#site-support

1 messages Β· Page 143 of 1

uncut hound
#

The room says 5, doesn't mean it's accurate. It's a ball park figure

rapid flax
#

Do you think it'd be ready if you're able to ping it or do you think there'd be other services and such that would start up on that system? I'm just thinking for when I try and get on later boxes. I'd assume there might be other things involved that may need to startup.

uncut hound
#

no

#

different services take different times to initialise

#

ping just means that it responds. Doesn't specify which service

#

Just run nmap as your form of knowing if it's up

rapid flax
#

So then yes, it'd take x time according to services and their startup time

uncut hound
#

it should go up in order of 111, 22, 3000

#

think that was what day 2 was for me

foggy blaze
#

It says 3000 is up now, has the name of the site on the nmap but nothing loads int the browser :/

#

3000 has been loaded for 3-4 mins noiw

uncut hound
#

are you doing ip:3000

rapid flax
#

so you're using <ip>:3000 just like yesterday?

uncut hound
#

If you do just ip it will take you to ip:80 by default and that will error

pallid gull
#

Hello, I'm always kicked from the group since yesterday, everytime I join it, I'm kicked in an hour. What is wrong?

uncut hound
#

Sounds more like a discord issue, this has been happening a fair amount recently with a few users. Audit logs have always been checked before and dont show any indication of being kicked

pallid gull
#

Yes it's really weird. Hope this will be fix soon

crimson fog
#

I can't run nmap on any of the 10.10.. ip addresses, like in RP: Nmap or in Blue

#

disregard that, now it works. I don't think I was being patient enough with letting the box load.

eager fulcrum
#

So my VPN keeps dropping out

#

Inactivity?

rigid oxide
#

VPN will automatically expire after 30 minutes of inactivity

eager fulcrum
#

I'm not inactive though @rigid oxide

#

I'm actively connecting to a host and doing a gobuster scan

#

And it's been connected for less than half an hour

rigid oxide
#

Do you possibly have two instances of the VPN up?

eager fulcrum
#

Nope, only got the one VM going and if it was on the same host it'd fail to add the route

rigid oxide
#

Hmmm

eager fulcrum
#

Gonna restart the VM and try again

#

Because it says I'm connected still on Access

rigid oxide
#

The access page can take a bit to update sometimes

eager fulcrum
#

Still showing connected

rigid oxide
#

Run this by Skidy once he's on in a bit, he might have a better idea of some troubleshooting

eager fulcrum
#

It's working, I'm just getting HTTP timeouts rn more often than usual. Heading to a practical session and I'll try again later

coral palm
#

hello... does the vm for christmas challenge 2 take more than 10 minutes to become available?

warm spear
#

no!

#

shouodnt do πŸ™‚

coral palm
#

or is finding the target machine part of the challenge too?

warm spear
#

nope

#

it'll give you the IP

#

actually, you should already have the Ip address

#

when you click "deploy" the IP address appears near the top of the page

coral palm
#

yes, i have that... its a 10.10.x.x ip... but if i go to it in a browser, i get a message this site cant be reached... and im on the vpn... the network access says that I have an internal virtual ip address of 10.8.x.x

warm spear
#

Yup! Sounds right. Have you nmapped the machine?

coral palm
#

not yet... let me try

#

ah, is that part of the challenge? thanks for the tip πŸ™‚

warm spear
#

Yup! It is πŸ™‚

#

Generally speaking, every single machine you'll do will require nmap πŸ™‚ If you're not used to using tools, the 3 most used tools are nmap, a directory searcher (I use gobuster but dirb comes with kali), and metasploit. 2 of these tools are required for this challenge πŸ˜„

coral palm
#

ah got it... thank you so much!

vapid dawn
#

For the Christmas challenges in particular, we'll talk about scanning if need be

#

For this, the port number to be used is specified in the task

warm spear
rustic hollow
#

it's in the previous task. tripped me up at first, too.

vapid dawn
#

Ah is it not

#

I must have accidentally removed it

#

Will add it in

#

Sorry about that all

#

Port is 3000 btw

rapid flax
#

It's no problem, but (for what it's worth) myself and other users discussed how kicking off recon with Nmap is usually a good start πŸ˜‰

deep trellis
#

@eager fulcrum Is the VPN still playing up?

eager fulcrum
#

Haven't tried, was in a lecture. Had some issues with it after restarting and reconnecting

#

Just dropped packets

#

Will give it another go later

deep trellis
#

Okay thanks

mossy ermine
#

you website tryhackme is down

#

your*

#

500 internal server error

steel rapids
#

@deep trellis

#

@rigid oxide DORK STORK SERVER BORK

rigid oxide
#

WAT

#

Ah one sec

odd mica
#

lmao

mossy ermine
#

i swear you people are just trying to make studing hard just for me

rigid oxide
#

...maybe today is the day we get load balancing finished...

#

Talking with the others now, we'll get that back up asap

mossy ermine
#

no worries 🀣

pale ridge
#

Is it down?

eager fulcrum
#

Yes @pale ridge

pale ridge
#

Oh noes

deep trellis
#

Eyo

#

I hear the site went down?#

thorn badger
#

Yes

deep trellis
#

Investigating

#

I was out at my Tennis lesson

#

Can anyone tell me the time it went down?

#

Roughly that is

thorn badger
#

Around 1.40 IST

deep trellis
#

Thanks

steel rapids
#

TIL Skidy plays tennis

deep trellis
#

🎾

eager fulcrum
#

@deep trellis I can confirm I'm still getting packets dropping etc that shouldn't be

#

Didn't time me out for inactivity now but my nmap scan at default timings reported dropped probes which never usually happens

deep trellis
#

OKay Ill restart the OpenVPN later

#

Let me know when you're around

rain hawk
#

@here what if I overwritten mrinvetory password and loged in then, accessed his inventory requests?

#

answear is correct neverthless

eager fulcrum
#

Then that's a valid method.

rain hawk
#

(NO SPOILERS HERE -acutally didn't told how to to something, and stuff here know what about am i talking)

#

ok...

eager fulcrum
#

I don't think you will be able to though.

#

You can't overwrite the password unless there's some SQL injection attack or something, and I very much doubt there will be.

rain hawk
#

well, the day 1 is about cookies, and yet i know the "correct method" for this challange

#

i just registered with mcinventory username

#

lol

uncut hound
#

If that’s day one

eager fulcrum
#

Wait and that worked?

uncut hound
#

Yes you can do that

rain hawk
#

yup

uncut hound
#

In fact that’s the method I used

eager fulcrum
#

Haha, ok. Unexpected

rain hawk
#

funny though

#

but works

dusty tapir
#

Hi guys. I'm a complete noob to all of this so forgive me if I sound like an idiot... but I can't get the Kali machine to work. It keeps crashing no matter what I do.

spare blaze
#

The kali machine from THM? Or your virtual machine?

dusty tapir
#

the one from THM. I don't have all the programs I would need, so I've been trying to use the Kali machine

#

I've opened it in the browser, I've RDPd, but it keeps crashing.

spare blaze
#

That is going to be an Admin matter, I won't be of any help, I am sure they will answer very quickly ;)

dusty tapir
#

No worries, thank you. πŸ™‚

rigid oxide
#

@dusty tapir how much ram does your machine have? It may be that the system doesn't have enough memory to support the connection. Unlikely but sometimes the case here

dusty tapir
#

Ah, that could be the case since I'm only using a laptop. I have 8gb.

rigid oxide
#

Oh gosh that should be plenty

#

hmm

#

Is the machine itself crashing or just the connection?

dusty tapir
#

It seems to be the connection. Basically, I stop being able to click on anything in the VM itself, and the box on the Kali page will say I've been disconnected.

naive dust
#

I have a problem with hashcat, I always got this error message, can someone help me or explain what is he problem? trooper@TrainingVM ~/Downloads $ hashcat -m 1800 buddy rockyou.txt --force
hashcat (v5.1.0) starting...

clGetDeviceIDs(): CL_DEVICE_NOT_FOUND

clGetDeviceIDs(): CL_DEVICE_NOT_FOUND

No devices found/left.

