#site-support
1 messages Β· Page 248 of 1
is that on a europe vpn? if so it's a known issue, try changing the server
EU-Regular-2?
done
different server working?
vpn is connected but not able to ping the machine & also the site is not showing i'm connected as well. tried regeneration the vpn pack & updated my openvpn still nothing
For a moment I thought that's a picture of an online casino slot machine π
When conducting an NMAP scan on my POLOTELNET machine it says that no ports are open. Any Ideas? Firewall issue?
I've tried with and without the OpenVN THM connection
I'm on EU-REGULAR-1
I'm not having issues with NMAP on any other IPs
Hey friends! Does anyone know how the THM Attack Box differs from the usual Kali image? I've been using the browser-based VM as a subscriber, but wanted to play with setting up my own home VM to try OpenVPN access and to have some configuration persistence between uses. Is the difference just that it's pre-configured for access to THM machines, or is it further customized than that?
As it seems like I'm not the only one having issue when behind a VPN, is there a ticket for this issue?
Hi eveyone..This is the place to ask something about linux?
I try to install, and stuck in some levels..I forget how to that and my friend Google(haha) doesn`t give the answer
What's the problem you are facing?
Is tech-support the wrong channel?
Maybe use #site-bugs
I having an issue with target machine not working. I already restarted the machine multiple times and also re downloaded my openvpn file. The issue still persists.
^same
More details would be great. What room, what task, what exactly is not working - so what have you tried ?
All of the rooms in Network Services 2. I ping the target machine and get 100% packet loss. I restarted the machines multiple times and also re download my openvpn file.
So you are on a VM or installed OS ?
Sorry it's actually all the rooms on Network Services. It's an OS.
Sry I didn't get that, it is an installed operating system ? Or a virtual machine you use as attacking machine ? Or you are using the web based attackbox?
yeah im using Kali linux as OS. It's my daily OS.. I connect to THM via openvpn.
Okay. Are you able to open 10.10.10.10 in your browser?
yes flag{connection_verified} Your VPN/TryHackMe IP is: 10.6.97.119
Can you ping 10.10.108.215 ?
yes PING 10.10.108.215 (10.10.108.215) 56(84) bytes of data.
64 bytes from 10.10.108.215: icmp_seq=1 ttl=61 time=102 ms
64 bytes from 10.10.108.215: icmp_seq=2 ttl=61 time=95.9 ms
64 bytes from 10.10.108.215: icmp_seq=3 ttl=61 time=98.1 ms
64 bytes from 10.10.108.215: icmp_seq=4 ttl=61 time=98.7 ms
64 bytes from 10.10.108.215: icmp_seq=5 ttl=61 time=97.8 ms
64 bytes from 10.10.108.215: icmp_seq=6 ttl=61 time=99.4 ms
64 bytes from 10.10.108.215: icmp_seq=7 ttl=61 time=98.0 ms
64 bytes from 10.10.108.215: icmp_seq=8 ttl=61 time=93.9 ms
64 bytes from 10.10.108.215: icmp_seq=9 ttl=61 time=95.7 ms
64 bytes from 10.10.108.215: icmp_seq=10 ttl=61 time=93.8 ms
64 bytes from 10.10.108.215: icmp_seq=11 ttl=61 time=92.0 ms
64 bytes from 10.10.108.215: icmp_seq=12 ttl=61 time=92.8 ms
64 bytes from 10.10.108.215: icmp_seq=13 ttl=61 time=98.3 ms
64 bytes from 10.10.108.215: icmp_seq=14 ttl=61 time=92.7 ms
64 bytes from 10.10.108.215: icmp_seq=15 ttl=61 time=97.4 ms
64 bytes from 10.10.108.215: icmp_seq=16 ttl=61 time=97.8 ms
64 bytes from 10.10.108.215: icmp_seq=17 ttl=61 time=97.1
Alright, so if you can ping that machine, that means the machines should be working fine for you in that room.
What's the Title of the target machine you have started atm ? It should be in the active machine information box on the room site
ftpfinal. It's working now! I don't know what you did but thanks a lot!
Gave +1 Rep to @crystal marlin
lol, well I did nothing, I can not even do anything beside trying to help you here in discord, but glad it's working now π
I've been having this problem since yesterday. Thanks again! π―
Hey. I'm having an issue where all the machines I use as part of the web-fundamentals course have a tendency to freeze and become unresponsive every 3-5 minutes. They do come back to life after 2 minutes of waiting. Has anybody faced a similar problem?
Are you on the web based attackbox or your own VM/install ?
Virtual Box
Now I'm thinking it could actually be the VPN. Might try to switch to another server
I would try to do sudo ifconfig tun0 mtu 1200 any see if that helps. In case it doesn't just but it back to 1500
Will try. Thanks!
Gave +1 Rep to @crystal marlin
Did it work?
I think it was the VPN. Just switched to a new one - works fine. Thank you!
Gave +1 Rep to @crystal marlin
Hi I try to use the VPN but I get error, it`s new machine and when I try to open the file openvpn I get something else
You see that there is a typo in it ?
this is when I try to use the openvpn
sorry, I don`t understand what you mean
In the first picture you typed "insatll" instead of "install"
Great π
ok but I still get error
Are you sure the file is called like that ? I think the config file has the ending .ovpn - Maybe change to your Downloads folder and type ls -al to check the file name
Have you changed the server or regenerated the config file on the access page on THM after downloading that config file ?
I would re download your config file and try it with the new one. And don't change server or press regenerate after downloading your config file, as the file might not work anymore after you do that.
otherwise..I thonk my error it`s about the IPV4
Becuase I tried downlaod again and still get error
and now I try to download again the file and I get 404
But you have internet access on that machine, right? So you can open websites in the browser of that machine, right?
yep
So do the following, delete you old config file in your download folder to make sure you have the new correct file downloaded, change vpn server, press regenerate, wait 3+ mins before trying to download the config file (as it's taking a little bit of time to regenerate the file). If the issue with 404 error keeps appearing follow these instruction: #site-support message
ok thanks I will try that
Gave +1 Rep to @crystal marlin
@crystal marlin it`s differnter between EU-regular-1 or EU-regular-2
I don't know what you mean
But either way what you meant, if you are subscriber you could choose the VIP servers, what I would do rather then going with the regular ones.
Ye I know what servers are there, but I don't know what you were asking me. But anyways, I would pick the EU-VIP -1 or 2
What changed here ??? What is outdated ? If you are referring to the new MITRE Engage site it doesn;t even have Use Cases anymore.
And the correct one in SHIELD site is the one I am putting in and it is saying it is wrong ??
well I dont understand what is differnet between VIP to regular..but VIP2 its working for me
thanks π
VIP is only for subscribers and regular for all. So most probably the VIP servers will work better due to not as many people use them as the regular ones. As far as I know.
ok thanks...I will continue after I watch the game
Hi guys im trying to do the room "owasptop10" but the vm "Injection v4" wont load. I can ping the machine but it wont load in the browser, i left it fort about 5 min. Anyone know what im doing wrong? The ip is 10.10.123.144
What task number is it and what's the url you try to open ?
Task nr 5, http://10.10.51.136 and http://10.10.51.136/evilshell.php
But i just restarted the vm so its still booting up i think
Its doing the same
Are you on the attackbox or VM or installed os ?
So you can open 10.10.10.10 just fine?
Yes
Have you tried ctrl + F5 already?
Could you send a screenshot?
It wont let me
You would have to verify first
But canb i dm u?
