect to thm with openvpn for better performance

valid nebula
#

Hello, it's normal to be able to use tryhackme's chat only once, that didn't answer my question and it's impossible for me to write a new message or contact support
thank you for your comeback

valid nebula
weary spindle
#

When*

valid nebula
#

this morning

weary spindle
#

Ah,

You might get a reply on the chat, certainly get one in the form of an E-mail, there is a 6-8 day reply time at the moment.

valid nebula
#

no you don't understand . i use the chat to try to find a answer no find it , but .. i have the message the conversation has ended and i can't put a message on it

weary spindle
#

Why did the message say?#

#

What*

#

my typing today

valid nebula
#

the last message say : Looks like you checked out an article. Did you find the answer you needed? . i can't answer or follow the conversation

unkempt harbor
#

There is an issue with machines in the Exploiting AD . None of them responds.

bronze vale
scenic torrentBOT
#

Gave +1 Rep to @bronze vale

bronze vale
scenic torrentBOT
#

Gave +1 Rep to @bronze vale

jovial echo
#

Michael Jordan also completed their SOC level 69 learning path

#

professional

#

what are the fraudster work arounds

#

because all I needed was ms paint

#

no

#

Yeah I used segoe ui

#

thanks ๐Ÿคฃ

#

you don't hear a lot about thm certificates being used in job applications a whole lot so it shouldn't matter too much

#

some people ask but everyone just says to keep it as certifications like sec+ or degrees

#

certificates are cool for hanging on your wall though

sage linden
#

hi, the overpass 2- hacked room pop a antivirus alert flag as a trojan, it's normal?

weary spindle
eager fulcrum
sage linden
#

ok,thanks

dull otter
#

Hello, how does this streak freeze work? I wonder because I once had 100+ days streak and I missed a day..... and back to zero ๐Ÿ˜„

plush bay
dull otter
scenic torrentBOT
#

Gave +1 Rep to @plush bay

unkempt harbor
#

Is there support on this site? I've been trying to work on the EXploting AD lab for 2 days with no luck!!!

#

No machine is responding!

plush bay
unkempt harbor
plush bay
#

hmmm

distant citrus
#

i have a general query regarding the website emails and links.

As often stated by Daniel Lowrie "don't click on links in email" i see every email i get encouraging me to click on a button link to check out a new room or whatever.

Is this practice of obscuring the long url link done out of habit/ default settings? Am i the strange one here and avoids links as suggested to stay safe?

Curious why there is a disconnect of theory vs practice. I would assume this audience of security people would not mind a long url link in their email but i am likely wrong on this.

robust bridge
mortal lava
#

Can anyone please help with access into a premium "tryhackme" account or can anyone help pay for mine?๐Ÿ™๐Ÿ™.

distant citrus
chrome zodiac
#

I am having issues with my premium account, THM has taken my monthly payment but has not given me access to premium features. This has happened a few times. I have been waiting for 9 days now for a response...

crystal marlin
unkempt harbor
#

It's dissapointing that someone have to wait so long even for a machine reset!

weary spindle
#

Holo network?

unkempt harbor
#

there is an issue with exploiting AD lab, there is no connection either using VPN or attack box. It nneds a reset and noone is responding from support.

crystal marlin
unkempt harbor
#

it nees votes!

crystal marlin
#

You can vote for a reset once per hour, it might take a bit, but you can do it on your own

unkempt harbor
#

i've trying it for 2 days with no luck

weary spindle
#

You can vote yourself every 30 min(s) or hourly.

unkempt harbor
#

I tried it too. the same message appears ...

weary spindle
#

Can you verify and share the message?

#

!docs verify

sharp bisonBOT
unkempt harbor
#

"you have already voted in the last hour" .... Thought over 3 hours has passed

weary spindle
#

Which subnet are you in?

unkempt harbor
#

10.50.95.0

crystal marlin
unkempt harbor
#

10.200.98.0

wanton bone
#

not able to access the site

bronze vale
wanton bone
#

sorry? actually m just satrted out wuith thm, could you please elaborate where m wrong?

wintry rampart
#

guessing the website is down

bronze escarp
#

Hi guys, on Nmap Live Host Discovery room has a bug I suppose,TASK 4 Question 1
"Send a packet with the following:

From computer1
To computer3
Packet Type: โ€œPing Requestโ€
What is the type of packet that computer1 sent before the ping?"
The Answer should be ARP Packet however it says it's wrong

#

any others option cam out w the same message

stone panther
#

thats what the "https://" stands for, try maybe a nmap scan first?

