#site-support
1 messages Β· Page 143 of 1
Do you think it'd be ready if you're able to ping it or do you think there'd be other services and such that would start up on that system? I'm just thinking for when I try and get on later boxes. I'd assume there might be other things involved that may need to startup.
no
different services take different times to initialise
ping just means that it responds. Doesn't specify which service
Just run nmap as your form of knowing if it's up
So then yes, it'd take x time according to services and their startup time
It says 3000 is up now, has the name of the site on the nmap but nothing loads int the browser :/
3000 has been loaded for 3-4 mins noiw
are you doing ip:3000
so you're using <ip>:3000 just like yesterday?
If you do just ip it will take you to ip:80 by default and that will error
Hello, I'm always kicked from the group since yesterday, everytime I join it, I'm kicked in an hour. What is wrong?
Sounds more like a discord issue, this has been happening a fair amount recently with a few users. Audit logs have always been checked before and dont show any indication of being kicked
Yes it's really weird. Hope this will be fix soon
I can't run nmap on any of the 10.10.. ip addresses, like in RP: Nmap or in Blue
disregard that, now it works. I don't think I was being patient enough with letting the box load.
VPN will automatically expire after 30 minutes of inactivity
I'm not inactive though @rigid oxide
I'm actively connecting to a host and doing a gobuster scan
And it's been connected for less than half an hour
Do you possibly have two instances of the VPN up?
Nope, only got the one VM going and if it was on the same host it'd fail to add the route
Hmmm
The access page can take a bit to update sometimes
Still showing connected
Run this by Skidy once he's on in a bit, he might have a better idea of some troubleshooting
It's working, I'm just getting HTTP timeouts rn more often than usual. Heading to a practical session and I'll try again later
hello... does the vm for christmas challenge 2 take more than 10 minutes to become available?
or is finding the target machine part of the challenge too?
nope
it'll give you the IP
actually, you should already have the Ip address
when you click "deploy" the IP address appears near the top of the page
yes, i have that... its a 10.10.x.x ip... but if i go to it in a browser, i get a message this site cant be reached... and im on the vpn... the network access says that I have an internal virtual ip address of 10.8.x.x
Yup! Sounds right. Have you nmapped the machine?
Yup! It is π
Generally speaking, every single machine you'll do will require nmap π If you're not used to using tools, the 3 most used tools are nmap, a directory searcher (I use gobuster but dirb comes with kali), and metasploit. 2 of these tools are required for this challenge π
ah got it... thank you so much!
For the Christmas challenges in particular, we'll talk about scanning if need be
For this, the port number to be used is specified in the task
@vapid dawn I don't think the port number is in the task? π
it's in the previous task. tripped me up at first, too.
Ah is it not
I must have accidentally removed it
Will add it in
Sorry about that all
Port is 3000 btw
It's no problem, but (for what it's worth) myself and other users discussed how kicking off recon with Nmap is usually a good start π
@eager fulcrum Is the VPN still playing up?
Haven't tried, was in a lecture. Had some issues with it after restarting and reconnecting
Just dropped packets
Will give it another go later
Okay thanks
lmao
i swear you people are just trying to make studing hard just for me
...maybe today is the day we get load balancing finished...
Talking with the others now, we'll get that back up asap
no worries π€£
Is it down?
Yes @pale ridge
Oh noes
Yes
Investigating
I was out at my Tennis lesson
Can anyone tell me the time it went down?
Roughly that is
Around 1.40 IST
Thanks
TIL Skidy plays tennis
πΎ
@deep trellis I can confirm I'm still getting packets dropping etc that shouldn't be
Didn't time me out for inactivity now but my nmap scan at default timings reported dropped probes which never usually happens
@here what if I overwritten mrinvetory password and loged in then, accessed his inventory requests?
answear is correct neverthless
Then that's a valid method.
(NO SPOILERS HERE -acutally didn't told how to to something, and stuff here know what about am i talking)
ok...
I don't think you will be able to though.
You can't overwrite the password unless there's some SQL injection attack or something, and I very much doubt there will be.
well, the day 1 is about cookies, and yet i know the "correct method" for this challange
i just registered with mcinventory username
lol
If thatβs day one
Wait and that worked?
Yes you can do that
yup
In fact thatβs the method I used
Haha, ok. Unexpected
Hi guys. I'm a complete noob to all of this so forgive me if I sound like an idiot... but I can't get the Kali machine to work. It keeps crashing no matter what I do.
The kali machine from THM? Or your virtual machine?
the one from THM. I don't have all the programs I would need, so I've been trying to use the Kali machine
I've opened it in the browser, I've RDPd, but it keeps crashing.
That is going to be an Admin matter, I won't be of any help, I am sure they will answer very quickly ;)
No worries, thank you. π
@dusty tapir how much ram does your machine have? It may be that the system doesn't have enough memory to support the connection. Unlikely but sometimes the case here
Ah, that could be the case since I'm only using a laptop. I have 8gb.
Oh gosh that should be plenty
hmm
Is the machine itself crashing or just the connection?
It seems to be the connection. Basically, I stop being able to click on anything in the VM itself, and the box on the Kali page will say I've been disconnected.
I have a problem with hashcat, I always got this error message, can someone help me or explain what is he problem? trooper@TrainingVM ~/Downloads $ hashcat -m 1800 buddy rockyou.txt --force
hashcat (v5.1.0) starting...
clGetDeviceIDs(): CL_DEVICE_NOT_FOUND
clGetDeviceIDs(): CL_DEVICE_NOT_FOUND
No devices found/left.
Started: Tue Dec 3 23:19:59 2019
Stopped: Tue Dec 3 23:19:59 2019
trooper@TrainingVM ~/Downloads $
@naive dust for a quick fix, have you tried using John the Ripper?
@dusty tapir what browser are you using?
