#site-support

1 messages ยท Page 72 of 1

scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2502)

robust saddle
#

lateral movement network works now

#

judging from your profile picture, if your that number 1 dude in the koth rankings, it's probably because you're winning too much. you've gotta give the other players some room to breathe

ivory spruce
#

Check your THM profile if you have it as a beginner or intermediate. Only intermediate and up are able to play KoTH.

vast urchin
#

every how much time does the tryhackme bot update roles?

ivory spruce
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #11 - 609)

weary spindle
cunning iron
#

Hello, I have a question regarding premium membership, let's say I have a personal account with premium membership (purchased annually), and then my employer purchases a business account and adds my personal account to their license, what happens to my existing premium membership?

wheat stone
#

Hello, maybe you know if i can change my name from a certificate? i already change from account manage but the certificate still appears with my old name, thank u ๐Ÿ™‚

weary spindle
weary spindle
graceful copper
#

any reason why some public rooms have been made private?

#

an example being subl3ster room

weary spindle
#

Old rooms being replaced, updated or removed

cunning iron
# weary spindle You'll still be premium regardless,

So will it use the remainder of the premium membership I paid for and then apply theirs or will it "pause" mine. Like let's say I have 3 months left when they add me to their license what happens to that 3 months

weary spindle
west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

woeful hedge
#

I would also, this is more life advice, keep work and personal accounts separated

west chasmBOT
woeful snow
#

Hello

woeful hedge
#

You can post screenshots by verifying with the link above your message.

crude kindle
#

Hello, for some reason when I used nmap localhost on the Kali Machine I could see the vnc port open but when I used nmap 10.10.XXX.XXX(Kali Machine IP) I could only see the ssh and http port open. (I am trying to access my kali machine with a vnc app)

woeful hedge
crude kindle
#

I verified acc

#

What now?

#

@weary spindle Look

weary spindle
crude kindle
#

Wait lemme post a SS

weary spindle
#

I don't think you can vnc in to that machine, I told you thus earlier

crude kindle
#

I could with attackbox tho

#

Is it really not possible with this one?

#

Is there like some sort of firewall or setting activated that blocks outside connection or something?

weary spindle
#

@zealous yoke correct me if I'm wrong, but you can't VNC in to thr Kali web box, only the Attackbox?

cerulean glacier
#

Unable to negotiate with 10.10.178.123 port 2222: no matching host key type found. Their offer: ssh-rsa

what am I doing wrong ??

#

I am guessing its some kind of key exchange cipher that my ssh client doesnt support

#

how do I use it ??

#

๐Ÿฅบ ๐Ÿฅบ ๐Ÿฅบ ๐Ÿฅบ

weary spindle
#

Do you have the id-rsa?

cerulean glacier
#

I have a password

fair dragon
#

Tryhackme Snort Challenge - The Basics
Task 2 What is the destination address of packet 63?

help

weary spindle
cerulean glacier
#

OverPass2

crude kindle
#

@weary spindle Guess what I just did

#

BOOM!

#

At Long Last

cerulean glacier
#

Install Kali Linux ๐Ÿค” ?

alpine aurora
#

hi new can some1 help me setup the openvpn connection ? for some reason it doesnt work for me

cerulean glacier
alpine aurora
#

i did

cerulean glacier
#

and download openvpn?

alpine aurora
#

yes

#

it doesnt connect

cerulean glacier
#

And use it only inside the virtualbox

alpine aurora
#

Only inside a virtual machine??

cerulean glacier
#

yes like you should download openvpn inside the kali/ubuntu vritual machine that you're using for hacking ... and use it from there

alpine aurora
#

Oh i just did it on my main windows machine

cerulean glacier
alpine aurora
#

Thank you sir

cerulean glacier
#

You're welcome

#

Also I kinda forgot that I came here asking for help myself

alpine aurora
#

i really wanna learn some hacking stuff, i have good background in IT and Networking

cerulean glacier
alpine aurora
#

Il start with the free stuff then il consider purchasing a subscription

cerulean glacier
#

I am learning it as well, even tho I have no background in IT or networking... so you probably have a bit of edge there

alpine aurora
#

Vmware pro station 17 is free nowdays

#

il use that ๐Ÿ™‚

cerulean glacier
#

Cool... I've always been a VirtualBox guy

alpine aurora
#

Vbox is also great

#

I like it

cerulean glacier
#

Does VMware have some advantage in something ?

alpine aurora
#

For Personal home labs i dont think so

cerulean glacier
#

ok

alpine aurora
#

As long everything works you are good to go

#

i had issues in vbox trying to copy stuff from host to guest

#

i enabled the related settings but still had issues thats why i moved.. but im sure it was solvable somehow

robust saddle
proper meteor
#

hello there . im facing a problem with connecting openvpn with the THM servers

ivory spruce
fossil current
#

could anything help me with metasploti on mac

#

everytime i do smth like run or exploit

#

it fails

#

and says exploit completed but no session created

hollow forge
fossil current
#

no vpn

#

i turned off the firewall too

hollow forge
#

@fossil current I don't know too much about mac, so sorry couldn't help

fossil current
#

nah its alr

weary spindle
#

Are you doing tryhackme?

fossil current
#

yeah

weary spindle
#

You said there is no vpn, are you connected to the THM one?

fossil current
#

wait nah nvm thought you meant doing the course

#

i mean in general

#

i dont use vpn

#

when i use my laptop terminal

weary spindle
#

Which room are you doing?

fossil current
#

๐Ÿ˜ญ ๐Ÿ™ huh

#

wait wym

weary spindle
#

Which Tryhackme room are you doing?

fossil current
#

not doing tryhackme

#

doing it on my laptop

weary spindle
#

Oh, can you please use #general and explain more on what you're doing please.

slim shadow
faint moat
#

hello,
I'm getting exasperated trying to understand why i can't connect with OpenVPN on windows.
This is the log:

Sat Jul 13 17:07:37 2024 OpenVPN 2.6.11 [git:v2.6.11/ddf6bf6d2a135835] Windows [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] [DCO] built on Jun 26 2024
Sat Jul 13 17:07:37 2024 Windows version 10.0 (Windows 10 or greater), amd64 executable
Sat Jul 13 17:07:37 2024 library versions: OpenSSL 3.3.1 4 Jun 2024, LZO 2.10
Sat Jul 13 17:07:37 2024 DCO version: 1.2.1
Sat Jul 13 17:07:37 2024 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25341
Sat Jul 13 17:07:37 2024 Need hold release from management interface, waiting...
Sat Jul 13 17:07:38 2024 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:55976
Sat Jul 13 17:07:38 2024 MANAGEMENT: CMD 'state on'
Sat Jul 13 17:07:38 2024 MANAGEMENT: CMD 'log on all'
Sat Jul 13 17:07:38 2024 MANAGEMENT: CMD 'echo on all'
Sat Jul 13 17:07:38 2024 MANAGEMENT: CMD 'bytecount 5'
Sat Jul 13 17:07:38 2024 MANAGEMENT: CMD 'state'
Sat Jul 13 17:07:38 2024 MANAGEMENT: CMD 'hold off'
Sat Jul 13 17:07:38 2024 MANAGEMENT: CMD 'hold release'
Sat Jul 13 17:07:38 2024 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.168.160:1194
Sat Jul 13 17:07:38 2024 ovpn-dco device [OpenVPN Data Channel Offload] opened
Sat Jul 13 17:07:38 2024 UDP link local: (not bound)
Sat Jul 13 17:07:38 2024 UDP link remote: [AF_INET]18.202.168.160:1194
Sat Jul 13 17:07:38 2024 MANAGEMENT: >STATE:1720883258,WAIT,,,,,,
Sat Jul 13 17:08:38 2024 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Sat Jul 13 17:08:38 2024 TLS Error: TLS handshake failed

Any help?

austere osprey
#

Its wraps broski

weary spindle
faint moat
weary spindle
faint moat
#

tried europe 1,2,3,4, same issue on all

weary spindle
#

Where do you live?

faint moat
#

italy

weary spindle
#

Ah, you're windows.