#

or just typing the IP into the url could work aswell

wanton bone
#

i got it

#

thanks mate

fresh eagle
#

I donโ€™t learn a few weeks I learn again I found this issue I reset progress itโ€™s still black how to fix

ivory spruce
robust bridge
weary spindle
#

6-8 days is the response time right now due to how busy they with E-mails and Def Con.

robust bridge
#

so when they answer the coupon is already expired ? XD

broken bear
#

if the coupon is valid, it is honored from what I have seen and heard here.... where did you get the coupon?

robust bridge
broken bear
elder dune
#

I know that THM announced darkmode earlier this year, is it out by now?

plush bay
#

nope but dark reader extension still works wonderfully

elder dune
#

merci

chrome zodiac
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

wide bridge
#

can i do the quests from tryhackme on my linux? is that have anyone problem ? on my vm or just the vm from website

fierce zealot
#

https://tryhackme.com/room/layer2 in the room in "Man-in-the-Middle: Sniffing" the host is never up. Can see the other host in this network training to arp it none stop also.

#

Found someone else having this issue in the forums

naive dust
weary spindle
fierce zealot
naive dust
#

@pastel tinsel

2023-08-18 02:55:49 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2023-08-18 02:55:49 Note: cipher 'AES-256-CBC' in --data-ciphers is not supported by ovpn-dco, disabling data channel offload.
2023-08-18 02:55:49 OpenVPN 2.6.3 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2023-08-18 02:55:49 library versions: OpenSSL 3.0.9 30 May 2023, LZO 2.10
2023-08-18 02:55:49 DCO version: N/A
2023-08-18 02:55:49 OpenSSL: error:0480006C:PEM routines::no start line
2023-08-18 02:55:49 OpenSSL: error:0A080009:SSL routines::PEM lib
2023-08-18 02:55:49 Cannot load inline certificate file
2023-08-18 02:55:49 Exiting due to fatal error

as I mentioned before this only happens with Wreath currently I am solving Breaching AD and it's working fine. Also I've been solving Wreath for a week and it was working fine until I regenerated my VPN config

fair tapir
naive dust
pastel tinsel
#

Config*

naive dust
# pastel tinsel When did you generate this ckngig?

Yesterday morning for some reasons I couldn't ping the network so I went and generated a new VPN config, since then I coudn't connect due to that error. I also tried to generate few more last one few minutes ago... it's still the same error

weary spindle
#

Fatal error, are you running sudo?

naive dust
#

I am running as root no need for sudo

fair tapir
#

try sudo regardless of root permissions

weary spindle
#

Which server are you using?

naive dust
weary spindle
fair tapir
#

I'm going to leave this to Scrubz so I don't cause confusion trying to do multiple things at once

naive dust
#

U can't select servers for networks afaik but for machines I am using regular EU 3

weary spindle
#

Oh, you're doing a network?

naive dust
#

Wreath yeah

weary spindle
#

I just joined, downloaded and it worked, can you open the file and show the contents?

You're on your home network?

naive dust
#

those are the headers, I am on my home network on a VM running bridged mode

#

also as I said before I can connect to other networks I just can't connect to Wreath

#

I also tried to downgrade the openvpn version doesn't seem to work either

stone panther
#

there is a pinned Comment by Jerome in here

#

it should help u get the ovpn file set up properly

#

what openvpn version r u on?

#

โ€˜openvpn โ€”versionโ€™ is the command i think

naive dust
#

my host is running 2.5.5 my kali vm running the latest version

weary spindle
fair tapir
#

Scrubz what version number of openssl shows when you run the wreath ovpn file?

weary spindle
#

3.0.9

naive dust
fair tapir
#

huh mine is an outdated library

weary spindle
naive dust
#

I just left and rejoined and downloaded a new config it is still the same error

fair tapir
#

I found something that might possibly work

naive dust
#

yes please

fair tapir
#

nevermind I tried to implement it and it was unrecognized

#

I'm still searching

naive dust
#

alr thanks for taking time anyways

fair tapir
#

okay

#

I fixed the wording so try this

naive dust
#

it is just frustrating I have only one machine left to pwn on the network

fair tapir
#

edit the configuration file and add this line

#

tls-cipher "DEFAULT:@SECLEVEL=0"

#

it's a temporary workaround of openvpn errors, so if it works it isn't necissarily digging at the root of the problem

#

and if it doesn't work that's another story

pastel tinsel
#

please don't

#

it'll lower your security level

fair tapir
#

yes that is true

naive dust
#

too late lol, but it is not working for what it is worth

fair tapir
#

okay then remove it

pastel tinsel
#

@zealous yoke looks like certificates are going bad on network 81 in wreath?

