#site-support
1 messages · Page 144 of 1
You're right.. 🙂
Nmap worked, I thought I read somewhere that pinging the box was the way to see if it was deployed.
not sure, i usually don't make assumptions about a box being up or down simply based on ICMP
Me neither I assumed tryhackme's boxes were all ICMP enabled 🙂
yeah, i don't know exactly how they work, i just go straight to nmap after i'm connected to the vpn
if you have powershell on your box you can try test-netconnection
No, there is no rule about having any indication that a box is "up" other than the tryhackme deployed room. You can block ping requests, nmap, or any port scanning if you want 🙂
The room Retro, for example, has a firewall which blocks ICMP packets 😄
@warm spear thank you for your confirmation
My general rule is: "deploy room, connect to vpn. go and make a nice cup of tea, or watch a youtube video. then straight to nmap"
+1, i do something similar
@foggy blaze We should have it, I'll confirm with Skidy. He's the main manager of that email
If you are a subscriber, I might (by default) make all VM's boot with loads more resources.
So it boots up quicker
@mossy ermine I had the same struggle a couple weeks ago. Wqs able to get it working with VMWare. Made a meme: Friendship ended with virtual box. Now VMWare is my best friend.
thanks
Can I ask why you want your account deleted?
i thought it was a simple ctf site now i see there are rooms and some weird things i dont think is for me
A room is a virtual space where you complete tasks
So it is CTF's
And walkthroughs
You do it on the platform
If you want I can run you through it?
no im fine
okay, then email away
anyone familiar with olleydb?
if so how the heck do you look at hidden files... you have to open olleydb inside itself and it is in the .wine folder
ubuntu 18.04 by the default you have to press ctrl + h to view hidden files but that doesnt work in olley
or if the tool is not used anymore let me know and ill skip it
@mossy ermine haven't heard of it :c
Can anyone recommend a more suitable Kali setup. I'm currently running Kali on a Oracle VirtualBox VM but when using the likes of Hashcat, the VM can't see my GPU so it's taking a lot of hours to crack a hash. From what I've read you can't use the host GPU on an Oracle VirtualBox, can anyone recommend a better setup so that Kali can use the GPU. Many thanks in advance.
@barren trail vmware? Or hyperV?
Ok @stone roost I'll have a look at those options, thanks.
I personally use what you are using and the box from the subscription
As far as i can see you can use gpu inside virtual box
Yeah, generally the VirtualBox I'm using is fine and I'm not having many issues with it, but this basic hash I'm trying to crack with Hashcat has been running for over 9 hours.
I'll give it a go when i get home
Oh? When I tried to set it up it couldn't see it.
Thanks @stone roost , appreciate the help.
@stone roost @barren trail You can't do GPU passthru unless you have a spare GPU. My advice would be grab the windows version of hashcat and run it from powershell.
This is what I personally do.
If you wanted to use the host's GPU in kali, it'd be a lot of hassle and work. You should be able to copy/paste hashes to and from the VM
And also possibly set up file sharing
Thanks for the help @eager fulcrum I'll look into that too
@eager fulcrum Oh, i didn't know that :c. Thank you for letting me know
Nice name
@warm spear pure coincidence bro I swear. My initial is B and I liked it
@deep trellis sure did!
Thanks for the help earlier @stone roost and @eager fulcrum I managed to use Hashcat in Powershell and it reduced the time massively. Thanks!
no problem @barren trail glad you managed to get it in the end, mind sharing the guide with me too?
i got a spare gpu i could possibly use for this rather than my main one
@stone roost it's literally just 'install hashcat on the host OS'
@eager fulcrum lol, really? thanks, haha!
@stone roost Yeah, GPU pass through is painful often
@eager fulcrum should i look into a usb plug and play for a graphics card?
Doesn't mean they're decent perf
But yeah. There's windows hashcat builds. Just install that on windows and use powershell
I dunno if its the machine or something else going on, but Retro is running terribly.
Slow? @vagrant crypt
Unbearably slow, yes
I am (in theory) a few steps away from root, but the thing takes 20 minutes to do a single thing
jesus, now its bugged
yea so im not sure if im doing the exploit incorrectly or if something just isnt loading correctly
There's something you need to fix, and it's an intended issue. At least fairly sure.
i think im doing it
yea as far as im aware, im doing it right, but it isnt working. or its being slow so things arent processing correctly. I'm not sure
yea no idea. screw it i guess
I will give retro more resources
I gave Retro loads of resources - should boot up quickly and not lag
thanks @deep trellis ill check it out later today
Any way I can change the capitalisation of my name on the platform?
Anyone who have made any learning path, I'd like to ask something.
by made you mean completed it 100%?
Do you mean like created a path? The primer path was built by me
Go for it, I'm at work right now so it might be a bit before I can reply
Lemme make sure I have you added on discord so you can DM me
No problem just want to know the workflow won't be much long.
Hello everyone I m having a problem with ssh connection for day 20 in cyber advent as I ssh as SAM user so after one minut I m not able to do anything ... have to restart openvpn and reconnect and after one minute the same...
@jagged crown I think i already answered you a while ago. Did you specify the port the SSH is running on?
@rigid oxide I have a question regarding the monthly leaderboard, but I guess it's better to talk about this in DMs if that's okay
Is PayPal payments down for maintenance?
Definitely missing on the gift page
On that purchase page, you can only pay with debit/credit
If you want a subscription for yourself
You can pay on your profile page
I can't check that then
Ok so trying to pay, I get this.
I'm doing a redhat linux enterprise course and, I don't understand this completely like, I feel as if it's an error https://gyazo.com/1c2f6917a1c1f6840bfd458d0ed272c5
What you mean? @lime path
all good now
Curious enough, what was it? @lime path
the file extensions where displaying incorrectly. I'm doing a redhat enterprise linux course.
displaying as a music file instead of what it should actually be showing.
