#site-support

1 messages ยท Page 68 of 1

light laurel
#

try accessing 10.10.10.10

#

check if this is accessable

#

or else try downloading something if still problem then switch vpn

quick kraken
#

how can i use another vpn?

lilac imp
#

not working

quick kraken
#

how can i combine another vpn with vm tryhackme

light laurel
#

https://tryhackme.com/access u can download another vpn from here

#

@quick kraken

#

or why not try with attackbox of thm , as cyborg is a small room u try it with attackbox as well

light laurel
weary spindle
#

Box creator?

north heron
#

there's no such role

#

sorry

#

i didn't know

quick kraken
scenic torrentBOT
#

Gave +1 Rep to @light laurel (current: #2080 - 1)

desert lava
#

I'm trying to update my email to my academic email address, but that block is greyed out ... I presume because I use my google account to authenticate...
Is there a work around?

cinder lotus
#

does anyone know when i try to bruteforce an login page Ethically it gives me a wrong password

desert lava
weary spindle
#

Support

west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

weary spindle
ivory spruce
pure rock
weary spindle
pure rock
#

The same task 4, 2nd question:
Once you find the email sender's IP address, where can you retrieve more information about the IP?

i tried to find on the internet info about any websites, didn't get anything in particular.
when i googled the answer for that it was http://www.arin.net; no idea how it is expected to get that answer.

weary spindle
pure rock
#

Ok, the last link has arin in it.

weary spindle
#

Which server?

#

Is there a other sever close you can try?

#

How are you connecting?

#

Can you add sudo?

scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2277)

desert lava
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2279)

hazy parcel
#

why it doesn't show me the os

weary spindle
hazy parcel
#

yes

#

but i need the os version, i belive its on the os

weary spindle
#

Strange, maybe retry, as it gave me the information.

#

You'd be correct.

hazy parcel
#

i think its a problem

#

or its normal

weary spindle
#

Attackbox or own VM?

hazy parcel
#

attackbox {kali}

weary spindle
hazy parcel
#

im using kali linux

weary spindle
#

Try the Attackbox, as it worked for me

hazy parcel
#

thx

weary spindle
bright ridge
#

i am able to view 10.10.10.10 and see my vpn/THM ip but unable to access machine. can anyone help me?

weary spindle
weary spindle
bright ridge
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2280)

marsh helm
#

Hello. I have lost the access to my 2fa app and I have 2fa enabled in my account. How do I disable 2FA with help of THM support

marsh helm
west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

marsh helm
#

Thanks

hazy parcel
#

anybody help im trying over a hour , im at task4 Exploiting SMB , it does not work what is wrong with my line.

weary spindle
#

It should be obvious.

hazy parcel
#

no

weary spindle
#

//10.10.87.147/profiels

#

Can you see it now?

surreal spire
#

over an hour you say..

hazy parcel
#

tf? what is it

weary spindle
#

You've spelt profiles wrong.

hazy parcel
#

its time to get off

#

thx scrubz

left geyser
#

Hello,
have been trying to submit my write-up since yesterday, still same error. (invalid url)

turbid plover
#

Guys i have a question abt OpenVPN. So I'm connected on Kali Linux VM, I noticed when I type find my IP on browser it's still my IP. So how am I supposed to use this vpn?

errant breach
weary spindle
turbid plover
#

But I can't type any commands in the terminal

weary spindle
#

Does the terminal say connection initlized?

turbid plover
#

Yes

weary spindle
#

Ok, just minimise that window.

turbid plover
#

Ok

#

Done

weary spindle
#

Now which room are you attempting to solve?

errant breach
turbid plover
weary spindle
turbid plover
#

Done

weary spindle
#

And you interact with the IP that appears

turbid plover
#

Like this is what I don't understand

weary spindle
#

If you close it, you close the connection.

turbid plover
#

Ok minimize terminal 1 and open terminal 2 , let's say I have to scan the victim machine

weary spindle
#

Yeah, you can use nmap for that

turbid plover
#

When I scan it from terminal 2 I am connected to the VPN and the victim sees the ip of thm?

weary spindle
#

Then it will allow it to be scanned as they're on the same network.

#

The VPN doesn't change your browsing control, it only allows the machines to talk to the other machines on the network

turbid plover
#

Aight thx, so after I connect to ovpn I always have the ip of ovpn on any terminal I use if I interact with the victim ip

#

Like for reverse shell I would use the ip of the vpn and i would see it on my terminal?

weary spindle
#

That IP is used to catch any reverse shells etc

#

It appears on the top right hand corner for me.

turbid plover
#

Yes I think I got it

#

Thx

quick kraken
white glen
#

Does THM not accept Github links for writeup submissions?

errant breach
#

I missed the "not". They are accepted.

white glen
#

I thought so as well, but I was getting a "this is not a valid URL" message when I was trying to upload one. Had to pivot to a tinyURL

errant breach
#

Unless something changed since they were all submitted and approved.

#

I just submitted mine without problems.

white glen
#

Hmm, must have been something with the URL itself then. Thanks for verifying!

errant breach
white glen
#

Yeah I think since mine had spaces in the name, it didn't like the %20s

light laurel
#

like nmap scans etc

left geyser
white glen
surreal kelp
#

are there known issues with booting windows machines in general? I can't seem to be able to control the windows machine, Guacamole Server Connection seems to be instable

ivory spruce
quick kraken
#

pls someone can help me

errant breach
#

have to be more specific

quick kraken
#

VPN Server working only US-West-Regular-1 but my ping becomes 350

#

Eu-1 not connect
Eu-2 Connected, but not ping 10.10.10.10, not working ip on ctf
Eu-3 not connect. infinite restarts

errant breach
#

I guess only THM staff could help you with that

quick kraken
#

ohhh, i see, i wrote on their mail, but their answer didn't helps me

#

i still waiting their next answer

wild turret
#

hie THM Team i am trying to run vpn on my main host kali linux os and it's not working ? help?

quick kraken
#

xd also such a problem

ivory spruce
ivory spruce
whole creek
#

ok, this is confusing, or i'm really stupid. Some of the rooms in THM, I can visit them without logging in. But if I'm logged in, it redirects me to the subscription page. (Like "Intro to Lan https://tryhackme.com/room/introtolan"). Are these rooms free or paid? I'm a complete beginner, learnt about THM recently.

errant breach
#

"Intro to LAN" is not on it, so you'd need a subscription.

#

And that's despite that room showing up in the search as free and having Free Room. Anyone can deploy virtual machines in the room (without being subscribed)! at the bottom of the page. That's apparently out of date info.

#

So I was told.

whole creek
scenic torrentBOT
#

Gave +1 Rep to @errant breach (current: #392 - 12)

whole creek
#

I saw one of my senior finished this room long ago. and he said he didn't pay for premium. Was this room ever free before ??

errant breach
#

I believe it was, yes.

whole creek
#

ok, that clarifies it. Thank you again.

errant breach
#

And they haven't updated the text since it was paywalled

#

Something I don't quite understand...

whole creek
whole creek
surreal kelp
halcyon shell
#

Hi Support. I can't access any room via openvpn. please help checking the log file. thank you.

sick nexus
halcyon shell
#

yes. i tired mutiple servers and different vpn and rooms e.g. exploitad , breachad , holo

weary spindle
halcyon shell
#

Hong Kong

#

normally i don't see this part on ifconfig :
"unspec 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00 txqueuelen 500 (UNSPEC)"

#

was running holo room and suddenly the connection lost and i tried reconnect then this happen

weary spindle
halcyon shell
#

no idea. it just happen today

weary spindle
#

So yes.

Are you on a home network or other?

halcyon shell
#

home network

weary spindle
#

Which vpn do you normally connect to?

halcyon shell
#

wdym which vpn do i normally connect to?

#

personal vpn?