Chrome, but I'm also trying to RDP into it with the same issues.
yes but I am not familiar with John, it run but asked me to specify the format at the end
If you don't mind, trying rebooting your computer @dusty tapir
No problem. I'm going to try one more time and then I'll reboot if it doesn't work.
That's quite strange with the VM, have you tried Firefox by change?
http://pentestmonkey.net/cheat-sheet/john-the-ripper-hash-formats @naive dust this link might help with that for John at least
ok I will try tomorrow, thx
if it adds anything, my conn to guacamole boxes is a bit hit and miss also
I gave a try again and end up with that:
john --format=sha512crypt --wordlist rockyou.txt buddy
Warning: invalid UTF-8 seen reading rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (sha512crypt, crypt(3) $6$ [SHA512 32/32 OpenSSL])
No password hashes left to crack (see FAQ)
You havenβt specified a hash
on a side note the login does not recognize with just nick and password... requires a email/pass to work.
probably causing a few locked out usernames
your john command should look like john hash /usr/share/wordlist/rockyou.txt
@mossy ermine The tryhackme login?
yes @eager fulcrum
Welp, looks like it's a confirmed issue then
I raised it with Skidy like a week or so back
easy fix just remove the login text saying you can use nick as a valid login and vola no more headaches
Yo... ummm
Im on another PC than usual... and forgot what password I used
I don't want to reset it, is there some way I can see what it was? my login was incorrect so Im locked out
Anyway I could do that?
I keep bugging people to use a password manager for situation including but not limited to this π
π€
there is no way in this world any site will show you your password
as if they do it for one, then it's a vuln for other accounts
Man
still
the windows email thing takes forever to load
It's a security risk
ya'll don't live in the real world if you think they'd just reach in and grab it for you xD
I wasn't expecting that... I was wondering if I could do it in a way where I could reuse an old password
Oh yeah you can
you can reset
then reset back to an old password I beleive
closest you'd get tho
Okay
Someone please make a moderate level room or recommend one.
ssh doesnt seem to be open on my box, can i get someone to check 10.10.76.96 for port 22
oh my bad thought that was just the web services ports, it worked for me now
it's been 15 minutes since i deployed the machine; port 22 is not active
earlier, i waited around 30 minutes to find that I am still not connected
what's the output you're getting? have you checked the vpn?
yes, vpn checked
so what does it say when you're trying to connect?
This site canβt be reachedThe webpage at http://10.10.105.253:22/ might be temporarily down or it may have moved permanently to a new web address.
ERR_UNSAFE_PORT
Its not a site, you have to ssh into that port
yup, command is ssh user@ipaddress
you don't need to specify a port since 22 is default for ssh
it running now
what do you mean? which challenge are you on
todays
you always have to use the vpn when interacting with a machine, yes
am i the only one not having questions to answer for the last challenge
if that's the case try leaving the room and reentering
can anybody help me?
@naive dust I wouldn't think so. I've never used the VM though. The boxes do take a little while to start up fully after deploying though
@light bluff I'm a little but that exact thing happened to a few of us yesterday. For me it was fixed by leaving the room and reentering, as suggested by someone here
Hi @jagged crown Whats up?
Hello @deep trellis Did I need to sign up to tryhackme with my university email to get the discount? I didn't realise there was a student subscription option until I signed up with my personal email address and I cant seem to find a student area
Thatβs a @deep trellis question @mystic dust
Ah, thankyou mate
^^
@mystic dust email hello@tryhackme.com with that question and we can get it all sorted out. Be sure to send the message with your student email.
Will do, thankyou @rigid oxide
Any help. Machine keep disconnecting. Cant do anything
@trim karma First check that you're connected through ovpn, wait around 10 minutes and if that doesn't work, let us know
I'm already connected.
I did some tasks, but it keep disconnecting and reconnect again and again
What SSH client are you using?
Did not connect
It works now after restarting my kali
Probably VPN dropping out
Thanks anyway
I am going to restart the VPN
@trim karma Screenshot of the openvpn command output?
And your kali VM is definitely connected to the internet?
if you do that, you'll have to download it again and run openvpn again
if I understood your question correctly
I mean maybe there's a problem with my config file
Looks like it worked
But after a while it will rest
I will see.
If didn't work
You have to give me the answer of #7 π
huh?
Just kidding
can we get a little more resources added to the kali box, keeps freezing on me with no way to kill processes
@mossy ermine Our cloud infastructure costs this month are rather high due to the Christmas event. If others are having similar issues, I can bump the machines resources for all Kali instances. As for now, I am going to keep it on using lower resources (which is still 4GB RAM + 3GHz CPU).
Hope you understand π
@deep trellis cool am happy to have just to have it on the to do list
If its really bad, I will increase it - don't want it to effect your functionality
but in return you have to recognize me a chill guy... which is very important distinction
I can no access any of the site while on my VM kali (v-box) but can on my local box. Anyone experience the same thing?
openvpn inside the vm?
Does your Kali VM have internet access at all?
@deep trellis You helped me last week with an issue deploying VMs. I worked around it in the end by using FF instead of Chrome. I just wanted to let you know that the problem seems to lay with Eset Nod32 Antivirus. If I add https://tryhackme.com/ as a URL whitelist then machines deploy ok. I worked this out as when trying to download the jpg from the advent Day 5 task, the item was blocked as THM is on a list of blocked websites...
TryHackMe is a platform for learning and teaching cyber security.
No problem. Just thought it might help if others contact you
@deep trellis I've submitted a false-positive report to Eset for the domain
@late atlas amazing, really appreciated!
@north palm Thanks, I'll pass that on if they push back
Response received from Eset. Domain is being removed from blacklist
Nice one
Hmmm... kinda strange that thm got blacklisted...
Eh, not surprising... See false-positives like this quite often
Mwell
Iβm runnin linux as main os
So...
