#site-support

1 messages · Page 77 of 1

naive dust
#

Doesn't work

potent garnet
#

Okat so It's side wide error from their end

naive dust
#

Sometime, it work

#

Why......

potent garnet
#

Guess It's HackTheBox time then

naive dust
#

Yes. Lol

#

Let's HACKTHEBOX BRO

naive dust
#

Fix that bug Bro

naive dust
west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

naive dust
#

i try to connect tryhackme
kali said initalize completed
but browzer shows offline and dosnt show ip
how can i do

wind wedge
naive dust
#

yes

#

is it related to firewall thing?

#

sorry it said online but doesn't show virtual ip

weary spindle
wild warren
#

yo guys im trying to connect via openvpn
i downloaded the EU-VIP 2 files and when i try to connect i get stuck on this
any help pls

#

virtual machine ^

bronze vale
#

It’s supposed to hang, you need to keep that open :)

wild warren
#

ah i see i thought it should say successfully connected or something

#

i connected but on the website it says not? i did refresh nothing changed

bronze vale
#

Ignore the website^
You can check whether you are connected by trying to access 10.10.10.10 in your browser

wild warren
#

perfect

#

got it, thank you

cobalt nest
#

Hi just to say that your soluition works properly thks for help

prime spoke
#

Hi everyone,

I can't connect to the network of my room (lateral movement and pivoting) even after trying the vpn method on my own computer or the attackbox.

The vpn works but the interface state is UNKNOWN when I type "ip a"

The command to set the dns server and domain seems to not working.

Help me please 🙏

quaint oak
#

Hi there! I'm having issues purchasing a monthly subscription (I'm not sure what channel is best to report this) - I read online people have been having issues making payments using Mastercard, and I seem to be one of those individuals. The main issues being according to my bank THM is based out of London and they won't let my card go through. I was hoping maybe there was another way to pay as I've attempted to process with PayPal/Venmo as well and get the same issue when discussing it with PayPal or Venmo. The bank for my secondary card is off as it's Saturday and won't return until Tuesday of next week but wanted to see if there were any other ways to purchase the THM Premium Subscription. I'm from the US if that helps at all

upbeat quarry
prime spoke
#

It works now. I Left the room and enter again

fallen quiver
#

Hello. I'm having a billing issue. I recently switched from a monthly to an annual subscription. Now my account prompts me to "Go Premium"

inner hearth
#

i get this

upbeat quarry
mint current
#

hello i can't download my VPN configuration from the website

keen scroll
#

You can try switching b/w the servers, regenerating the configuration file followed by waiting for some time (a few minutes) and then download

wild warren
#

It worked for me

fallen garden
#

need help in Boogeyman 3, i connected via vpn and waited more than 15 mn but still the page doesn't work, i can ping the ip, nmap works too but nothing loads up it just says : Kibana server is not ready yet.
Ps : i tried another ip but same prob
Edit : guess third time relaunching the machine works xD

ivory spruce
wind wedge
ivory spruce
west chasmBOT
#

@fallen quiver

TryHackMe's Email

TryHackMe's support email address.

ivory spruce
fallen quiver
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #11 - 672)

ivory spruce
# fallen quiver Thanks. Sent one off.

Take note that THM Support may not be able to reply in a day or two (@wind wedge can confirm), but be patient as sending another email will put you at the back of the queue.

fallen quiver
quaint oak
fallen quiver
weary spindle
next bison
#

Thank you all for fixing the linux foundations 1 & and >> bugs. Feels good to be able to progress through the lesson ❤️

valid merlin
#

Hi can someone help me i am in room IAM Principals on IAM users Tab. i login to aws with cloud details data and i create aws credential profile. On gui i have this info everywher in iam "Access denied
You don't have permission to iam:ListUsers. To request access, copy the following text and send it to your AWS administrator. Learn more about troubleshooting access denied errors.
User: arn:aws:iam::711387107278:user/711387107278
Action: iam:ListUsers
On resource(s): arn:aws:iam::711387107278:user/
Context: no identity-based policy allows the action" and in aws cli "❯ aws iam list-users --profile thm

An error occurred (AccessDenied) when calling the ListUsers operation: User: arn:aws:iam::711387107278:user/711387107278 is not authorized to perform: iam:ListUsers on resource: arn:aws:iam::711387107278:user/ because no identity-based policy allows the iam:ListUsers action". Can someone help me

grand abyss
#

Hi please help me when I try to join room nothing changed

frigid willow
#

Reset the room or log out and in again

grand abyss
#

this not work for me

#

[Intercom] Launcher is disabled in settings or current page does not match display conditions
in console this error appear

foggy ivy
#

seeing tons of people ask abt it for months. yikes.

upbeat quarry
# grand abyss does not work

Breaching AD does work with the AtttackBox, but, because of an issue with the room, you have to download the VPN configuration for the Breaching Active Directory network to the AttackBox and run openvpn with that file to get an interface called breachad

upbeat quarry
foggy ivy
#

yeah no i did not

#

i did connect to openvpn from my kali vm

#

was surprised it didnt work from my host windows

#

openvpn i mean

#

well at least it works now

#

thanks guys

upbeat quarry
upbeat quarry
west chasmBOT
foggy ivy
#

yup, thanks

lethal bridge
#

My friends Learning page has a "Road Map" option, but mine doesn't?

lethal bridge
#

What do you mean?

analog spade
#

Hi, i have troubles today with the attacker machines, i have to termiate it redeploy again because it not reacting to anything, closing opening clicking into terminal or webbrowser, has someone similar issues today?

weary spindle
upbeat quarry
# analog spade Hi, i have troubles today with the attacker machines, i have to termiate it rede...

I have not experienced that myself
Hence, I can only offer some suggestions:

  • have you had the AttackBox running clean before? If yes, it is worth wondering if you have made any changes to your local setup (VPN, network connectivity, OS, browser, antivirus, etc.)
  • the other area worth considering is to disable all extensions in your browser, or switch to another browser (without extensions) altogether
analog spade
#

Hi Shy1, yes started clean machine, i didn't changed anything in browser, it worked with my extensions previously

upbeat quarry
analog spade
#

it seems to work now for a while, sinde two crashes, it works again propertly

#

thanks

analog spade
#

yes

red wyvern
#

can i share a premuim account features to my tryhackme friends?

keen scroll
#

how so?

red wyvern
keen scroll
#

There are referrals, that you can use

#

That's not sharing the features but gives you and your friend (new to TryHackMe) joining the premium a bit of credits.

red wyvern
upbeat quarry
red wyvern
#

will look forward to that

upbeat quarry
#

iirc you could not take advantage of these deals while you had a subscription already running, so you had to time the end of your current subscription in order to start a new one with the promo deal

upbeat quarry
#

I cannot help you with that issue, but look at this message: it may get the troubleshooting starting:
#site-support message

sweet wren
#

A generell question how long does it usally take for a response on the thm website email support ?

wind wedge
polar pecan
#

Hey guys. I'm trying to solve "Fowsniff CTF" room, but I can't ping the machine from my own kali machine!
I'm in the THM network, and even tried to start attack box and ping it's IP and I could do that. But still can't ping this specific machine, tried to restart everything but no use. Any suggestions?

weary spindle
polar pecan
gleaming flume
#

Not all machines respond to pings

weary spindle
polar pecan
lament flame
#

Is there a reason THM is telling me the Captcha request has failed when I try to log in? I didn't even see one. I've tried using an incognito browser, changing my IP address, restarting the modem, what's going on?

polar pecan
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2716)

weary spindle
polar pecan
winter tinsel
#

I'm new the the site and I'm having some issues with target pages loading within the Jr Penetration Tester Path > Introduction to Web Hacking Course > Content Discovery and Authentication Bypass rooms. The Acme target site doesn't allow me to connect to it and I can't proceed with the lessons. Is there something in particular I should be doing to connect? I'm on Chrome.

upbeat quarry
winter tinsel
scenic torrentBOT
#

Gave +1 Rep to @upbeat quarry (current: #78 - 87)

green crystal
#

I am creating new ctf (planing yo make it hard difficultly) any tips?

#

If u have any guidelines that will make it easier to deploy then please inform me about them.

restive gate
#

Hey all anyone that assist me on getting my THM 2fa reset for one reason or the other the app that I setup for THM has removed the account how can I get it reset and setup a new app, I do have the backup codes so I can still login but when I try to remove the 2 fa it ask me for the code from the app

eager forum
#

HELLO
I CANT RESUME MY Subscription
it says that Subscription paused when i try to resume it doesnt show anything
when i click suscribe now it dosnt show me any payment option

#

@scenic torrent

#

@weary spindle

#

anyone?

weary spindle
west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

eager forum
#

should i messege the same

weary spindle
#

Yes.

gaunt rivet
#

Hi Team,
I am facing high ping when I am connected to thm. When I ping 8.8.8.8, its normal. But not the target machine. Kindly please advise what should I do next

Steps done

  1. I have tried different VPN files from different region.
  2. I have regenerated the files but issues persists
  3. sudo ip link set dev tun0 mtu 1200
┌──(root㉿kali)-[/opt]
└─# sudo ip link set dev tun0 mtu 1200
                                                                    
┌──(root㉿kali)-[/opt]
└─# ping 10.10.192.234                
PING 10.10.192.234 (10.10.192.234) 56(84) bytes of data.
64 bytes from 10.10.192.234: icmp_seq=1 ttl=127 time=252 ms
64 bytes from 10.10.192.234: icmp_seq=2 ttl=127 time=281 ms
64 bytes from 10.10.192.234: icmp_seq=3 ttl=127 time=307 ms
64 bytes from 10.10.192.234: icmp_seq=4 ttl=127 time=320 ms
64 bytes from 10.10.192.234: icmp_seq=5 ttl=127 time=239 ms
64 bytes from 10.10.192.234: icmp_seq=6 ttl=127 time=263 ms
^C
--- 10.10.192.234 ping statistics ---
24 packets transmitted, 24 received, 0% packet loss, time 23047ms
rtt min/avg/max/mdev = 221.771/291.900/453.665/57.778 ms
naive dust
#

Also make sure your adapter is on NAT, as that usally works the best

gaunt rivet
#

its on NAT

keen scroll
#

Is the target a Windows box by any chance?