#

i can't use any openvpn file provided by tryhackme

weary spindle
#

No, openvpn server for TryHackMe.

weary spindle
halcyon shell
#

only holo

#

INDIA server

weary spindle
halcyon shell
#

no

weary spindle
#

Try EU-Vip-1

halcyon shell
#

seems working now. let me check the holo room again

#

is that any holo-vip vpn? or only the normal one?

weary spindle
#

Holo only has one VPN.

#

You can try using the cog button on the to leave for 15 min(s) and re enter with a new subnet, then ensuring your regenerating the configuration before downloading a new one.

halcyon shell
#

seems my room stuck.

where's the cog button? you mean let the room reset itself?

halcyon shell
#

ok then i wait for 15mins to connect back

weary spindle
#

atleast 15.

Should place you on a subnet.

halcyon shell
#

thanks. will get back to you

halcyon shell
#

@weary spindle Same issue.

#

I connect to the holo-openvpn file but seems no connection to the server side

weary spindle
halcyon shell
#

I tried different physical desktop same issue happen

weary spindle
#

Do ip a

halcyon shell
#

I should be able to ping 10.200.108.33 (L-SRV01) and visit its sites but I couldn't process them right now

halcyon shell
#

i give up on using vpn. luckily still can use web kali for this room thank you for the support @weary spindle

scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2284)

brittle vapor
#

Hello I have a question, does anyone know if a bug bounty learning path will be added to TryHackMe ?

brittle vapor
#

But could a learning path be added in the future ?

weary spindle
#

I mean, the majoroty of bug bounty is just owasp top 10, so who knows.

brittle vapor
#

okay no problem thanks

wind wedge
#

There is a web application path coming out

#

Which can be conidered somewhat as bug bounties

autumn lynx
#

Ahh nvm web app pentesting... Same thing tho ๐Ÿ˜‰

weary spindle
#

I can't say what's in the making ๐Ÿ˜„

crisp tinsel
#

how accurate is the streak feature? I ask because I worked on rooms yesterday and i think i was at 12 or 13 days in a row. however, it has reset to 1 today. I think the issue has a lot to do with I'm in the US and days start and end at different times than THM...

wind wedge
#

Could be an incorrect timezone

pine scarab
#

hello some one can help me i can connect to vpn here is the log

autumn lynx
pine scarab
#

i change region for eu but dont work

#

here is the message

#

"""WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-05-21 13:32:00 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-05-21 13:32:00 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-05-21 13:32:00 OpenVPN 2.6.9 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-05-21 13:32:00 library versions: OpenSSL 3.2.2-dev , LZO 2.10
2024-05-21 13:32:00 DCO version: N/A
2024-05-21 13:32:00 OpenSSL: error:0480006C:PEM routines::no start line:Expecting: CERTIFICATE
2024-05-21 13:32:00 OpenSSL: error:0A080009:SSL routines::PEM lib:
2024-05-21 13:32:00 Cannot load inline certificate file
2024-05-21 13:32:00 Exiting due to fatal error
"""

autumn lynx
#

Yea I know... Try using us-west though

#

Had some success helping others with this same problem using us-west ...

pine scarab
#

@autumn lynx is work thank so much

scenic torrentBOT
#

Gave +1 Rep to @autumn lynx (current: #98 - 65)

crisp tinsel
scenic torrentBOT
#

Gave +1 Rep to @wind wedge (current: #54 - 124)

crisp tinsel
trim orbit
#

I hope this is the right place to ask but every time I try and open any room I haven't done yet in the intro to cyber security room, I constantly get prompted to subscribe. I'm assuming its a free room so I'm a bit confused

surreal spire
#

its not free

autumn lynx
surreal spire
#

first few are, but eventually for that path you need to subscribe

trim orbit
#

ohhh okay thanks for letting me know

surreal spire
#

it's worth it. i find the classes here are quite good. ive done stuff with this virtual machines i havent done in years ๐Ÿ˜›

inner timber
#

Hi guys. Can someone help with something pls?
Iam trying to connect to thm with openvpn. I already got my linux vm, i installed openvpn, i downloaded the machine configuration file, but when i try to do the command: "sudo openvpn /path/file-name.ovpn" i get a fatal error, because it couldnt load the inline certificate file
Idk what iam doing wrong. I watched a video on youtube and iam doing exactly what iam supposed to do, i think

trim orbit
#

Im thinking of getting it cause I'm going to be pursuing cyber security professionally anyways.

surreal spire
#

i run sudo openvpn from the folder tht contains the ovpn file

inner timber
surreal spire
#

but i recently added it to a script that specifies full path, still works

hazy parcel
#

can someone help me ?

#

im at task 4 of network services i cant get the info of the file

surreal spire
#

Try regenerating your openvpn configs

#

put filenames with spaces in " "

#

you've opened a file called "Working" in nano with that command

hazy parcel
#

i think its the right one but still

inner timber
scenic torrentBOT
#

Gave +1 Rep to @autumn lynx (current: #96 - 66)

autumn lynx
naive dust
#

I keep getting error messages that I gave the wrong answer, but the answers are correct. Is this a known issue?

crystal marlin
naive dust
#

NVM, I was entering words not numbers.

weary spindle
polar hollow
#

Hello,
I am new on TryHackMe.
I have completed the 'Network Fundamentals' module, all rooms are green.
There's nothing left open, but unfortunately, I haven't received my badge.
I would be very grateful if you could help me.
Thank you.

turbid copper
#

Hey so I lost access to my 2fa app but I still have the backup codes (which is how I was able to login) but now I want to disable it to put it on another auth. I went to settings but to disable it I need a 2fa code and my backup codes are not working. Can anyone help?

sick nexus
#

Does it give you an error?

turbid copper
hasty cloud
#

Task 7 of #exploitingad room. my attempt to use Rubeus tool failed with this error - [X] KRB-ERROR (16) : KDC_ERR_PADATA_TYPE_NOSUPP.

#

seems like a common issue here. anyone has a solution?

surreal kelp
#

I keep having a instable connection with the windows machine im on, linux works fine

rotund steeple
#

Just wanted you to know it is not only you, I'm dealing with same issue in only the burp suite basics room ( https://tryhackme.com/r/room/burpsuitebasics ) ; it's so laggy, i cant even complete it, unable to interact with answer boxes

Thanks for your comment, I was so confused by how bad the lag was I wondered if it was a site-wide issue but can confirm it's only that room

TryHackMe

An introduction to using Burp Suite for web application pentesting.

scenic torrentBOT
#

Gave +1 Rep to @runic heart (current: #1385 - 2)

spice nacelle
#

attackbox is very slow

#

today

#

what i can do

plush bay
surreal spire
amber shell
#

source room not working , ide room also

modest fulcrum
#

hii, im having some problems with thm machines, yesterday i started doing "fowsniff ctf" but the machine website cant be loaded even nmap scan is failed with 0 ports open, now i tried "source" room i still get same thing nmap scan with 0 port open, anyone have experienced with this? anyone knows fix or thm has some problems for now? also openvpn is configured

modest fulcrum
amber shell
#

But who knows?

normal raven
#

Hi when i terminate an attackbox, the machine is reset or not ?

weary spindle
normal raven
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2290)

worn wharf
scenic torrentBOT
#

Gave +1 Rep to @autumn lynx (current: #95 - 67)

jaunty roost
#

Have you noticed that the username and password are sent in clear text. What is the category of this security risk?

ivory spruce
#

Are you connected to THM OpenVPN when trying to access the machine / targets (unless you are using the Attackbox)?

ivory spruce
sharp kraken
#

hello, I'm facing an issue with my streak, on my dashboard, my streak near my profile is 170, and on the questions answered panel, it is 169, is it happening with anyone else.?

sharp kraken
scenic torrentBOT
#

Gave +1 Rep to @errant breach (current: #321 - 15)

runic heart
errant breach
runic heart
#

it has long gifs

#

that s the only noticeable difference

errant breach
#

task 12 for example with the large animated gif

#

no difference here

runic heart
errant breach
#

Or task 14 with several

#

Win 10

runic heart
#

me and probably also the other guy were on Kali

#

if not I am left totally clueless to what might have cause that problem

errant breach
#

It's not as amazingly snappy as on my i7 desktop, but scrolls smoothly and far, far away from being unable to interact with it/complete tasks.