Got a win10 in vm for the times i gotta do presentations and stuff, but thatβs it
Everytime I join a room, all tasks are completed. Leaving & rejoining does nothing. This happens to every room, regardless of its age. Only been happening for the last 10 mins or so π
Hm
Relaly?
Hi @warm spear Can you try again please?
Is this for every room?
Just tested on my end its fine hm
Someone else the same issue earlier tho
(nothing on my end, btw)
Weird sorry about that
first timethis has happened to me haha
That happened to me on the two days before yesterday
Yesterday it was ok
Had to leave and rejoin and it was OK, happened only on the Christmas room tho
@deep trellis, I could be wrong but two badges should be showing on my profile. Any idea? Mr Robot and CTF. Working towards Linux one now
These two have badges, on the site π
Did you finish every answer? Make sure to click completed next to questions with no answers
Yeah, it has a green tick
Mr. Robot is sub only?
woot, gonna do it after lunch
Yeah, I still don't have the Blue badge either - May still be on Skid's TODO list, not exactly a critical issue haha
@late atlas if you want the blue badge DM me with your username π
@copper mist Ah - some badges were added after people completed, gimme your username and I will have it updated
Man
is there anyway to allow copy and paste between web kali and local machine. i know in remote desktop you can enable it in the options ?
do you use virtualbox?
ohh my bad
So it should work, chrome requests access to your clipboard @mossy ermine
oh been useing firefox
IDK about firefox
lol
Wonβt work in ff
Hey moderators can someone please check port 999 of today's machine
I think service got crashed and you should restart it so that everyone can complete today's challenge
Is there any way I can manually provide my University email for my HackMe account that has a non ac.uk domain registered to get the student discount?
You need to contact hello@tryhackme.com about it iirc
roger-dodger, I'll give 'em a buzz. Cheers!
@zealous yoke from your acuk email prefereably
Hi. π Iβm still having trouble with the kali machine (the THM one). I figured out that clicking commands too quickly was causing it to crash so Iβve been slowly working through the initial setup screens, but then as soon as I try to launch an application of any kind, it crashes again.
This has happened on two machines that Iβve tried it on.
Sounds like something @deep trellis can look into further
@naive dust Restart the system, at least that worked for me
can anyone explains how XXE works ?
Have you checked out the info on the portswigger site? https://portswigger.net/web-security/xxe
this is unbearable guys,
each time i connect to the network and access today's machine, the vpn restart and i have to wait for about 5 min in order to access the machine again, and it reset again.
i spent my whole day just trying to write a single command.
is it my machine problem? or the network?
I haven't connected today but, your report is the first I've seen saying there are connection issues so, it's probably unlikely to be the THM server(s)
it was fine in the morning, i did #1,2,3 but trying for few hours now on #4 but it keep rest
You just letting the VPN disconnect and reconnect or have you tried killing your ovpn client and starting it again?
@late atlas even regenerate my config file
@trim karma could you run an ifconfig and paste the output here?
Have you tried the clichΓ© 'turn it off and on again' on your vm? Haha
You appear to have 2 tun interfaces
have to chime in here
thats mean?
i had to restart the vpn connection earlier every min or so
like 6ish hours ago
not sure if the vpn server or my own connection though
@trim karma Reboot your machine and connect to the VPN again
Not much I can do to help with that haha
The connection issue was probably the two tun interfaces fighting eachother. Glad it's working for you now though
Hello I managed to get connected with site's server but I can't connect to the machines .Here is the last messages in terminal
RTNETLINK answers: File exists
ERROR: Linux route add command failed: external program exited with error status: 2
WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Initialization Sequence Completed
Kill your openvpn process, then run:
killall openvpn
and then try running the vpn again
I tried it but I can't connect the deployed machine.On the access page it shows that I am connected
did you give it time?
A general rule of thumb for troubleshooting OpenVPN issues:
- Run an
ifconfig, if there are multiple tunX interfaces, restart your machine.
yes it changed my virtual ip and I tried again .I will restart and I will do it again thank you
@open crater it shouldn't change your VPN IP
I restarted my OS and did the process again but still I can't connect to the deployed machine
ifconfig command shows a tun0 and under it an (UNSPEC
)
Any ideas ?
If you're still getting ERROR: Linux route add command failed: external program exited with error status: 2 - That is probably your issue
No I am not getting that error.I am not getting any errors
If I get a status 'exausted' from hashcat does that mean that no password was found?
@livid osprey it means your wordlist or dict or keyspace didn't have the password
hey your twitter discord link isnt working... but the one on the website does... though you should know
hi. no matter what i do, i cant seem to connect to the Open VPN Virtual IP.
It shows i am connected on this page(https://tryhackme.com/vpn/regen-config) and in the OpenVPN GUI.
but I can't connect to my Internal Virtual IP Address. or am I not supposed to do that?
@fringe flicker your internal address is your IP on the VPN. How are you trying to connect to your own machine?
In the browser, it wouldn't work unless you had a web server running
Pretty sure you shouldn't need to connect to your VPN IP in any way, but you need to use it sometimes when things connect back to you
so im trying to do do advent calender(thought it was a more a tech question so i asked here)
and the 1st task is asking me to "Deploy the machine and access the website at http://<your_machines_ip>:3000"
Yep so that's a bit vaguely worded. It means the IP of the machine you deployed in the room
how do i get that?
Click the deploy button, and at the top of the room below the leaderboard it will say the IP of the VM
Weird, unless you deployed it from another browser instance
Need help on Room Blue, metasploit fails to exploit with an unknown reason
never mind, finally worked
Yeah I had the same problem, sometimes you just need to reset the room and it'll work, exploits aren't always as stable as they should be :p
Would a 64gb USB stick be enough for me to use an installation of Kali without it filling up too fast?
Yes.