gaunt rivet
keen scroll
#

Usually, Windows machines don't respond to ping (by default)

naive dust
#

xd

gaunt rivet
keen scroll
keen scroll
gaunt rivet
#

target ip

keen scroll
#

Isn't it working?
The time for 8.8.8.8 is lesser because they (Google) have multiple datacenters around the world and the one you are reaching out to is most probably closer than where the THM VPN is running. That's why it's longer for the target machine. One of the main reasons here

#

The best you can do is use the Attackbox, it's part of the network and would be much closer giving shorter ping time and probably a faster scan too
Or select the geographically closer server from Access on THM site

#

Sorry, but I can't figure out your problem 😅

keen scroll
#

What could be the reasons here that we can manually fix?

naive dust
#

But I don't have much ideas neither

keen scroll
#

Fair enough, me got no ideas either 🥲

naive dust
#

But like you said, indeed pick the closest VPN location possible. @gaunt rivet where are you located?

gaunt rivet
#
fedora:~$ ping 10.10.192.234                      16:10:37 [6/6]
PING 10.10.192.234 (10.10.192.234) 56(84) bytes of data.   
64 bytes from 10.10.192.234: icmp_seq=1 ttl=127 time=211 ms
64 bytes from 10.10.192.234: icmp_seq=2 ttl=127 time=194 ms
64 bytes from 10.10.192.234: icmp_seq=3 ttl=127 time=197 ms
64 bytes from 10.10.192.234: icmp_seq=4 ttl=127 time=184 ms 
64 bytes from 10.10.192.234: icmp_seq=5 ttl=127 time=187 ms 
64 bytes from 10.10.192.234: icmp_seq=6 ttl=127 time=188 ms 

Host machine

upbeat quarry
gaunt rivet
#
fedora:~$ ping 10.10.10.10
PING 10.10.10.10 (10.10.10.10) 56(84) bytes of data.
64 bytes from 10.10.10.10: icmp_seq=1 ttl=63 time=186 ms
64 bytes from 10.10.10.10: icmp_seq=2 ttl=63 time=199 ms
64 bytes from 10.10.10.10: icmp_seq=3 ttl=63 time=202 ms
64 bytes from 10.10.10.10: icmp_seq=4 ttl=63 time=203 ms
#
 traceroute 10.10.192.234
traceroute to 10.10.192.234 (10.10.192.234), 30 hops max, 60 byte packets
 1  10.9.0.1 (10.9.0.1)  180.146 ms  192.801 ms  192.761 ms
 2  10.10.192.234 (10.10.192.234)  193.536 ms  193.484 ms  193.081 ms

naive dust
#

So indeed the connection to the VPN.

#

Are you on WiFi or on ethernet?

gaunt rivet
#

wifi

naive dust
#

Mmm. Do you have the resources to try ethernet?

gaunt rivet
#

not atm, but working on it

naive dust
#

Mmm okay

#

And which VPN server are you on, right now?

gaunt rivet
#

at office, they have some blocking atm. the IT team working on it. I could try once they have settled it

#

for ethernet connection

#

EU-Regular-2

naive dust
#

Could try an Australia one?

gaunt rivet
#

aust one even worse xD lemme send you the ss

naive dust
#

And are you on a work device / in your works network?

gaunt rivet
#

personal laptop but using work internet

#

dont have any restrictions on my laptop

naive dust
#

Mmm, could be a firewall inspecting VPN traffic maybe?

#

Do you have cellular connection to test on?

gaunt rivet
#

i did also, issue persists. Lemme try on the host machien

#

for aust

traceroute 10.10.192.234
traceroute to 10.10.192.234 (10.10.192.234), 30 hops max, 60 byte packets
 1  10.4.0.1 (10.4.0.1)  112.644 ms  112.671 ms  112.695 ms
 2  * * *
 3  * * *
 4  10.10.192.234 (10.10.192.234)  369.264 ms  369.314 ms  368.303 ms
upbeat quarry
keen scroll
#

Obviously

#

Really Shy1?

gaunt rivet
#

To verify the issue

upbeat quarry
naive dust
gaunt rivet
#

Ping and vpn both on host machine

keen scroll
#

BTW, Shy1 and Deditio. How much are you getting? ATM, I cannot check

naive dust
#

But if it was that slow for everyone, I can assure you, there would be more people here

upbeat quarry
stoic jay
#

Hi everyone

gaunt rivet
#

Where are you from?

upbeat quarry
gaunt rivet
#

Could you please try aus vpn just to see the frequency

upbeat quarry
gaunt rivet
#

I tried with kali vm which is on another host machine(windows). Issue persists

upbeat quarry
gaunt rivet
#

Ive been facing this issue since yesterday

#

It's the same

naive dust
#

And before yesterday? It was normal?

naive dust
gaunt rivet
naive dust
#

Ohh okay

upbeat quarry
gaunt rivet
#

Just now, i tried with htb vpn. Tried with both eu and us vpn. Issue persists

gaunt rivet
naive dust
#

Is your openvpn up-to-date?

gaunt rivet
#

I think since htb vpn aso causing same issue. Can i rectify that the vpns is not the issue?

gaunt rivet
naive dust
naive dust
gaunt rivet
#

I'm reinstalling kali. Will update once done

naive dust
#

👍

#

Not sure if that makes any difference as it is the same on your host...

weary spindle
gaunt rivet
#

I don't understand your question
From my kali vm to thm vpn?

restive gate
#

anyone?
Hey all anyone that assist me on getting my THM 2fa reset for one reason or the other the app that I setup for THM has removed the account how can I get it reset and setup a new app, I do have the backup codes so I can still login but when I try to remove the 2 fa it ask me for the code from the app

gaunt rivet
weary spindle
gaunt rivet
#

Work wifi
Mobile hotspot

weary spindle
#

Ok, two reason why it might not work.

#

Wifi-hotspot won't be strong/good enough.

#

Work network will probably be blocking port 1194, which the VPN uses.

naive dust
weary spindle
#

Hotspot will be latency

naive dust
gaunt rivet
modern musk
#

Hi,

I'm facing an issue on Active Directory basics lab.

modern musk
#

The vm is showing this message: "The remote desktop server has forcibly closed the connection. If this is undesired or unexpected, please notify your system administrator, or check your system logs."

upbeat quarry
west chasmBOT
naive dust
#

Task 4 for NMAP POST PORT SCANS

#

The answer doesnt work

#

and the port it asks you to scan on the VM is closed

#

all the answers on the internet dont work

upbeat quarry
weary spindle
errant vale
#

I have some problem on openvpn connect, and I need some help

#

2024-09-02 22:43:49 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-09-02 22:43:49 Note: cipher 'AES-256-CBC' in --data-ciphers is not supported by ovpn-dco, disabling data channel offload.
2024-09-02 22:43:49 OpenVPN 2.6.12 [git:makepkg/038a94bae57a446c+] x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO] built on Jul 18 2024
2024-09-02 22:43:49 library versions: OpenSSL 3.3.1 4 Jun 2024, LZO 2.10
2024-09-02 22:43:49 DCO version: N/A
2024-09-02 22:43:49 TCP/UDP: Preserving recently used remote address: [AF_INET]..96:94
2024-09-02 22:43:49 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-09-02 22:43:49 UDPv4 link local: (not bound)
2024-09-02 22:43:49 UDPv4 link remote: [AF_INET]
...96:*94
2024-09-02 22:44:49 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2024-09-02 22:44:49 TLS Error: TLS handshake failed
2024-09-02 22:44:49 SIGUSR1[soft,tls-error] received, process restarting
2024-09-02 22:44:49 Restart pause, 1 second(s)

#

someone can give me suggestion?

weary spindle
errant vale
#

manjaro

weary spindle
#

And which server are you using?

errant vale
#

I tried EU-VIP-1 and US-WEST-VIP-1

weary spindle
#

Which country are you in/

I'm on VIP-1 now.

errant vale
#

China, It's GFW worked?

#

when stop clash,i can't access google/discord etc

weary spindle
#

You'll need to use the attackbox.

errant vale
#

I got it.Thanks bro

pearl gulch
#

Not sure if right channel for this, lmk and I'll repost elsewhere if appropriate.

some tricky / annoying questions about discord verification:

will my employer be able to see that I'm here? (it's their subscription)
inversely, will THM backend be able to track my discord activity and tie it to my THM ID
if yes to either of the above, is there an alternative verification method that avoids these

Just privacy concerns really

weary spindle
#

Even if your employer was to join the server.

They won't know who is who unless you tell them.

Or do something stupid like post a screenshot with your pfp.

west chasmBOT
bronze vale
#

The bot is completely public, you can see everything for yourself^

proud echo
#

Thank you

gaunt rivet
# weary spindle Yeah.

Just tried with home wifi

┌──(kali㉿kali)-[~/Downloads]
└─$ ping 10.10.153.160 -c 4
PING 10.10.153.160 (10.10.153.160) 56(84) bytes of data.
64 bytes from 10.10.153.160: icmp_seq=1 ttl=127 time=182 ms
64 bytes from 10.10.153.160: icmp_seq=2 ttl=127 time=183 ms
64 bytes from 10.10.153.160: icmp_seq=3 ttl=127 time=182 ms
64 bytes from 10.10.153.160: icmp_seq=4 ttl=127 time=177 ms

--- 10.10.153.160 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3005ms
rtt min/avg/max/mdev = 177.394/180.834/182.713/2.036 ms
                                                                                                                            
┌──(kali㉿kali)-[~/Downloads]
└─$ ping 10.10.10.10 -c 4  
PING 10.10.10.10 (10.10.10.10) 56(84) bytes of data.
64 bytes from 10.10.10.10: icmp_seq=1 ttl=63 time=180 ms
64 bytes from 10.10.10.10: icmp_seq=2 ttl=63 time=180 ms
64 bytes from 10.10.10.10: icmp_seq=3 ttl=63 time=180 ms
64 bytes from 10.10.10.10: icmp_seq=4 ttl=63 time=180 ms

--- 10.10.10.10 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3004ms
rtt min/avg/max/mdev = 179.593/179.902/180.182/0.228 ms
                                                                                                                            
┌──(kali㉿kali)-[~/Downloads]
└─$ traceroute 10.10.10.10 
traceroute to 10.10.10.10 (10.10.10.10), 30 hops max, 60 byte packets
 1  10.23.0.1 (10.23.0.1)  188.643 ms  188.709 ms  188.843 ms
 2  10.10.10.10 (10.10.10.10)  188.883 ms  188.919 ms  188.950 ms
                                                                                                                            
┌──(kali㉿kali)-[~/Downloads]
└─$ traceroute 10.10.153.160
traceroute to 10.10.153.160 (10.10.153.160), 30 hops max, 60 byte packets
 1  10.23.0.1 (10.23.0.1)  180.368 ms  183.751 ms  183.861 ms
 2  * 10.10.153.160 (10.10.153.160)  183.819 ms *
#

also i tried nmap -p- -T5 --host-timeout 30m 10.10.73.91

proud echo
#

I have followed the link to get my discord token but it’s not straight forward on the website . How do I get my discord token? So I can verify as I can’t send messages

chilly sundial
fallen quiver
scenic torrentBOT
#

Gave +1 Rep to @ivory spruce (current: #11 - 675)

digital gate
#

Hello, does anyone know why I keep getting Upload ID is required when I'm trying to start a machine? I've tried the following:

  • Re-logging
  • Rejoining the room
  • Clearing browser cache
    None of the above seems to help.
proud echo
#

Please how do I solve this problem? I m stuck here

weary spindle
upbeat quarry
upbeat quarry
gleaming moon
#

Hello !!