Oh
So, playing around with it, it appears to be somehow related to the student discount being applied. Normal email would send me back to the paypal page perfectly fine.
Hi guys, I have an account but not under my student email, how is it possible for me to get the student discount as ready to start my subscription again
I just paid for it again, if you could hit me up before i finish work ill be able to tell my account and change it for next month please
Email hello@tryhackme.com with your student email and they’ll be able to help you out
I shall do that now thank you
@ornate comet This is interesting, I will investigate, thanks for letting me know!
no worries 🙂 glad I could help @deep trellis
Really weird, just tested it out and it seems to work fine
Ill keep an eye on the logs incase it happens again so I can better identify the error
Trying to open the kali machine getting an message
REMOTE TRYHACKME
With login and password
Can you try terminating it and re-deploying it?
I have lol
Now im at a blue screen with Xorg on it
but kaliroot is not the password
can you print screen please?
Im at work an the print screen not working
Login with kali and root
the middle one
Or the RDP details shown in the Kali room
@ornate comet helped test and diagnose the PayPal bug - its now fixed.
thank you very much for the support!
@stiff coral Have you managed to fix the in-browser machine problem?
Been approved to use my own kali XD
@deep trellis Can I DM you? I have a question regarding a reward
Yeah sure
One last thing!!!! i think most of the problems because im at work
I used the heartbleed vm and it works online, but trying to use a SQL vm and it has the 10.10 network which is not online right? and my vpn is not working (maybe because of where i am)
Is there anyway to make the machines online as some seems to be online anyways 😄
I think the only option for your case would be the Kali VM provided by THM
but you have to subscribe for that
and you can access it via browser
Hey guys, I'm new to TryHackMe and I am unsure about the policies of writing blog posts about premium challenges. Is this allowed?
Ahh okay, cheers for the information
@stiff coral what's up?
lol
thank you mate
Np
hi ! cannot connect to rdp host on retro room
@everyone
Stop.
This is from a mod, stop spamming every channel with that message. It goes in #room-help, without the everyone tag @fresh stone
Anyone have experience utilizing airgeddon with the Alfa awus036ach?
I'm running Parrot (Security) and have been bashing my head against google trying to get it to run happily. Both airmon-ng start on the adapter and setting monitor mode inside airgeddon results in the process hanging and after a little while the entire OS freezes up
Side note: I can put it in monitor mode manually via ifconfig & iwconfig
Maybe check kill first then monitor?
Have tried that as well, all that runs is wpa_supplicant and NetworkManager. Killing both has same results as leaving them running
Killing one at a time and testing also has same results
Checked if it was due to it disliking multiple wlan adapters so I took all but the Alfa down, still hanging
I think I’ve seen this before due to parrot. I’ve heard it sometimes has issues
Sad day, here's to hoping someone found a resolution and sees this then 😅
Maybe, I’d say maybe attempt another os just to check if it resolves or not.m
Yeah, I'll spin up my kali box and give it a try. Was just hoping I could get it working on Parrot since I like it a bit more
That’s fair enough. It is a nice os
Someone knows if there is a restriction for language to write the writeups ?
From what I gather it can be any language just ensure it is specified in title when submitting
English is obviously preferred but other languages can’t hurt
Oky doky
You gotta ask the question otherwise we don't know if we can help or not.
haha sorry yea my bad. So basically when I deploy a box on the website and run openvpn, my connection is pretty bad. when I run nmap on a box I usually get this reply tarting Nmap 7.80 ( https://nmap.org ) at 2020-01-12 22:30 GMT
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.01 seconds
Nmap Free Security Scanner, Port Scanner, & Network Exploration Tool. Download open source software for Linux, Windows, UNIX, FreeBSD, etc.
in this instance, Blue
How long did you wait between deploying and nmapping?
like a minute or two, but even now for example. It has been deployed for longer but no matter how long I leave it it always does that
May I recommend trying it with -Pn
Also what commands are you putting into the nmap command?
I’d say try without -T4
Ngl -A is even overkill on blue
-v might help as well
I’d say do a bare bones scan just nmap ip
yea I mean of course at first I tried a normal scan. same result. All scans give me the same result really. I've done this box before on HTB, its just on Tryhackme I have to do this one because of the Path. I
whatever flags I set its always the same result
I know but the concept and exploits are identical
both based on eternalblue
I'll try a different box and see what it says, maybe its just an issue with that box
Lol I don’t think there’s a single box on thm that’s the same as htb
Blue unfortunately has the same name and exploit as Blue on HTB. Ironically, it was developed when I had no knowledge of that box and it was just a situational irony that this happened lol
Otherwise there are no boxes that are the same between the two platforms, we're really picky about that since we really respect and love HTB
oh okay
I say that having done some box dev for HTB as well lol
@uncut hound there is one that was on htb before. Node I think
Yeah you're correct now that I think of it
That one was submitted here from it's creator following the end of it's exclusivity period on HTB
Oh I see
If that’s the case get felamos to release chaos on here!
Still to this day one of my favourite boxes on htb
I can certainly ask him to, I'd love too see that on here with a proper walkthrough variant of the machine similar to Ice
Please do I love that machine so much
@drifting zinc whatcha think?
sure, its retired on HTB
Heck yeah
Can somebody explain to me how the point system works? I find it very confusing
Hello, my openvpn keeps tossing me this error after a few minutes: [server] Inactivity timeout (--ping-restart), restarting. Not sure what to do
Main issue is it kicks my connections every few minutes when it restarts and reinitializes a connection
Check you're not logged in elsewhere, restart the system and try again @young bison
Will do!
@eager fulcrum good call on that!
I had that issue
The thing is, all the issues happen to me so I have fixes for so many of them
LOL it's what makes you a good mod xD
^^
Worked like a charm. Thank you all! Really been enjoying the site
❤️
First time using the kali room, everytime I login and get prompted with the Initial Setup panel, arriving at the end, the machine doesn't answer anymore even after several minutes, is it normal? I chose English then French keyboard.