#

for the vpn

fair tapir
#

sorry for not being able to help

pastel tinsel
#

it's good troubleshooting

naive dust
#

dw I appreciate it

fair tapir
#

I learned a bit more along the way aswell so I think it was worth my time

pastel tinsel
#

ben will be in chat when he has time, he got more knowledge about the vpn servers

naive dust
#

alright thanks

pastel tinsel
#

can you send a picture of your network on wreath?

#

so we can get what IP's you have

#

helps ben knowing what server he has to get access to if there's something needed to be fixed on it

fair tapir
#

did ben stop the network? Or has it been in that state the whole time?

naive dust
#

nah I didn't start it since the vpn issue started yesterday

#

wait could that be the problem ?

fair tapir
#

possibly

pastel tinsel
#

you should still be able to connect to the vpn even if the network is stopped, but give it a try

naive dust
#

no still not working

fair tapir
#

mainly the first two (the second one being more specific to your problem as far as I can see)

naive dust
#

I swear I went over every tryhackme troubleshooting tip even the ones in the forum pepehands

fair tapir
#

that's okay I'm just throwing things out there. I'm sure it will get fixed as soon as possible if it's server sided

pastel tinsel
#

random question, did you generate the file in windows and put it in linux or just linux?

naive dust
#

No I was in my kali vm the whole time, and btw my host os is linux too

fair tapir
#

have you tried running it on the host os?

#

I know it's also bridged

naive dust
#

yeah not working either

#

but not the same error iirc since my host is running 2.5.5 openvpn

pastel tinsel
#

it is a formatting/certificate error, so nothing of those will help sadly

fair tapir
#

okay I'll remember that

naive dust
#

woudn't that affect every player on the network? Scrubz tried to connect few minutes ago and it worked

weary spindle
#

Maybe just the people in their subnet.

naive dust
#

alr I see

pastel tinsel
#

it'll maybe just be only the .81.xxx network

fair tapir
#

is it possible to switch subnets?

weary spindle
#

Yes, leaving the room for 5-10 min(s)

fair tapir
#

if it ends up just being the .81.xxx subnet, wouldn't leaving for a period of time and joining back allow @naive dust to complete the room?

naive dust
#

yep I just done that I'll be rejoining after 15-30 min

weary spindle
#

It might erase all the work they've done.

fair tapir
#

hmm

#

that might not be a viable solution if it does

#

considering you said you were almost done you might not want to do that

naive dust
#

that's alright I mean what good does it do me if I can't finish the room

fair tapir
#

if you want to go ahead and try then by all means

#

although they might be working on it so you still have the option to wait but it's your choice