I'm experiencing issues connecting to the OpenVPN service from Switzerland. Here are the details:

Environment:

  • OS: Darwin 14.6.1
  • Architecture: arm64
  • OpenVPN Version: 2.6.12
  • Kernel Version: 23.6.0
  • Configuration: Tried EU-REGULAR 1-4 and EU-VIP 1-2

Steps taken:

  1. Downloaded OpenVPN for ARM architecture
  2. Imported configuration files
  3. Attempted connection via GUI and CLI

Both method timeout. I've attached part of the logs from the CLI and GUI attempts.

Questions:

  1. Could my location (Switzerland) be causing this issue?
  2. I see warnings about compression, cipher and unsupported / unused options. These warnings are across all .ovpn files. Any idea why ?
  3. Are there any additional troubleshooting steps I should try ?

Thank you for your help!

2024-09-02 19:11:05 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-09-02 19:11:05 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-09-02 19:11:05 OpenVPN 2.6.12 aarch64-apple-darwin23.4.0 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD]
...
2024-09-02 19:12:05 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2024-09-02 19:12:05 TLS Error: TLS handshake failed
⏎[Sep 2, 2024, 18:47:43] NOTE: This configuration contains options that were not used:
⏎[Sep 2, 2024, 18:47:43] Unsupported option (ignored)
⏎[Sep 2, 2024, 18:47:43] 0 [resolv-retry] [infinite]
⏎[Sep 2, 2024, 18:47:43] 1 [persist-key]
⏎[Sep 2, 2024, 18:47:43] 2 [persist-tun]
⏎[Sep 2, 2024, 18:47:43] 3 [data-ciphers] [AES-256-CBC]
...
⏎[Sep 2, 2024, 18:47:53] Server poll timeout, trying next remote entry...
delicate oar
#

any suggestion on fixing this error while connecting using openvpn ?
tryhackme@<ip>: Permission denied (publickey).

#

do i need to add my public key to the THM VM

gleaming flume
#

What room is this that you trying to connect to?

gleaming flume
#

Doesn't seem like you SSH into that room at all - what are you trying to do?

delicate oar
#

I've connected with the openvpn perfectly fine
then i am trying to ssh into the Target Machine and i face this error

gleaming flume
#

I understand that but you don't need to SSH into the victim machine to complete that room

delicate oar
#

it is very slow on the browser i want to test it out on the terminal

gleaming flume
#

Did you follow the steps outlined in the task?

#

Ah well that's not how this room works - not every room allows or requires SSH access

delicate oar
#

it does give me an IP so i can ssh into it

gleaming flume
#

You could probably still do the room from your own VM - you just run the tools like gobuster and the like from your VM against the victim

#

Though that room does have its own wordlist it seems, so you may want to just do it via browser

delicate oar
#

what I think is that is something related to keys

debug2: pubkey_prepare: done
debug1: Offering public key: /home/mohrazzak/.ssh/id_rsa RSA SHA256:<rest of key> agent
debug3: send packet: type 50
debug2: we sent a publickey packet, wait for reply
debug3: receive packet: type 51
debug1: Authentications that can continue: publickey
debug1: Trying private key: /home/mohrazzak/.ssh/id_ecdsa
debug3: no such identity: /home/mohrazzak/.ssh/id_ecdsa: No such file or directory
debug1: Trying private key: /home/mohrazzak/.ssh/id_ecdsa_sk
debug3: no such identity: /home/mohrazzak/.ssh/id_ecdsa_sk: No such file or directory
debug1: Trying private key: /home/mohrazzak/.ssh/id_ed25519
debug3: no such identity: /home/mohrazzak/.ssh/id_ed25519: No such file or directory
debug1: Trying private key: /home/mohrazzak/.ssh/id_ed25519_sk
debug3: no such identity: /home/mohrazzak/.ssh/id_ed25519_sk: No such file or directory
debug1: Trying private key: /home/mohrazzak/.ssh/id_xmss
debug3: no such identity: /home/mohrazzak/.ssh/id_xmss: No such file or directory
debug1: Trying private key: /home/mohrazzak/.ssh/id_dsa
debug3: no such identity: /home/mohrazzak/.ssh/id_dsa: No such file or directory
debug2: we did not send a packet, disable method
debug1: No more authentication methods to try.
tryhackme@<ip> Permission denied (publickey).
gleaming flume
#

Yes permission is denied because you do not, nor are you supposed to, have SSH access

delicate oar
#

I will never be able to ?
or its just some type of vms on THM

gleaming flume
#

Most THM rooms can be completed from your own VM, how you access the room's VM is not always through SSH though

digital gate
scenic torrentBOT
#

Gave +1 Rep to @upbeat quarry (current: #74 - 93)

scenic torrentBOT
#

Gave +1 Rep to @gleaming flume (current: #45 - 171)

digital gate
delicate oar
#

Hey!,
As for the password on ssh into an attack box
What is it ?

upbeat quarry
digital gate
scenic torrentBOT
#

Gave +1 Rep to @upbeat quarry (current: #74 - 94)

upbeat quarry
# gleaming moon Hello !! I'm experiencing issues connecting to the OpenVPN service from Switzer...
  1. I do not think that Switzerland is an issue for the VPN
  2. I have some warnings myself , but not the Unsupported optionsYou can compare your openvpn output to mine in the attached file
  3. additional ideas:
  • can you use your setup with openvpn for another VPN
  • can you confirm port 1194 is not blocked at your end
  • can you use THM VPN with another computer/VM?
  • are you on a wired connection to the internet (not wifi/cellular/satellite)
little shoal
#

hi could I please update my discord token? :)

gaunt rivet
scenic torrentBOT
#

Gave +1 Rep to @upbeat quarry (current: #73 - 96)

ivory spruce
eager forum
#

guys still no solution to my suscription

#

ive contacted the sipport team still no response

#

I CANT RESUME MY Subscription
it says that Subscription paused when i try to resume it doesnt show anything
when i click suscribe now it dosnt show me any payment option

gleaming flume
#

If you've contacted support then just wait for their response, payment issues aren't handled over discord

eager forum
#

i did not pay anyhting yet

#

i want to pay

#

but they are not letting me pay ....lol

gleaming flume
#

Hmm, email support is still probably the best place

ivory spruce
eager forum
#

its been more tha a day

#

i didnt raise ticket

#

just mailed them

ivory spruce
#

Yeah.. the standard response time is ~1 to 3 days and they don't work on weekends.

eager forum
#

ticket asks me about payment date....

#

ohh

#

my streak will go then?

ivory spruce
ivory spruce
eager forum
#

can you share the mail please

west chasmBOT
#

@eager forum

TryHackMe's Email

TryHackMe's support email address.

eager forum
#

thanks

upbeat quarry
#

@bronze vale
Checking if THM is OK with this

bronze vale
scenic torrentBOT
#

Gave +1 Rep to @upbeat quarry (current: #73 - 97)

deft quiver
#

Hello every one. I have a trouble to use thm openvpn for connecting to attacked machine. After success connection via openvpn to thm, I check my vpn connection by ping 10.10.10.10 but got only for 5-6 first packets, other next packets will be lost (((
I check all article about issues with vpn but could not finde answer what is going wrong
and why my vpn do not work prorerly

slate locust
#

Just going through Active Directory Basics, and on Task 4 where you have to use the machine to log onto different users to change passwords using RDP. Its just not working? Anyone have a fix for it?

upbeat quarry
slate locust
weary spindle
#

Log out then log in with phillip, or switch user

slate locust
#

I tried that, logging out disconnects the machine :/

#

Idk if im going crazy or not

weary spindle
#

I'll check.

slate locust
#

Coolio. Thanks

weary spindle
#

GIF incoming.

#

As you can see from my GIF, I was able to log in to Administrator, log out, then log back in as phillip.

deft quiver
#

what is wrong with vpn?

weary spindle
slate locust
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2723)

deft quiver
#

ping 10.10.10.10
PING 10.10.10.10 (10.10.10.10) 56(84) bytes of data.
64 bytes from 10.10.10.10: icmp_seq=1 ttl=63 time=65.3 ms
64 bytes from 10.10.10.10: icmp_seq=88 ttl=63 time=68.8 ms
64 bytes from 10.10.10.10: icmp_seq=89 ttl=63 time=65.8 ms
64 bytes from 10.10.10.10: icmp_seq=90 ttl=63 time=71.7 ms
64 bytes from 10.10.10.10: icmp_seq=91 ttl=63 time=66.0 ms
64 bytes from 10.10.10.10: icmp_seq=92 ttl=63 time=68.5 ms
64 bytes from 10.10.10.10: icmp_seq=120 ttl=63 time=56.7 ms
64 bytes from 10.10.10.10: icmp_seq=121 ttl=63 time=57.2 ms
64 bytes from 10.10.10.10: icmp_seq=122 ttl=63 time=57.2 ms
64 bytes from 10.10.10.10: icmp_seq=149 ttl=63 time=80.8 ms
64 bytes from 10.10.10.10: icmp_seq=150 ttl=63 time=60.9 ms
64 bytes from 10.10.10.10: icmp_seq=151 ttl=63 time=57.5 ms
64 bytes from 10.10.10.10: icmp_seq=169 ttl=63 time=65.7 ms
64 bytes from 10.10.10.10: icmp_seq=170 ttl=63 time=72.5 ms
64 bytes from 10.10.10.10: icmp_seq=242 ttl=63 time=125 ms
64 bytes from 10.10.10.10: icmp_seq=243 ttl=63 time=67.6 ms
64 bytes from 10.10.10.10: icmp_seq=244 ttl=63 time=65.1 ms
64 bytes from 10.10.10.10: icmp_seq=245 ttl=63 time=64.6 ms
64 bytes from 10.10.10.10: icmp_seq=246 ttl=63 time=226 ms
64 bytes from 10.10.10.10: icmp_seq=247 ttl=63 time=353 ms
64 bytes from 10.10.10.10: icmp_seq=248 ttl=63 time=68.1 ms
^C
--- 10.10.10.10 ping statistics ---
321 packets transmitted, 21 received, 93.4579% packet loss, time 859158ms
rtt min/avg/max/mdev = 56.663/89.688/352.816/69.050 ms

weary spindle
#

There's an issue on your network.