My kali VM only has 30gb of storage allocated, you should be fine unless you install a boatload of dev packages
Okay, thanks
Honestly even 16GB should be fine
Thanks - I didn't want to install it and realise that I can't do anything because there's no space left
Kali says there is a minimum of 20GB but you can install Kali in a 8GB VM so I'm sure it'll be fine :)
Thank you for your help
@eager fulcrum we were talking about disk space, not ram :) however kali only has a 1GB ram requirement
how did you run out?
Base system uses a bunch
dev packages?
Adding tools that kali is missing adds more
Then downloading extra wordlists, extra tools, payloads
base doesn't take that much honestly
but yes downloading extra stuff will indeed increase your usage by a lot
@pale ridge update metasploit if you can
i should
That CVE is known for being essentially 5050
It worked reliably from one install of kali, unreliably from another. Msf is weird sometimes
More or less identical except different hypervisors
Apt install metasploit-framework iirc
just apt upgrade metasploit-framework
Updating took it from 0% success to like 60% on my laptop's vm
No reason that it should have, but eh
Just for info, anyone who has any trouble with Kali... Just apt update and upgrade. It always seems to solve my problems.
Rolling release so it will do often
First try, updated msf, WIN
I guess I had to just update...
well not now
Im just damned
Twitter link!
@mossy ermine Thank you updated π
seem to be having VPN issues atm
getting inactivity timeouts whilst trying to work on today's challenge
same here about half an hour back
For the metasploit challenge, SSH is not responding, anyone else facing the same issue?
ok its working
hello folks. i was working in RP: Metasploit and the connection timed out, I don't have an option to deploy the machine again. can someone advise on how to proceed please?
Hello I have a problem with connect to server for day 7 .... openvpn working, machine deployed but still nothing
The machine takes a few minutes to deploy :)
yes got it ... not few but long:D
how do tryhackme boxes find ur timezone
is there a setting i missed
my time is always off by like an hour and 15 minutes
oh yeah that's it lol
π
No worries
Hi, I was wondering if it is possible to do the tasks in the Learn Burp Suite room in the THM Kali machine? I can't seem to connect to the IP for task 3.
Hmm, I managed to load the DVWA page by selecting 'No proxy' in the Firefox settings, but then I won't be able to use burp suite, so I'm a little stuck.
I think I'm in the wrong channel, sorry!
Hiya, no worries - you dont need an OpenVPN connection when onthe Kali machine
And it should just be the same standard Burp configuration on the machine
I am not sure on your experience level, have you set it up before ok?
Yeah, I've done a couple of days of advent and used burp suite for one of those, it worked fine.
Used burp inside the Kali?
So other machines work, its just DVWA machine that doesn't?
The page won't load until you manually approve every request in BURP, I assume you know that? @dusty tapir
I'd turned burp off and tried to access the IP, and it gave a proxy error.
I've managed to get it working now, but I still think I'm doing something wrong. Sadly my lunch break is over so my allotted practice time is up. π
But I'm running the sniper attack as the task says to do, and I know for a fact that one of the words in the word list is the right password, but I'm not seeing anything in the results to indicate the attack was successful. I'll just try it again later.
Ah, it actually wasnβt working. βThe proxy server is refusing connectionsβ shows as soon as I close burp suite.
if you close burp, you have to reset your proxy settings. if you tell your system to use burp as a proxy and then close burp, it's not going to get a connection. there'a handy addon on firefox with which you can do this very easily, called foxy proxy if I recall correctly @dusty tapir
Ah cool, Iβll look into it. Thank you!
Are you VPN'd?
Yes
Is it actually connected?
How are you trying to connect?
Not getting you?
Like. How are you testing your connection to the machines? What rooms have you tried? How are you trying to connect?
I have tried 25days challenge there i was trying to access the challenge 4 i think. I thought that because of day was over i wasn't able to but then i was not able to access today's machine also.
Then try to access vulnversity that one too gave no response
I tried by pinging
Only one machine gave response
How long are you leaving between deploying and trying to ping?
I thought that the challenge was for that day so deploying that machine is of no use that's why I tried deploying machine simultaneously
one by one
I mean, how much time are you leaving between pressing the deploy button and trying to ping
Maybe 1-2 minutes
The machines take time to boot, sometimes up to 10 minutes depending on load on THM
Most rooms say 3-5
Ohhh so the time was for booting okay got it
Thank you
I thought page was not up means it's not working
No problem
Got it
Also, you can do previous days challenges today
Yeah i will try to complete allπ
When making a room, how do I add a task?
But I need to set it up... Im making a room but I need to set the server up
Like
how do I set up what it has on it
nvm
Did everything get worked out?
Day13 isn't connecting for me, anyone else had issues with it? Terminated twice now
Hey just wondering if I can be marked as a student for the student premium discount?
uhhh
and then you can be
and also maybe delete your email message
unless you're okay with everyone here knowing your email
I did that
Hello I have set up open VPN however I do not understand how can I used it to connect my kali Vm to the target machine on tryhackme
Any help here?
You need to use OpenVPN on the Kali machine (follow the Linux video on https://tryhackme.com/access)
The steps are essentially:
Download the profile from https://tryhackme.com/access
Open terminal
sudo apt-get install openvpn && openvpn ~/Downloads/{username}.ovpn (Replace {username} with your username)
TryHackMe is a platform for learning and teaching cyber security.
As long as you don't close that terminal the VPN will stay connected
I normally open a new tab and have the VPn running in that one
i normally put it into tmux
Hi, I keep losing my connection to the deployed machine in day 13 || in RDP ||
do u have the vpn on in both ur vm and ur hos tmachine
You need to run it with sudo privileges @fresh stone
yes but it doessn't work @woeful stone
options error: In [CMD-LINE]:1: Error opening configuration file: Sancelisso.ovpn
Use --help for more information.
ah but i see 0kb
Whats your username on TryHackMe?