!docs verify
I would just verify so in case you need help in the future you can send screenshots
Mh, anything in the dev console that would give you a clue ?
Could this be it?
Not sure if that could be the issue but somehow I don't think so. Anything else?
I do find something weird, when i open devtools and do shift+ctrl+r i can see a bit of the page, but when i close devtools its gone. And i cant type in the input field when in devtools
I would try to restore firefox to it's default settings
Well i tried it in the attackbox and it works fine
So i think that could be it
Could it be something with the vpn? It also doesnt work in chromium
Maybe, you could try sudo ifconfig tun0 mtu 1200 to see if that solves it, if it doesn't put it back to 1500
Well uhh, good news webpage loaded fast. But it also froze my entire pc
Not just the kali vm but also the host
Uhm, that sounds strange ^^ You have openvpn only inside your kali VM, right ? Not on the host machine too ?
I'm not too sure, you have to look it up if you want to know it, but I think it's about packet size.
Well it works fine in my vm now and my host didnt crash again so thx!
Great, you're welcome π
Does someone know if there is a problem with the THM servers? I tried to download my OpenVPN config file but i'm redirected to the 404 page
@crystal marlin Thank you !!
Gave +1 Rep to @crystal marlin
hey, I just finished the "Penetration Testing Tools" series but I didn't receive a badge is that normal ?
is there a badge for that?
might not be in yet, I've done all those rooms but don't have a badge either, and can't see it as a badge in badges
Is there a link to it ? As I don't even have series on the site anymore. I do have that badge, but don't know how I got it ^^
I can't see it as an avaliable badge on here even, can you screenshot yours?
https://tryhackme.com/badges
mine ?
have you completed all these rooms?
Man, I would love to see these series, but as already figured out, some can still see them and others can't π
I think, new version if site might not have them implemented yet
and my account is still currently on the old version
yes all except john
ok, well I guess that's why you don't have the badge
Hello, downloading openvpn configuration for EU servers result in a 404 error. Works fine for other locations.
Have you tried that?
#site-support message
Try everything except log out, but I download the US configuration and it works
thank you it works!
Gave +1 Rep to @haughty glacier
Yep I saw that EU servers doesn't seems to work fine
Hey all. I'm going crazy try to fix my SSH connection issues. I'm 100% connected to openVPN (have IP in top right of machine in green bubble). I'm on my 3rd config file.
I've been able to connect to the THM machines before but now its just not working at all. Connection just keeps timing out
Anything on this issue?
I don't know if I should write here but I don't know where to put it. Why if I want to buy a subscription for a tryhackme month and try to pay with PayPal, I have to give a credit card? (I have funds on my account to purchase the service)
And what is this subscription about? how does it work and how can i turn it off?
If it's asking you about a credit card inside the paypal window while trying to pay, that's most probably related to paypal
And by any chance not with the fact that paypal simply gives you a tryhackme card so that they can take money from donation every month?
Could you rephrase that as I'm not quite sure what you mean ?
is that in my opinion I should not be asked for a card as I have funds in my account
although I suspect that paypal is asking me for a card so that it can activate their "subscription", which I don't even know how it works and how I can turn it off later
Hey, sorry about that. I ended up finding an old walkthrough. The identifier slightly changed. From SO to SU or something?
Well like I said, that's up to paypal and most probably not because THM choose to do so. And I suspect it is as this a recurring payment, they want some kind of security that the payment could be done every month.
ok, how can i turn off this subscription afterwards?
You just cancel it in your thm account.
SO you mean it changed from DCU0234 to DCO0234 ?
when I cancel subscription?
When are you going to cancel it ? Well that's up to you obviously ^^
That sounds right!
because I would only like to buy this service for a month, and I am afraid that if I give my card, then I will have a problem to cancel the subscription.
Well you could get the subscription and right after that cancel it, so you are not getting charged after the month is over but still be able to access all the subscriber stuff within the month you paid for.
ok, have you ever bought this service?
Sure, you can click on my name here in discord for example, everyone who has the "subscriber" role is actually buying the subscription.
have you had any problems with this tryhackme subscription?
Nope
This is a very legit and well known site, so there is no need to worry that much π
ok, thanks
Gave +1 Rep to @crystal marlin
how can i disconnect card for my account?
Having an issue with Linux Fundamentals 3. I was able to connect via SSH to the machine yesterday, but today it attempts to connect and a couple mins later, it says:
Connection closed by 10.10.15.116 port 22
This is before entering in a password
Nmap shows SSH is up
Initiating Parallel DNS resolution of 1 host. at 17:48
Completed Parallel DNS resolution of 1 host. at 17:48, 0.17s elapsed
Initiating Connect Scan at 17:48
Scanning 10.10.15.116 [1000 ports]
Discovered open port 80/tcp on 10.10.15.116
Discovered open port 22/tcp on 10.10.15.116
Completed Connect Scan at 17:49, 22.79s elapsed (1000 total ports)
Nmap scan report for 10.10.15.116
Host is up (0.49s latency).
Not shown: 998 closed ports
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
Read data files from: /usr/bin/../share/nmap
Nmap done: 1 IP address (1 host up) scanned in 23.02 seconds
Tried on 3 different machines throughout the day today. This is connected through the VPN if that helps.
I was still connected to my VPN outside of the VM. I'm dumb. π
Is the room "SET" down. unable to ping the ip even after 15 mins . Also the nmap and gobusters are not getting through vpn connected . ping to 10.10.10.10 is fine. same from attacker box as well
same issue after terminating and powering up a new vm
Trying to crack this hash on john for a THM challenge:
$2a$06$7yoU3Ng8dHTXphAg913cyO6Bjs3K5lBnwq5FJyA6d01pMSrddr1ZG
Here is the command im using:
john --format=bcrypt --wordlist=/usr/share/wordlists/rockyou.txt hashfile
The error im getting:
No password hashes loaded (see FAQ)```
Hi I am not able to download OpenVPN config file. Getting 404 error. Can somebody please help me ?
Not quite sure what you mean, if it's about not getting charged after the month we have spoken about, you simply have to press Cancel Subscription
Have you checked if you already cracked it maybe? john --show hashfile
Morning!
I had a short break and yesterday went back to my Linux fundamentals 3 rooms.
I found that I cannot connect to the machine via SSH. (Permission denied)
Tried the default credentials (AttackBox)
Did I miss something?
The syntax is ssh user@IP you did it the other way around, IP@user
Haha what a shame.. thanks a lot! π
Gave +1 Rep to @crystal marlin
Not a site issue but your JTR version is broken.
There are some steps online that might work (you will have to google your error), but the only way I fixed this was literally by reinstalling and setting up the whole of John.
I had this issue during one KoTH game. john wasn't working for my regular user. I had a terminal session logged in as root and tried there.
It worked for it.
So possibly, you can try to clear the .config or .cache for john
install after purge should work as well
BTW, for me john stopped working after Ctrl+C (I used that to stop it)
heyy
when i try to download the openvpn config file, it redirects me to /404
any solution around it?
can I change my nickname in THM?
I think yes, but therefore you might have to send an email to support@tryhackme.com and probably the best to include your current username, your new username and your email address.
ok thank you
Gave +1 Rep to @crystal marlin
linkedin link is not working properly
Why am I getting SSH connection timeouts when trying to connect to THM machines? Iβm connected to the VPN and have tried different config files (on my 3rd). It worked before but now it isnβt working at all.
it might be related to this
I was testing this MTU size stuff recently.
If this solves your issue, and you want to keep this change.