#

Are you using OpenVpn connect or communities?

faint moat
#

yes

#

i mean community

weary spindle
#

Communities should work, however, I would not put your host on the vpn, I'd suggest you use a VM.

faint moat
rich crystal
weary spindle
faint moat
rich crystal
#

Enable OpenVPN on your firewall app settings

#

@faint moat

weary spindle
#

If you need to edit your firewall rules, is it worth it? ๐Ÿค”

faint moat
faint moat
faint moat
robust saddle
acoustic barn
#

unanle to connect to thm network but able to ping other sites using my vm

#

any idea what is wrong/

#

?

robust saddle
weary spindle
robust saddle
weary spindle
cold fog
rare hawk
faint moat
#

@rich crystal @weary spindle i've installed kali on a VM.
i still can't connect NotLikeThis

#
2024-07-13 13:03:40 DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305). OpenVPN ignores --cipher for cipher negotiations. 
2024-07-13 13:03:40 Note: Kernel support for ovpn-dco missing, disabling data channel offload.
2024-07-13 13:03:40 OpenVPN 2.6.9 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-07-13 13:03:40 library versions: OpenSSL 3.2.2 4 Jun 2024, LZO 2.10
2024-07-13 13:03:40 DCO version: N/A
2024-07-13 13:03:40 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.168.160:1194
2024-07-13 13:03:40 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-07-13 13:03:40 UDPv4 link local: (not bound)
2024-07-13 13:03:40 UDPv4 link remote: [AF_INET]18.202.168.160:1194
2024-07-13 13:04:40 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2024-07-13 13:04:40 TLS Error: TLS handshake failed
robust saddle
scenic torrentBOT
#

Gave +1 Rep to @cold fog (current: #29 - 282)

limber valley
#

Man, been trying for a week to finish the Exploiting Active Directory room. Anybody else keep having to start all over every hour or so? Was about to execute the command on task 7 to authenticate to THMDC when my rdp sesh just closes and the network shuts down. Is there something that can be done to improve these networks? Really frustrating.

ivory spruce
weary spindle
mortal siren
#

Will be done !!

naive dust
#

hello i cant seem to connect to the secure shell through the terminal, this is what it does:

ssh -i id_rsa cappucino@10.10.194.97 -v
OpenSSH_9.7p1 Debian-5, OpenSSL 3.2.2 4 Jun 2024
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: Reading configuration data /etc/ssh/ssh_config.d/20-systemd-ssh-proxy.conf
debug1: /etc/ssh/ssh_config line 21: Applying options for *
debug1: Connecting to 10.10.194.97 [10.10.194.97] port 22.
debug1: Connection established.
debug1: identity file id_rsa type -1
debug1: identity file id_rsa-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_9.7p1 Debian-5
debug1: Remote protocol version 2.0, remote software version OpenSSH_7.6p1 Ubuntu-4ubuntu0.3
debug1: compat_banner: match: OpenSSH_7.6p1 Ubuntu-4ubuntu0.3 pat OpenSSH_7.0*,OpenSSH_7.1*,OpenSSH_7.2*,OpenSSH_7.3*,OpenSSH_7.5*,OpenSSH_7.6*,OpenSSH_7.7* compat 0x04000002
debug1: Authenticating to 10.10.194.97:22 as 'cappucino'
debug1: load_hostkeys: fopen /home/kali/.ssh/known_hosts: No such file or directory
debug1: load_hostkeys: fopen /home/kali/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: ssh-ed25519
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
robust saddle
#

hi everyone

#

i've started the exploit ad room server again, however the domain controller is down

#

should i wait 2-3 more minutes in case it didn't boot up yet or is it broken?

#

or turned off

slim shadow
ivory spruce
naive dust
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #11 - 610)

ivory spruce
#

๐Ÿ˜…

ivory spruce
#

6 gb of RAM and 4 cores? I suppose kali can work fine even at 2 cores.

fast veldt
#

Actually not my machine doesn't become unresponsive

#

Only terminal become unresponsive

ivory spruce
#

Did you convert linpeas into an executable after copying linpeas into your target?

fast veldt
#

I did

ivory spruce
#

Or have you tried the other linpeas file types if .sh doesn't work?

fast veldt
#

Yeah neither working

#

Its not just about linpeas I always get issue

#

When using ssh with my vm

ivory spruce
ivory spruce
fast veldt
#

Getting above 100mbs

fast veldt
#

@ivory spruce you still there?

ivory spruce
ivory spruce
fast veldt
#

fine*

ivory spruce
fast veldt
#

I performed wget... It doesn't seem to work either

ivory spruce
fast veldt
fast veldt
#

I have python server running on the target machine

ivory spruce
fast veldt
#

I don't see any command

fast veldt
#

Okay okay got it

ivory spruce
fast veldt
#

yes

fast veldt
#

And its showing its connected

ivory spruce
fast veldt
#

Blank

ivory spruce
#

You can also try piping the results on linpeas to a file and sending the results to your attack VM via nc or curl

fast veldt
fast veldt
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #11 - 611)

ivory spruce
#

There is an explanation from Scrubz for it, but don't have time to go looking for it at the moment.

ivory spruce
fast veldt
acoustic barn
acoustic barn
ivory spruce
naive river
#

Thanks so much for this. Could not work out how to make it work myself.

scenic torrentBOT
#

Gave +1 Rep to @rare hound (current: #2131 - 1)

faint moat
karmic seal
#

any room I solve, its ip address goes down for some minutes and then goes up. Is it with everyone ?

acoustic barn
#

please confirm

weary spindle
#

That could be it.

acoustic barn
#

okayy

#

@weary spindle thanks for confirming

scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2509)

naive dust
#

hey im having trouble connecting the tryhackme vpn on windows

grizzled robin
#

Having issues with Snort Challenge - The Basics and I have reset the room 4 times and even check google for some walkthroughs and my answers come the same each time even following the walkthrough videos, some reason they keep showing incorrect each time you hit submit. Not sure if the room is buggy but the rest of the questions take the answers I provided and said they are correct.
by following this video and reading walkthroughs the answers should be correct.
https://www.youtube.com/watch?v=UPpJUTf7wEY

In this video walk-through, we covered using Snort to detect FTP and HTTP traffic by creating and configuring the appropriate rules. To apply what we learned, we analyzed given network captures using Snort to test the created rules and detect traffic patterns. This was part of TryHackMe Snort Challenge - The Basics.


Receive Cyber Security ...

โ–ถ Play video
obtuse terrace
#

who can u contact about restoring my streak?

west chasmBOT
#

@obtuse terrace

TryHackMe's Email

TryHackMe's support email address.

frosty island
#

can anyone help me in buying the premium subscription

#

my credit card is not working

#

ill pay u immediiately

ivory spruce
frosty island
#

nvm i bought voucher and used it

#

it would have been better if i payed using credit card i would have got 5$ discount

weary spindle
frosty island
#

ok my bad

young horizon
#

Hey ? if we buy Annual Premium Can We Cancel it ?Later also like after 1/2 months?

frosty island
#

how to change the country?

weary spindle
untold harness
#

I keep getting this error

weary spindle
naive dust
#

hello!, when using the attackbox, are there any keys that you could use to paste the previous command in the terminal again?

fast veldt
#

Getting issue connecting to vpn

weary spindle
fast veldt
#

Its happening in vm only...

#

I tried restoring snapshots but doesn't work

weary spindle
frosty island
naive dust
scenic torrentBOT
#

Gave +1 Rep to @frosty island (current: #2132 - 1)

naive dust
#

it really speeds up the process sometimes

random sleet
marsh frigate
#

Hey guys, How do I reset my progress? I want to start over.

frail sorrel
#

Its in the options of any room

true plover
#

Hi

#

Is it normal that the VPN doesn't come with a certificate? It comes with private key, ca cert, tls key, but cert part is empty

#

nvm created a ticket

cobalt mural
fossil belfry
#

i started a machine on the web but nothing show up i connected to openVPN

#

it happened for like 2 days now

elder gate
#

room zero logon >>> The questions do not appear and only the video appears

cunning thicket
#

Can I unlink my previous Discord on THM to link this account ?

weary spindle
cunning thicket
#

Lost my 2FA when my phone went in the sea ๐Ÿ˜‚

#

Have since recovered it but just stuck with this one.