#

Check the output of your VPN and see if it's either;
a) restarting
b) Network is unreachable.

deft quiver
#

but for others hosts like google ping is well

#

no lost packets

#

only for 10.10.10.10

weary spindle
#

If it was the VPN, there would be a high increase of users reporting.

However as you're not giving the information I've requested twice, it will be almost impossible to help diagnose the issue.

deft quiver
oblique nexus
#

Hi,

I can't post a writeup from my medium blog since it's telling me "invalid url" . What's wrong ? :

weary spindle
slate locust
#

Thanks for the help @weary spindle! Got it in the end.

scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2724)

deft quiver
#

PING 10.10.33.98 (10.10.33.98): 56 data bytes
64 bytes from 10.10.33.98: icmp_seq=0 ttl=61 time=554.874 ms
64 bytes from 10.10.33.98: icmp_seq=1 ttl=61 time=577.415 ms
64 bytes from 10.10.33.98: icmp_seq=2 ttl=61 time=598.215 ms
64 bytes from 10.10.33.98: icmp_seq=3 ttl=61 time=527.253 ms
Request timeout for icmp_seq 4
Request timeout for icmp_seq 5
Request timeout for icmp_seq 6
Request timeout for icmp_seq 7
Request timeout for icmp_seq 8
Request timeout for icmp_seq 9
Request timeout for icmp_seq 10

#

only 4 ping request completed

weary spindle
deft quiver
#

sudo openvpn ~/Downloads/a500.ovpn
[sudo] password for kali:
2024-09-03 09:12:18 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-09-03 09:12:18 Note: cipher 'AES-256-CBC' in --data-ciphers is not supported by ovpn-dco, disabling data channel offload.
2024-09-03 09:12:18 OpenVPN 2.6.12 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-09-03 09:12:18 library versions: OpenSSL 3.2.2 4 Jun 2024, LZO 2.10
2024-09-03 09:12:18 DCO version: N/A
2024-09-03 09:12:18 TCP/UDP: Preserving recently used remote address: [AF_INET]54.76.30.11:1194
2024-09-03 09:12:18 Socket Buffers: R=[212992->425984] S=[212992->425984]
2024-09-03 09:12:18 UDPv4 link local: (not bound)
2024-09-03 09:12:18 UDPv4 link remote: [AF_INET]54.76.30.11:1194
2024-09-03 09:12:18 TLS: Initial packet from [AF_INET]54.76.30.11:1194, sid=0ceb6d34 0c53a0f9
2024-09-03 09:12:18 VERIFY OK: depth=1, CN=ChangeMe
2024-09-03 09:12:18 VERIFY KU OK
2024-09-03 09:12:18 Validating certificate extended key usage
2024-09-03 09:12:18 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2024-09-03 09:12:18 VERIFY EKU OK
2024-09-03 09:12:18 VERIFY OK: depth=0, CN=server
2024-09-03 09:12:19 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bits RSA, signature: RSA-SHA256, peer temporary key: 253 bits X25519

#

2024-09-03 09:12:19 [server] Peer Connection Initiated with [AF_INET]54.76.30.11:1194
2024-09-03 09:12:19 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
2024-09-03 09:12:19 TLS: tls_multi_process: initial untrusted session promoted to trusted
2024-09-03 09:12:20 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
2024-09-03 09:12:20 PUSH: Received control message: 'PUSH_REPLY,route 10.10.0.0 255.255.0.0,route-metric 1000,comp-lzo no,route-gateway 10.9.0.1,topology subnet,ping 5,ping-restart 120,ifconfig 10.9.1.202 255.255.0.0,peer-id 135'
2024-09-03 09:12:20 OPTIONS IMPORT: --ifconfig/up options modified
2024-09-03 09:12:20 OPTIONS IMPORT: route options modified
2024-09-03 09:12:20 OPTIONS IMPORT: route-related options modified
2024-09-03 09:12:20 Using peer cipher 'AES-256-CBC'
2024-09-03 09:12:20 net_route_v4_best_gw query: dst 0.0.0.0
2024-09-03 09:12:20 net_route_v4_best_gw result: via 192.168.88.1 dev eth0
2024-09-03 09:12:20 ROUTE_GATEWAY 192.168.88.1/255.255.255.0 IFACE=eth0 HWADDR=08:00:27:21:b1:d0
2024-09-03 09:12:20 TUN/TAP device tun0 opened
2024-09-03 09:12:20 net_iface_mtu_set: mtu 1470 for tun0
2024-09-03 09:12:20 net_iface_up: set tun0 up
2024-09-03 09:12:20 net_addr_v4_add: 10.9.1.202/16 dev tun0
2024-09-03 09:12:20 net_route_v4_add: 10.10.0.0/16 via 10.9.0.1 dev [NULL] table 0 metric 1000
2024-09-03 09:12:20 Initialization Sequence Completed
2024-09-03 09:12:20 Data Channel: cipher 'AES-256-CBC', auth 'SHA512', peer-id: 135, compression: 'stub'
2024-09-03 09:12:20 Timers: ping 5, ping-restart 120
2024-09-03 09:12:20 Protocol options: explicit-exit-notify 3

weary spindle
#

and does it stop there?

deft quiver
#

2024-09-03 09:14:53 [server] Inactivity timeout (--ping-restart), restarting
2024-09-03 09:14:53 SIGUSR1[soft,ping-restart] received, process restarting
2024-09-03 09:14:53 Restart pause, 1 second(s)
2024-09-03 09:14:54 TCP/UDP: Preserving recently used remote address: [AF_INET]54.76.30.11:1194
2024-09-03 09:14:54 Socket Buffers: R=[212992->425984] S=[212992->425984]
2024-09-03 09:14:54 UDPv4 link local: (not bound)
2024-09-03 09:14:54 UDPv4 link remote: [AF_INET]54.76.30.11:1194
2024-09-03 09:14:54 TLS: Initial packet from [AF_INET]54.76.30.11:1194, sid=c2ccc16f e493b8b4
2024-09-03 09:14:54 VERIFY OK: depth=1, CN=ChangeMe
2024-09-03 09:14:54 VERIFY KU OK
2024-09-03 09:14:54 Validating certificate extended key usage
2024-09-03 09:14:54 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2024-09-03 09:14:54 VERIFY EKU OK
2024-09-03 09:14:54 VERIFY OK: depth=0, CN=server
2024-09-03 09:14:54 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bits RSA, signature: RSA-SHA256, peer temporary key: 253 bits X25519

#

2024-09-03 09:14:54 [server] Peer Connection Initiated with [AF_INET]54.76.30.11:1194
2024-09-03 09:14:54 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
2024-09-03 09:14:54 TLS: tls_multi_process: initial untrusted session promoted to trusted
2024-09-03 09:14:55 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
2024-09-03 09:14:55 PUSH: Received control message: 'PUSH_REPLY,route 10.10.0.0 255.255.0.0,route-metric 1000,comp-lzo no,route-gateway 10.9.0.1,topology subnet,ping 5,ping-restart 120,ifconfig 10.9.1.202 255.255.0.0,peer-id 189'
2024-09-03 09:14:55 OPTIONS IMPORT: --ifconfig/up options modified
2024-09-03 09:14:55 OPTIONS IMPORT: route options modified
2024-09-03 09:14:55 OPTIONS IMPORT: route-related options modified
2024-09-03 09:14:55 Using peer cipher 'AES-256-CBC'
2024-09-03 09:14:55 Preserving previous TUN/TAP instance: tun0
2024-09-03 09:14:55 Initialization Sequence Completed
2024-09-03 09:14:55 Data Channel: cipher 'AES-256-CBC', auth 'SHA512', peer-id: 189, compression: 'stub'
2024-09-03 09:14:55 Timers: ping 5, ping-restart 120
2024-09-03 09:14:55 Protocol options: explicit-exit-notify 3

#

that is the end of output for vpn

weary spindle
#

2024-09-03 09:14:53 [server] Inactivity timeout (--ping-restart), restarting

Something is happening in your network.

deft quiver
#

what it could be in my network?

lucid pebble
#

Hi, I'm facing the same issue with my connection to the VPN, I tried several things :

  • Getting another config file : KO
  • Reboot my vm : KO
  • pinging 10.10.10.10 : OK but I can't ping the target machine
  • VPN messages seem ok
deft quiver
#

I have tried different wifi network and even LTE connetion via IPhone, result is the same... Only 4-5 ping packets pass via vpn

weary spindle
lucid pebble
#

10.10.77.252

weary spindle
lucid pebble
weary spindle
lucid pebble
weary spindle
lucid pebble
#

yep

weary spindle
#

Oh it's Windcorps.

lucid pebble
#

yes

weary spindle
#

Yeah, there is a reason you can't ping it.

lucid pebble
#

the SMB connection didn't work too, let me try again

weary spindle
#

The machine is behaving as expected.

lucid pebble
weary spindle
lucid pebble
#

I know for the ping, I mean for the SMB attempt, it is supposed to work 🙂

coral bluff
weary spindle
coral bluff
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2726)

long oxide
#

I completed the Jr Penetration Tester learning path and I'm wondering after how long I should receive the Certificate of Completion

weary spindle
long oxide
#

I didn't see that

weary spindle
#

😄 That's ok.

I was only asking in case there was another reason why it wouldn't work.

long oxide
#

ok, I had to "enroll" again in the learning path and I see the button to fetch the certificate now, thank you

bitter thicket
#

Sry for disturbing but could i have some suggestion because my tryhackme is not connecting to my kali, even after getting IP from openvpn. Pls help

weary spindle
#

If you have an IP assigned, what are you having an issue with?

bitter thicket
#

when i try to refresh on the site it still shows no connection

weary spindle
#

That page is broken.