Started: Tue Dec 3 23:19:59 2019
Stopped: Tue Dec 3 23:19:59 2019
trooper@TrainingVM ~/Downloads $

rigid oxide
#

@naive dust for a quick fix, have you tried using John the Ripper?

#

@dusty tapir what browser are you using?

dusty tapir
#

Chrome, but I'm also trying to RDP into it with the same issues.

naive dust
#

yes but I am not familiar with John, it run but asked me to specify the format at the end

rigid oxide
#

If you don't mind, trying rebooting your computer @dusty tapir

dusty tapir
#

No problem. I'm going to try one more time and then I'll reboot if it doesn't work.

rigid oxide
#

That's quite strange with the VM, have you tried Firefox by change?

naive dust
#

ok I will try tomorrow, thx

steel rapids
#

if it adds anything, my conn to guacamole boxes is a bit hit and miss also

naive dust
#

I gave a try again and end up with that:

#

john --format=sha512crypt --wordlist rockyou.txt buddy
Warning: invalid UTF-8 seen reading rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (sha512crypt, crypt(3) $6$ [SHA512 32/32 OpenSSL])
No password hashes left to crack (see FAQ)

uncut hound
#

You haven’t specified a hash

mossy ermine
#

on a side note the login does not recognize with just nick and password... requires a email/pass to work.

#

probably causing a few locked out usernames

uncut hound
#

your john command should look like john hash /usr/share/wordlist/rockyou.txt

eager fulcrum
#

@mossy ermine The tryhackme login?

mossy ermine
#

yes @eager fulcrum

eager fulcrum
#

Welp, looks like it's a confirmed issue then

#

I raised it with Skidy like a week or so back

mossy ermine
#

easy fix just remove the login text saying you can use nick as a valid login and vola no more headaches

naive dust
#

Yo... ummm

#

Im on another PC than usual... and forgot what password I used

#

I don't want to reset it, is there some way I can see what it was? my login was incorrect so Im locked out

#

Anyway I could do that?

warm spear
#

what OS?

#

tbh this seems like a perfect test of your hacking skills hahaha

naive dust
#

windows

#

Otherwise I happily would πŸ˜‚

#

(of course with prior permission πŸ˜‰ )

odd mica
#

yes

#

no illegals

lone urchin
#

I keep bugging people to use a password manager for situation including but not limited to this πŸ˜›

uncut hound
#

lol

#

just reset it πŸ˜‚

naive dust
#

I dont want to πŸ˜‚

#

If Im forced to I will tho

uncut hound
#

πŸ€”

#

there is no way in this world any site will show you your password

#

as if they do it for one, then it's a vuln for other accounts

naive dust
#

Man

lone urchin
#

it won't if it's properly configured

#

passwords are stored as hashes

uncut hound
#

still

naive dust
#

the windows email thing takes forever to load

uncut hound
#

It's a security risk

#

ya'll don't live in the real world if you think they'd just reach in and grab it for you xD

naive dust
#

I wasn't expecting that... I was wondering if I could do it in a way where I could reuse an old password

uncut hound
#

Oh yeah you can

#

you can reset

#

then reset back to an old password I beleive

#

closest you'd get tho

naive dust
#

Okay

last olive
#

Someone please make a moderate level room or recommend one.

eager fulcrum
last olive
#

Oh crap, I couldn't see that channel

#

Dumb me

mossy ermine
#

ssh doesnt seem to be open on my box, can i get someone to check 10.10.76.96 for port 22

eager fulcrum
#

@mossy ermine How long has it been deployed?

#

It takes like 3+min

mossy ermine
#

oh my bad thought that was just the web services ports, it worked for me now

inland nebula
#

it's been 15 minutes since i deployed the machine; port 22 is not active

#

earlier, i waited around 30 minutes to find that I am still not connected

lone urchin
#

what's the output you're getting? have you checked the vpn?

inland nebula
#

yes, vpn checked

lone urchin
#

so what does it say when you're trying to connect?

inland nebula
#

This site can’t be reachedThe webpage at http://10.10.105.253:22/ might be temporarily down or it may have moved permanently to a new web address.
ERR_UNSAFE_PORT

pseudo kiln
#

Its not a site, you have to ssh into that port

lone urchin
#

yup, command is ssh user@ipaddress

#

you don't need to specify a port since 22 is default for ssh

inland nebula
#

it running now

naive dust
#

Okay

#

ssh isnt working in the kali browser thing

#

do I have to use the VPN in that?

lone urchin
#

what do you mean? which challenge are you on

naive dust
#

todays

lone urchin
#

you always have to use the vpn when interacting with a machine, yes

naive dust
#

Im using the subscriber kali vm

#

from THM

lone urchin
#

I'm not sure about that actually, I'm not a subscriber

#

I suppose so though

light bluff
#

am i the only one not having questions to answer for the last challenge

uncut hound
#

if that's the case try leaving the room and reentering

jagged crown
#

can anybody help me?

late atlas
#

@naive dust I wouldn't think so. I've never used the VM though. The boxes do take a little while to start up fully after deploying though

lone urchin
#

@light bluff I'm a little but that exact thing happened to a few of us yesterday. For me it was fixed by leaving the room and reentering, as suggested by someone here

deep trellis
#

Hi @jagged crown Whats up?

mystic dust
#

Hello @deep trellis Did I need to sign up to tryhackme with my university email to get the discount? I didn't realise there was a student subscription option until I signed up with my personal email address and I cant seem to find a student area

snow oriole
#

That’s a @deep trellis question @mystic dust

mystic dust
#

Ah, thankyou mate

snow oriole
#

^^

rigid oxide
#

@mystic dust email hello@tryhackme.com with that question and we can get it all sorted out. Be sure to send the message with your student email.

mystic dust
#

Will do, thankyou @rigid oxide

trim karma
#

Any help. Machine keep disconnecting. Cant do anything

odd mica
#

@trim karma First check that you're connected through ovpn, wait around 10 minutes and if that doesn't work, let us know

trim karma
#

I'm already connected.
I did some tasks, but it keep disconnecting and reconnect again and again

odd mica
#

What SSH client are you using?

trim karma
eager fulcrum
#

That connected.

#

Are you sure your VPN isn't cutting out?

trim karma
#

It works now after restarting my kali

eager fulcrum
#

Probably VPN dropping out

trim karma
#

Thanks anyway

deep trellis
#

I am going to restart the VPN

eager fulcrum
#

@trim karma Screenshot of the openvpn command output?

trim karma
eager fulcrum
#

And your kali VM is definitely connected to the internet?

trim karma
#

Yes

#

Do i need to regenerate my config file?

lone urchin
#

if you do that, you'll have to download it again and run openvpn again

#

if I understood your question correctly

trim karma
#

I mean maybe there's a problem with my config file

eager fulcrum
#

@trim karma try dig tryhackme.com

#

Something's getting in the way

trim karma
eager fulcrum
#

OK, it resolves just fine

#

And your OpenVPN doesn't connect properly?

trim karma
#

Same issue

eager fulcrum
#

That's a normal output

#

Weird that yours sets the adapter before all the TLS

trim karma
eager fulcrum
#

Looks like it worked

trim karma
#

But after a while it will rest

#

I will see.
If didn't work
You have to give me the answer of #7 😁

eager fulcrum
#

huh?

trim karma
#

Just kidding

mossy ermine
#

can we get a little more resources added to the kali box, keeps freezing on me with no way to kill processes

deep trellis
#

@mossy ermine Our cloud infastructure costs this month are rather high due to the Christmas event. If others are having similar issues, I can bump the machines resources for all Kali instances. As for now, I am going to keep it on using lower resources (which is still 4GB RAM + 3GHz CPU).