#

Is it possible or is it going to be a rite PITA ?

tulip lotus
#

hey

#

little prob

#

i am on a kali vm

#

and i try to connect to openvpn

#

it does connect but only through the terminal

#

and it hijackes one of my terminals, never ending the command prompt, as if it loaded forever

weary spindle
cunning thicket
#

FR sent

robust saddle
#

hi @weary spindle unfortunately the exploitAD network is still not functioning. could you please tell someone to check what is wrong with the main domain controller for that room?

jovial cloak
#

Anyone know why my attackbox is so laggy

#

used to not be like this but now it takes 5 seconds for a button press to register

tulip lotus
#

Maybe it's been up for too long?

jovial cloak
#

I just restarted it

small spoke
#

Hello

#

Please anyone can help me

#

With error on openvpm

west chasmBOT
robust saddle
karmic seal
#

My vpn is not having stable connection. Like it disconnects for 3 to 4 mins then automatically gets connected

rare ore
#

out of curiousity is there a way to swap which side the attackbox / vm loads on?

frosty island
#

can anyone explain how does leaderboards work

ivory spruce
rare ore
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #11 - 616)

rare ore
#

attack box died on me, giving me this error, I now cant start it, getting the same error ๐Ÿ˜ฆ

wind pike
#

(never mind I figured out where my error was. Apologies for any notifications)

robust saddle
#

exploit AD room there is no flag on the desktop of the administrator user from tier 2 admin

robust saddle
#

tested with other users in the tier admins 2 group in case someone before me has deleted the flag but none of the accounts have the flag on the desktop

steep drift
#

Hello,
I get a connection error in open vpn as in the screenshot, can you help?

steep drift
#

Can you help me?

west chasmBOT
marsh magnet
naive dust
steep drift
#

this is how it is

marsh magnet
#

Have you tried the link above?

naive dust
#

Is your openvpn up-to-date?

steep drift
#

yes I tried

languid pier
steep drift
#

I am trying to connect to the vpn from the configuration file I downloaded

marsh magnet
#

Redownload your file on another server

naive dust
#

Yeah, if you leave this running and open an new terminal, can you do curl 10.10.10.10/whoami?

naive dust
#

@steep drift :)

steep drift
#

I am doing

#

Couldn't connect to server

#

curl: (7) Failed to connect to 10.10.10.10 port 80 after 21034 ms: Couldn't connect to server

#

I have something to do. If I can come back in a couple of days, can we take another look?

#

need to get out thank you for your support, see you again

open mauve
#

What will be your role as a Junior Security Analyst? please someone should help me answer this question is from TryHackMe

untold harness
#

https://tryhackme.com/r/room/windowsprivesc20 TASK6 machine will not connect
Here is my command

โ””โ”€$ xfreerdp /dynamic-resolution +clipboard /cert:ignore /v:10.10.26.17 /u:THMBackup /p:'CopyMaster555'
[08:20:34:819] [2199937:2199938] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[08:20:34:819] [2199937:2199938] [ERROR][com.freerdp.core] - failed to connect to 10.10.26.17

The machine has been online for 5+ minutes already. If when the machine ever comes up and I try to use it/click anywhere etc., this happens immediately:

โ”Œโ”€โ”€(stonedใ‰ฟkali)-[~]
โ””โ”€$ xfreerdp /dynamic-resolution +clipboard /cert:ignore /v:10.10.26.17 /u:THMBackup /p:'CopyMaster555'
[08:22:17:954] [2200881:2200882] [INFO][com.freerdp.gdi] - Local framebuffer format  PIXEL_FORMAT_BGRX32
[08:22:17:954] [2200881:2200882] [INFO][com.freerdp.gdi] - Remote framebuffer format PIXEL_FORMAT_BGRA32
[08:22:18:998] [2200881:2200882] [INFO][com.freerdp.channels.rdpsnd.client] - [static] Loaded fake backend for rdpsnd
[08:22:18:998] [2200881:2200882] [INFO][com.freerdp.channels.drdynvc.client] - Loading Dynamic Virtual Channel rdpgfx
[08:22:18:998] [2200881:2200882] [INFO][com.freerdp.channels.drdynvc.client] - Loading Dynamic Virtual Channel disp
[08:22:20:787] [2200881:2200882] [INFO][com.freerdp.client.x11] - Logon Error Info LOGON_FAILED_OTHER [LOGON_MSG_SESSION_CONTINUE]
[08:22:59:571] [2200881:2200882] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 110: Connection timed out
[08:22:59:571] [2200881:2200882] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[08:22:59:571] [2200881:2200882] [INFO][com.freerdp.client.common] - Network disconnect!

I am not able to do this task

#

Machine comes up, I try to open cmd.exe, it crashes. If I try to click somewhere or type something, this happens.

spice nacelle
#

Since yesterday I have been having problems with the website, it does not let me press the links or sometimes it does not even let me scroll, it freezes many times and even restarting does not solve the problem

untold harness
#

It also says this is in Kali linux, but I am not able to find this smb server script in Kali linux

#

I found them I guess in a diff place. So that problem solved. But the first instability problem with task 6 machine remains

โ””โ”€$ locate smbserver.py
/usr/lib/python3/dist-packages/impacket/smbserver.py
/usr/lib/python3/dist-packages/scapy/layers/smbserver.py
/usr/share/doc/python3-impacket/examples/smbserver.py
#

Now it won't connect at all.

deep wolf
#

@west chasm Is there someone that can help me with an issue with a room? I have asked in other places but no one responded.
I am in the Threat Intelligence Tools room on Task 5 and the IP address I have is correct but it is not being accepted as the answer. I have checked every where and my answer is right. I have also tried other things and nothing is working. can someone please help me?!

acoustic barn
#

@west chasm @sharp bison you guys need to look at ssh connection systems, they are not stable at all, they behave stuck every time i try to connect i see something new, few are the screen shots attached.

All the screenshots have delay of system restart between them, still it;s been an issue, i have restarted machine since couple of times... do something , this is not only today's problem, i face it everyday, but today i am tired of all these things.

Many other users might be also facing it, please look into it, it's very troublesome to operate with these unstable systems.

#

i wrote the above whole issue and still it's stuck, A LIVE EXAMPLE.

#

I am tired, I am not able to finish my room.

zealous yoke
#

run this command in a new terminal, while your VPN is running sudo ip link set dev tun0 mtu 1200 and attempt the SSH connectionagain.

This command basically changes the amount of data you send and recieve over the VPN at a time, some network connections can be a bit ... fussy

lunar zenith
#

Does anyone happen to know of a way to contact THM support? I am in the AWS EC2 Attack and defense room and am experiencing problems with my AWS environment. I've reset the environment several times, and no change with the issues I'm seeing. Thanks.

zealous yoke
scenic torrentBOT
#

Gave +1 Rep to @zealous yoke (current: #8 - 852)

zealous yoke
deep wolf
scenic torrentBOT
#

Gave +1 Rep to @zealous yoke (current: #8 - 853)

zealous yoke
acoustic barn
#

@zealous yoke thanks for showing a way out ๐Ÿ™‚

scenic torrentBOT
#

Gave +1 Rep to @zealous yoke (current: #8 - 854)

zealous yoke
acoustic barn
heady olive
#

hi im new in this, im in the learning path ofJunior Security Analyst Intro and i answer the questions (i think correct) and no matter what i put in the answer it always marks it as incorrect lol Maybe im wrong but is a really really basic question

zealous yoke
acoustic barn
zealous yoke
heady olive
#

Task 1 A career as a Junior (Associate) Security Analyst

zealous yoke
#

Okay cool. What do you think the answer is?

heady olive
#

Monitor network traffic logs and events, work on tickets, close alerts, and perform basic investigations and mitigations.

zealous yoke
#

Okay, so that's not exactly wrong - that would be part of the responsibilities and tasks that you would have

#

However the room is looking for a specific answer. If you look at the question, there are asterisks (*) indicating the length of the answer

#

The question is looking for a specific answer. Hint it's been provided in that task :). It's asking about the role, not responsibilities

heady olive
#

LOL

#

Now i start to understand the format

#

Thank you very much

zealous yoke
#

NP(: the answer format can be quite helpful sometimes

acoustic barn
#

and i have question can i increase mtu 1200 to 1400 or more?

zealous yoke
#

Great to hear ๐Ÿ™‚ you can increase it, but I would say just trial and error (i.e. trying different values and seeing if it works). If 1200 works then I would stick with that personally

zealous yoke
acoustic barn
scenic torrentBOT
#

Gave +1 Rep to @zealous yoke (current: #8 - 855)

zealous yoke
acoustic barn
#

ohh okayyy

#

thanks again for sorting this out

zealous yoke
#

You're welcome!

hot jasper
#

where to verify in order to send screenshots?

acoustic barn
#

type /verify

#

@hot jasper

hot jasper
acoustic barn
#

you're welcome man

plush bay
#

try making a new firefox profile or clear out cache and cookies and history

brazen patrol
#

does Firefox only freeze when using THM or other websites too? Run it from the terminal and when it freezes see if there are any warnings or errors that might be related

sour quartz
#

That's why it's saying it is wrong. Not a bug.