#

Just ignore it.

bitter thicket
#

but the machine is not connecting due to that

weary spindle
#

That won't be the reason.

#

Which machine are you connecting to?

bitter thicket
#

thanks it seems its working for now....i tried for 3hrs....thanks for responding

frail adder
#

E1 and Cloudflare are not the answers "Who is TryHackMe's HTTPS certificate issued by?" Can you please tell me what is it?

wind wedge
frail adder
#

thanks thanks but how can i find it

wind wedge
#

You won't be able to. It no longer appears

#

The room is under maintenace due to this one answer

frail adder
wicked elbow
#

hello. I can't seem to ping my running machines/ rooms since they have 10.x.x.x , meanwhile the openvpn provides me a 10.x.x.x ip. Does anyone have a solution?

#

Thanks

weary spindle
wicked elbow
#

Fowsniff CTF

weary spindle
#

Fowsniff doesn't react to pings.

wicked elbow
#

even scans?

#

meaning I cannot play the box using physical machines

#

but i can play it using attack box? since it is pingable using attack box

weary spindle
#

ARP takes over due to being on the same network.

wicked elbow
#

for context fownsniff has 10.10.x.x ip while my machine is 10.8.x.x

weary spindle
#

That's intended, all VPN's are different.

wicked elbow
#

I see, can you recommend some boxes that I can ping over the network just to test if the problem is not the openvpn connection that I have thanks.

weary spindle
#

Are you a subscriber?

wicked elbow
#

yes

weary spindle
#

Linux Fundemental 2 and 3 (not one)

#

Linux hardening.

wicked elbow
#

I will try those boxes thank you

weary spindle
#

Papercut is a Windows box btw, that's why you can't ping it without ARP.

wicked elbow
#

Is there a solution that I can do to be able to access those boxes thru my physical machine

wicked elbow
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2732)

weary spindle
wicked elbow
wicked elbow
weary spindle
wicked elbow
weary spindle
wicked elbow
weary spindle
#

No Ping != Online

wicked elbow
#

Oh yeahhhhh! I just remembered that what ping does is to send those icmp packets and received but if those packets are blocked means no ping but not necessarilly not online

weary spindle
#

"safety" feature for Windows.

tight hound
dull lichen
#

any idea why I nor my friend can't add each other to friends on thm? says "friend request already sent" but no one had received anything

misty kelp
#

Having some trouble accessing URL: https://LAB_WEB_URL.p.thmlabs.com for the "Jr Penetration Tester>Introduction to Web Hacking> Walking An Application. I keep getting routed to an error page.

ivory spruce
misty kelp
ivory spruce
west chasmBOT
hexed galleon
#

hello, i have to find the https cert issuer and i cannot. it is a two letter/number answer. I am having a hard time finding it

gleaming flume
#

The room needs to be updated

hexed galleon
#

thanks

#

how can i get the download file ontop the attack box?

#

I have to get an rsa file and put it through john the ripper

gleaming flume
#

Normally task files are already on the attackbox if needed, if you can't find it there I'd just copy and paste the file contents into and id_rsa file that you can make on the attackbox

hexed galleon
#

where abouts are the task files, ihave found files for some tasks but not the encryption room.

#

I looked for encryption crypto 101

gleaming flume
#

Not sure, I think it would be with all of the rest, but perhaps they don't have the files for every room there

green crystal
#

Hi! how mush time does it usually take to make submitted rooms public? and what if I want to edit something in the vm?

#

@weary spindle

weary spindle
lofty owl
#

Hey i need help for the room TShark Challenge I: Teamwork task 2 ques 2
Whatever answer I Find and types it shows incorrect. i even tried from walkthrough

devout flare
#

hello i recently joined thm using my friend referral link but it is showing invalid coupon so what should i do (its not been 7 days since i got it)

upbeat quarry
west chasmBOT
#

@devout flare

TryHackMe's Email

TryHackMe's support email address.

fathom arrow
#

success isn’t just about giving up, it’s about you appreciating every step you take, every hurdle you clear, every challenges you overcome and every sale you make. Be proud of each win, no matter how small, and let them remind you of just how far you've come. Keep goingyou’re on your way to something incredible. New sales made🎉🎉 . All thanks to GOD🙏🙏

fast geyser
#

Authenticate/Decrypt packet error: packet HMAC authentication failed
error pops up
while connecting to openvpn

languid pier
fast geyser
#

Yes

upbeat quarry
# fast geyser Yes

Regenerate the VPN config file before re-downloading
Check if it is different from the previous one by doing a md5 checksum on both

dull lichen
#

I've sent a friend request on thm website, the person never received it and I can't send more since "friend request already sent". Same happened when my friend tried to add me via website.
Ok, we tried to add each other via email, same story, no friend requests were seen from both sides.

upbeat quarry
fast geyser
#

now it still does not work

weary spindle
fast geyser
#

IN-Regular-1

weary spindle
#

That VPN is having issues, use Eu-Reg-3

fast geyser
#

Let me try

#

It shows connection

#

Not connected

#

And by openvpn I have been assigned a ip address

weary spindle
#

The access machines page is broken.

#

Ignore that

fast geyser
#

Then how should I test it

#

That I am connected or not

weary spindle
#

You can either

Browse to http://10.10.10.10

in terminal curl 10.10.10.10/whoami

fast geyser
#

Curl command is showing me assigned ip

#

And I am able to ping the machine io

weary spindle
#

Then you're connected.

#

Happy hacking.

fast geyser
#

But 10.10.10.10 is not working

#

Web

weary spindle
#

Are you using https ?

fast geyser
#

No

fast geyser
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2737)

weary spindle
#

Access machine page is broken.

If you run your VPN script and see Initialization sequence connected, you're good to go, as this page no effect on machines not connecting or reverse shells.

You can verify your connect with 3 ways listed in my screenshot.

  1. curl 10.10.10.10/whoami

  2. ip a | grep "tun" <-- This command is usefull for being able to tell if you're running more than one VPN (tun) as it will conflict.

  3. Browsing to http://10.10.10.10 in your web browser.

wide flame
#

Hey, I have recently experienced some issues while trying to connect on the THM machine;after running the ssh command I get either a message saying that the connection is refused due to port22 or I get in and then the password(which is tryhackme) doesn't authentificate

gleaming flume
#

What machine from what room at you attempting to SSH into?

wide flame
#

The machines from the "network sevices 2" but I had the issue with other rooms before

weary spindle
wide flame
#

I don't get it, I think that in the Linux fundamentals 2 room it's shown that you must use the ssh protocol to get into the THM rooms any other ways of doing it?

gleaming flume
#

You can use the protocol to do that on some rooms, but not all of them - there are many other ways to access the machines and perform various actions outside of just SSH

wide flame
#

You mean using other protocols like telnet

gleaming flume
#

Or enumerating it and attacking it with various tools, or accessing it via a web browser if a website is part of the room, etc. It all depends on the room - that should be a walkthrough room though yeah? So read the task information and see how it wants you to interact with the machine.

wide flame
#

Hmm I think I understand what you mean hh

#

Thanks a lot!

gleaming flume
#

np

naive dust
#

hello. I am in the "breaching active directory" room. I am using the attackbox and am not automatically connected to DNS.

#

is anybody there?

upbeat quarry
# naive dust hello. I am in the "breaching active directory" room. I am using the attackbox a...

On the AttackBox, download the VPN config for that network and run it with openvpn That will give an interface called breachad
With that you can ping the DC
For the DNS follow the instructions for the AttackBox from the room material Task 1
Troubleshooting:

  • make sur the network is running
  • if you cannot ping the DC, consider leave/join, possibly mulitple times; allow some minutes (15?) before joining back in
  • read the Pinned Messages from #breaching-ad
naive dust
#

the network is running

wide flame
gleaming flume
#

I don't think you SSH into that room either

wide flame
#

Task 1 is about deploying the machine

gleaming flume
#

Yep and then task 2 is about perform recon on the machine through nmap - not SSHing into it

wide flame
#

Okay I get it thanks

weary spindle
#

Vulnversity guides you through getting access to the machine, providing you pay attention.

wide flame
#

I'm still new to the platform that's why.. 😅

west chasmBOT
weary spindle
#

Please read the linked article for a better understanding!

I understand being new can be quite frustrating when things don't work as you expect.

modern musk
#

Hi,

I can't connect to the THM machines using provided vpn servers.

gleaming flume
#

Elaborate? Are you getting an error message from openvpn? What machine are you trying to connect to and how?

modern musk
# gleaming flume Elaborate? Are you getting an error message from openvpn? What machine are you t...

Yes, Im getting an error messages.

2024-09-05 00:32:35 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2024-09-05 00:32:35 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-09-05 00:32:35 Note: '--allow-compression' is not set to 'no', disabling data channel offload.
2024-09-05 00:32:35 OpenVPN 2.6.3 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2024-09-05 00:32:35 library versions: OpenSSL 3.0.14 4 Jun 2024, LZO 2.10
2024-09-05 00:32:35 DCO version: N/A
2024-09-05 00:32:35 TCP/UDP: Preserving recently used remote address: [AF_INET]3.7.33.194:1194
2024-09-05 00:32:35 Socket Buffers: R=[212992->212992] S=[212992->212992]
2024-09-05 00:32:35 UDPv4 link local: (not bound)
2024-09-05 00:32:35 UDPv4 link remote: [AF_INET]3.7.33.194:1194
2024-09-05 00:32:35 TLS: Initial packet from [AF_INET]3.7.33.194:1194, sid=1efb21a9 9f34d986
2024-09-05 00:33:35 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2024-09-05 00:33:35 TLS Error: TLS handshake failed
gleaming flume
#

What VPN server is this? Did you try switching server and then regenerating and redownloading the config file?

modern musk
gleaming flume
#

What country are you in?

modern musk
gleaming flume
#

Some countries block openvpn or UDP traffic, that may be the issue here

modern musk
gleaming flume
#

Well I would google if that is the case for you, if that is indeed the issue then your only option would be to use the attackbox

modern musk
modern musk
scenic torrentBOT
#

Gave +1 Rep to @gleaming flume (current: #44 - 176)

gleaming flume
#

Sounds like a block then

modern musk
gleaming flume
#

That'd be illegal, so no

modern musk
gleaming flume
#

Unfortunately I can't do anything about that, just use the attackbox and complete things the best you can

modern musk
gleaming flume
#

As in reach out to openvpn about it? If your country is blocking it they are not going to be able to help

scenic torrentBOT
#

Gave +1 Rep to @gleaming flume (current: #44 - 177)

cerulean glacier
#

ahhh nvm its one of the -stans

modern musk
lime estuary
#

hello guys, i have a problem with OpenVPN in this screenshot it shows me that im not connected to the VPN. But when i am running "sudo openvpn --config filename.ovpn" its working and i have access to the machines. Do you know what can i do?

gleaming flume
#

I believe its bugged, if you can access the machines you are good to go

lime estuary
#

ye but it doesn't show me an IP, and when im using netcat i can't get a reverse shell because of that

gleaming flume
#

Go into your terminal and type ip a your tun0 ip is the one you can use for rev shells and the likes

lime estuary
#

okay i'll try it thank you

dire sequoia
#

Hello guys! I tried to finished host evasions in red team path, but 3 modules didnt load the room page, so i cant finish it

#

Cant post an screenshot here

ivory spruce
west chasmBOT
dull lichen
#

I've sent a friend request on thm website, the person never received it and I can't send more since "friend request already sent". Same happened when my friend tried to add me via website.
Ok, we tried to add each other via email, same story, no friend requests were seen from both sides.

upbeat quarry
# dull lichen I've sent a friend request on thm website, the person never received it and I ca...