naive dust
#

I already left the room kekw

#

it's ok I was planning to redo it again anyways

#

the worst thing is if my work is gone and I still can't access the network lol

fair tapir
#

lol that would really be dookie

#

if it works then it ends up just being learning reinforcement

#

good luck rebel ๐Ÿ™

naive dust
#

thanks for the help u'all I appreciate it

fair tapir
#

I tried my best lol

zealous yoke
naive dust
left schooner
#

sudo openvpn cybertechnician.ovpn
2023-08-18 06:39:31 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2023-08-18 06:39:31 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2023-08-18 06:39:31 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2023-08-18 06:39:31 OpenVPN 2.6.3 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2023-08-18 06:39:31 library versions: OpenSSL 1.1.1n 15 Mar 2022, LZO 2.10
2023-08-18 06:39:31 DCO version: N/A
2023-08-18 06:39:31 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.129.195:1194
2023-08-18 06:39:31 Socket Buffers: R=[212992->212992] S=[212992->212992]
2023-08-18 06:39:31 UDPv4 link local: (not bound)
2023-08-18 06:39:31 UDPv4 link remote: [AF_INET]18.202.129.195:1194
2023-08-18 06:39:31 read UDPv4 [ECONNREFUSED]: Connection refused (fd=3,code=111)
2023-08-18 06:39:33 read UDPv4 [ECONNREFUSED]: Connection refused (fd=3,code=111)
2023-08-18 06:39:37 read UDPv4 [ECONNREFUSED]: Connection refused (fd=3,code=111)
2023-08-18 06:39:45 read UDPv4 [ECONNREFUSED]: Connection refused (fd=3,code=111)
2023-08-18 06:40:01 read UDPv4 [ECONNREFUSED]: Connection refused (fd=3,code=111)
2023-08-18 06:40:31 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2023-08-18 06:40:31 TLS Error: TLS handshake failed

weary spindle
left schooner
#

Azerbaijan

#

it worked like a charm yesterday

#

now i changed connection to bridged on vm

jovial echo
#

change it back to the NAT for the time being if you need to access thm via openvpn

left schooner
#

should it be work only with NAT ?

jovial echo
#

I mean if it worked with NAT previously then it works, it should probably work with both but I don't know what the error is I only briefly looked over it

weary spindle
#

I'd have kept it on NAT anyway.

jovial echo
#

yep

split kraken
#

Hello everyone, I have an issue with connecting to THM network via VPN. Error : Client exception in transport_recv: crypto_alg: BF-CBC: bad cipher for data channel use . It seems like the server is suggesting BF-CBC but my machine (macos) doesn't really want to use it. Does anyone know how to force OpenVPN client to use the suggested cipher without complaining about it?

#

P.S. my virtual kali connects to the same profile with no issues

weary spindle
#

What OS gives you the error?

split kraken
#

Macos (host machine)

oak pulsar
#

I got charged twice for a yearly membership, I sent out an email last Saturday and I've still heard nothing back :/

fair tapir
weary spindle
oak pulsar
#

Appreciate it

sullen heron
#

Hello everyone
The situation is the same with others.

Here is my output
Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC' to --data-ciphers.

Note:Kernel support for ovpn-dco missing, disabling data channel offload.

The output after the command
'sudo openvpn -version'

OpenVPN 2.6.3 x86_64-pc-linux-gnu

I am using Kali Linux 6.3.7-1kali1(2023-06-29)

Please, help me.
I searched Google, chatgpt and YouTube, all were useless

sullen heron
#

Uzbekistan

weary spindle
#

I think Uzbekistan blocks VPN's

#

Uzbekistan blocks OpenVPN.

#

It won't work.

sullen heron
#

But I used it roughly a year ago
Ohh no

weary spindle
#

I'm not sure where you got that information from.

#

No, it's ok.

Google is giving mixed messages.

sullen heron
#

Ok,
Then what can I do now
Should I use another VPN and OpenVPN?
Any other suggestions, please

sullen heron
weary spindle
vast plinth
#

Hi everyone, can someone help me get past the last part of the defensive security section? It is part of the Intro to cybersecurity module. I am being asked to block the malicious IP addresses, but everytime I input the addresses it keeps saying it is an invalid entry.

stone panther
#

screenshots @vast plinth

dense mason
#

Hello. I am unable to access any target machines. tried several rooms.

#

Also tried to redownload the OpenVPN configuration file and that did not help.

#

Everthing worked fine yesterday.

#

I do have a tun0 IP and it does match the IP at the top right corner of the site. But cannot ping target IPs of any room

dense mason
#

@stone panther Figured it out. there is an issue on the THM side with the west-VIP VPN server.

#

I connected to west-regular vpn server and it works fine

stone panther
#

nice!!

split kraken
stone panther
#

@split kraken can you look at what NoHat tried and maybe that will fix it?

split kraken
#

nope, still doesn't work. I get the same error

stone panther
#

what Openvpn version are you on?

split kraken
#

3.4.3 (4617) - latest

stone panther
#

what room are you trying to connect you

split kraken
#

okay I think I figured it out. Under settings -> Advanced settings -> Security Level, pick "Insecure (Not Recommended)" option to allow client machine use legacy ciphers such as BF-CBC

clever chasm
#

does anybody know if this issue is resovled?. I am facing the same thing. Cannot find the files email2.txt and email3.eml both.