Create a backup before testing it out
You can add the following line to your .ovpn file

tun-mtu 1200
I made all the changes but still getting timeout. I could visit the 10.10.10.10 webpage and it said I am connected the servers. I ran the GitHub ovpn troubleshoot tool as well but that still hasnβt helped.
Iβm using Kali Linux in a virtual box and trying to connect to the NMAP machine in my lessons
is the room you are doing nmap?
Yes, as part of the complete beginner pathway
what task are you up to? (trying to find one that requires ssh)
Did you read the "Please note:" in task 1 ?
yeah, I think your main issue here is that machine likely doesn't even have ssh and I don't think any of the tasks require it
Iβm in task 4. I just read that note now. I guess this is my problem all along.
so, you use that machine as the target of your nmap scans (that you run from your kali system)
should be good to go π haha
Iβll be sure to read everything thoroughly to avoid this. Iβm going to try SSH a machine that actually requires it to check everything is still working
ok
I successfully logged into Linux fundamentals part 2 machine. Things are working. It was just me being a complete beginner and not reading things properly. Thanks for pointing me in right direction
main takeaway here would be just remember not all machines will have a website, not all will have ssh etc etc just follow the instructions and if something doesn't make sense, you likely missed something (on a walkthrough room), doesn't hurt to ask though π
Yep I 100% will keep this in mind. Note taken π
I'm trying to access https://tryhackme.com/room/rpmetasploit but the loading time is endless..
loaded for me pretty quickly
maybe refresh your page or browser? other stuff working OK?
it does have an embedded video that might make it take a bit longer than a room without
I tried for weeks and let it load for an hour in a tab, it doesn't load
https://tryhackme.com/room/hackpark doesn't load
same here, doesn't load
I think we can narrow it done to rooms that have embedded media (video) that tries it to autoplay when loading room
I see you talking about that for days already, maybe try to send them an email to support@tryhackme.com to see if you can get some help with that π
I was sent over to this channel
Oh okay :/
so if you a thm staff, maybe you open a ticket?
as it seems others have same problem?
what do you think?
And to just turn off your personal VPN is no option for you? Or maybe try to use a different VPN provider.
No way
I'm not staff
ok
Because it appears to have something to do with your VPN provider. I tried the same pages with my personal VPN provider and it was working just fine.
Yes, because I configured the VPN to block trackiing, ads, and crap sites
Is the issue because of the embedded video script making some HTTP requests that are getting blocked by your external VPN causing the room page to not load anything after that?
exactly
k4wld, I responded in #site-bugs, if you're purposely blocking traffic and it's denying access to our site, that's not our problem π
Isn't there any option to provide a whitelist for some requests?
lol
Straight, but right π
not our problem, that's the asnwer we love
Well, it isn't:)
As you're purposely changing configurations and interfering with the traffic, that's something you're doing.
If it works perfectly fine without and whatever you are doing is interfering with it, then it's not something we're going to "fix".
You can probably try to allow some of those HTTP requests, I don't think they can cause any issues.
Given that they are provided on TryHackMe site
the good thing is that 98% of the rroms work just fine
so if you keep these rooms with loading videos as is, it's your decision
I can't do anything about it
I mean, you cannot say that the TryHackMe site is slow because you want to use tor (just an example)π
So, to be clear, your VPN is breaking the site?
yes, I have tracking protection on, similar to pi-hole. It's blocking porn etc, crap sites
so I can't switch that off
So your tracking protection is getting a false positive, and breaking the site.
Wouldn't you agree that means the issue lies in the tracking protection, not the site?
Yes, the ask to make the rooms like the 98% that just works and not load videos when starting the room and autoplay
it's a change I agree
Hey could I get some quick help with something friends
The fault lies with the VPN, fix that?
I'm trying to download my openvpn access configuration file thing, but it just 404s every time. I've googled it and it seems like other people have had this issue (forum posts on the site), but nobody seems to have figured out a solution.
Yooo thanks man. Sorry I should've looked first, my bad.
Hey @naive dust π
Want to take this into a thread to discuss it? π
Seems like there are other users that face the same problem
perhaps it's really an issue on thm
Okay, gimme a second
the javascript used or whatever
Idk if this is the right room for this, but I lost my streak and even the yearly-activity page on my profile shows I have atleast 1 event every day for the past 60+ days
Just to let you know, an event doesn't mean your streak can't break, for the streak to not break you have to answer a question every day, an event can be generated by simply starting a target machine π
Hello,
I wanted to make a telnet machine run from this lesson:
https://tryhackme.com/room/networkservices
Unfortunately, the problem is that I have been waiting 10 minutes and still scanning ip nmap shows me that the ports are closed
What's the nmap command you are using?
nmap ip
That's it? If yes, by default nmap only scans the 1000 most common ports, so if the open port is outside that scope, you won't find it without to specify how many ports to scan
only when it scans a telnet port does it show that it is closed
Sry, could you rephrase that as I didn't understand?
I entered the command:
nmap -p23 ip
and showed me that the port is closed
Alright, then the port is closed ^^ Why does the telnet port has to be on port 23?
because they have not written anywhere that there should be others. So that's what they meant, I guess
Well like I said, you have to do a proper nmap scan to find the open ports. Only scanning 1000 ports might be not enough.
that is, scan all?
the room is a walkthrough and it tells you what to do for each question, and I don't see any stating to do nmap -p23 ip
Right, do a proper scan.
ok sorry for the bother
it turned out that he is on a different port
sorry for wasting your time
Not a problem, glad you found it.
Yeah, but then there's also this.
I think it's more related to some background timezone stuff idk
π
Oh, ye I'm not saying that you didn't answered a question each day, just wanted to point that out for the yearly activity, so that you are not going to rely on that chart for the daily streak π
Dear team, I am on Linux Fundamentals -Part 2. However, I tried ssh(ing) into a machine and got the notification "ssh: connect to host x.x.x.x (my IP) port 22: No route to host". Yesterday, I ssh(ed) seamlessly, today the above error ca,e up, kindly assist pls. Thank you.
came up...
I am trying unfriend someone on my THM account but I cannot
Help please
The 'X' button is all the way on the bottom when I hover over a friend from the list and I can't click on it cuz the 'X' goes away when I move the mouse
Room - Upload Vulnerabilities
I am unable to navigate to any of the pages suggested uploadvulns.thm. Nothing works, overwrite..* shell.. all give me a cannot connect message. Unable to proceed in the room.
hey so I havent been in this server much and as such am not sure if this is a common issue but I connected to the open vpn on laptop with kali running on a virtual box within it (the vpn is running on the normal windows) and on tryhackme it says im connected to the vpn and have an ip and everything but when im trying to connect to any machine I run (such as the one needed for vulversity) it cannot ping the ip or access it in any way
you should connect to the VPN from within your VPN
did you add the entries to /etc/hosts ?
Quick question, when you connect to OpenVPN, it should be no different than connected to an attackbox right? I tried going to the local hosted site when connected through OpenVPN and it'd just keep loading
if you have done it right, it should be
Hmm well I can't connect to the address for some reason by using OpenVPN
either that or I'm just dumb
ok well, how are you connected? using a kali VM?
someone might accidentally copy ur username for whatever reason too btw probably not a very safe one to use here
(or anywhere)
i would like to ask a question (i am new )
i already connect to open vpn successfully , but i also cant see any thing like attack box appear
and i am using window ,not linux
its it need to use linux althought i success connect to tryhackme mechine
im not understand about the how attack box and the open vpn work...........
Check out this room https://tryhackme.com/room/openvpn
What room you were asking?