untold harness
#

https://tryhackme.com/r/room/windowsprivesc20 TASK6 machine will not connect
Here is my command

โ””โ”€$ xfreerdp /dynamic-resolution +clipboard /cert:ignore /v:10.10.26.17 /u:THMBackup /p:'CopyMaster555'
[08:20:34:819] [2199937:2199938] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[08:20:34:819] [2199937:2199938] [ERROR][com.freerdp.core] - failed to connect to 10.10.26.17

The machine has been online for 5+ minutes already. If when the machine ever comes up and I try to use it/click anywhere etc., this happens immediately:

โ”Œโ”€โ”€(stonedใ‰ฟkali)-[~]
โ””โ”€$ xfreerdp /dynamic-resolution +clipboard /cert:ignore /v:10.10.26.17 /u:THMBackup /p:'CopyMaster555'
[08:22:17:954] [2200881:2200882] [INFO][com.freerdp.gdi] - Local framebuffer format  PIXEL_FORMAT_BGRX32
[08:22:17:954] [2200881:2200882] [INFO][com.freerdp.gdi] - Remote framebuffer format PIXEL_FORMAT_BGRA32
[08:22:18:998] [2200881:2200882] [INFO][com.freerdp.channels.rdpsnd.client] - [static] Loaded fake backend for rdpsnd
[08:22:18:998] [2200881:2200882] [INFO][com.freerdp.channels.drdynvc.client] - Loading Dynamic Virtual Channel rdpgfx
[08:22:18:998] [2200881:2200882] [INFO][com.freerdp.channels.drdynvc.client] - Loading Dynamic Virtual Channel disp
[08:22:20:787] [2200881:2200882] [INFO][com.freerdp.client.x11] - Logon Error Info LOGON_FAILED_OTHER [LOGON_MSG_SESSION_CONTINUE]
[08:22:59:571] [2200881:2200882] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 110: Connection timed out
[08:22:59:571] [2200881:2200882] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[08:22:59:571] [2200881:2200882] [INFO][com.freerdp.client.common] - Network disconnect!

I am not able to do this task

#

I can't connect, even though the machine is up. It connected once, then disconnected when I tried to use it.

spice nacelle
#

im using a web browser called web and it works

turbid gorge
#

@untold harness remove some of the options. I connected just now with no such issues. However earlier, I did have an issue because I was using a few different options.

spice nacelle
#

im sure is a bug

naive dust
#

hey guys, non of the websites that are the in the jr pentester rooms are working, i've tried multiple times during different times

turbid gorge
#

Are you connected via vpn or the attack box?

obsidian plume
#

Attackbox or OpenVPN for beginners?

spice nacelle
pliant crag
#

I can't connect via openvpn, why is that? Due to proxy settings etc. ?

#

I look connected on OpenVpn

#

I can't also access anything on Attackbox's firefox

#

Probably due to sth about proxy settings but I don't know, I couldn't solve

#

I have firefox and burp community connected each other on my main windows host

#

I closed them both but didn't work

#

idk, it's just weird

#

I can't access any fucking thm machine rn

vestal lagoon
#

hello, this happened 3 times in a row, any tips to fix this? thank you

naive dust
vestal lagoon
#

but it works now

naive dust
#

Fair

agile basin
#

I am curious, is it possible to reset the account progress? I want to start over and I just bought Premium again, because it was some time ago

vestal lagoon
agile basin
vestal lagoon
zenith roost
#

hello guys,

start machine and split screen wont come out? How to fix?

frank night
#

hey, there is one missing answer box on the "Cyber Kill Chain" Task 9 site. I am only shown 6 answer boxes, however there is 7 questions that needs to be answered. As a result, i keep getting denied from completing :<

#

can't seem to provide an image though.

frank night
zenith roost
#

i also tried opening it on MS Edge, same result. When I click Start Machine it wont show me the split screen

plush bay
#

at that point it sounds like the browser is not the issue but something else is

untold harness
#

Meterpreter started opening dozens of sessions by itself. I only ran the eternalblue exploit on window ms17-010

cobalt mural
untold harness
#

payload => windows/x64/shell/reverse_tcp

cobalt mural
#

And then try running the exploit

untold harness
#

Not following

#

'target'?

cobalt mural
#

Change this to something more specific.

untold harness
#

Oh

#

I am not seeing that in there

cobalt mural
# untold harness

type set target then use tab autocomplete to list available options

untold harness
#

Oh I think we're in the wrong channel for room support.

#

ok

#

That's not working. I don't get anything autocompleted

pliant crag
west chasmBOT
marsh magnet
pliant crag
pliant crag
#

Btw, I am connected via openvpn but cannot reach machines.

#

When the vpn connection is off, it says that "ERR_NETWORK_CHANGED" and "you are disconnected", as expected:

#

But when I am connected via vpn, I have this error:

#

"ERR_ADDRESS_UNREACHABLE"

#

And, when I wait a little bit, it says "ERR_CONNECTION_TIMED_OUT", again as expected:

pliant crag
#

Because I am in the thm's private network, I am connected but somehow I cannot reach the machine.

#

@marsh magnet

#

so this made me think that this is because something about proxy settings, but I shutted them off, all of them(chrome, firefox, burp), again nothing changed

#

idk, I go crazy

marsh magnet
#

Yeah, if you leave this running and open an new terminal, can you do curl 10.10.10.10/whoami?

#

Wait are you on windows?

pliant crag
#

yes

#

windows

plush bay
#

well guess you are using the windows openvpn client then

plush bay
#

which could be the cause of the problem as that would limit your access to only the tryhackme network and no other stuffs

pliant crag
#

btw I also downloaded wsl-ubuntu my windows, wanted to say just in case

#

idk if that's the issue

pliant crag
#

but I can't

plush bay
#

also could because you turned on foxyproxy and never turned it off

#

as then you are using a connection to a proxy that no longer exists which would also cause no websites to work

pliant crag
#

I don't have and never had foxyproxy. The only proxy was burp, but I connected burp to firefox

marsh magnet
#

I actually don't like windows as a host so I can't help you I'm afraid.

plush bay
plush bay
pliant crag
plush bay
#

welp meep it no idea what is going wrong

#

but there is a reason people don't use windows to hack

#

and use kali linux vm:s instead

pliant crag
pliant crag
#

Because it uses the same network with host machine

plush bay
#

nope the vm is segmenting it out to its own network

#

and if you use the command line linux openvpn client it should not cause any issues either

pliant crag
#

for example, I couldn't reach also firefox and thm machine inside attackbox

plush bay
#

yeah something is obviously wonky but no idea what

pliant crag
#

Okay guys I will try vm as a last hope:) thank you for your time @marsh magnet @plush bay

scenic torrentBOT
#

Gave +1 Rep to @marsh magnet (current: #45 - 166)

marsh magnet
#

+rep @plush bay

scenic torrentBOT
#

Gave +1 Rep to @plush bay (current: #3 - 1832)

summer halo
#

Hey so I found a something that needs small fixing in this
Room:
https://tryhackme.com/r/room/splunkdatamanipulation

Task6:
Restart Splunk
Save the file and restart Splunk using the command~~ /opt/bin/splunk~~ restart. Open the Splunk instance at 10.10.55.95:8000 and navigate to the search head.

it should be /opt/splunk/bin/splunk restart

zenith roost
turbid gorge
#

The machine can take up to 10 minutes to be ready, and the attackbox in full screen is suggested in the notes. I assume you've been waiting a while?

#

Machine appears to be functional on my end via attackbox. Logged into the OpenCTI Dashboard. Also working via VPN.

turbid gorge
#

Are you using the attackbox or vpn?

zenith roost
#

the attackbox button on the top of the page works but the dedicated attack box on the tasks arent opening.