#

Hope you understand πŸ™‚

mossy ermine
#

@deep trellis cool am happy to have just to have it on the to do list

deep trellis
#

If its really bad, I will increase it - don't want it to effect your functionality

mossy ermine
#

but in return you have to recognize me a chill guy... which is very important distinction

deft root
#

I can no access any of the site while on my VM kali (v-box) but can on my local box. Anyone experience the same thing?

wispy sundial
#

openvpn inside the vm?

late atlas
#

Does your Kali VM have internet access at all?

north palm
#

@deep trellis You helped me last week with an issue deploying VMs. I worked around it in the end by using FF instead of Chrome. I just wanted to let you know that the problem seems to lay with Eset Nod32 Antivirus. If I add https://tryhackme.com/ as a URL whitelist then machines deploy ok. I worked this out as when trying to download the jpg from the advent Day 5 task, the item was blocked as THM is on a list of blocked websites...

deep trellis
#

@north palm This is really useful to know

#

Thanks for informing me!

north palm
#

No problem. Just thought it might help if others contact you

late atlas
#

@deep trellis I've submitted a false-positive report to Eset for the domain

deep trellis
#

@late atlas amazing, really appreciated!

late atlas
#

<3

#

I'm just waiting for some WPA2 handshakes to crack so, I got time to spare jaha

north palm
#

FYI it was the /deploy part specifically

late atlas
#

@north palm Thanks, I'll pass that on if they push back

late atlas
#

Response received from Eset. Domain is being removed from blacklist

north palm
#

Nice one

snow oriole
#

Hmmm... kinda strange that thm got blacklisted...

late atlas
#

Eh, not surprising... See false-positives like this quite often

snow oriole
#

Mwell

#

I’m runnin linux as main os

#

So...

#

Got a win10 in vm for the times i gotta do presentations and stuff, but that’s it

eager fulcrum
#

Yep

#

||It comes up on the screen|| @warm spear

warm spear
#

Everytime I join a room, all tasks are completed. Leaving & rejoining does nothing. This happens to every room, regardless of its age. Only been happening for the last 10 mins or so πŸ™‚

deep trellis
#

Hm

#

Relaly?

#

Hi @warm spear Can you try again please?

#

Is this for every room?

#

Just tested on my end its fine hm

#

Someone else the same issue earlier tho

spare blaze
#

(nothing on my end, btw)

warm spear
#

fixed!

#

thanks!

deep trellis
#

Weird sorry about that

warm spear
#

first timethis has happened to me haha

deep trellis
#

Really weird

#

Not sure

#

If it happens again and the issues persists, lemme know

lone urchin
#

That happened to me on the two days before yesterday

#

Yesterday it was ok

#

Had to leave and rejoin and it was OK, happened only on the Christmas room tho

copper mist
#

@deep trellis, I could be wrong but two badges should be showing on my profile. Any idea? Mr Robot and CTF. Working towards Linux one now

naive dust
#

Not all have badges

#

I’ve finished 10 rooms with 3 badges

copper mist
#

These two have badges, on the site πŸ™‚

naive dust
#

Did you finish every answer? Make sure to click completed next to questions with no answers

copper mist
#

Yeah, it has a green tick

lone urchin
#

Mr. Robot is sub only?

naive dust
#

Hmmmm

#

I don’t think it is @lone urchin

lone urchin
#

woot, gonna do it after lunch

late atlas
#

Yeah, I still don't have the Blue badge either - May still be on Skid's TODO list, not exactly a critical issue haha

deep trellis
#

@late atlas if you want the blue badge DM me with your username πŸ™‚

#

@copper mist Ah - some badges were added after people completed, gimme your username and I will have it updated

naive dust
#

Man

copper mist
#

@deep trellis WillGreen98 πŸ™‚

#

@deep trellis, cheers bud πŸ™‚ WillGreen98

mossy ermine
#

is there anyway to allow copy and paste between web kali and local machine. i know in remote desktop you can enable it in the options ?

lone urchin
#

do you use virtualbox?

eager fulcrum
#

Web kali

#

So the THM VM

lone urchin
#

ohh my bad

eager fulcrum
#

So it should work, chrome requests access to your clipboard @mossy ermine

mossy ermine
#

oh been useing firefox

eager fulcrum
#

IDK about firefox

mossy ermine
#

lol

naive dust
#

Won’t work in ff

burnt holly
#

Hey moderators can someone please check port 999 of today's machine

#

I think service got crashed and you should restart it so that everyone can complete today's challenge

zealous yoke
#

Is there any way I can manually provide my University email for my HackMe account that has a non ac.uk domain registered to get the student discount?

spare blaze
zealous yoke
#

roger-dodger, I'll give 'em a buzz. Cheers!

eager fulcrum
#

@zealous yoke from your acuk email prefereably

naive dust
#

how do i stop this from happenign?

dusty tapir
#

Hi. πŸ™‚ I’m still having trouble with the kali machine (the THM one). I figured out that clicking commands too quickly was causing it to crash so I’ve been slowly working through the initial setup screens, but then as soon as I try to launch an application of any kind, it crashes again.

This has happened on two machines that I’ve tried it on.

uncut hound
#

Sounds like something @deep trellis can look into further

eager fulcrum
#

@naive dust Restart the system, at least that worked for me

bronze jetty
#

can anyone explains how XXE works ?

late atlas
#

Have you checked out the info on the portswigger site? https://portswigger.net/web-security/xxe

trim karma
#

this is unbearable guys,

each time i connect to the network and access today's machine, the vpn restart and i have to wait for about 5 min in order to access the machine again, and it reset again.

i spent my whole day just trying to write a single command.

is it my machine problem? or the network?

late atlas
#

I haven't connected today but, your report is the first I've seen saying there are connection issues so, it's probably unlikely to be the THM server(s)

trim karma
#

it was fine in the morning, i did #1,2,3 but trying for few hours now on #4 but it keep rest

late atlas
#

You just letting the VPN disconnect and reconnect or have you tried killing your ovpn client and starting it again?

trim karma
#

@late atlas even regenerate my config file

supple sonnet
#

@trim karma could you run an ifconfig and paste the output here?

late atlas
#

Have you tried the clichΓ© 'turn it off and on again' on your vm? Haha

trim karma
late atlas
#

You appear to have 2 tun interfaces

wispy sundial
#

have to chime in here

trim karma
#

thats mean?

wispy sundial
#

i had to restart the vpn connection earlier every min or so

#

like 6ish hours ago

#

not sure if the vpn server or my own connection though

late atlas
#

@trim karma Reboot your machine and connect to the VPN again

trim karma
#

@late atlas i hope this will work

#

@late atlas it did work, :), but its slow

late atlas
#

Not much I can do to help with that haha
The connection issue was probably the two tun interfaces fighting eachother. Glad it's working for you now though

naive dust
#

Hello I managed to get connected with site's server but I can't connect to the machines .Here is the last messages in terminal
RTNETLINK answers: File exists
ERROR: Linux route add command failed: external program exited with error status: 2
WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Initialization Sequence Completed

steel rapids
#

Kill your openvpn process, then run:
killall openvpn
and then try running the vpn again

naive dust
#

I tried it but I can't connect the deployed machine.On the access page it shows that I am connected

lone urchin
#

did you give it time?

supple sonnet
#

A general rule of thumb for troubleshooting OpenVPN issues:

  • Run an ifconfig, if there are multiple tunX interfaces, restart your machine.
naive dust
#

yes it changed my virtual ip and I tried again .I will restart and I will do it again thank you

eager fulcrum
#

@open crater it shouldn't change your VPN IP

naive dust
#

I restarted my OS and did the process again but still I can't connect to the deployed machine

#

ifconfig command shows a tun0 and under it an (UNSPEC
)

#

Any ideas ?

late atlas
#

If you're still getting ERROR: Linux route add command failed: external program exited with error status: 2 - That is probably your issue

naive dust
#

No I am not getting that error.I am not getting any errors

supple sonnet
#

kill the VPN

#

run an
ifconfig tun0 down

#

re-initialize the VPN connection

livid osprey
#

If I get a status 'exausted' from hashcat does that mean that no password was found?

eager fulcrum
#

@livid osprey it means your wordlist or dict or keyspace didn't have the password

livid osprey
#

Okay, thanks πŸ‘

#

aha got it working now, just didn't do the command correctly

mossy ermine
#

hey your twitter discord link isnt working... but the one on the website does... though you should know

fringe flicker
#

hi. no matter what i do, i cant seem to connect to the Open VPN Virtual IP.