Linux Fundamentals Part 2
are you in task 2 atm?
yayaya
it say need my linus system
but im using window ,can?
the tryhackme attack box is expired
you have to use attack machine iirc for fundamentals 2, click this to start
I use my windows machine when I did this room while ago
oh so you cant even spawn it?
yah
its it same if i connect to openvpn and using cmd (window)?
same as the attack box? the result came out is same?
ssh is secure shell
task 2 suppose to teach you how to use ssh to connect to a machine
the mechine is mean like a computer?
yes
the tryhackme given mechine is like a virtual mechine right?
yes, virtual machine as our target
open vpn is using to connect to tryhackme network
what different between connect to tryhackme betwork and non-connect
what function of tryhackme network?
I believe this room explain it well what is thm openvpn network
oops sry i missed it out ""However, to access these machines you need to be connected to our network.""
@hollow otter thank you for helping
Gave +1 Rep to @hollow otter
glhf
??what is that
this one
reputation system in thm discord
cheers
How can i verify please guide me
!docs verify
oh i need this too
!docs verify
no no click on the link
lol
thanks
Gave +1 Rep to @hollow otter
Hi Team - I am currently on Linux Fundamentals - Part 2. I am tried changing from tryhackme user to root its asking me for a password, can someone assit with the pasword pls.
what task? i dont remember ever change user to root
Its Task 6
unable to ping this machine but and i am successfully connect through vpn
for some reason I can't catch any shells
but the vpn works
I've had this issue across my last few rooms
even when I try to mimic a writeup to confirm it doesn't work, it doesn't
I tried regenerating but that doesn't fix it
and I'm on EU-VIP-2 and EU-VIP-1
so what i do any solution
not every machine responds to icmp
tryhackme@10.10.60.229: Permission denied (publickey).Does anybody have any idea how to fix this?
its the burpsuite room
it means you need a private key and a public key in authorized_keys
to connect through ssh
where do I get them?
ssh works fine on other rooms
and I have my ovpn working fine in another terminal
so how can i scan the port not blue machine also not responding
nmap also not working
this part?
Guys, How do we change country in the profile.
Thanks for quick reply, it redirects to homepage π¦
Gave +1 Rep to @hollow otter
I've read that using that link will update timezone which also update county
Assuming you don't use vpn while clicking the link
Yes, no vpn
Is the country updated now?
No, same redirects to homepage
Hi someone should help pls. Tried running "wget http://10.10.224.16:8000/.flag.txt" on Linux Fundamentals Part 3, Task 4 and got an error.
Thanks dear, you rock
it worked!! π
Can someone assist pls.
Share the error dear
beautiful
share the error, to send a screenshot you need to verify your discord. Follow this linkl
!docs verify
Finding it difficult to paste the screen shot here after snipping
lets move this to #room-help
Kindly find the error received on Linux Fundamental - Part 3, Task 4
What does !rank do in #bot-commands I seen a few tried it but didn't seem to tell them anything, curiosity got the better of me so tried it also, but didn't tell me anything in the channel or via DM.
back before the bot disfunction it will return your rank on thm
Oh is the bot broken atm then? is that what you mean?
Ah ok gotcha
Hey, so uh if I ping the IP address of a VM deployed on TryHackMe it should respond if it's functional, right?
not always, and not that often even
Oh they've got no internet connection right
they just might not be configured to respond to pings
and well they have no internet mostly but that should be irrelevant if you are using the VPN or attackbox as it puts you on the same network
Ah I see, thank you
hello, someone can tell me whats the tryhackme support email?
thx mate
Gave +1 Rep to @zealous yoke
npnp
Wait I can give rep
Thanks
Gave +1 Rep to @haughty glacier
Oh nice, sorry for the ping though
all good
@ebon ore I am having similar issues a yesterday. No luck even with attack box or room such as set,
Not sure if this is the right place but is anyone having an issues with Autopsy in Disk Analysis & Autopsy? I canβt extract any files, they are extracted with 0 bytes. Can review the registry either.
Whats the best thing to do if the flag is not where it is supposed to be? I am guessing its just reboot the box but hopeful thats not the case.
How do you know where it is supposed to be ?
The Alfred box gives the location for the root.txt.
Ok, well unless you have deleted it I would say it should be at the location where they said it should be. But unfortunately I have not done that room, but would be the first time I heard that a reboot would solve the flag not being there, but maybe it does.
ya, seems odd for it to not be there. Guess I will terminate and start again.
If I don't make any mistake this channel is only for the website support and not rooms related, you should rather ask in #room-help
@naive dust Thanks. I have tried that but havenβt gotten a response yet.
Gave +1 Rep to @soft thunder
Any time
Anyone use crackmapexec with the mimikatz module and have it hang on 'waiting on 1 host'
it does the HTTP GET but never gets to the post
hello guys
I was playing koth and some guy restart machine just to kick me off
we was both root
and he changed password
then restart machine
..
sad
ty for this
Gave +1 Rep to @haughty glacier
hello people is the friends list working?
π That seems like the elegant way of getting the file across.
Hello anyone help me
i got my access succesfully
but i cant ssh to the mechine ,why?
I don't see any information in that room that you would be able to ssh into that machine, it's most probably just a target machine for you to attack and not to ssh into.
Erm so what is that mechine use for?
To attack it. Like scan it, try to gain access to it via an exploit etc.
that machine probably doesn't have SSH, might have RDP though.
it should open in the split view
Yes, or use your own setup, like a VM.
VM?
π
Oh yah ic that , so this mechine is browser-based mechine?
A virtual machine with for example a kali linux on it.
Erm.....yah i dont have kali linux as iam using window
naw they were referring to the attackbox
Yes, that's why I said using a virtual machine π
Oh
so the room is a guided room, just go step by step
you're skipping ahead a bit too much
So i just use attack box to attack the mechine ?
Oh yah it seen like im worried too much
Like I said, yes use the attackbox or set up your own virtual machine to attack it.
Yah my problem is i set up my virtual mechine in the pass is using ssh to the THM virtual mechine
So this time i cant ssh to it make me confused
ok there's a bunch of stuff open, but not 22 π
I think you are confusing something or I didn't understand you correctly. But the virtual machine to attack would be same as the attackbox, but it's just locally on your own system rather then being a web based machine to attack. It's like having another computer where for example kali linux would be the operating system rather then windows which is on your current computer.
unless they did something like Linux Fundamentals 1 first, which had an in-browser interface
Oh yah
oh i try to understand just now . u mean that window is not a virtual mechine that is able to attack?
so i need to get a virtual mechine from
attack box
thm given virtual mechine or
mine virtual mevhine
i can use virtual mechine to attack by this three method ?
No I'm saying you are kind of limited to use your windows operating system to attack targets. So kali linux for example is an operating system being packed with lot's of tools for penetration testing. Just google "set up kali linux virtual machine" maybe you'll understand better then. The attackbox on THM has nothing to do with installing your own locally virtual machine. But of course you can just use the attackbox, but as you are not a subscriber you are limited to 1 hour per day to use it.
erm... so the virtual box of kali linux is a type of vitual mechine?
like this?
what have you been doing on the site so far to get to 0x5?
you have two main options to connect to the site, attack box (web hosted system on THM), or using OpenVPN from your own system
most people using the OpenVPN route do it within a virtual machine for security & to use something like kali to hack with
the machine you deployed earlier is a 'target' machine - that you would attack with either the attackbox or OpenVPN connected system.
ohohoh it mean thm got provide two type mechine to use?
well THM provides "Targets" within rooms
and it provides and "attack box" you attack the "target" with
Up the top is the "Attack Box" - that you attack with
Down the bottom is the "Start Machnie" - the target you deploy to attack
Maybe watch that and get familiar with the kali virutal machine or just virtual machines in general. https://www.youtube.com/watch?v=wX75Z-4MEoM
What is a Virtual Machine? Magic...that's what it is!! In this video, NetworkChuck explains what a Virtual Machine is, when you might need one, and how to setup a Kali Linux and Ubuntu VM on Windows 10 with Virtual Box.