Let me check whats going on with your config file.
Sancelisso
On my end its ok
can you please try regenerating the config file
And re-downloading it
Then let me know the file size
Because I can see its 8.4Kb in our storage
not work
no
No? So its 8.4Kb?
8.2kb
Ey
There we go
Now do sudo openvpn <file name>
And you could automatically get connected
not working π¦
What is the error?
Options error: In [CMD-LINE]:1: Error opening configuration file: Sancelisso-cedo.ovpn
Use --help for more information.
What operating system are you on?
kali
Okay
the latest version
Can you please send me your configuration file (hello@tryhackme.com)
Works for me
Are you doing running the command right?
Wait
When you run it
Are you running the openvpn command in the same directory as the file?
If its in the /home/root/Downloads/ directory
you need to change directories (cd) into there
Before you do it
Or supply the full path of the file
sudo openvpn "/home/<path to file>/<file name>"
Hi :)
I have a problem with the VM of 25dayofchristmas, day13.
I'm connected to the VPN, can deploy the VM, but the ping always fails due to no response. When I for example curl the IP I see the "IIS Windows Server" screen π€
That's correct.
Okay thanks π I thought it was an error
Working on day 13 but my nmap scans aren't working against the vm. It did at one point the other day? Has this been an issue for anyone else?
Sorry this is for the Christmas Event
Thank you! I actually got into the admin portal right after I sent this. Haha
hello! please, how can I change my pseudo on TryHackMe?
Can't yet
I'm on a Kali vm with OpenVPN installed. How do I connect to the machine to complete these challenges?
I searched online but am unable to find an answer.
I entered the following into BASH "openvpn --config tawarstudents.ovpn"
Yes, I have the config file
Entered as instructed online as indicated above.
Here's the output from the terminal:
Tue Dec 17 12:45:24 2019 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Tue Dec 17 12:45:24 2019 TLS Error: TLS handshake failed
Tue Dec 17 12:45:24 2019 SIGUSR1[soft,tls-error] received, process restarting
Tue Dec 17 12:45:24 2019 Restart pause, 5 second(s)
^CTue Dec 17 12:45:28 2019 SIGINT[hard,init_instance] received, process exiting
why does nmap do this?
it's usually when I --script vuln iirc
@velvet remnant you just openvpn yourname.ovpn
no need for any other flag/option
No difference @lone urchin
Tue Dec 17 12:53:57 2019 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Tue Dec 17 12:53:57 2019 TLS Error: TLS handshake failed
Tue Dec 17 12:53:57 2019 SIGUSR1[soft,tls-error] received, process restarting
Tue Dec 17 12:53:57 2019 Restart pause, 5 second(s)
Tue Dec 17 12:54:02 2019 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.129.195:1194
Tue Dec 17 12:54:02 2019 Socket Buffers: R=[212992->212992] S=[212992->212992]
Tue Dec 17 12:54:02 2019 UDP link local: (not bound)
Tue Dec 17 12:54:02 2019 UDP link remote: [AF_INET]18.202.129.195:1194
this doesn't help, close your terminal, open again, then run openvpn yourname.ovpn and send a screenshot, where yourname.ovpn = the file you downloaded
what's kali's equivalent to windows' snipping tool?
go the menu and type "screenshot", although you can probably do this from your host as well
minimize all your windows except the vm, then go to your host and use your snipping tool
when you run the command, refresh your access page (on the site) and see what it says, does it say you're connected?
yes, it says i'm connected.
alright, so you're set
you go to a room, you join, then if there's a "Deploy" button, when you click it a VM will start which you will have access too
sorry, i'm dyslexic. i'm NOT connected
a new panel will appear that will tell you your vm's ip, that's your target
are you sure? try refreshing the page, because that output looks normal to me
command + refresh = NOT connected
maybe you've regenerated your .ovpn file and used an old one?
if you regenerate, you need to download the .ovpn file again, and use that one
for good measure do this now
delete any .ovpn files you have, click regenerate, and download a new one
OK, I'll deal with this when I get home. Thanks.
also before you do this do ifconfig and tell me if you see more than one tun# interface, so like tun0, tun1
if you see more than one, reboot your machine. if you connect with the openvpn command and then ifconfig and see one tun0 interface, then you're probably set
I don't see any tun#s
Looking for some help please, I'm connected via the openvpn, and I've deployed the machine I'm working on, but it won't find the web server on port 3000? any help appreciated
When I visit the Access page it says I'm connected too
give it a good 5 mins before you try to access it @barren trail
and make sure you're using the correct ip address. you don't want your own internal ip (the one in the access page) but the one in the room page (above your tasks)
Yes, that's it working now @lone urchin , I must have been just too keen! π Thanks for the help!