It shows i am connected on this page(https://tryhackme.com/vpn/regen-config) and in the OpenVPN GUI.
but I can't connect to my Internal Virtual IP Address. or am I not supposed to do that?

eager fulcrum
#

@fringe flicker your internal address is your IP on the VPN. How are you trying to connect to your own machine?

#

In the browser, it wouldn't work unless you had a web server running

#

Pretty sure you shouldn't need to connect to your VPN IP in any way, but you need to use it sometimes when things connect back to you

fringe flicker
#

so im trying to do do advent calender(thought it was a more a tech question so i asked here)
and the 1st task is asking me to "Deploy the machine and access the website at http://<your_machines_ip>:3000"

eager fulcrum
#

Yep so that's a bit vaguely worded. It means the IP of the machine you deployed in the room

fringe flicker
#

how do i get that?

eager fulcrum
#

Click the deploy button, and at the top of the room below the leaderboard it will say the IP of the VM

fringe flicker
#

oh. i had to refresh the page to see it

#

thanks :)

eager fulcrum
#

Weird, unless you deployed it from another browser instance

pale ridge
#

Need help on Room Blue, metasploit fails to exploit with an unknown reason

#

never mind, finally worked

mighty zealot
#

Yeah I had the same problem, sometimes you just need to reset the room and it'll work, exploits aren't always as stable as they should be :p

livid osprey
#

Would a 64gb USB stick be enough for me to use an installation of Kali without it filling up too fast?

mighty zealot
#

Yes.

steel rapids
#

My kali VM only has 30gb of storage allocated, you should be fine unless you install a boatload of dev packages

livid osprey
#

Okay, thanks

mighty zealot
#

Honestly even 16GB should be fine

livid osprey
#

Thanks - I didn't want to install it and realise that I can't do anything because there's no space left

mighty zealot
#

Kali says there is a minimum of 20GB but you can install Kali in a 8GB VM so I'm sure it'll be fine :)

livid osprey
#

Thank you for your help

eager fulcrum
#

@mighty zealot 8GB of ram.

#

Is like ideal

#

You need a decent amount of disk

mighty zealot
#

@eager fulcrum we were talking about disk space, not ram :) however kali only has a 1GB ram requirement

eager fulcrum
#

I ran out of disk with 20GB

#

No wait

#

30

#

I hqd to bump it to 40

mighty zealot
#

how did you run out?

eager fulcrum
#

Base system uses a bunch

steel rapids
#

dev packages?

eager fulcrum
#

Adding tools that kali is missing adds more

#

Then downloading extra wordlists, extra tools, payloads

mighty zealot
#

base doesn't take that much honestly

#

but yes downloading extra stuff will indeed increase your usage by a lot

pale ridge
#

Still facing the same issue again

#

This is so unstable

eager fulcrum
#

@pale ridge update metasploit if you can

pale ridge
#

i should

steel rapids
#

That CVE is known for being essentially 5050

eager fulcrum
#

It worked reliably from one install of kali, unreliably from another. Msf is weird sometimes

#

More or less identical except different hypervisors

pale ridge
#

1 GB update available

#

I'll check later

eager fulcrum
#

Apt install metasploit-framework iirc

pale ridge
#

just apt upgrade metasploit-framework

eager fulcrum
#

Updating took it from 0% success to like 60% on my laptop's vm

#

No reason that it should have, but eh

pale ridge
#

Just for info, anyone who has any trouble with Kali... Just apt update and upgrade. It always seems to solve my problems.

eager fulcrum
#

Rolling release so it will do often

pale ridge
#

First try, updated msf, WIN

#

I guess I had to just update...

#

well not now

#

Im just damned

mossy ermine
deep trellis
#

@mossy ermine Thank you updated πŸ˜„

woeful stone
#

seem to be having VPN issues atm

#

getting inactivity timeouts whilst trying to work on today's challenge

lone urchin
#

same here about half an hour back

short forum
#

hi

#

can we give the host for today's challenge a little more resources?

severe furnace
#

For the metasploit challenge, SSH is not responding, anyone else facing the same issue?

#

ok its working

night vapor
#

hello folks. i was working in RP: Metasploit and the connection timed out, I don't have an option to deploy the machine again. can someone advise on how to proceed please?

jagged crown
#

Hello I have a problem with connect to server for day 7 .... openvpn working, machine deployed but still nothing

vapid dawn
#

The machine takes a few minutes to deploy :)

jagged crown
#

yes got it ... not few but long:D

sick shard
#

how do tryhackme boxes find ur timezone

#

is there a setting i missed

#

my time is always off by like an hour and 15 minutes

deep trellis
#

It should use your local time @sick shard

#

What time zone are you in?

sick shard
#

central

#

oh maybe

#

my vm isnt

deep trellis
#

Yeah lots of people do that aha πŸ™‚

#

They forget to update

sick shard
#

oh yeah that's it lol

deep trellis
#

πŸ™‚

sick shard
#

:)

#

thanks xD

deep trellis
#

No worries

dusty tapir
#

Hi, I was wondering if it is possible to do the tasks in the Learn Burp Suite room in the THM Kali machine? I can't seem to connect to the IP for task 3.

#

Hmm, I managed to load the DVWA page by selecting 'No proxy' in the Firefox settings, but then I won't be able to use burp suite, so I'm a little stuck.

#

I think I'm in the wrong channel, sorry!

deep trellis
#

Hiya, no worries - you dont need an OpenVPN connection when onthe Kali machine

#

And it should just be the same standard Burp configuration on the machine

#

I am not sure on your experience level, have you set it up before ok?

dusty tapir
#

Yeah, I've done a couple of days of advent and used burp suite for one of those, it worked fine.

deep trellis
#

Used burp inside the Kali?

#

So other machines work, its just DVWA machine that doesn't?

eager fulcrum
#

The page won't load until you manually approve every request in BURP, I assume you know that? @dusty tapir

dusty tapir
#

I'd turned burp off and tried to access the IP, and it gave a proxy error.
I've managed to get it working now, but I still think I'm doing something wrong. Sadly my lunch break is over so my allotted practice time is up. πŸ™‚

#

But I'm running the sniper attack as the task says to do, and I know for a fact that one of the words in the word list is the right password, but I'm not seeing anything in the results to indicate the attack was successful. I'll just try it again later.

#

Ah, it actually wasn’t working. β€œThe proxy server is refusing connections” shows as soon as I close burp suite.

lone urchin
#

if you close burp, you have to reset your proxy settings. if you tell your system to use burp as a proxy and then close burp, it's not going to get a connection. there'a handy addon on firefox with which you can do this very easily, called foxy proxy if I recall correctly @dusty tapir

dusty tapir
#

Ah cool, I’ll look into it. Thank you!

rigid swallow
#

Unable to access any machine don't know whay

#

*why

eager fulcrum
#

Are you VPN'd?

rigid swallow
#

Yes

eager fulcrum
#

Is it actually connected?

rigid swallow
#

Yeah it showed connected and green tick

#

I was able to ping one machine

eager fulcrum
#

How are you trying to connect?

rigid swallow
#

Not getting you?

eager fulcrum
#

Like. How are you testing your connection to the machines? What rooms have you tried? How are you trying to connect?

rigid swallow
#

I have tried 25days challenge there i was trying to access the challenge 4 i think. I thought that because of day was over i wasn't able to but then i was not able to access today's machine also.
Then try to access vulnversity that one too gave no response

#

I tried by pinging

#

Only one machine gave response

steel rapids
#

How long are you leaving between deploying and trying to ping?

rigid swallow
#

I thought that the challenge was for that day so deploying that machine is of no use that's why I tried deploying machine simultaneously

#

one by one

steel rapids
#

I mean, how much time are you leaving between pressing the deploy button and trying to ping

rigid swallow
#

Maybe 1-2 minutes

steel rapids
#

The machines take time to boot, sometimes up to 10 minutes depending on load on THM

copper mist
#

Most rooms say 3-5

rigid swallow
#

Ohhh so the time was for booting okay got it

#

Thank you

#

I thought page was not up means it's not working

#

No problem

#

Got it

steel rapids
#

Also, you can do previous days challenges today

rigid swallow
#

Yeah i will try to complete allπŸ‘Œ

naive dust
#

When making a room, how do I add a task?

rigid oxide
#

Link on the right hand side under manage

#

*left hand

naive dust
#

Ah, didn't see that

#

thanks

#

Now how do I make the deployable IP?