#

i mean some arent

#

ive been jumping from rooms to rooms so I can keep my streak ๐Ÿ˜ญ

#

i just changed to chrome and still same issue

frosty fox
#

I am trying to connect to a room and have the VPN correctly set up, but for some reason I can't access the machine (and don't get a response from 10.10.10.10). Does anyone have an idea about what could be wrong?

frosty fox
#

Nevermind, it worked!

real verge
#

Hello, Iโ€™m trying to download my vpn access file but keep on getting error 500

#

When I click on regenerate I get same error too. Please I need help to solve this

haughty oak
#

is it intentional/normal that a whole bunch of previously-free rooms suddenly became premium? these aren't new rooms; some have been out for years

#

eg, mrphisher, several print nightmare rooms, templates, posheclipse, a dozen others

haughty oak
#

๐Ÿ‘

#

these seem like fairly low quality rooms so far, which seems odd to turn into premium, but as long as people are aware

brazen patrol
#

Can someone manually apply student discount on my account, I'm replying to the problem which I had with my college email. Blackout had told me in dms that it would be applied manually after I switch to my regular email and subscribe (which I did now after a month) but he isn't responding to my dms about it

turbid gorge
#

I believe you have to email support for that.

#

I'm not 100% certain what the email is though.

royal leaf
#

Hi, i'm new to THM and i have little to no knowledge about how OpenVPN works. When trying to connect using the given configuration file here is what i am prompted with :

2024-07-18 04:17:10 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.

2024-07-18 04:17:10 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.

2024-07-18 04:17:10 Note: '--allow-compression' is not set to 'no', disabling data channel offload.

2024-07-18 04:17:10 OpenVPN 2.6.9 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]

2024-07-18 04:17:10 library versions: OpenSSL 3.2.2-dev , LZO 2.10

2024-07-18 04:17:10 DCO version: N/A

2024-07-18 04:17:10 OpenSSL: error:0480006C:PEM routines::no start line:Expecting: CERTIFICATE

2024-07-18 04:17:10 OpenSSL: error:0A080009:SSL routines::PEM lib:

2024-07-18 04:17:10 Cannot load inline certificate file

2024-07-18 04:17:10 Exiting due to fatal error

turbid gorge
#

I'm about to head to bed, but are you using the attack box or the VPN on your own VM?

#

To continue my limited brain function, if you are using the VPN on your own VM, are you using sudo?

royal leaf
turbid gorge
#

awesome, apologies but i'm heading to bed.

royal leaf
turbid gorge
#

If you need anything else, I'll message you back tomorrow. Good luck!

naive dust
mild vortex
#

Hello support. My issue is with Wazuh 30062023. I cannot access the server. I have waited, tried different browsers and checked firewall settings. I am using Chrome on a Mac. The server is accessible thru the attack machine, but the password does not work.

mild vortex
#

solved..nevermind

idle grotto
#

Exploiting AD issues. I exited the ssh session as I waited for the permission changes I made to propagate through the domain. Now, no matter what I do, I can't reconnect via ssh. I keep getting an issue that says -
"ssh: connect to host thmwrk1.za.tryhackme.loc port 22: no route to host"
Nslookup dns request resolved to the proper IP.
The subnet is 10.200.77.0/24

#

I can ping all the other machines in the domain, but not thmwrk1!!!!!!

idle grotto
#

I get the same "no route to host" message via AttackBox and my own machine

maiden path
#

@foggy rover Hey there is a typo in the 'Active Directory Basic' room. Task 7 -> second question (... request further tickets known as TGS?) Where TGS is refering to Ticket Granting Ticket (TGT).

idle grotto
#

Working now. Weird

weary spindle
west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

weary spindle
maiden path
#

sorry

weary spindle
#

It's ok

versed jasper
#

i had lost my 72 days streak is there a way to get it back

dreamy heart
#

hi, so i wanna unlink my previous account and link this account to my tryhackme

ocean sable
#

my openvpn is not working it keeps saying exeting due to fatal error and cannot load inline certificate files is there any fix?

ocean sable
#

i did use sudo

dreamy heart
ocean sable
#

not letting me send it for some reason

turbid gorge
#

Need to verify your account to send screens.

west chasmBOT
marble breachBOT
#

Done!

paper snow
#

Hey i dont now if there is any machine based search possible ,

I want to search for rooms that have windows based machines

Is it possible to add : windows/linux category on search filter as well

naive dust
#

And if someone could explain me why I got 2 lines instead of one (that's fhe result i usually get)

weary spindle
#

Where did your friend get it?

weary spindle
naive dust
#

I dunno he just sent me the file and told me "let's see if you got some skills"

#

I saw that with a gtx 1060 you could get pretty good results with hashcat but my gpu isn't that good so I couldn't try those kind of approaches

weary spindle
#

Since we can't verify where they got the file from, I'd appreciate if you don't send it in here, and stop asking for help.

naive dust
#

I didn't send the file

#

I sent the hash I got from the rar2john tool

#

I'm sorry if it seemed like it was some scam or virus but it's not

naive dust
solid wasp
#

Im doing Enumerating Active Directory (https://tryhackme.com/r/room/adenumeration) room using AttackBox however "enumad" interface required to connect to the dns, seems to cease to exist
only interfaces that exist are
lo
ens5
breachad
lateralmovement
docker0
veth91492349@k1d
vethhhb9123sfd141234

ivory spruce
west chasmBOT
#

@versed jasper

TryHackMe's Email

TryHackMe's support email address.

versed jasper
#

@ivory spruce thank you

scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #11 - 618)

toxic loom
#

@west chasm I got a message from an account hijacker and DDOSer that is in this server. He is a known malicious actor on Xbox and has stolen dozens of accounts and knocks people offline anytime he wants. I have screenshots of him bragging to me but I cannot upload an image in this channel

#

Vote to ban from this Server

spice nacelle
toxic loom
#

Vote to ban the dude who just spammed me with messages about how he stole 4 accounts today

spice nacelle
#

but he is in this channel?

toxic loom
#

Heโ€™s in this server

#

Just sent you screenshots

#

skinertin

#

Heโ€™s a known malicious actor

#

In the screenshots I sent you he says โ€˜this is skinny btwโ€™ and once I read that I knew it was skinnyrat

spice nacelle
#

just dont send me any screenshot, delete that

toxic loom
#

Done

spice nacelle
#

They are strong accusations, and the truth is I don't know if they can do anything here, in any case if it is real and you can defend it, report the user, and email support commenting on the situation.

signal lotus
scenic torrentBOT
#

Gave +1 Rep to @signal lotus (current: #2141 - 1)

crisp osprey
#

Hello

#

is there anyone i need a help

#

trying to connct to openvpn showing this

pulsar scarab
#

redownload

naive dust
#

Mmm yeah try re-generate one

crisp osprey
#

try many times

pulsar scarab
#

try a different server

ivory spruce
crisp osprey
#

wow what an amazing servers !! tried 5 diff servers

pulsar scarab
#

@crisp osprey do you still have problems?

marble breachBOT
#

Done!

lean wolf
#

Hello. It is impossible to download VPN configurations

weary spindle
lean wolf
#

Config files download are never starting

#

never mind, it is ok now. But that wasn't during a while before

#

BTW there is some issue with the connection

karmic flicker
# crisp osprey

I had the same issue.

It's a backwards compatibility issue - basically your openvpn version is out of date.

Easy fix is just to edit the ovpn file and at the very top you will see a line that says 'data-ciphers AES-256-CBC'

Above it, add a line that says 'cipher AES-256-CBC' Then it should work.

Screenshot shows example highlighted

#

Or just download the most up-to-date version of openvpn and that should sort it too

lean wolf
#

How do you explain that we cannot upload screenshot in a support channel

weary spindle
west chasmBOT
lean wolf
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2513)

#

You're still on cooldown

lean wolf
#

So, looks like there was some issues with the site and available files

karmic flicker
#

That message just says the file you are trying to download already exists on your computer and is asking if you wanna replace it

#

so go to your downloads folder and see if it is there maybe?

lean wolf
#

was talking about the size

#

config file with a size of ~3.7Kio = openvpn just doesn't try anything
config file with a size of ~8.1Kio = openvpn connection never end

#

i can connect to the VPN of HackTheBox, so i think there is no issue from my side

#

When trying to download eu-regular-3 file

pulsar scarab
#

same happens when I try it, probably a bug.

lean wolf
#

Looks like the THM team have works to do

ivory spruce
lean wolf
#

tried many times before

#

or you wanna mean i need to retry now because someone patched it?

ivory spruce
#

Wait for 2 to 3 mins after changing the server before downloading the OpenVPN config.

lean wolf
#

i am waiting since 1h

ivory spruce
#

Have you tried to generate your OpenVPN config file again?

karmic flicker
#

So if you try to download EU 1, 2 or 4 it says Access denied?