I do not use this feature
I understand it works with email addresses: I guess these are the ones associated with the THM accounts involved here
As a way of making another attempt, which seems to be blocked at this stage, could you not modify your THM account to another email address (possibly coming back to the orginal one later) so that your friend can use that one in the fresh "friend request"?

dull lichen
#

I believe the person responsible for the website and its functionality should simply fix this bug rather than me hassling around with my emails etc

lofty owl
#

I was able to complete the rest of the questions by myself. But Task 2 question 2 from the room TShark Challenge I: Teamwork is not like that. I found the answer but it shows the format is not correct. then I referred to walkthroughs and tried to find the answer. I entered the same answer they entered from walkthroughs but it shows incorrect for me but correct for them.

lime estuary
weary spindle
lime estuary
#

For now mobile

weary spindle
#

Click the channel, you'll see pinned posts

lime estuary
#

Yes i found it

lime estuary
wind wedge
#

Hi All

I have updated the support bot on the site. It includes more options

If there are any issues with the bot please let me know

weary spindle
lime estuary
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2739)

naive dust
#

Hi, this IP: 10.10.171.170 is inaccessible & I need to access it for a burpsuite task

hollow cairn
#

I tried subscribing to make a premium account. The money was taken from my bank account, but it didn’t upgrade me to premium and showed an error saying there wasn't enough money in the bank, even though the money was already taken from the account

#

can any one help me plz

west chasmBOT
#

@hollow cairn

TryHackMe's Email

TryHackMe's support email address.

gleaming flume
#

I'd email support

hollow cairn
#

i sended an email to them

gleaming flume
#

Then wait and let them help you

gleaming flume
#

Did you try terminating the machine and relaunching it?

naive dust
#

yes I've tried that

gleaming flume
#

It seems to be working just fine, what are you having issues accessing specifically? The website?

naive dust
#

it does the same on the attackbox also

#

& with gobuster etc

gleaming flume
#

You did port scan it correct? So you know that ||The website is running on port 3333 which means you need to specify that when trying to access it 10.10.171.170:3333||

naive dust
#

I tried that before

gleaming flume
#

No?

#

Works for me

naive dust
#

I tried it when I was having issues with gobuster

#

1 sec

#

@gleaming flume

#

(im connected with openvpn btw)

hollow cairn
gleaming flume
#

1-3 days I think

hollow cairn
#

okay ty

gleaming flume
# naive dust <@405858023744077824>

Hmm that IP is responding to pings, but it doesn't seem to have the web port open that vulnversity should - you sure you spawned the right machine there?

#

Can you access http://10.10.10.10 in your web browser? Just to make sure the VPN is working

naive dust
#

but I'm still having this error

gleaming flume
naive dust
scenic torrentBOT
#

Gave +1 Rep to @gleaming flume (current: #44 - 178)

naive dust
#

I have https always enabled by default thats why

#

ty 🙂

gleaming flume
#

No problem, happy to help

wide jacinth
#

Did you get any help with this? I've been having issues connecting

velvet otter
#

https://tryhackme.com/r/room/somesint
task-3 question-2, the answer is wrong or maybe the reddit account details are wrong

TryHackMe

An intro to SOCMINT (Social Media Intelligence/Investigation) techniques and tooling. Use your awesome OSINT skills to perform an online investigation of a mysterious husband!

#

how i supposed to let the THM authorities know about this, so that they can fix it ?

#

here in the reddit the cake date is 19-dec but the answer is 20-dec

tawdry orbit
strong prawn
#

Yoyo gang does anyone have any knowledge in john the ripper ?

strong prawn
#

cuz when i try to use john it responds with

"john name.txt
No password hashes loaded (see FAQ)"

and i've been sitting around for like 2 hours cant find solution so i'm grasping straws right now 🙂

astral night
#

Can i change the timezone to USA? I keep getting streak interruptions because i access the site at different hours and miss the time difference with the UK sometimes

gleaming flume
#

I believe streaks should use your local timezone

#

Though if you used a VPN when you first signed up your timezone could be messed up

astral night
gleaming flume
upbeat quarry
strong prawn
#

Sup just fixed it i just didn't have the hash format correctly formated 🙂

flat tiger
#

I've been receiving an inline certificate error for the past few weeks with the US-East-Regular-1 server. I've tried regenerating the .ovpn and reconfiguring with multiple ciphers/ fallbacks and none seem to work. Anyone else experiencing this issue or know how to resolve?

ivory spruce
flat tiger
unique beacon
#

anyone know how long the reset password emails take, been waiting about 20 minutes now.

cunning isle
#

Hi, Im trying to complete the CI/CD and Build Security room. Im using an Attack Box, but I cannot get a response from the network hosts (GitLab or Jenkins) with either host name or IP address. The network was already reset.

upbeat quarry
steel field
#

Do I have to download VPN config files for Active Directory rooms too? I don't get the appropriate network interfaces on the Attack Box.

scenic torrentBOT
#

Gave +1 Rep to @upbeat quarry (current: #68 - 110)

steel field
opaque crest
#

hey guys i 've already attached my thm account to another discord account, but i forgot my discord account. So i want to use my discord token for this account but refused. Can anyone help me with this?

keen scroll
frail adder
#

hey guys my burpsuite is not catching js even though I already removed ^js$| in proxy setting. How should I troubleshoot it

gritty grail
#

Hi, can the notification "We're making improvements to TryHackMe..." be disabled or entirely removed? I never want to be notified about this and I think most users feel the same.

delicate crypt
#

hi

#

not able to attch file to attack box from my pc

ivory spruce
ivory spruce
frail adder
simple plume
#

hello i am stuck with the question Who is TryHackMe's HTTPS certificate issued by?#

wild warren
weary spindle
simple plume
#

@weary spindlethanks bro since week i was stuck on these question

sullen coyote
#

Im getting an error while connecting the the VPN, compaining about ciphers not being support. Ive downgraded OpenVPN and it works. Is this an issue my end or with the THM VPN?

naive dust
#

Hi,
I don't understand why connecting via SSH doesn't work. The command tells me that the password is incorrect, but the SSH password is always 'tryhackme', right? Could you help me correct this?(I use AttackBox)

weary spindle
naive dust
#

I tested several machines and none worked, it's not linked to a particular machine

sullen coyote
weary spindle
weary spindle
#

If you're required to SSH in you'll get;

a) The credentials.
b) You'll enumerate the machine and receive hints/credentials.

#

In short, Only a small % of machines actually have the password Tryhackme

sullen coyote
weary spindle
#

Happy hacking.

swift karma
ivory spruce
#

Uhm.... I don't think this is the correct discord server to post this.

ivory spruce
young horizon
#

Hello? Can I know why the Subscription?Am not getting discounts as a student.there was written I need to pay 14$ for first months and in second month i need to pay 8.4$ but It still asking subscription so i stopped my subscription after 1month i subscribe thinking it will be discounted in 2nd subscription but still same why?

gleaming flume
young horizon
gleaming flume
#

Did you read the student discount help page?

west chasmBOT
swift karma
#

¿What is offensive security?

#

help me please

#

say format of answer ***** *****

civic horizon
#

Hello! I wanted to see my level 5 mins ago, and in dashboard it says 0x6, but in profile and discord 0x5

keen scroll
weary spindle
naive dust
#

@daring sigil access page is broken

#

dont worry about that

daring sigil
#

ok cool

#

thanks

#

I see I was also in the wrong channel for that.

#

thanks for the hint

#

+rep @naive dust

scenic torrentBOT
#

Gave +1 Rep to @stiff barn (current: #57 - 129)

daring sigil
#

noice

wanton stream
#

Hello,

I have an student account on tryhackme and I just learn I will use the website in my study. So I have to change my mail from my personal one to my academic one but on the website, it's lock. Someone can help me plz ?

wanton stream
weary spindle
west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

wanton stream
#

Ok, ty

safe briar
#

Is this a real badge or an error? Past few days I've been getting this, lol.

safe briar
weary spindle
plush bay
wind wedge
#

Do you have one that is a 365 day badge by any chance?

safe briar
#

that's why it seems weird and I'm mentioning it.

wind wedge
#

Yea, that's weird that shouln't happen

#

I have raised this.

frail adder
#

Does someone here know the reason why reverse shell(.elf) being segmentation fault

#

after generating msfvenom

keen scroll
west chasmBOT
frail adder
#

ok

keen scroll
#

It might be because of the staged or stageless payloads, the way you are listening for it

#

Or the target architecture compatibility issue

frail adder
#

I don't see option to share my screenshot

keen scroll
#

Also, please continue in #room-help if your issue persists

keen scroll
tidal kestrel
#

Hello ! I have a question, why does my account doesn’t show how many hours I did the last 7 days ?

Others students in my class have this on their main page

I tried to Connect on their device to see if it come from my device, but it does not show either, so I guess it’s the account ?

frail adder
scenic torrentBOT
#

Gave +1 Rep to @keen scroll (current: #32 - 237)

naive dust
#

My TryHackMe Streak Was Freezed in 244 days

#

@deep trellis

#

i'm a subscriber

gleaming flume
#

naive dust
#

@weary spindle

marsh magnet
#

@naive dust what is the confusion?