#

@rigid oxide

warm spear
#

you dont

#

its made dynamically when the user deploys the room

#

the vm*

naive dust
#

But I need to set it up... Im making a room but I need to set the server up

#

Like

#

how do I set up what it has on it

#

nvm

rigid oxide
#

Did everything get worked out?

copper mist
#

Day13 isn't connecting for me, anyone else had issues with it? Terminated twice now

graceful zenith
#

Hey just wondering if I can be marked as a student for the student premium discount?

warm spear
#

uhhh

#

email

#

and then you can be

#

and also maybe delete your email message

#

unless you're okay with everyone here knowing your email

graceful zenith
#

I did that

robust sandal
#

Hello I have set up open VPN however I do not understand how can I used it to connect my kali Vm to the target machine on tryhackme

#

Any help here?

trail wedge
#

You need to use OpenVPN on the Kali machine (follow the Linux video on https://tryhackme.com/access)

The steps are essentially:
Download the profile from https://tryhackme.com/access
Open terminal
sudo apt-get install openvpn && openvpn ~/Downloads/{username}.ovpn (Replace {username} with your username)

#

As long as you don't close that terminal the VPN will stay connected

eager fulcrum
#

I normally open a new tab and have the VPn running in that one

warm spear
#

i normally put it into tmux

severe furnace
#

Hi, I keep losing my connection to the deployed machine in day 13 || in RDP ||

sick shard
#

do u have the vpn on in both ur vm and ur hos tmachine

severe furnace
#

Im not using VM

#

I have VPN in my host

fresh stone
#

openvpn Sancelisso.ovpn doesn't work for me

#

i have already installed openvpn

woeful stone
#

You need to run it with sudo privileges @fresh stone

fresh stone
#

yes but it doessn't work @woeful stone

#

options error: In [CMD-LINE]:1: Error opening configuration file: Sancelisso.ovpn
Use --help for more information.

deep trellis
#

How large is the OpenVPN file @fresh stone

#

Should like like 8.4Kb

fresh stone
#

ah but i see 0kb

deep trellis
#

Whats your username on TryHackMe?

#

Let me check whats going on with your config file.

fresh stone
#

Sancelisso

deep trellis
#

On my end its ok

#

can you please try regenerating the config file

#

And re-downloading it

#

Then let me know the file size

#

Because I can see its 8.4Kb in our storage

fresh stone
#

not work

deep trellis
#

What happened?

#

Still at 0Kb?

fresh stone
#

no

deep trellis
#

No? So its 8.4Kb?

fresh stone
#

8.2kb

deep trellis
#

Ey

#

There we go

#

Now do sudo openvpn <file name>

#

And you could automatically get connected

fresh stone
#

not working 😦

deep trellis
#

What is the error?

fresh stone
#

Options error: In [CMD-LINE]:1: Error opening configuration file: Sancelisso-cedo.ovpn
Use --help for more information.

deep trellis
#

What operating system are you on?

fresh stone
#

kali

deep trellis
#

Okay

fresh stone
#

the latest version

deep trellis
fresh stone
#

ok

#

file sent

deep trellis
#

Works for me

#

Are you doing running the command right?

#

Wait

#

When you run it

#

Are you running the openvpn command in the same directory as the file?

#

If its in the /home/root/Downloads/ directory

#

you need to change directories (cd) into there

#

Before you do it

#

Or supply the full path of the file

#

sudo openvpn "/home/<path to file>/<file name>"

fresh stone
#

you're right

#

it is orking now

#

thankss

#

working*

tired fox
#

Hi :)
I have a problem with the VM of 25dayofchristmas, day13.
I'm connected to the VPN, can deploy the VM, but the ping always fails due to no response. When I for example curl the IP I see the "IIS Windows Server" screen πŸ€”

rigid oxide
#

That's correct.

tired fox
#

Okay thanks πŸ™‚ I thought it was an error

obtuse delta
#

Working on day 13 but my nmap scans aren't working against the vm. It did at one point the other day? Has this been an issue for anyone else?

#

Sorry this is for the Christmas Event

warm spear
#

hallo!

#

nmap -p- -A -sC -vvv -Pn

#

should work πŸ™‚

obtuse delta
#

Thank you! I actually got into the admin portal right after I sent this. Haha

surreal moth
#

hello! please, how can I change my pseudo on TryHackMe?

naive dust
#

Can't yet

velvet remnant
#

I'm on a Kali vm with OpenVPN installed. How do I connect to the machine to complete these challenges?

#

I searched online but am unable to find an answer.

deep trellis
#

@narrow needle What do you mean?#

#

Have you downloaded your configuration path?

velvet remnant
#

I entered the following into BASH "openvpn --config tawarstudents.ovpn"

#

Yes, I have the config file

#

Entered as instructed online as indicated above.

#

Here's the output from the terminal:

#

Tue Dec 17 12:45:24 2019 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Tue Dec 17 12:45:24 2019 TLS Error: TLS handshake failed
Tue Dec 17 12:45:24 2019 SIGUSR1[soft,tls-error] received, process restarting
Tue Dec 17 12:45:24 2019 Restart pause, 5 second(s)
^CTue Dec 17 12:45:28 2019 SIGINT[hard,init_instance] received, process exiting

lone urchin
#

why does nmap do this?

#

it's usually when I --script vuln iirc

#

@velvet remnant you just openvpn yourname.ovpn

#

no need for any other flag/option

velvet remnant
#

No difference @lone urchin

#

Tue Dec 17 12:53:57 2019 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Tue Dec 17 12:53:57 2019 TLS Error: TLS handshake failed
Tue Dec 17 12:53:57 2019 SIGUSR1[soft,tls-error] received, process restarting
Tue Dec 17 12:53:57 2019 Restart pause, 5 second(s)
Tue Dec 17 12:54:02 2019 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.129.195:1194
Tue Dec 17 12:54:02 2019 Socket Buffers: R=[212992->212992] S=[212992->212992]
Tue Dec 17 12:54:02 2019 UDP link local: (not bound)
Tue Dec 17 12:54:02 2019 UDP link remote: [AF_INET]18.202.129.195:1194

lone urchin
#

this doesn't help, close your terminal, open again, then run openvpn yourname.ovpn and send a screenshot, where yourname.ovpn = the file you downloaded

velvet remnant
#

what's kali's equivalent to windows' snipping tool?

lone urchin
#

go the menu and type "screenshot", although you can probably do this from your host as well

#

minimize all your windows except the vm, then go to your host and use your snipping tool

velvet remnant
#

@lone urchin not sure how clear that capture is.

#

thoughts?

lone urchin
#

when you run the command, refresh your access page (on the site) and see what it says, does it say you're connected?

velvet remnant
#

yes, it says i'm connected.

lone urchin
#

alright, so you're set

#

you go to a room, you join, then if there's a "Deploy" button, when you click it a VM will start which you will have access too

velvet remnant
#

sorry, i'm dyslexic. i'm NOT connected

lone urchin
#

a new panel will appear that will tell you your vm's ip, that's your target

#

are you sure? try refreshing the page, because that output looks normal to me

velvet remnant
#

command + refresh = NOT connected

lone urchin
#

maybe you've regenerated your .ovpn file and used an old one?

#

if you regenerate, you need to download the .ovpn file again, and use that one

#

for good measure do this now

#

delete any .ovpn files you have, click regenerate, and download a new one

velvet remnant
#

OK, I'll deal with this when I get home. Thanks.

lone urchin
#

also before you do this do ifconfig and tell me if you see more than one tun# interface, so like tun0, tun1

#

if you see more than one, reboot your machine. if you connect with the openvpn command and then ifconfig and see one tun0 interface, then you're probably set

velvet remnant
#

I don't see any tun#s

lone urchin
#

ok then

#

regenerate the access file and download it

barren trail
#

Looking for some help please, I'm connected via the openvpn, and I've deployed the machine I'm working on, but it won't find the web server on port 3000? any help appreciated

#

When I visit the Access page it says I'm connected too

lone urchin
#

give it a good 5 mins before you try to access it @barren trail

barren trail
#

Ah ok, will do.