#

EU 3 download is broken for everyone it seems

lean wolf
#

No, but error 500 on EU 3. Access Denied don't show up again

#

but nothing working btw

karmic flicker
#

So what happens now when you click to download on EU 4

#

or 1 or 2

lean wolf
#

i can download, but VPN is not working

karmic flicker
#

Okay so show the error message for the vpn

lean wolf
#

I am sorry i have to lunch. My goal wasn't to work on a server side VPN issue today

ivory spruce
karmic flicker
#

For some reason, the openvpn client isn't recognising the data-ciphers argument but only recognises the 'cipher' argument. This was with a fresh download from the openvpn website today.

So, tryhackme servers are fine there is just a weird compatibility thing with the client and the config files - at least for me anyway.

But if it is the same for you, that is an easy fix.

robust saddle
#

why is this happening?

#

and yes, the network is already started

turbid gorge
#

Did you join the exploit ad VPN?

#

It's a separate network, different vpn file.

turbid gorge
#

when you hit "ip a" do you see the adapter called exploitad?

lean wolf
#

the only way to make that working is starting the VPN without NetworkManager

karmic flicker
#

So are you connected now?

scarlet steppe
#

What is the delay to get the student discount approved usually?

plush bay
#

but it can change widely dependin on how many support tickets there are

scarlet steppe
#

I need to create a ticket for it ?

plush bay
west chasmBOT
#

@scarlet steppe

TryHackMe's Email

TryHackMe's support email address.

plush bay
#

if you wanna send a ticket for it

lean wolf
sand peak
#

anyone know why ?

ivory spruce
frozen echo
#

Im using Kali and I am able to navigate to the TryHackMe access page and it says Iโ€™m connected and provides the ip. But the access machine button in the upper right corner is still red and says disconnected. Has this happened to anyone else

ivory spruce
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #11 - 620)

kindred mesa
#
Problem converting VM. Check prerequisites.```
#

Ubuntu 20.04

#

Anyone can help?

ivory spruce
kindred mesa
weary spindle
#

?*

kindred mesa
sage topaz
#

hello,trying new things

green ice
#

In the past there was a post on the help center to explain the rules for write-ups (solutions). E.g. delay after a room released to be allowed to publish a WU, what the WU must not contain, etc.
I don't find anything anymore either on the blog or on https://help.tryhackme.com/en/
Does someone can point me to the rules if they have the link?

untold harness
#

You can't sudo echo something with >>. It won't work. Syntax is wrong. You will get permission issues on /etc/hosts

#
sudo -s
echo 10.10.6.20 lists.tryhackme.loc >> /etc/hosts

would work.

digital pine
#

Iโ€™m having trouble seeing when I connected the OpenVPN configuration/connection on the access site. I tried using different servers, regenerating the configuration and installing the config. I tried via OpenVPN GUI on macOS, no luck; OpenVPN command (sudo openvpn /user/Downloads/file.ovpn ) via terminal, no luck; same command and process of new server, config, etc, on Kali Linux but no luck. When I connect to the VPN using the commands, the website doesnโ€™t identify it but when I open a new tab and type โ€œcurl 10.10.10.10/whoamiโ€, I get the VPN IP, as expected.

cobalt mural
# digital pine

Check your interfaces with ip a
You may have connected to the VPN more than once, if so you will need to delete the additional interfaces

digital pine
karmic oak
wanton sandal
#

@karmic oak 1 answer: Get-WinEvent -LogName Application -FilterXPath '*/System/Provider[@Name="WLMS"] and /System/TimeCreated[@SystemTime="2020-12-15T01:09:08.940277500Z"]'
2 answer: Get-WinEvent -LogName Security -FilterXPath '
/EventData/Data[@Name="TargetUserName"]="Sam" and */System/EventID=4720'

half granite
#

not able to submit the answer

brazen quail
#

i am 0x4 but i have 0x1 rank

#

pls help

#

pls

cobalt mural
ivory spruce
scenic torrentBOT
#

Gave +1 Rep to @wanton sandal (current: #2142 - 1)

digital pine
#

oh, I just noticed the pinned messages ye_smh
update: andddddddd, still apparently "disconnected"

simple sedge
#

hello! I'm having issues accessing Target machines using OpenVPN.
I connect to the vpn as instructed, and i see the " Initialization Sequence Completed".
curl 10.10.10.10/whoami
returns the right ipaddress.
but when I go to the site, there is the red "access machine" button.
I ran the troubleshooting script and it shows nothing is wrong.
but when i enter the target ip in my browser, the site refuses to connect.

weary spindle
simple sedge
weary spindle
#

Each task has its own thing. First machine is smb.

simple sedge
dusty plaza
#

Does somebody can helps me ?

weary spindle
weary spindle
simple sedge
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2522)

dusty plaza
brazen crystal
#

Is there any way to download this file to my local system?

#

FYI.. I developed that room, and that's my file ๐Ÿ™ƒ

dusty plaza
weary spindle
torpid rain
#

Hey guys, a ran into a problem, the excersise lab doesn't work in Windows Forensics 1 and Investigating Windows. The machine is opening in split view, i'm recieving an IP, but i dont actually see the machine, just a black screen. Could anyone help me pls?:)

mint yew
#

Reach out support. prayge

thorn karma
#

help me

cobalt mural
smoky fog
#

hello please i have so trouble when i want to access to some machine ip nmap and ping it work but in firefox it's not work

#

i use script troubleshooting thm

#

i don't know what's the problem

#

it just search for ip but bo results of error or any proxy problem just loading without output

weary spindle
#

Are you using a VM?

smoky fog
#

my local machine

#

ping and nmap work correctly ffuf work correctly

#

but the Firefox no

weary spindle
#

Is there a webserver on port 80?

smoky fog
#

yes

weary spindle
smoky fog
#

yes

weary spindle
#

sudo ip link set dev tun0 mtu 1200

smoky fog
#

it stay like this hour and hour without output

#

i try it

weary spindle
#

Leave your VPN running.

smoky fog
#

i use thm troubleshooting

#

script

#

and tell me about mtu

#

w and i conf it

#

ffuf it work corrctly

#

every room that i open Firefox have the same problem and i try to restart the machine on TryHackMe with a new ip but the same

heavy crypt
#

Hi I'm in room: [TryHackMe]
Splunk: Data Manipulation

Task 6: The url to regex101.com goes to a room that doesn't exist called reg101.com, if someone types that into their browser it brings them to a domain registration site.

Thought that might want to be fixed at some point to avoid confusion.

#

Also further down in that tasks it refers to the wrong command to start splunk

/opt/bin/splunk restart

When it should be

/opt/splunk/bin/splunk restart
spice lion
#

Hello Pals, Can anyone help me out on how to blast bulk email at once.

terse shale
#

hi i am in network services and have been stuck for a bit trying to get enum4linux to work . i have a no reply from target ip in the nbtstat and a global workgroup concatenation error. can any one help?

dusty plaza
#

Hello, I tried to log in to VPN in both the company environment and at home, but it didn't work and the prompt was' check your network connectivity '
Have all IP addresses in China been blocked?

#

This problem has been bothering me for a long time. I have tried many methods, even reinstalling the system, resetting the router, changing the VPN file, and trying to log in in in different network environments, but the error messages are the same

ivory spruce
ivory spruce
mint yew
#

https://tryhackme.com/r/login/sso prayge

#

@wind wedge is this for who has Bussiness THM acc? ^^^

agile jackal
#

Not getting audio form my attack box

gaunt pier
#

Hello

#

Im getting this error when Im logging into the Active Directory DC using xfreerdp

#

I have tried the following command

#

When connecting through rdp, I am unable to login to the machine using the given password

#

But I am able to access the machine using Split-Screen-View without the hassle of inputing the logging the credentials. It all okay for me. Just wanted to know why is this happening?

near edge
#

Vm box firefox browser not working even though I checked the internet connection, and cleared cache. Please help!

turbid gorge
#

Sub in your machines IP obviously.

gaunt pier
scenic torrentBOT
#

Gave +1 Rep to @turbid gorge (current: #161 - 43)

gaunt pier
#

it worked

#

Just saw that I was connecting to the wrong domain

#

Noob Mistake ๐Ÿ˜…

terse shale
# ivory spruce Where are you running enum4linux from - Attackbox or your VM? If the latter, are...

hi i was using the attack box through browsers. i tried some work arounds but i think it is a bug within the samba and i havent been able to figure it out yet. here is the message--- Use of uninitialized value $global_workgroup in concatenation (.) or string at /root/Desktop/Tools/Miscellaneous/enum4linux.pl line 437.
[E] Server doesn't allow session using username '', password ''. Aborting remainder of tests.