Both happening with the web and my RDP client.
Yep
No problem, keep me updated!
@spare blaze
Its really weird, I am having no problems
Can you terminate and re-deploy
Then can you DM me the machines IP
Will do!
@spare blaze @deep trellis this exact thing is happening to me too, also first time using the kali vm and I've tried terminating and re-deploying numerous times
Interesting
@oak basalt @spare blaze Can you both check again please?
how i get a role ?
@naive dust check your DMs from the bot
It's the !verify command
With your discord token from your TM profile, sent as a DM to the bot.
ok checking ...thanks @eager fulcrum
Yeah:)
While creating a room, I have like a lot of written material and I'm having issues in formatting them like I'm not...like used to that stuff, anyone can give me a hand on this? Or does THM have a feature of making a room with collaboration?
I can create the materials and they can add it up on my behalf😅
We don't support collaborative room creations 😦
What do you mean issues formatting? Can I have an example?
Like I want to add full walkthrough of how to exploit the binary itself and I want to add the walkthrough for both 32 bit as well 64 bit
So, the full walkthrough requires the attachment of disassembly and other stuff, that's why I'm having a problem.
So, I have other option which is...I can add a link to my YT video on how I am doing it and link to GitHub repo that has notes?
Please let me know people, since I'm doing it for you guys so it solely depends on how you want it to be.
Having a YouTube video would be awesome
That would make your life easier too 🙂
Saves you writing so much material
How can I add my cert roles?
I'd say contact one of the admins @azure kernel
hello
you can always just paste your notes onto the room @last olive ?
@vapid dawn Working on it.
https://github.com/21y4d/nmapAutomator
Did anyone use this tool? How is it?
Sounds like https://github.com/Tib3rius/AutoRecon to me
It’s supposed there will be a room delivery on Thursday ?
*Friday 😄
Every Friday at 8pm (GMT), we will release a challenge room.
Every Tuesday at 8pm (GMT), we will release a walkthrough room. ```
Both rooms will be delivered on Friday ?
yeah - for now we're planning to release rooms every Friday
This is confirmed
Through the next few months, we'll be releasing rooms on Tuesday as well :))
Thanks @vapid dawn
THM has twice the room releases because THM is twice as good
Hello guys. I don't see any networks in linux, but my wifi adapter is listed in lsusb. Im in a Virtual Box. Any advice?
If u want to use the bulit-in wireless adapter from your laptop, I'm afraid that's not possible
you have to get an external wireless adapter and connect it through USB
and attach that usb device to your VM
Did you check that VM has a permission to use your adapter?
@novel shard @leaden token the usb wifi adapter is passed through with usb passthru, just isn't picking up any networks
I was helping with this earlier
Yeah neither
Weird, Ill take a look when I can
thnks
what does the time zone do when your not connected through vpn?
i just realize i wasnt connected to the network
Oh I suppose I usually don’t turn my vpn on until after deploying
The timezone is handled clientside
i need help getting RDP to work i have no idea where to start in the seance of what program i need to install to connect
Something like remimma from Linux
so it cant be a windows box app to get in?
wouldnt a VNC program allow me to RDP in? on windows because all the RDP apps i find are like ones where u need to install them on both computers lol
nvm i found it!
I am wanting to get a subscription and am wondering how to get the student discount?
@tardy rune if you didn't sign up with a UK academic email then it's not automatic.
I think you might be able to talk to Skidy about it
@tardy rune hiya, have you signed up with your student email as James said??
@deep trellis I did not, I used my gmail account on signup, I am a student in the US
@tardy rune send an email to hello@tryhackme.com with your thm name and student email (if you have one)
@steel rapids Thank you
We can have multiple deploy for multiple task for a room, right?
Yeah @last olive
One machine can be deployed per room
But you can attach multiple VMs in a room
Yeah, if you deploy whilst a machine is running in the room, it will say "Only one instance allowed"
Ah ok that makes sense
hi hi -- how can i see which machines are currently running for a room?
slash which machines i have running, in general
^ nvm. it didn't show up on one page load, for some reason, but reloading fixed it...
Is Ninja Skills box not working? I haven't been able to deploy for a couple day now
What happens when you try to deploy?
It should deploy
@naive dust The only way to know is if you're in the room and deployed
skidy ily

the bull is here

@deep trellis it kept saying an error, but I tried to reconnect about 10 times and it finally worked lol
What said error?
The inbrowser console?
Did you try connect via ssh?
Also next time can you screenshot it?
Anyone know if I can disable kali 2019.4 trying to reopen the programs after a reboot?
I feel like I found a way to turn it off in 2019.3
I'm trying to do the subscription but it says my card is declined even though I have plenty on it =/ any idea why that is? I verified my account already and selected the right country
Correct billing details?
It only allows me to put in card number/exp/CVC and I have checked that multiple times. Is there a place where I put in my address or?
I don’t think you need address for that
Card number/Expire date/CVC should be enough
Yeah it's weird because I've double and triple checked but it's still declining. I emailed tryhackme since I need to get the student thing sorted out, so hopefully I can get some insight on why this is happening. I appreciate everyone's help!
It might sound stupid but maybe your bank is rejecting it?
Got the same thought
That actually doesn't sound stupid, I'll see if that is the case
Definitely worth checking with your bank to see if the request has actually been received.
@heavy vine Hiya
Are you still having issues?
Ah, I think I can see why you're having issues - DM me or email hello@tryhackme.com (if you havn't already)
I'm assuming updating our deployed kali machine won't persist between deployments? Unless they're setup to be per subbed user
@deep trellis Trying to verify my student email (just because the banner keeps yelling at me) but not getting the email, in the Inbox or junk. Am I able to send an email from my student email to verify manually somehow or any other option?
@vapid dawn Some emails are still not going through? Had this on other occations too.
will take a look at this in a few :))
@languid storm I think there is a problem with how we're sending emails, some ppl get them, others don't. Thanks for reporting 🙂
👌
@languid storm when exactly did you trigger your email?