#

It clearly says 245

#

244 at the bottom is just the chart not updating

naive dust
#

i did not get today's streak

marsh magnet
#

If you were on 244 yesterday. You have because it says 245

naive dust
marsh magnet
#

I guess you're just not going to listen to what I'm saying

#

It says at the top 245. The bottom hasn't updated yet

#

If you were on 244 yesterday. Your streak has been granted

naive dust
#

but today when im solving a room i did not get any streak massage.

#

that's why

tidal kestrel
# naive dust

Here the « 4 hours » I dont get that on my profile, why ?

naive dust
zenith urchin
marsh magnet
naive dust
#

thats im saying u

#

its the problem

marsh magnet
# naive dust yes

Then if at the top it says 245. Then it has gone up. Regardless of you getting the message or not

tidal kestrel
marsh magnet
#

There is nothing wrong. You have increased your streak. It quite clearly states 245 which is higher than 244

#

Message or not it has increased

naive dust
#

but its 244 in questions section and friends section

marsh magnet
#

I have explained this

#

That bit hasn't updated yet

#

The number at the top is your current streak

#

You have your streak

naive dust
marsh magnet
#

You might have not. Or you may have not seen it.

#

But at the end of the day you have your streak

#

Happy?

naive dust
#

1 min

#

finnaly

#

wait i will show u

marsh magnet
#

Yeah, that sounds like you either didn't answer enough questions. Or it didn't register it for whatever reason.

naive dust
#

when its 246 it means i get my todays streak

scenic torrentBOT
#

Gave +1 Rep to @marsh magnet (current: #45 - 176)

marsh magnet
#

Your most welcome!

naive dust
split lotus
#

Is it possible to get files for some rooms which require RDP connection to windows machine. When i did RDP to do for a room it was very slow to load the files into the software

#

with this it will users will use less resources of THM and it will be faster for learners

#

Room : Disk Analysis & Autopsy

thorny sparrow
#

Hi, for this room [ https://tryhackme.com/r/room/cicdandbuildsecurity ], it says "If you are using the Web-based AttackBox, you will be connected to the network automatically if you start the AttackBox from the room's page. "

But i'm unable to access the network at all.
"root@ip-10-10-251-69:~# ping 10.200.6.200
PING 10.200.6.200 (10.200.6.200) 56(84) bytes of data.
^C
--- 10.200.6.200 ping statistics ---
8 packets transmitted, 0 received, 100% packet loss, time 7156ms
"

hot pollen
#

Hi I just finished my Jr Pentest Path recently but sadly the name of the cert of completion is my username i edited the profile to my name and generate the certificate still the same I already emailed at the support but until now there's no answer.

gleaming flume
#

I don't think the name on the certificate can be changed after its generated for the first time, outside of yknow editing it manually

hot pollen
#

So I can put the aws link of the Cert with my name to my LinkedIn in the future anyways thanks for your answer if you know their support email can you send i guess i emailed the wrong email.

gleaming flume
hot pollen
scenic torrentBOT
#

Gave +1 Rep to @gleaming flume (current: #42 - 183)

upbeat quarry
hexed galleon
#

anyone know how I can get eternalblue working on msfconsole

upbeat quarry
hot pollen
#

I just watch youtube while reading also i used my own kali machine connected to thm ovpn

upbeat quarry
#

Even on the AttackBox, you have to use the VPN (as there is currently an issue)
Download the VPN config for that network and run openvpn with that: you will get an additional interface that will allow you to ping the DC
I am surprised it did not work on your Kali VM: can you share a screenshot for that?

upbeat quarry
#

I have just done it
let's go step by step
for the VPN, you are downloading the config file for the right network as per my screenshot?

#

sorry, I am dull guy: I use defaults

#

I do not know if it matters too much now that there is that issue with the VPN on the AttackBox, but the expectation is that you start the AttackBox from the page for Lateral Movement and Pivoting, not from a random THM room

#

you download the VPN config to your host (mine is Windows), open the file on your host (it is text file of say 100 lines) and copy/paste that to the AttackBox using the clipboard box that separates the left pane and the right pane in Split View mode

#

that screenshot is about DNS configuration on Kali, you will not use that on the AttackBox, right?

#

OK, I'll switch my Kali VM too then

scenic torrentBOT
#

Gave +1 Rep to @upbeat quarry (current: #67 - 113)

coarse tulip
#

Sorry please, anyone with coupons code for tryhackme please 🙏

upbeat quarry
#

So, where are you with the VPN now on your Kali instance?

#

regeneration is key
you are not wasting my time
I discovered only yesterday (troubleshooting breaching AD for hours) that it is what solves all the troubles

#

Just to finish, I have posted quite a few messages about getting these AD networks to work, and usually I was suggesting to troubleshoot by leaving the network and joining back in
now, I would very much put the emphasis on regenerating the VPN config file once the network has been running for, say, 5 minutes
have fun with AD

last mortar
#

hi , i have a problem with phising prevention room , when i submit the answer which is "<domain> service ready" dose not working, please help me to solve the problem i still just have this question and than finsh the whole room on soc1

minor grove
#

Question: Is it possible to reset any progress, and start from fresh?

weary spindle
#

Unless you want to create a new account.

minor grove
scenic torrentBOT
#

Gave +1 Rep to @weary spindle (current: #1 - 2749)

thorn mulch
#

Intro to Defensive Security- What is the flag that you obtained by following along?

weary spindle
thorn mulch
#

didn't know the answer

weary spindle
#

..Because you need to follow along with the static site you launch in the task.

thorn mulch
#

@weary spindle You are part of a Security Operations Center (SOC) responsible for protecting a bank. This bank’s SOC uses a Security Information and Event Management (SIEM) system. A SIEM gathers security-related information and events from various sources and presents them via one system. For instance, you would be notified if there is a failed login attempt or a login attempt from an unexpected geographic location. Moreover, with the advent of machine learning, a SIEM might detect unusual behavior, such as a user logging in at 3 AM when he usually logs in only during work hours.

In this exercise, we will interact with a SIEM to monitor the different events on our network and systems in real-time. Some of the events are typical and harmless; others might require further intervention from us. Find the event flagged in red, take note of it, and click on it for further inspection.

Next, we want to learn more about the suspicious activity or event. The suspicious event might have been triggered by an event, such as a local user, a local computer, or a remote IP address. To send and receive postal mail, you need a physical address; similarly, you need an IP address to send and receive data over the Internet. An IP address is a logical address that allows you to communicate over the Internet. We inspect the cause of the trigger to confirm whether the event is indeed malicious. If it is malicious, we need to take due action, such as reporting to someone else in the SOC and blocking the IP address.

Answer the questions below
What is the flag that you obtained by following along?
NOW ANSWER. IM STUCK HERE

weary spindle
#

Wow, you're being rude.

#

I've already told you twice, here is a third time.

thorn mulch
#

Got it. thank you:)

wooden oriole
#

i am facing the problem like i am able to connect with openVPN and even my ip address also changed but yet i am not able to run the machine it showing i am not connected

#

@weary spindle

keen scroll
naive dust
#

Hey mods please fix the issue i did not collect my streak i solved over 2 rooms today

#

im facing this issue from tommorow

#

please fix it

wooden oriole
#

thanks to reply i am using windows in that in website help section they told to try to open10.10.10.10 i am able to open it but at the same time not able to open the lab machines. in OWASP Top 10 2021

keen scroll
#

Are you using WSL?

wooden oriole
#

no

#

just windows

naive dust
#

i dont want to losse my streak

keen scroll
# wooden oriole no

Ok, some other issue maybe.
You could verify and share some screenshots here for a clearer idea

keen scroll
# naive dust please fix my issue

Hey! Firstly, mods cannot help with site issues.
Secondly, if you lose your streak because of a site bug you can contact the support to restore it back. Not a big deal

west chasmBOT
naive dust
#

can u provide me the email ??

#

@keen scroll

west chasmBOT
#
TryHackMe's Email

TryHackMe's support email address.

naive dust
#

thx

#

brother

wooden oriole
#

but yet i am facing this issue

#

@keen scroll

keen scroll
#

Where's the issue?
That Not connected component is probably broken, you can ignore it

wooden oriole
#

but yet http://MACHINE_IP this kind of link is not opening

keen scroll
wooden oriole
#

i clicked on the atteckbox

keen scroll
#

See that green two rows icon on the right, you have to start the machine in your task.
Attackbox is not the target, machine_ip is replaced with the target machine not attackbox

wooden oriole
#

if i go with task 2 machine then no machine open and if i click on the question mark then this page appers

keen scroll
#

Yep, you have started the machine. You can close this modal/pop-up. The machine IP will be visible after a minute when you start it.

wooden oriole
#

thank you so much

#

i didn't know that we have to search that ip

#

now it is working

copper terrace
#

question i am working on the Common Linux Privesc when i ran the chmod +x LinEnum.sh ./LinEnum.sh this long report ran but it was cut off and what i need to answer the question was cut off i had to google the answer i tried to change the settings but access denied why arer the setting set up this way

autumn fox
#

Hey guys I am troubleshooting the VPN on a mates kali box.
He can start the VPN and 10.10.10.10 is reachable.

He can successfully reach the rootme box and interact with it: https://tryhackme.com/r/room/rrootme

He cannot reach port 80 on that room.
We tried: use different VPN server and regenerate certificate, install latest updates and reboot vm

Then I tried the certificate on my vm, it worked fine.
I could properly reach 80.

Felt like we have a little forensics challenge at hand.
Verified routing was fine, then decided to start wireshark.

We see a fine tcp handshake is fine and then we see duplicate ACK and retransmission.

He also cannot access ssh on this box https://tryhackme.com/r/room/ctf
In the second screenshot you can see the ssh connection with TCP Retransmissions and duplicate ACKs.

Any clue where this could come from?

TryHackMe

A ctf for beginners, can you root me?

TryHackMe

Hack this machine and get the flag. There are lots of hints along the way and is perfect for beginners!

#

Since his vpn cert works fine on my vm it is definitely a him problem. Was just wondering if you have seen this before as I cannot put my finger on the issue and losing mental cohesion over here...

upbeat quarry
finite wigeon
#

using Virtualbox to run the kali VM, the original VM was installed with an ISO, we also tried to boot up a "ready to use" Virtual box Kali, problem persisted.