#

mystery

runic heart
#

yeah is a total mystery then

torpid patio
#

Can any1 please help with VPN connection, I have this error:
VERIFY ERROR: depth=1, error=self-signed certificate in certificate chain: CN=ChangeMe

weary spindle
thin heath
#

How do I put the incorrect timezone back? lost a day in the streak in real time ๐Ÿ˜‚

weary spindle
#

If you want to change your time zone, just use a vpn and log in.

#

Or E-mail support and ask them to reset it back.

thin heath
# weary spindle Wdym incorrect? lol

I was lurking the threads and I saw the way to fix the timezones, but since the TZ was originally on UK time and Im on US PT...I lost a whole day on my streak haha

#

its not a big deal really..

weary spindle
thin heath
#

I see

#

email support and wait...or just answer another questions...hmmm decisions pathmm

weary spindle
thin heath
weary spindle
thin heath
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2295)

autumn lynx
tender basin
#

just logged into my THM account showing different numbers in my skills matrix, is there anything I can do to make it go back to before?

tender basin
#

worse ๐Ÿ˜ฆ

#

im not sure of the exact numbers but I know I was in the 90s with linux and now its saying 45

weary spindle
#

They could have re-worked tags.

#

Which leads to this.

Remember, it's still in beta

dawn token
#

I see, thank you :)

weary spindle
#

Also new rooms get added too, which could make the number go down.

dawn token
#

I don't think it could go down that much just by having published 2-3 rooms x)

weary spindle
#

No, but tag changes and new rooms published would hit it quite a bit.

tender basin
#

is there a time line for when its out of beta?

weary spindle
burnt rivet
#

o.m.g.

#

mine shrunk too. it used to look like a rat now it looks a distant NASA image from the outer universe

burnt rivet
#

NASAs image of the day... on THM

tender basin
wind wedge
fiery owl
#

guys I have a problem with my openvpn connection
when I try to connect it keeps connecting forever when I downloaded the troubleshoot sh script it said tun0 wasn't there

#

how do I fix it

#

I'm using pop os

amber shell
#

My machine is linux pro max 14

weary spindle
amber shell
#

vpn

#

Maybe vpn issue?

weary spindle
#

Is the vpn on?

amber shell
#

Yes

weary spindle
#

Can you confirm by doing ip a | grep "tun"

amber shell
#

$ ip a | grep "tun"
4: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
inet 10.9.4.109/16 scope global tun0

weary spindle
#

And which machine are you tryign to access?

amber shell
#

You mean room

#

Source?

weary spindle
#

Yeah...

Is the room called "source" ?

amber shell
#

Yes

#

Bro thx for help @weary spindle

weary spindle
surreal spire
#

Oh I though that was something I did, My Linux skill went from 65 to like 30

#

I'm like it definitely did not.

tawdry orbit
modest fulcrum
#

0 port open on scan result

#

and webserver isnt loading

#

i also connect with openvpn

#

pinging machine will give response

crystal marlin
modest fulcrum
#

i tried these 3

#

and same thing

ivory spruce
drowsy hound
#

having troubles with my terminal in attack box. im on authentication bypass/logic flaw. I have written the curl code in and shows that the page source code is different but when i go to the website it hasn't changed. I don't understand i followed the instructions. if anyone could help me that would be great.

drowsy hound
#

jr penetration tester > introduction to web hacking > authentication bypass

weary spindle
drowsy hound
#

yes. I did have to shut down the terminal at task 3 to go to a doctor appointment. would that have messed with everything for task 4?

drowsy hound
#

okay ill try again from the start

drowsy hound
#

same thing changes in the terminal but not the website.

modest fulcrum
analog jungle
#

hi, is anyone else feeling that the site is very slow? (my internet is fast 300mps> )

ivory spruce
ivory spruce
analog jungle
#

it's strange, when i ping thm the connection seems good

#

it got better now but i was struggling for an hour

modest fulcrum
#

thanks for responding

tawdry orbit
weary spindle
dawn token
scenic torrentBOT
#

Gave +1 Rep to @tawdry orbit (current: #16 - 444)

dawn token
tawdry orbit
#

Awesome. ๐Ÿฅณ

primal silo
#

Launcher is disabled in settings or current page does not match display conditions; this is the error in the console it gives me

#

Failed to load resource: the server responded with a status of 404 ()

unkempt mortar
#

guys can i do openvpn on ubuntu server on my laptop as a beginner?

west chasmBOT
jovial wagon
#

Hey guys. Is this normal:

untold knoll
#

Hello i am just getting started with hacking. Which learning path should i use? my goal is to just have fun and learn pen testing (i want a lot of labs)

azure night
ivory spruce
# jovial wagon

What do you mean? 0xD is the highest level at the moment and you still earn points as you complete rooms.

jovial wagon
#

just wanted to know if that is normal

ivory spruce
ivory spruce
jovial wagon
#

cool. Thanks

vale jasper
#

http://machine_ip/customers/signup can anyone connect to this? its for a task i'm on but I can't connect =/

vale jasper
#

okay, i'll just work on something else in the mean time. Thanks!

timid talon
vale jasper
#

i see, it's saying I already have three open machines. Is there a way to see my open machines?

timid talon
vale jasper
#

okay, thanks

tawny river
#

Event: Download denied
User:
User type: Initiator
Application name: brave.exe
Application path: C:\Program Files\BraveSoftware\Brave-Browser\Application
Component: Safe Browsing
Result description: Blocked
Type: Software that may cause harm
Name: HEUR:HackTool.Script.Inject.heur
Precision: Heuristic Analysis
Threat level: Medium
Object type: File
Object name: tasks?roomCode=windowsapi
Object path: https://tryhackme.com/api/v2/rooms
MD5 of an object: 5CD1E8EA01DF9420602ADB66A802CC2E
Reason: Expert analysis
Databases release date: 23/05/2024 8:12:00 PM

tawny river
#

is it a false positive

#

?

unkempt mortar
#

do i need to make Port forwarding with openvpn server or not?

ivory spruce
unkempt mortar
thin heath
#

Does THM support ever lurk these channels?

bronze vale
thin heath
scenic torrentBOT
#

Gave +1 Rep to @bronze vale (current: #6 - 1245)

ivory spruce
thin heath
ivory spruce
tall flare
#

hello i put Local Cache for an anwser to this question "Where is the very first place your computer would look to find the IP address of a domain?" it suppose to be right but it said Uh-oh! Your answer is incorrect

ivory spruce
weary spindle
errant breach
weary spindle
naive dust
#
  .then(r => r.json())
  .then(vms =>
    vms.forEach(vm =>
      fetch('/api/vm/terminate', {
        method: 'POST',
        body: JSON.stringify({ code: vm.roomId }),
        headers: {
          'csrf-token': csrfToken,
          'Content-Type': 'application/json'
        }
      })
    )
  )```
#

Run this script in browser console

#

@iron idol

#

Yeah was reacting to a queston in General Scrubz xD

weary spindle
iron idol
scenic torrentBOT
#

Gave +1 Rep to @stiff barn (current: #173 - 37)

iron idol
#

although restarting the site works well too

errant breach
weary spindle
errant breach
# weary spindle Not much of an argument, changes are addressed in the server in channels wheneve...

You misunderstood me. I wasn't talking about implementing changes in the first place but about being transparent when changes/corrections are made. The discord server where not even 1% of users are present and even less search the server history for every room they attempt, that's not transparency.