Unsure on exact times but about 14.5 hours ago then again about 1.5 hours ago
is it possible to change your username?
@crisp hound not at this moment in time, sorry
Wow thats lame
hai
@hazy shell 👋
😄
Username changes coming this year tho
What happens when I create a room in the 'Manage rooms' tab? Is it going to be public?
No, by default it's private
Then you choose to make it public and it goes into review (reviewed by a member of staff)
You making a room :O
Ye
Okay, thanks for info
The room isn't a big deal tbh, just some beginner level guide
That's great and we love to see that:)
hey I think I'm having issues with openvpn. Just walking through Vulniversity room nmap and gobuster keep dying... a lot. I've noticed this issue with HTB attempts as well.
Everything is up to date as far as I know. Maybe there is something I need to adjust I'm not aware of?
It can take up to 5 minutes for the room to be fully set up
right, this would be happening after a while. Should I just reconnect open vpn/ reset the box?
by the way... this is a lot more fun than HTB for me right now... My kid got into it Sunday as well, had to send him away lol
well.. to his room with his laptop 👍
@bold folio Thats amazing
Thanks for the kind words too
Yeah if you could wait a bit before attempting to connect
When you deploy a machine it takes a minute to boot/configure.
@deep trellis @rigid oxide is there a possibility of changing my subscription date to the 4 or 5th of the month each month?
Yeah we can likely do that, Skidy can probably help you once he's back in the world of the living haha
haha thnks @me i set my phone to always notify me if you need anything from me
I am also having issues with Openvpn but with a slightly different approach.
It keeps dropping even though the VPN is still connected.
Does anyone have a solution for this.
Even pinging the box is impossible until connection is established again.
Error = ‘event wait: Interrupted system call’
OpenVPN version 2.4.7.1
Any solution will be really helpful as it is slowing me down.
Try rebooting Kali and make sure you only have one vpn connection to the site open at once
Also make sure it's in it's own terminal tab of course
Can I add multiple docker service to a room?
@mossy ermine email us and we can change the date for you
@last olive If you create different docker containers, you can put it on VM 🙂
Or make several VM's with a few docker containers on them
I'll make Vm, better than hefty work
hi everybody. i'm trying to use kali room, but it keeps freezing on the initial setup.
What language are you selecting?
I think there is a reported problem with that
@vapid dawn is setting up a new Kali machine
Italian, but that's ok. i'll try with the default
Hello. I have been trying to root Dailybungle , which I got credentials via Sqli cant login. is it supposed behaviour? or is something wrong.
@unique rover did you do any password cracking?
@ yes, sure I did, got the cleartext password and verified it in the question. but same cred doesnt log me in in joomla admin login,
This is a #room-help. I'd help but I have somewhere to be in 10mins
@eager fulcrum Thank you!
@eager fulcrum I've got it solved. I had to redeploy the vm. Maybe sqlmap messed something up. Thank you alot.
Yes, appreciate.
Hi, may not be the correct place to ask, but I was trying to sign up for a month to try out the learning paths, but my card isn't working for the month by month trial, and paypal is limited to 3/6/12 months? I wanted to see if this is right for me, but don't want to pay for 3 months if it's not
@deep trellis
Sorry due to the PayPal fees, we only have 3/6 and 12 months available via PayPal
Copy, thank you
Hey Guys!
TryHackMe is a platform for learning and teaching cyber security.
Deployment is failing
Hitting deploy, and nothing is happening. Tried refreshing after a while.. Was due to go live in 7 minutes!
any issues deploying?
@deep trellis any advice buddy?
https://tryhackme.com/room/attacktivedirectory is at fault
TryHackMe is a platform for learning and teaching cyber security.
Oh, people have been having issues with that lately @harsh thunder
Just dropping another message @vapid dawn that attempting to verify email still isn't getting to my Inbox or Junk. I'm happy to send an email from my edu address to verify myself
ah okay weird
have you had another other problems with emails(e.g. when you sign up/reset your password)
Originally signed up with a non-edu email, then later updated it to the edu email. Hadn't had any issues whatsoever with my .edu email personally with getting emails
I suppose to my knowledge, nobody has told me they sent me something that I didn't get though 🙂
@eager fulcrum so It's not my fault, good to hear!
i'm guessing Attackive Directory is fubar
TryHackMe is a platform for learning and teaching cyber security.
the deploy feature doesn't seem to work
^ there's a known issue with the room
I think the creator is currently trying to fix it
I made the room private until its fixed 🙂
thanks dude
Will work on the fix for it today after I'm done with work ❤️ thanks for your patience
just wanted to say that picking the UK keyboard layout during the kali setup seems to freeze the box
Yeah, just been reported, I will update the box and re-release it during the week
thanks!
No worries! 🙂
you'll need to move the other partitions
I cannot avail my student discount...My college domain is @sonatech.ac.in and @webportal.sonatech.ac.in
@fleet sluice It's only automatic for UK academic addresses
@eager fulcrum so can't i avail student discount?? 😦
@fleet sluice
I will add .ac.in to the student discount list
Visit THM tomorrow, and it will automatically update your student discount on your proifle
tqsm 🙏
Are you subscribed already?
If so, I will need to update your payment amount manually
Otherwise yeah just wait till tomorrow 🙂
Hello everyone. I have a problem in the OSCP path Challange Corp. I have done all steps necessary. Decoded the encoded password. But still cant get login as Administrator.
It says "The password for this account has expired.", have anyone encountered problem like this?\
So I have a vulnversity machine deployed that I can't even ping after I attempted to get a proper shell working with python
wait no it doesn't crash but it does freeze for random amounts of time average 73% packet loss
Hey all, attempting to connect to the DVWA while going through the Burpsuite room, but I cannot seem to connect, even though it says the box is up, I'm able to connect to any other site
having a bit of bother getting hackpark online
@bold wave Are you subscribed?