heady root
#

Hello i submited this ticket last week and has been over 5 days and have not recived any response and not been able to do any of the courses ๐Ÿ˜ฆ

#

Ticket ID 30628

#

I am getting an error opening configuration file: .ovpn

#

I have tried all the steps in the recommendation and also have reinstalled the OS and done different servers and regenerated the file still a problem

#

Any help would be appricated as i have not been able to do Try Hack me for 5 days now ๐Ÿ˜ฆ

restive hatch
#

i have the solution for you @heady root

heady root
restive hatch
#

you need to regenerate and download another region config pack

#

you can try us one

ivory ermine
#

server until it finally works

#

i had the same problem

heady root
#

Ok let me try

ivory ermine
heady root
#

Just trying all the servers

#

No luck at the moment ๐Ÿ˜ฆ

restive hatch
#

sometimes europe servers are not working

heady root
#

No luck

restive hatch
#

all?

heady root
#

Yeap i have tried every server

restive hatch
#

BUT WHAT IS THE PROBLEM

heady root
#

So annoying as i am paying for this

restive hatch
#

YOU ARE PREMUIM RIGHT

heady root
#

Yes let me get you the error message

restive hatch
#

CAN YOU GIVE ME SCREENSHOT

#

OF

#

PROBLEM

ivory ermine
#

bit of a silly question guys but when im in web developer tools

#

im trying to change some code from id=50 to id=1

#

and its not letting me edit anything

ivory spruce
ivory spruce
#

After switching your server, wait for about ~2 to 3 minutes before generating your ovpn config file.

ivory spruce
brave garnet
#

found a problem in the Threat Intelligence Tools on task 7 "From Talos Intelligence, the attached file can also be identified by the Detection Alias that starts with an H...". after giving the sha256 hash of the Email2.eml to Talos it finds it, but the answer is nowhere to be seen. only got it from looking into medium.com to confirm i didn't do anything wrong .

#

can't post screenshots but the hash is "97028b1b198af6da1043b78e40e1efe519fe3def754cd9d1f29380ca11e5c361" and the answer is "HIDDENEXT/Worm.Gen" coming from the detection alias in talos

terse shale
ebon ruin
#

I am trying to sign up to website but everytime it shows Captcha has failed. pls help !

timber charm
#

If you pause subscription do you still have to pay?

floral cloak
#

@rare ore any idea?

rare ore
# floral cloak

like @steep pelican said, might need to post the last 5-6 lines , does it say ?

floral cloak
#

i have peer-id: 29 and no compression after that

#

ill send more tho 1 sec

rare ore
#

looks good to me, whats not working for you?

floral cloak
#

the command line supposed to be blank?

#

can i just do new tab

rare ore
steep pelican
#

Yes, seems you are connected. There will nothing more happen.

rare ore
#

yeah

floral cloak
#

ok thanks

#

also do you have nod on twitter?

#

thats a sweet alias

steep pelican
#

Now you can test to connect to 10.10.10.10

floral cloak
#

yea it works thanks boys

clear raft
#

Hi everyone ๐Ÿ‘‹, I'm looking for help setting a streak goal. Specifically, I want to set a goal and have the website remind me so I don't forget.

maiden folio
#

Hi guys any idea on this error ? I tried multiple things but I can't access to the vpn

weary spindle
#

But i think it's hit or miss with some mailboxes.

coral anvil
#

i mail to tryhackme for reset progress not delete account and they deleted my account lmao

weary spindle
weary spindle
#

They can't reset it without deleting

coral anvil
#

now i lost my username

#

and cant take it back because system saying its already use

weary spindle
#

You might need to email support for help with that.

What is your username?

coral anvil
#

caesar00

weary spindle
burnt birch
#

In my opinion is some kind of issue with Kerberos in room (CVE-2022-26923): https://tryhackme.com/r/room/cve202226923

while testing a ticket I got error:

**certipy auth -pfx thm.pfx
Certipy v3.0.0 - by Oliver Lyak (ly4k)

[] Using principal: thm@lunar.eruca.com
[] Trying to get TGT...
[-] Got error while trying to request TGT: Kerberos SessionError: KDC_ERR_PADATA_TYPE_NOSUPP(KDC has no support for padata type)
**

Both attachebox and openvpn have the same symptom. Restarting the machine does not help.

agile shard
#

Hi. I'm having problems on starting the Network on room - Breaching AD
When I click "Start" this is the error message: "Uh-No! Failed to start the network"
I tried the other AD rooms and always the same error message

maiden folio
vale basin
#

quick question. Can I keep attack box running through multiple curses or do i need to terminate it everytime

weary spindle
vale basin
#

thanks

hot cypress
#

Hello everyone, I have a small question about the THM subscription. Since it's my first time, I forgot to unsubscribe to cancel the auto-renewal in order to take a break to properly assimilate what I have learned. So, if I click on pause for a month, my subscription will be valid again between August 23 - September 23? If I don't cancel the auto-renewal around September 22, it will resume, is that correct if I understood correctly?

weary spindle
hot cypress
#

Okay thanks for your opinion, i ll ask the support directly on the website then

weary spindle
#

I mean, I just pinged them, but sure. ๐Ÿ™‚

wind wedge
weary spindle
scenic torrentBOT
#

Gave +1 Rep to @wind wedge (current: #52 - 143)

sand peak
#

guys why i cant see this room
i have the link

weary spindle
vestal lagoon
#

is this really what im paying for?...

weary spindle
sand peak
vestal lagoon
weary spindle
weary spindle
vestal lagoon
#

im really disappointed by this issue bc this is not the first time it happened

vestal lagoon
weary spindle
#

Excluding public holidays and weekends.

vestal lagoon
#

thst like 2-3 more days than i expected lmao

weary spindle
#

THM has over 3 million members, if 1% of that was to E-mail that's still 30000 E-mails.

vestal lagoon
#

yeah i get that, employ more people or dont do things that result in issues like mine

#

it was last week when it happened for the first time

#

it was not a problem before

#

so something definitely changed, not in a good way

wind wedge
vestal lagoon
scenic torrentBOT
#

Gave +1 Rep to @wind wedge (current: #51 - 144)

wind wedge
#

@vestal lagoon Does this happen in any room and how often does it happen?

vestal lagoon
leaden kiln
#

Can I change my email address on the TryHackMe platform I want to use my student email ID to avail the student discount.

weary spindle
leaden kiln
weary spindle
leaden kiln
wind wedge
#

Windows room again?

vestal lagoon
#

yes it's the same room

#

help via the chat on the website is very helpful as well (y)

#

thank you @wind wedge , I guess there is nothing more you can do

scenic torrentBOT
#

Gave +1 Rep to @wind wedge (current: #51 - 145)

wind wedge
#

Unfortunately not ๐Ÿ˜ฆ we've got a few reports that I have raised

vestal lagoon
#

yeah it's alright, as i said earlier, the issue is a new thing, it has never happened to me until the last week so I assume that just some overlooked bug got to the production environment, at the end of the day, this can happen even to the biggest cybersecurity companies :))

autumn knot
#

Hey, is it just me, or the vpn file for the holo network is empty for everyone? Can you guys pls fix this asap?

naive dust
#

Can support change the email? Even when signed in with google?

naive dust
#

I'm still wondering how in earth that could have happened

grim cedar
#

I canโ€™t move further on the SNORT CHALLENGE, kindly help me , I have answered the question correctly but Iโ€™m unable to get it corrected, which makes me stucked

dusk kestrel
#

hi everyone hope you are doing well i have a problem in the Breaching Active Directory room . i can ping to the DNS but i cant 'nslookup tryhackme.com 10.200.26.101 ' it gives me communications error to 10.200.26.101#53: timed out . can anyone help me ?

winter roost
#

Sorry if this has been asked before, I searched for the term SOC and didn't find any discussion related to this.

Is the SOC 1 path update still happening? Seems that the blog post has been removed. Can't find any other announcement other than the email sent July 11

dusty plaza
#

Hi teasm๏ผŒIs there no other way to deal with the Chinese firewall? I have no ill intentions

dawn raft
#

Hi, i've been working on my path for the last few hours and since the last couple of minutes i have termination on the windows vms i'm working on (https://tryhackme.com/r/room/winadbasics), already happend 3 times in less than 10 minutes so if anyone can help please?