That paid-for rooms like Snort-Challenge1 have been blatantly wrong for >25 months despite paying subscribers reporting them several times over the years with zero feedback, that's an entirely different discussion.

weary spindle
wind wedge
slender latch
#

yo

#

guys

wind wedge
#

Hey

slender latch
#

openvpn 6alal.ovpn
2024-05-25 13:52:36 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-05-25 13:52:36 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-05-25 13:52:36 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-05-25 13:52:36 OpenVPN 2.6.9 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-05-25 13:52:36 library versions: OpenSSL 3.2.2-dev , LZO 2.10
2024-05-25 13:52:36 DCO version: N/A
2024-05-25 13:52:36 OpenSSL: error:04800064:PEM routines::bad base64 decode:
2024-05-25 13:52:36 OpenSSL: error:0A080009:SSL routines::PEM lib:
2024-05-25 13:52:36 Cannot load inline certificate file
2024-05-25 13:52:36 Exiting due to fatal error

#

SOS

#

i cant login

wind wedge
#

Which server you on?

slender latch
#

EU 1

wind wedge
#

Regenerate and switch to EU 2

slender latch
#

bet

#

ok so its from eu 1 ?

#

cuz incase it happens to my frnds

slender latch
scenic torrentBOT
#

Gave +1 Rep to @wind wedge (current: #54 - 125)

thin heath
undone hazel
#

Hello, the password reset part is not working, what should I do?

#

Hello, the password reset part is not working, what should I do?

weary spindle
west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

undone hazel
#

thank you

dusky wing
#

how can i disable the develop mode removing the button in the navbar?

desert gull
#

I have problems connecting via VPN, here are my Logs:

2024-05-26 15:04:47 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-05-26 15:04:47 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-05-26 15:04:47 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-05-26 15:04:47 OpenVPN 2.6.5 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-05-26 15:04:47 library versions: OpenSSL 3.0.10 1 Aug 2023, LZO 2.10
2024-05-26 15:04:47 DCO version: N/A
2024-05-26 15:04:47 OpenSSL: error:0480006C:PEM routines::no start line
2024-05-26 15:04:47 OpenSSL: error:0A080009:SSL routines::PEM lib
2024-05-26 15:04:47 Cannot load inline certificate file
2024-05-26 15:04:47 Exiting due to fatal error

I am using Kubuntu 23.10, OpenVPN 2.6.5 and OpenSSL 3.0.10

#

Fixed it, I had to swich VPN Server a bunch of times

muted marsh
#

Hello, I want to ask if the issuance of a certificate after completing the training is free or is it paid?

wind wedge
muted marsh
#

I have a paid subscription

#

i know i have to complete all the trainings

#

my question is whether this certificate is paid? ๐Ÿ˜€

weary spindle
muted marsh
weary spindle
muted marsh
weary spindle
muted marsh
#

Yes, I know this. But my question is whether the certificate must be paid separately from the paid subscription?

weary spindle
#

Oh!

#

Not at all.

#

The only the thing that is paid outside the subscription is the AWS path.

muted marsh
#

I understand. Thanks ๐Ÿ‘ ๐Ÿ˜€

blazing spire
#

Hello All, I need to report a room bug "httpindetail"

#

the very last task is not working "POST the username of thm and a password of letmein to /login"

#

can someone check it ?

weary spindle
short halo
blazing spire
#

That makes 2 of us . Please check Scrubz . Thank you ๐Ÿ™‚

weary spindle
#

I can't check, I can only let staff know.

blazing spire
short halo
short halo
#

ahh i see, missed it

soft swift
#

This is a general question about THM and AttackBox. Should I install the update? I didn't even think the machine was connected to the outside internet so I wasn't sure.

errant breach
scenic torrentBOT
#

Gave +1 Rep to @errant breach (current: #245 - 21)

calm wren
#

I got the following error when i try to connect to the vpn:Fatal Error: Inline Certificate is invalid

I tried using different vpn servers and regenerating but it did not work. Any suggestion about how to solve it?

nimble trench
#
2024-05-26 19:59:10 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-05-26 19:59:10 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-05-26 19:59:10 OpenVPN 2.6.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-05-26 19:59:10 library versions: OpenSSL 3.1.4 24 Oct 2023, LZO 2.10
2024-05-26 19:59:10 DCO version: N/A
2024-05-26 19:59:10 OpenSSL: error:0480006C:PEM routines::no start line:Expecting: CERTIFICATE
2024-05-26 19:59:10 OpenSSL: error:0A080009:SSL routines::PEM lib:
2024-05-26 19:59:10 Cannot load inline certificate file
2024-05-26 19:59:10 Exiting due to fatal error

Im having problems trying to connect to my openvpn

somber gorge
#

I can't connect to tryhackme's VPN on Kali Linux, as Fatal Error keeps appearing, how can I solve it?

weary spindle
ivory spruce
ivory spruce
somber gorge
#

Do you think it could be because I have the Proxy installed?

somber gorge
#

Do you think I should uninstall the Proxy and try to connect again?

calm wren
edgy wigeon
#

I think the thm website is slowing down my firefox

#

even selecting text is a pain

errant breach
edgy wigeon
#

could it be due to using ublock origin

#

I see it is blocking domains in thousands

#

sometimes it goes up to 10k

somber gorge
weary spindle
somber gorge
topaz nacelle
#

hi guys

#

I enroll in learning path pre-cybersecurity and in task 7 last question i encounter a problem that i can't find the login page, can someone help me with it pls

topaz nacelle
#

it's HTTP in detail

weary spindle
#

Is this the post question?

topaz nacelle
#

yes, even if i do exactly like it asked, it shows me that cannot find the page

weary spindle
topaz nacelle
#

๐Ÿ˜ฎ

#

thank you very much

sullen oriole
#

proxychains Strict chain ... 127.0.0.1:9050 ... 10.200.113.31:445 <--denied
any idea?

weary spindle
soft swift
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2316)

sullen oriole
pure rock
#

Phishing Analysis Tools;
task 7: phising case 1.
Last question "What is the shortened URL? Defang the URL."
After i used cyberchef inside the machine for the task i got 19 urls, but the needed ones are
hxxps[://]t[.]co/yuxfZm8KPg?amp=3D=
or
hxxps[://]t[.]co/yuxfZm8KPg?amp=3D1

the answer is: hxxps[://]t[.]co/yuxfZm8KPg?amp==1

Why i didn't get that answer?

dusky wing
#

Hello!
how can i disable the develop mode removing the button in the navbar?

fallow pulsar
#

The network services rooms are set to private? Is that intentional?

heady pine
#

Hey, I'm trying to connect to the THM VPN using openvpn. I've followed every guide that I could find online and they all say the same thing and it isn't working. I keep getting a TLS error saying that key negotiation failed. I'm using openvpn-2.6.10 from the pacman package manager.

#

This is my log when trying to connect:

2024-05-28 00:36:11 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-05-28 00:36:11 Note: cipher 'AES-256-CBC' in --data-ciphers is not supported by ovpn-dco, disabling data channel offload.
2024-05-28 00:36:11 OpenVPN 2.6.10 [git:makepkg/ba0f62fb950c56a0+] x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO] built on Mar 20 2024
2024-05-28 00:36:11 library versions: OpenSSL 3.2.1 30 Jan 2024, LZO 2.10
2024-05-28 00:36:11 DCO version: N/A
2024-05-28 00:36:11 TCP/UDP: Preserving recently used remote address: [AF_INET]52.4.198.155:1194
2024-05-28 00:36:11 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-05-28 00:36:11 UDPv4 link local: (not bound)
2024-05-28 00:36:11 UDPv4 link remote: [AF_INET]52.4.198.155:1194
2024-05-28 00:37:11 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2024-05-28 00:37:11 TLS Error: TLS handshake failed
2024-05-28 00:37:11 SIGUSR1[soft,tls-error] received, process restarting
2024-05-28 00:37:11 Restart pause, 1 second(s)
2024-05-28 00:37:12 TCP/UDP: Preserving recently used remote address: [AF_INET]52.4.198.155:1194
2024-05-28 00:37:12 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-05-28 00:37:12 UDPv4 link local: (not bound)
2024-05-28 00:37:12 UDPv4 link remote: [AF_INET]52.4.198.155:1194
^C2024-05-28 00:37:20 event_wait : Interrupted system call (fd=-1,code=4)
2024-05-28 00:37:20 SIGTERM received, sending exit notification to peer
2024-05-28 00:37:24 SIGTERM[soft,exit-with-notification] received, process exiting
#

and yes I'm running with sudo

ivory spruce
ivory spruce
weary spindle
main merlin
#

Hey guys, i am a noob doing the wreath room on kali linux running via utm on a mac. After activating openvpn, tryhackme is still disconnected. Anyone could help? I tried all the troubleshooting that i found online. Thanks in advance ๐Ÿ™‚

weary spindle
main merlin
#

Yes

weary spindle
main merlin
#

No i check that

main merlin
weary spindle
#

Which part is saying you're not active.