np ^^ don't worry, we've all been there π
@velvet remnant did you have any luck? I'll be off work soon and can try to chip in for getting you setup
Hello. I'm running a Kali vm and am unable to connect. Here is the feedback from the terminal. Notice the last line: Fatal Error
tony@mark-kali:/media/tony/EHD/Programs$ openvpn students.ovpn
Tue Dec 17 19:02:06 2019 OpenVPN 2.4.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Feb 20 2019
Tue Dec 17 19:02:06 2019 library versions: OpenSSL 1.1.1d 10 Sep 2019, LZO 2.10
Tue Dec 17 19:02:06 2019 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Tue Dec 17 19:02:06 2019 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Tue Dec 17 19:02:06 2019 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.129.195:1194
Tue Dec 17 19:02:06 2019 Socket Buffers: R=[212992->212992] S=[212992->212992]
Tue Dec 17 19:02:06 2019 UDP link local: (not bound)
Tue Dec 17 19:02:06 2019 UDP link remote: [AF_INET]18.202.129.195:1194
Tue Dec 17 19:02:06 2019 TLS: Initial packet from [AF_INET]18.202.129.195:1194, sid=218a6000 56ab2dfc
Tue Dec 17 19:02:06 2019 VERIFY OK: depth=1, CN=ChangeMe
Tue Dec 17 19:02:06 2019 VERIFY KU OK
Tue Dec 17 19:02:06 2019 Validating certificate extended key usage
Tue Dec 17 19:02:06 2019 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Tue Dec 17 19:02:06 2019 VERIFY EKU OK
Tue Dec 17 19:02:06 2019 VERIFY OK: depth=0, CN=server
Tue Dec 17 19:02:07 2019 Control Channel: TLSv1.2, cipher TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Tue Dec 17 19:02:07 2019 [server] Peer Connection Initiated with [AF_INET]18.202.129.195:1194
Tue Dec 17 19:02:08 2019 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Tue Dec 17 19:02:08 2019 PUSH: Received control message: 'PUSH_REPLY,route 10.10.0.0 255.255.0.0,route-metric 1000,route-gateway 10.8.0.1,topology subnet,ping 10,ping-restart 120,ifconfig 10.8.5.179 255.255.0.0,peer-id 37,cipher AES-256-GCM'
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: timers and/or timeouts modified
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: --ifconfig/up options modified
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: route options modified
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: route-related options modified
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: peer-id set
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: adjusting link_mtu to 1625
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: data channel crypto options modified
Tue Dec 17 19:02:08 2019 Data Channel: using negotiated cipher 'AES-256-GCM'
Tue Dec 17 19:02:08 2019 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Tue Dec 17 19:02:08 2019 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Tue Dec 17 19:02:08 2019 ROUTE_GATEWAY 10.0.2.2/255.255.255.0 IFACE=eth0 HWADDR=08:00:27:28:28:a3
Tue Dec 17 19:02:08 2019 ERROR: Cannot ioctl TUNSETIFF tun: Operation not permitted (errno=1)
Tue Dec 17 19:02:08 2019 Exiting due to fatal error
That worked; thanks.
It's been a little over 5 minutes and I'm unable to connect to the machine per the instrctions for task 6: http://IP:3000
Thoughts?
task 6 of what? π
do you mean advent?
you're connected to the vpn, deployed the machine and it doesnt work
okay that doesnt sound like a problem i can deal with, sorry haha
@weary token Hm, did you get it working in the end?
having an issue with jokerctf, towards the end...the container image that showed up last week isn't showing up this week
I think I had the same @tame mortar
I haven't fixed it so I'm interested if you fix it
It means the room has a recurring issue that's now known
or that π
@eager fulcrum found a way thru
@tame mortar how?
exported an image from another Linux box with lxd, then uploaded it to the jokervm and loaded it up
@deep trellis I think someone is ripping off our website: https://securitychallengeplatform.com/
Security Challenge Platform is a platform for learning and teaching cyber security.
you might want to look into it, but let me know if i'm just being stupid, lol
yeah just noticed
was looking into insight on one of the rooms i just completed
and found this
they replaced event the T&Cs with their domain name
that's stupid
That makes me incredibly sad and frustrated, I guess I shouldn't be surprised what people will do Β―_(γ)_/Β―
yo what
i'm 5th on their leaderboard
do not approve
i want 2nd π¦
their SEO is completely dead
like no one has indexed them at all
must be like a day old
looks more like a phising attack tbh
wait i just moved to 4th
oh this is exciting
yup 14 days old
Thanks @warm spear
Holy... That's like an exact ripoff
hehe
i think i stumbled upon another one
nvm that's just tryhackme.com 's public ip address being indexed by google
can they get in trouble... it doesn't look like you copyright your website ?
i'm not sure
oh never mind your copyright only shows when you are not logged in on the dashboard but it run out at the end of 2019
i mean.... yes obviously
you dont have to copyright things to own the IP, at least in the UK. like if I write something, it's mine and if other people post it pretending it to be theirs I can request a takedown and I've never failed so far
also
tryhackme is a legal company
you dont have to do anything to get copyright, you automatically get it whenever you create an original piece of work
There isn't a register of copyright works in the UK. You automatically get copyright protection when you create: original literary, dramatic, musical and artistic work, including illustration and photography. original non-literary written work, such as software, web content and databases.
cyberlaw is so interesting
Hi everyone! I'm new and I just started with the room "Advent of cyber". I deploy the machine for Day 1. I am connected to the VPN (I can access the machine for room "RP: Nmap"). When I try to access the machine through my browser, I get "Safari can't access the server" (http://10.10.179.124:3000). Did anyone got the same problem? Resolved it? Thank you!
@nocturne igloo how long have you let it deploy for?
@nocturne igloo im having the same problem, idk why i cant access the machine
Again, how long hve you let it deploy for?
at least 5 minutes
@nocturne igloo Either your VPN is not connected or you need to redeploy the machine
@nocturne igloo Yeah it's down, redeploy it.
Did it right now: http://10.10.251.17:3000. Do you manage to access it?
Maybe need too wait 3 minutes as I did it right now
What's your local time?
add an hour if you can
Yeah I'm in westcoast time but my laptop's UK. timezones messy
Yeah so that VM isn't running the service
Interesting
Yes because I could log to another room
Yes! I'll work on it now!
If someone need to investigate, don't hesitate to PM me π
yeah so it took a while to deploy
I did try 10 times today but never tried to add an hour
Seems that this triggered the deployment
I'm trying to do task 6 on day 1 and I can't seem to get the deployed machine to show up
yes
when i try to access the page it is showing as site refused to connect
sorry this is the first time I've used the site and I am just getting started
is the IP you're connecting to the one on the page for the room? @abstract onyx
And how long have you let it deploy?