weary spindle
fair tapir
#

lemme just delete that rq and paste a new one

clever chasm
weary spindle
clever chasm
weary spindle
#

You can see if you're in the right machine or not with the grey box.

fair tapir
#

it should open split screen view:

bronze vale
weary spindle
fair tapir
#

@clever chasm if it doesn't open splitscreen there should be a "show splitscreen" blue button near the top next to the attackbox button

clever chasm
fair tapir
#

you're not stupid sometimes things are just hard to see when they're right in front of us

clever chasm
scenic torrentBOT
#

Gave +1 Rep to @fair tapir

fair tapir
#

I swear when I look at my screen it's like I'm farsighted lol

clever chasm
#

thanks @weary spindle !!!

weary spindle
#

No worries, glad you got there. ๐Ÿ™‚

Enjoy the room.

weary spindle
#

Which server?

#

Try Eu reg 1

#

Which country are you in?

#

How are you running the config?

#

The vpn file.

#

Are you doing sudo openvpn file.ovpn ?

#

Yeah, use sudo ๐Ÿ™‚

scenic torrentBOT
#

Gave +1 Rep to @weary spindle

split kraken
bronze vale
#

It does

#

!vpn

sharp bisonBOT
bronze vale
split kraken
#

Thanks!

astral mango
#

I saw that other people had this problem but I am not able to solve it, can someone help me here?

fair tapir
bronze comet
#

On OpenVPN client V3.4.1 (3150) (Windows) i get the following Error on Connection:
โŽ[Aug 20, 2023, 07:35:12] Connected via TUN_WIN โŽ[Aug 20, 2023, 07:35:12] Per-Key Data Limit: 48000000/48000000 โŽ[Aug 20, 2023, 07:35:12] Client exception in transport_recv: crypto_alg: BF-CBC: bad cipher for data channel use โŽ[Aug 20, 2023, 07:35:12] Client terminated, restarting in 2000 ms... โŽ[Aug 20, 2023, 07:35:12] SetupClient: signaling tun destroy event

naive dust
#

Says there bad cipher being used. Try the thm-troubleshooter script found here:

#

!vpnscript

sharp bisonBOT
bronze comet
#

Doens't work on WIndows, forgot to mention it

naive dust
#

Ahhh you're on windows

#

And you are trying to download the open VPN connect to windows ?

bronze comet
#

yes

naive dust
#

Let me guess...the toggle option just sits and loads for you correct ?

bronze comet
#

yes

naive dust
#

That's what it was doing to me earlier

#

so what i did is downloaded this one instead

#

Download the version 2.7.1

#

and then it worked

#

was able to connect just fine after that

bronze comet
#

ok seems to connect. but i don't get access to the machine

naive dust
#

Check if you have access here :

#

click on your profile icon and then click on 'Access'

bronze comet
#

yes it shows connected

naive dust
#

then you are connected

#

might have to refresh

#

or restart machine

#

Also try using a different browser

bronze comet
#

Still cant ping the machine. Restarted it, restarted my pc, used firefox and chrome

#

even stopped firewall

naive dust
#

don't forget to turn it back on

bronze comet
#

its back on

weary spindle
#

It's not a good idea to use your host on the vpn.

Your tun0 can be scanned.

#

Although THM is for teaching cyber security and ethical topics, I would operate a zero trust policy on other users who aren't staff.

bronze comet
#

ok seems to work on a kali vm

#

so using kali vm should be safer?

weary spindle
#

Yes, vm is much safer.

And it's better to do on Kali than Windows.

astral mango
noble hare
#

can someone help with connecting to the open vpn?

#

it says failed to connect

crystal marlin
#

!docs verify

sharp bisonBOT
noble hare
#

@crystal marlin how do I send screenshots?

#

it doesn't work

crystal marlin
#

Check the link above

noble hare
#

I'll let you know

#

@crystal marlin could you tell me where the bot is?

crystal marlin
#

@sharp bison

noble hare
#

@crystal marlin see

crystal marlin
noble hare
#

windows

crystal marlin
# noble hare windows

Hard to troubleshoot from that output, if you would try to connect from some kind of linux OS, they output would be much more extensive

noble hare
#

i have kali linux in vm

#

should i?

crystal marlin
noble hare
#

can you tell me the commands i need?

crystal marlin
#

But basically just sudo openvpn your_ovpn_config

noble hare
#

i get this --The command could not be located because '/usr/bin:/bin' is not included in the PATH environment variable.