#

thanks @lone urchin

lone urchin
#

and make sure you're using the correct ip address. you don't want your own internal ip (the one in the access page) but the one in the room page (above your tasks)

barren trail
#

Yes, that's it working now @lone urchin , I must have been just too keen! πŸ™‚ Thanks for the help!

lone urchin
#

np ^^ don't worry, we've all been there πŸ˜›

rigid oxide
#

@velvet remnant did you have any luck? I'll be off work soon and can try to chip in for getting you setup

weary token
#

Hello. I'm running a Kali vm and am unable to connect. Here is the feedback from the terminal. Notice the last line: Fatal Error

#

tony@mark-kali:/media/tony/EHD/Programs$ openvpn students.ovpn
Tue Dec 17 19:02:06 2019 OpenVPN 2.4.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Feb 20 2019
Tue Dec 17 19:02:06 2019 library versions: OpenSSL 1.1.1d 10 Sep 2019, LZO 2.10
Tue Dec 17 19:02:06 2019 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Tue Dec 17 19:02:06 2019 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Tue Dec 17 19:02:06 2019 TCP/UDP: Preserving recently used remote address: [AF_INET]18.202.129.195:1194
Tue Dec 17 19:02:06 2019 Socket Buffers: R=[212992->212992] S=[212992->212992]
Tue Dec 17 19:02:06 2019 UDP link local: (not bound)
Tue Dec 17 19:02:06 2019 UDP link remote: [AF_INET]18.202.129.195:1194
Tue Dec 17 19:02:06 2019 TLS: Initial packet from [AF_INET]18.202.129.195:1194, sid=218a6000 56ab2dfc
Tue Dec 17 19:02:06 2019 VERIFY OK: depth=1, CN=ChangeMe
Tue Dec 17 19:02:06 2019 VERIFY KU OK
Tue Dec 17 19:02:06 2019 Validating certificate extended key usage
Tue Dec 17 19:02:06 2019 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Tue Dec 17 19:02:06 2019 VERIFY EKU OK
Tue Dec 17 19:02:06 2019 VERIFY OK: depth=0, CN=server

#

Tue Dec 17 19:02:07 2019 Control Channel: TLSv1.2, cipher TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Tue Dec 17 19:02:07 2019 [server] Peer Connection Initiated with [AF_INET]18.202.129.195:1194
Tue Dec 17 19:02:08 2019 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Tue Dec 17 19:02:08 2019 PUSH: Received control message: 'PUSH_REPLY,route 10.10.0.0 255.255.0.0,route-metric 1000,route-gateway 10.8.0.1,topology subnet,ping 10,ping-restart 120,ifconfig 10.8.5.179 255.255.0.0,peer-id 37,cipher AES-256-GCM'
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: timers and/or timeouts modified
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: --ifconfig/up options modified
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: route options modified
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: route-related options modified
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: peer-id set
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: adjusting link_mtu to 1625
Tue Dec 17 19:02:08 2019 OPTIONS IMPORT: data channel crypto options modified
Tue Dec 17 19:02:08 2019 Data Channel: using negotiated cipher 'AES-256-GCM'
Tue Dec 17 19:02:08 2019 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Tue Dec 17 19:02:08 2019 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Tue Dec 17 19:02:08 2019 ROUTE_GATEWAY 10.0.2.2/255.255.255.0 IFACE=eth0 HWADDR=08:00:27:28:28:a3
Tue Dec 17 19:02:08 2019 ERROR: Cannot ioctl TUNSETIFF tun: Operation not permitted (errno=1)
Tue Dec 17 19:02:08 2019 Exiting due to fatal error

deep trellis
#

run as sudo

#

sudo openvpn "..."

weary token
#

That worked; thanks.

#

It's been a little over 5 minutes and I'm unable to connect to the machine per the instrctions for task 6: http://IP:3000

#

Thoughts?

warm spear
#

task 6 of what? πŸ™‚

#

do you mean advent?

#

you're connected to the vpn, deployed the machine and it doesnt work

#

okay that doesnt sound like a problem i can deal with, sorry haha

deep trellis
#

@weary token Hm, did you get it working in the end?

tame mortar
#

having an issue with jokerctf, towards the end...the container image that showed up last week isn't showing up this week

eager fulcrum
#

I think I had the same @tame mortar

#

I haven't fixed it so I'm interested if you fix it

tame mortar
#

lol

#

that means i'd have to learn lxd for realz

eager fulcrum
#

It means the room has a recurring issue that's now known

tame mortar
#

or that πŸ˜‰

tame mortar
#

@eager fulcrum found a way thru

eager fulcrum
#

@tame mortar how?

tame mortar
#

exported an image from another Linux box with lxd, then uploaded it to the jokervm and loaded it up

stone roost
#

you might want to look into it, but let me know if i'm just being stupid, lol

rapid flax
#

That's insane.

stone roost
#

yeah just noticed

#

was looking into insight on one of the rooms i just completed

#

and found this

#

they replaced event the T&Cs with their domain name

#

that's stupid

rapid flax
#

That makes me incredibly sad and frustrated, I guess I shouldn't be surprised what people will do Β―_(ツ)_/Β―

warm spear
#

yo what

#

i'm 5th on their leaderboard

#

do not approve

#

i want 2nd 😦

#

their SEO is completely dead

#

like no one has indexed them at all

#

must be like a day old

#

looks more like a phising attack tbh

#

wait i just moved to 4th

#

oh this is exciting

#

yup 14 days old

deep trellis
#

Thanks @warm spear

eager fulcrum
#

Holy... That's like an exact ripoff

stone roost
#

hehe

#

i think i stumbled upon another one

mossy ermine
#

can they get in trouble... it doesn't look like you copyright your website ?

stone roost
#

i'm not sure

mossy ermine
#

oh never mind your copyright only shows when you are not logged in on the dashboard but it run out at the end of 2019

warm spear
#

i mean.... yes obviously

#

you dont have to copyright things to own the IP, at least in the UK. like if I write something, it's mine and if other people post it pretending it to be theirs I can request a takedown and I've never failed so far

#

also

#

tryhackme is a legal company

#

you dont have to do anything to get copyright, you automatically get it whenever you create an original piece of work

#

There isn't a register of copyright works in the UK. You automatically get copyright protection when you create: original literary, dramatic, musical and artistic work, including illustration and photography. original non-literary written work, such as software, web content and databases.

mossy ermine
#

cyberlaw is so interesting

warm spear
nocturne igloo
#

Hi everyone! I'm new and I just started with the room "Advent of cyber". I deploy the machine for Day 1. I am connected to the VPN (I can access the machine for room "RP: Nmap"). When I try to access the machine through my browser, I get "Safari can't access the server" (http://10.10.179.124:3000). Did anyone got the same problem? Resolved it? Thank you!

eager fulcrum
#

@nocturne igloo how long have you let it deploy for?

rose sky
#

@nocturne igloo im having the same problem, idk why i cant access the machine

eager fulcrum
#

Again, how long hve you let it deploy for?

rose sky
#

at least 5 minutes

nocturne igloo
#

Hi

#

I tried every 5 minutes for at least 30 imnutes

eager fulcrum
#

@nocturne igloo Either your VPN is not connected or you need to redeploy the machine

#

@nocturne igloo Yeah it's down, redeploy it.

nocturne igloo
#

Maybe need too wait 3 minutes as I did it right now

eager fulcrum
#

@nocturne igloo Nope, that VM is down

#

or at least not running the webserver

nocturne igloo
#

I got this in the room

eager fulcrum
#

What's your local time?

nocturne igloo
#

18:45

#

I'm in LosAngeles right now

#

But don't live there

eager fulcrum
#

add an hour if you can

#

Yeah I'm in westcoast time but my laptop's UK. timezones messy

#

Yeah so that VM isn't running the service

nocturne igloo
#

Did it!

eager fulcrum
#

Interesting

nocturne igloo
#

Yes because I could log to another room

eager fulcrum
#

It's open now

#

Might have just taken forever

nocturne igloo
#

Yes! I'll work on it now!