And port 3000?
ohhh i see it now. that wasn't intuitive haha
i thought it meant my ip address...doh
Do you know if dirsearch is compatible with python 3.8?
nevermind. i figured it out
Any way I can change my email?
i hope this helps
+1
Task 12 (Day 7) I'm getting a Permission denied (publickey) error when trying to ssh. Am I even supposed to be accessing the machine?
I retried day 4 to see if it would let me connect on to that box and it was fine.
Oops sorry, thought I was on cyber advent room
@tame gate So I get the unroutable error IF i have a second machine connected to the VPn at the same time
I highly recommend you a) check this and b) regenerate your vpn config
ah that may be the issue
ye ill regen
it wasnt connected at the same time
however it has been connected before
thanks
hello, i have issue with access with openvpn, the log says TLS Error: Unroutable control packet received from, few days ago it's normal anyway. any solution for this ?
edit: resolved, i have issue with udp openvpn (blocked).
How long does it take to receive a password reset? Been waiting 25 minutes. Update finally received it 30 minutes total
@uncut hound It should be within a few minutes max
Oh really? Weird - we're moving over to another provider to send our emails
So the delay shouldn't be that bad in the future
Thanks for letting me know (and updating your message later too)
I'm having issues deploying machines, Hydra-ha-ha-haa was deployed for 18 minutes and still wasn't up, so I just gave up, terminated the machine and deployed ELF JS 6 minutes ago and it's still not up.
Still not up even after 11 minutes have passed.
@eager fulcrum I think there may be a server issue, can you confirm?
I can try
Thanks.
@mighty zealot I can confirm that at least one box has deployed just fine for me
Very confusing since my box is still not up.
Are you VPN'd properly?
Want to give me an IP of one of them so I can check for you?
... I'm an idiot.
vpn?
I forgot to connect to it this time
Glad it's fixed.
Wow alright thanks anyways and sorry for wasting your time ^^
Day 2 Site
Randomly Works / Stops working
Ping Doesnβt return anything when it stops working
https://i.imgur.com/DefNQc2.png
127ms Response when it does
https://i.imgur.com/9q0Wyt8.png
I just wanna be 1337 Pen Tester
I guess i'll skip Day #2 and try #3
now its happening on Day #4
_<
When using kali-linux in Virtual box the mouse randomly stops working, I can move it around the screens but clicking any of the buttons doesn't do anything.
What am i doing wrong?
Did i accidently press a hotkey that disables the mouse?
I can click on the taskbar but nothing else
@naive dust trying killing your openvpn connection and restarting it π
for the web issues
hi guys question does anyone have problems of openvpn reconnecting itself to the server and disconnecting the current connection
because was stuck on task 13 trying to find the path and got confused when the python script would hang
@unreal niche normally when you have 2 devices connected on the same ovpn profile.
could it be that me running python in the terminal
and the tryhackme site open be the cause because i use linux only
Nope. That's normal to do.
well i dont know then guess it was just during task13
i opened up ifconfig it showed two vpn enabled devices
maybe thats the cause
@vapid dawn Sorry about ping, but its still happening >_<
@naive dust You gotta wait for like ~5-10 minutes
This is the input you are about to create:
OpenVPN connectivity
Check OpenVPN connectivity - connection keeps dropping off
-- Created by: Ashu
Issue has been created by @vapid dawn!
will double check on this :)
how can I get a server rank?
Use !verify <discord token>
thx
Your discord token it found on your TryHackMe profile
oh and where do it write this comand?
Privately DM the TryHackMe bot π
oh ok thanks
hi is nfs supposed to come preinstalled on linux?
On my Kali I had to install "nfs-common"
am i dumb, or in the "The find command" room is supposed to be a VM?
i can't find it lol
@lone urchin
no vm in this room, wait
TryHackMe is a platform for learning and teaching cyber security.
sorry for the link, got confused and thought you couldn't find the room lol
have fun
ok. i'm dumb. sorry
@trail wedge I ended up having to install all the packages and libraries required to install nfs common yesterday
Hi.
I'm not receiving the email to activate account, since yesterday.
I'm using self hosted, but it's Gandi mail servers..
I checked junk mail: nothing there too.
Do you have problems with .xyz ?
I created another account, will the old account be deleted ?
@sleek otter did your new account get the email?
Also email us and we can sort out the problem
Yes I'm an idiot: the old account had a typo in the mail. And I can't seem to remember the password, too.
Update your email :)
So the account "0xTHMS" is now useless.
Ah, email us anyway and I'll see what I can do to recover the account for you
Can you give me the email please ?
Sorry I cant
I mean the email to contact you π
Done.
Cyber Advent Day 13 machine is not working for some reason. Been waiting for 20 minutes
@leaden token pings are blocked
nmap is not working too π¦
try with -Pn flag set
thanks
Hello, how do I access the website for a specific task, I followed the instructions with the IP in the middle but still can't connect
I'm using Kali machine
@storm eagle they don't all have websites
Shit, my membership ticked over
I've been inactive due to christmas
Is there any way I can cancel?
It ticked over last night :/
Shoot an email over to hello@tryhackme.com and we might be able to take care of that
Cheers!
Hope I'm in, but how do you exit out of the openvpn on Kali Linux? I've tried CTRL + C in the same terminal as the connection and sudo killall openvpn, neither of those seem to work .-.