Virtual Machine Setup
-Download Virtual Box: http://bit.ly/368FS7Z
-Down...
Oh yah
What to do if my attack box is over limit
I got non-sunscribe
Use mine virtual mechine(like kali linux) to connect to thm network to attack the target mechine
That's where you either subscribe or get a virtual machine.
It is?
like I said earlier, you can use OpenVPN to connect to the THM network and use your own system to attack the target
Finally i understand it
you don't need a "virtual machine" @crystal marlin that is not the technology that allows you to do it
though, most people would do it from a virtual machine
Erm.....i confused again
Not sure what you mean.
Is it the kali linux as a type of virtual mechine?
If yes why @haughty glacier say no need virtual mechine
you said you either subscribe or get a virtual machine, you either use attackbox or connect with openvpn
you can connect with openvpn from anything
Oh oh oh
So kali linux is a virtual mechine ? But we still need to connect to open vpn to acces thm network right
however, yes, look into setting up a virtual machine for kali
https://www.kali.org/docs/virtualization/install-virtualbox-guest-vm/
This guide is about virtualizing Kali Linux inside of VirtualBox, allowing you to have a Kali VM. This is a great way to use Kali, as it is completely separate from the host, allows you to interact with other VMs (as well as the host machine and other machines on the network), and allows you to revert to snapshots.
Well, he is on a windows machine, so I don't think it's a good choice to just connect with open vpn and then go to attack targets. So that's why I'm letting him know to get a virtual machine with kali linux on it.
kali linux is an operating system
people use virtualisation software to run it within their operating system
that guide I linked above shows you how
Yah yah im using window so .....yab that is mine problem @crystal marlin thank
Gave +1 Rep to @crystal marlin
So i still can get linux if i use window as my operating system
yes. that is the idea of a virtual machine
As an example download the virtual box and install the kali linux ,then connect to open vpn then access to thm network , right?
Right.
yeah, download virtualbox > import kali > download ur OpenVPN config inside Kali > Conenct via terminal to OpenVPN > proceed to do THM
Hurry i finally understand what is the concept of virtual box..
Oh oh @haughty glacier thank you
Thank for help
I'll do it for Kodo as he is on cooldown for the rep π Thanks
Gave +1 Rep to @haughty glacier
Oh i am thinking why he didnt got rep
Alr cya
can I assume, that the "official writeup" i have to link in a room in order to go public is only accessible for the revierers, not for the room visitors/ctf challengers? or how do i launch a ctf room w/o writeup?
you may assume this π (just leaving this here for posterity)
just try to be sure it doesn't get indexed by google
I am connected to tryhackme but I am not able to ping the machine.
This is the room link:
https://tryhackme.com/room/linuxfundamentalspart3
Did you run through the troubleshooting script?
Not being able to ping a machine doesn't automatically mean there is something wrong.
I did run the troubleshooting script
I tried to access the machine using ssh command
but it is not getting connected
Could you try to open 10.10.10.10 in the browser of the machine you tried to ssh with and let me know if that works?
Yes, it is working now
Thank you so much!
Hello Tech support, I am having a problem downloading the OpenVPN configs.... I go to my access page, inside the OpenVPN room, Server is US-East-Regular-1, but when I hit Download my Configuration Files, the page i get isUh-oh, this page has been lost in the matrix.
Vaders Mask Goes Here
Perhaps, go to your dashboard
Hello everyone
Why is this appearing? It used to work :/ any help is really appreciated. Been trying to tackle this for an hour
Looks like your configuration file .ovpn is invalid, try regenerating another one
And/or update openvpn if it isn't up to date
I'm having VPN issues too:
2021-09-14 20:17:24 DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-256-CBC' to --data-ciphers or change --cipher 'AES-256-CBC' to --data-ciphers-fallback 'AES-256-CBC' to silence this warning.
2021-09-14 20:17:24 OpenVPN 2.5.1 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on May 14 2021
2021-09-14 20:17:24 library versions: OpenSSL 1.1.1l 24 Aug 2021, LZO 2.10
2021-09-14 20:17:24 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2021-09-14 20:17:24 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2021-09-14 20:17:24 TCP/UDP: Preserving recently used remote address: [AF_INET]63.34.238.50:1194
2021-09-14 20:17:24 Socket Buffers: R=[212992->212992] S=[212992->212992]
2021-09-14 20:17:24 UDP link local: (not bound)
2021-09-14 20:17:24 UDP link remote: [AF_INET]63.34.238.50:1194
2021-09-14 20:17:24 TLS: Initial packet from [AF_INET]63.34.238.50:1194, sid=9b127cad b039e1a8
2021-09-14 20:17:24 VERIFY OK: depth=1, CN=ChangeMe
2021-09-14 20:17:24 VERIFY KU OK
2021-09-14 20:17:24 Validating certificate extended key usage
2021-09-14 20:17:24 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2021-09-14 20:17:24 VERIFY EKU OK
2021-09-14 20:17:24 VERIFY OK: depth=0, CN=server
2021-09-14 20:18:24 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2021-09-14 20:18:24 TLS Error: TLS handshake failed
2021-09-14 20:18:24 SIGUSR1[soft,tls-error] received, process restarting
2021-09-14 20:18:24 Restart pause, 5 second(s)
Updated everything. Tried recreating and downloading the config file
This is for Wreath Network but having similar problems with the main config
The Access Machines pop up is not changing when i connect to Indian server VPN... Can someone suggest any fixes
Have you tried changing vpn server and then regenerate and download too ?
Thanks, I did, yes
ah sorry, didn't try changing the main server. I'll do that now
What do you mean by access machines pop up ?
Still not connecting
I got the same Uhoh page as BindEyeVend when trying to download the EU-Regular-2
Custom 404 basically
oooh EU Regular 1 connects OK so it can't be an issue with my version of OpenVPN
Could it be the OpenVPN server on Wreath network
I think thats the 10.200.x.250 machine
Did you wait 3+ mins after pressing regenerate before trying to download?
I didn't wait 3+ mins. Just waited for the timer which was a few seconds. I can try waiting 3+ mins though
Ye, do that. If it's not working after that you can try to log out of your account and back in again to see if it's working then.
OK thanks for the suggestions @crystal marlin
Gave +1 Rep to @crystal marlin
#site-support The attackboxes I start are really slow is there anything I can do?
Waiting those few mins appears to have done the trick. Thanks again
That previous message wasn't for you, you can subscribe to get more resources in your machines
i am subscribed
is there a way to close every room and attackbox
it is doing of 1 password with hydra
every second
What do you mean by that?
hydra 18 tries a minute
i am not sure i closed my previous rooms and attack boxes
Those should terminate automatically once you leave themπ€
18 tries a minute for hydra is not much right
By rooms, I guess you are talking about target machines that you get to deploy in the rooms. Those are also terminated after one hour if you don't extend their time
It depends upon the target machine whether it is causing delays between consecutive trials
its the H4cked room
Please refer to #room-help π
I didn't suggest you to wait for 2 hours, did I?π€
you did not
Great, you got the passwordπ₯³
Have funπ
Hey guys,
Ive been trying to solve the Overpass challenge but the web server seems to be very slow. Ive tried on public instance and it even didnt want to let me in on the website. On the VIP instance pages seem to be loading but not fully. Other challenges work just fine. Pls help :/
Hi, I canβt access the machine IP address provided in the tutorial
Are you opening the IP inside the browser of the attackbox or you trying to open it on your own machines browser?