#

If someone need to investigate, don't hesitate to PM me πŸ™‚

eager fulcrum
#

yeah so it took a while to deploy

nocturne igloo
#

I did try 10 times today but never tried to add an hour

#

Seems that this triggered the deployment

eager fulcrum
#

Nah

#

probably just took a while

nocturne igloo
#

OK, I'll wait for it then

#

Whatever, thanks for all!

abstract onyx
#

I'm trying to do task 6 on day 1 and I can't seem to get the deployed machine to show up

eager fulcrum
#

@abstract onyx Are you VPN'd?

#

And show up how?

abstract onyx
#

yes

#

when i try to access the page it is showing as site refused to connect

#

sorry this is the first time I've used the site and I am just getting started

eager fulcrum
#

is the IP you're connecting to the one on the page for the room? @abstract onyx

#

And how long have you let it deploy?

#

And port 3000?

abstract onyx
#

ohhh i see it now. that wasn't intuitive haha

#

i thought it meant my ip address...doh

eager fulcrum
#

Which part?

#

yeah it's weirdly worded

#

You get used to it

abstract onyx
#

okay it works now

#

thank you

abstract onyx
#

Do you know if dirsearch is compatible with python 3.8?

abstract onyx
#

nevermind. i figured it out

pale ridge
#

Any way I can change my email?

leaden token
stone roost
#

+1

last epoch
#

Task 12 (Day 7) I'm getting a Permission denied (publickey) error when trying to ssh. Am I even supposed to be accessing the machine?

#

I retried day 4 to see if it would let me connect on to that box and it was fine.

#

Oops sorry, thought I was on cyber advent room

eager fulcrum
#

@tame gate So I get the unroutable error IF i have a second machine connected to the VPn at the same time

#

I highly recommend you a) check this and b) regenerate your vpn config

tame gate
#

ah that may be the issue

#

ye ill regen

#

it wasnt connected at the same time

#

however it has been connected before

#

thanks

desert hornet
#

hello, i have issue with access with openvpn, the log says TLS Error: Unroutable control packet received from, few days ago it's normal anyway. any solution for this ?
edit: resolved, i have issue with udp openvpn (blocked).

uncut hound
#

How long does it take to receive a password reset? Been waiting 25 minutes. Update finally received it 30 minutes total

deep trellis
#

@uncut hound It should be within a few minutes max

#

Oh really? Weird - we're moving over to another provider to send our emails

#

So the delay shouldn't be that bad in the future

#

Thanks for letting me know (and updating your message later too)

mighty zealot
#

I'm having issues deploying machines, Hydra-ha-ha-haa was deployed for 18 minutes and still wasn't up, so I just gave up, terminated the machine and deployed ELF JS 6 minutes ago and it's still not up.

#

Still not up even after 11 minutes have passed.

#

@eager fulcrum I think there may be a server issue, can you confirm?

eager fulcrum
#

I can try

mighty zealot
#

Thanks.

eager fulcrum
#

@mighty zealot I can confirm that at least one box has deployed just fine for me

mighty zealot
#

Very confusing since my box is still not up.

eager fulcrum
#

Are you VPN'd properly?

#

Want to give me an IP of one of them so I can check for you?

mighty zealot
#

... I'm an idiot.

eager fulcrum
#

vpn?

mighty zealot
#

I forgot to connect to it this time

eager fulcrum
#

Glad it's fixed.

mighty zealot
#

Wow alright thanks anyways and sorry for wasting your time ^^

naive dust
naive dust
#

When using kali-linux in Virtual box the mouse randomly stops working, I can move it around the screens but clicking any of the buttons doesn't do anything.
What am i doing wrong?
Did i accidently press a hotkey that disables the mouse?

I can click on the taskbar but nothing else

vapid dawn
#

@naive dust trying killing your openvpn connection and restarting it πŸ™‚

#

for the web issues

unreal niche
#

hi guys question does anyone have problems of openvpn reconnecting itself to the server and disconnecting the current connection
because was stuck on task 13 trying to find the path and got confused when the python script would hang

eager fulcrum
#

@unreal niche normally when you have 2 devices connected on the same ovpn profile.

unreal niche
#

could it be that me running python in the terminal
and the tryhackme site open be the cause because i use linux only

eager fulcrum
#

Nope. That's normal to do.

unreal niche
#

well i dont know then guess it was just during task13

unreal niche
#

i opened up ifconfig it showed two vpn enabled devices
maybe thats the cause

naive dust
#

@vapid dawn Sorry about ping, but its still happening >_<

last olive
#

@naive dust You gotta wait for like ~5-10 minutes

sharp bisonBOT
#
TryHackMe
New issue

This is the input you are about to create:

Name

OpenVPN connectivity

Description

Check OpenVPN connectivity - connection keeps dropping off
-- Created by: Ashu

#

Issue has been created by @vapid dawn!

vapid dawn
#

will double check on this :)

warm herald
#

how can I get a server rank?

deep trellis
#

Use !verify <discord token>

warm herald
#

thx

deep trellis
#

Your discord token it found on your TryHackMe profile

warm herald
#

oh and where do it write this comand?

deep trellis
#

Privately DM the TryHackMe bot πŸ™‚

warm herald
#

oh ok thanks

unreal niche
#

hi is nfs supposed to come preinstalled on linux?

trail wedge
#

On my Kali I had to install "nfs-common"

crude yew
#

am i dumb, or in the "The find command" room is supposed to be a VM?

#

i can't find it lol

#

@lone urchin

lone urchin
#

no vm in this room, wait

#

sorry for the link, got confused and thought you couldn't find the room lol

#

have fun

crude yew
#

ok. i'm dumb. sorry

unreal niche
#

@trail wedge I ended up having to install all the packages and libraries required to install nfs common yesterday

sleek otter
#

Hi.

#

I'm not receiving the email to activate account, since yesterday.

#

I'm using self hosted, but it's Gandi mail servers..
I checked junk mail: nothing there too.

Do you have problems with .xyz ?

naive dust
#

Damn it... I have a typo on my email

#

Any <@&568449888682246145> ?

sleek otter
#

I created another account, will the old account be deleted ?

deep trellis
#

@sleek otter did your new account get the email?

#

Also email us and we can sort out the problem

sleek otter
#

Yes I'm an idiot: the old account had a typo in the mail. And I can't seem to remember the password, too.

deep trellis
#

Update your email :)

sleek otter
#

So the account "0xTHMS" is now useless.

deep trellis
#

Ah, email us anyway and I'll see what I can do to recover the account for you

sleek otter
#

Can you give me the email please ?

deep trellis
#

Sorry I cant

sleek otter
#

I mean the email to contact you πŸ™‚

deep trellis
#

Ah

#

Ok yes aha

#

I'll have the account recovered for ya

sleek otter
#

Done.

leaden token
#

Cyber Advent Day 13 machine is not working for some reason. Been waiting for 20 minutes

crude yew
#

@leaden token pings are blocked

leaden token
#

nmap is not working too 😦

crude yew
#

try with -Pn flag set

leaden token
#

thanks

storm eagle
#

Hello, how do I access the website for a specific task, I followed the instructions with the IP in the middle but still can't connect

#

I'm using Kali machine

eager fulcrum
#

@storm eagle they don't all have websites

foggy blaze
#

Shit, my membership ticked over

#

I've been inactive due to christmas

#

Is there any way I can cancel?

#

It ticked over last night :/

rigid oxide
#

Shoot an email over to hello@tryhackme.com and we might be able to take care of that

foggy blaze
#

Cheers!

subtle osprey
#

Hope I'm in, but how do you exit out of the openvpn on Kali Linux? I've tried CTRL + C in the same terminal as the connection and sudo killall openvpn, neither of those seem to work .-.

lone urchin
#

@subtle osprey Ctrl+C should work

stone roost
#

@lone urchin i'm not sure that works lol, on my VM i closed the openvpn tab after ctrl c and i still have the tunnel on

#

or it might just be a problem in 2019.4

lone urchin
#

are we talking about the browser vm? because I've never used it

#

no I'm on 2019.4, this hasn't happened to me

stone roost
#

do you get flashy shells too? or taskbar?