#

?*

main merlin
#

Top part where it says access

#

If i click on that it shows โ€œdisconnectedโ€

#

And i couldnt continue with one exercise as it wasnโ€™t giving me the complete results

main merlin
#

Oh ok. Can i send you a screenshot later to double check?

#

@main merlin
@.scrubz.

main merlin
main merlin
main merlin
naive dust
#

shit how can we access it then?

main merlin
#

Maybe the attack box would be the only solution. But I would prefer to do it on my VM

snow bobcat
#

Hi, can anyone help me? I have 366 days streak today, but not get 365 days badges? Where I can send request. Thanks

swift tendon
#

Hello everyone! I am new here and i stumbled into a strange issue with the TryHackMe website.
In ALL of the rooms i try to complete that involve any website ON THE MACHINE ATTACKBOX the URLs simply take forever to load.
So out of the 1 hour i got i sit 30 minuetes in wait for a url to load for pentest.
I also tried the use OPENVPN to finish the rooms on my VM but to my anger that option too is blocked.
I need help i am way behind my class because od this and im desperate, please help me

main merlin
ivory spruce
ivory spruce
west chasmBOT
#

@snow bobcat

TryHackMe's Email

TryHackMe's support email address.

swift tendon
#

@weary spindle @ivory spruce
The OPENVPN for me does not work, i even got a script from my lecturer to fix it and yet its still doesnt work.
I have to got to work now but as soon as im back ill upload both how the tryhackme site is slow and what errors i got while trying to connect with openvpn

#

I have already sent out an email for support on THM i hope they'll answer because im really angry at how this site treated me

ivory spruce
main merlin
main merlin
soft estuary
#

Hello all, how could I expedite the response to my queries on THM portal? any email ID other than support@tryhackme.com (regarding card details deletion and / or account deletion) for quick response

soft estuary
#

okay, thanks

weary spindle
#

Don't email multiple times.

Just once and wait patiently

sage summit
#

Hey, I'm trying to connect to the THM VPN using openvpn. I tried to connect first from Windows but it didn't work, even following the most common resolution guides and also regenerating the certificate, but nothing. I then tried to download it on my Kali Linux machine and it didn't work there too. When I try to connect it gives me the error (look at the last lines for the error):

#
Tue May 28 15:07:57 2024 Note: cipher 'AES-256-CBC' in --data-ciphers is not supported by ovpn-dco, disabling data channel offload.
Tue May 28 15:07:57 2024 OpenVPN 2.6.8 [git:v2.6.8/3b0d9489cc423da3] Windows [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] [DCO] built on Nov 17 2023
Tue May 28 15:07:57 2024 Windows version 10.0 (Windows 10 or greater), amd64 executable
Tue May 28 15:07:57 2024 library versions: OpenSSL 3.1.4 24 Oct 2023, LZO 2.10
Tue May 28 15:07:57 2024 DCO version: 1.0.0
Tue May 28 15:07:57 2024 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25343
Tue May 28 15:07:57 2024 Need hold release from management interface, waiting...
Tue May 28 15:07:57 2024 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:58470
Tue May 28 15:07:57 2024 MANAGEMENT: CMD 'state on'
Tue May 28 15:07:57 2024 MANAGEMENT: CMD 'log on all'
Tue May 28 15:07:57 2024 MANAGEMENT: CMD 'echo on all'
Tue May 28 15:07:57 2024 MANAGEMENT: CMD 'bytecount 5'
Tue May 28 15:07:57 2024 MANAGEMENT: CMD 'state'
Tue May 28 15:07:57 2024 MANAGEMENT: CMD 'hold off'
Tue May 28 15:07:57 2024 MANAGEMENT: CMD 'hold release'
Tue May 28 15:07:57 2024 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.168.160:1194
Tue May 28 15:07:57 2024 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue May 28 15:07:57 2024 UDPv4 link local: (not bound)
Tue May 28 15:07:57 2024 UDPv4 link remote: [AF_INET]18.202.168.160:1194
#
Tue May 28 15:07:58 2024 MANAGEMENT: >STATE:1716901678,AUTH,,,,,,
Tue May 28 15:07:58 2024 TLS: Initial packet from [AF_INET]18.202.168.160:1194, sid=3160291b 081412ab
Tue May 28 15:07:58 2024 VERIFY ERROR: depth=1, error=self-signed certificate in certificate chain: CN=ChangeMe, serial=425397202556807641543660048237946304772097879576
Tue May 28 15:07:58 2024 OpenSSL: error:0A000086:SSL routines::certificate verify failed:
Tue May 28 15:07:58 2024 TLS_ERROR: BIO read tls_read_plaintext error
Tue May 28 15:07:58 2024 TLS Error: TLS object -> incoming plaintext read error
Tue May 28 15:07:58 2024 TLS Error: TLS handshake failed```

Can anyone help me, please?
heady pine
#

i have also tried to connect to US-West-Regular-1 and I've redownloaded the configuration file for both servers

swift tendon
#

@ivory spruce i am unable to connect through OPENVPN i get an error on my VM
2 i am using a kali linux VM machine
3 Israel
4 home connection

#

I am running a script by MuirlandOracle that is supposetly resolving my issue, i would upload a screenshot but the server wont allow me

#

But that wont resolve any issue with the computer i still get an error message while i try to connect via openvpm
I have switched servers for all of the eu servers as well as tried to use attackbox but each comes with its own problems

#

Also redownloaded the files for each server seperatly multiple times

main merlin
swift tendon
#

Yeah

swift tendon
#

Ok i solved it, my classmate told me how to@main merlin
Now what you need is first to download the namefile for your openvpn
Then sudo openvpn [your name]
And as long as you didnt get an error youre good.
After that open a terminal and a THM page and press START MACHINE on THM (not start attackbox)
Then wait 2/3 minuetes and ping the IP adress THM gave you.
If theres a ping youre inside THM and can work with it.
Your browser is also in this so you can put IPs from THM to access in your browser
Worked for me GL fixing yours

autumn lynx
main merlin
scenic torrentBOT
#

Gave +1 Rep to @swift tendon (current: #2084 - 1)

autumn lynx
autumn lynx
west chasmBOT
autumn lynx
#

Can also just ping 10.10.10.10 and if you receive any packets then you are connected to THM network

sage summit
scenic torrentBOT
#

Gave +1 Rep to @autumn lynx (current: #92 - 69)

autumn lynx
#

No problem

autumn lynx
heady pine
#

i had already tried connecting to us west. and I redownloaded the config file for each server and did the change from cipher to data-ciphers

autumn lynx
#

Whats the error you get using us-west without editing data-ciphers..? From the output from above I do see errors but I also see sigterm...