Am able to access the machine using browser, am on exploiting SMB tutorial then I used the IP address of the system allocated for my tutorial to try out the commands as it were on instruction menu, itβs not working. Most commands am typing on CLI isnβt working
I used βenum4linux-A (ip address of the machine info I got connected to) itβs not showing information about the system. I got error with that I couldnβt complete the task
Oh I thought you were talking about the "tutorial" room π
Hmm hmm
Maybe lets move that to #room-help as I don't think it's a technical issue.
Hey, I'm experiencing issues with the zthobscurewebvulns Task 18 [Section 3.5 - JWT]: Challenge Machine (JWT_2). It fires up and gives me an IP, but whatever app is there appears to hang and eventually time out.
There's a web server running (can be confirmed by random URLs returning 404). From reading around the web I would expect the /auth end point to do something at least but it times out as per above. Let me know if there's any more info I can provide π
Can confirm all the obvious too: no proxy, other machines work just fine, have tried turning it on and off a few times.
I don't know that room, but if you face some kind of connection issues while being connected via openvpn you could try sudo ifconfig tun0 mtu 1200 to see if that solves your issue. If it doesn't solve it just put it back to 1500. If you are on the web based attackbox, just forget what I wrote π
That did the trick. Thanks!
Hello people, I'm having trouble on the Upload Vulnerabilities room, I added the host to /etc/hosts as specified in the beginning of the room and I am able to access the different websites from my browser, but Burp fails to. When I turn on intercept and forward the request, it never comes back and I have an error in the dashboard "Error Proxy Failed to connect to java.uploadvulns.thm:80", I did not find any solution from Burp doc so far, did anyone ever had this problem ?
Check your /etc/hosts file if you accidentally added the hosts multiple times.
Indeed there were two lines, changed it and restared burp and it's working π Didn't know about this thank you very much for the help
Is there an issue doing Task 26 in the OWASP Top 10 Course ("Insecure Deserialization - Code Execution") from the Attack Box? I've successfully generated the encoded string after creating the script, but it's having no effect when I replace that value for the field in my cookie. Any idea what I might be missing? I've checked my script letter-for-letter and copy-pasted against successful writeups, but refreshing the page after updating the encodedPayload just instantly refreshes with no nc connection.
the red box on top of the rooms is not changing to green...
When we access a machine and connect to VPN we see the ip of the vpn on top in a green box(which without connection is red and say access machine)
But this is not happening in the case of Indian VPN servers
So could you connect to the THM network with openvpn and send a screenshot of the output of openvpn?
You have to verify first in order to be able to send screenshots.
!docs verify
Check this out!
Aren't you able to ping 10.10.10.10 and visit 10.10.10.10 in your web browser?
everything is working fine just the pop switch isnt working!!
Access Machines?
yes
Is it affecting you in any way?
yes i need my machine ip which is generally displayed in that spot to be visible
You can get you IP by typing ifconfig in your terminal, it will be the tun0 interface
Are you talking about target machine ip?
π€¦π» DUH...
i need a couple of screenshots of that portal and want it to have the ip
no...
Ok, the web page won't show your IP in that spot if that's what you are asking. (EDIT: it does show that)
You can instead visit https://tryhackme.com/access and have your IP displayed there
Not pretty nice of you to poste the "facepalm" emote while people are trying to help you, so whatever ... π
BRO... not being rude!!
just stuck in a messy situation
no intention to offend!
I have an assignment to submit and this ss thing is irritating me... Proctors wants me to send with ip on that page
I was wrong, it does show you your IP.
Try switching to the correct server here and it should show your IP at your described location
You don't need to regenerate or use a different VPN config
Only select the correct VPN Server from the drop-down list
yeah now u got me right... so the thing is for Indian servers the Access Machines is not changing for the ip!
if we connect to a ovpn file of indian server the access machines part is not changing else it is!
So you have IN-... selected there and you are using IN-... config file?
yes sir...
There have been some issues with that part of the site, VPN config
If you are required to add your IP in your screenshot for any assignment, please consult with your mentor
Or you can edit that Access Machines element to show your IP, if you can π
π yeah i am keeping that as the last resort
You just need to change the class attribute from thm-disconnected to thm-connected and change Access Machines text to your IP
yeah right...
Thanx man for helping me out!!
Getting 404 when trying to download openvpn config
Anyone else experiencing this or am i doing something wrong?
show ur step
like, i've tried changing the VPN Server between the two regular ones, and I've regenerated it (after i got the first 404)
yes
maybe u tried to reload whole page and did it again
no succes, tried reloading with ctrl+shift+r
erm excuss me ....which country u live in
denmark
and which server u choose
so ur problem is got 404 error when when u click download?
yes when i try to download the openvpn config
using both the green button and the link further down
hm
maybe this will help u , the 404 error is when the url (the button ) u click is removed or not exist
#site-support message try this
I'm getting this as well, I'm from Australia
will do, thanks
Gave +1 Rep to @hollow otter
thanks mosquittos I'll try that also
Hi everyone, just upload my first vm file. How long will it take for converting?
@hollow otter I did not get it to work following both of those suggestions..
Hi I receive 404 wheb trying to download vpn configuration files.
@agile fossil This was suggested to me: #site-support message
But it didn't work for me. Hopefully it works for you
sorry cant help you more, gotta wait for thm staff to help you ig
I tried to change my payment info but i don't see an option, so i decided to cancel the subscription but I still don't know how to do it 'cause this button appear. My subscription end yesterday. Can you help me?
does clicking that button do anything?
I think usually after you cancel, you have to wait till it expires before you can re-subscribe
that button kinda looks like what you want?
Cancel your subscription then resubscribe with your new details:)
All you need to do now is wait for the time you paid for to expire
if i click the button it like i never cancel the subscription but it dont let me change my payment info and my subscription expire end yesterday
Hi! I'm getting still the 404 error code when trying to download an OpenVPN from EU-Regular-1 -server or from EU-Regular-2 -server. I've been trying these instructions: #site-support message but didn't help. I've also tried to make a new account, but same thing. Any ideas? I've been using USA East, but eg NMAPing is so slow that it makes it tedious, living in Europe. :D I'll try to make a new account again, and see if it would this time work. Thanks in advance! :)
Edit: I've tried to use another browser that did not have any kind of extensions but did not work either.
Same here.
Is it just me or even after connecting openvpn (Initialization Sequence Completed) it shows disconnected? It's been 15 mins now and several refresh.
Same here re. 404
Yep
Is it possible to change my display name on the site?
as per pins
#site-support message
is username something other than display name?
No, but I wanna change it on THM, not in here
Or are you saying there isnt a way to do it on my own, to email support. If so, thank you!
lol, yes you have to email
Word, appreciated
np
I would not rely on that "disconnected graph", rather just try if you can access machines.
Nope I cannot access machine too.
So just to clarify, you can not access a target machine or you simply can not access 10.10.10.10 in your browser which would just show you that you are connected?