Subscribers machines boot quicker qith more resources.
If you are not subscribed, it wont load as quickly.
Hi, I need some help with Nessus room. I installed Nessus on Windows, but when I run a Web Application scan on the host, its returning no results. Anyone who faced this issue/can help with it?
Are you connected to the VPN?
Does it say you are connected here: https://tryhackme.com/access
TryHackMe is a platform for learning and teaching cyber security.
Yes I am
Try using a Kali VM, either hosting one locally, or accessing s virtual one by subscribing to THM
Yeah, using Windows as a hacking platform is.... less than ideal
@eager fulcrum Thank you.
Guessing attacktivedirectory is still not working?
How do you delete an account? I don't know if I'm being blind but I can't see anything relating to deletion
You can't, email support directly hello@tryhackme.com
i dont think there is a way in the settings of accounts atm
but obviously you can - thm is gdpr compliant
They just use voodoo magic for parts of the site. Its why its so difficult to implement a darkmode/name changing/accounf deletion
:P
@mild jungle does the virtual one by THM have enough space for Nessus? It says minimum space recommended is 30 GB
I had installed Nessus on Ubuntu, but I started running out of space because of it, so I switched to Windows
is it just me or does the vpn connection seem very unstable ?
@glossy cairn probably just you. Check you only have 1 instance running
@eager fulcrum i do 🙂
@eager fulcrum will regenerating the conf file cause any existing connections to disconnect ?
Not 100%
cuz after doing so and closing my vm it still states Connected
aight
not currently, but a little while a go it kept sending PUSH REQUEST and then after the connection was established it kept restarting after a while
Yeah I think that's normally when you have two connections running
hmm weird
well for now it seems stable
now its not ..
Tue Feb 4 12:40:44 2020 TLS: new session incoming connection from [AF_INET]18.202.129.195:1194 Tue Feb 4 12:40:44 2020 TLS: new session incoming connection from [AF_INET]18.202.129.195:1194 Tue Feb 4 12:40:46 2020 VERIFY OK: depth=1, CN=ChangeMe Tue Feb 4 12:40:46 2020 VERIFY KU OK Tue Feb 4 12:40:46 2020 Validating certificate extended key usage Tue Feb 4 12:40:46 2020 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication Tue Feb 4 12:40:46 2020 VERIFY EKU OK Tue Feb 4 12:40:46 2020 VERIFY OK: depth=0, CN=server Tue Feb 4 12:40:46 2020 TLS: move_session: dest=TM_ACTIVE src=TM_UNTRUSTED reinit_src=1 Tue Feb 4 12:40:46 2020 TLS: tls_multi_process: untrusted session promoted to semi-trusted Tue Feb 4 12:40:46 2020 Control Channel: TLSv1.2, cipher TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Tue Feb 4 12:42:52 2020 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1) Tue Feb 4 12:42:57 2020 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1) Tue Feb 4 12:43:02 2020 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1) Tue Feb 4 12:43:07 2020 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
If material has been "successfully converted", how can I add it to my room? To e.g. deploy an instance?
I can't find anything in the room settings that makes reference to it
can anyone help me im struggling to deploy my machine ?
both on my laptop and PC i have made sure that my openvpn is connected with the config file imported and i deploy my machine but the box doesn't open even after waiting for 10 minutes
nvm at what I said, figured it out
@humble vortex if you go to https://tryhackme.com/access on the device you're trying to connect from, do you see anything like "Connect [tick]" and your "Internal Virtual IP address"?
TryHackMe is a platform for learning and teaching cyber security.
remember to only connect to the TryHackMe network on one device at a time! This always catches me out 🙂
yeah i am connected yet when i go to deploy a vm the only options i have are terminate and add 1 hour but i cant see the vm on the web page
So you see something like this?
yeah thats all i see
If so, try pinging the IP address
depending upon the challenge, you may not be able to access it just by going to the IP address on your browser
E.g. a web server might be running on port 8080 and not port 80 (which is the default your browser would try and connect too)
That's where you have to enumerate and figure out what is running and where 🙂
the ping worked
Sweet!
So the instance has definitely deployed okay, and you can connect to it fine
Now you just need to enumerate it and figure out what's running on it 🙂 (nmap!)
The Nmap primer room is super-useful in getting used to the syntax of Nmap https://tryhackme.com/room/rpnmap if you're unfamiliar
TryHackMe is a platform for learning and teaching cyber security.
is it meant to deploy a box like in the linux challenges?
not necessarily, it depends on the challenge. Out of curiosity, what room / challenge are you trying?
If it has an "Deploy" button, generally speaking it will launch some sort of VM, it might take a couple of minutes for it to fully launch although.
is that meant to deploy a terminal or do i access it by putting the ip in a browser
and you get no useful output from Nmap when trying to use it?
Oh!
No, you have to put that IP into whatever you're using e.g. Kali
Oh thank you i got used to the linux challenge format
and thought that was the way the vm was meant towork
Ah gotcha!
thank you 🙂
you're more then welcome, glad it's all sorted 🙂
@humble vortex Whatsup?
any admin able to help me regarding some technical problems
@deep trellis @rigid oxide anyone of you available :)?
getting this error Tue Feb 4 17:45:30 2020 /sbin/ip addr add dev tun1 10.8.21.103/16 broadcast 10.8.255.255 Tue Feb 4 17:45:30 2020 /sbin/ip route add 10.10.0.0/16 metric 1000 via 10.8.0.1 RTNETLINK answers: File exists Tue Feb 4 17:45:30 2020 ERROR: Linux route add command failed: external program exited with error status: 2
Oh you have multiple instances of the vpn open
You can only have one instance of the connection open
sudo pkill openvpn
Essentially your system is complaining that it's already connected and that the route already exists, just might have gone inactive if you haven't done anything in 30+ minutes
aight
pkill openvpn will fix that?
or do you need to kill any old session from your end
?