#

and this --- Command 'sudo' is available in the following places

  • /bin/sudo
  • /usr/bin/sudo
#

@crystal marlin ?

crystal marlin
noble hare
#

@crystal marlin yeah but screenshots don't work there

crystal marlin
noble hare
#

how do i download the configuration file in kali linux?

#

only then will it work

#

@crystal marlin ?

crystal marlin
noble hare
#

@crystal marlin it's the same thing

#

as the previous link

crystal marlin
bronze vale
noble hare
#

what should I do?

noble hare
#

never mind

#

@crystal marlin thanks I got it

scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

noble hare
#

what is that?

winter solstice
fresh eagle
#

How to fix network diagrams did not show I reset twice the Active Directory path itโ€™s not work

spice tangle
#

Hey! I'm using Kali and trying to use OpenVPN. I've followed the steps and in the .ovpn file "data-ciphers...." text is written, but i still get a error message.

spice tangle
#

It seems i can't send a screenshot either here in the chat, to show the full error message in the terminal, but it says something about "cipher negotiations failed...."

#

"....if i need this fallback please add --data-ciphers-fallback BF-CBC"

finite aurora
#

what version of openvpn are you using

spice tangle
#

2.6.3

finite aurora
#

and to send screenshot here , you need to be verified

spice tangle
#

Ok, how can i be verified?

broken bear
#

!docs verify

sharp bisonBOT
broken bear
#

tldr; DM the TryHackMe bot with your THM profile token

spice tangle
#

Thanks! I'll be back in a sec

#

This is the message i get

#

do you want me to send scr of my ovpn file?

broken bear
#

no

#

you can fix the warning by running sed -i "s/cipher/data-ciphers AES-256-CBC/g" <path/to/ovpn>

#

but that may not fix your problem, it may be a problem with the inline certificate in the profile

#

iof that's the case, regenerate it on the web interface, wait 2 minutes and download the new profile

plush bay
#

....

#

think that is not what the problem is here juun

spice tangle
#

Okey ill try those, thanks!

#

..

finite aurora
broken bear
#

error about the inline certificate is pretty indicative.... and i said 'fix the warning' not the problem

plush bay
#

also shadow has been scolded multiple times for providing the above command

spice tangle
#

I've tried the steps in the above guide from the forum

#

none worked

broken bear
#

I would also recommend finding the THM VPN troubleshoot script from the pinned messages and running that

plush bay
#

!vpnscript

sharp bisonBOT
spice tangle
#

Okey

plush bay
#

yes shadow has memorised these commands

#

think in this instance a regeneration of the vpn file might also help

#

assuming it is not an isp level vpn block

spice tangle
#

hmm maybe ISP block

#

my ISP i swedish Telia

plush bay
#

ooh doubt they block vpns

#

sweden is known to basically be free for all on the vpn markets

broken bear
#

The problem with the certificate is most likely to be the cause, I think.

Did you regenerate the ovpn file, wait a few minutes, and then re-download the new profile?

weary spindle
#

Which server are they using?

#

I've seen some people have issues with Eu Reg 3 recently.

plush bay
#

huh yeah that could be a potential problem causer

spice tangle
#

Ah

#

Yes eu reg 3 is the one!

#

I will try another!

#

I will be back with results, thanks!

weary spindle
#

Try Eu Reg 1.

visual snow
#

Since my country strictly uses cash only iโ€™m not really familiar with how subscriptions work %100 and with tryhackmeโ€™s subs being my first ever online purchase i was wondering what happens if i cancelled it will it still give me the one month i paid for? Or if i forgot to cancel and my card doesnโ€™t have enough money will it still charge me and make it a debt or something?

weary spindle
#

If you ever forget to cancel you don't have enough funds to make the purchase, It will try again in 3 days, if it fails again, it will automatically cancel.

weary spindle
visual snow
scenic torrentBOT
#

Gave +1 Rep to @weary spindle

lone kernel
#

how long until a ticket gets resolved on average?

broken locust
#

Hello

#

I need support with charging

stiff yarrow
#

Hi, what is the best way to update your payment method? I can't seem to find a way to do that. Thanks.

fair tapir
weary spindle
crystal marlin