Cannot access 10.10.10.10
So I would try if you can access a target machine, maybe it's just somehow not working properly as the website does. Btw, you keep the terminal open where you started openvpn and you are also not pressing ctrl + C after connecting via openvpn? Because if you close the terminal where you started openvpn you will get disconnected.
Nope no ctrl+c
And you also keep that terminal open and just minimise it rather then closing it?
Mh, well. Then I don't know, as the open vpn output looks pretty normal as far as it is visible in your picture.
instead I can use Attack box but for 1 time only
Have you already tried to change VPN server, regenerate a new config file and try again with that new config file?
Yes. This is the same problem I faced #site-support message
Even tried #site-support message but no luck
Well then your problem might be that you are using a old openvpn config as you tried to regenerate a new one, so I believe that old config file will not working anymore.
That is also not a problem, as soon as I regenerated IN-regular-1 (||btw this vpn server is working, I mean I can just connect openvp||) I downloaded new config file and connected with openvpn
Anyway Let me use Attackbox for today, I'll checkout openvpn stuff after day or two.
I didnt have a problem using the vpn I had a problem downloading the configuration in the first place. We solved it, though we had to switch to IN servers while we are from EU
Yup its working for me too
thanks everyone
msf6 exploit(multi/http/apache_mod_cgi_bash_env_exec) > exploit
[] Started reverse TCP handler on 10.17.22.82:4444
[] Command Stager progress - 100.46% done (1097/1092 bytes)
[*] Exploit completed, but no session was created.
i am try to solve 0day but getting this error just whole day i am try getting this error i am just frustrated please guide me on this
Can you share the output for show options while in the same msfconsole session as above?
Did you modify all of the required options?
Like LHOST (you did this one), RHOSTS, TARGETURI, HEADER, ...?
And please share any code or output in between ``` to prevent any text formatting by Discord or post images
CMD_MAX_LENGTH 2048 yes CMD max line length
CVE CVE-2014-6271 yes CVE to check/exploit (Accepted: CVE-2014-6271, CVE-2014-6278)
HEADER User-Agent yes HTTP header to use
METHOD GET yes HTTP method to use
Proxies no A proxy chain of format type:host:port[,type:host:port][...]
RHOSTS 10.10.64.229 yes The target host(s), see https://github.com/rapid7/metasploit-framew
ork/wiki/Using-Metasploit
RPATH /bin yes Target PATH for binaries used by the CmdStager
RPORT 80 yes The target port (TCP)
SRVHOST 0.0.0.0 yes The local host or network interface to listen on. This must be an a
ddress on the local machine or 0.0.0.0 to listen on all addresses.
SRVPORT 8080 yes The local port to listen on.
SSL false no Negotiate SSL/TLS for outgoing connections
SSLCert no Path to a custom SSL certificate (default is randomly generated)
TARGETURI /cgi-bin/test.cgi yes Path to CGI script
TIMEOUT 5 yes HTTP read response timeout (seconds)
URIPATH no The URI to use for this exploit (default is random)
VHOST no HTTP server virtual host
Payload options (linux/x86/meterpreter/reverse_tcp):
Name Current Setting Required Description
---- --------------- -------- -----------
LHOST 10.17.22.82 yes The listen address (an interface may be specified)
LPORT 4444 yes The listen port
Lets not discuss here, stick to one channel #room-hints or #room-help
hi
i faced an issue with openvpn conf file π
can i get some hjelp?
i mean im getting 404 after clicking on downlad button
Hi guys, i have a question, i need to perform an nmap on an IP address and I did :
nmap [IP]
nmap -sS [IP]
nmap -sT [IP]
This is on network services 1 / FTP / Question 1
The only port i can see is Port 21 FTP, but the answer is 2
I did a mistake or not enough precisions in my command ?
maybe try a full scan with -p-
hey im running the burpsuite room and im running the request analysis and after pausing at around 10k requests I am not able to click the analyze now button
#site-support message
I would even wait 3+ mins rather then only 2.
Hey guys - I've just enrolled in the Pre-Security pathway but I previous completed the cat linux.txt badge / rooms (linux part 1-3) but in the Pre-security pathway its saying I have not completed them... is this a bug or intended?
Some context ^
Have you tried to do a hard refresh with ctrl + F5 if you are on chrome or firefox?
i remember having that bug also back in the day. I can't recall exactly what I did to resolve it. I think I actually just went through each page in the room and made sure I hadn't missed any "completes"
Sure, I'll give that a go, thanks S0cket
Well these rooms also got updated, so if it was ago quite a while when you did them you received the badge for the older linux Fundamentals rooms but haven't done the new ones.
Aye its been maybe 4 months?
Ye then it's most likely that's why
Can't hurt to have a refresher, just wanted to check, thanks for the info
You can check by opening that room to see if you solved it, then it is because of the updated rooms: https://tryhackme.com/room/linux1
Gave +1 Rep to @crystal marlin
new question, im running vulnversity and pinging the server works just fine but for some reason i cant seem to access the website on firefox for the burpsuite stuff
What's the url you try to open?
the ip of the machine I started (in this case 10.10.76.67)
Have you finished task 2 already?
yes as well as task 3, although that was yesterday and I took a break, do I need to redo any of those steps?
What does the url in task 3 say ? http://<ip>:3333 π
this is why i shouldve just powered through
thanks
Gave +1 Rep to @crystal marlin
Am I blind? Where does one shutdown a machine from a previous room? - Yep im blind
hello, can i still get tickets from completing the pre security path rooms?
same thing happened to me. try downloading a different vpn package(like, if you tried US, try one from the EU)
Unfortunately no the event has ended since a couple of weeks
( Or months ? Can't remember
)
is anyone able to access OpenVPN via Indian Servers?
Do you need a USB flash to copy a linux distro file into your SSD or will a pendrive work?
(I'm tryna change my OS
)
I want to ask about discount for student. I have registered with mail edu but that last 2 months. it automatically deducted my 10$ monthly
You'll have to email support@tryhackme.com and they will apply the discount for you
Thanks
i m getting this error in nagio room
Databse Error
A database connection error has been detected, please follow the repair prompt below. If the issue persists, please contact Nagios support.
Run the following from the CLI as root to attempt to repair the DB:
/usr/local/nagiosxi/scripts/repair_databases.sh
have you tried changing vpn server???
if yes have you tried regenerating and waiting a few mins
if yes shadow dunno what the next step was
Having issues with OWASP Top ten task 7. I run the <iframe src="javascript:alert('xss')"> command and get the pop up but the search results box is blank. I dont get the flag needed to proceed. I have restarted attackbox, and active machine several times, enabled and disabled popups in firfox and changed themes to see if I am missing something. Inspection shows nothing either
solved
Which channel is good for support with box creation? I have a tech issue
Probably the creators-lounge. A mod will have to add you to it
this is a problem with only one of the servers. is it a US one? I and a few others have had the same problem. I mentioned it here but no one from thm has acknowledged ityet
no clue if this can help, is ad block disabled
I had the same issue this morning but it cleared up. Try agin.
I think so, but will double check.
Anyhow, I'm reviewing SMB under the learning thing but the target host doesn't response either by VPN or by using their little 'attack boxes'. Can ping localhost, defaut gw but the target at 10.10.10.2 is dead. is this normal?
its the firefox inside the vm. does that have ad block on it?
i would strongly recommend removing ad blocker on the browser you use for hacking. it can mess up the way the website looks
i highly doubt it; i never use the vms. google how to find what firefox extensions are installed
try connecting to it with with smbclient or smbmap? it could still be up, just not responding to pings
I did
and?
arp cache empty, smbclient = connection failed, nmo arp cache entry anyhow
simple ping fails
foxyproxy was the only extension. turning it off had no effect
ok, you can rule out firefox extensions as the problem then
To which target?