Should kill all instances of ovpn
Then you start a new one as normal
You could also find the process id using ps -aux and then kill <id>
might need a full system restart
I recommend using tmux and running the vpn in a tmux tab
yeah doing that 🙂
like now, i have deployed kenobi @ 10.10.248.252
now its not responding to pings anymore
timed out
now it is
weird
do the boxes usually flap in their connection ?
yeah
happens to me all the time
on all boxes
:/
thought it was vpn
but it appears stable Tue Feb 4 17:55:55 2020 Preserving previous TUN/TAP instance: tun0 Tue Feb 4 17:55:55 2020 Initialization Sequence Completed
times out all the time, and then it comes back
@rigid oxide Do you know what the problem might be... :)?
Maybe your internet? Check to make sure it's stable
it's table 🙂
I'm not quite sure what's going on there
weird :/
Don't forget, the boxes will take a minute or two to boot
yeh but it has been up for a while, and still keeps doing this
@deep trellis cannot avail student discount
@fleet sluice ?
DM me, I added your .ac extension, you should have it if you're using your student email
Having a strange issue, the bruteforce attack on a specific themed box is taking a very long time. I re-deployed, any suggestions?
@deep trellis
yo
Sorry for the ping, not sure how to handle these issues.
Oof.
Yeah so odd
Only 1716 passwds too
omfg lol
🤣
If you subscribe you can use a Kali machine (on the same network, so remove the OpenVPN requirment) which will speed itup.
However you shouldn't need to, not sure why its taking so long. This week I am adding a new OpenVPN server to the network
So spread the load
Perhaps that will help
Understood, I will absolutely be subscribing.
I can't suggest much other than that I'm afraid soz my dude
So I look forward to that
Ey cool, cool
It's okay 😦 I'll just see if it loads 🙂
Yeah, by this weekend there will be another OpenVPN server, Ill move you over to the fresh one
And perhaps you can re-test?
For sure, I appreciate it.
I can try to regen the VPN and see if that helps
Dont want your scan to break
lol, want me to extend your machine by 10 hours?
So you can leave it over night?
lol
haha, sure!
Got it! Thanks again!
Was a crappy solution, but will do for now
Eyy, thats really great to here
This year we have lots coming
Networks (coming in march), recruitment, mentorship programs, videos + 10 other stuff I'll keep private for now
So stay tuned
I will absolutely be staying tuned, expect a subscription soon ❤️ 🙂
Anyone connected to the VPN that can check if a box is up for me? Been a good ~15 mins and not seeing anything on it..
yeah sre
Cool cool, DMing
Are we able to remove "Materials" that we have uploaded? I've got a VM up there that isn't necessary any more ... seems like a waste to just keep it stored there. Unless I'm missing something?
Not yet but I think it's been requested
Ah coolio, cheers @eager fulcrum
I have a couple versions from WiFi hacking that I want to delete
Skidy might be able to help with that
It's okay, it's not at all urgent! The OVA was something shy of just over 2GB IIRC, just thought y'know - storage costs and all
I think there ended up being 5 copies of my next room's VM on the back end, something like 25-100GB
yikes
cloning it was easier than making a 5 minute change and uploading for 2 hours kek
cloning the room or cloning the material? O.o
material
I am so glad it's not just me that's got a bunch of outdated VMs up. Being able to delete them will be a gift.
Hey guys
I just signed up on TryHackMe
I don't know anything about cyber security but i do have some experience coding
Do you guys have any tips for a beginner like me?
Do walkthrough rooms
Take notes
Eventually you'll kind of have your own personal wiki of commands/tools/resources etc.
I at least do
No way I could remember all the stuff
feel free to DM me if you want other advice @coral citrus
I really appreciate the help!
it looks like your room completion list on your dashboard isnt calculating the completion correctly
@deep trellis @rigid oxide
not sure but i know you just updated that room
earlier today i also had to re-complete a question in that room that had already been answered ... but it didnt change anything
hmmm @deep trellis might have to take a peeksie here
Hey guys, anyone fixed the Attactive room yet?
Should be done soon! I know Spooky was working really hard on that last ngiht
any admin here rn ?
Just post your issue
@mossy ermine So Kaliroom is 100% complete, but on your dashboard its just showing as 50% complete
it was yesterday let me check again
it is currently not showing but i posted proof yesterday @deep trellis
if the room progress was expandable i could see all rooms but currently it only shows three at a time
or a scroll bar
it looks like it ranks by percentage of completion so it should be showing as my second is 48 % and kali was showing at 50%
Weird, I'lll check it out
Hi there - question, is the connection to the rooms more stable when becoming a subscriber?
@molten bolt Machines will deploy with more resources, so in theory yes. But it should be stable when deploying as a non-subscriber too.
Ok discord,
How would i decode/ decompile a file like this
http://72.2.249.206:39021/Mozi.a
uhhhh
hexeditor?
text editor?
strings?
ngl but there is no way on this planet i am even attempting to download that file to see how it's possible to do it
if it's just a normal file, strings, hexeditor, open it in radare2 maybe, binwalk
big monkaS energy
bliss 
Just inspect it in a vm if you're so scared
I opened it in notepad++ and it was all garbled as if it was a exe file idk bruuuuuuuuuuh
or you could inspect it in a vm so that you're not scared, using the tools that @warm spear suggested. Remember that this environment is primarily for sharing knowledge and learning. This channel, specifically, is for "VPN and other technical questions related to TryHackMe". It's not to get people to solve your problems for you, and I say that in the kindest sense possible. Take it as a learning opportunity, by all means ask for help (probably over in #thm-community-media, but a mod or admin would be better confirming that) -- you'll find that it's a very supportive community -- but please don't ask the community to just outright do it for you.
I want to do it but idk how,
In terms of expanding on that advice, for the record, I would suggest looking at it with strings in a Linux VM. See if there's anything that stands out as being particularly abnormal. Failing that you're probably going to have to decompile it with radare2.