#

If all else fails I guess you could always use an older version of OpenVPN before 2.5... probably not the recommended fix but it should work, I did this when OpenVPN updated a while back... @heady pine

heady pine
autumn lynx
#

That's why I asked what errors did you get without editing the config file of us-west ..

heady pine
#

i dont think I tested wothout editing the config for us-west, but every test I did resulted in the same TLS error after 60 seconds

autumn lynx
#

I would try us-west again without editing and see what errors you receive...

heady pine
#

ok. ill try it out when I can

main merlin
autumn lynx
main merlin
autumn lynx
main merlin
#

I get this when trying to open the config file:
sudo] password for kali:
2024-05-28 17:32:04 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.

autumn lynx
sage summit
#

Sorry to ask again, I have started a virtual machine instance in a room but this machine is not connected to the internet in general. Is there any way to get me to send a file from the vm to my pc? PS. I am already connected to VPN and the ping between the two machines works.

errant breach
#

If you wanted to transfer a file to the THM attackbox, you'd use something like python3 -m http.server 8080 on the target and then wget server:8080/file on the THM attackbox

sage summit
errant breach
#

Then SCP might make it happen

#

You could probably also copy&paste some C-code for a simple web server and compiile it on the target. If two machines are connected, it's almost impossible to stop you from exchanging files.
But if you had to go to such great lengths, it's probably not necessary to solve the room

autumn lynx
sage summit
scenic torrentBOT
#

Gave +1 Rep to @errant breach (current: #224 - 24)

errant breach
#

Out of curiosity: Which file do you want to look at?

sage summit
#

Otherwise for a text file I would have copied the text directly block by block at worst, as you suggested

bronze vale
#

We purposely make the files only available on the machines for your safety

errant breach
sage summit
errant breach
snow bobcat
scenic torrentBOT
#

Gave +1 Rep to @west chasm (current: #176 - 36)

heady pine
#

@autumn lynx using US-West-Regular-1 with no modifications worked. Oddly enough, downloading the us-west config already included the data-ciphers tag, and now I can't remember exactly what modifications I made to it last time. I also saw an extra option in the us-west config called comp-lzo which had no effect when adding it to the us-east config

fervent thistle
#

how do i change it to usa?

heady pine
#

wdym

forest matrix
#

@white turtle

white turtle
#

I see๏ผŒreally appriaciate it

white turtle
#

hello guys ,here i met some problems: i wanna learn the lessons with my iPad,and when I logged in THM with the Ggoogle and switched the desktop site,then screen turnt into blank,is there some ways to fix it?

weary spindle
white turtle
#

fine

#

actually i really you one day we can use an app LOL

white turtle
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2325)

muted hinge
#

can someone help me with this error with connecting openvpn?
i cant send the image of it
Error message: Peer certificate verification failure

weary spindle
#

Which server are you using?

Which os and country?

muted hinge
#

I am now using windows - EU-Regular-3 - Czech Republic @weary spindle

#

I tried it on Kali linux and didnt works

muted hinge
weary spindle
#

(Would not suggest hackin from your host.)

muted hinge
#

why

muted hinge
gloomy venture
#

Hi, many task files fail to download in my system as my browser says the file is malicious. Is this expected?

weary spindle
# muted hinge why?

Because you're placing your host computer on the THM vpn, although THM monitors all traffic, we can't (and won't) assure you that somebody won't try and mess with your system.

weary spindle
muted hinge
#

or is the safest

gloomy venture
gloomy venture
weary spindle
weary spindle
muted hinge
#

kali?

weary spindle
muted hinge
gloomy venture
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2326)

weary spindle
muted hinge
weary spindle
muted hinge
weary spindle
#

He does in a different room AFAIK.

weary spindle
grizzled folio
#

Hey guys im currently doing the introductory to network course. Im in the dig section. The question is where is the first place your computer would look to find the ip address of a domain. I type local cache. Then googled the answer to get local cache again but even when i copy and paste its incorrect. Does anyone know the answer?

stoic cargo
#

Open vpn continusly giving me this error < SIGUSR1[soft,network-unreachable] received, process restarting , restart pause [..]sec > when I try to connect my local mechine with tryhack me. I'm using parrot os and Eu-VIP-1 openvpn configaration. Help me out of this.

stoic cargo
#

Tried

#

But cann't connect

weary spindle
#

Which os and country?

#

@muted hinge Please no DM's without permission (Unless it's regaring another user and needs immediate attention)

muted hinge
weary spindle
west chasmBOT
muted hinge
#

okey

stoic cargo
ivory spruce
stoic cargo
ivory spruce
ivory spruce
#

Although the error message you got says network unreachable, which shouldn't be the case.

stoic cargo
stoic cargo
ivory spruce
stoic cargo
#

Can you send the that link?

ivory spruce
ivory spruce
# stoic cargo No

You should join the network first, then click on your profile image, select access, in the screen, there should be a selection for machines and networks, select networks and you should be able to generate your OpenVPN config for it.

stoic cargo
ivory spruce
#

There should be a 'Networks' word right next to it.

harsh coyote
#

hi, how come i got the peer cert error when i connec tthe openvpn

weary spindle
tepid bridge
#

i am having issue with my attack box
in a room of AD enumeration but enumad interface is not showing

weary spindle
tepid bridge
#

ok

static brook
#

any ideas how to fix it

errant breach
#

Which of the >800 THM rooms are you talking about?

broken bear
#

It's just to keep things in places where you are more likely to get help

harsh coyote
hybrid portal
#

Afternoon guys, I most often use my PC on a company owned network which blocks the use of OpenVPN. Does anyone have any advice for other options/circumvent this? I would use the in browser machine but it tends to run quite slowly

weary spindle
hybrid portal
#

Though that might be the case, thanks for the help

short depot
#

How can I view Certificates I have earned on THM?

weary spindle
jaunty roost
#

Which stage of penetration testing involves using publicly available information? R:Information collection

weary spindle
jaunty tapir
#

hi, I'm having hard time connecting to openvpn with my kali machine in windows 11. this is the output after I run sudo openvpn <filename>:

sudo openvpn --config ||nigaroido||.ovpn
2024-05-30 12:44:59 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-05-30 12:44:59 WARNING: Compression for sending and receiving enabled. Compression has been used in the past to break encryption. Allowing compression allows attacks that break encryption. Using "--allow-compression yes" is strongly discouraged for common usage. See --compress in the manual page for more information 
2024-05-30 12:44:59 Note: --data-cipher-fallback with cipher 'BF-CBC' disables data channel offload.
2024-05-30 12:44:59 OpenVPN 2.6.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-05-30 12:44:59 library versions: OpenSSL 3.1.4 24 Oct 2023, LZO 2.10
2024-05-30 12:44:59 DCO version: N/A
2024-05-30 12:44:59 WARNING: INSECURE cipher (BF-CBC) with block size less than 128 bit (64 bit).  This allows attacks like SWEET32.  Mitigate by using a --cipher with a larger block size (e.g. AES-256-CBC). Support for these insecure ciphers will be removed in OpenVPN 2.7.
2024-05-30 12:44:59 TCP/UDP: Preserving recently used remote address: [AF_INET]54.193.240.194:1194
2024-05-30 12:44:59 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-05-30 12:44:59 UDPv4 link local: (not bound)
2024-05-30 12:44:59 UDPv4 link remote: [AF_INET]54.193.240.194:1194
2024-05-30 12:45:59 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2024-05-30 12:45:59 TLS Error: TLS handshake failed
2024-05-30 12:45:59 SIGUSR1[soft,tls-error] received, process restarting
2024-05-30 12:45:59 Restart pause, 1 second(s)
2024-05-30 12:46:00 TCP/UDP: Preserving recently used remote address: [AF_INET]54.193.240.194:1194
2024-05-30 12:46:00 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-05-30 12:46:00 UDPv4 link local: (not bound)
2024-05-30 12:46:00 UDPv4 link remote: [AF_INET]54.193.240.194:1194

this is my configuration file: config.bash

naive dust
weary spindle
autumn lynx
jaunty tapir
#

looked up the configuration file and saw that the <cert>[empty]</cert> cenrtification wasn't even there, so I tried some other locations and finally found the working one. Additionally I killed all the processes for openvpn, ensure you have only one when you do ps aux | grep openvpn

#

also ensure you first change location and then generate each time you download, otherwise the configurations will stay the same

jaunty tapir
bitter berry
#

idk why but it says that medium is an invalid url

bitter berry
errant breach
# bitter berry same

When I submitted a write-up for Blizzard a couple of weeks ago somebody also ran into this problem. Don't know if they resolved it but it's not new. Github worked for me back then.

vernal wigeon
#

Is anyone expieriencing the site being unresponsive? Its barely taking up any memory and its the only page that keeps consistently crashing in my browser --please assume I checked/troubleshooted the obvious.