#

Our latest troubleshoot was to reboot my router, but problem is still persisting

upbeat quarry
finite wigeon
#

positive using the standard sudo openvpn [path]

#

we went through the certification file and the stuff inside we deemed to be correct, Ori is also able to run everything correctly using my certificate

upbeat quarry
finite wigeon
#

stable i would argue, only information coming is like this :

2024-09-08 14:38:49 Initialization Sequence Completed
2024-09-08 14:38:49 Data Channel: cipher 'AES-256-CBC', auth 'SHA512', peer-id: 223, compression: 'stub'
2024-09-08 14:38:49 Timers: ping 5, ping-restart 120
2024-09-08 14:38:49 Protocol options: explicit-exit-notify 3

#

and thereafter nothing

upbeat quarry
jagged kettle
#

Hello i have a problem with meterpreter in quest expletion of metaspolitExploit

#

I try with my kali vmware and with the attackbox of site but doesen't work

upbeat quarry
scenic torrentBOT
#

Gave +1 Rep to @jagged kettle (current: #2213 - 1)

finite wigeon
#

and I can now confirm it is definitely my homework.

#

I can without problem connect through my phone network.

upbeat quarry
# finite wigeon I can without problem connect through my phone network.

interesting in many ways, as a wireless connection to THM VPN is not likely to give you good performance (not first-hand experience from me, rather people sharing their experience on Discord)
with your home network, are you on wifi? Can you share a screenshot of ping 10.10.10.10 so we can the latency of, say, 15-20 pings?

finite wigeon
#

I can full agree with that, but it is definitely a problem with my router/Isp

#

throwing it up now

upbeat quarry
finite wigeon
#

home

upbeat quarry
finite wigeon
#

seems like I can't upload the picture..

#

but yeah, pinging 10.10.10.10 is no problem at all

upbeat quarry
finite wigeon
#

there you go

upbeat quarry
upbeat quarry
# finite wigeon throwing it up now

I do not have other ideas at the moment
hopefully something works out at your end, and then please consider sharing the outcome in this place for others, and me, to learn Thank you

scenic torrentBOT
#

Gave +1 Rep to @finite wigeon (current: #2213 - 1)

merry hound
#

I am not seeing the VM machine after clicking on start machine . The status shows Machine started and could see the IP, but not able to see the VM screen. Please help, Thanks

upbeat quarry
merry hound
#

Hi @upbeat quarry please find screenshot attached

pearl gulch
#

that's the target machine

#

you need to also open an attackbox, or connect over the VPN

merry hound
#

but usually when I click on start machine, it will show the VM in split view , but now I am not seeing the screen in split view, just the status shows target machine is running

glass chasm
#

tryhackme photos are not displayed in all courses

#

I think the problem would have passed but 8/25 to today is too much

rustic crater
#

Can anyone give me an idiots guide to going through https://tryhackme.com/r/room/breachingad with an attackbox? When I start the attackbox, it doesn't have the interface ("breachad") the room expects, nor can it ping to the THMDC host. It feels like I'm supposed to be starting the attackbox in a specific way, but other than ensuring I'm on the breachingad page when clicking the "start attackbox" button, I'm not sure what else I can do. (I'm definitely using attackbox rather than a kali vm. The instructions just say "If you are using the Web-based AttackBox, you will be connected to the network automatically if you start the AttackBox from the room's page", so I'm missing something)

Ah, I've discovered #breaching-ad, so will look for help in there, seems to be a known issue. Thank you.

teal mountain
#

I would like to buy "subscriptions voucher" but each payment is rejected. I have the money in my account, I have tried 3 different banks and it has always been rejected. Is there a problem with the payments at the moment? https://tryhackme.com/subscriptions

glass chasm
rustic crater
# rustic crater ~~Can anyone give me an idiots guide to going through https://tryhackme.com/r/ro...

Okay, so when the room says "If you are using the Web-based AttackBox, you will be connected to the network automatically if you start the AttackBox from the room's page", that is false (currently) incorrect. You still need to follow the instructions to download the "BreachingAD" openvpn config file from your https://tryhackme.com/r/access page, run it from within the attackbox, and that will get you onto the correct network. Hope this helps someone in the future.

keen scroll
#

That's not false, but a known issue probably some configuration changes on AWS or wherever the Attackbox is hosted. VPC stuff

rustic crater
muted ravine
#

Hi all
I'm fairly new to the platform and I have a question about one of the task that I didn't understand the question, can someone point me to the right place to ask about tasks?

upbeat quarry
# merry hound but usually when I click on start machine, it will show the VM in split view , b...

For some rooms, pressing the Start Machine green button opens the screen in Split View mode, with the target on the right pane I would not say this is the usual behaviour, as in my experience only a minority of rooms work like that
For this Summit room however, you have to start 2 machines:

  • the task machine, also referred as target machine
  • the attack machine: THM AttackBox or your own VM
    I have attached a screenshot showing the scenario with the AttackBox
    Note that the AttackBox itself always opens initially in Split Screen view
upbeat quarry
upbeat quarry
primal matrix
#

I am facing an error with the Slow Web attack machine how do I fix it?

upbeat quarry
primal matrix
#

Yes. Attackbox

upbeat quarry
primal matrix
# upbeat quarry can you describe the error?

I'm currently participating in the Friday Overtime Threat Intelligence session using a web-based attack machine. However, I'm experiencing significant delays and slow response times with the attack box.

upbeat quarry
primal matrix
#

SOC Level 1
Cyber Threat Intelligence
Friday Overtime

upbeat quarry
# primal matrix SOC Level 1 Cyber Threat Intelligence Friday Overtime

Thanks, just found it and starting the instance
My understanding is that you do not need the AttackBox for this room
The target opens in Split View, and you have to wait some minutes to have the docintel platform open automatically
I agree with you that the docintel interface is slow

scenic torrentBOT
#

Gave +1 Rep to @primal matrix (current: #2213 - 1)

gleaming flume
#

Which room is this?

hot pollen
#

My understanding is that, once the certificate has been downloaded, there is not way to modify it, even through THM support
This idea, although (very) painful, may work:

  • reset the progress for all the rooms involved in the path
  • redo all the rooms involved in the path (remember: I said (very) painful) If you have done a copy/paste of all the answers before resetting the progress, this may go pretty fast
  • maybe (no guarantee) you will have the chance to download again a certificate of completion with the current details
    What do you have to lose but time?
    BTW, please move this discussion to #site-support as this topic is not room-specific
#

@upbeat quarry

north marsh
hot pollen
#

Ill try i still have all the answer in obsidian but it will take a effort

#

Very painful lol

#

I spent a month only to print the username in jr pentest path

#

Cert

#

🥲

gleaming flume
hot pollen
past prawn
#

Currently starting to use Tryhackme, in Task 2 of Intro to Defensive Security (areas of defensive security), it's not letting me put in the right answer, it says it's wrong, but it's correct

past prawn
#

Yup

gleaming flume
#

Did you try the full spelled out version?

past prawn
#

yep

gleaming flume
#

Did you try the american english version of the last word?

past prawn
#

Ah. That's it.

#

😂 Apologies for that

gleaming flume
#

No worries

hot pollen
keen scroll
#

Maybe try Figma? Gotta signup first, but it's online

keen scroll
#

You can load the fonts, create a mask around the current name and apply the new name as an overlay

hot pollen
# upbeat quarry that was a smart check

Yeah that is why I somehow doubt about the suggestion anyways thank you for that suggestion.
Maybe in the future thm will do something about it a lot of people like me i read it on reddit has the username in their cert of completion in a thm path

scenic torrentBOT
#

Gave +1 Rep to @upbeat quarry (current: #61 - 124)

hot pollen
#

^ ok i will practice photoshop later 😅

upbeat quarry
light sun
#

how do I access "my rooms"

gleaming flume
light sun
#

thx

autumn fox
#

We were able to fix the duplicate ACK and retransmission errors by adding this to the ovpn

tun-mtu 1000

So it sees for what ever reason the Router won't traverse mtu's larger then 1280 bytes.
Don't know why, don't know if any tools need larger mtu's and will now not function properly anymore.
But this fixed it on this cursed network for now.

upbeat quarry
scenic torrentBOT
#

Gave +1 Rep to @autumn fox (current: #1471 - 2)

unique flume
#

Hi I am trying to use open VPN on wsl Kali with kex, it's not connecting, any advice?

unique flume
#

Thank you

steep reef
#

hello

rancid cloak
#

Hi, is it the right place to report mistakes in the room?
In the Intro to Docker, task3: instead of "helloworld" should be "hello-world", e.g.
docker run -it helloworld /bin/bash --> docker run -it hello-world /bin/bash

gleaming flume
scenic torrentBOT
#

Gave +1 Rep to @gleaming flume (current: #42 - 186)

hexed galleon
#

Hello, there is mention of tun0 ip and a vpn. upto this point I have not used a vpn as it seemed a little more involved considering some of the problems I am having. I am on "what the shell" and a task mentions using tun0. I have not covered that upto this point yet, how can they just throw that in there with no explanation of what it is? I assumed (my mistake) that you could do this course without prior knowledge of what a tun0 is or using a vpn.

pearl gulch
#

have you done pre-security path

hexed galleon
#

I am trying to use openvpn and it is not connecting

gleaming flume
#

This on windows?

hexed galleon
#

yes

#

i have changed the locations four times

#

is this the tun0 thing?

gleaming flume
#

What do you mean? The OpenVPN should make a tun interface yes

#

Make sure your internet connection is stable and that openvpn and udp aren't blocked in your country

hexed galleon
#

I do not know what the tun0 thing is, I have seen it a few times but have no explanation what it is or why/how i should use it

#

I would imagine that openvpn and udp are allowed in the uk? is udp like tcp? that udp?

gleaming flume
#

hmm yeah, that wouldn't be the issue in the uk

hexed galleon
#

Its alright Hiro, I will have a look at something else. Thanks for the attempt.

gleaming flume
#

alright

hexed galleon
#

cheers budd

pearl gulch
hexed galleon
#

maybe wind up someone else brd

pearl gulch
#

i'm trying to help you

#

but ok i will cease trying

upbeat holly
#

Hi guys im trying to get vpn ip from tryhackme but something is wrong , i downloaded the conf. File instaled it in my kali linux terminal i got the mesage “initalization sequence completed” but after that it still pings something and then got msg: event wait: inerupted system call fd fode -1 , code 4 and etc

gleaming flume
#

Can you send screenshots? You'll need to verify to do so

west chasmBOT
ivory spruce