Like @warm spear, I don't fancy downloading it myself to take a look at it, but I would use file on it first, as you say it looks like an exe file, but you're not sure
file will give you an idea of what kind of file it actually is. If that fails you could use hexeditor to take a look at the magic number manually, which might also help
I see, thanks for giving me your insight
It's a botnet
Or that...
Specifically for routers
So it is: https://blog.netlab.360.com/mozi-another-botnet-using-dht/
Thanks @steel rapids
Mozi Botnet relies on the DHT protocol to build a P2P network, and uses ECDSA384 and the xor algorithm to ensure the integrity and security of its components and P2P network. The sample spreads via Telnet with weak passwords and some known exploits
Never underestimate the power of google
I have no idea how you're so awake at 0100.
Yeah, Googling it should probably be the first step before breaking out the decompilation tools...
Because I woke up at 7pm 
Lmao I'm glad I didn't open that file then 😂😂😂
That would be it smh
but thanks for the virus, might come in handy
Stroke of luck that
@naive dust please don't post viruses lol
Can't believe this is actually necessary, but might be an idea to explicitly put that in the rules...
@rigid oxide?
tbh I think it's a given
I think my request was more from a user than a moderator but you'd be surprised. Assumptions are different for different people
I thought it was a given too...
I think we also need a rule about blackhat activities etc too
Wasn't that added a little while ago?
I'd say Malware comes under that one under many jurisdictions
It's a little complicated
I would agree with that analysis, which is part of why I can't believe it's apparently necessary to explicitly state it 😄
Just an idea though.
Maybe an addition to the rule. See what dark says I guess
all done
the fuck
Haha the discord/community on the whole is one of the major two things I manage
I have that and I'm the content director administrator for the site
Hence the quick rule introduction
I like how most of the recent rules could fall under "don't be a script kiddy" but that sounds too harsh on people just starting out
Skidy's are welcomed here 😉
Uh, is that what Skidy stands for?..
scriptkid=skid=skidy
Yeah, I see that now, I just didn't make the connection between that and our great and glorious leader 😁
!dark
Wondering how to make rooms and content, what would be a good starting point? Any tips appreciated :)
What kind of thing are you looking to do @copper mist?
@copper mist Really find a topic you are interested in, and learn. Detail how you learned that topic, and you have a room
Right, can someone explain this, once and for all:
Kali subscriber machine, access in browser. What, the heck, are the creds
Ah yeah, it's hit or miss with it working. I remember there was a fix
It should automatically auth?
The new or old kali machine?
Huh, that's a bug then @deep trellis. This literally happens with every machine I deploy that has browser access -- always has.
I usually just skip it and log in a different way. I just can't be bothered booting my laptop just now and I took a bad screenshot earlier...
MuirlandOracle
Thanks 😁
Try now
Just redeployed 👍
I'll let you know if it lets me straight in
Yep, that's done it @deep trellis , thanks!
Why does it take more than 1 ctrl+c to clear the line in linux?
How does one get the OSCP basge on their profile 🙂 sorry if its not for this channel
@maiden pike No badge, but I could make one for the pathway
Ahhh nice yeah that would be cool
Could someone help trouble shoot this issue I am having with scp. I am trying to scp a file FROM my VM to my Mac machine. I'm using the command scp [MY_USER]@192.168.1.1:/root/opt/file.txt . however I am getting a permission denied. With Kali not removing root user, i'm guesing I can't type root@ip. I should note, I did open up port 22 so I should be able to pull files~
I can't get this metasploit module to work
I copied it into the correct location, and when I select it it doesn't actually select
is it possible to copy something from ur local machine to Kali browser? Cause I can't get it to work
@warm spear internet is broken on kali machine for now
Hi all, I'm trying to create a room to use for some recruitment challenges. I've seen some other rooms that have an initial task walking people through connecting to the VPN. Is that a resource I can use or do you need to write this?
Also, I've seen in these other rooms a box above the chart and underneath the description which can offer logos and terms of service etc. How can I put this in? e.g the pwcbsides room.
You could link to https://tryhackme.com/room/openvpn
TryHackMe is an online platform for learning and teaching cyber security.
@weak beacon email us : hello@tryhackme.com - some rooms (if you're the owner) allow you to generate detailed reports about a candidates progress (talent assessment platform)
We can also brand the room etc..
@steel rapids thanks. @deep trellis I will definitely send you an email about this as that sounds just what I'm after.
np
I have emailed. Thanks for that.
Just seen, someone will respond (most likely me) in the next few hours - thanks :)
@lost lantern So what's happening/not happening?
Hey, so basically I finished Task 1 and Task 2, working on Task 3 now. I am connected via the VPN and every time I try to Deploy the room, nothing happens, it just shows http://prntscr.com/r2sbwi
@uncut hound It worked for you, right?
@lost lantern I'm explicitly prohibited by Tobi from joining the room, so there's a limited amount that I can do to help
@deep trellis might be able to take a look
Worked for me
have revisited this room every other day to update my report so can confirm it works
So it's an issue just for you, so I think one of the admins might be able to check out the AWS instance for you
Skidy won't be back for a wee bit as he's has been out today
I'm having the same issue
Cheers, dude
Weird...
Let me try again
did you deploy the Kali one or the CW?
cw
Ensure you click deploy and leave it for a couple minutes, also make sure you are connected to ovpn the entire time
Once you click on "Deploy" (http://prntscr.com/r2sjmo), after a few minutes and with a refresh, I'm supposed to see a kali screen?
CW one
Where did you get the "10.10.229.104" IP from?
^^
It worked
Where did you get the "10.10.229.104" IP from?
@lost lantern Still have this question though
If it doesn't show up, that's an issue
When i want to connect to the ip with remote connect I need login
Yes it worked properly
Do you know what the problem was?