If you can @ me Id appreciate it

vernal wigeon
#

Could dark reader somehow be crashing the site/pages?

boreal prism
#

I am on the Linux Priv escalation room of pentest+ and the screen keeps freezing, none of my other windows in chrome have issues. I have to constantly exit the page and go back to tryhackme, anyone else have this issue? its never happened with any other room

empty locust
olive veldt
#

Happening to me as well on multiple rooms now. Has made things take a lot longer to complete. The error code :Result_code_hung been doing labs most of the week and havent had this issue. =/

ivory spruce
boreal prism
#

seems like they are having issues if multiple people are having the same issue today

short panther
#

Exiting and re-entering the page has since stopped fixing it for me.

#

@olive veldt experiencing the same thing you are with the code_hung.

vernal wigeon
#

Thanks guys!

vernal wigeon
#

I love THM but for some reason they deal with alot of issues ๐Ÿคฆ๐Ÿปโ€โ™‚๏ธ

naive dust
#

Having same freezing problem with Linux Fundamentals room. Same problem in FF and Edge.

arctic plank
#

Why does my access page show "No connection" for OpenVPN but the VPN connected in the command line successfully ?

ivory spruce
arctic plank
#

Aii bet. I just connected to US West to fix it lol

burnt gale
#

Hmm I thought I had an isolated issue when tryhackme tab started using a entire CPU core and pretty much crashing the tab.
but looks like others are also complaining on reddit.
Still looking for a way to reproduce but It happened twice

#

Also I don't think you had this much telemetry before but the telemetry from customer.io is making a little too many requests

#

and cpu spike to 100% happened again

deft gulch
#

I am trying to download my certificate after completing the Pre-Security Learning path but when I click on download it just shows fetching certificate, please wait message and then disappears. I am not able to download it at all.

polar fossil
#

I don't know, it's just me who has such a problem!
The room - "adventofcyber2023" works very terribly (slows down, freezes, reacts slowly, eats the ram resource)?
I did not notice this in the previous rooms of "Advent of Cyber".
Is this normal or is it being treated somehow?๐Ÿคทโ€โ™‚๏ธ

visual remnant
#

Hi guys, is it only me who experiences bad performance on TryHackMe? I had to reload page for 3 times in 20 minutes, it just freezes and I can't do anything, while the rest of the tabs in my browser and browser itself operate well

visual remnant
burnt beacon
#

holaa, anyone knows how can i open a ticket ?

ivory spruce
burnt beacon
#

thankss

west chasmBOT
#

@burnt beacon

TryHackMe's Email

TryHackMe's support email address.

deft gulch
pliant heart
#

I've had the same issue with the pages freezing in any room I've gone to. I've logged into THM in a VM using Firefox, on my own computer using regular Chrome, and in incognito mode. (All have duckduckgo extension)*

karmic seal
#

hey um my thm site keeps on crashing, I am running it on firefox and after 10 to 15mins it is crashing any idea why it is happening?

weary spindle
karmic seal
#

it is like site is crashing ..

burnt gale
#

basically pegs a CPU to 100% and crashes the tab. Likely rouge JS loop

#

haven't yet figured out what

karmic seal
#

yes kind off.. but rest other websites and applications are running fine

burnt gale
#

yeah all tabs being sandboxed helps there

#

shift+esc and sort by cpu usage you'll see your tab. Just end process and reload and I guess do that again in 10Minutes when it happens

karmic seal
#

its working now ... let me wait for some minutes ..

burnt gale
#

i don'thave the time to test it right now but you should probably also try it with all your extensions disabled just to make sure that it's not any extensions causing it.

deft gulch
visual remnant
#

Same, in 20 minutes I had to reload the page for 3 times, I used Google and I didn't have any extensions

burnt gale
#

from my observation it happens when tab is left idle (switched to different tab) now once you click back on the tab it freezes pegging tab cpu usage at 100% (likely just a vcore)

karmic seal
#

so what should be done to prevent it

burnt gale
#

~~not sure i'm guessing

periodicallyClear() {
                to((()=>{
                    this.clear(),
                    this.loop && this.periodicallyClear()
                }
                ))
            }

this function might the one to blame an i'm seeing way too many calls to it in debugger but would take a bunch of time to actually debug~~

#

Might have found the culprit actually this time. It'll take some time for me to validate it

karmic seal
#

okayy

wind wedge
#

Hi all,

Weโ€™re aware of the issue and waiting for a fix. Iโ€™ll update here once I have an update

burnt gale
#

should be this

    function r(n) {
        return n <= 1 ? n : r(n - 1) + r(n - 2)
    }

which is called here

function l() {
        window.setTimeout(p, 500 * r(u)),
        u += 1
    }
#

anything above 40 as input to r(n) takes quite a while to compute

#

idk why window.setTimeout needed to be handled that way

#

@wind wedge ^

#

it's the tracking.g2crowd.com script so caused by 3rd party

#

lol didn't notice it but its trying to calculate nth fibonacci sequence?! (ooh i see it's trying to do exponential backoff )

#

problem is they're redoing a lot of calculations for the numbers instead of storing previously calculated fib numbers. which leads to way too many recursive calls

burnt gale
# karmic seal froze again

fixed it for myself. But i don't want to announce what to do here. cause it'll likely break some of their telemetry. Should wait for THM to actually make a temp fix until 3rd party vendor fixes it. Till then if you really want to the hints are above and it's a pretty easy step

wind wedge
#

Hi all,

The error should be fixed, please do hard refresh ctrl + F5

Let me know if there are any issues

burnt gale
#

yup script no longer being loaded. should fix the issue

weary spindle
#

You need to verify for a pic.

west chasmBOT
tall lodge
naive dust
#

hello guys, i got a question
when i tried to start a machine in thm with openvpn (im using linux btw) i got this error

2024-05-31 10:31:09 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-05-31 10:31:09 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-05-31 10:31:09 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-05-31 10:31:09 OpenVPN 2.6.9 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-05-31 10:31:09 library versions: OpenSSL 3.2.2-dev , LZO 2.10
2024-05-31 10:31:09 DCO version: N/A
2024-05-31 10:31:09 OpenSSL: error:0480006C:PEM routines::no start line:Expecting: CERTIFICATE
2024-05-31 10:31:09 OpenSSL: error:0A080009:SSL routines::PEM lib:
2024-05-31 10:31:09 Cannot load inline certificate file
2024-05-31 10:31:09 Exiting due to fatal error

pls help me fix it

flint olive
#

Hmm, boxes keep stopping and timing out after 1 hr, even if I extend the timer on them.

runic heart
#

cd into the folder where the vpn is located

#

do sudo openvpn filename.vpn

#

enter your password

#

after it is done close that terminal

#

if u control c it will close the openvpn

#

after you are done using it you can do kill openvpn

#

hope it works

real bronze
#

Can someone tell me how to access free rooms

runic heart
real bronze
runic heart
woven parcel
#

I just need some advice

weary spindle
woven parcel
errant breach
errant breach
naive dust
#

@runic heart thx man imma try it

scenic torrentBOT
#

Gave +1 Rep to @runic heart (current: #632 - 6)

naive dust
runic heart
naive dust
#

Cuz the error occured when I ran openvpn myConfigFile.ovpn

#

I tried running the command inside the app directory but doesn't work either

timid talon
vast fossil
#

10.10.10.10 says i'm connected. the tryhackme site "Access Machines" is red, signifying I don't have access and I can't ping the target box. I've tried switching vpns. anyone else having trouble?