#

it's so damn annoying

lone urchin
#

what do you mean flashy?

stone roost
#

like flashing

lone urchin
#

no nothing like that, everything's smooth

stone roost
#

it's like going white and black very quickly

lone urchin
#

are you using vbox?

stone roost
#

yea

#

hyper-v was breaking my network for whatever reason

#

it was throttling my download speed to 128 kbps on both host and guest

lone urchin
#

I don't know sadly, I think it hasn't happened to me but I'll keep an eye out

#

you can check google/forums

stone roost
#

i am in the bugs forum for kali and i see it's quite often. I'll just do a clean install and see if that works any better

lone urchin
#

I don't think that would help unless you've manually messed around with something

stone roost
#

i haven't touched anything lol, i am a noob

#

also, my vm might be a little bit old and piled with junk from the advent calendar (forgot to do a checkpoint) 😦

lone urchin
#

if it's old then a clean install can't hurt but a few files on the disk shouldn't be a problem I think

#

I clean-installed 2019.4 so I can't know if it's something that occurs if you upgrade from a previous version

stone roost
#

it's stupid, lol

lone urchin
#

you're way more likely to find the answer there than from me tbh πŸ˜›

stone roost
#

i guess. let's see how it goes. if it keeps flashing i might just move to parrot

#

or is there any other os that might stand out?

lone urchin
#

not really, but think of it more as a collection of tools than an os

#

if even after a clean install you have the same problem and you can't find a solution, it be worth it to look into parrot

eager fulcrum
#

@stone roost works for me on vbox

subtle osprey
#

Wow I missed a whole convo here when you guys were trying to help! Sorry .-.

#

Yeah the flashy happened to me too @stone roost .

#

I think the disabling 3D Animations helped. Because it doesn't happen to me anymore.

#

And yeah, @lone urchin CTRL + C doesn't work for me, and I do it on the same terminal as my connection. However, I'm on Kali 2019.4, so it may be a bit buggy, idk.

#

@stone roost Have you found the solution to closing the openvpn? I got it to close, but I don't know what I did to make it close again, unfortunately .-.

stone roost
#

@subtle osprey @eager fulcrum fresh install and fully upgraded kali seems to work fine

eager fulcrum
#

Sounds bout right

subtle osprey
#

Alrighty then, I will try that! Thank you πŸ™‚

#

Did you uninstall VBox too, or just Kali? Trying to figure out if this is an issue of virtual box or kali

stone roost
#

just kali

subtle osprey
#

Gotcha, thanks!

stone roost
#

seems to work fine for now

stone roost
#

@subtle osprey didn't find a solution for the openvpn. I just stopped carrying about it loool

subtle osprey
#

Aww .-. perhaps it's an issue with Kali 2019.4? I think I'll try an earlier version of Kali later to see if it works.

stone roost
#

Might be. I have 2 vms for kali so i don't mind it that much

empty solar
#

I'm connected via openVPN and the website

#

yet I can't seem to connect to the deployed machine in the room

trail wedge
#

If you run nmap can you see the open ports? Sometimes these machines take 5 minutes to boot up

empty solar
#

is it normal for the deployed machines to take a while then?

deep trellis
#

Yes

#

It takes between 4-5 minutes

#

πŸ™‚

empty solar
#

Ah in the video tutorial it was instant

#

so if I'm fully connected on the access page all my openVPN stuff should be fine then?

deep trellis
#

We had a machine pre-loaded to make it quick to show people πŸ™‚

chilly meadow
#

Hey what’s the best place to study CHFI online

rigid oxide
#

CFHI?

steel rapids
#

EC council forensics

chilly meadow
#

@rigid oxide computer forensics

rigid oxide
#

Oooooh

#

I believe Pentester Academy has a course on that actually

chilly meadow
#

How credible are these trainers has anyone used them for training

rigid oxide
#

I'm not personally familiar with them

chilly meadow
#

@rigid oxide they only do pentest stuff, I have checked them out, They’re good though you can subscribe and download all the videos

subtle osprey
#

@stone roost Alright, so after trying a couple things, it seems I figured out a way to disconnect the openvpn on kali linux 2019.4

#
  1. Press CTRL + C in the terminal of connection, 2. Delete ovpn file, 3. retype "sudo ovpn /path-to-file/filename.ovpn" and it should show that it cannot connect 4. Refresh the page and it should show it's not connected anymore.
#

There might be a more efficient method out there, but I haven't found it yet. This has worked for me a couple of times, so it should work for your 2019.4 kali machine too.

chilly meadow
#

What’s a way to grab network traffic to analyze on wireshark if the endpoint is not connected to a siem only an edr. The end user believes they encountered the ryuk ransomware

naive dust
#

Can you just not subscribe with a Credit/Debit card on TryHackMe.com/profile ?
I've tried different days and it always says card declined.
I'm 99% sure there isn't anything wrong with my card since i just used it to buy other stuff and there wasn't a probelm

icy hill
#

@naive dust insufficient funds?

naive dust
#

I have a few thousand on the card

rigid oxide
#

It's likely your card company detecting the purchase as anomalous and blocking it

snow oriole
#

@chilly meadow Pentester Acad has linux+windows forensics. Might be interesting to watch. And they also have labs to practice ur skills

deep trellis
#

@naive dust Ah this is weird - it doesn't happen to be a Discover card does it?

#

Sorry about the trouble you're having too - if you DM me we can sort it out?

naive dust
#

@rigid oxide

#

Let me dm u

#

:\

rigid oxide
#

I have that so only friends can dm me haha

#

Because rule 1 yo

#

Oh just post your emotes here

naive dust
#

this 1 >:) :m00:

#

and then ill host a vote for #2

naive dust
#

ok the people have voted

#

#2 emote

#

:cyclops:

leaden token
#

nice emote!

rigid oxide
naive dust
#

yeah I love them

#

and I love their logo

#

Mine comes from BeEF

naive dust
#

the peoppe have voted

#

emote2 will be horshark

#

@rigid oxide

rigid oxide
leaden token
stone roost
#

Just passing by horshark

naive dust
novel shard
stone roost
chilly meadow
#

Would grabbing a memory image be the best way to figure this out since no files have been encrypted?

mossy ermine
#

oof no admins, anyone have any experience setting up shared folders on oracle vm. they changed the method and cant figure it out ?

uncut hound
#

folder path on host machine and then mount point is where it will be mounted within the vm I assume

#

seems pretty straight forward

mossy ermine
#

you would think so but it is not mounting... i pointed the folder path and have tried multiple mount points but it isnt working

#

@uncut hound

#

in the old day you just added the folder path and it would drop the folder on the desktop

uncut hound
#

I mena have you tried adding a directory specifically for it? /home is very vague and would likely screw the machine so might of refused

#

failing that google is your friend in this one

trail widget
#

@mossy ermine you got the guest additions add-on on the host, and installed inside the VM? I’d definitely change /home to something more specific too, like /mnt/files or /home/user/files

mossy ermine
#

@trail widget i screwed around with oracle vm for about a hour before getting pissed and just installing vmware fusion... took me two seconds to figure it out in there

#

restalled my linux enviroment and am now a happy man

trail widget
#

@mossy ermine nw. Fusion > Virtualbox anyway IMO. Glad you got up and running anyway.

mossy ermine
#

yes am now going to sing praise for fusion for all to hear going forward

foggy blaze
#

@rigid oxide hey man, I sent an email over re: the refund as suggested by you last wednesday, did you get it?

sleek otter
#

10+ minutes to deploy a room is normal delay ?

#

I deployed Alfred at 14:39 and it's now 14:52 and still ICMP reply

stone roost
#

just because you don't get icmp reply back doesn't mean a host is down. try nmapping

#

@sleek otter that might work, or try browising it over port 80