@subtle osprey Ctrl+C should work
@lone urchin i'm not sure that works lol, on my VM i closed the openvpn tab after ctrl c and i still have the tunnel on
or it might just be a problem in 2019.4
are we talking about the browser vm? because I've never used it
no I'm on 2019.4, this hasn't happened to me
what do you mean flashy?
like flashing
no nothing like that, everything's smooth
it's like going white and black very quickly
are you using vbox?
yea
hyper-v was breaking my network for whatever reason
it was throttling my download speed to 128 kbps on both host and guest
I don't know sadly, I think it hasn't happened to me but I'll keep an eye out
you can check google/forums
i am in the bugs forum for kali and i see it's quite often. I'll just do a clean install and see if that works any better
I don't think that would help unless you've manually messed around with something
i haven't touched anything lol, i am a noob
also, my vm might be a little bit old and piled with junk from the advent calendar (forgot to do a checkpoint) π¦
if it's old then a clean install can't hurt but a few files on the disk shouldn't be a problem I think
I clean-installed 2019.4 so I can't know if it's something that occurs if you upgrade from a previous version
idk either, i'll download it again and see how it goes, those flashy screens makes me very very annoyed. https://www.reddit.com/r/Kalilinux/comments/e2zfkj/does_anyone_else_has_glitches_with_kali_20194_on/ it's also on reddit
it's stupid, lol
you're way more likely to find the answer there than from me tbh π
i guess. let's see how it goes. if it keeps flashing i might just move to parrot
or is there any other os that might stand out?
not really, but think of it more as a collection of tools than an os
if even after a clean install you have the same problem and you can't find a solution, it be worth it to look into parrot
@stone roost works for me on vbox
Wow I missed a whole convo here when you guys were trying to help! Sorry .-.
Yeah the flashy happened to me too @stone roost .
I think the disabling 3D Animations helped. Because it doesn't happen to me anymore.
And yeah, @lone urchin CTRL + C doesn't work for me, and I do it on the same terminal as my connection. However, I'm on Kali 2019.4, so it may be a bit buggy, idk.
@stone roost Have you found the solution to closing the openvpn? I got it to close, but I don't know what I did to make it close again, unfortunately .-.
@subtle osprey @eager fulcrum fresh install and fully upgraded kali seems to work fine
Sounds bout right
Alrighty then, I will try that! Thank you π
Did you uninstall VBox too, or just Kali? Trying to figure out if this is an issue of virtual box or kali
just kali
Gotcha, thanks!
seems to work fine for now
@subtle osprey didn't find a solution for the openvpn. I just stopped carrying about it loool
Aww .-. perhaps it's an issue with Kali 2019.4? I think I'll try an earlier version of Kali later to see if it works.
Might be. I have 2 vms for kali so i don't mind it that much
I'm connected via openVPN and the website
yet I can't seem to connect to the deployed machine in the room
If you run nmap can you see the open ports? Sometimes these machines take 5 minutes to boot up
is it normal for the deployed machines to take a while then?
Ah in the video tutorial it was instant
so if I'm fully connected on the access page all my openVPN stuff should be fine then?
We had a machine pre-loaded to make it quick to show people π
Hey whatβs the best place to study CHFI online
CFHI?
EC council forensics
@rigid oxide computer forensics
How credible are these trainers has anyone used them for training
Email: info@ignitetechnologies.in
Website: www.ignitetechnologies.in
I'm not personally familiar with them
@rigid oxide they only do pentest stuff, I have checked them out, Theyβre good though you can subscribe and download all the videos
@stone roost Alright, so after trying a couple things, it seems I figured out a way to disconnect the openvpn on kali linux 2019.4
- Press CTRL + C in the terminal of connection, 2. Delete ovpn file, 3. retype "sudo ovpn /path-to-file/filename.ovpn" and it should show that it cannot connect 4. Refresh the page and it should show it's not connected anymore.
There might be a more efficient method out there, but I haven't found it yet. This has worked for me a couple of times, so it should work for your 2019.4 kali machine too.
Whatβs a way to grab network traffic to analyze on wireshark if the endpoint is not connected to a siem only an edr. The end user believes they encountered the ryuk ransomware
Can you just not subscribe with a Credit/Debit card on TryHackMe.com/profile ?
I've tried different days and it always says card declined.
I'm 99% sure there isn't anything wrong with my card since i just used it to buy other stuff and there wasn't a probelm
@naive dust insufficient funds?
I have a few thousand on the card
It's likely your card company detecting the purchase as anomalous and blocking it
@chilly meadow Pentester Acad has linux+windows forensics. Might be interesting to watch. And they also have labs to practice ur skills
@naive dust Ah this is weird - it doesn't happen to be a Discover card does it?
Sorry about the trouble you're having too - if you DM me we can sort it out?
I have that so only friends can dm me haha
Because rule 1 yo
Oh just post your emotes here
You know that's the logo for TrustedSec right? https://www.trustedsec.com/
Cybersecurity consultants with expertise in penetration testing, social engineering and enterprise risk management - Learn how TrustedSec can help protect your company.
yeah I love them
and I love their logo
Mine comes from BeEF


Just passing by 





Would grabbing a memory image be the best way to figure this out since no files have been encrypted?
oof no admins, anyone have any experience setting up shared folders on oracle vm. they changed the method and cant figure it out ?
folder path on host machine and then mount point is where it will be mounted within the vm I assume
seems pretty straight forward
you would think so but it is not mounting... i pointed the folder path and have tried multiple mount points but it isnt working
@uncut hound
in the old day you just added the folder path and it would drop the folder on the desktop
I mena have you tried adding a directory specifically for it? /home is very vague and would likely screw the machine so might of refused
failing that google is your friend in this one
@mossy ermine you got the guest additions add-on on the host, and installed inside the VM? Iβd definitely change /home to something more specific too, like /mnt/files or /home/user/files
@trail widget i screwed around with oracle vm for about a hour before getting pissed and just installing vmware fusion... took me two seconds to figure it out in there
restalled my linux enviroment and am now a happy man
@mossy ermine nw. Fusion > Virtualbox anyway IMO. Glad you got up and running anyway.
yes am now going to sing praise for fusion for all to hear going forward
@rigid oxide hey man, I sent an email over re: the refund as suggested by you last wednesday, did you get it?