#

boo tryhackme booooo

plush bay
#

it will tell you your ip

#

if you still have problems connecting to machines when you can curl said ip shadow would point you towards the openvpn troubleshooting guide

west chasmBOT
vast fossil
scenic torrentBOT
#

Gave +1 Rep to @west chasm (current: #169 - 38)

plush bay
#

lul the bot got the reputation point

vast fossil
#

yeah, that sucks ;p

green nymph
#

bruh I lost my 19 day streak while doing it everyday

#

is there a way to like contact support for my streak back?

errant breach
green nymph
scenic torrentBOT
#

Gave +1 Rep to @errant breach (current: #155 - 43)

undone flare
#

I have subscribed.
I'm trying to use /room/wreath, but I can't get the network settings.
Is it a known issue?
When I tried to download the VPN settings from the network tab on the "access" page, I got a whiteout while switching tabs.
Even if I start the dedicated Attackbox, wreath.ovpn on the desktop is an empty file.
I am connected to a general room VPN.

ivory spruce
#

I don't think there is a way to generate the certificate using the new design. You could try asking THM Support though.

ivory spruce
naive dust
naive dust
#

Update :
I tried chaging regions, after some attemps it worked but the new problem is that my ip network is different from the room's ip network so i can't practice

weary spindle
naive dust
#

i know
to test i tried the blue room

#

i tried to use nmap on the target machine

#

but it gives me an output like the target's not in my network

naive dust
#

here's my terminal output

Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-06-01 04:50 EDT
Nmap scan report for 10.10.44.110
Host is up.
All 1000 scanned ports on 10.10.44.110 are in ignored states.
Not shown: 1000 filtered tcp ports (no-response)

Nmap done: 1 IP address (1 host up) scanned in 201.33 seconds

wind wedge
#

Unfortunately as off yet, there is no way to generate the new certificate

ivory spruce
naive dust
ivory spruce
#

and the web service is running on a non-standard port

naive dust
naive dust
ivory spruce
ivory spruce
naive dust
naive dust
ivory spruce
#

Ok, let's step back for a bit.

#

First, you wanted to see if your openvpn works, right?

ivory spruce
naive dust
#

i tried that

#

im connected

ivory spruce
#

if it shows you your IP, you are successfully connected

ivory spruce
#

Next, you are working on blue.

ivory spruce
naive dust
#

then i tried to scan the target ports

ivory spruce
#

By default, nmap only scans the top 1000 most popular ports

#

You need to supply another flag to instruct nmap to scan ports 0 to 65535

naive dust
#

hold on imma try

#

i tried this command
sudo nmap -p- 10.10.44.110
i got this output :

Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-06-01 05:42 EDT
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.10 seconds

ivory spruce
naive dust
#

hold on ill try this

naive dust
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #13 - 568)

naive dust
#

thank y'all guys

brittle parcel
#

i wanna change my discord account

weary spindle
weary spindle
nocturne blaze
#

Hi there, Just got premium subscription and got email receipt and went through on my billing method but my account does not yet reflect it

#

Please assist

errant breach
weary spindle
#

Shoot support an emailm

west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

nocturne blaze
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2344)

brittle parcel
#

hello

#

i want to change my discord account

#

give roles to this dude

#

@slender latch

weary spindle
thin heath
#

Checked the help center and didnโ€™t find an answer but does thm keep account of hour many hours are logged? I know it does the 7 days but wondering if there is a total somewhere?

wind wedge
#

Only the 7 days. I can raise it as feedback when iโ€™m back to have a total hours section. I know a lot that would like that

weary spindle
#

How would you count the hours though.

X hours spent on website
X hours of machines deployed

Or both?

wind wedge
#

I would imagine take the average hours out of the rooms/tasks as some room have an estimate time it will take to complete

stable charm
#

i cant use the attacker box for a while
the attack box got to much screen lags its not possible to use it
and no one answer me
i feel like i pay for free i swear

ivory spruce
stable charm
#

i'm from israel

#

but i'm subscriber for the attack box i got kali vm but its more comfortable to use this attackre box

#

i feel like i drop my money for free , and i got fast ethernet

naive dust
#

Guys, I wanted to ask a question about the Takeover exploit

#

Can I or not

ivory spruce
naive dust
#

๐Ÿ‘

grim ruin
#

Figured it out

feral delta
#

hi, in my THM account my ranks aren't increasing eventhough i have more points. so as above ss my points is 26k which is crossed the max point of level 13 which is 20k.
how can i resolve this issue? is it form my side or THM's?

wind wedge
feral delta
scenic torrentBOT
#

Gave +1 Rep to @wind wedge (current: #54 - 128)

keen anchor
#

hey, I am a complete beginner here.
I started with the "pre security" path and as I progressed I noticed that some of the rooms in there are locked behind premium. So, I wanted to ask some queries about that:

  1. Will I still get my certification for completing the free part of the module or will I need to purchase the premium and complete premium rooms as well for it ??
  2. In the future, I am aiming to land an internship/ a role in offensive security. So, is the free content on the site enough to get me the practical knowledge required to get some entry level roles or internships in this field ??
ivory spruce
half rock
#

Hello

#

so i may or may not been using a random name as a 'full name' on the site

#

so when i downloaded my certificate i got that name instead of my actual one

#

and even when i changed it on my account after completing the certification it still didn't change

#

so i got something like this ๐Ÿ˜ญ

#

please help ๐Ÿ˜ญ

languid pier
#

Donโ€™t think you can change it

#

It donโ€™t really matter tho

half rock
#

it looks stupid ๐Ÿ˜ญ

languid pier
#

๐Ÿ˜‚

half rock
#

LMFAO

languid pier
#

Youโ€™re lol now

half rock
#

well

#

i guess i'm lol

ivory spruce
# half rock

What @languid pier said. It will reflect in your succeeding certificates though.

half rock
#

so if i finish another it should appear correctly right ?

acoustic inlet
#

I am connecting to the vpn i downloaded so i can access the rooms through sudo openvpn but no luck. Log: ```2024-06-02 15:19:08 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.129.195:1194
2024-06-02 15:19:08 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-06-02 15:19:08 UDPv4 link local: (not bound)
2024-06-02 15:19:08 UDPv4 link remote: [AF_INET]18.202.129.1:1194

earnest salmon
#

burp suite : the basics room , kinda laggy for me , can't type or even open a task , I'm using firefox , any idea how can i fix this lag ?

acoustic inlet
#
2024-06-02 15:19:07 TLS Error: TLS handshake failed
ivory spruce
ivory spruce
acoustic inlet
half rock
ivory spruce
# acoustic inlet EU Reg 1

Try EU-Reg-2, wait ~2 to 3 minutes upon changing the VPN server before generating your OpenVPN config file.

ivory spruce
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #13 - 570)

earnest salmon
errant breach
runic heart
# half rock

it doesn't really matter and you can't change it unless you write an email to support

#

you can change your name in the profile section

runic heart
#

you can't?

weary spindle
#

Nope.

#

Once they're generated that's it, you'd need to use photoshop

runic heart
#

im they are the only ones that I supposed could generate another one

#

just as scrubz said

tiny plaza
#

hey

#

how can i get courses for free on TryHackMe

ivory spruce
#

There are free rooms that teach you concepts that you can join and complete without being subscribed.

tiny plaza
#

yes i meant rooms

errant breach
tiny plaza
#

im still new

#

Ty