Actually I was just deploying the wrong way. Make sure you are connected via OpenVPN and once you go to Access page it shows that you are connected. Then go and Deploy the Kali Linux Room, and use the IP Address that appears to you when you Deploy the CW room. It should show you the frozen yogurt company's website.
Hi, im having an issue with my kali VM. I've set-up kali on VirtualBox and I have both the openvpn running on my kali vm and my actual PC however when trying to access the VM launched on the room it times out 80% of the time. Sometimes the connection will go through however sometimes it'll just time out. Any advice?
On the Kali machine you do not need your OpenVPN connection running
You can only have ONE openvpn connection at a time
Getting disconected every 2 minutes? Only 1 OpenVPN connection is allowed.
Hope that helps
So I should only have the openVPN connection on my main PC and not my VM?
Only one one machine, but the Kali (deployed from THM), you dont need an OpenVPN connection
Ok, so i've only got my openVPN connection running on my PC and NOT on my VM however im still getting timed out
My connection to google and that is all fine on my VM but I cannot connect to the room
It depends on how you've configured your VM (network wise).
To ensure its not us, disconnect from everything, deploy JUST from your main PC (not a VM)
And see if you can access a machine
TryHackMe is an online platform for learning and teaching cyber security.
My Openvpn doesn't have the import option
what do you mean?
@spark timber what's your host OS?
win 10
Are you looking down here?
im re-installing just in-case i've got an outdated version if thats an issue
Yes I am
Okay, yeah reinstall
Ok so i've reinstalled and i've got it all set-up and the connect seems fine on my host PC. However, still getting timeouts on my VM. I've set the network up with NAT on my VM and I am ONLY running ONE openVPN connection and thats on my host (just to clarify)
The timeouts don't seem as long however with the change but still getting them
@spark timber VPN from the VM, it'll give you a LOT less hassle
ok
ovpn should already be installed on kali iirc
so you just need to download your connection pack and sudo openvpn <username>.ovpn
Ah
Okie
Yep im still getting timeouts
It works fine for like 2mins once I set-up the VPN connection however after 2mins it just timesout
this is when it cuts out
and timesout
at 31:05
Also, I have STOPPED both my VPN connection on my VM & on my host PC however it still states im connected to tryhackme : https://puu.sh/FbfOl/c83d7aab36.png
(no openVPN processes running on windows via Taskmanager[host PC])
Are you running the VPN on both the host and the VM simultaneously? That will cause connectivity problems.
Also the connection status doesn't update right away
I am not no
At this point im not running the openVPN connection on either the host or VM
That's ok. that would be a rather silly thing to do 😛
but on my VM im still able to access the room
@spark timber the THM connection panel isn't 100%
I think you're probably running the VPN in the background unless it's a public IP VM
I've gone through task manager on my host PC and there is no openvpn task running
and i've closed the terminal for the vpn connection on my VM
Reboot your host machine and regenerate your connection pack then connect only from the VM
ok
Hi there. I'm a new user and couldn't find my answer on the website. Is there an option to create a room and limit who has access to it (via a password or some other means)? Goal is to have a private challenge hosted.
Mhmm
New rooms are private by default
You can change the room password and give it out to only those who you want to have access to it
You can change the room password and give it out to only those who you want to have access to it
@rigid oxide Thank you so much
You're welcome! ❤️
Not on Kali, but:
➜ sudo apt install john
[sudo] password for bee:
Reading package lists... Done
Building dependency tree
Reading state information... Done
john is already the newest version (1.9.0-Jumbo-1-0kali3).
0 upgraded, 0 newly installed, 0 to remove and 114 not upgraded.
~ took 3s
➜ john
zsh: command not found: john
Even on Bash 😦 Any ideas?
bee@bee-pc:~$ john
bash: john: command not found
That's an oof
ok i found the actual binary of where john is
Is it just not correctly loading the path?
yee
ok thanks
Same as windows
<@&568449888682246145> I m not able to pay with my card (it has 19 numbers) and paypal lets me pay only for 3 months. i want to start with one month.
I ll do just now, thx
Thanks
@deep trellis email sent, thanks again. hope for an answer
hey, i been having connectivity issues with the VPN for a couple days. it just seems to disconnect every like 30 seconds.
Sounds like you have 2 VPN connections running
i kill the openVPN connection (ctrl+c) and then reconnect again and its fine for another 30 seconds
do you think if i regen the vpn config file it will sort it?
yeah think your right
who is this stranger hahahaha
Ah looks you're running it in the background
bloody thing ill kill it, thanks Skidy!
Restarted vm, regenerated openvpn file, my connection is excellent, i’m connected with openvpn. However, when i deploy the machine i cant access the ip
Any help?
Btw the room is: Vulnversity
Yea i did, and it was successful
It might take a few minutes to configure
I guess its just with vulnversity because i just tried accessing another box and it worked
Maybe tho i waited
<your machine IP>:3333/
@deep trellis the card thing is an issue with Stripe, they only accept 16 digit cards
I posted a link in general
Kinda sucks but no ETA on a fix
Well, that worked thanks😅
Yeah, Stripe are good have their limitations
Yeah, my credit card didn't work with Stripe altough it's standard 16 credit card
Had to use another card
is there a way to change University in a created Team ? I mean other than uk universities, Mexico University for example.
UK only for now
Are you sure it's running a web server that you'd be able to connect to with your browser?
hey, so i'm running on elementary OS and i came across your website today. so i installe dopenvpn, and i'ms tarting it with my config file. in the access panel on the website it says i'm connected, and it's serving me a internal ip address
and it just worked
oke wtf
ty !!
If it's connecting to a VM, they take a while to deploy
Not always but sometimes
Can anyone help out with this error?
Wfuzz runs normally for about 5 seconds then spits out this and stops working
wfuzz -w subdomains-top1million-5000.txt -u "cmess.thm" -H "Host: FUZZ.cmess.thm"
is what im running
anyone help why when i try log into the kali machine i get invalid login?
Can you send a screenshot @naive dust?