Did you try it with 10.10.10.10?
anyhow, that faild also
Actually, 10.10.10.10 is to test your connection to THM network
you'd think this platform would work as described
Hey, I have a problem with room blue from offensive pentesting. I know which exploi should I use, but it cannot create session and after few tries machine stops responding at all.
I assume your openvpn is working correctly and you are connected.
Could you try to fix your MTU size?
yes, connected via VPN and on their little hackbox, neither see .2
i would run this https://github.com/tryhackme/openvpn-troubleshooting
just to be extra sure everything with the vpn is 100%
again, i can ping my default gw, localhost and .10 responded. just not .2. It's not a VPN issue
derp
good answer
@sinful iron The machine may not respond to pings
have you tried turning it off and back on again? xP
we know that. DOesn't respond to smbclient nor nmap
reboted already, re-VPN-ed, got fresh VPN config
i see gregs patience slowly dwindling xP
Oh ok. The AttackBox should be able to connect to the target.
I knew, GregM might know thatπ
You'd think
well, if 10.10.10.10 works it makes me think the problem is with the box he's targeting. if he reverted, i'm unsure where to go from there
ok but admit it
Ah, sorry. My text got cut smhπ
There is some other issue
lot of the time it is user error xP
certainly but I've done all the troubleshooting things imaginable to me
wonder if my 10. network is causing this. I'm on a 192 but tun0/VPN.
me and infloop don't have premium so we can't boot up the room ourselves xP
hold up
your tun0 lhost is on 10. right lol
yes
any firewall rules ?
not on the host
that wouldn't explain why ICMP fails
He tried with AttackBox as well so no interference from his system in any wayπ€
i conclude the box is messed up
you two have fun with this, i got PWK machines to pwn
testing for OSCP in 3 days π
same
like Proving Grounds?
I got some cool writeups on proving ground vulnhub boxes at madunix.com
might help on your oscp
get a signed cert xP
i shold!
its free
Room USTOUN
Fucking room, not fuction!
Port 1433 closed
5 Restart and not function
alright. see yas.
What is this academic material?
Did you mean the target MACHINE_IP value as shown on the room page?
Can any of you help me with eternalblue issue? Blue room. Exploit completed, but no session was created?
Please refer to #room-help or #room-hints first
ok ,thx
^-- and reboot the machine
I did it like 5 times
The room has been working for me, so there might not be a tech-issue , thus not requiring tech-support so soonπ
every time i hit download on OpenVPN Config .... it's keep giving me error
anyone know how to solve it ????]\
Yeah... it did work Thx BTW π
Gave +1 Rep to @crystal marlin
Hi all, is it just me or does network connection to the machines become unstable during rush hour?
What you mean by that, so what's happening?
I know my connection is stable but I am constantly losing connection to the boxes I am attacking, and I only got this behavior during what I can interpret as EU rush hour
and I was just trying to figure out if in fact it has something to do with network traffic
So I assume you are using your own machine connected with openvpn?
yeap
Well if you say that's only happening while "rush hour" then it might be really just because of that. Either way, the next time you face that issue you could try sudo ifconfig tun0 mtu 1200 to see if that solves your issue, if it does - great, otherwise just put it back to 1500.
Thanks but why would that help me?
Because that's an already known solution for such connection issues here. But like I said, if it's not helping you just put it back to 1500.
Ah, ok. Didn't know that. Thanks @crystal marlin
Gave +1 Rep to @crystal marlin
What are we looking at?
thank you
Gave +1 Rep to @wind wedge
Anyone know why I would be getting Color Depth error's when trying to use Remmina to connect to my lab machine?
Anyone here? I can't use the attack box at home
quick question if I run kali linux on my Virtual box do i need to lauch open vpn on mac or install and run it in the virutal box?
I have been having troubles with very slow connections when accessing any of the rooms http sites through OpenVPN. The page will get hung up when they try to access a cloudfare or bootstrap site. Internet connection should be plenty fast enough.
Disregard. Read back through and setting the mtu to 1200 seems to work well enough.
you can run it in the VM itself. here is the command
sudo openvpn <your ovpn file>
Yes, you have to run it inside your kali VM, otherwise that will cause issues with reverse shells and so on.
hey guys, I'm having problem with the Network Service room, the problem is that the option to put the answers is not available, and the room seems already green like they have already answered.
Anyone has the link how to generate invoices for vouchers that I bought last year?
in tryhackme dashboard ts says that when you get 45 badges then you will get a 5% discount so i want to know weather the discount is for monthly premium or annual premium
@Staff
@zealous yoke
Hi, please be a bit patient -- someone will help you out when they can
The 5% discount is "off [the] swag" meaning THM merchandise store.tryhackme.com (not your subscription)
You have to email support'tryhackme.com to receive your voucher. Please include your THM username
try emailing support
any one know if there's a convenient page that shows all currently running vms? it would be nice to see where i have left the lights on, as well as have one page to refer to for the IP, time, and similar info
This is what you need (: https://tryhackme.com/api/vm/running you can see the room code here and then navigate to that in your browser and terminate the vm etc
there is a javascript snippet to terminate all of them at one time but I can't quite remember what it is with the new API route
oohh api :3
are there any api docs out of intrest? that answers that question tho π
thank you
There is, but the api docs currently are quite out of date as of recent (as we just had a whole refactor for the API see here: #announcements message). To be completely honest, I really haven't had the time to update them @vapid mirage
Maybe I can make some time over the next week or so but here is a community repo for the API, no reason why others cant commit ((:
the only actively maintained API docs are our education & business APIs (:
I'll work on the community/site stuff when I can
Thanks I'll give it a look
M not able to upgrade to premium, it's not accepting payment
Is the thm-api-py the current API code?
Does anyone know how to enable the teacher dashboard? I'd like a better way to assign rooms to students that just sending them direct links
Ive just signed up for the premium tier, i am trying to connect to the VPN from my own linux host and I am getting the following errors:
2021-09-17 15:33:56 library versions: OpenSSL 1.1.1l 24 Aug 2021, LZO 2.10
2021-09-17 15:33:56 OpenSSL: error:0909006C:PEM routines:get_name:no start line
2021-09-17 15:33:56 OpenSSL: error:140AD009:SSL routines:SSL_CTX_use_certificate_file:PEM lib
2021-09-17 15:33:56 Cannot load inline certificate file
2021-09-17 15:33:56 Exiting due to fatal error
I have regenerated the connection pack, rebooted, updated my distro and tried again, same issue.
I can connect to other VPN's via openvpn (https method) without issue.
Can someone please help me out?
I'm still getting 404 on my EU regular openvpn config download. Tried everything I can find/have been suggested here, including regenerating (and waiting 5 min), changing VPN server, logging out and in. I'm at a loss here, no idea what to do. Anyone?
@rapid shore I am trying
VPN Server Name EU-Regular-2
Is this same server you are having issues with?
access page has the status as UP
I have tried both EU-Regular-1 and EU-Regular-2, tried several times over the past few days
OH
finally
got a ovpn file
nvm haha π
...so ive got the file... but
it isnt connecting
chucking the errors i posted above ^^^
@rapid shore can you connect okay?
gimme a sec and i'll try
π let's see if i can get in too
seems i'm connected just fine. Finally I can get to the fun part π
hii can some one tell me how to change the country from my profile
You can try this
https://tryhackme.com/api/user/update-timezone