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

#

(and yeah i read the link on the why)

leaden kiln
dawn raft
# leaden kiln I am currently facing the same problem, and it has appeared four times. Is there...

shot a mail to support i got this :

- Open your browser settings.
- Locate the option to clear browsing data.
- Select "Cached images and files" and "Cookies and other site data."
- Click on "Clear data" or equivalent.

2. Disable Browser Extensions:
- Open your browser's extension or add-ons menu.
- Disable all extensions.
- Restart your browser.

3. Try Incognito/Private Mode:
- Open a new incognito/private window.
- Check if the issue persists. This step helps identify if extensions are causing the problem.

4. Update Your Browser:
- Ensure your browser is up to date with the latest version.
- Check for updates in your browser settings.

5. Switch to Another Browser:
- If possible, try accessing the website using a different browser.
#

trying to use solely the split view now (i was using xfreerdp)

leaden kiln
#

Ok

undone ruin
#

I am having issues with my vpn, I have tried regenerating and connecting but i am not being able to connect, can someone help me figure out what's happening ?

opaque echo
#

In the room https://tryhackme.com/r/room/fileinc Challenge 2 i changed to Cookie value to Admin and i'm getting the following error Warning: include(includes/Admin.php) [function.include]: failed to open stream: No such file or directory in /var/www/html/chall2.php on line 37

Warning: include() [function.include]: Failed opening 'includes/Admin.php' for inclusion (include_path='.:/usr/lib/php5.2/lib/php') in /var/www/html/chall2.php on line 37

gaunt fulcrum
#

how can in send a screenshot in discord ? thanks

turbid gorge
#

verify your account.

west chasmBOT
gaunt fulcrum
#

the + doesn permit to me to send anythinj

echo sage
#

sudo openvpn ~/Downloads/SYER7171.ovpn
2024-07-24 10:39:52 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-07-24 10:39:52 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-07-24 10:39:52 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-07-24 10:39:52 OpenVPN 2.6.11 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-07-24 10:39:52 library versions: OpenSSL 3.2.2-dev , LZO 2.10
2024-07-24 10:39:52 DCO version: N/A
2024-07-24 10:39:52 OpenSSL: error:0480006C:PEM routines::no start line:Expecting: CERTIFICATE
2024-07-24 10:39:52 OpenSSL: error:0A080009:SSL routines::PEM lib:
2024-07-24 10:39:52 Cannot load inline certificate file
2024-07-24 10:39:52 Exiting due to fatal error

#

What The Problrm

naive dust
wild oyster
#

servers have lag as hell. i couldnt get any response to my requests. nmap fails, gobuster fails, web requests fails. tried to change server but still the same

tidal maple
#

Hello,
When I was a premium subscriber I finished the devsecops Learning Path and now I'm not a premium subscriber, I'm not allowed to revise what I've already learned? Where's the logic in that?

charred stump
tidal maple
weary spindle
scenic torrentBOT
#

Gave +1 Rep to @charred stump (current: #1073 - 3)

tidal maple
prisma garden
#

I am trying to do the new "Summit" room in SOC lvl 1. I click start machine and it does not show me the split screen view with the VM, and there is no option at the top to start it that way either. Any ideas?

weary spindle
weary spindle
tidal maple
rotund sluice
prisma garden
scenic torrentBOT
#

Gave +1 Rep to @rotund sluice (current: #82 - 80)

twin moon
#

can i make a portfolio using the task on the tryhackme rooms, i want to put it in github. is it allowed or no?

weary spindle
light seal
#

what do you mean by subscription content?

turbid gorge
#

I can only make assumptions, but posting content from premium rooms verbatim, essentially giving someone the information / graphics for free?

rotund sluice
harsh root
#

Hello,

I am currently experiencing difficulties with loading virtual machines on your platform. Here are the details of the issue:

Virtual machines, especially those running Windows, do not load properly when I try to start them. After the download, the screen goes black in the web browser and the machine becomes unresponsive. Virtual machines running Linux work correctly only windose ???
Browser used: Firefox and chrome (edge)
Actions already taken:
Checked my internet connection
Refreshed the page
Tried a different browser
Cleared browser cache and cookies !!!!
Disabled browser extensions
I am a premium subscriber, and despite these efforts, the problem persists. Could you please assist me in resolving this issue?

Thank you in advance for your help.

Best regards,

main sedge
#

Hi, how much memory can you have for your virtual machine?
I think the limit without asking for more is 256?

stoic orchid
#

hello guys

vast urchin
#

uh i found something very strange when doing a room, it contains nsfw words, should i send screenshot?

stoic orchid
#

i do have a problem with my openvpn. I am unable to make a conncetion to the server. I need your help to get this sorted

#

here is a screenshot of my error message

vast urchin
#

idk if its normal people showing ip here so i will better stay quiet ๐Ÿค

stoic orchid
#

you are right.

vast urchin
stoic orchid
#

however, i do need help with the openvpn issue. Any idea on how to get it sorted

main sedge
#

So if you're using EU-Regular-1, try EU-Regular-2.
For me that fixed everything.
if that does not work, there is a script online which fixes it for you.

vast urchin
#

btw, yall, is this normal to find in a room? ๐Ÿ˜ญ

turbid gorge
#

yeah, nope...

vast urchin
turbid gorge
#

are you on the vpn. and did you type the address correctly?

#

Which task specifically?

vast urchin
#

attackbox

main sedge
turbid gorge
#

lol.

vast urchin
#

this was my command, which was a command that the tasks didn't ask for

vast urchin
#

i can only adress the webpage with the domain name, which i wrote beforehand in /etc/hosts

#

it is indeed correct

#

checked 4 times

main sedge
vast urchin
#

i am doing the task with normality, it is indeed the right server

#

as you can see is part of the web enumeration tasks, and in the right tab i have the flag

#

this is wild ๐Ÿ˜‚

#

also i was just recommending a new person tryhackme and how it works, this is crazy

main sedge
#

This is by-far the weirdest thing I've seen on THM so far.

vast urchin
#

im glad yall are here to see this with me ๐Ÿ™‚

main sedge
turbid gorge
#

Oh, this is epic fuckery...

tight bay
turbid gorge
#

lol

vast urchin
#

i was just showing this is indeed the testing domain

main sedge
vast urchin
#

okay doing it asap

main sedge
vast urchin
#

WHAT

#

IT HAS CHANGED

main sedge
#

I'm gonna quickly grep that wordlist to see if it actually contains any NSFW words

vast urchin
#

im out here living on a prayer to not get banned now ๐Ÿ˜ญ

#

btw im aware i got the wordlist wrong for a subdomain search

main sedge
#

But there can't be any domains with. what she had o_O?

#

Surely not?

turbid gorge
#

yeah...

main sedge
#

That's something, perhaps it bugged out and thought it found some NSFW sites. Could be an AttackBox issue.

vast urchin
#

still, even if i dont have that giant nsfw title, i can still find subdomain like ladies

#

im sad i didnt found this before my feedback interview with tryhackme ๐Ÿ˜ญ

main sedge
vast urchin
#

wait wait wait, it is about to hallucinate the same again?

#

it is refinding the same titles

#

the command is the same for dirb right?

main sedge
#

@vast urchin Just checked, that word list does contain those weird sites, Gobuster must have bugged out and shown some of the "known" NSFW sites.
Why ladies DNS exists, is beyond me.

#

it may have been caused by you ctrl-c'ing a bunch of times maybe.

vast urchin
#

it wasnt control c actually, it was right arrow

#

idk why it is spelled in terminal as control c too

main sedge
#

Ahh, looks like ctrl-c

vast urchin
#

yeah i noticed too, i think the difference its that theres 2 "["?

#

or idk

stoic orchid
#

2024-07-25 03:52:06 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-07-25 03:52:06 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-07-25 03:52:06 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-07-25 03:52:06 OpenVPN 2.6.11 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD] [DCO]
2024-07-25 03:52:06 library versions: OpenSSL 3.2.2 4 Jun 2024, LZO 2.10
2024-07-25 03:52:06 DCO version: N/A
2024-07-25 03:52:06 TCP/UDP: Preserving recently used remote address: [AF_INET]3.7.33.194:1194
2024-07-25 03:52:06 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-07-25 03:52:06 UDPv4 link local: (not bound)
2024-07-25 03:52:06 UDPv4 link remote: [AF_INET]3.7.33.194:1194

vast urchin
#

(in another terminal)

#

because i think those are just warning but you got connection

main sedge
main sedge
stoic orchid
#

thank you brother